This Privacy Policy explains how LegalAnalytics ("we," "us," or "our") gathers, utilizes, and shares personal information when you access our website and platform (collectively referred to as the "Service"). LegalAnalytics is a HIPAA-compliant platform designed for legal professionals to analyze medical-legal documents. By using the Service, you agree to the collection, use, and sharing of your personal information as outlined in this Privacy Policy.
Information We Collect
Contact Information: Such as your name, email address, and phone number.
User Profile Information: Such as your job title, company name, and role (Admin, Operator, or Expert).
Authentication Information: Including password (encrypted), two-factor authentication codes, and account verification data.
Case and Document Data: Medical records, legal documents, case information, and associated metadata you upload or create.
Protected Health Information (PHI): Medical information extracted from documents, including conditions, procedures, medications, and dates.
Chat and Conversation History: Your interactions with our AI-powered chat system, including questions, responses, and citations.
Usage Information: Pages you visit, features you use, time and date of your visits, and system actions.
Device and Browser Information: Device type, operating system, browser type, and IP address.
Audit Logs: Records of data access, modifications, and security events for HIPAA compliance.
How We Use Your Information
To provide and maintain our document analysis and case management services
To process medical documents using AI/ML and extract relevant information
To generate legal reports (Appendix 3, case summaries) and provide AI-powered chat assistance
To authenticate users and maintain HIPAA-compliant access controls
To communicate with you about your account, cases, and service updates
To improve our services, fix bugs, and develop new features
To comply with legal obligations and maintain audit trails
To detect and prevent fraud, security breaches, and unauthorized access
We may also use your personal information for other purposes with your explicit consent.
How We Share Your Information
We do not sell your personal information. We may share your information only in the following circumstances:
Within Your Organization: Case data may be shared with other authorized users in your organization based on role-based access controls.
Service Providers: We share data with trusted third-party service providers who assist us with the Service, including:
Google Cloud Platform (infrastructure and AI services)
Resend (email notifications and 2FA delivery)
Cloud storage providers (document storage)
All service providers are required to maintain HIPAA compliance and sign Business Associate Agreements (BAAs).
Legal Requirements: When required to comply with legal obligations, court orders, or to protect our rights and prevent illegal activities.
Business Transactions: In connection with mergers, acquisitions, or asset sales, with appropriate safeguards for your data.
HIPAA Compliance
LegalAnalytics is designed to be HIPAA-compliant for handling Protected Health Information (PHI). We implement:
Custom Authentication: No third-party authentication providers that would require additional BAAs
AES-256 Encryption: All sensitive data is encrypted at rest
TLS/SSL Encryption: All data transmitted over networks is encrypted in transit
Role-Based Access Control (RBAC): Granular permissions based on user roles
Comprehensive Audit Logging: All access to PHI is logged and monitored
Two-Factor Authentication (2FA): Additional security layer for account access
Secure Cloud Infrastructure: HIPAA-compliant Google Cloud Platform services
Data Storage and Infrastructure
We store data on Google Cloud Platform (GCP) services, including:
Cloud SQL (PostgreSQL): For structured data with automated backups and encryption
Cloud Storage (GCS): For documents, images, and generated reports
Cloud Run: For serverless API and processing jobs
All cloud services are configured with HIPAA-compliant security measures and Business Associate Agreements are in place.
Security
We implement industry-standard security measures to protect your information, including:
Encryption at rest (AES-256) and in transit (TLS 1.2+)
Regular security audits and penetration testing
Multi-factor authentication requirements
Automated threat detection and monitoring
Secure software development lifecycle practices
Regular security patches and updates
However, no internet or electronic storage method is completely secure, and we cannot guarantee absolute security. We will notify you of any data breaches as required by law.
Data Retention
We retain your personal information and case data as follows:
Account Information: Retained while your account is active and for up to 7 years after deletion for legal compliance
Case and Document Data: Retained according to your organization's data retention policies and legal requirements
Chat Conversations: Retained as part of case history for audit and reference purposes
Audit Logs: Retained for at least 6 years to comply with HIPAA requirements
Deleted Data: Permanently removed from active systems within 30 days, with secure overwriting of storage media
You can request deletion of your data at any time through your privacy settings or by contacting us.
International Data Transfers
Our services are primarily hosted in the United States using Google Cloud Platform. Data may be stored and processed in any country where our cloud providers maintain facilities. By using our Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules.
We implement appropriate safeguards to ensure your data remains protected, including:
Standard Contractual Clauses (SCCs) for EU data transfers
HIPAA-compliant Business Associate Agreements (BAAs)
Data Processing Agreements with all service providers
Encryption in transit and at rest regardless of location
Your Rights and Choices (GDPR Compliance)
You have comprehensive rights regarding your personal data. You can exercise these rights through your account's Privacy Settings dashboard:
Right to Access (Article 15): Request a copy of all personal data we hold about you in JSON or CSV format via the Data Privacy page
Right to Rectification (Article 16): Update or correct your account information at any time
Right to Erasure (Article 17): Request deletion of your account and associated data (with 30-day processing time)
Right to Data Portability (Article 20): Download your data in machine-readable formats
Right to Object (Article 21): Object to certain types of data processing
Right to Restrict Processing (Article 18): Request limitation of data processing activities
Right to Withdraw Consent (Article 7): Manage consent preferences through the Consent Management interface
To exercise these rights:
Visit your Dashboard → Privacy Settings for consent management and data privacy actions
Visit Dashboard → Data Privacy to request data access or download your information
Contact us at the email address below for assistance
All GDPR-related requests are tracked with unique request IDs and processed according to legal timelines. You can view the history of your consent decisions and data access requests in your privacy dashboard.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to:
Maintain your session and keep you logged in
Remember your preferences and settings
Track usage patterns to improve the Service
Prevent fraud and maintain security
You can configure your browser to refuse cookies, but this may limit your ability to use certain features of our Service. Essential cookies required for authentication and security cannot be disabled while using the platform.
Children's Privacy
Our Service is designed for professional use by legal practitioners and medical experts. We do not knowingly collect information from anyone under the age of 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately, and we will take steps to remove that information from our systems.
Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
Consent: When you provide explicit consent for specific processing activities
Contract: To fulfill our contractual obligations to provide the Service
Legal Obligation: To comply with HIPAA, GDPR, and other legal requirements
Legitimate Interest: To improve our services, prevent fraud, and maintain security
All consent decisions are tracked with version numbers and timestamps in our audit system for compliance purposes.
Automated Decision-Making and AI Processing
LegalAnalytics uses artificial intelligence and machine learning for:
Document classification and page type detection
Medical information extraction from documents
Case analysis and report generation
AI-powered chat and question answering
All AI-generated outputs are subject to human review by legal and medical experts. We use Google Vertex AI (Gemini) for AI processing, with all data processing covered by HIPAA-compliant Business Associate Agreements. You have the right to request human review of any AI-generated decisions that significantly affect you.
Data Breach Notification
In the event of a data breach involving your personal information or PHI, we will:
Notify affected individuals within 72 hours of discovery (GDPR requirement)
Notify the U.S. Department of Health and Human Services if PHI is involved (HIPAA requirement)
Provide details about the breach, affected data, and remediation steps
Offer assistance such as credit monitoring if appropriate
Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.
Policy Updates
We may revise this Privacy Policy periodically to reflect changes in our practices or legal requirements. When we make significant changes:
We will update the version number and effective date at the top of this policy
We will notify you via email at least 30 days before the changes take effect
We will post a notice on the Service
We may require you to review and consent to the updated policy
Your continued use of the Service after the effective date indicates your acceptance of the revised Privacy Policy. You can view previous versions of this policy by contacting us.
Contact Us and Data Protection Officer
For questions about this Privacy Policy, to exercise your data rights, or to report privacy concerns:
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.
This privacy policy reflects our commitment to transparency and compliance with HIPAA, GDPR, and other applicable data protection regulations. We continuously monitor and update our practices to ensure the highest level of data protection for our users.