This policy is written under United Kingdom law first — the UK GDPR and the Data Protection Act 2018, both as amended by the Data (Use and Access) Act 2025 ("DUAA") — because Dogetlawyer is operated from England. If you use Dogetlawyer from the Republic of Ireland, the EU/EEA, the United States, Canada, Australia or New Zealand, section 16 explains how your local law applies on top.
1. Who we are
Dogetlawyer.com (including contract.dogetlawyer.com and its related pages and apps — together the "Service") is operated by Dogetlawyer AI Ltd, a company registered in England and Wales, company number 16719329, registered office 124–128 City Road, London EC1V 2NX, United Kingdom ("Dogetlawyer", "we", "us"). We are the data controller for the personal data described in this policy, except where section 14 (processor role) applies.
Contact for privacy matters: support [at] dogetlawyer [dot] com (put "Privacy" in the subject line so it is routed quickly), or write to the registered office above.
2. Who this policy covers
- Visitors — people browsing the site without an account;
- Account holders — people using the free or paid features (documents, AI chat, contract tools, CLM);
- Business/team accounts — firm owners, their staff members, and people whose data appears in content those accounts upload (see section 14);
- Tele-legal professionals — independent practitioners who apply to be listed for consultations (see section 15);
- People who contact us — by email, WhatsApp or forms.
3. What we collect
- Account data — name, email address, password (stored only as a secure hash), and optional details such as phone number or country;
- Your content — documents you create or upload, questions and messages you send to the AI features, contract-register entries, and files you store;
- Payment data — plan, transaction history and billing records. Card details are entered directly with our payment processor; we never see or store full card numbers;
- Usage and device data — server logs (IP address, browser type, pages requested, timestamps), error logs, and — only with your consent through the cookie banner — analytics data (see the Cookies Policy);
- Consent and rights records — your cookie choices, and records of privacy requests and complaints (we must be able to prove how we handled them);
- Tele-legal professional data — identity-verification details for listed professionals;
- Support communications — messages you exchange with us.
Special category and criminal-offence data inside your content
Legal matters are sensitive. A question about unfair dismissal, family issues or a dispute may reveal health information, trade-union membership, or alleged offences. We do not ask for this data, we never use it for marketing or profiling, and you can delete the content that contains it at any time (section 9).
⚖ Legal details
4. Why we use it — purposes and lawful bases
| Purpose | Data used | Lawful basis (UK GDPR Article 6) |
|---|---|---|
| Providing the Service to you as the account holder — your account, documents, AI features, contract tools, CLM, Tele-legal bookings, payments and support | Account, content, payment, support | Article 6(1)(b) — performance of a contract |
| Handling personal data about other people that appears in an individual user's content (for example the other party to a contract or dispute) | Content | Article 6(1)(f) — legitimate interests (delivering the service the user requested); see the note below this table |
| Securing the Service — preventing fraud, abuse and attacks; monitoring; debugging; keeping backups | Usage/device, logs, account | Article 6(1)(f) — legitimate interests (network and information security — a purpose the DUAA now lists in the UK GDPR itself as an example of a legitimate interest) |
| Service analytics and improvement (aggregate patterns, feature usage) | Usage data; consent-based analytics | Article 6(1)(f) for our own aggregate server statistics; Article 6(1)(a) — consent — for cookie-based analytics (the provider is named in the Cookies Policy) |
| Sending service emails (receipts, renewal notices, security alerts, material changes to terms) | Account | Article 6(1)(b)/(c) — contract and legal obligations |
| Marketing emails about our own similar services | Account (email) | Article 6(1)(a) consent, or the PECR "soft opt-in" for existing customers — every message has a working unsubscribe link, and direct marketing is recognised in the UK GDPR (as amended by the DUAA) as a purpose that may be a legitimate interest, subject to your absolute right to object (section 11) |
| Complying with law — tax, accounting, responding to lawful requests, handling rights requests and complaints | Billing, account, rights records | Article 6(1)(c) — legal obligation |
| Establishing or defending legal claims | Relevant records | Article 6(1)(f) — legitimate interests |
Other people in your content. If your documents or questions include personal data about someone other than you, we process it only as part of providing the Service to you — never for any independent purpose of ours. Where we obtain personal data about another person through user-submitted content, we assess whether UK GDPR Article 14 requires us to provide privacy information to that person directly; where we rely on an exception — such as disproportionate effort — we document that assessment and take appropriate measures instead, including making this Privacy Policy publicly available. Where a business customer uploads such data, section 14 applies instead: the business is the controller and our Data Processing Addendum governs.
We do not use the "recognised legitimate interests" fast-track basis introduced by the DUAA (in force 5 February 2026); if that ever changes we will update this table first.
5. AI-enabled processing
When you request an AI-enabled feature, the relevant instruction and, where necessary, limited document content may be processed through contracted AI-inference, language-processing or legal-information infrastructure.
External infrastructure providers supply individual technical components. They do not operate the complete Dogetlawyer Service, determine Dogetlawyer’s legal-content framework or provide legal advice to users.
Dogetlawyer controls the user-facing workflows, provider routing, system instructions, legal structures, safety controls and presentation of results.
We do not use private user documents or chats to train a publicly available Dogetlawyer model. We select and configure business-grade services with the objective of preventing submitted content from being used for general-purpose model training, subject to the relevant contracted terms, safety requirements and account configuration. Safety, abuse-prevention and operational records may exist for limited periods under the applicable contracted service.
The "Legal Basis & Sources" feature sends a minimised legal topic, citation request or search query — not your account identity — to specialist legal-information retrieval infrastructure.
The infrastructure used may vary according to the feature, availability, performance, security and jurisdictional requirements.
No solely automated decisions with legal or similarly significant effects are made about you. The AI drafts documents and explains issues; it does not decide anything about you such as pricing, access or eligibility. AI outputs can be wrong — they are legal information and drafting assistance, not legal advice: see How we use AI.
6. Cookies and similar technologies
Our cookie banner gives you real choices: Strictly Necessary cookies always run (login, security, your consent record); Preferences, Analytics and Performance and Marketing and Advertising load only if you switch them on. Reopen your choices any time via the "Privacy choices" control shown on every page. Consent-based session analytics (with typed text masked) runs only after you accept "Analytics and Performance". Full details — including every cookie name, the named analytics provider and each duration — are in the Cookies Policy.
⚖ Legal details
7. Who we share personal data with
We share personal data only where reasonably necessary to provide, secure, administer and improve the Service, where a user requests the disclosure, or where disclosure is required by law.
Depending on the features used, the categories of recipients may include:
| Recipient category | Purpose and information involved |
|---|---|
| Hosting, storage and backup infrastructure providers | Host the application and process account information, user content, application records, technical logs and protected backups. Our primary application hosting environment is located in the Netherlands, within the EEA. Limited support, administration, communications or resilience functions may involve processing in other locations. |
| AI-inference and language-processing infrastructure providers | Process the minimum relevant instruction, question, document extract or other content required to perform an AI-enabled feature requested by the user. |
| Legal-information and search infrastructure providers | Process minimised legal topics, citation requests or search queries required to retrieve relevant public legal information. |
| Communications providers | Deliver account-verification messages, security notices, receipts, service updates and user-requested communications. |
| Payment-service providers | Process subscriptions, payments, refunds, fraud-prevention information and legally required transaction records. Full payment-card details are entered directly with the selected payment provider — named on the checkout screen — and are not stored by Dogetlawyer. |
| Security, monitoring and technical-support providers | Process limited device, network, usage, diagnostic and error information required to protect the Service and resolve technical problems. |
| Consent-based analytics providers | Process limited interaction and device information only where the user has provided the required consent through our privacy controls. The provider is named in the Cookies Policy. |
| Independent professionals | Receive booking information and content that a user chooses to provide in connection with an independent professional consultation. They are responsible for their own professional services and associated processing (section 15). |
| Professional advisers, regulators and public authorities | Receive relevant information where reasonably necessary to meet legal obligations or establish, exercise or defend legal claims. |
| Parties involved in a business transaction | May receive relevant information where Dogetlawyer is involved in a proposed or completed investment, financing, merger, reorganisation, acquisition or sale, subject to appropriate confidentiality and data-protection safeguards. |
Providers acting on our behalf are required to process personal data under appropriate contractual, confidentiality, security and data-protection obligations.
We maintain internal records identifying the organisations involved, their processing functions, locations, retention arrangements and applicable safeguards.
Where Dogetlawyer acts as a processor for a business customer, information about relevant subprocessors and material changes is provided in accordance with the applicable Data Processing Addendum.
We do not sell personal data or disclose it to data brokers.
8. International processing and transfers
Dogetlawyer is based in the United Kingdom, and our primary application hosting environment is located in the Netherlands.
Some contracted service providers may process limited personal data from the United Kingdom, the EEA, the United States or other locations according to the service involved.
Where processing involves a restricted international transfer, we use an applicable lawful transfer mechanism. Depending on the circumstances, this may include:
- United Kingdom adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission’s Standard Contractual Clauses; or
- another transfer mechanism permitted under applicable data-protection law.
We also apply supplementary safeguards where appropriate, including data minimisation, access restrictions, encryption, contractual controls and transfer-risk assessments.
Further information about safeguards relevant to a particular processing activity may be requested through the Privacy & Data Rights system.
⚖ Legal details
9. How long we keep things
| Data | How long | Why |
|---|---|---|
| Your documents, chats and contract register | Individual deletions: removed from live systems without undue delay, normally within 30 days. Account closure: 30-day export window, then deleted from live systems normally within 30 days after it ends — normally no later than 60 days after closure | They are yours; we keep them only to serve them back to you |
| Account records | Life of the account + up to 60 days (the closure timeline above) | Running the Service |
| Billing and tax records | 6 years from the end of the relevant financial year | Legal obligation (UK tax and accounting law) |
| Security and audit logs | Up to 24 months | Permitted retention — legitimate interests in security and abuse prevention, and defence of legal claims (Articles 6(1)(f), 17(3)(e)); the length is kept under review against necessity. Retained even after an erasure request (see Your Data Rights) |
| Cookie-consent and rights-request records | Up to 6 years | Needed to demonstrate compliance (UK GDPR Article 5(2) accountability) |
| Encrypted backups | Expire automatically on a rolling schedule, normally within 90 days after live-system deletion | Disaster recovery; deleted content is not restored from backups except during genuine disaster recovery (and is then re-deleted) |
10. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration and disclosure. These measures include encrypted connections, protected credential storage, role-based access controls, restricted administrative access, security logging and protected backups.
Security measures are reviewed according to the nature of the processing, available technology and the risks to individuals. No online service can eliminate every security risk.
Where a personal-data breach triggers a legal notification obligation, we will notify the relevant authority and affected individuals within the periods required by applicable law.
⚖ Legal details
11. Your rights and how to use them
Under the UK GDPR you have the right to:
- Access your personal data (a "subject access request") — Article 15;
- Rectify inaccurate data — Article 16;
- Erase data ("right to be forgotten") — Article 17, subject to the legal-retention exceptions in Article 17(3) explained on the Your Data Rights page;
- Restrict processing — Article 18;
- Data portability — Article 20 (we provide copies in common machine-readable formats);
- Object — Article 21, including an absolute right to stop direct marketing;
- Withdraw consent at any time where consent is the basis (e.g. analytics cookies) — Article 7(3);
- Rights around significant automated decisions — Articles 22A–22D (we make none — section 5).
How to exercise your rights. The fastest route for an account holder is your dashboard → Privacy & Data Rights, where requests can be submitted and tracked. Visitors, former users and anyone who cannot access an account may use the public Privacy & Data Rights form — no account or subscription is needed. You can also email support [at] dogetlawyer [dot] com ("Privacy" in the subject) where you cannot use the online routes. We may request information reasonably necessary to verify identity, protect personal data and locate relevant records — never more than the risk requires. We respond within one month, extendable by up to two further months for complex requests (we will tell you if so, within the first month). Requests are free unless manifestly unfounded or excessive. Searches in response to access requests must be reasonable and proportionate, and if we need clarification the clock pauses until you reply. Rights requests and data-protection complaints are different processes and may have different response periods (section 12).
12. Complaints — to us first, then the ICO
- Step 1 — us: use Privacy & Data Rights (account holders), the public Privacy & Data Rights form (no account needed), or email support [at] dogetlawyer [dot] com with "Privacy complaint" in the subject.
- Step 2 — the regulator: you can complain at any time to the Information Commissioner's Office (ICO): ico.org.uk · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
- Step 3 — court: you also have the right to an effective judicial remedy and to compensation for damage caused by infringement (UK GDPR Articles 79 and 82; Data Protection Act 2018 sections 167–169).
13. Children
The Service is for adults: you must be at least 18 to create an account, and we do not knowingly collect personal data from anyone under 18 as a user. However, the documents and matters users work on (for example family, employment or housing matters) may contain information about children. We process that information only where necessary for the requested service, with safeguards appropriate to its sensitivity and risk, and never for marketing or profiling. If you believe a child has created an account, contact us and we will delete it.
14. When we act as a processor for your business
If you use Dogetlawyer for your organisation and upload personal data about your own clients, staff or contacts (for example in contracts, HR records or intake forms), you are the controller of that data and we act as your processor: we process it only on your documented instructions to provide the Service, apply the security measures in section 10, use the recipient categories in section 7, and delete or return it as described in section 9. Our Data Processing Addendum (UK GDPR Article 28) forms part of our Terms automatically whenever we process Customer Content on behalf of a business customer — no request or signature is needed, though we will countersign a copy on request at support [at] dogetlawyer [dot] com. You are responsible for having a lawful basis to upload such data.
15. Tele-legal professionals
To keep the directory trustworthy we verify the identity of professionals before public listing; where a profile uses a regulated title (such as solicitor or barrister) we also verify current public-register status and registration number before publication and periodically thereafter. Verification records are retained while the listing is active plus 24 months after it ends (defence of legal claims — Article 17(3)(e)). Public profiles show only the details the professional chooses to publish. When you book a consultation, the professional receives your booking details and anything you choose to share with them — for that information they are an independent controller under their own professional obligations, and their own privacy notice applies alongside this one.
16. Users outside the UK — country sections
The UK GDPR sections above apply to everyone. If you are in one of the countries below, the following applies in addition.
🇮🇪 Republic of Ireland and the EU/EEA
Ireland-specific services are coming soon. Dogetlawyer does not currently offer an Ireland-specific service and does not target the EU/EEA market. If you nevertheless access the Service from Ireland or elsewhere in the EU/EEA, the EU GDPR applies to our processing of your data and your rights match section 11; transfers of your data to us in the UK are covered by the European Commission’s UK adequacy decisions (renewed 19 December 2025, running to 27 December 2031). You may complain to your local supervisory authority — in Ireland, the Data Protection Commission (dataprotection.ie) — as well as, or instead of, using section 12. Because we do not currently target the EU/EEA market, we have not appointed an EU representative under EU GDPR Article 27; if we launch Ireland-specific services, this section will be updated first.
🇺🇸 United States
We are a UK company and may not meet the thresholds that make state privacy laws such as the California Consumer Privacy Act as amended by the CPRA (Cal. Civ. Code §1798.100 et seq.), the Virginia CDPA, or the Colorado, Connecticut, Texas and similar state acts directly applicable to us. Regardless, we voluntarily extend the substance of those rights to all US users: to know/access, to correct, to delete, and to obtain a portable copy — through the same routes as section 11, without discrimination for exercising them.
- We do not "sell" personal information, and we do not "share" it for cross-context behavioural advertising (as those terms are defined in California law). Where legally applicable, we recognise supported Global Privacy Control signals as an opt-out request — and optional analytics remains disabled unless the required consent has been provided.
- We do not use or disclose sensitive personal information for purposes requiring a "limit use" right.
- We do not knowingly collect data of consumers under 18 (section 13).
- Categories collected (CCPA terms): identifiers; commercial information; internet activity; professional information you include; and the content you provide. Sources, purposes and recipients are as set out in sections 3, 4 and 7. Retention is per section 9.
🇨🇦 Canada
For Canadian users we handle personal information consistently with the Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair-information principles: we obtain meaningful consent (this policy plus the cookie banner), limit collection and use to the purposes in section 4, and give you access to and challenge of the accuracy of your information via section 11. Complaints may be made to us (section 12) and to the Office of the Privacy Commissioner of Canada (priv.gc.ca). Quebec residents: consistent with the Act respecting the protection of personal information in the private sector (as amended by Law 25), the person in charge of protection of personal information is reachable at support [at] dogetlawyer [dot] com; your data may be processed outside Quebec (UK/US/EEA) with the safeguards in section 8.
🇦🇺 Australia
For Australian users we apply practices consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs): open and transparent management (APP 1 — this policy), collection only of what we need (APP 3), notification (APP 5), use limited to stated purposes (APP 6), cross-border safeguards (APP 8 — see section 8), security (APP 11), and access and correction rights (APPs 12–13) via section 11. If a data breach is likely to result in serious harm we follow Notifiable Data Breaches-style notification. Complaints: us first (section 12), then the Office of the Australian Information Commissioner (oaic.gov.au).
🇳🇿 New Zealand
For New Zealand users we handle personal information consistently with the Privacy Act 2020 and its Information Privacy Principles, including collection limits (IPPs 1–4), use and disclosure limits (IPPs 10–11), cross-border protections (IPP 12 — the safeguards in section 8 provide comparable protection), security (IPP 5), and your rights of access (IPP 6) and correction (IPP 7) via section 11. Complaints: us first (section 12), then the Office of the Privacy Commissioner (privacy.org.nz).
🌍 Everywhere else
We apply the UK-law standards in this policy to every user. If your local law gives you additional rights, contact us and we will honour them where they apply.
17. Changes to this policy
We will post changes here with a new version number and effective date. For material changes we will also notify you by email or in-app before they take effect. Earlier versions are available on request.
18. Contact
Dogetlawyer AI Ltd · Company number 16719329 (England and Wales) · 124–128 City Road, London EC1V 2NX, United Kingdom · support [at] dogetlawyer [dot] com · WhatsApp (text only): +44 7520 648820. WhatsApp is for general enquiries only — please do not send identity documents, legal documents or sensitive personal information through WhatsApp; use the Privacy & Data Rights routes in section 11 instead.
Version 3.3 · Effective 6 August 2026 · Framework: UK GDPR and Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025 (main data-protection provisions in force 5 February 2026; complaints provisions in force 19 June 2026) · PECR 2003 as amended · EU–UK adequacy renewed 19 December 2025. This page is our privacy notice under UK GDPR Articles 13–14. · 5 August 2026: presentation redesigned (new header, contents sidebar and footer); the contact e-mail is never displayed on the page — the “our support inbox” link opens your e-mail app directly, which defeats spam harvesters. · 6 August 2026 (v3.3): provider disclosures now use functional recipient categories (named vendors remain in the Cookies Policy, at checkout, and in our internal and business-customer records); AI-enabled processing clarified; a public Privacy & Data Rights form added alongside the dashboard route; service complaints and data-protection complaints distinguished; Ireland-specific services marked as coming soon. These changes do not reduce your rights. The previous version is available on request.