Privacy policy — Legalnaut  A Markdown version of this page is available at https://legalnaut.com/privacy.md for AI and LLM tools. 

  Privacy policy
==============

 LAST UPDATED 2026-09-11

This policy covers legalnaut.com and the Legalnaut application. The controller is **A2Z WEB PTE. LTD.**, 7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987, registration 202614429R.

1. What we collect
------------------

**Account data.** Name, email address, password hash, workspace membership and role.

**Case material.** The documents you import, the text extracted from them, and the analysis derived from that text. We treat this as confidential material belonging to you, not to us.

**Usage data.** Server logs, error reports, and a record of consequential actions in the audit log.

**Billing data.** Handled by Stripe. We never see or store card numbers.

2. Why we process it
--------------------

To provide the service you have subscribed to, to bill you for it, to keep the service secure, and to meet our legal obligations. Case material is processed only to provide the service.

3. Sub-processors
-----------------

ProcessorPurposeLocationLanguage model providersDocument analysis and chat answersEU / USCloud hosting and object storageApplication hosting, file storageEUAmazon Web Services (Textract)OCR when local extraction failsEUStripeSubscription billingUS / EUZoho MailInbound document forwardingEUOur agreements with every model provider prohibit training on customer content.

4. Retention
------------

Case material is kept for as long as your workspace exists. Nothing deletes it on a schedule. If a subscription lapses, the workspace becomes read-only; clearing it is a deliberate action taken on request or after a documented period, never automatically. Invoicing records are kept for five years under Singapore tax law. Server logs are kept for 90 days.

5. Your rights
--------------

If the GDPR applies to you, you have the right to access, rectification, erasure, restriction, portability and objection, and the right to complain to a supervisory authority. Write to  and we respond to verified requests within 30 days.

6. Security
-----------

TLS 1.2 or better in transit. Encryption at rest for databases and backups. Hashed passwords. Optional two-factor authentication. Separate database and file storage per workspace. Access to production restricted on the principle of least privilege. SOC 2 Type II certified infrastructure.

No transmission over the internet is completely secure. If you believe an account has been compromised, write to us immediately.

7. Cookies
----------

We set a session cookie needed to keep you signed in, a cookie recording your theme choice, and one recording whether the sidebar is collapsed. None of them track you across sites. Analytics, if enabled, runs only with your consent.

8. Changes
----------

Material changes are announced in the application before they take effect.

 SCREENSHOT

    ![]()
