Privacy Policy
Last updated 7 June 2026 — draft, pending solicitor review
This Privacy Policy explains how Copacetic Legal Technologies Ltd ("Copacetic Legal Technologies", "we", "us") collects, uses, shares and protects personal data in connection with Copacetic. Your firm is the data controller for personal data within your workspace's Customer Data; Copacetic Legal Technologies is the data processor for that data, and the controller for account, billing and marketing data. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Copacetic Legal Technologies Ltd is a company registered in England and Wales (No. 14820019), with its registered office in Sunderland, Tyne and Wear. Contact us at privacy@copacetic.legal.
Data Protection Officer: Andrew Boyles is the designated point of contact for data protection matters. Direct any data protection query to privacy@copacetic.legal, marked for the attention of the Data Protection Officer.
ICO registration: pending — this section will be updated with our registration number once complete.
2. The personal data we collect
Account data: your name, email address and authentication metadata, managed via Supabase Auth.
Billing data: billing name, address and payment method, processed by Stripe; we do not store full card numbers.
Workspace data: matters, tasks, calendar entries, time entries, documents, team messages and Lutey conversation logs that your firm creates.
Providing your name, email address and (for password sign-in) a password is required to create an account — without it we cannot provide the Service to you. Providing further profile information is optional.
If a colleague at your firm invites you to join a workspace, they provide your name and email address to send that invitation before you interact with us directly — we process this solely to deliver the invitation and set up your account if you accept it.
3. How and why we use your data (lawful bases)
To provide the Service and perform our contract with you (Article 6(1)(b)): creating your account, delivering features, processing payments and providing support.
For our legitimate interests (Article 6(1)(f)): securing and improving the Service and preventing fraud and abuse — balanced against your rights.
With your consent (Article 6(1)(a)): optional marketing communications and, where introduced, optional analytics.
4. Lutey — AI processing
Lutey processes workspace metadata (task names, calendar entries, matter metadata) and the messages you send it to provide workload suggestions and administrative assistance. No client-confidential document content is sent to the AI model unless you explicitly include it in a message to Lutey.
Lutey is powered by the Google Gemini API, under contractual terms barring Google from training its models on data submitted via the API. See our Lutey DPIA for a full risk assessment of this processing.
Lutey does not make solely automated decisions that produce legal or similarly significant effects about you. Any action that would change data in your workspace always requires your explicit confirmation before it happens — Lutey proposes, a human decides.
5. Sharing your data
We share personal data only with sub-processors who help us deliver the Service, under written contracts requiring equivalent protection: Supabase (database and authentication, London), Cloudflare (document storage, EU), Stripe (billing), Resend (email), Google Gemini API (Lutey AI processing), Vercel (hosting) and Sentry (error monitoring). See our published sub-processor list for full detail.
We do not sell personal data, and we do not use Customer Data to train third-party AI models.
6. International transfers
Customer Data is stored in the UK/EU (Supabase London; Cloudflare R2 EU). Some processing involves data transiting or being processed outside the UK/EU, using the following safeguards per recipient: Google Gemini API (UK International Data Transfer Addendum / Standard Contractual Clauses), Stripe (Standard Contractual Clauses), Resend (Standard Contractual Clauses), and Sentry (Standard Contractual Clauses). See our published sub-processor list for the current, authoritative detail.
7. Data retention
Account data is retained while your account is active. Team messages and Lutey conversation logs are retained for 101 days by default, or 1 year with the extended retention add-on. Audit logs are retained for 7 years, reflecting regulatory record-keeping expectations for legal practices. Customer Data is retained for the life of the workspace and deleted within 30 days of cancellation, unless deleted sooner or law requires otherwise.
8. Security
We apply encryption in transit (TLS 1.2+) and at rest (AES-256), Row Level Security (RLS) enforcing workspace isolation at the database layer, API rate limiting, and comprehensive audit logging. Authentication is provided by Supabase Auth.
9. Your rights
Under the UK GDPR you have the right to access, rectify, erase, restrict processing, object to processing, data portability, and to withdraw consent. Where we process Customer Data as a processor, requests should generally be directed to your firm (the controller); you may also contact us at privacy@copacetic.legal and we will route your request appropriately.
To exercise your rights, email privacy@copacetic.legal. We aim to respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
10. Cookies
We use strictly necessary cookies to operate the Service and, with your consent, optional functional and analytics cookies as they are introduced. See our Cookie Policy for details.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or in-product notice. The "last updated" date above shows when this version took effect.
To exercise your rights or ask a question, Contact our Data Protection Officer at privacy@copacetic.legal.
