Data controller: Dogetlawyer AI Ltd, registered in England and Wales (company number 16719329) · 124–128 City Road, London EC1V 2NX, United Kingdom · support@dogetlawyer.com
- The UK framework in one map
- What the DUAA 2025 changed — and when
- Your rights, one by one
- Subject access requests — how they work here
- Erasure — what we delete, what we must keep
- Automated decisions and AI
- Complaints — the statutory route
- Controller or processor — whose request is it?
- Your rights outside the UK — country sections
- Contact
1. The UK framework in one map
| Law | What it does |
|---|---|
| UK GDPR | The core rulebook: lawful bases, your rights (Articles 12–23), security, transfers, accountability |
| Data Protection Act 2018 | Fills in UK detail: conditions for sensitive data (Schedule 1), exemptions, ICO enforcement, court remedies (ss.167–169) |
| PECR 2003 | Cookies and electronic marketing — see the Cookies Policy |
| Data (Use and Access) Act 2025 ("DUAA") | Amends all three — it did not replace them. Royal Assent 19 June 2025; commencement in phases (section 2) |
The regulator is the Information Commissioner's Office (ICO). The DUAA provides for the ICO to be reconstituted as the "Information Commission"; until that change is commenced, the ICO continues under its current name.
2. What the DUAA 2025 changed — and when
Honest status as at 24 July 2026:
| Change | What it means for you | Status |
|---|---|---|
| Complaints to controllers (s.103) | You have a statutory right to complain to us; we must make that easy (including electronically), acknowledge within 30 days, and respond without undue delay | In force 19 June 2026 |
| Subject access requests | Searches must be "reasonable and proportionate"; the response clock can pause while we wait for clarification we genuinely need | In force 5 February 2026 |
| Automated decision-making (new UK GDPR Articles 22A–22D) | Significant decisions made solely by automation are allowed with safeguards (information, human review, the right to contest) — stricter rules remain for special category data | In force 5 February 2026 — we make no such decisions (section 6) |
| Recognised legitimate interests | A fast-track lawful basis for a short list of public-interest purposes | In force 5 February 2026 — we do not use it |
| Purpose limitation examples | Statutory examples of when re-use of data is compatible with the original purpose | In force 5 February 2026 |
| International transfers — "data protection test" | Outcomes-based test: protection abroad must not be materially lower than the UK standard | In force 5 February 2026 |
| PECR cookie exemptions | Consent exemptions for some statistical/appearance cookies — we stay opt-in anyway | In force 5 February 2026 |
| PECR fines raised | Cookie/marketing breaches now attract UK GDPR-level penalties (up to £17.5m / 4% of turnover) | In force 5 February 2026 |
| ICO → Information Commission | Regulator restructure | Not yet commenced |
3. Your rights, one by one
| Right | UK GDPR | What it does | Fastest route |
|---|---|---|---|
| Be informed | Arts 13–14 | Know what happens to your data — that is the Privacy Policy | Read it; ask us anything unclear |
| Access | Art 15 | Get a copy of your personal data plus the key information about how it is used | Privacy & Data Rights → Access request (section 4) |
| Rectification | Art 16 | Correct inaccurate data | Edit your profile directly, or submit a request |
| Erasure | Art 17 | "Right to be forgotten" — with legal-retention limits | Section 5 — the full honest breakdown |
| Restriction | Art 18 | Freeze processing while something is disputed | Submit a request |
| Portability | Art 20 | Take your data elsewhere in machine-readable form | Export documents from your dashboard; account data as CSV/JSON on request |
| Object | Art 21 | Object to legitimate-interests processing; absolute for direct marketing | Unsubscribe link, or submit a request |
| Withdraw consent | Art 7(3) | As easy as giving it | "Privacy choices" for cookies; unsubscribe for email |
| Automated decisions | Arts 22A–22D | Safeguards for solely automated significant decisions | We make none — section 6 |
| Complain | DUAA s.103; Art 77 | To us, to the ICO, and to court | Section 7 |
Every request: free of charge (unless manifestly unfounded or excessive), answered within one month, extendable by up to two further months for complex or numerous requests — and if we extend, we tell you within the first month with reasons. We may need to verify your identity first; we ask only for what verification genuinely requires (UK GDPR Article 12).
4. Subject access requests — how they work here
- Submit via Privacy & Data Rights (or email support@dogetlawyer.com, subject "SAR"). Logged-in requests are already identity-verified; email requests may need verification.
- Scope. Tell us if you want everything or something specific (faster). Under the DUAA our search must be reasonable and proportionate — we search account records, your content, billing, support messages and logs; we do not have to trawl systems where your data could not plausibly be.
- Clock. One month from receipt (or from identity verification). If we genuinely need clarification, the clock pauses until you reply ("stop the clock", DUAA, in force 5 February 2026).
- What you get. A copy of your personal data plus: purposes, categories, recipients (the subprocessor list), retention, your rights, data sources, and whether any automated significant decisions apply (none do).
- Limits. We must not disclose other people's data with yours (DPA 2018 Schedule 2 balancing) — for example, the other side's details in a matter you typed in may be redacted from what identifies them rather than you.
5. Erasure — what we delete, what we must keep
When you ask for erasure (Article 17) — or simply close your account — this is exactly what happens:
Deleted
- Your documents, uploads, chats, contract-register entries and stored files — individual deletions are removed from live systems within 30 days; on account closure you have a 30-day export window, after which content is deleted from live systems within 30 days (normally no later than 60 days after closure);
- Your profile and account record;
- Analytics identifiers we control (and Clarity data expires on Microsoft's schedule — replays ≈ 30 days);
- Marketing preferences — replaced by a minimal suppression record so we don't contact you again.
Retained — what the law requires us to keep, and what it permits
| Record | Kept for | Why (legal basis) |
|---|---|---|
| Invoices, billing and tax records | 6 years from the end of the relevant financial year | Required by law — UK tax and accounting law; Article 17(3)(b) (legal obligation) |
| Security and audit logs | Up to 24 months | Permitted — legitimate interests in fraud/abuse prevention and defence of legal claims (Articles 6(1)(f), 17(3)(e)); the length is kept under review against necessity |
| Consent, rights-request and complaint records | Up to 6 years | Needed to demonstrate compliance — accountability (Article 5(2)): we must be able to prove we handled your rights correctly |
| Encrypted backups | Expire automatically within 90 days after live-system deletion | Permitted — disaster recovery; deleted content is not restored from backups except during genuine disaster recovery, and is then re-deleted |
| Tele-legal verification records (professionals only) | Listing period + 24 months | Permitted — integrity of the directory; defence of claims (Article 17(3)(e)) |
Two further cases: content belonging to a business customer (where we act as processor) is deleted or returned on the controller's instructions under the Data Processing Addendum, not under this table; and if we are subject to a legal hold or a lawful preservation order, it overrides these periods for the specific records it covers, for as long as it lasts.
6. Automated decisions and AI
- Dogetlawyer's AI generates content you asked for (drafts, reviews, explanations). That is automated processing, not an automated decision about you.
- We make no decision producing legal or similarly significant effects on you solely by automated means — not on pricing, access, eligibility or anything else. Account-suspension decisions (Terms section 15) involve a human.
- If that ever changes, UK GDPR Articles 22A–22D (in force 5 February 2026) give you the rights to be informed, to obtain human intervention, to make representations and to contest the decision — and we would update this page and the Privacy Policy first.
- AI outputs can be wrong; they are information, not advice — the full honesty statement is at How we use AI.
7. Complaints — the statutory route
- To us (statutory since 19 June 2026, DUAA s.103). Use Privacy & Data Rights or email support@dogetlawyer.com ("Privacy complaint"). We acknowledge within 30 days — usually much faster — investigate, and respond without undue delay with what we found and what we are doing about it.
- To the ICO — at any time (you do not have to wait for us): ico.org.uk/make-a-complaint · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
- To court. You have the right to an effective judicial remedy against us or the ICO, and to compensation for material or non-material damage caused by an infringement — UK GDPR Articles 78–82; DPA 2018 sections 166–169.
8. Controller or processor — whose request is it?
- Your own data (your account, your questions, documents about your own matters): we are the controller — every right on this page is exercised directly with us.
- Data inside a business customer's content (for example, you are an employee named in a contract that a firm uploaded): the firm is the controller and we are its processor. Send your request to the firm; if it reaches us first we will pass it on promptly and help the firm respond (UK GDPR Article 28(3)(e)) — we cannot lawfully answer it over the controller's head.
9. Your rights outside the UK — country sections
🇮🇪 Republic of Ireland and the EU/EEA
Your rights arise under the EU GDPR (Articles 12–23 — access, rectification, erasure, restriction, portability, objection, ADM safeguards under Article 22) and, in Ireland, the Data Protection Act 2018 (IE). Exercise them through exactly the same routes as sections 3–5. You may complain to the Data Protection Commission (dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2) or your local supervisory authority, and you have EU GDPR Articles 79/82 court and compensation rights. The DUAA does not reduce these — and EU→UK data flows rest on the renewed adequacy decisions (section 2).
🇺🇸 United States
State laws (California CCPA/CPRA, Virginia, Colorado, Connecticut, Texas and others) give rights to know/access, correct, delete, and port, plus opt-outs of "sale"/"sharing" (we do neither) — and an appeal if a request is refused. We honour the substance of these for all US users through the same routes as section 3, without discrimination. California's "verifiable consumer request" standard matches our identity checks; if we decline a request we explain why and you can reply to appeal to a human reviewer.
🇨🇦 Canada
Under PIPEDA you may access your personal information, challenge its accuracy and completeness (Principles 8–9 / section 8), and withdraw consent subject to legal or contractual restrictions. Quebec's Law 25 adds rights to cessation of dissemination and data portability. Same routes as section 3; complaints to the OPC (priv.gc.ca) or the Commission d'accès à l'information for Quebec.
🇦🇺 Australia
Under the Privacy Act 1988 (Cth), APP 12 gives you access to your personal information and APP 13 correction; we answer within the Act's reasonable timeframes using the section 3 routes. Complaints: us first, then the OAIC (oaic.gov.au). Australia has no general statutory erasure right — we give you the section 5 deletion anyway.
🇳🇿 New Zealand
Under the Privacy Act 2020, IPP 6 gives you a legally enforceable right of access to your personal information and IPP 7 the right to request correction (with a statement of correction if we disagree). Same routes as section 3; complaints to the Office of the Privacy Commissioner (privacy.org.nz), and NZ has no general erasure right — section 5 applies to you anyway.
10. Contact
Dogetlawyer AI Ltd · Company number 16719329 (England and Wales) · 124–128 City Road, London EC1V 2NX, United Kingdom · support@dogetlawyer.com ("Privacy" in the subject) · Self-service: dashboard → Privacy & Data Rights.
Version 1.2 · Effective 24 July 2026 · Framework: UK GDPR Articles 7, 12–23, 77–82; Data Protection Act 2018 (Schedules 1–2, ss.166–169); Data (Use and Access) Act 2025 (main provisions in force 5 February 2026; complaints provisions in force 19 June 2026); EU GDPR; PIPEDA and Law 25; Privacy Act 1988 (Cth) APPs 12–13; Privacy Act 2020 (NZ) IPPs 6–7; CCPA/CPRA and other US state privacy acts.