Privacy controls and data handling
Direct answer: LegalDoc.app applies data minimization, retention controls, explicit consent capture, and auditable deletion workflows across legal automation operations.
By LegalDoc.app · Last updated 2026-09-23
Privacy design principles
Teams evaluating legal workflow automation privacy controls need implementation details, not policy slogans. The principles below map directly to product behavior: what is collected, how it is processed, who can access it, and how quickly it can be removed.
Data minimization
Only required contract and workflow data is processed for drafting, review, and storage features.
Configurable retention
Draft documents and their exports default to 30-day retention, adjustable in the vault. Uploaded reviews and agent outputs remain until you delete them from their histories.
Consent and disclosure
AI processing and lawyer-handoff actions capture explicit consent events with versioned records.
User-initiated deletion
Users can delete drafts and exports in the vault, uploaded reviews in saved reviews, and agent outputs in run history. Consent, audit, billing, and lawyer-request records are retained separately.
Data lifecycle in legal operations workflows
Collection
Collect only inputs required for document generation, review analysis, billing, and support operations.
Processing
Apply ownership scoping and consent checks before review or assistant workflows process content.
Storage
Store data using encrypted infrastructure and retention policies controlled by user preference and policy defaults.
Deletion
Support immediate deletion requests and verify background purges when automatic expiry is enabled.
Retention decision matrix
Privacy controls are most defensible when teams decide retention policy by scenario, not by one static default. This matrix gives legal operations teams a repeatable way to align retention windows with matter lifecycle, sensitivity, and escalation requirements.
High-volume drafting with low retention needs
Use shorter retention windows and rely on vault exports for required long-term records.
Active negotiation cycle with frequent redlines
Extend retention only for active matters and set automatic reversion after closure.
Sensitive document categories
Apply stricter access controls, explicit consent checkpoints, and accelerated deletion where permitted.
Counsel escalation with external handoff
Record handoff consent, shared artifact scope, and deletion responsibility boundaries.
Regulatory references
Privacy workflows are designed with common legal obligations in mind. For regulatory context, see GDPR guidance and California CCPA information.
Related pages: Security and Compliance.
Privacy operations checklist
- Capture explicit consent before AI processing or lawyer handoff.
- Expose retention settings at vault level and respect immediate delete requests.
- Record deletion events with purge verification for compliance traceability.
- Review disclosures against actual data flows before publishing policy changes.
Privacy risk scenarios to monitor
- Disclosure language promises retention or deletion behavior that is not enforced by runtime policy.
- Access permissions remain broader than required after guest-to-user upgrades or workflow role changes.
- Escalation packets include unnecessary personal data fields beyond review and legal decision scope.
- Policy updates are published without validating downstream queues, storage jobs, and audit events.
Disclosure review checklist
- Confirm product behavior and policy language still match after workflow or retention updates.
- Verify consent text versions are reflected in all relevant user-action screens.
- Check that deletion and retention language reflects current background purge behavior.
- Document owner and review date for each major disclosure section.
Policy-to-product alignment checks
Privacy pages become unreliable when policy language and runtime behavior drift apart. After any workflow update, confirm that consent prompts, retention controls, and deletion behavior still match public disclosures. Treat mismatches as release blockers, not documentation cleanup tasks.
Before release
Verify updated flow screenshots, wording, and consent versions in all user-facing touchpoints.
After release
Sample live records to confirm retention and deletion outcomes match stated policy behavior.
Teams should also verify that internal training material and support responses match public privacy language. Misalignment between external policy text and internal instructions is a common source of operational privacy drift.
Reviewing these scenarios monthly helps teams catch privacy drift early, especially when product workflows evolve quickly. Tie each observed issue to a named owner and remediation timeline so privacy posture improves as part of normal release operations.
Note: This policy is a starting template and must be reviewed by counsel before relying on it for compliance.
LegalDoc.app Privacy Policy
Effective date: 2026-02-24 · Last updated: 2026-09-23
This Privacy Policy explains how LegalDoc.app ("we", "us") collects, uses, shares, and safeguards information when you use our legal workflow automation services. Capitalized terms not defined here have the meaning given in our terms of service.
Information we collect
- Account information: name, work email, organization, role, and authentication identifiers used to create and manage your account.
- Contract content: documents, clauses, prompts, and metadata you upload, generate, or process through drafting, review, vault, and assistant workflows.
- Usage data: feature interactions, request and response logs, error and performance telemetry used to operate and improve the service.
- Payment data: billing contact details and subscription records. Card data is collected and stored by our payment processor; we do not retain full card numbers.
- Cookies and analytics: session cookies, preference cookies, and aggregated analytics signals used to keep you signed in and measure product usage.
How we use your information
- Service provision: deliver drafting, review, vault, and assistant features you request.
- Security: detect, investigate, and prevent abuse, fraud, and unauthorized access.
- Billing: process subscriptions, invoices, refunds, and tax records.
- Communications: send transactional notices, product updates, and support responses.
- Legal compliance: meet recordkeeping, tax, and other obligations and respond to lawful requests.
Legal bases for processing (GDPR)
- Contract necessity: processing required to provide the service you signed up for.
- Legitimate interests: securing the platform, preventing abuse, and improving features, balanced against your rights.
- Consent: for optional processing such as certain analytics or marketing communications, where consent applies.
- Legal obligation: retaining records required by tax, accounting, or other applicable law.
How we share information
- Team workspaces and signatures: shared agreements, version history, comments, and approval activity are visible to workspace members. Sharing a private draft creates a separate team copy. Signature recipients can access the specific agreement sent to their verified email and its signature record. Signing records the account, typed name, consent, document fingerprint, and timestamp.
- Sub-processors: we use vendors in the following categories to operate the service — cloud hosting and storage, payment processing, transactional email delivery, customer support tooling, and product analytics. We require contractual safeguards with each category.
- Legal disclosures: we may disclose information when required by law, valid legal process, or to protect rights, safety, and the integrity of the service.
- Business transfers: in the event of a merger, acquisition, financing, or asset sale, information may be transferred subject to this policy.
Data retention
Personal draft and export retention is managed in the vault. Team agreements, their versions, comments, approval records, and signature records are retained separately and are not included in personal-vault deletion or scheduled retention. Archiving a shared agreement preserves its records. Contact privacy support for requests involving these retained records. See the document retention workflow for in-product retention controls and our approach to deletion verification.
Your rights
Subject to applicable law (including the EU GDPR, UK GDPR, and CCPA), you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of your personal data, subject to legal exceptions.
- Receive a portable copy of personal data you provided to us.
- Object to or restrict certain processing.
- Withdraw consent for processing that relies on your consent.
How to exercise your rights
Send your request to asad@ztabs.co. We aim to acknowledge receipt promptly and substantively respond within 30 days. We may need to verify your identity before fulfilling certain requests.
International transfers
Where personal data is transferred internationally, we rely on recognized safeguards such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or other equivalent transfer mechanisms permitted by applicable law.
Children
The service is intended for business use and is not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can take appropriate action.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the service, by email to your account contact, or by updating the effective date above. Continued use of the service after the effective date constitutes acceptance of the updated policy where permitted by law.
Contact
Questions or requests: asad@ztabs.co
Mailing address: [Address — update before publishing]
Privacy FAQ
What privacy principle is most important for legal workflow tools?
Data minimization is foundational: collect only what is required to complete drafting, review, and escalation workflows.
Can users control retention and deletion directly?
Draft and export retention is managed in the vault. Completed or failed reviews and agent runs can be deleted from their histories. Deleting an agent output does not delete a document or lawyer request it created. Active processing must finish before deletion.
How is consent captured for AI and lawyer handoff?
Consent is captured as a versioned event before AI processing and before any lawyer intake handoff action.
Does this page constitute legal advice?
No. This page describes operational controls and should not be treated as legal advice for specific regulatory obligations.
This page explains platform controls and should be combined with your own counsel guidance for policy decisions.
Teams should revisit this framework whenever retention policy, AI processing scope, or external handoff behavior changes so privacy controls remain synchronized with actual workflow implementation.
Include data subject request handling in privacy operations reviews, including ownership, response timelines, and evidence retention for completed requests. This strengthens day-to-day privacy readiness and reduces reactive policy work during high-pressure periods.
Documenting response outcomes also improves repeatability for future privacy request handling.
Repeatable workflows are critical for demonstrating privacy control reliability during internal and external reviews.