Privacy Policy

Last Updated: August 2026


Table of Contents

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Basis for Processing
  5. Data Sharing and Disclosure
  6. Sub-Processors
  7. International Data Transfers
  8. Data Security
  9. Data Retention
  10. Your Rights
  11. Cookies
  12. Changes to This Policy
  13. Contact Us

1. Introduction

The Lawfair platform is operated by Cyber Mangrove Ltd (Company No. SC625467) ("Cyber Mangrove", "we", "us", "our"), which is the data controller for the personal data described in this notice. Cyber Mangrove Ltd is registered with the Information Commissioner's Office (ICO), registration reference ZC207142.

Registered address: Hudson House, 8 Albany Street, Edinburgh, Scotland, EH1 3QB

Lawfair is an AI-assisted legal analysis tool for Scottish civil litigation. Given the sensitive nature of legal case data — which may include special-category data such as health information contained in case materials — we apply strict data minimisation and security controls.

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

If the Lawfair business is later transferred to a successor entity (including a company incorporated to operate Lawfair), that entity may become the data controller. We will update this notice to name it and notify you before it takes over that role.


2. Information We Collect

Account data:

Case data:

Usage data:

Technical data:

Cookie data: See Cookie Policy.


3. How We Use Your Information

PurposeLegal Basis
Providing the analysis serviceContract performance
Account management and authenticationContract performance
Contacting you for feedback and support during the beta (by email, and by phone if you provide a number)Legitimate interests
Verifying that your firm is genuine before approving accessLegitimate interests
Security monitoring and fraud preventionLegitimate interests
Service improvement and debuggingLegitimate interests
Analytics (with consent)Consent
Legal compliance and auditLegal obligation

Case data is used solely to generate the analysis you request. It is not used to train AI models, profile users, or shared with third parties for commercial purposes.


4. Legal Basis for Processing

We process personal data under UK GDPR on the following bases:


5. Data Sharing and Disclosure

We do not sell your personal data. We share data only:


6. Sub-Processors

Sub-ProcessorPurposeLocation
AWSCloud infrastructure (compute, database, storage, task queue)UK (eu-west-2)
Auth0Authentication and identity managementUK
AnthropicAI analysis engine (no model training; ≤30-day retention)USA (SCCs applied)
OpenAIText embeddings for RAG retrieval (no model training; ≤30-day retention)USA (SCCs applied)
Google AnalyticsTraffic analysis (consent-gated)USA (SCCs applied)

Anthropic and OpenAI — no training, limited retention: We use these providers' APIs in configurations where your data is not used to train their models. Each provider may retain API inputs and outputs for a limited period (up to 30 days) for abuse-monitoring and security purposes, after which they are deleted. Your case data is not used by these providers for any other purpose.


7. International Data Transfers

Some sub-processors are based outside the UK/EEA (notably Anthropic and OpenAI in the USA). Where data is transferred internationally, we rely on:


8. Data Security

We implement appropriate technical and organisational measures to protect your data:

Personal data breaches. Where a breach of personal data occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.


9. Data Retention

Data TypeRetention Period
Account dataUntil account deletion (immediate)
Case analysesUntil account deletion (immediate)
Uploaded documents90 days after you last use them, or until you delete the case or your account — whichever is sooner
Usage dataUp to 2 years
Technical logsUp to 2 years
Cookie consent records3 years (GDPR accountability)

Account deletion is immediate. When you delete your account from Settings, your account, every case analysis on it, and every document you uploaded are permanently destroyed at once. Settings provides an export so you can take your data with you first. One qualification, so that "immediate" is not misread: our database keeps encrypted automated backups for seven days, so a deleted record persists in those backups until they age out. The backups are encrypted, are never read in the ordinary course, and are not restorable by you or by anyone outside our infrastructure administration.

Why we keep the documents you upload. A document is kept with its case so that the case can be re-run, added to or corrected without you uploading the bundle again, and so that improvements to how we read documents — a scanned exhibit we could not read at the time you sent it, for instance — can be applied to work you have already submitted. Documents are encrypted at rest and are never made publicly accessible. They are deleted 90 days after the case they belong to was last used; using the case resets that period, and deleting the case or your account deletes them at once.

What survives deletion, and why. We retain a small number of records with all identifiers removed, so they cannot be linked back to you: consent records and terms acceptances, kept for accountability and to establish or defend legal claims, and aggregate usage data. Where the law requires us to keep a record — financial and accounting records, for instance — we keep it for the period the law requires.


10. Your Rights

Under UK GDPR, you have the right to:

To exercise your rights, contact us at privacy@lawfair.uk. We will respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk


11. Cookies

See our Cookie Policy for full details of cookies used and how to manage your preferences.


12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification. The "Last Updated" date at the top reflects the most recent revision.


13. Contact Us

Data controller: Cyber Mangrove Ltd (Company No. SC625467)

Registered address: Hudson House, 8 Albany Street, Edinburgh, Scotland, EH1 3QB

Data protection enquiries / to exercise your rights: privacy@lawfair.uk

ICO registration: ZC207142

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint