Privacy Policy
Last updated: January 2026
1. Introduction
YR Legal Services Ltd (trading as Lexona.AI) ("we", "our", "us") is committed to protecting your privacy and ensuring the security of your personal data. This comprehensive Privacy Policy explains how we collect, process, store, and safeguard your information when you visit our website (lexona.ai), use our AI-powered legal software platform, or interact with our services.
As a provider of legal technology services, we adhere to stringent data protection standards, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable global privacy frameworks. YR Legal Services Ltd is a company registered in England and Wales under company number 16885532, acting as the Data Controller for personal data concerning our own customers, and as a Data Processor for personal data uploaded by legal practices, including sole practitioners, using our platform.
2. Information We Collect
We collect several categories of information to provide and improve our services:
2.1 Information You Provide to Us
- Account Information: Name, professional email address, phone number, legal practice name, job title, and authentication credentials.
- Financial Information: Billing address, payment details (processed securely via our payment gateways, e.g., Stripe), and subscription history.
- Communications Data: Information you provide when contacting customer support, submitting feedback, or participating in webinars and surveys.
2.2 Information Automatically Collected
- Device and Usage Data: IP addresses, browser types, operating systems, referring URLs, pages viewed, API calls, and interaction metrics.
- Cookies and Tracking Technologies: Information gathered via cookies, web beacons, and similar tracking technologies to analyse trends and administer the platform (see Section 11 regarding Cookies).
- Security Logs: Authentication attempts, access logs, and anomaly detection data to ensure platform security.
2.3 Client and Matter Data (Processor Role)
In the context of providing our core AI services to legal practices (including sole practitioners and practices), we process highly sensitive information, including case files, client identities (KYC/AML documents), financial records, and legal correspondence. For this data, Lexona acts solely as a Data Processor acting on the strict, documented instructions of the relevant legal practice (the Data Controller). We do not use this data for our own purposes, and we do not use it to train underlying foundational AI models.
3. How We Use Your Information (Legal Bases)
We process your personal data under the following lawful bases established by the UK GDPR:
| Purpose/Activity | Data Categories | Lawful Basis |
|---|---|---|
| Registering a new account | Account Info | Performance of a contract |
| Processing payments and billing | Financial, Account | Performance of a contract; Legal obligation |
| Providing core application features | Account, Usage, Client Data | Performance of a contract |
| Managing security, fraud prevention | Usage, Security Logs | Legitimate interests; Legal obligation |
| Improving platform via analytics | Usage Data | Legitimate interests |
| Marketing communications | Account, Usage | Consent or Legitimate interests |
4. Data Sharing and Disclosure
We strictly limit the sharing of your personal data. We do not sell, rent, or trade your personal information. We may share data under the following circumstances:
- Service Providers (Sub-processors): We use providers for UK core application compute (IONOS), database/authentication/document storage (Supabase), vector retrieval (Qdrant), model processing, public-site hosting (Vercel), email, and enabled integrations. The current subprocessor schedule and applicable locations are available for diligence.
- AI Model Providers: To deliver configured legal AI functions, data may be processed through API-based model providers such as OpenAI or Anthropic. Lexona only enables production model-provider accounts for customer client and matter data after the executed downstream agreement and account configuration prohibit training on customer content and require zero retention of client and matter prompts and outputs.
- Legal Compliance and Protection: We may disclose information if required to comply with a legal obligation, court order, or regulatory request (e.g., ICO, SRA requirements), or to protect our legal rights against fraud or security threats.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, data may be transferred subject to confidentiality agreements and notification to users.
5. Data Security and Confidentiality
Our current security controls and planned assurance work are documented in the Lexona security pack. Lexona is not currently certified to Cyber Essentials or ISO 27001 and has not completed a SOC 2 examination.
- Encryption: Public production services use HTTPS. At-rest and downstream transit protection are provided under the applicable provider architecture and agreement. Customer-managed keys and KMS/HSM options are subject to a future architecture review.
- Access Controls: We use role-based access control, explicit practice scoping, authenticated service boundaries, MFA capability, and database RLS as defence in depth. Production RLS activation is a deployment gate.
- Monitoring: Health checks, structured logs, correlation IDs, telemetry instrumentation, and operations alerts are implemented; live production delivery and alerting must be verified during deployment.
- Incident Response: We will notify an affected customer controller without undue delay after becoming aware of a personal data breach and support its assessment and regulatory obligations.
6. Data Retention Policies
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Account Data: Kept for the duration of the active subscription, plus a standard archiving period (usually 6-12 months) to facilitate account recovery or handle billing disputes.
- Client and Matter Data: Retained during the term of the agreement. Upon termination or specific request by the relevant legal practice, all associated matter data is securely deleted or anonymized within 30 days, unless longer retention is mandated by law (e.g., anti-money laundering regulations).
- Logs and Analytics: Security and audit logs are typically retained for 12 months for compliance purposes before being purged.
7. International Data Transfers
The core production application stack is selected for deployment on a UK-located IONOS VPS. Database, authentication, document, vector, model-provider, backup, support, and integration processing locations depend on the configured downstream services. For customer client and matter data, the customer legal practice is the Controller and YR Legal Services Ltd acts as Processor under Article 28 where applicable. Lexona acts separately as Controller for its own website leads, business contacts, billing administration, security administration, and legal obligations.
In circumstances where engaging a sub-processor necessitates transferring data outside the UK/EEA (e.g., to the United States for API-based LLM services), we ensure all such transfers are safeguarded by appropriate legal mechanisms: the UK International Data Transfer Agreement (IDTA) for transfers from the UK, and the European Commission's Standard Contractual Clauses (EU SCCs 2021/914) for transfers from the EEA, supplemented by the UK Addendum where required. Any transfer outside the UK is subject to an explicit contractual basis and appropriate safeguards. Copies of our DPA, IDTA, and EU SCCs are available on request.
8. Your Data Subject Rights
Depending on your location (such as if you reside in the UK, EU, or California), you possess significant rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data under certain conditions.
- Right to Restrict Processing: Request suspension of data processing in specific scenarios.
- Right to Data Portability: Receive your data in a structured, machine-readable format to transfer to another provider.
- Right to Object: Object to processing based on legitimate interests or direct marketing purposes.
- Automated Decision Making: The right not to be subject to a decision based solely on automated processing that produces legal effects. Lexona ensures human oversight (Human-in-the-Loop) is maintained for critical legal actions.
To exercise these rights, please contact our Data Protection Officer at privacy@lexona.ai. We will respond within 30 days. Legal practice clients handling data subject requests from their own end-clients can utilize platform administration tools to satisfy these requests.
9. Additional Notice for California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act provides specific rights regarding your personal information. We do not "sell" or "share" your personal information for cross-context behavioral advertising. You have the right to request access to the specific pieces of personal information we have collected, request deletion, and not face discrimination for exercising these rights. We act as a "Service Provider" when processing data on behalf of our business clients.
10. Children's Privacy
Our services are designed exclusively for business professionals and legal practices, including sole practitioners and practices. We do not knowingly collect personal data directly from children under the age of 18. If a parent or guardian becomes aware that a minor has provided us with personal information, they should contact us immediately.
11. Cookies and Tracking
Our website uses cookies to distinguish you from other users, providing a personalised and secure experience.
- Strictly Necessary Cookies: Essential for authentication, security, and session management.
- Performance and Analytics Cookies: Used to aggregate anonymous metrics on site usage to improve functionality.
- Functional Cookies: Remember your preferences (e.g., theme, language).
You can manage your cookie preferences at any time via your browser settings or our website's cookie consent banner. Please note that disabling necessary cookies may impede platform functionality.
12. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy periodically to reflect technological changes, new features, or evolving legal frameworks. We will notify you of material changes by posting the updated policy on our website and, where appropriate, sending an email notification to registered administrators. Continued use of the platform after updates signifies acceptance of the revised terms.
13. Contact Information and Complaints
If you have inquiries, concerns, or complaints regarding this Privacy Policy or our data handling practices, please contact our Data Protection Officer:
YR Legal Services Ltd
Email: privacy@lexona.ai
Company Registration: 16885532 (England and Wales)
DPO Contact: dpo@lexona.ai
You retain the right to lodge a formal complaint with the UK supervisory authority, the Information Commissioner's Office (ICO), at https://ico.org.uk/, or with your local data protection authority.