Privacy Policy

Last Updated: March 2026


Table of Contents

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Basis for Processing
  5. Data Sharing and Disclosure
  6. Sub-Processors
  7. International Data Transfers
  8. Data Security
  9. Data Retention
  10. Your Rights
  11. Cookies
  12. Changes to This Policy
  13. Contact Us

1. Introduction

Lawfair ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect information when you use the Lawfair platform.

Lawfair is an AI-assisted legal analysis tool for Scottish civil litigation. Given the sensitive nature of legal case data, we apply strict data minimisation and security controls.


2. Information We Collect

Account data:

Case data:

Usage data:

Technical data:

Cookie data: See Cookie Policy.


3. How We Use Your Information

PurposeLegal Basis
Providing the analysis serviceContract performance
Account management and authenticationContract performance
Security monitoring and fraud preventionLegitimate interests
Service improvement and debuggingLegitimate interests
Analytics (with consent)Consent
Legal compliance and auditLegal obligation

Case data is used solely to generate the analysis you request. It is not used to train AI models, profile users, or shared with third parties for commercial purposes.


4. Legal Basis for Processing

We process personal data under UK GDPR on the following bases:


5. Data Sharing and Disclosure

We do not sell your personal data. We share data only:


6. Sub-Processors

Sub-ProcessorPurposeLocation
AWSCloud infrastructure (compute, database, storage, task queue)UK (eu-west-2)
Auth0Authentication and identity managementEU
AnthropicAI analysis engine (zero-retention API)USA (SCCs applied)
OpenAIText embeddings for RAG retrieval (zero-retention API)USA (SCCs applied)
Google AnalyticsTraffic analysis (consent-gated)USA (SCCs applied)

Anthropic and OpenAI zero-retention: We use these APIs with zero-retention / no-training configurations. Your case data is processed to generate a response and is not stored or used by these providers for model training.


7. International Data Transfers

Some sub-processors are based outside the UK/EEA (notably Anthropic and OpenAI in the USA). Where data is transferred internationally, we rely on:


8. Data Security

We implement appropriate technical and organisational measures to protect your data:


9. Data Retention

Data TypeRetention Period
Account dataUntil account deletion + 30 days
Case analysesUntil account deletion + 30 days
Usage dataUp to 2 years
Technical logsUp to 2 years
Cookie consent records3 years (GDPR accountability)

Following account deletion, personal data is deleted within 30 days except where retention is required by law.


10. Your Rights

Under UK GDPR, you have the right to:

To exercise your rights, contact us at privacy@lawfair.uk. We will respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk


11. Cookies

See our Cookie Policy for full details of cookies used and how to manage your preferences.


12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification. The "Last Updated" date at the top reflects the most recent revision.


13. Contact Us

Data controller: Lawfair

Email: privacy@lawfair.uk

For general enquiries: legal@lawfair.uk