Legal Analytics Logo
LegalAnalytics
Betav0.2.0
Back To Home

Privacy Policy

Effective Date: January 25, 2026 | Version: 1.0.0

This Privacy Policy explains how LegalAnalytics ("we," "us," or "our") gathers, utilizes, and shares personal information when you access our website and platform (collectively referred to as the "Service"). LegalAnalytics is a HIPAA-compliant platform designed for legal professionals to analyze medical-legal documents. By using the Service, you agree to the collection, use, and sharing of your personal information as outlined in this Privacy Policy.

Information We Collect

  • Contact Information: Such as your name, email address, and phone number.
  • User Profile Information: Such as your job title, company name, and role (Admin, Operator, or Expert).
  • Authentication Information: Including password (encrypted), two-factor authentication codes, and account verification data.
  • Case and Document Data: Medical records, legal documents, case information, and associated metadata you upload or create.
  • Protected Health Information (PHI): Medical information extracted from documents, including conditions, procedures, medications, and dates.
  • Chat and Conversation History: Your interactions with our AI-powered chat system, including questions, responses, and citations.
  • Usage Information: Pages you visit, features you use, time and date of your visits, and system actions.
  • Device and Browser Information: Device type, operating system, browser type, and IP address.
  • Audit Logs: Records of data access, modifications, and security events for HIPAA compliance.

How We Use Your Information

  • To provide and maintain our document analysis and case management services
  • To process medical documents using AI/ML and extract relevant information
  • To generate legal reports (Appendix 3, case summaries) and provide AI-powered chat assistance
  • To authenticate users and maintain HIPAA-compliant access controls
  • To communicate with you about your account, cases, and service updates
  • To improve our services, fix bugs, and develop new features
  • To comply with legal obligations and maintain audit trails
  • To detect and prevent fraud, security breaches, and unauthorized access

We may also use your personal information for other purposes with your explicit consent.

How We Share Your Information

We do not sell your personal information. We may share your information only in the following circumstances:

  • Within Your Organization: Case data may be shared with other authorized users in your organization based on role-based access controls.
  • Service Providers: We share data with trusted third-party service providers who assist us with the Service, including:
    • Google Cloud Platform (infrastructure and AI services)
    • Resend (email notifications and 2FA delivery)
    • Cloud storage providers (document storage)
    All service providers are required to maintain HIPAA compliance and sign Business Associate Agreements (BAAs).
  • Legal Requirements: When required to comply with legal obligations, court orders, or to protect our rights and prevent illegal activities.
  • Business Transactions: In connection with mergers, acquisitions, or asset sales, with appropriate safeguards for your data.

HIPAA Compliance

LegalAnalytics is designed to be HIPAA-compliant for handling Protected Health Information (PHI). We implement:

  • Custom Authentication: No third-party authentication providers that would require additional BAAs
  • AES-256 Encryption: All sensitive data is encrypted at rest
  • TLS/SSL Encryption: All data transmitted over networks is encrypted in transit
  • Role-Based Access Control (RBAC): Granular permissions based on user roles
  • Comprehensive Audit Logging: All access to PHI is logged and monitored
  • Two-Factor Authentication (2FA): Additional security layer for account access
  • Secure Cloud Infrastructure: HIPAA-compliant Google Cloud Platform services

Data Storage and Infrastructure

We store data on Google Cloud Platform (GCP) services, including:

  • Cloud SQL (PostgreSQL): For structured data with automated backups and encryption
  • Cloud Storage (GCS): For documents, images, and generated reports
  • Cloud Run: For serverless API and processing jobs

All cloud services are configured with HIPAA-compliant security measures and Business Associate Agreements are in place.

Security

We implement industry-standard security measures to protect your information, including:

  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Regular security audits and penetration testing
  • Multi-factor authentication requirements
  • Automated threat detection and monitoring
  • Secure software development lifecycle practices
  • Regular security patches and updates

However, no internet or electronic storage method is completely secure, and we cannot guarantee absolute security. We will notify you of any data breaches as required by law.

Data Retention

We retain your personal information and case data as follows:

  • Account Information: Retained while your account is active and for up to 7 years after deletion for legal compliance
  • Case and Document Data: Retained according to your organization's data retention policies and legal requirements
  • Chat Conversations: Retained as part of case history for audit and reference purposes
  • Audit Logs: Retained for at least 6 years to comply with HIPAA requirements
  • Deleted Data: Permanently removed from active systems within 30 days, with secure overwriting of storage media

You can request deletion of your data at any time through your privacy settings or by contacting us.

International Data Transfers

Our services are primarily hosted in the United States using Google Cloud Platform. Data may be stored and processed in any country where our cloud providers maintain facilities. By using our Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules.

We implement appropriate safeguards to ensure your data remains protected, including:

  • Standard Contractual Clauses (SCCs) for EU data transfers
  • HIPAA-compliant Business Associate Agreements (BAAs)
  • Data Processing Agreements with all service providers
  • Encryption in transit and at rest regardless of location

Your Rights and Choices (GDPR Compliance)

You have comprehensive rights regarding your personal data. You can exercise these rights through your account's Privacy Settings dashboard:

  • Right to Access (Article 15): Request a copy of all personal data we hold about you in JSON or CSV format via the Data Privacy page
  • Right to Rectification (Article 16): Update or correct your account information at any time
  • Right to Erasure (Article 17): Request deletion of your account and associated data (with 30-day processing time)
  • Right to Data Portability (Article 20): Download your data in machine-readable formats
  • Right to Object (Article 21): Object to certain types of data processing
  • Right to Restrict Processing (Article 18): Request limitation of data processing activities
  • Right to Withdraw Consent (Article 7): Manage consent preferences through the Consent Management interface

To exercise these rights:

  • Visit your Dashboard → Privacy Settings for consent management and data privacy actions
  • Visit Dashboard → Data Privacy to request data access or download your information
  • Contact us at the email address below for assistance

All GDPR-related requests are tracked with unique request IDs and processed according to legal timelines. You can view the history of your consent decisions and data access requests in your privacy dashboard.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Maintain your session and keep you logged in
  • Remember your preferences and settings
  • Track usage patterns to improve the Service
  • Prevent fraud and maintain security

You can configure your browser to refuse cookies, but this may limit your ability to use certain features of our Service. Essential cookies required for authentication and security cannot be disabled while using the platform.

Children's Privacy

Our Service is designed for professional use by legal practitioners and medical experts. We do not knowingly collect information from anyone under the age of 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately, and we will take steps to remove that information from our systems.

Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

  • Consent: When you provide explicit consent for specific processing activities
  • Contract: To fulfill our contractual obligations to provide the Service
  • Legal Obligation: To comply with HIPAA, GDPR, and other legal requirements
  • Legitimate Interest: To improve our services, prevent fraud, and maintain security

All consent decisions are tracked with version numbers and timestamps in our audit system for compliance purposes.

Automated Decision-Making and AI Processing

LegalAnalytics uses artificial intelligence and machine learning for:

  • Document classification and page type detection
  • Medical information extraction from documents
  • Case analysis and report generation
  • AI-powered chat and question answering

All AI-generated outputs are subject to human review by legal and medical experts. We use Google Vertex AI (Gemini) for AI processing, with all data processing covered by HIPAA-compliant Business Associate Agreements. You have the right to request human review of any AI-generated decisions that significantly affect you.

Data Breach Notification

In the event of a data breach involving your personal information or PHI, we will:

  • Notify affected individuals within 72 hours of discovery (GDPR requirement)
  • Notify the U.S. Department of Health and Human Services if PHI is involved (HIPAA requirement)
  • Provide details about the breach, affected data, and remediation steps
  • Offer assistance such as credit monitoring if appropriate

Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.

Policy Updates

We may revise this Privacy Policy periodically to reflect changes in our practices or legal requirements. When we make significant changes:

  • We will update the version number and effective date at the top of this policy
  • We will notify you via email at least 30 days before the changes take effect
  • We will post a notice on the Service
  • We may require you to review and consent to the updated policy

Your continued use of the Service after the effective date indicates your acceptance of the revised Privacy Policy. You can view previous versions of this policy by contacting us.

Contact Us and Data Protection Officer

For questions about this Privacy Policy, to exercise your data rights, or to report privacy concerns:

If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.

This privacy policy reflects our commitment to transparency and compliance with HIPAA, GDPR, and other applicable data protection regulations. We continuously monitor and update our practices to ensure the highest level of data protection for our users.

LegalAnalytics