Version 1.2 Effective: 24 July 2026 UK GDPR · DPA 2018 · DUAA 2025

Data controller: Dogetlawyer AI Ltd, registered in England and Wales (company number 16719329) · 124–128 City Road, London EC1V 2NX, United Kingdom · support@dogetlawyer.com

At a glance. This page is the practical guide to your data rights on Dogetlawyer: what each right does, how to use it in two clicks from your dashboard → Privacy & Data Rights, exactly what gets deleted when you ask for erasure (and the short list of records the law makes us keep), and what the Data (Use and Access) Act 2025 changed — with the real in-force dates.
  1. The UK framework in one map
  2. What the DUAA 2025 changed — and when
  3. Your rights, one by one
  4. Subject access requests — how they work here
  5. Erasure — what we delete, what we must keep
  6. Automated decisions and AI
  7. Complaints — the statutory route
  8. Controller or processor — whose request is it?
  9. Your rights outside the UK — country sections
  10. Contact

1. The UK framework in one map

LawWhat it does
UK GDPRThe core rulebook: lawful bases, your rights (Articles 12–23), security, transfers, accountability
Data Protection Act 2018Fills in UK detail: conditions for sensitive data (Schedule 1), exemptions, ICO enforcement, court remedies (ss.167–169)
PECR 2003Cookies and electronic marketing — see the Cookies Policy
Data (Use and Access) Act 2025 ("DUAA")Amends all three — it did not replace them. Royal Assent 19 June 2025; commencement in phases (section 2)

The regulator is the Information Commissioner's Office (ICO). The DUAA provides for the ICO to be reconstituted as the "Information Commission"; until that change is commenced, the ICO continues under its current name.

2. What the DUAA 2025 changed — and when

Honest status as at 24 July 2026:

ChangeWhat it means for youStatus
Complaints to controllers (s.103)You have a statutory right to complain to us; we must make that easy (including electronically), acknowledge within 30 days, and respond without undue delayIn force 19 June 2026
Subject access requestsSearches must be "reasonable and proportionate"; the response clock can pause while we wait for clarification we genuinely needIn force 5 February 2026
Automated decision-making (new UK GDPR Articles 22A–22D)Significant decisions made solely by automation are allowed with safeguards (information, human review, the right to contest) — stricter rules remain for special category dataIn force 5 February 2026 — we make no such decisions (section 6)
Recognised legitimate interestsA fast-track lawful basis for a short list of public-interest purposesIn force 5 February 2026 — we do not use it
Purpose limitation examplesStatutory examples of when re-use of data is compatible with the original purposeIn force 5 February 2026
International transfers — "data protection test"Outcomes-based test: protection abroad must not be materially lower than the UK standardIn force 5 February 2026
PECR cookie exemptionsConsent exemptions for some statistical/appearance cookies — we stay opt-in anywayIn force 5 February 2026
PECR fines raisedCookie/marketing breaches now attract UK GDPR-level penalties (up to £17.5m / 4% of turnover)In force 5 February 2026
ICO → Information CommissionRegulator restructureNot yet commenced
Also relevant: the European Commission renewed both UK adequacy decisions on 19 December 2025 (to 27 December 2031) after reviewing the DUAA — personal data continues to flow freely between the EEA and the UK.

3. Your rights, one by one

RightUK GDPRWhat it doesFastest route
Be informedArts 13–14Know what happens to your data — that is the Privacy PolicyRead it; ask us anything unclear
AccessArt 15Get a copy of your personal data plus the key information about how it is usedPrivacy & Data Rights → Access request (section 4)
RectificationArt 16Correct inaccurate dataEdit your profile directly, or submit a request
ErasureArt 17"Right to be forgotten" — with legal-retention limitsSection 5 — the full honest breakdown
RestrictionArt 18Freeze processing while something is disputedSubmit a request
PortabilityArt 20Take your data elsewhere in machine-readable formExport documents from your dashboard; account data as CSV/JSON on request
ObjectArt 21Object to legitimate-interests processing; absolute for direct marketingUnsubscribe link, or submit a request
Withdraw consentArt 7(3)As easy as giving it"Privacy choices" for cookies; unsubscribe for email
Automated decisionsArts 22A–22DSafeguards for solely automated significant decisionsWe make none — section 6
ComplainDUAA s.103; Art 77To us, to the ICO, and to courtSection 7

Every request: free of charge (unless manifestly unfounded or excessive), answered within one month, extendable by up to two further months for complex or numerous requests — and if we extend, we tell you within the first month with reasons. We may need to verify your identity first; we ask only for what verification genuinely requires (UK GDPR Article 12).

4. Subject access requests — how they work here

  1. Submit via Privacy & Data Rights (or email support@dogetlawyer.com, subject "SAR"). Logged-in requests are already identity-verified; email requests may need verification.
  2. Scope. Tell us if you want everything or something specific (faster). Under the DUAA our search must be reasonable and proportionate — we search account records, your content, billing, support messages and logs; we do not have to trawl systems where your data could not plausibly be.
  3. Clock. One month from receipt (or from identity verification). If we genuinely need clarification, the clock pauses until you reply ("stop the clock", DUAA, in force 5 February 2026).
  4. What you get. A copy of your personal data plus: purposes, categories, recipients (the subprocessor list), retention, your rights, data sources, and whether any automated significant decisions apply (none do).
  5. Limits. We must not disclose other people's data with yours (DPA 2018 Schedule 2 balancing) — for example, the other side's details in a matter you typed in may be redacted from what identifies them rather than you.

5. Erasure — what we delete, what we must keep

When you ask for erasure (Article 17) — or simply close your account — this is exactly what happens:

Deleted

  • Your documents, uploads, chats, contract-register entries and stored files — individual deletions are removed from live systems within 30 days; on account closure you have a 30-day export window, after which content is deleted from live systems within 30 days (normally no later than 60 days after closure);
  • Your profile and account record;
  • Analytics identifiers we control (and Clarity data expires on Microsoft's schedule — replays ≈ 30 days);
  • Marketing preferences — replaced by a minimal suppression record so we don't contact you again.

Retained — what the law requires us to keep, and what it permits

RecordKept forWhy (legal basis)
Invoices, billing and tax records6 years from the end of the relevant financial yearRequired by law — UK tax and accounting law; Article 17(3)(b) (legal obligation)
Security and audit logsUp to 24 monthsPermitted — legitimate interests in fraud/abuse prevention and defence of legal claims (Articles 6(1)(f), 17(3)(e)); the length is kept under review against necessity
Consent, rights-request and complaint recordsUp to 6 yearsNeeded to demonstrate compliance — accountability (Article 5(2)): we must be able to prove we handled your rights correctly
Encrypted backupsExpire automatically within 90 days after live-system deletionPermitted — disaster recovery; deleted content is not restored from backups except during genuine disaster recovery, and is then re-deleted
Tele-legal verification records (professionals only)Listing period + 24 monthsPermitted — integrity of the directory; defence of claims (Article 17(3)(e))

Two further cases: content belonging to a business customer (where we act as processor) is deleted or returned on the controller's instructions under the Data Processing Addendum, not under this table; and if we are subject to a legal hold or a lawful preservation order, it overrides these periods for the specific records it covers, for as long as it lasts.

Why we say this out loud: a service that promises to "delete everything" is either breaking tax law or not telling the truth. We would rather show you the real list — separating what the law requires us to keep from what it permits us to keep. Everything retained is locked to its stated purpose and is never used for marketing or profiling.

6. Automated decisions and AI

  • Dogetlawyer's AI generates content you asked for (drafts, reviews, explanations). That is automated processing, not an automated decision about you.
  • We make no decision producing legal or similarly significant effects on you solely by automated means — not on pricing, access, eligibility or anything else. Account-suspension decisions (Terms section 15) involve a human.
  • If that ever changes, UK GDPR Articles 22A–22D (in force 5 February 2026) give you the rights to be informed, to obtain human intervention, to make representations and to contest the decision — and we would update this page and the Privacy Policy first.
  • AI outputs can be wrong; they are information, not advice — the full honesty statement is at How we use AI.

7. Complaints — the statutory route

  1. To us (statutory since 19 June 2026, DUAA s.103). Use Privacy & Data Rights or email support@dogetlawyer.com ("Privacy complaint"). We acknowledge within 30 days — usually much faster — investigate, and respond without undue delay with what we found and what we are doing about it.
  2. To the ICO — at any time (you do not have to wait for us): ico.org.uk/make-a-complaint · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
  3. To court. You have the right to an effective judicial remedy against us or the ICO, and to compensation for material or non-material damage caused by an infringement — UK GDPR Articles 78–82; DPA 2018 sections 166–169.

8. Controller or processor — whose request is it?

  • Your own data (your account, your questions, documents about your own matters): we are the controller — every right on this page is exercised directly with us.
  • Data inside a business customer's content (for example, you are an employee named in a contract that a firm uploaded): the firm is the controller and we are its processor. Send your request to the firm; if it reaches us first we will pass it on promptly and help the firm respond (UK GDPR Article 28(3)(e)) — we cannot lawfully answer it over the controller's head.

9. Your rights outside the UK — country sections

🇮🇪 Republic of Ireland and the EU/EEA

Your rights arise under the EU GDPR (Articles 12–23 — access, rectification, erasure, restriction, portability, objection, ADM safeguards under Article 22) and, in Ireland, the Data Protection Act 2018 (IE). Exercise them through exactly the same routes as sections 3–5. You may complain to the Data Protection Commission (dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2) or your local supervisory authority, and you have EU GDPR Articles 79/82 court and compensation rights. The DUAA does not reduce these — and EU→UK data flows rest on the renewed adequacy decisions (section 2).

🇺🇸 United States

State laws (California CCPA/CPRA, Virginia, Colorado, Connecticut, Texas and others) give rights to know/access, correct, delete, and port, plus opt-outs of "sale"/"sharing" (we do neither) — and an appeal if a request is refused. We honour the substance of these for all US users through the same routes as section 3, without discrimination. California's "verifiable consumer request" standard matches our identity checks; if we decline a request we explain why and you can reply to appeal to a human reviewer.

🇨🇦 Canada

Under PIPEDA you may access your personal information, challenge its accuracy and completeness (Principles 8–9 / section 8), and withdraw consent subject to legal or contractual restrictions. Quebec's Law 25 adds rights to cessation of dissemination and data portability. Same routes as section 3; complaints to the OPC (priv.gc.ca) or the Commission d'accès à l'information for Quebec.

🇦🇺 Australia

Under the Privacy Act 1988 (Cth), APP 12 gives you access to your personal information and APP 13 correction; we answer within the Act's reasonable timeframes using the section 3 routes. Complaints: us first, then the OAIC (oaic.gov.au). Australia has no general statutory erasure right — we give you the section 5 deletion anyway.

🇳🇿 New Zealand

Under the Privacy Act 2020, IPP 6 gives you a legally enforceable right of access to your personal information and IPP 7 the right to request correction (with a statement of correction if we disagree). Same routes as section 3; complaints to the Office of the Privacy Commissioner (privacy.org.nz), and NZ has no general erasure right — section 5 applies to you anyway.

10. Contact

Dogetlawyer AI Ltd · Company number 16719329 (England and Wales) · 124–128 City Road, London EC1V 2NX, United Kingdom · support@dogetlawyer.com ("Privacy" in the subject) · Self-service: dashboard → Privacy & Data Rights.

Version 1.2 · Effective 24 July 2026 · Framework: UK GDPR Articles 7, 12–23, 77–82; Data Protection Act 2018 (Schedules 1–2, ss.166–169); Data (Use and Access) Act 2025 (main provisions in force 5 February 2026; complaints provisions in force 19 June 2026); EU GDPR; PIPEDA and Law 25; Privacy Act 1988 (Cth) APPs 12–13; Privacy Act 2020 (NZ) IPPs 6–7; CCPA/CPRA and other US state privacy acts.

<