CaseFlow Automation Ltd ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the LegalDocs Assist software service (the "Service").
CaseFlow Automation Ltd is the data controller for personal data relating to your user account and your use of the Service. For any personal data about your own customers or claimants that you choose to process through the Service, you remain the data controller and we act as your data processor in line with our contract and data processing terms.
We are registered with the Information Commissioner's Office (ICO) under registration number ZC013423.
We may collect personal information that you voluntarily provide when using our Service, including:
Before user inputs are transmitted to external AI providers, they are processed by an automated PII masking gateway that detects and replaces common personal identifiers. This gateway acts as the primary safeguard for data hygiene. As additional good practice, we encourage you to avoid entering unnecessary personal data about third parties where practical, but manual redaction is not required as a precondition for using the Service.
We automatically collect certain information when you access the Service, including:
Where you upload a text‑based PDF within the Service, the document is read in your browser and only the extracted text is transmitted to our backend, both for the drafting tools and for the Witness Statement document slots. Word and plain‑text documents submitted to the document slots are reduced to text on the server and masked before any AI processing. That extracted text is deleted shortly after the tool finishes (see Section 5). Three documented exceptions apply where an original file does reach the server: (i) scanned or image‑only documents, briefly processed so the text can be read at all; (ii) photographs submitted to the document slots, which the AI reads directly because there is no text to mask first; and (iii) the medical‑bundle pagination tool, which processes the uploaded PDF on our servers to assemble the paginated bundle and then deletes it within approximately one hour of completion. All exception paths run under Zero Data Retention terms, prompts and outputs are not stored by the AI provider, and the platform's automated deletion controls apply.
An automated PII masking gateway processes all text before it reaches external AI providers, detecting and replacing common personal identifiers as a built‑in safeguard. While we encourage good data hygiene practices, manual redaction is not a prerequisite for using the Service.
The Service is routinely used to process special‑category health data such as medical records, injury detail and treatment history. This is expected and necessary for clinical‑negligence and personal‑injury work. The safeguards that apply are: browser‑side processing of source documents so the original file stays on the user's device, mandatory server‑side PII masking before any text reaches the AI, encryption in transit and at rest, and immediate deletion of source text and generated output within 24 hours. As data controller, your firm is responsible for the Article 9 lawful basis on which it processes that data; we act as processor on your instructions.
We use the information we collect for the following purposes and lawful bases under UK GDPR:
We do not use your data to train AI models. The AI provider operates under the Lovable AI Gateway's Zero Data Retention terms, in force since March 2026: your prompts and the model's responses are not retained by the provider and are not used to train any model.
Before any text is sent to the AI model, it passes through a mandatory server‑side masking gateway with no bypass. Structured personal data is replaced with neutral placeholders: email addresses, phone numbers, vehicle registration marks, residential addresses, sort codes and bank account numbers, IBANs, payment card numbers, National Insurance numbers, NHS numbers, HMRC tax identifiers (Unique Taxpayer References and PAYE references), driving licence numbers, dates of birth, and policy, claim and file references.
UK postcodes are not masked. A postcode is a non‑unique geographical identifier shared by many households, and it is material to the locality arguments the tools support. A separate output‑side check prevents the model introducing any postcode that did not appear in your input. This is an integrity guard, not a privacy one, and it is described as such.
Party names in the Witness Statement Generator. In the Witness Statement Generator, the party names you enter on the form (claimant, defendant, witnesses) are passed to the model so the statement attributes evidence to the correct person. In the analysis tools, titled and labelled names are masked like any other identifier.
We do not sell your personal information. We may share your information with:
If any service providers are located outside the UK or EEA, we will ensure that appropriate safeguards are in place for international data transfers (such as standard contractual clauses or equivalent measures).
We implement appropriate technical and organisational measures to protect your personal information, including:
No method of transmission or storage is completely secure, but we work to maintain security in line with industry standards and legal requirements.
CaseFlow Automation holds Cyber Essentials certification with whole organisation scope. Our security and compliance statement sets out the certificate details and how to verify them.
LegalDocs Assist is designed not to retain personal case data. Uploaded source documents and the outputs the tool generates (witness statements, paginated bundles, chronologies, timelines, advice and correspondence) are deleted shortly after they are produced or on session close, and a scheduled purge runs continuously as a backstop so case content is never retained beyond 24 hours. Firms are expected to download or save their own copy of any output they need, and to re‑run the tool if they need it again. Medical‑bundle pagination files are deleted within roughly one hour of completion, on a fifteen‑minute cleanup cycle. Inactive login sessions expire automatically. Activity and audit logs are retained as described elsewhere in this policy.
Recovery drafts on your device. Nothing is kept on our servers beyond 24 hours. So that a crashed tab or a closed window does not cost a fee earner her work, the platform keeps a recovery draft of typed and confirmed details in the user's own browser storage for up to 48 hours, then deletes it. Uploaded documents are never stored in the browser, so a restored draft asks the user to drop the files again. Signing out clears every recovery draft immediately.
Backups. Uploaded files are never included in any backup. The database has standard disaster‑recovery backups, but because case content is deleted within 24 hours those backups hold essentially no personal case data, and once a record is deleted there is nothing to restore it from.
On termination. On contract termination your firm's tenant is archived immediately. The archive remains reversible for thirty (30) days as a grace period, during that window the tenant can be reinstated if termination is rescinded or if the firm needs a final extract. At the end of that window, and in any event within thirty (30) days of termination, the tenant is permanently erased from the archived list as a second gate (see Deletion and erasure below). This is a contractual commitment honoured operationally by CaseFlow Automation Ltd platform administrators, not an automated platform feature; firms cannot self-delete a tenant. Minimal account and billing records required for accounting and limitation purposes are retained for the statutory period and then deleted.
Deletion on the platform is immediate and permanent. When a record or document is deleted it is removed from the live database and, where it has associated files, from storage. Deleted storage objects are not held in any backup and cannot be restored.
Account deletion. An individual user account can be deleted on request. The user's profile and account data are removed. Case content created under your firm remains under your firm's control until your firm deletes it or the contract ends.
Firm‑level erasure. On contract termination, or on a verified erasure request, we permanently delete your firm's tenant: all case content, witness statements, chronologies, correspondence, generated documents and the associated storage objects, together with the user accounts. The action runs only via a hardened admin path executed by CaseFlow Automation Ltd platform administrators, firms cannot self-delete, and requires the tenant to be archived first as a reversible step, then permanently deleted from the archived list as a second gate. Where erasure is triggered by contract termination it is completed within thirty (30) days. It is recorded in a deletion audit log that holds only the fact of deletion, who performed it, when, and the counts, never the deleted content itself. The only data retained is the minimal account and billing record required by law, and the Data Processing Agreement audit history, both stripped of unnecessary personal data. This is a contractual commitment honoured operationally, not an automated platform feature.
Under UK GDPR you have the rights of access, rectification, erasure, restriction, portability and objection.
For personal data about your firm's own clients and claimants, your firm is the data controller and CaseFlow Automation Ltd is the data processor. Data subject requests relating to that data are handled by your firm; we support you in fulfilling them, including by deleting or exporting the relevant records on your instruction.
For the account data we hold as controller (user credentials, usage logs), you can exercise these rights directly by contacting us. You also have the right to complain to the Information Commissioner's Office.
To exercise any of these rights, please contact us at info@caseflowautomation.co.uk. You also have the right to lodge a complaint with the ICO at www.ico.org.uk.
We use essential cookies to ensure the proper functioning of the Service, for example to keep you signed in and secure your session. These cookies are necessary for authentication and security purposes and cannot be switched off in our systems.
We do not currently use cookies for advertising purposes. If we introduce analytics or other non‑essential cookies in future, we will update this policy and, where required, request your consent.
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and update the "Last updated" date above. If we make material changes, we may also notify you by email or through the Service.
If you have any questions about this Privacy Policy or our data practices, please contact us:
CaseFlow Automation Ltd
7–9 Macon Court, Crewe, CW1 6EA
United Kingdom
ICO Registration: ZC013423