Privacy Policy
Last Updated: January 2025
1. Information We Collect
Account Information
- Name, email address, password (encrypted)
- Organization name and role
- Billing information (processed by Stripe/Razorpay)
Usage Data
- Documents created, edited, and stored
- AI feature usage (prompts, generations, research queries)
- API requests and system interactions
- IP address, browser type, device information
Legal Content
- Documents you create or upload
- Templates you use or customize
- Legal research queries and results
2. How We Use Your Information
- Provide and improve the Service
- Process AI requests and generate legal content
- Manage subscriptions and billing
- Send important service updates and notifications
- Analyze usage patterns to improve features
- Ensure security and prevent fraud
- Comply with legal obligations
3. Data Storage and Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/SSL) and at rest
- Secure database access with authentication
- Regular security audits and penetration testing
- Access controls and audit logging
- Automated backups and disaster recovery
Your documents are stored securely and accessed only for providing the Service. We do not use your confidential legal documents to train AI models without explicit consent.
4. AI Model Training
Our AI models are trained on publicly available legal texts, case law, and statutes. We do NOT use your confidential documents or private data for model training unless you explicitly opt-in to a training program with appropriate safeguards.
5. Data Sharing
We do NOT sell your personal data. We share data only with:
- Service Providers: Payment processors (Stripe, Razorpay), hosting providers, analytics tools
- Legal Requirements: When required by law, subpoena, or court order
- Business Transfers: In case of merger, acquisition, or asset sale
- Your Consent: When you explicitly authorize sharing
6. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate information
- Delete your account and data
- Export your documents and data
- Opt-out of marketing communications
- Restrict certain data processing
To exercise these rights, contact us at privacy@cognexiaailegal.com
7. GDPR Compliance (EU Users)
For users in the European Union, we comply with GDPR requirements:
- Lawful basis: Consent, contract performance, legitimate interests
- Data minimization: We collect only necessary information
- Right to be forgotten: Request complete data deletion
- Data portability: Export data in machine-readable format
- EU data representative: [Contact details to be added]
8. Cookies and Tracking
We use cookies and similar technologies for authentication, preferences, and analytics. You can control cookie settings through your browser. Essential cookies are required for the Service to function.
9. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. After account deletion, we may retain certain data for legal compliance, dispute resolution, and enforcing our agreements (typically 7 years for legal documents).
10. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect information from children.
11. Changes to Privacy Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or service notification.
12. Contact Us
For privacy concerns or questions, contact us at:
Email: privacy@cognexiaailegal.com
Data Protection Officer: dpo@cognexiaailegal.com