Our commitment: LawAOS does not sell firm content, use it for third-party advertising, or use firm documents and client information to train LawAOS-owned models. Customers retain their rights in workspace content.
Account Information: When you create an account, we collect your name, email address, firm name, billing contact details, and subscription metadata. A configured payment processor receives payment-card or bank details used to complete a transaction.
Usage Data: We collect operational information about how the Service is used, including feature events, session and device information, and diagnostic records. We use this information to operate, secure, support, and improve the platform.
Your Content: Customers retain their rights in documents, matter data, client information, and other workspace content. We process that content to provide, secure, troubleshoot, and support the Service, follow authorized instructions, and comply with legal obligations.
Technical Data: We automatically collect device type, browser type, IP address, and operating system information for security monitoring and Service optimization.
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process transactions and send billing-related communications
- Send service-related notifications (e.g., security alerts, maintenance windows)
- Respond to your requests, comments, and questions
- Monitor and prevent fraud, abuse, and security threats
- Generate aggregated analytics to improve the platform
We do not sell firm content, share it with advertisers, or use firm documents and client data to train LawAOS-owned models. AI requests use the provider configured for the feature or firm; provider retention, training, residency, and contractual terms vary.
Where applicable law requires a legal basis, we process personal data as needed to perform a contract or take requested steps before one, comply with legal obligations, protect users and the Service, and pursue legitimate interests such as security, support, and product reliability. We rely on consent where the law requires it, and consent can be withdrawn without affecting earlier lawful processing.
The legal role of the Provider and the customer depends on the data and context. A firm generally controls why its workspace and client content is processed, while the Provider processes that content to deliver the Service under the applicable agreement. The Provider may separately determine purposes for account administration, security, billing, support, and public website data. A signed data-processing agreement may define these roles more specifically.
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- Service Providers: We use providers for hosting, authentication, communications, payment processing, support, and configured AI features. Their access is limited to the services they provide and is governed by applicable contracts and configuration.
- Legal Requirements: We may disclose information if required by law, subpoena, or court order, or if necessary to protect the rights, property, or safety of LawAOS, our users, or the public.
- Business Transfers: Information may transfer as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable notice and privacy requirements.
We implement technical and organizational measures to protect your data:
- Provider-managed encryption for stored data
- Encrypted transport for application traffic
- Postgres row-level security for per-firm tenant isolation
- Role-based access controls with audit logging
- Server-side handling for payment, email, and AI provider secrets
- Security review, incident handling, and controlled change management
For more detail, see our Security page.
We retain personal data and workspace content for as long as reasonably necessary to provide the Service, maintain security and auditability, meet contractual commitments, resolve disputes, and comply with legal obligations. The period depends on the type of record, account status, firm settings, applicable agreement, and law.
Authorized users should export required records before account closure. After termination or a valid deletion request, data is deleted or de-identified in accordance with the applicable agreement and operational process, subject to legal holds, security records, and time-limited backup cycles. Firms with a mandatory retention or deletion schedule should confirm it in a written agreement before onboarding.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (“right to be forgotten”).
- Portability: Request your data in a structured, machine-readable format.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Objection: Object to the processing of your data for specific purposes.
To exercise a right that applies to you, contact privacy@lawaos.com. We may need to verify your identity and will respond within the period required by applicable law.
LawAOS uses cookies and similar device storage that are necessary for authentication, security, request routing, saved preferences, and operation of the Service. This includes the record that remembers your privacy choice. Necessary technologies cannot be disabled through the site because the requested function would not work reliably without them.
The public LawAOS marketing site does not currently load optional analytics or advertising trackers. LawAOS does not use firm workspace content for behavioural advertising. If an optional analytics or marketing technology is introduced, it must be identified here and remain off until a required choice is made. You can review the current categories at any time using “Privacy choices” in the footer.
Authenticated workspaces may create operational events and diagnostic records needed for reliability, security, audit, and support. Those records are governed by this Policy and the applicable customer agreement; they are not advertising profiles.
When an authorized user invokes an AI-assisted feature, LawAOS may send the selected prompt, instructions, and relevant context to the AI provider configured for that feature or firm. The amount of context depends on the action, permissions, and configuration. Users should not submit information that their firm has not authorized for that provider.
LawAOS does not use firm documents or client information to train LawAOS-owned models. Third-party provider retention, training, residency, abuse-monitoring, and contractual settings can differ, so firms should review the configured provider terms before enabling AI for confidential work.
Connecting Google is optional. Each member authorizes their own account through Google. LawAOS receives authorization tokens, not your Google password. Where provided by Google, we store your account identifier and email to identify the connection.
Calendar and scheduling: We access event details such as titles, descriptions, times, locations, attendees, and meeting links to display or import your primary calendar events and manage appointments you request. We use availability information to avoid conflicting bookings. Booking actions may create, reschedule, or cancel a Google Calendar event and create a Google Meet link.
Drive and documents: We request access to individual files created by LawAOS or explicitly made available to it, rather than your entire Drive. We use file content and metadata for the document actions you initiate, including creating a Google document and importing or exporting its content.
Storage and sharing: Connection tokens are encrypted on the server and associated with your member account and firm. Imported events and document copies become workspace records and are subject to the firm's access permissions and the retention terms in this policy. Google and our hosting and storage providers process data needed to deliver these features. Booking details may be shared with the participants you select. We do not sell Google user data or use it for advertising.
Disconnecting and deletion: You can disconnect Google in Settings > API & Integrations. Disconnecting disables syncing and removes the stored access and refresh tokens. You can also revoke access in your Google Account connections. Disconnecting does not automatically delete events or document copies already saved in your workspace or Google account. Authorized users can remove those records through the relevant product controls or request deletion through our contact form, subject to the retention and legal obligations described above.
LawAOS's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. These requirements apply to Google user data in addition to this policy's general data-handling terms.
The Service is not directed to children. If you believe a child has provided personal data outside a lawful client or legal-services context, contact privacy@lawaos.com so we can investigate and take appropriate action.
The primary application database is currently hosted in the Asia-Pacific (Sydney) region. Other providers may process operational, authentication, communications, payment, support, or configured AI data in additional regions under their service configuration.
Where cross-border processing requires a transfer mechanism or additional contractual terms, those requirements must be addressed in the applicable deployment and agreement. Contact our team before onboarding if data residency is mandatory.
We may update this Privacy Policy from time to time. We will provide notice of material changes when required by applicable law or contract. The “Last updated” date at the top identifies the latest published revision.
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Questions about this policy, a data-subject request, or a deployment that needs a data processing agreement?
