LegalWise

Privacy policy

Effective from 07.10.2026

1. Controller

ESTERN TECH OÜ, registry code 17478852 (Estonian Commercial Register), Visase tn 12, 11415 Tallinn, Estonia, e-mail maikovernest@gmail.com. For data protection questions write to the same address.

2. What data we process

  • Account: e-mail address, password hash (we never know the password), interface language, plan and its validity, promo codes used, time of sign-up and of accepting the terms.
  • Questions and answers: your questions, the answers, the legal sources cited and your feedback on answers.
  • Documents: the text of an uploaded document and the review report; drafted documents and the details entered for them; research memos (the question, the facts and the memo).
  • Notes and team: your notes on provisions and whether a note is shared with your team; the team name, its members and their roles; the e-mail addresses of people invited to the team.
  • Usage: number of questions and documents per month (for plan limits), the computing cost of answers per month (for the fair-use limit), laws you follow.
  • Technical data: the login and language cookies. We do not store IP addresses — they are used only briefly in memory to limit abuse.

3. Purposes and legal bases

  • Providing the service, managing your account and law-change alerts — contract (GDPR art. 6(1)(b)).
  • Security and abuse prevention — legitimate interest (art. 6(1)(f)).
  • Billing and bookkeeping for paid plans — legal obligation (art. 6(1)(c)).
  • Improving quality based on your feedback — legitimate interest (art. 6(1)(f)).

We do not use your data for advertising, do not sell it, do not profile you and do not use your questions or documents to train language models.

4. How an answer is produced and who receives data

The law database, search and all account data are on our own server in Estonia. To write an answer, your question (with the earlier part of the same chat) and the retrieved legal provisions (and, for document review, drafting or a research memo, the document text, the details entered or the facts) are sent to a processor. Before sending, personal codes, e-mail addresses, phone numbers, bank accounts and card numbers are replaced with placeholders (pseudonymisation); the originals are put back only on our server. Names, addresses and other data are not replaced — do not include personal data the answer does not need. Processors:

  • Anthropic Ireland, Limited / Anthropic, PBC — writing answers, reports and document drafts. Data is not used to train models.
  • Cloudflare, Inc. — encrypted delivery of web traffic to our server and attack protection; for this Cloudflare also processes your IP address.
  • E-mail delivery provider (currently Google, Gmail) — confirmation, password reset and alert e-mails.
  • Payment provider — online payments for the paid plan, once introduced (we never see or store card details).

Anthropic, Cloudflare and Google may process data outside the European Economic Area (in the USA); such transfers rely on the European Commission's standard contractual clauses (GDPR art. 46) or the EU–US Data Privacy Framework (GDPR art. 45).

If you are in a team, the other members see your e-mail address and the notes you share with the team (with author and date). Only you see your private notes. The team owner sees pending invitations. We send the invitation to the invited person by e-mail; only the owner of that address can accept it, after confirming it.

5. Retention

  • Account, questions and answers, drafted documents and research memos — until you delete them or the account (Settings → Privacy and data).
  • Notes — until you delete them or the account. When you leave a team (or the owner removes you), your shared notes become private again; deleting the account deletes all your notes, shared ones included. If the team owner deletes their account, the longest-standing member becomes the owner. Invitations not accepted are deleted after 30 days.
  • The text of an uploaded document (and, for a Word file, the file itself, so the copy with comments keeps its original formatting) is deleted automatically after 30 days; the review report is kept until you delete it.
  • Login sessions expire after 30 days, password reset links after 1 hour. An account whose e-mail is not confirmed within 7 days is deleted.
  • Database backups are deleted automatically after 7 days; until then they may still contain data you have deleted.
  • Accounting source documents (invoices) are kept for 7 years from the end of the financial year, as required by law (Accounting Act § 12).

6. Your rights

You have the right to access, rectify and erase your data, restrict its processing, receive it in a machine-readable form and object (GDPR arts. 15–21). Download and deletion are one click in Settings. You may complain to the Estonian Data Protection Inspectorate (www.aki.ee).

7. Automated answers

Answers and reports are produced automatically (with artificial intelligence) and checked against the sources before they are shown. They are general legal information: no automated decisions with legal effect are taken about you (GDPR art. 22).

8. Cookies

We use only strictly necessary cookies — see the cookie policy.

9. Changes

We announce material changes by e-mail and on the website.