Privacy Policy
Last Updated: August 2026
Table of Contents
- Introduction
- Information We Collect
- How We Use Your Information
- Legal Basis for Processing
- Data Sharing and Disclosure
- Sub-Processors
- International Data Transfers
- Data Security
- Data Retention
- Your Rights
- Cookies
- Changes to This Policy
- Contact Us
1. Introduction
The Lawfair platform is operated by Cyber Mangrove Ltd (Company No. SC625467) ("Cyber Mangrove", "we", "us", "our"), which is the data controller for the personal data described in this notice. Cyber Mangrove Ltd is registered with the Information Commissioner's Office (ICO), registration reference ZC207142.
Registered address: Hudson House, 8 Albany Street, Edinburgh, Scotland, EH1 3QB
Lawfair is an AI-assisted legal analysis tool for Scottish civil litigation. Given the sensitive nature of legal case data — which may include special-category data such as health information contained in case materials — we apply strict data minimisation and security controls.
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
If the Lawfair business is later transferred to a successor entity (including a company incorporated to operate Lawfair), that entity may become the data controller. We will update this notice to name it and notify you before it takes over that role.
2. Information We Collect
Account data:
- Name, work email address, company/firm name, and role/job title (required at sign-up)
- Mobile phone number (optional — used only to contact you for feedback and support during the beta)
- Company/firm registration number (optional — used only to verify your firm)
- Account credentials (managed by Auth0 — we do not store passwords)
Case data:
- Factual narratives and documents you upload for analysis (documents are retained with the case — see Data Retention)
- Analysis outputs generated by the Service
- Procedural posture, case references, and metadata you provide
Usage data:
- Features used, pages visited, time spent
- Pipeline step completion, analysis frequency
Technical data:
- IP address, browser type, operating system
- Access times, error logs
Cookie data: See Cookie Policy.
3. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Providing the analysis service | Contract performance |
| Account management and authentication | Contract performance |
| Contacting you for feedback and support during the beta (by email, and by phone if you provide a number) | Legitimate interests |
| Verifying that your firm is genuine before approving access | Legitimate interests |
| Security monitoring and fraud prevention | Legitimate interests |
| Service improvement and debugging | Legitimate interests |
| Analytics (with consent) | Consent |
| Legal compliance and audit | Legal obligation |
Case data is used solely to generate the analysis you request. It is not used to train AI models, profile users, or shared with third parties for commercial purposes.
4. Legal Basis for Processing
We process personal data under UK GDPR on the following bases:
- Contract performance: Processing necessary to deliver the Service you have signed up for
- Legitimate interests: Security monitoring, service improvement, fraud prevention — where these do not override your rights
- Consent: Analytics cookies and associated tracking — only where you have explicitly consented
- Legal obligation: Retention of certain records as required by applicable law
5. Data Sharing and Disclosure
We do not sell your personal data. We share data only:
- With sub-processors necessary to deliver the Service (see Section 6)
- Where required by law, court order, or regulatory authority
- To protect the rights, property, or safety of Lawfair, our users, or the public
6. Sub-Processors
| Sub-Processor | Purpose | Location |
|---|---|---|
| AWS | Cloud infrastructure (compute, database, storage, task queue) | UK (eu-west-2) |
| Auth0 | Authentication and identity management | UK |
| Anthropic | AI analysis engine (no model training; ≤30-day retention) | USA (SCCs applied) |
| OpenAI | Text embeddings for RAG retrieval (no model training; ≤30-day retention) | USA (SCCs applied) |
| Google Analytics | Traffic analysis (consent-gated) | USA (SCCs applied) |
Anthropic and OpenAI — no training, limited retention: We use these providers' APIs in configurations where your data is not used to train their models. Each provider may retain API inputs and outputs for a limited period (up to 30 days) for abuse-monitoring and security purposes, after which they are deleted. Your case data is not used by these providers for any other purpose.
7. International Data Transfers
Some sub-processors are based outside the UK/EEA (notably Anthropic and OpenAI in the USA). Where data is transferred internationally, we rely on:
- Standard Contractual Clauses (SCCs) approved by the ICO
- Sub-processor commitments to equivalent data protection standards
8. Data Security
We implement appropriate technical and organisational measures to protect your data:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Infrastructure in a dedicated cloud account, with API and database in private subnets, not publicly accessible
- Web application firewall (AWS WAF) in front of the application, with rate limiting
- Infrastructure audit trail (AWS CloudTrail) with log integrity validation, including access to stored documents
- Auth0 with mandatory MFA for all accounts
- Role-based access controls, with every account's activity recorded in an audit log you can view
- Security is reviewed internally before each stage change; no independent penetration test has yet been carried out
- Security incidents are handled directly by the operator, and affected users are notified without undue delay
Personal data breaches. Where a breach of personal data occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
9. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion (immediate) |
| Case analyses | Until account deletion (immediate) |
| Uploaded documents | 90 days after you last use them, or until you delete the case or your account — whichever is sooner |
| Usage data | Up to 2 years |
| Technical logs | Up to 2 years |
| Cookie consent records | 3 years (GDPR accountability) |
Account deletion is immediate. When you delete your account from Settings, your account, every case analysis on it, and every document you uploaded are permanently destroyed at once. Settings provides an export so you can take your data with you first. One qualification, so that "immediate" is not misread: our database keeps encrypted automated backups for seven days, so a deleted record persists in those backups until they age out. The backups are encrypted, are never read in the ordinary course, and are not restorable by you or by anyone outside our infrastructure administration.
Why we keep the documents you upload. A document is kept with its case so that the case can be re-run, added to or corrected without you uploading the bundle again, and so that improvements to how we read documents — a scanned exhibit we could not read at the time you sent it, for instance — can be applied to work you have already submitted. Documents are encrypted at rest and are never made publicly accessible. They are deleted 90 days after the case they belong to was last used; using the case resets that period, and deleting the case or your account deletes them at once.
What survives deletion, and why. We retain a small number of records with all identifiers removed, so they cannot be linked back to you: consent records and terms acceptances, kept for accountability and to establish or defend legal claims, and aggregate usage data. Where the law requires us to keep a record — financial and accounting records, for instance — we keep it for the period the law requires.
10. Your Rights
Under UK GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — restrict how we process your data
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent
To exercise your rights, contact us at privacy@lawfair.uk. We will respond within one calendar month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk
11. Cookies
See our Cookie Policy for full details of cookies used and how to manage your preferences.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification. The "Last Updated" date at the top reflects the most recent revision.
13. Contact Us
Data controller: Cyber Mangrove Ltd (Company No. SC625467)
Registered address: Hudson House, 8 Albany Street, Edinburgh, Scotland, EH1 3QB
Data protection enquiries / to exercise your rights: privacy@lawfair.uk
ICO registration: ZC207142
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint