CaseFlow Automation Ltd

Privacy Policy

Last updated: 24 July 2026

CaseFlow Automation Ltd ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the LegalDocs Assist software service (the "Service").

CaseFlow Automation Ltd is the data controller for personal data relating to your user account and your use of the Service. For any personal data about your own customers or claimants that you choose to process through the Service, you remain the data controller and we act as your data processor in line with our contract and data processing terms.

We are registered with the Information Commissioner's Office (ICO) under registration number ZC013423.

1. Information We Collect

Personal information you provide

We may collect personal information that you voluntarily provide when using our Service, including:

  • Name and email address
  • Company name and business contact details
  • Account credentials and profile information
  • Content you submit through the Service (prompts, case details, correspondence text, and generated letters you choose to save)

Before user inputs are transmitted to external AI providers, they are processed by an automated PII masking gateway that detects and replaces common personal identifiers. This gateway acts as the primary safeguard for data hygiene. As additional good practice, we encourage you to avoid entering unnecessary personal data about third parties where practical, but manual redaction is not required as a precondition for using the Service.

Usage data

We automatically collect certain information when you access the Service, including:

  • IP address and browser type
  • Pages visited and features used
  • Date and time of access
  • Device and technical information
  • Log data relating to security and performance of the Service

Documents and PDFs

Where you upload a text‑based PDF within the Service, the document is read in your browser and only the extracted text is transmitted to our backend, both for the drafting tools and for the Witness Statement document slots. Word and plain‑text documents submitted to the document slots are reduced to text on the server and masked before any AI processing. That extracted text is deleted shortly after the tool finishes (see Section 5). Three documented exceptions apply where an original file does reach the server: (i) scanned or image‑only documents, briefly processed so the text can be read at all; (ii) photographs submitted to the document slots, which the AI reads directly because there is no text to mask first; and (iii) the medical‑bundle pagination tool, which processes the uploaded PDF on our servers to assemble the paginated bundle and then deletes it within approximately one hour of completion. All exception paths run under Zero Data Retention terms, prompts and outputs are not stored by the AI provider, and the platform's automated deletion controls apply.

An automated PII masking gateway processes all text before it reaches external AI providers, detecting and replacing common personal identifiers as a built‑in safeguard. While we encourage good data hygiene practices, manual redaction is not a prerequisite for using the Service.

Special category (health) data

The Service is routinely used to process special‑category health data such as medical records, injury detail and treatment history. This is expected and necessary for clinical‑negligence and personal‑injury work. The safeguards that apply are: browser‑side processing of source documents so the original file stays on the user's device, mandatory server‑side PII masking before any text reaches the AI, encryption in transit and at rest, and immediate deletion of source text and generated output within 24 hours. As data controller, your firm is responsible for the Article 9 lawful basis on which it processes that data; we act as processor on your instructions.

2. How We Use Your Information

We use the information we collect for the following purposes and lawful bases under UK GDPR:

  • To provide, operate, and maintain the Service, including AI‑assisted drafting and document generation (performance of a contract).
  • To manage your account, billing, and customer support (performance of a contract / legitimate interests).
  • To improve and personalise your experience, including troubleshooting, analytics, and feature development (legitimate interests).
  • To communicate with you about updates, security alerts, and administrative matters (performance of a contract / legitimate interests).
  • To ensure security, prevent fraud and misuse, and protect our rights and those of other users (legitimate interests / legal obligations).
  • To comply with legal and regulatory obligations, including responding to lawful requests from authorities (legal obligation).

We do not use your data to train AI models. The AI provider operates under the Lovable AI Gateway's Zero Data Retention terms, in force since March 2026: your prompts and the model's responses are not retained by the provider and are not used to train any model.

Before any text is sent to the AI model, it passes through a mandatory server‑side masking gateway with no bypass. Structured personal data is replaced with neutral placeholders: email addresses, phone numbers, vehicle registration marks, residential addresses, sort codes and bank account numbers, IBANs, payment card numbers, National Insurance numbers, NHS numbers, HMRC tax identifiers (Unique Taxpayer References and PAYE references), driving licence numbers, dates of birth, and policy, claim and file references.

UK postcodes are not masked. A postcode is a non‑unique geographical identifier shared by many households, and it is material to the locality arguments the tools support. A separate output‑side check prevents the model introducing any postcode that did not appear in your input. This is an integrity guard, not a privacy one, and it is described as such.

Party names in the Witness Statement Generator. In the Witness Statement Generator, the party names you enter on the form (claimant, defendant, witnesses) are passed to the model so the statement attributes evidence to the correct person. In the analysis tools, titled and labelled names are masked like any other identifier.

3. Data Sharing and Disclosure

We do not sell your personal information. We may share your information with:

  • Service providers and sub‑processors: Third parties that help us operate the Service (hosting, database, AI model providers, monitoring, analytics, and email providers). These parties are only allowed to process personal data on our instructions and under appropriate data protection terms.
  • Legal and regulatory requirements: Where required to do so by law or in response to valid legal processes, or to protect our rights, property, or safety or that of others.
  • Business transfers: In connection with a merger, acquisition, or sale of all or part of our business, subject to appropriate safeguards.

If any service providers are located outside the UK or EEA, we will ensure that appropriate safeguards are in place for international data transfers (such as standard contractual clauses or equivalent measures).

4. Data Security

We implement appropriate technical and organisational measures to protect your personal information, including:

  • Encryption of data in transit and at rest
  • Logical separation and row‑level security to isolate each customer's data
  • Access controls, authentication measures, and least‑privilege access
  • Regular security assessments and monitoring

No method of transmission or storage is completely secure, but we work to maintain security in line with industry standards and legal requirements.

CaseFlow Automation holds Cyber Essentials certification with whole organisation scope. Our security and compliance statement sets out the certificate details and how to verify them.

5. Data Retention

LegalDocs Assist is designed not to retain personal case data. Uploaded source documents and the outputs the tool generates (witness statements, paginated bundles, chronologies, timelines, advice and correspondence) are deleted shortly after they are produced or on session close, and a scheduled purge runs continuously as a backstop so case content is never retained beyond 24 hours. Firms are expected to download or save their own copy of any output they need, and to re‑run the tool if they need it again. Medical‑bundle pagination files are deleted within roughly one hour of completion, on a fifteen‑minute cleanup cycle. Inactive login sessions expire automatically. Activity and audit logs are retained as described elsewhere in this policy.

Recovery drafts on your device. Nothing is kept on our servers beyond 24 hours. So that a crashed tab or a closed window does not cost a fee earner her work, the platform keeps a recovery draft of typed and confirmed details in the user's own browser storage for up to 48 hours, then deletes it. Uploaded documents are never stored in the browser, so a restored draft asks the user to drop the files again. Signing out clears every recovery draft immediately.

Backups. Uploaded files are never included in any backup. The database has standard disaster‑recovery backups, but because case content is deleted within 24 hours those backups hold essentially no personal case data, and once a record is deleted there is nothing to restore it from.

On termination. On contract termination your firm's tenant is archived immediately. The archive remains reversible for thirty (30) days as a grace period, during that window the tenant can be reinstated if termination is rescinded or if the firm needs a final extract. At the end of that window, and in any event within thirty (30) days of termination, the tenant is permanently erased from the archived list as a second gate (see Deletion and erasure below). This is a contractual commitment honoured operationally by CaseFlow Automation Ltd platform administrators, not an automated platform feature; firms cannot self-delete a tenant. Minimal account and billing records required for accounting and limitation purposes are retained for the statutory period and then deleted.

Deletion and erasure

Deletion on the platform is immediate and permanent. When a record or document is deleted it is removed from the live database and, where it has associated files, from storage. Deleted storage objects are not held in any backup and cannot be restored.

Account deletion. An individual user account can be deleted on request. The user's profile and account data are removed. Case content created under your firm remains under your firm's control until your firm deletes it or the contract ends.

Firm‑level erasure. On contract termination, or on a verified erasure request, we permanently delete your firm's tenant: all case content, witness statements, chronologies, correspondence, generated documents and the associated storage objects, together with the user accounts. The action runs only via a hardened admin path executed by CaseFlow Automation Ltd platform administrators, firms cannot self-delete, and requires the tenant to be archived first as a reversible step, then permanently deleted from the archived list as a second gate. Where erasure is triggered by contract termination it is completed within thirty (30) days. It is recorded in a deletion audit log that holds only the fact of deletion, who performed it, when, and the counts, never the deleted content itself. The only data retained is the minimal account and billing record required by law, and the Data Processing Agreement audit history, both stripped of unnecessary personal data. This is a contractual commitment honoured operationally, not an automated platform feature.

6. Your Rights (UK GDPR)

Under UK GDPR you have the rights of access, rectification, erasure, restriction, portability and objection.

For personal data about your firm's own clients and claimants, your firm is the data controller and CaseFlow Automation Ltd is the data processor. Data subject requests relating to that data are handled by your firm; we support you in fulfilling them, including by deleting or exporting the relevant records on your instruction.

For the account data we hold as controller (user credentials, usage logs), you can exercise these rights directly by contacting us. You also have the right to complain to the Information Commissioner's Office.

To exercise any of these rights, please contact us at info@caseflowautomation.co.uk. You also have the right to lodge a complaint with the ICO at www.ico.org.uk.

7. Cookies

We use essential cookies to ensure the proper functioning of the Service, for example to keep you signed in and secure your session. These cookies are necessary for authentication and security purposes and cannot be switched off in our systems.

We do not currently use cookies for advertising purposes. If we introduce analytics or other non‑essential cookies in future, we will update this policy and, where required, request your consent.

8. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and update the "Last updated" date above. If we make material changes, we may also notify you by email or through the Service.

9. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

CaseFlow Automation Ltd

7–9 Macon Court, Crewe, CW1 6EA

United Kingdom

info@caseflowautomation.co.uk

ICO Registration: ZC013423

CaseFlow Automation Ltd - Legal Processes. Streamlined.
See also: How We Protect Your Data | AI Safety & Security Policy | Plain English Guide | ← Back to Home