Last updated: July 06, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
Account means a unique account created for You to access our Service or parts of our Service.
Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
Company (referred to as either "the Company", "We", "Us" or "Our" in this Privacy Policy) refers to Bircher Intelligence LLC, 44 Potter Place, Fairport, New York 14450.
Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
Country refers to: New York, United States
Device means any device that can access the Service such as a computer, a cell phone or a digital tablet.
Legal Documents means documents, contracts, correspondence, and other materials that You upload to the Service for analysis, including materials that may be subject to attorney-client privilege or work product protection.
Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual. We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.
Service refers to Sovereign Legal, the AI-powered legal document intelligence platform accessible from the Website.
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
Website refers to Sovereign Legal, accessible from https://sovereignlegal.ai/.
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Special Notice for Legal Professionals
Sovereign Legal is designed for use by law firms and legal professionals. This Privacy Policy addresses how We handle Legal Documents, including documents that may be subject to attorney-client privilege. You remain solely responsible for determining what documents to upload to the Service and for maintaining appropriate ethical and professional obligations, including those related to attorney-client privilege and work product doctrine.
By using Our Service, You represent that You have the authority to upload Legal Documents and that doing so does not violate any confidentiality obligations, ethical rules, or applicable laws.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
Email address
First name and last name
Phone number
Law firm name and business address
Job title/role within your organization
Payment information (processed by our payment provider)
Legal Documents and Matter Data
Documents You Upload: When You use Our Service, You may upload Legal Documents for analysis. We process these Legal Documents as follows:
Storage: Legal Documents are stored in dedicated, isolated Amazon S3 buckets assigned exclusively to Your law firm. Your firm's documents are never commingled with documents from other firms. Each law firm receives its own S3 bucket with strict access controls.
AI Processing: Legal Documents are processed using Amazon Web Services (AWS) Bedrock, which provides access to Claude AI language models developed by Anthropic. Document text is analyzed to enable search, comparison, and question-answering features. Your Legal Documents are NEVER used to train AI models. AWS Bedrock does not retain Your data or use it for model improvement.
Vector Embeddings: Document content is converted into mathematical representations ("embeddings") and stored in a Weaviate vector database. These embeddings enable semantic search and are tagged with Your firm name and matter identifiers to ensure data isolation. Vector embeddings cannot be reverse-engineered to reconstruct original documents.
Metadata: We collect metadata about Legal Documents including file names, upload dates, page counts, file sizes, matter names, document hashes (for version tracking), and usage statistics.
Query Logs: We log all queries You submit to the Service, including the question asked, the matter context, AI responses generated, source documents cited, and timestamps. Query logs are used for service improvement, security monitoring, and billing purposes.
Attorney-Client Privilege: You are responsible for determining whether documents You upload are privileged or confidential. We do not review documents for privilege, and uploading documents to Our Service does not waive attorney-client privilege or work product protection. However, You should:
Only upload documents You are authorized to process electronically
Comply with all applicable ethics rules and professional responsibilities
Obtain client consent where required by Your jurisdiction
Maintain Your own records and backups of Legal Documents
Use appropriate access controls within Your firm to limit who can access the Service
Data Sovereignty and Isolation: We implement technical and organizational measures to isolate Your firm's data:
Dedicated Storage: Each law firm has a dedicated AWS S3 bucket. Your documents are not stored in shared infrastructure.
Query Filtering: All AI queries are automatically filtered to return results only from Your firm's data and the specific matter You have selected. Cross-firm data access is technically impossible due to our architecture.
Access Controls: Only users with Your firm's unique access credentials can view or query Your Legal Documents. We do not have routine access to Your document content.
Geographic Location: Your data is stored in AWS US-East-1 (Northern Virginia) data centers unless You request otherwise. All data remains within the United States.
Network Isolation: Each firm's S3 bucket has dedicated IAM policies preventing access from other firms or unauthorized users.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device's unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit Our Service or when You access the Service by or through a mobile device.
Tracking Technologies and Cookies
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies We use include beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:
Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.
Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of a certain section and verifying system and server integrity).
Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.
Where required by law, we use non-essential cookies (such as analytics, advertising, and remarketing cookies) only with Your consent. You can withdraw or change Your consent at any time using Our cookie preferences tool (if available) or through Your browser/device settings. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
We use both Session and Persistent Cookies for the purposes set out below:
Necessary / Essential Cookies
Type: Session Cookies
Administered by: Us
Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided, and We only use these Cookies to provide You with those services.
Cookies Policy / Notice Acceptance Cookies
Type: Persistent Cookies
Administered by: Us
Purpose: These Cookies identify if users have accepted the use of cookies on the Website.
Functionality Cookies
Type: Persistent Cookies
Administered by: Us
Purpose: These Cookies allow Us to remember choices You make when You use the Website, such as remembering your login details or language preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter your preferences every time You use the Website.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
To provide and maintain our Service, including to monitor the usage of our Service and to provide AI-powered document analysis features.
To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
For the performance of a contract: the development, compliance and undertaking of the subscription agreement for the Service You have purchased or of any other contract with Us through the Service.
To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
To provide You with news, special offers, and general information about other goods, services and events which We offer that are similar to those that you have already purchased or inquired about unless You have opted not to receive such information.
To manage Your requests: To attend and manage Your requests to Us, including demo requests and customer support inquiries.
For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.
For service improvement: We analyze Usage Data and query patterns to improve AI accuracy, enhance search relevance, and develop new features. This analysis uses aggregated, anonymized data whenever possible.
For security and fraud prevention: We monitor usage patterns to detect unauthorized access, potential security breaches, and fraudulent activity.
For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service, products, services, marketing and your experience.
Sharing of Your Personal Data
We may share Your Personal Data in the following situations:
With Service Providers: We may share Your Personal Data with Service Providers to monitor and analyze the use of our Service, to process payments, and to contact You. See the "Third-Party Service Providers and Subprocessors" section below for details.
For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company. In such cases, We will require the acquiring party to honor this Privacy Policy.
With Affiliates: We may share Your Personal Data with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us.
With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.
At Your direction: If You use features that involve sharing data with third parties (such as integration partners), We will share data as directed by You.
We do NOT:
Sell Your Personal Data or Legal Documents to third parties
Share Your Legal Documents with other law firms or users
Use Your Legal Documents for marketing or promotional purposes
Provide Your data to AI training initiatives or model development efforts
Third-Party Service Providers and Subprocessors
We use the following third-party service providers to operate Our Service. Each processes Personal Data and/or Legal Documents on Our behalf as a data processor:
Infrastructure and AI Services
Amazon Web Services (AWS)
Services Used: S3 (document storage), Bedrock (AI processing), EC2/infrastructure hosting
Purpose: Secure document storage, AI-powered document analysis, and application infrastructure
Data Processed: Legal Documents, vector embeddings, usage logs, account information, application data
Location: United States (US-East-1, Northern Virginia)
Privacy Policy: https://aws.amazon.com/privacy/
Data Processing Agreement: AWS Customer Agreement includes GDPR-compliant data processing terms and Standard Contractual Clauses
Security: SOC 2 Type II certified, ISO 27001 certified, HIPAA compliant infrastructure
Anthropic (via AWS Bedrock)
Services Used: Claude AI language models for natural language processing and document analysis
Purpose: Provide AI-powered question answering, document summarization, and contract analysis
Data Processed: Document text and queries submitted for AI analysis (processed in real-time, not retained)
Location: Processed within AWS Bedrock infrastructure (US-East-1)
Privacy Policy: https://www.anthropic.com/legal/privacy
Important Data Protection: When accessed via AWS Bedrock, Anthropic does NOT:
Retain Your Legal Documents or queries after processing
Use Your data to train or improve AI models
Share Your data with other Anthropic customers
All data sent to Claude via AWS Bedrock is processed and immediately discarded. AWS Bedrock's data protection terms apply.
Weaviate (SeMI Technologies B.V.)
Services Used: Vector database for document search and retrieval
Purpose: Enable fast, semantic search across Your Legal Documents using AI-powered vector embeddings
Data Processed: Vector embeddings (mathematical representations of document content), metadata (matter names, firm identifiers, document references)
Location: Cloud infrastructure hosted on AWS US-East-1
Privacy Policy: https://weaviate.io/privacy
Note: Vector embeddings stored in Weaviate cannot be reverse-engineered to reconstruct original document text
Payment Processing
Stripe, Inc.
Purpose: Payment processing for subscriptions and invoicing
Data Processed: Credit card information, billing address, transaction history, payment method details
Location: United States (with global infrastructure for payment processing)
Privacy Policy: https://stripe.com/privacy
Security: PCI DSS Level 1 certified (highest level of payment security)
Note: We do not store Your credit card information on Our servers. Stripe handles all payment data directly.
Communication and Business Services
Google Workspace (Google LLC)
Purpose: Business email (hello@sovereignlegal.ai, support communications), internal collaboration
Data Processed: Email correspondence with customers, support tickets, customer communications
Location: United States
Privacy Policy: https://policies.google.com/privacy
Note: Google Workspace for Business includes GDPR-compliant data processing terms
Framer (Framer B.V.)
Purpose: Website hosting and content delivery
Data Processed: Website visitor data, form submissions, cookies
Location: European Union and United States
Privacy Policy: https://www.framer.com/privacy
Subprocessor Updates: We may update this list of subprocessors from time to time as We add or change service providers. Material changes to subprocessors will be announced via email to registered users at least 30 days in advance. Enterprise customers may request advance notification of new subprocessors by contacting Us.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if We are required to retain Your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
Where possible, We apply shorter retention periods and/or reduce identifiability by deleting, aggregating, or anonymizing data. Unless otherwise stated, the retention periods below are maximum periods ("up to") and We may delete or anonymize data sooner when it is no longer needed for the relevant purpose.
Retention Periods by Data Type
Account Information
User Accounts: Retained for the duration of your account relationship plus up to 90 days after account closure to handle any post-termination issues or resolve disputes
After 90 days: Account data is anonymized or deleted unless retention is required for legal/tax purposes
Legal Documents
Active Accounts: Legal Documents remain in Your dedicated S3 bucket for as long as Your account is active
Upon Account Termination:
You have 30 days to download/export all Legal Documents
After 30 days: Legal Documents are permanently deleted from Our systems
Vector embeddings associated with deleted documents are also permanently deleted
Upon Your Request: You may request immediate deletion of specific documents or entire matters at any time
Backup Retention: Deleted documents may remain in encrypted backup systems for up to 30 additional days, after which they are permanently purged
Query Logs and Usage Data
Query logs (questions asked, AI responses): Up to 24 months for service improvement and billing verification
Website analytics data (IP addresses, page views): Up to 24 months
Server logs (access logs, security events): Up to 12 months for security monitoring
Audit logs (admin actions, document access): Up to 7 years to comply with legal and professional record-keeping requirements for law firms
Customer Support Data
Support tickets and correspondence: Up to 24 months from ticket closure
Email communications: Retained in accordance with our business email retention policy (up to 7 years)
Payment and Billing Data
Transaction records, invoices: Up to 7 years to comply with tax and accounting regulations
Payment method details: Stored by Stripe (not on Our servers); deleted when You remove the payment method
Extended Retention Reasons
We may retain Personal Data beyond the periods stated above for the following reasons:
Legal obligation: We are required by law to retain specific data (e.g., financial records for tax authorities, audit logs for professional compliance)
Legal claims: Data is necessary to establish, exercise, or defend legal claims
Your explicit request: You ask Us to retain specific information (e.g., for your own records or regulatory compliance)
Technical limitations: Data exists in backup systems that are scheduled for routine deletion according to our data lifecycle policies
You may request information about how long We will retain Your Personal Data or Legal Documents by contacting Us at hello@sovereignlegal.ai.
Data Deletion Procedures
When retention periods expire, We securely delete or anonymize Personal Data according to the following procedures:
Deletion: Personal Data is removed from Our production systems using secure deletion methods that prevent recovery
S3 Document Deletion: Legal Documents are deleted from Your dedicated S3 bucket and cannot be recovered
Vector Database Cleanup: Associated vector embeddings are purged from Weaviate
Backup retention: Residual copies may remain in encrypted backups for up to 30 days consistent with our backup retention schedule. These backups are not restored except where necessary for disaster recovery or legal compliance.
Anonymization: In some cases, We convert Personal Data into anonymous statistical data that cannot be linked back to You. This anonymized data may be retained indefinitely for research, product improvement, and analytics.
Transfer of Your Personal Data
Your information, including Personal Data and Legal Documents, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ from those from Your jurisdiction.
Data Location: All Legal Documents and Personal Data are primarily stored and processed in the United States (AWS US-East-1, Northern Virginia). We do not transfer data outside the United States without appropriate safeguards.
Where required by applicable law, We will ensure that international transfers of Your Personal Data are subject to appropriate safeguards and supplementary measures. The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.
International Transfer Mechanisms:
For transfers to AWS and other U.S.-based processors: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission
AWS has implemented supplementary measures including encryption in transit and at rest
For EU/UK customers: Data Processing Agreements are available upon request
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data and Legal Documents that We have collected about You.
Our Service gives You the ability to delete certain information about You from within the Service:
Individual documents can be deleted through the Service interface
Entire matters can be purged, deleting all associated documents and vector embeddings
You can request complete account deletion through the admin console or by contacting Us
You may update, amend, or delete Your information at any time by signing in to Your Account and visiting the account settings section that allows you to manage Your personal information. You may also contact Us to request access to, correct, or delete any Personal Data that You have provided to Us.
Please note, however, that We may need to retain certain information when we have a legal obligation or lawful basis to do so, including:
Financial records (invoices, payment history) for tax compliance (up to 7 years)
Audit logs for professional record-keeping requirements
Data necessary to defend against legal claims
Data required by law enforcement or court orders
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy. In such transactions:
We will require the acquiring party to honor the terms of this Privacy Policy
You will be notified via email at least 30 days before the transfer
You will have the right to delete Your account and data before the transfer
For law firms, We recognize that business transitions may trigger additional ethical obligations and will work with You to address them
Law Enforcement and Legal Process
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Legal Process for Document Requests:
We will not disclose Legal Documents in response to informal requests
We require a valid subpoena, court order, or search warrant to disclose Legal Documents
Whenever legally permitted, We will notify You before disclosing Your data to give You the opportunity to seek a protective order
We recognize that Legal Documents may be subject to attorney-client privilege and will assert applicable privileges on Your behalf where appropriate
We maintain detailed records of all law enforcement requests and government data requests
Other Legal Requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
Comply with a legal obligation
Protect and defend the rights or property of the Company
Prevent or investigate possible wrongdoing in connection with the Service
Protect the personal safety of Users of the Service or the public
Protect against legal liability
Respond to valid legal process (subpoenas, court orders)
Security of Your Personal Data and Legal Documents
The security of Your Personal Data and Legal Documents is critically important to Us. We implement industry-standard security measures appropriate for handling confidential legal materials:
Technical Security Measures
Encryption in Transit: All data transmitted between Your browser and Our Service uses TLS 1.3 encryption with strong cipher suites
Encryption at Rest: Legal Documents stored in AWS S3 are encrypted using AES-256 encryption. Encryption keys are managed by AWS Key Management Service (KMS).
Access Controls:
Multi-factor authentication (MFA) is available and recommended for all accounts
Role-based access controls limit who can access Legal Documents within Your firm
Administrative access to production systems requires MFA and is logged
Infrastructure Security: We leverage AWS's SOC 2 Type II certified infrastructure with:
Built-in DDoS protection
Network isolation and firewalls
Regular security patching and updates
Physical security for data centers (AWS facilities)
Data Isolation: Each law firm's data is stored in dedicated S3 buckets with strict IAM policies that prevent access from other firms or unauthorized users. This architectural isolation provides defense-in-depth.
Audit Logging: All document access, queries, admin actions, and system events are logged for security monitoring and compliance. Logs are retained for 12 months.
Vulnerability Management: We conduct regular security assessments and vulnerability scans of Our infrastructure and application code
Organizational Security Measures
Background Checks: All employees with access to production systems undergo background checks
Confidentiality Obligations: All employees and contractors sign confidentiality agreements
Security Training: Regular security awareness training for all team members
Least Privilege Access: Production access is granted on a need-to-know basis
Secure Development: Code reviews, automated security scanning, and secure coding practices
Security Incident Response
In the event of a security incident that affects Your Personal Data or Legal Documents:
We will notify You within 72 hours of discovering the incident (or sooner if required by applicable law)
We will provide details about:
What data was affected
When the incident occurred
What actions We are taking to investigate and remediate
Steps You should take to protect Your data
We will cooperate with You to meet any notification obligations You may have to clients or regulatory authorities
For law firms, We recognize that data breaches may trigger professional responsibility obligations (state bar reporting, client notification) and will work with You to address them promptly
We maintain cyber liability insurance to cover potential security incidents
Your Security Responsibilities
Security is a shared responsibility. You are responsible for:
Maintaining the confidentiality of Your account credentials (access keys, passwords)
Using strong, unique passwords for Your account (We recommend password managers)
Enabling multi-factor authentication when available
Promptly notifying Us of any unauthorized access to Your account (email hello@sovereignlegal.ai)
Ensuring that Your use of the Service complies with Your firm's security policies and professional obligations
Restricting access to the Service to authorized personnel within Your firm
Maintaining Your own backups of critical Legal Documents
Using the Service from secure networks (avoid public WiFi for accessing confidential documents)
Important Limitation: While We use commercially reasonable security measures appropriate for handling confidential legal documents, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security. You should maintain Your own backups of critical documents and implement appropriate security measures within Your organization.
Your Privacy Rights
General Rights
Depending on Your location, You may have the following rights regarding Your Personal Data:
Access: Request a copy of the Personal Data We hold about You, including details about how We process it
Correction: Request that We correct inaccurate or incomplete Personal Data
Deletion: Request that We delete Your Personal Data (subject to legal retention requirements and exceptions described above)
Portability: Request that We export Your Personal Data and Legal Documents in a machine-readable format
Objection: Object to certain processing of Your Personal Data, particularly for direct marketing purposes
Restriction: Request that We temporarily stop processing Your Personal Data in certain circumstances
Withdraw Consent: Where processing is based on consent, You may withdraw consent at any time (does not affect the lawfulness of prior processing)
Legal Document Export and Portability
You have the right to export Your Legal Documents at any time:
Individual Documents: You may download individual documents through the Service interface in their original format
Bulk Export: You may request a complete export of Your firm's data by contacting Us at hello@sovereignlegal.ai. We will provide access to download all documents within 7 business days.
Upon Account Termination: We will provide You with access to download all Legal Documents for 30 days after account closure. After 30 days, documents are permanently deleted.
Export Format: Documents are exported in their original file format (typically PDF). Metadata and folder structure are preserved.
S3 Access: For enterprise customers, We can provide direct access to Your dedicated S3 bucket for bulk downloads using AWS tools
California Privacy Rights (CCPA/CPRA)
If You are a California resident, You have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to Know: You have the right to request:
Categories of Personal Data We collect about You
Categories of sources from which Personal Data is collected
Business or commercial purpose for collecting Personal Data
Categories of third parties with whom We share Personal Data
Specific pieces of Personal Data We have collected about You
Right to Delete: You have the right to request deletion of Your Personal Data, subject to certain exceptions (legal obligations, completing transactions, security purposes, etc.)
Right to Opt-Out: You have the right to opt-out of the "sale" or "sharing" of Personal Data. We do not sell or share Your Personal Data for cross-context behavioral advertising.
Right to Correct: You have the right to request correction of inaccurate Personal Data
Right to Limit Use of Sensitive Personal Information: If We use or disclose sensitive Personal Information for purposes beyond what is necessary to provide the Service, You have the right to limit such use. We do not use Legal Documents for purposes beyond providing Our document analysis Service.
Right to Non-Discrimination: You have the right not to be discriminated against for exercising Your privacy rights. We will not:
Deny You goods or services
Charge different prices or rates
Provide a different level of quality
Suggest You will receive different pricing or quality
Sensitive Personal Information: Under California law, Legal Documents uploaded to Our Service may be considered "sensitive" personal information. We use Legal Documents solely to provide Our AI-powered document analysis Service and do not use them for other purposes. We do not infer characteristics about You from Legal Documents.
California "Shine the Light" Law: California Civil Code Section 1798.83 permits California residents to request certain information about disclosure of Personal Data to third parties for direct marketing purposes. We do not share Personal Data with third parties for their direct marketing purposes.
European Privacy Rights (GDPR)
If You are located in the European Economic Area (EEA), United Kingdom, or Switzerland, You have specific rights under the General Data Protection Regulation (GDPR) and equivalent laws:
Legal Basis for Processing: We process Personal Data based on:
Contract Performance: To provide the Service You have subscribed to (GDPR Art. 6(1)(b))
Legitimate Interests: To improve Our Service, prevent fraud, and ensure security (GDPR Art. 6(1)(f))
Legal Obligations: To comply with applicable laws and regulations (GDPR Art. 6(1)(c))
Consent: Where required by law, such as for marketing communications or non-essential cookies (GDPR Art. 6(1)(a))
Right to Object: You have the right to object to processing based on legitimate interests. We will stop processing unless We can demonstrate compelling legitimate grounds that override Your interests.
Right to Restrict Processing: You may request temporary restriction of processing in certain circumstances (e.g., while We verify accuracy of data)
Right to Data Portability: You have the right to receive Your Personal Data in a structured, commonly used, machine-readable format and transmit it to another controller
Right to Lodge a Complaint: You have the right to lodge a complaint with Your local supervisory authority if You believe Our processing violates GDPR:
EU: List of supervisory authorities: https://edpb.europa.eu/about-edpb/board/members_en
UK: Information Commissioner's Office (ICO): https://ico.org.uk/
Right to Withdraw Consent: Where processing is based on consent, You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal
Automated Decision-Making: We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects You
International Data Transfers: For transfers of Personal Data from the EEA/UK to the United States:
We rely on Standard Contractual Clauses (SCCs) approved by the European Commission
AWS has implemented supplementary security measures as recommended by the European Data Protection Board
Data Processing Agreements incorporating SCCs are available upon request
EU Representative: We do not currently have an EU representative as We do not fall within GDPR's establishment criteria requiring one. However, You may contact Us directly at hello@sovereignlegal.ai for all privacy matters.
Other Jurisdictions
Residents of other jurisdictions may have additional privacy rights under applicable local laws. Please contact Us to inquire about rights specific to Your jurisdiction.
Exercising Your Rights
To exercise any of these rights, please contact Us:
Email: hello@sovereignlegal.ai or privacy@sovereignlegal.ai
Subject line: "Privacy Rights Request"
Include: Your name, email address associated with Your account, and specific request
Verification: We will respond to Your request within 30 days (or as required by applicable law, e.g., 45 days under CCPA). To protect Your privacy, We may need to verify Your identity before processing certain requests. Verification may require:
Confirming access to the email address associated with Your account
Providing additional identifying information
For sensitive requests (e.g., deletion), We may require additional verification steps
Authorized Agents: California residents may designate an authorized agent to submit requests on Your behalf. Authorized agents must provide proof of authorization (e.g., power of attorney).
No Fee: We will not charge a fee to process Your privacy rights requests unless the request is manifestly unfounded, excessive, or repetitive. In such cases, We may charge a reasonable fee or refuse the request.
Children's Privacy
Our Service does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18. The Service is designed for use by legal professionals and law firms only.
If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 18 without verification of parental consent, We take steps to remove that information from Our servers.
If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent's consent before We collect and use that information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Third-Party Integrations: If You choose to integrate Our Service with third-party applications (future feature), You will be subject to those third parties' privacy policies for any data shared through the integration. We will clearly disclose what data is shared before You authorize any integration.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time to reflect changes in Our practices, technology, legal requirements, or other factors. We will notify You of any material changes by:
Posting the new Privacy Policy on this page
Updating the "Last updated" date at the top of this Privacy Policy
Sending You an email notification at Your registered email address
Displaying a prominent notice on Our Service when You log in
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Material Changes: For material changes that significantly affect Your privacy rights or how We handle Legal Documents, We will:
Provide at least 30 days' advance notice via email
Give You the opportunity to review the changes and, if You disagree, terminate Your account and export Your data before the changes take effect
Not apply changes retroactively to data collected under prior versions of this Privacy Policy
Prior Versions: Previous versions of this Privacy Policy are available upon request. Contact Us at hello@sovereignlegal.ai to request historical versions.
Contact Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise Your privacy rights, You can contact us:
Email: hello@sovereignlegal.ai
Privacy-Specific Inquiries: privacy@sovereignlegal.ai (aliases to hello@sovereignlegal.ai)
Mail: Bircher Intelligence LLC
Attn: Privacy Officer
44 Potter Place
Fairport, NY 14450
United States
Response Time: We aim to respond to all privacy inquiries within 2 business days. For formal privacy rights requests (access, deletion, etc.), We will respond within 30 days as required by law.
Security Incidents: If You believe Your account has been compromised or You notice suspicious activity, contact Us immediately at hello@sovereignlegal.ai with "SECURITY INCIDENT" in the subject line.
Law Enforcement Requests: Law enforcement agencies should direct requests for data to hello@sovereignlegal.ai and include appropriate legal process (subpoena, court order, search warrant). We will review all requests for legal sufficiency and, where permitted, notify affected customers.
This Privacy Policy was last updated on July 06, 2026 and is effective immediately.