Privacy Policy

PRIVACY POLICY WEBLEGAL.NET

LAST UPDATED: JULY 5, 2026

1. INTRODUCTION, PARTIES, AND SCOPE

1.1. This Privacy Policy is published by the administration of the “WebLegal.net” website, accessible at the URL: https://weblegal.net, hereinafter referred to as the “Operator.” Where applicable data protection law uses the term “controller,” “data controller,” “business,” “service provider,” “processor,” “contractor,” or similar term, the Operator shall be treated according to the role that applies to the relevant processing activity.

1.2. This Privacy Policy explains how the Operator collects, receives, stores, uses, processes, analyzes, discloses, transfers, protects, retains, deletes, and otherwise handles information relating to visitors, registered users, subscribers, purchasers, team administrators, team members, counterparties, invitees, persons using artificial intelligence tools, persons uploading documents for review, persons generating or downloading documents, persons contacting support, and any other individual interacting with WebLegal.net, collectively referred to as “Users.”

1.3. This Privacy Policy applies to the website, web pages, web applications, user accounts, dashboards, templates, document-generation tools, document-management tools, artificial intelligence tools, AI chat, AI contract review, AI clause generation, file upload features, negotiation and approval links, team features, counterparty features, payment-related functionality, support features, marketing communications, cookies, analytics tools, downloadable files, and any other current or future services, content, tools, or features provided through WebLegal.net, collectively referred to as the “Service.”

1.4. This Privacy Policy should be read together with the Terms of Use and any additional notices, product terms, checkout terms, subscription terms, consent notices, cookie notices, or feature-specific disclosures displayed through the Service.

1.5. By accessing or using the Service, creating an account, purchasing access, subscribing to a plan, uploading a document, using AI features, generating a document, sharing a link, inviting a counterparty or team member, contacting support, accepting cookies, or otherwise interacting with the Service, the User acknowledges that the User has read this Privacy Policy.

1.6. If the User does not agree with this Privacy Policy, the User must not use the Service, must not submit personal data, must not upload documents, must not use AI features, must not create documents, and must not purchase or subscribe to paid features.

1.7. This Privacy Policy is intended to provide transparency about data practices. It does not create any professional, fiduciary, attorney-client, legal, tax, accounting, escrow, trust, agency, partnership, employment, or other special relationship between the User and the Operator.

1.8. The Service is not a law firm, legal representative, lawyer referral service, accounting firm, tax adviser, financial adviser, notary, court filing service, government agency, escrow service, or regulated professional service provider. Information submitted through the Service is not treated as privileged legal communication merely because it relates to contracts, documents, legal questions, legal templates, risk reports, AI review, or legal subject matter.

1.9. The Operator may update this Privacy Policy at any time by posting a revised version on the website or otherwise making it available through the Service. The revised version becomes effective when posted, unless it states a later effective date. Continued use of the Service after the effective date constitutes acknowledgement of the revised Privacy Policy.

1.10. This Privacy Policy is drafted broadly to cover current and future Service functionality. Some categories of data, purposes, recipients, or features may not apply to every User or every interaction.

2. DEFINITIONS

2.1. “Account” means a registered profile or login credential used to access the Service, including dashboards, document storage, document generation, AI features, subscription features, purchase history, team access, reviews, counterparty management, and related functionality.

2.2. “AI Features” means any feature using artificial intelligence, machine learning, large language models, automated analysis, algorithmic processing, natural language processing, OCR, automated drafting, automated review, automated classification, automated summarization, automated risk detection, or similar technology.

2.3. “AI Input” means any prompt, instruction, question, document, clause, file, image, message, selected term, field entry, uploaded contract, business information, personal data, or other content submitted to or processed through AI Features.

2.4. “AI Output” means any answer, clause, suggestion, correction, summary, risk report, marked-up file, extracted information, generated text, explanation, draft, comment, classification, warning, review result, or other output generated or assisted by AI Features.

2.5. “Controller” means the person or entity that determines the purposes and means of processing personal data, where such term is used under applicable law.

2.6. “Processor” means a person or entity that processes personal data on behalf of a controller, where such term is used under applicable law.

2.7. “Personal Data” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person, depending on applicable law.

2.8. “Sensitive Data” means data treated as sensitive, special category, highly sensitive, protected, regulated, or similar under applicable law, including data relating to health, biometrics, government identifiers, financial account credentials, precise geolocation, children, race, ethnicity, religion, political opinions, trade union membership, genetic data, sex life, sexual orientation, criminal history, or other protected categories.

2.9. “User Content” means any data, information, file, document, prompt, response, field value, selected term, clause, comment, message, counterparty information, team information, party profile, business information, uploaded contract, uploaded image, uploaded PDF, uploaded DOCX, uploaded TXT file, support message, feedback, or other material submitted, uploaded, entered, transmitted, shared, generated, stored, or otherwise provided by or on behalf of the User.

2.10. “Document” means any agreement, contract, policy, notice, form, letter, clause, legal template, business template, generated file, uploaded file, reviewed file, marked-up file, risk report, downloaded file, exported file, or other document-related content created, uploaded, edited, reviewed, shared, stored, or downloaded through the Service.

2.11. “Generated Document” means a Document created or assembled through the Service using templates, selected terms, filled fields, custom clauses, AI-generated clauses, uploaded information, User Content, or other functionality.

2.12. “Counterparty” means any person or entity invited by a User to review, complete, edit, approve, negotiate, or access a Document through a shared link, QR code, email invitation, account invitation, or other sharing method.

2.13. “Team Administrator” means a User who creates, controls, pays for, manages, or has administrative rights over a team account, organization account, shared workspace, or multi-user plan.

2.14. “Team Member” means a User who is invited to, added to, or granted permissions under a team account, organization account, shared workspace, or multi-user plan.

2.15. “Processing” means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, transmission, alignment, combination, restriction, erasure, destruction, analysis, automation, conversion, hosting, sharing, or transfer.

3. ROLES OF THE OPERATOR, USERS, TEAMS, AND COUNTERPARTIES

3.1. For account registration, authentication, billing, subscriptions, service operation, support, security, fraud prevention, analytics, marketing, legal compliance, and general website administration, the Operator generally acts as a controller of Personal Data.

3.2. Where a User, Team Administrator, employer, organization, client, or other entity enters, uploads, stores, or shares Personal Data of third parties through the Service, that User or entity may be an independent controller or responsible party under applicable law. In such cases, the User is responsible for determining whether the data may be lawfully submitted to the Service.

3.3. The Operator may act as a processor or service provider for certain limited processing performed on behalf of a User or organization, depending on the feature, plan, legal relationship, and applicable law. Unless a separate written data processing agreement is executed, this Privacy Policy and the Terms of Use govern such processing to the maximum extent permitted by law.

3.4. Team Administrators are responsible for all Personal Data they or their Team Members submit, manage, invite, or share through the Service. Team Administrators are responsible for informing Team Members and Counterparties about data processing where required by law.

3.5. Counterparties who access a shared document link, QR code, approval request, negotiation workflow, or invitation may have their Personal Data processed by the Operator to provide the requested sharing, access, logging, security, approval, and document workflow functionality.

3.6. The Operator is not responsible for the privacy notices, consents, lawful bases, professional obligations, confidentiality obligations, employment obligations, client obligations, or internal policies of Users, Team Administrators, organizations, Counterparties, employers, clients, or other third parties.

4. CATEGORIES OF PERSONAL DATA COLLECTED

4.1. The Operator may collect account and registration data, including name, email address, password or password hash, login credentials, account ID, user ID, authentication tokens, verification status, registration date, account status, plan status, subscription status, language preferences, timezone, account settings, and similar account information.

4.2. The Operator may collect contact data, including email address, support contact details, communication preferences, message metadata, support history, and other information provided when a User contacts the Operator.

4.3. The Operator may collect identity and business data entered by Users, including names of individuals, company names, legal entity names, business addresses, mailing addresses, phone numbers, email addresses, signatory names, job titles, business roles, party details, counterparty details, team details, and similar information used to prepare, manage, review, or share Documents.

4.4. The Operator may collect document-generation data, including selected templates, selected terms, selected options, filled fields, custom clauses, party names, counterparty names, dates, amounts, addresses, document titles, document categories, document status, document versions, draft history, download history, format choices, and other information entered or selected during document preparation.

4.5. The Operator may collect Document content, including Generated Documents, uploaded documents, reviewed documents, marked-up documents, downloaded files, AI-generated clauses, custom clauses, attachments, exhibits, comments, changes, risk reports, and other document-related content.

4.6. The Operator may collect AI interaction data, including prompts, questions, AI Inputs, AI Outputs, chat messages, character counts, usage limits, request counts, timestamps, model interaction metadata, error messages, safety signals, review status, and data necessary to provide AI chat, AI clause drafting, AI contract review, AI risk reports, and related features.

4.7. The Operator may collect uploaded file data, including file name, file type, file size, page count, document content, images, text extracted by OCR, metadata, upload time, review time, processing status, conversion outputs, detected formatting, risk report data, suggested edits, and download history.

4.8. The Operator may collect team and workspace data, including Team Administrator information, Team Member information, invitations, roles, permissions, seat counts, activity logs, shared documents, access levels, organization settings, and team billing information.

4.9. The Operator may collect counterparty and negotiation data, including recipient email addresses, link access events, approval status, document comments, fields completed by counterparties, terms selected or changed by counterparties, timestamps, IP-related security logs, browser data, and workflow activity.

4.10. The Operator may collect payment and commercial data, including purchased products, selected plans, subscription status, billing cycle, payment amount, currency, invoice metadata, transaction identifiers, payment processor identifiers, refund status, chargeback status, tax-related metadata, coupon or promotion usage, and purchase history. Full payment card numbers, CVV codes, and sensitive card credentials are generally processed by third-party payment processors rather than stored by the Operator.

4.11. The Operator may collect technical and device data, including IP address, approximate location derived from IP address, browser type, browser version, device type, operating system, screen size, language, referring URL, pages visited, session identifiers, cookie identifiers, log files, error logs, crash logs, performance data, security logs, access times, and similar technical information.

4.12. The Operator may collect analytics and usage data, including pages viewed, buttons clicked, templates searched, templates opened, features used, time spent, session duration, AI request usage, document review usage, subscription interactions, conversion events, referral sources, cookie preferences, and aggregated behavioral information.

4.13. The Operator may collect marketing and communication data, including email preferences, campaign interactions, unsubscribe records, promotional usage, referral source, consent records, and related marketing metadata.

4.14. The Operator may collect security and compliance data, including suspected fraud signals, abuse reports, rate-limit data, login attempts, failed payment records, chargeback records, blocked requests, sanctions-related signals, suspicious activity indicators, access logs, administrative logs, and legal request records.

4.15. The Operator may collect support and feedback data, including support messages, screenshots, bug reports, feature requests, survey responses, user comments, complaint records, and attachments voluntarily provided by Users.

4.16. The Operator may collect publicly available information or information from third parties where permitted by law, including information received from payment processors, analytics providers, email providers, security providers, cloud providers, AI providers, fraud prevention tools, affiliate or referral systems, and other service providers.

4.17. The Operator may collect Sensitive Data only if the User voluntarily includes such information in User Content, uploaded files, prompts, documents, support messages, party profiles, counterparty profiles, or other submissions. The Operator does not request that Users submit Sensitive Data unless a specific feature expressly requires it and the User has determined that submission is lawful and appropriate.

4.18. The Operator may collect de-identified, anonymized, aggregated, or statistical information derived from Personal Data or Service usage. Such information may not identify a particular User and may be used for any lawful purpose to the extent permitted by applicable law.

5. INFORMATION USERS SHOULD NOT SUBMIT

5.1. The User should not submit Sensitive Data unless the User has a lawful basis, all required consents, all required notices, and has determined that the Service is appropriate for processing such information.

5.2. The User must not submit payment card numbers, CVV codes, bank passwords, online banking credentials, private keys, seed phrases, account passwords, government secrets, classified information, unlawful content, malware, data obtained unlawfully, or information the User is not authorized to process.

5.3. The User should not submit protected health information, medical records, highly regulated financial information, children’s information, biometric data, criminal records, immigration records, or other highly regulated data unless the User has independently determined that such submission is lawful and appropriate.

5.4. The Service is not designed to serve as a HIPAA-compliant system, PCI DSS card data vault, government classified system, professional privilege repository, litigation hold platform, regulated financial records platform, or specialized compliance archive unless the Operator expressly agrees otherwise in a separate written agreement.

5.5. If the User submits Sensitive Data or regulated data despite this warning, the User authorizes the Operator and its service providers to process such data to provide the Service, maintain security, troubleshoot, comply with law, enforce terms, and perform other purposes described in this Privacy Policy.

5.6. The Operator may delete, restrict, quarantine, block, refuse to process, or remove Sensitive Data or other User Content where the Operator believes such data may create legal, technical, security, privacy, operational, professional, payment, or reputational risk.

6. SOURCES OF PERSONAL DATA

6.1. The Operator may collect Personal Data directly from the User when the User creates an account, signs in, purchases a document, subscribes to a plan, fills fields, selects terms, uploads documents, asks AI questions, generates clauses, contacts support, accepts cookies, changes settings, or otherwise uses the Service.

6.2. The Operator may collect Personal Data from Team Administrators, Team Members, employers, organizations, clients, representatives, or other Users who invite, add, mention, upload, enter, or share information about another person.

6.3. The Operator may collect Personal Data from Counterparties who access shared document links, fill fields, review documents, approve terms, comment, or otherwise interact with document workflows.

6.4. The Operator may collect Personal Data automatically from devices, browsers, servers, cookies, logs, analytics tools, security tools, and similar technologies.

6.5. The Operator may collect Personal Data from third-party service providers, including payment processors, email providers, fraud prevention providers, analytics providers, cloud providers, hosting providers, AI providers, OCR providers, file conversion providers, and support tools.

6.6. The Operator may collect Personal Data from public sources, where permitted by law, including publicly available websites, business registries, public records, or other sources if needed for security, fraud prevention, legal compliance, support, or service functionality.

7. PURPOSES OF PROCESSING

7.1. The Operator may process Personal Data to provide, operate, maintain, secure, troubleshoot, and improve the Service.

7.2. The Operator may process Personal Data to create, maintain, authenticate, secure, suspend, or terminate Accounts.

7.3. The Operator may process Personal Data to allow Users to select templates, choose terms, complete fields, add clauses, generate Documents, save drafts, preview text, download files, and export Documents in available formats.

7.4. The Operator may process Personal Data to store, organize, display, retrieve, manage, and make available Documents through user accounts, dashboards, document-management tools, or similar features.

7.5. The Operator may process Personal Data to provide AI Features, including AI chat, AI clause generation, AI contract review, AI document analysis, AI risk reports, AI suggested corrections, summaries, automated text extraction, and related functionality.

7.6. The Operator may process Personal Data to upload, parse, convert, OCR, analyze, mark up, summarize, review, and return uploaded documents or generated review results.

7.7. The Operator may process Personal Data to enable negotiation, approval, link sharing, counterparty access, field completion, advanced counterparty workflows, comments, and related document collaboration features.

7.8. The Operator may process Personal Data to provide team access, Team Administrator functionality, Team Member permissions, shared workspaces, role management, seat management, and team-related billing.

7.9. The Operator may process Personal Data to store and reuse party details and counterparty details where such functionality is available.

7.10. The Operator may process Personal Data to process payments, subscriptions, single-document purchases, renewals, cancellations, refunds, invoices, taxes, chargebacks, coupons, promotions, billing errors, and payment disputes.

7.11. The Operator may process Personal Data to provide technical support, respond to inquiries, investigate problems, debug errors, communicate with Users, and improve support quality.

7.12. The Operator may process Personal Data to send transactional, administrative, service-related, security-related, payment-related, subscription-related, legal, and policy-related communications.

7.13. The Operator may process Personal Data to send marketing communications, promotional offers, product updates, newsletters, or other non-essential messages where permitted by law or with consent where required.

7.14. The Operator may process Personal Data to personalize, measure, improve, and optimize the Service, including templates, user flows, AI features, document review quality, search, dashboard functionality, pricing flows, and website performance.

7.15. The Operator may process Personal Data to conduct analytics, research, testing, product development, feature development, performance measurement, conversion measurement, aggregated reporting, and business intelligence.

7.16. The Operator may process Personal Data to maintain security, prevent fraud, detect abuse, enforce quotas, apply rate limits, prevent unauthorized access, prevent scraping, protect accounts, protect documents, investigate suspicious activity, and enforce the Terms of Use.

7.17. The Operator may process Personal Data to comply with legal obligations, court orders, regulatory requests, law enforcement requests, tax obligations, accounting obligations, payment obligations, sanctions obligations, consumer protection obligations, and other applicable requirements.

7.18. The Operator may process Personal Data to establish, exercise, defend, investigate, settle, or preserve legal claims, contractual rights, security rights, intellectual property rights, payment rights, and other rights of the Operator, Users, or third parties.

7.19. The Operator may process Personal Data to protect the rights, property, privacy, safety, security, and interests of the Operator, Users, Counterparties, Team Members, service providers, and third parties.

7.20. The Operator may process Personal Data in connection with mergers, acquisitions, financing, restructuring, sale of assets, corporate transactions, transfer of business, due diligence, insolvency, or similar events.

7.21. The Operator may process Personal Data for any other purpose disclosed to the User at the time of collection or otherwise permitted by applicable law.

8. LEGAL BASES FOR PROCESSING

8.1. Where applicable law requires a legal basis, the Operator may process Personal Data on one or more of the following bases.

8.2. The Operator may process Personal Data because processing is necessary to enter into or perform a contract with the User, including providing the Service, maintaining an Account, generating Documents, processing purchases, providing subscriptions, delivering AI Features, and providing support.

8.3. The Operator may process Personal Data because processing is necessary for the Operator’s legitimate interests or the legitimate interests of a third party, provided such interests are not overridden by applicable rights and freedoms. Legitimate interests may include service operation, security, fraud prevention, abuse prevention, product improvement, analytics, marketing to existing Users where permitted, legal claims, payment protection, and business administration.

8.4. The Operator may process Personal Data because the User has given consent, including for optional cookies, marketing communications, certain AI uses, certain Sensitive Data processing, or other processing where consent is required.

8.5. The Operator may process Personal Data because processing is necessary to comply with legal obligations, including tax, accounting, consumer protection, sanctions, payment, data protection, court order, regulatory, or law enforcement obligations.

8.6. The Operator may process Personal Data because processing is necessary to protect vital interests where applicable, including preventing serious harm, security threats, fraud, or unlawful activity.

8.7. The Operator may process Personal Data because processing is necessary for the establishment, exercise, or defense of legal claims.

8.8. Where the Operator processes Sensitive Data, the Operator may rely on explicit consent, the User’s voluntary submission, the necessity of processing for legal claims, the User’s manifest disclosure, legal obligations, substantial public interest where applicable, or another lawful basis available under applicable law.

8.9. The legal basis may vary depending on the User’s location, the type of data, the feature used, the applicable law, and the purpose of processing.

9. AI FEATURES, AI CHAT, AI CLAUSE GENERATION, AND AI CONTRACT REVIEW

9.1. AI Features process AI Inputs and generate AI Outputs automatically. AI Inputs may include prompts, legal questions, selected terms, custom clauses, uploaded documents, images, extracted text, party information, counterparty information, business information, and other User Content.

9.2. The Operator may process AI Inputs and AI Outputs to provide AI chat, answer user questions, draft clauses, suggest wording, identify possible risks, generate risk reports, highlight risky wording, find potential inaccuracies, suggest corrections, create marked-up documents, and provide related functionality.

9.3. AI Features may be provided using third-party AI providers, cloud providers, OCR providers, file conversion providers, storage providers, security providers, logging systems, monitoring systems, and related technology providers.

9.4. User Content submitted to AI Features may be transmitted to, stored by, processed by, logged by, or otherwise handled by such providers to provide the requested functionality, maintain the Service, improve reliability, detect abuse, ensure safety, troubleshoot errors, and comply with applicable law.

9.5. The Operator may use AI interaction data, including AI Inputs, AI Outputs, usage metadata, error metadata, feedback, anonymized data, aggregated data, and de-identified data, to maintain, test, evaluate, debug, secure, improve, and develop AI Features, to the extent permitted by applicable law and applicable provider terms.

9.6. The Operator does not guarantee that AI Features will be confidential in the same way as communications with a licensed attorney, advocate, solicitor, barrister, accountant, tax adviser, or other regulated professional. The User must not assume that AI Inputs or AI Outputs are protected by attorney-client privilege, work-product doctrine, professional secrecy, litigation privilege, accountant-client privilege, or similar doctrines.

9.7. AI Outputs may be inaccurate, incomplete, outdated, misleading, biased, unsafe, irrelevant, or unsuitable. The Operator may retain AI Inputs and AI Outputs for support, debugging, safety, abuse prevention, legal compliance, security, and service improvement, subject to this Privacy Policy.

9.8. The AI chat interface may display a specific retention period for chat history. Deletion from the visible chat interface does not necessarily mean immediate deletion from backups, logs, security systems, analytics systems, provider systems, legal records, or archived systems.

9.9. AI contract review may require processing the full content of uploaded contracts, agreements, addenda, exhibits, attachments, images, PDFs, DOCX files, TXT files, and other supported file types. Such files may contain Personal Data and Sensitive Data. The User is solely responsible for confirming that the User is authorized to upload and process such files through the Service.

9.10. The Operator may refuse, restrict, delete, or block AI Inputs, uploaded files, or AI Outputs that appear unlawful, abusive, harmful, excessive, fraudulent, infringing, technically unsafe, privacy-risky, or otherwise inappropriate.

9.11. The Operator may use automated systems to enforce character limits, request limits, review limits, rate limits, file limits, page limits, subscription limits, abuse-prevention rules, and security controls.

9.12. The Operator does not intend AI Features to make decisions that produce legal or similarly significant effects concerning the User without human involvement, unless such processing is disclosed, authorized by law, necessary for a contract, based on consent, or otherwise permitted by applicable law. However, AI Features do produce automated drafts, analyses, suggestions, risk reports, classifications, and outputs that the User may choose to review and use at the User’s own discretion.

10. DOCUMENTS, GENERATED DOCUMENTS, AND UPLOADED FILES

10.1. Documents may contain Personal Data, Sensitive Data, confidential business information, trade secrets, financial terms, employment information, lease information, transaction details, personal addresses, contact information, signatures, identity information, family information, real estate information, loan information, corporate information, and other sensitive or confidential content.

10.2. The Operator may process Documents to provide document-generation, document-management, editing, downloading, exporting, sharing, AI review, risk reporting, file conversion, formatting, storage, and related functionality.

10.3. Generated Documents may be stored in the User’s Account or made available for download depending on the feature, plan, access period, technical settings, and payment status.

10.4. Uploaded documents for AI contract review may be processed to extract text, analyze content, generate suggested corrections, create marked-up versions, produce risk reports, and return downloadable results.

10.5. Document-related metadata may be processed, including document name, category, status, created date, modified date, downloaded date, shared date, counterparty access status, amount, key dates, party names, and similar dashboard information.

10.6. The Operator may use encryption, account-based access controls, technical restrictions, and other safeguards to protect Documents. However, no system can guarantee absolute security, and the Operator does not guarantee that Documents will never be lost, corrupted, accessed, disclosed, or unavailable.

10.7. Support personnel may be technically restricted from accessing certain created Documents in ordinary support workflows. However, authorized personnel, systems, or service providers may process or access limited User Content where necessary for security, legal compliance, debugging, abuse prevention, system administration, account recovery, file processing, AI processing, or other legitimate operational purposes.

10.8. The User is responsible for downloading and keeping independent copies of Documents. The Service is not a permanent archive, official record system, evidence preservation service, legal hold platform, regulated records service, or backup provider.

10.9. The Operator may delete, disable, restrict, or make unavailable Documents, drafts, uploaded files, review results, links, and generated files after access periods expire, when accounts are inactive, when payment fails, when limits are exceeded, when storage policies require deletion, or when required for security, legal, compliance, or operational reasons.

11. PARTY MANAGEMENT, COUNTERPARTY MANAGEMENT, AND SHARING FEATURES

11.1. The Service may allow Users to store, reuse, edit, delete, and manage party or counterparty details, including names, addresses, emails, phone numbers, entity names, signatory information, role information, business information, and other data.

11.2. The User is responsible for ensuring that party and counterparty information is accurate, lawful, authorized, and submitted with all necessary notices and consents.

11.3. When a User sends a document link, QR code, approval request, negotiation request, or invitation, the recipient may view Personal Data and other content included in the Document or workflow.

11.4. The Operator may process recipient email addresses, access timestamps, IP-related security logs, device data, approval status, completed fields, comments, edits, selected terms, and related workflow data to provide sharing and negotiation functionality.

11.5. The Operator is not responsible for a User sending a link to the wrong person, a recipient forwarding a link, unauthorized access caused by User conduct, or a Counterparty’s use, disclosure, copying, downloading, printing, photographing, or misuse of shared content.

11.6. Shared links may be accessible to anyone with the link unless access controls are enabled. The User is responsible for deciding whether to share a link and for verifying the recipient’s identity, authority, and permissions.

11.7. The Operator may log access to shared links and workflow actions for security, audit, support, troubleshooting, fraud prevention, and dispute purposes.

12. TEAM ACCOUNTS AND ORGANIZATION USE

12.1. Where team or organization features are used, the Operator may process Team Administrator data, Team Member data, invitations, roles, permissions, team seat information, shared documents, workspace activity, team billing information, and related data.

12.2. Team Administrators may be able to access, manage, edit, export, delete, share, or restrict documents, profiles, activity, permissions, and other information associated with the team account, depending on feature settings.

12.3. Team Members should understand that information they create, upload, edit, or store under a team account may be visible to Team Administrators or other authorized team users.

12.4. Team Administrators are responsible for ensuring that all Team Members and Counterparties receive legally required privacy notices and that all team processing complies with applicable law.

12.5. The Operator may rely on instructions from Team Administrators regarding access, deletion, export, billing, permissions, member removal, and account changes unless the Operator determines that such instruction is unlawful, risky, unclear, or inconsistent with the Service.

12.6. The Operator is not responsible for disputes between Team Administrators, Team Members, employers, employees, contractors, clients, affiliates, or other persons regarding access to data, ownership of documents, confidentiality, internal policies, or privacy obligations.

13. PAYMENTS, BILLING, AND SUBSCRIPTIONS

13.1. The Operator may process payment-related data to provide paid features, single-document access, subscriptions, plan renewals, cancellations, refunds, invoice records, tax records, fraud prevention, and customer support.

13.2. Payment processing may be performed by third-party payment processors. The Operator may receive limited payment metadata, such as transaction ID, payment status, amount, currency, product purchased, subscription status, billing period, refund status, card brand, last four digits, billing country, or similar non-sensitive payment information.

13.3. Full card numbers, CVV codes, and sensitive payment credentials should be entered only into secure payment processor pages or fields intended for that purpose. Users must not submit payment card details through AI chat, document fields, uploaded files, email, support messages, or other ordinary website fields.

13.4. Payment processors may process Personal Data according to their own terms and privacy policies. The Operator is not responsible for all acts, omissions, security measures, retention practices, or legal obligations of payment processors.

13.5. The Operator may process payment and billing data to detect fraud, investigate chargebacks, prevent abuse, manage failed payments, enforce subscription terms, comply with tax and accounting obligations, and resolve disputes.

14. COOKIES, TRACKING TECHNOLOGIES, AND ANALYTICS

14.1. The Service may use cookies, pixels, tags, local storage, session storage, software development kits, server logs, device identifiers, analytics identifiers, and similar technologies.

14.2. Essential cookies and similar technologies may be used to provide login, authentication, security, fraud prevention, session management, cookie preferences, account functionality, payment flow, document drafting, AI chat, and other core Service functions.

14.3. Functional cookies may be used to remember preferences, improve usability, maintain settings, support chat functionality, remember dismissed notices, or provide enhanced features.

14.4. Analytics cookies and similar technologies may be used to measure performance, understand usage, monitor errors, analyze conversion, improve templates, improve user flows, evaluate marketing effectiveness, and develop the Service. This may include Google Analytics or similar analytics tools.

14.5. Marketing cookies or advertising technologies may be used if implemented by the Operator to measure campaigns, understand referral sources, promote the Service, or deliver relevant messages, subject to applicable law and consent requirements.

14.6. Cookie banners or settings may allow Users to accept, decline, or manage certain cookies where required or provided. Essential cookies may not be disabled through the Service because they are necessary for operation.

14.7. The User may block or delete cookies through browser settings. Blocking cookies may affect login, document generation, account access, AI features, payment flow, chat functionality, and other Service features.

14.8. The Operator may interpret continued use of the Service as acceptance of cookies where permitted by law. Where applicable law requires consent for non-essential cookies, the Operator may request consent before placing such cookies.

14.9. Third-party analytics providers may collect data through cookies and similar technologies according to their own terms and privacy practices. The Operator does not control all third-party cookie practices.

14.10. The Service may not respond to every “Do Not Track” signal because there is no uniform technical standard. Where legally required and technically feasible, the Operator may honor recognized opt-out preference signals, such as Global Privacy Control, for applicable processing.

15. MARKETING COMMUNICATIONS

15.1. The Operator may send marketing communications, promotional offers, product updates, educational content, feature announcements, newsletters, and similar messages where permitted by law.

15.2. The Operator may use name, email address, account status, plan status, purchase history, template interest, feature usage, campaign interactions, referral source, and similar data for marketing purposes.

15.3. Users may unsubscribe from marketing emails by using an unsubscribe link where available or by contacting the Operator. Unsubscribing from marketing does not stop transactional, legal, payment, security, account, or service-related communications.

15.4. The Operator may send service-related messages even if the User has opted out of marketing, including messages about accounts, purchases, subscriptions, security, policy changes, legal notices, payment failures, document access, and support.

15.5. The Operator may use aggregated or anonymized analytics to promote, evaluate, and improve the Service.

16. SHARING AND DISCLOSURE OF PERSONAL DATA

16.1. The Operator may disclose Personal Data to service providers, processors, contractors, vendors, and technology providers who help operate, maintain, secure, improve, and provide the Service.

16.2. Categories of service providers may include hosting providers, cloud providers, database providers, storage providers, AI providers, large language model providers, OCR providers, file conversion providers, analytics providers, payment processors, email providers, customer support tools, security providers, fraud prevention providers, monitoring providers, logging providers, error tracking providers, communication providers, marketing providers, professional advisers, and other operational vendors.

16.3. The Operator may disclose Personal Data to AI providers and related technology providers to process AI Inputs, generate AI Outputs, review documents, create risk reports, analyze uploaded files, and provide related AI functionality.

16.4. The Operator may disclose Personal Data to payment processors to process payments, subscriptions, refunds, failed payments, chargebacks, fraud checks, and billing disputes.

16.5. The Operator may disclose Personal Data to analytics providers to measure traffic, performance, conversions, user behavior, and marketing effectiveness.

16.6. The Operator may disclose Personal Data to email providers and communication providers to send transactional, service, support, marketing, security, and legal communications.

16.7. The Operator may disclose Personal Data to security and fraud prevention providers to protect accounts, payments, documents, infrastructure, and the Service.

16.8. The Operator may disclose Personal Data to Team Administrators, Team Members, Counterparties, recipients, invitees, or other Users as necessary to provide team, sharing, negotiation, approval, and document workflow features.

16.9. The Operator may disclose Personal Data to professional advisers, including lawyers, accountants, auditors, insurers, consultants, tax advisers, and compliance advisers.

16.10. The Operator may disclose Personal Data to courts, law enforcement, regulators, government authorities, payment networks, payment processors, hosting providers, or other third parties when the Operator believes disclosure is necessary or appropriate to comply with law, respond to legal process, enforce rights, protect security, investigate fraud, prevent harm, or comply with contractual obligations.

16.11. The Operator may disclose Personal Data in connection with a merger, acquisition, financing, restructuring, asset sale, bankruptcy, insolvency, transfer of business, due diligence, or similar transaction.

16.12. The Operator may disclose aggregated, anonymized, or de-identified information for analytics, research, marketing, business development, reporting, service improvement, or any other lawful purpose.

16.13. The Operator does not sell Personal Data for money in the ordinary meaning of “sell.” However, some privacy laws define “sale,” “sharing,” “targeted advertising,” or “cross-context behavioral advertising” broadly. If any analytics, advertising, or tracking activity is deemed a “sale” or “share” under applicable law, the Operator will provide applicable opt-out rights where required.

16.14. The Operator may share data with affiliates, successors, assigns, contractors, or service providers for business administration and Service operation, subject to applicable law.

16.15. The Operator may disclose Personal Data with the User’s consent or at the User’s direction.

17. INTERNATIONAL DATA TRANSFERS

17.1. The Operator, its service providers, and third-party technology providers may process, store, access, or transfer Personal Data in countries other than the User’s country of residence.

17.2. Such countries may have data protection laws that differ from the laws of the User’s country.

17.3. Personal Data may be transferred to or processed in any country where the Operator, hosting providers, cloud providers, AI providers, payment processors, analytics providers, support providers, or other vendors operate or maintain infrastructure.

17.4. The Operator may use appropriate safeguards where required by applicable law, which may include contractual protections, data processing agreements, standard contractual clauses, adequacy decisions, consent, necessity for contract performance, necessity for legal claims, or other lawful transfer mechanisms.

17.5. The Operator does not guarantee that Personal Data will remain in one country unless expressly agreed in a separate written agreement.

17.6. By using the Service, the User acknowledges that international processing and transfer may be necessary to provide cloud hosting, AI features, payment processing, analytics, support, security, and other Service functionality.

18. RETENTION OF PERSONAL DATA

18.1. The Operator retains Personal Data for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer or shorter retention period is required or permitted by law.

18.2. Retention periods may depend on the type of data, account status, plan status, payment status, feature used, document type, legal obligations, operational needs, security needs, dispute risk, backup cycles, user settings, deletion requests, and applicable law.

18.3. Account data may be retained for as long as the Account is active and for a reasonable period thereafter for legal, operational, security, fraud prevention, tax, accounting, dispute resolution, and business continuity purposes.

18.4. Document data, Generated Documents, drafts, uploaded files, AI review results, risk reports, and related metadata may be retained while the Account, plan, access period, or feature remains active and for a reasonable period thereafter, unless deleted earlier according to feature settings, user actions, or Operator policies.

18.5. AI chat history may be removed from the visible user interface according to the retention period displayed in the chat feature. Copies may remain for a longer period in backups, logs, security systems, provider systems, legal records, or other systems as described in this Privacy Policy.

18.6. Payment, subscription, invoice, refund, tax, accounting, and transaction records may be retained for the period required or permitted by tax, accounting, consumer protection, payment, chargeback, anti-fraud, and legal requirements.

18.7. Security logs, access logs, fraud signals, abuse prevention records, rate-limit data, and system logs may be retained for as long as reasonably necessary to protect the Service, investigate incidents, detect abuse, preserve evidence, comply with law, and enforce rights.

18.8. Support communications may be retained for as long as reasonably necessary to resolve issues, improve support, maintain records, comply with law, and defend legal claims.

18.9. Marketing records may be retained until the User unsubscribes or until the data is no longer needed, subject to retention of suppression lists to honor opt-out requests.

18.10. Aggregated, anonymized, and de-identified information may be retained indefinitely to the extent permitted by law.

18.11. Deleted data may remain for a period in backups, caches, logs, archives, disaster recovery systems, and third-party provider systems until overwritten, deleted, or no longer needed.

18.12. The Operator may retain data despite a deletion request if retention is necessary or permitted for legal obligations, fraud prevention, security, payment disputes, chargebacks, tax records, accounting, legal claims, contractual obligations, user safety, system integrity, or other lawful purposes.

18.13. The Operator may delete inactive accounts, expired documents, old drafts, unused review files, outdated logs, or other data at any time where permitted by law and consistent with operational needs.

19. SECURITY MEASURES

19.1. The Operator uses reasonable technical, organizational, administrative, and security measures designed to protect Personal Data against unauthorized access, loss, misuse, alteration, disclosure, and destruction.

19.2. Security measures may include encryption where feasible, account-based access controls, password protection, secure transmission, access restrictions, logging, monitoring, backups, provider security controls, administrative safeguards, and abuse prevention systems.

19.3. The Operator may limit access to Personal Data to personnel, contractors, service providers, and systems that need access for Service operation, security, support, compliance, or other legitimate purposes.

19.4. The Operator may use third-party providers to host, store, secure, monitor, and process Personal Data. The security of those providers may affect the security of the Service.

19.5. No online service, website, AI system, cloud storage system, payment system, email system, or internet transmission can be guaranteed to be completely secure. The Operator does not guarantee absolute security or that Personal Data will never be accessed, disclosed, altered, lost, corrupted, or destroyed.

19.6. The User is responsible for securing login credentials, passwords, devices, email accounts, shared links, team permissions, and any copies of Documents downloaded from the Service.

19.7. The User must promptly notify the Operator of any suspected unauthorized access, compromised credentials, incorrect sharing, account misuse, suspicious payment activity, or security incident.

19.8. The Operator may suspend or restrict access where the Operator believes an Account, document, link, payment method, device, IP address, or activity presents security, privacy, payment, abuse, or legal risk.

19.9. The Operator may investigate security incidents and notify Users, regulators, service providers, law enforcement, or other parties where required by law or where the Operator determines that notification is appropriate.

20. USER RESPONSIBILITIES FOR THIRD-PARTY DATA

20.1. The User must not submit Personal Data of another person unless the User has a lawful basis, has provided required notices, has obtained required consents, and has authority to process such data through the Service.

20.2. The User is responsible for Personal Data entered into templates, party profiles, counterparty profiles, team accounts, documents, AI prompts, uploaded files, custom clauses, support messages, and shared links.

20.3. The User is responsible for ensuring that document sharing, link sharing, counterparty invitations, team invitations, AI review, AI chat, and document generation comply with confidentiality obligations, employment obligations, professional obligations, client obligations, privacy laws, data protection laws, and contractual restrictions.

20.4. The User must not use the Service to collect, process, or disclose Personal Data unlawfully, deceptively, unfairly, without authorization, or in violation of third-party rights.

20.5. The User is responsible for responding to privacy requests from persons whose Personal Data the User entered, uploaded, or shared through the Service, unless applicable law requires otherwise.

20.6. The User agrees to indemnify the Operator for claims, losses, liabilities, penalties, fines, costs, and expenses arising from the User’s unlawful, unauthorized, or improper submission or processing of third-party Personal Data, as further described in the Terms of Use.

21. USER RIGHTS AND CHOICES

21.1. Depending on applicable law and the User’s location, the User may have rights to request access, confirmation of processing, a copy of Personal Data, correction, update, completion, deletion, erasure, destruction, restriction, blocking, portability, withdrawal of consent, objection, opt-out of marketing, opt-out of certain disclosures, limitation of certain sensitive data uses, or review of certain automated decisions.

21.2. The availability and scope of rights depend on applicable law, the type of data, the processing purpose, the User’s relationship with the Operator, identity verification, legal exceptions, technical feasibility, and competing rights.

21.3. The Operator may require information to verify the User’s identity, authority, account ownership, email address, payment record, document relationship, or entitlement before responding to a request.

21.4. The Operator may refuse, limit, delay, or charge a reasonable fee for requests that are manifestly unfounded, excessive, repetitive, technically infeasible, legally restricted, harmful to others, inconsistent with rights of third parties, or otherwise permitted to be refused by law.

21.5. The Operator may retain certain data despite a rights request where necessary or permitted for legal obligations, security, fraud prevention, payment disputes, tax records, accounting, legal claims, contractual obligations, backups, system integrity, or other lawful purposes.

21.6. Users may access and update certain Account information directly through account settings where available.

21.7. Users may delete or modify certain documents, party details, counterparty details, or account content through available Service functionality where provided. Such deletion may not remove all copies from backups, logs, provider systems, or legal records.

21.8. Users may opt out of marketing emails through unsubscribe links where available or by contacting the Operator.

21.9. Users may manage cookies through cookie settings where available or browser controls.

21.10. Users may contact the Operator regarding privacy rights through the contact email displayed on the website or through any privacy contact method made available by the Operator.

21.11. The Operator will respond to privacy requests within the time required by applicable law. Response times may vary depending on the law, complexity, verification, request volume, technical feasibility, and legal exceptions.

21.12. If a User believes that privacy rights have been violated, the User may have the right to lodge a complaint with a competent data protection authority, regulator, court, or other body, depending on applicable law.

22. CONSENT AND WITHDRAWAL OF CONSENT

22.1. Where processing is based on consent, the User may withdraw consent at any time, subject to applicable law and technical limitations.

22.2. Withdrawal of consent does not affect processing that occurred before withdrawal.

22.3. Withdrawal of consent may prevent the Operator from providing certain features, including AI features, marketing communications, optional cookies, document sharing, file processing, or other functions dependent on consent.

22.4. The Operator may continue processing Personal Data after withdrawal of consent where another legal basis applies, including contract performance, legal obligations, legitimate interests, security, fraud prevention, legal claims, accounting, tax, or other lawful purposes.

23. AUTOMATED PROCESSING, PROFILING, AND DECISION-MAKING

23.1. The Service uses automated systems for account operation, document generation, AI chat, AI clause drafting, AI contract review, file processing, OCR, suggested corrections, risk reports, analytics, security, fraud prevention, rate limits, subscription limits, and abuse detection.

23.2. Automated processing may produce AI Outputs, document suggestions, risk classifications, warnings, usage counts, subscription restrictions, payment risk signals, security alerts, or other automated results.

23.3. The Operator does not intend automated processing to make decisions that produce legal or similarly significant effects about the User without human involvement, unless permitted by applicable law or disclosed in connection with a specific feature.

23.4. AI Outputs, risk reports, suggested corrections, and automated analyses are informational outputs that the User may accept, reject, edit, or ignore. The Operator does not make legal decisions for the User and does not determine the User’s legal rights or obligations.

23.5. The Operator may use automated systems to suspend, restrict, rate-limit, or flag Accounts, payments, uploads, AI requests, or other activity where necessary for security, fraud prevention, abuse prevention, payment protection, or legal compliance. Users may contact the Operator if they believe such action was incorrect.

24. DATA OF CHILDREN AND MINORS

24.1. The Service is intended for Users who are at least 18 years old.

24.2. The Operator does not knowingly collect Personal Data from children under 13 years old or from minors where parental consent is required, except where permitted by law and expressly authorized.

24.3. Users must not submit children’s Personal Data unless they have lawful authority and have determined that the Service is appropriate for such processing.

24.4. If the Operator learns that it has collected Personal Data from a child in violation of applicable law, the Operator may delete, restrict, or de-identify such data.

24.5. Parents or guardians who believe that a child has submitted Personal Data may contact the Operator through the contact email displayed on the website.

25. PRIVACY RIGHTS FOR USERS IN GEORGIA

25.1. Where the laws of Georgia apply, Users may have rights under applicable personal data protection legislation, including rights to information, access, copies, rectification, update, completion, erasure, destruction, termination of processing, blocking, portability, withdrawal of consent, objection or restrictions relating to automated decision-making, and appeal.

25.2. The Operator may respond to Georgian data subject requests within the period required by applicable Georgian law, subject to verification, legal exceptions, technical feasibility, and permitted extensions.

25.3. The Operator may refuse or restrict a request where permitted by applicable law, including where processing is necessary for legal claims, legal obligations, contract performance, security, fraud prevention, protection of rights, or other lawful purposes.

25.4. If required by Georgian law, the Operator may inform competent authorities or affected persons about certain data security incidents.

25.5. If required by Georgian law, the Operator may conduct data protection impact assessments, maintain incident records, implement technical and organizational measures, or take other steps required for high-risk processing.

26. PRIVACY RIGHTS FOR USERS IN THE EEA, UK, OR SIMILAR JURISDICTIONS

26.1. Where the GDPR, UK GDPR, or similar law applies, Users may have rights to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.

26.2. Users may object to processing based on legitimate interests where applicable. The Operator may continue processing if compelling legitimate grounds exist or if processing is necessary for legal claims.

26.3. Users may object to direct marketing at any time. If a User objects to direct marketing, the Operator will stop using the User’s Personal Data for direct marketing purposes, subject to retention of suppression records.

26.4. Users may request portability of Personal Data they provided to the Operator where processing is based on consent or contract and carried out by automated means, subject to technical feasibility and legal limitations.

26.5. Users may request restriction of processing where applicable, including where accuracy is contested, processing is unlawful, data is needed for legal claims, or objection is pending.

26.6. Where the Operator relies on consent, the User may withdraw consent at any time.

26.7. The Operator may transfer Personal Data outside the EEA, UK, or other protected jurisdictions using lawful transfer mechanisms where required.

26.8. The Operator may appoint an EU or UK representative or data protection officer only where required by applicable law. Unless expressly stated on the website or in a separate notice, the contact email displayed on the website is the primary privacy contact.

27. PRIVACY RIGHTS FOR CALIFORNIA AND CERTAIN U.S. RESIDENTS

27.1. This section applies only where California or other U.S. state privacy laws apply to the Operator and the User.

27.2. Depending on applicable law, Users may have rights to know, access, correct, delete, obtain a copy, opt out of sale, opt out of sharing, opt out of targeted advertising, limit certain sensitive personal information uses, opt out of certain profiling, and not be discriminated against for exercising privacy rights.

27.3. The Operator may collect the following categories of personal information, depending on the User’s interaction with the Service:

(a) identifiers, such as name, email address, IP address, account ID, and similar identifiers;

(b) customer records information, such as billing information, contact information, and account information;

(c) commercial information, such as purchases, subscription status, payment metadata, and product usage;

(d) internet or electronic network activity, such as device data, log data, pages viewed, cookies, analytics, and feature usage;

(e) approximate geolocation data derived from IP address;

(f) professional or employment-related information if included in documents, accounts, team profiles, or business use;

(g) education information if voluntarily included in User Content;

(h) sensitive personal information if voluntarily submitted in documents, prompts, uploads, support messages, or other User Content;

(i) inferences or analytics derived from usage, preferences, or interactions;

(j) audio, visual, or image data if the User uploads images or screenshots.

27.4. The Operator may collect such categories from Users, devices, browsers, cookies, Team Administrators, Team Members, Counterparties, service providers, payment processors, analytics providers, security providers, and other sources described in this Privacy Policy.

27.5. The Operator may use such categories for the business and commercial purposes described in this Privacy Policy, including service provision, account management, payments, document generation, AI features, document review, support, security, fraud prevention, analytics, marketing, legal compliance, and business administration.

27.6. The Operator may disclose such categories to the categories of recipients described in this Privacy Policy, including hosting providers, cloud providers, AI providers, analytics providers, payment processors, email providers, support providers, security providers, professional advisers, authorities, business transferees, Team Administrators, Team Members, Counterparties, and other Users as directed by sharing features.

27.7. The Operator does not knowingly sell Personal Data for money. The Operator does not knowingly sell or share Personal Data of children under 16.

27.8. If the Operator’s use of analytics, advertising cookies, pixels, or similar technologies is considered a “sale,” “share,” or “targeted advertising” under applicable law, Users may have the right to opt out using available cookie controls, browser signals recognized by law, or privacy contact methods.

27.9. The Operator may use Sensitive Data only for purposes permitted by applicable law, including providing the requested Service, security, fraud prevention, legal compliance, and other permitted purposes. The Operator does not intend to use Sensitive Data to infer characteristics where prohibited by law.

27.10. The Operator may require verification before responding to privacy requests. Authorized agents may submit requests where permitted by law, but the Operator may require proof of authority and direct verification from the User.

27.11. The Operator will not unlawfully discriminate against Users for exercising applicable privacy rights. However, certain features may be unavailable if data necessary to provide them is deleted, restricted, or withheld.

28. DATA PROCESSING AGREEMENTS AND BUSINESS USERS

28.1. Business Users, Team Administrators, organizations, and other entities are responsible for determining whether a data processing agreement, business associate agreement, standard contractual clauses, transfer agreement, confidentiality agreement, or other document is required before using the Service.

28.2. Unless the Operator expressly enters into a separate written agreement, the Operator does not agree to User-provided data processing terms, procurement terms, vendor terms, security schedules, business associate terms, or similar terms.

28.3. The Service is not intended for processing data subject to special enterprise, healthcare, financial, government, education, or regulated industry requirements unless the Operator expressly agrees otherwise in writing.

28.4. If a business User requires a separate data processing agreement, the User must contact the Operator before submitting regulated or high-risk data. The Operator may refuse such request or require additional terms, fees, or technical limitations.

29. THIRD-PARTY SERVICES AND LINKS

29.1. The Service may contain links to third-party websites, services, content, payment pages, resources, articles, or tools.

29.2. This Privacy Policy does not apply to third-party websites or services that are not controlled by the Operator.

29.3. Third-party services may collect, use, disclose, store, transfer, or otherwise process Personal Data according to their own privacy policies and terms.

29.4. The Operator is not responsible for third-party privacy practices, security practices, content, availability, accuracy, policies, or compliance.

29.5. Users should review third-party privacy policies before submitting Personal Data to third-party services.

30. LEGAL REQUESTS, COMPLIANCE, AND PROTECTION OF RIGHTS

30.1. The Operator may access, preserve, use, or disclose Personal Data if the Operator believes it is reasonably necessary to:

(a) comply with applicable law;

(b) respond to court orders, subpoenas, warrants, legal process, regulatory requests, or government requests;

(c) enforce the Terms of Use, this Privacy Policy, or other agreements;

(d) collect unpaid amounts or resolve payment disputes;

(e) detect, prevent, or investigate fraud, abuse, security incidents, or unlawful activity;

(f) protect the rights, privacy, safety, property, or security of the Operator, Users, Counterparties, Team Members, service providers, or third parties;

(g) establish, exercise, or defend legal claims;

(h) comply with tax, accounting, payment, sanctions, or reporting obligations;

(i) respond to emergencies or prevent harm.

30.2. The Operator may challenge legal requests where appropriate but is not obligated to do so.

30.3. The Operator may notify affected Users of legal requests where permitted and appropriate, but may refrain from notice if prohibited by law, court order, security concerns, confidentiality obligations, or risk of harm.

31. BUSINESS TRANSFERS

31.1. Personal Data may be disclosed, transferred, assigned, licensed, or otherwise made available in connection with any merger, acquisition, financing, investment, reorganization, sale of assets, transfer of business, corporate transaction, due diligence, bankruptcy, insolvency, or similar event.

31.2. The recipient of Personal Data in a business transfer may continue processing Personal Data according to this Privacy Policy or another privacy policy provided after the transaction, subject to applicable law.

31.3. The Operator may disclose Personal Data to advisers, potential buyers, investors, lenders, counterparties, and their representatives in connection with evaluation or completion of such transactions.

32. DE-IDENTIFIED, ANONYMIZED, AND AGGREGATED DATA

32.1. The Operator may create, use, retain, disclose, sell, license, publish, or otherwise process de-identified, anonymized, or aggregated data to the extent permitted by law.

32.2. Such data may be used for analytics, product development, AI feature improvement, template improvement, service performance, marketing, research, benchmarking, reporting, security, and business purposes.

32.3. The Operator will not attempt to re-identify anonymized data where prohibited by law.

32.4. De-identified, anonymized, or aggregated data may be retained indefinitely.

33. USER-GENERATED CONTENT AND PUBLIC DISCLOSURE

33.1. The Service is primarily designed for private account-based document preparation and management. However, Users may choose to share documents, links, comments, fields, approvals, or other content with Counterparties, Team Members, or other persons.

33.2. Any Personal Data shared by a User through a link, invitation, download, email, screenshot, printout, exported file, copied text, or other external method may be accessible outside the Service.

33.3. The Operator cannot control what recipients do with information shared by the User.

33.4. The User should carefully review all documents and sharing settings before sending links or files.

34. EMAIL, SUPPORT, AND COMMUNICATION SECURITY

34.1. Email and ordinary internet communications may not be secure. Users should avoid sending Sensitive Data, payment card details, passwords, private keys, or highly confidential documents by email unless they have determined that doing so is appropriate.

34.2. The Operator may retain support communications, including emails and attachments, for support, training, quality, security, legal, and recordkeeping purposes.

34.3. The Operator may use support tools, email providers, ticketing systems, logging systems, or other providers to manage support communications.

34.4. The Operator may ask for additional information to verify the User’s identity or authority before responding to account, billing, document, privacy, or security requests.

34.5. Support communications do not constitute legal advice, tax advice, accounting advice, professional advice, or privileged communications.

35. ACCOUNT CLOSURE AND DELETION REQUESTS

35.1. Users may request account closure or deletion through available account settings or by contacting the Operator.

35.2. Account closure may result in loss of access to documents, downloads, drafts, AI Outputs, uploaded files, risk reports, payment history, subscriptions, team workspaces, party profiles, counterparty profiles, and shared links.

35.3. Closing an account does not automatically cancel subscriptions unless the User follows the applicable cancellation procedure.

35.4. The Operator may retain data after account closure as described in this Privacy Policy.

35.5. The Operator may refuse or delay deletion where necessary for legal obligations, payment disputes, chargebacks, fraud prevention, security, legal claims, tax records, accounting, enforcement, backups, or other lawful purposes.

36. DATA ACCURACY

36.1. The Operator relies on Users to provide accurate, complete, and current information.

36.2. The User is responsible for correcting inaccurate account data, document data, party data, counterparty data, billing data, prompts, uploaded files, and other User Content.

36.3. The Operator does not independently verify the accuracy of User-entered document fields, party information, counterparty information, legal entity information, addresses, dates, amounts, or uploaded files.

36.4. Incorrect Personal Data may result in incorrect documents, failed payments, account access issues, failed communications, incorrect sharing, or other problems.

37. LIMITATIONS OF PRIVACY POLICY AND LIABILITY

37.1. This Privacy Policy describes the Operator’s privacy practices but does not guarantee absolute privacy, absolute security, uninterrupted confidentiality, perfect deletion, error-free processing, or complete control over third-party systems.

37.2. The Operator is not responsible for privacy breaches, disclosures, or losses caused by:

(a) User error;

(b) weak passwords;

(c) shared credentials;

(d) compromised devices;

(e) compromised email accounts;

(f) wrong recipient links;

(g) forwarding by Counterparties;

(h) downloaded files stored outside the Service;

(i) User-submitted third-party data without authority;

(j) third-party service failures;

(k) internet transmission risks;

(l) force majeure events;

(m) unlawful acts of third parties;

(n) circumstances outside the Operator’s reasonable control.

37.3. The limitations of liability, disclaimers, indemnities, governing law, jurisdiction, and dispute provisions in the Terms of Use apply to privacy-related matters to the maximum extent permitted by law.

38. DATA BREACHES AND INCIDENTS

38.1. The Operator may investigate suspected data security incidents involving Personal Data.

38.2. If the Operator determines that notification is required by applicable law, the Operator will notify affected Users, regulators, or other parties as required.

38.3. The timing, content, and recipients of notifications may depend on legal requirements, investigation needs, law enforcement instructions, risk assessment, available information, and technical feasibility.

38.4. The Operator may delay or limit notification where permitted by law, including where notification would interfere with investigation, increase risk, violate law, reveal security measures, or harm the rights of others.

38.5. The Operator may maintain incident records as required or permitted by law.

39. CHANGES TO THIS PRIVACY POLICY

39.1. The Operator may modify this Privacy Policy at any time.

39.2. Changes may be made to reflect new features, AI tools, templates, payment methods, providers, legal requirements, security practices, business operations, or other developments.

39.3. The Operator may notify Users of material changes by posting the revised Privacy Policy, updating the “Last Updated” date, sending an email, displaying an in-product notice, or using another reasonable method.

39.4. Continued use of the Service after changes become effective constitutes acknowledgement of the revised Privacy Policy.

39.5. The User should review this Privacy Policy periodically.

40. GOVERNING LAW AND DISPUTES

40.1. This Privacy Policy and privacy-related disputes arising out of or related to the Service shall be governed by the laws of Georgia, the country, without regard to conflict-of-law rules, except where mandatory law provides otherwise.

40.2. Subject to mandatory law that cannot be waived, the courts of Georgia, the country, shall have exclusive jurisdiction over privacy-related disputes arising out of or related to the Service, this Privacy Policy, Personal Data, User Content, Documents, AI Features, or payments.

40.3. Before initiating legal proceedings, the User should contact the Operator through the contact email displayed on the website and provide a detailed description of the privacy concern, requested remedy, account email, and supporting information.

40.4. The Operator may seek urgent injunctive relief, equitable relief, security protection, payment protection, intellectual property protection, or legal enforcement in any court of competent jurisdiction.

41. CONTACT INFORMATION

41.1. Privacy questions, requests, complaints, and concerns may be sent to the contact email displayed on the WebLegal.net website.

41.2. The current contact email displayed on the website may be used for privacy-related communications unless the Operator provides a separate privacy contact method.

41.3. The Operator may require verification of identity, account ownership, authority, payment relationship, or data relationship before responding.

41.4. The Operator may be unable to respond to requests that do not provide sufficient information to identify the User, Account, data, document, payment, or issue.

41.5. The Operator’s response to a privacy request does not constitute legal advice, tax advice, accounting advice, admission of liability, waiver of rights, or professional service.

42. LANGUAGE

42.1. This Privacy Policy is provided in English.

42.2. The English version is the authoritative version.

42.3. Any translation is provided for convenience only. In the event of conflict between the English version and any translation, the English version controls to the maximum extent permitted by law.

43. ADDITIONAL DISCLOSURE TABLE

43.1. The following table summarizes common categories of Personal Data, purposes, and possible recipients. It is illustrative and does not limit the broader provisions of this Privacy Policy.

Category: Account and registration data.
Examples: name, email, password hash, account ID, login status, plan status.
Purposes: account creation, authentication, service access, security, support, legal compliance.
Recipients: hosting providers, authentication systems, email providers, support providers, security providers.

Category: Document and template data.
Examples: selected templates, selected terms, completed fields, generated documents, drafts, custom clauses.
Purposes: document generation, document management, download, storage, editing, support, security.
Recipients: hosting providers, storage providers, file conversion providers, AI providers where AI features are used.

Category: Uploaded file data.
Examples: contracts, PDFs, DOCX files, images, TXT files, attachments, extracted text.
Purposes: AI contract review, OCR, risk reports, suggested corrections, marked-up documents, file processing.
Recipients: cloud providers, AI providers, OCR providers, file conversion providers, security providers.

Category: AI interaction data.
Examples: prompts, legal questions, chat messages, AI outputs, risk reports, usage counts.
Purposes: AI chat, clause generation, contract review, safety, debugging, improvement, abuse prevention.
Recipients: AI providers, cloud providers, logging providers, security providers, support providers.

Category: Party and counterparty data.
Examples: names, addresses, emails, phone numbers, entity names, signatory details.
Purposes: document generation, reuse, counterparty management, negotiation, approval links.
Recipients: hosting providers, Team Administrators, Counterparties, email providers, cloud providers.

Category: Team data.
Examples: team members, administrators, permissions, invitations, activity.
Purposes: team access, workspace management, permissions, billing, support.
Recipients: hosting providers, Team Administrators, Team Members, email providers, support providers.

Category: Payment and commercial data.
Examples: plan, subscription status, amount, currency, transaction ID, invoice metadata.
Purposes: purchases, subscriptions, billing, refunds, taxes, chargebacks, fraud prevention.
Recipients: payment processors, accounting providers, tax advisers, fraud prevention providers, professional advisers.

Category: Technical and device data.
Examples: IP address, browser, device, logs, cookies, session IDs, error logs.
Purposes: security, analytics, performance, fraud prevention, troubleshooting, service operation.
Recipients: hosting providers, analytics providers, security providers, logging providers.

Category: Marketing and analytics data.
Examples: email preferences, campaign activity, pages viewed, referral source, cookie identifiers.
Purposes: marketing, analytics, conversion measurement, product improvement.
Recipients: analytics providers, email providers, marketing providers, cookie technology providers.

Category: Support and feedback data.
Examples: emails, support messages, screenshots, bug reports, feature requests.
Purposes: support, troubleshooting, quality improvement, legal records.
Recipients: support providers, email providers, hosting providers, professional advisers where necessary.

Category: Legal and compliance data.
Examples: legal requests, complaints, abuse reports, sanctions signals, dispute records.
Purposes: compliance, enforcement, legal claims, fraud prevention, security.
Recipients: courts, authorities, professional advisers, payment processors, security providers, hosting providers.

44. ADDITIONAL COOKIE DISCLOSURE

44.1. The Operator may use the following categories of cookies and similar technologies.

44.2. Strictly necessary technologies support login, security, authentication, account access, subscription access, payment flow, cookie consent, document generation, and core website operation.

44.3. Preference technologies remember settings, language, interface preferences, dismissed banners, and similar user choices.

44.4. Analytics technologies help the Operator understand visits, usage, performance, errors, conversion, and feature effectiveness.

44.5. Marketing technologies, if used, help measure advertising campaigns, referrals, promotions, and user interest.

44.6. Security technologies help detect fraud, prevent abuse, protect accounts, prevent automated attacks, and maintain service integrity.

44.7. Third-party technologies may be provided by analytics, hosting, payment, security, email, marketing, and AI-related providers.

44.8. Users can manage many cookies through browser settings. Some browser settings may not affect server-side logs, essential cookies, or third-party technologies already set.

45. FINAL ACKNOWLEDGMENT

45.1. By using the Service, the User acknowledges that:

(a) the Operator may process Personal Data as described in this Privacy Policy;

(b) the Service includes document generation, document management, AI chat, AI clause drafting, AI contract review, uploaded file processing, counterparty sharing, team access, payments, cookies, analytics, and support features;

(c) User Content may contain Personal Data and Sensitive Data;

(d) the User is responsible for ensuring that User Content and third-party Personal Data are submitted lawfully;

(e) AI Features may process prompts, uploaded files, documents, and other User Content;

(f) the Operator may use third-party providers to provide, secure, process, analyze, host, and improve the Service;

(g) Personal Data may be transferred internationally;

(h) no online service can guarantee absolute security;

(i) the User has read and understood this Privacy Policy.

By continuing to use the site you agree to the use of cookies. Read more in the Privacy Policy.