Legalnaut

Privacy policy

LAST UPDATED 2026-09-11

This policy covers legalnaut.com and the Legalnaut application. The controller is A2Z WEB PTE. LTD., 7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987, registration 202614429R.

1. What we collect

Account data. Name, email address, password hash, workspace membership and role.

Case material. The documents you import, the text extracted from them, and the analysis derived from that text. We treat this as confidential material belonging to you, not to us.

Usage data. Server logs, error reports, and a record of consequential actions in the audit log.

Billing data. Handled by Stripe. We never see or store card numbers.

2. Why we process it

To provide the service you have subscribed to, to bill you for it, to keep the service secure, and to meet our legal obligations. Case material is processed only to provide the service.

3. Sub-processors

Processor Purpose Location
Language model providers Document analysis and chat answers EU / US
Cloud hosting and object storage Application hosting, file storage EU
Amazon Web Services (Textract) OCR when local extraction fails EU
Stripe Subscription billing US / EU
Zoho Mail Inbound document forwarding EU

Our agreements with every model provider prohibit training on customer content.

4. Retention

Case material is kept for as long as your workspace exists. Nothing deletes it on a schedule. If a subscription lapses, the workspace becomes read-only; clearing it is a deliberate action taken on request or after a documented period, never automatically. Invoicing records are kept for five years under Singapore tax law. Server logs are kept for 90 days.

5. Your rights

If the GDPR applies to you, you have the right to access, rectification, erasure, restriction, portability and objection, and the right to complain to a supervisory authority. Write to contact@legalnaut.com and we respond to verified requests within 30 days.

6. Security

TLS 1.2 or better in transit. Encryption at rest for databases and backups. Hashed passwords. Optional two-factor authentication. Separate database and file storage per workspace. Access to production restricted on the principle of least privilege. SOC 2 Type II certified infrastructure.

No transmission over the internet is completely secure. If you believe an account has been compromised, write to us immediately.

7. Cookies

We set a session cookie needed to keep you signed in, a cookie recording your theme choice, and one recording whether the sidebar is collapsed. None of them track you across sites. Analytics, if enabled, runs only with your consent.

8. Changes

Material changes are announced in the application before they take effect.