Legal & Compliance

Privacy Policy

Last updated: March 2025

LexBridge FZ-LLC ("LexBridge", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use our legal practice management platform. We comply with the UAE Personal Data Protection Law (PDPL), the DIFC Data Protection Law 2020, ADGM Data Protection Regulations, and the EU General Data Protection Regulation (GDPR) where applicable.

1. Who We Are

LexBridge is a Software-as-a-Service (SaaS) platform designed for law firms and legal professionals operating in the Gulf Cooperation Council (GCC) region. Our registered office is in the UAE. If you have privacy questions, contact our Data Protection Officer at privacy@lexbridge.io.

2. Data We Collect

We collect the following categories of personal data:

Category Examples Purpose
Account Data Name, email, phone, job title Account creation, authentication, support
Client Matter Data Case details, documents, hearing records Service delivery to law firms
Billing Data Invoice records, payment status Subscription management
Usage Data IP address, browser, login timestamps Security, analytics, improvement
KYC Data ID documents, nationality, date of birth Client identity verification (firm-level)

3. Legal Basis for Processing

  • Contract performance: to provide the LexBridge platform under our subscription agreement.
  • Legitimate interests: security monitoring, fraud prevention, and platform improvement.
  • Legal obligation: where required by UAE law, DIFC, or other applicable regulations.
  • Consent: for marketing communications and optional cookies (where required).

4. How We Use Your Data

We use personal data to:

  • Provide, maintain, and improve the LexBridge platform
  • Authenticate users and secure your account
  • Process payments and manage subscriptions
  • Send service notifications, invoices, and product updates
  • Respond to support requests
  • Comply with legal and regulatory obligations
  • Conduct security audits and investigate breaches

5. Data Sharing & Sub-Processors

We do not sell your personal data. We may share it with:

  • Cloud infrastructure providers (AWS — Middle East region, me-south-1) — hosting and storage under Data Processing Agreements
  • Payment processors — for subscription billing, under PCI-DSS compliance
  • Email service providers — for transactional emails only
  • Legal authorities — when required by UAE law or court order
  • Anthropic PBC (United States) — solely when you explicitly activate the optional AI Advisor feature and provide informed consent. Anthropic processes queries via their API under Standard Contractual Clauses. No case files, client identity documents, or KYC data are transmitted; only the text you type into the AI chat window. You may revoke consent at any time by contacting your system administrator.

All third-party processors are bound by data processing agreements and may not use your data for any purpose other than service delivery.

6. Data Retention

We retain account and matter data for the duration of your subscription plus 7 years to comply with UAE commercial record-keeping requirements. After this period, data is securely deleted or anonymised. You may request earlier deletion subject to our legal obligations.

7. Your Rights

Depending on your jurisdiction, you have the right to:

Access your personal data
Correct inaccurate data
Request deletion
Restrict processing
Data portability
Object to processing
Withdraw consent
Lodge a complaint with a regulator

To exercise any right, email privacy@lexbridge.io. We will respond within 30 days.

8. Security

We implement encryption at rest and in transit (TLS 1.2+), role-based access control, two-factor authentication, and regular security assessments. See our Security page for full details.

9. International Data Transfers

Data is primarily stored in AWS Middle East (UAE) region. Where data is transferred outside the UAE or DIFC, we use Standard Contractual Clauses or ensure the receiving jurisdiction offers adequate data protection.

10. Cookies

We use essential session cookies required for platform operation. We do not use third-party advertising cookies. Analytics cookies (if used) are anonymised and you may opt out via your browser settings.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before the change takes effect. Continued use constitutes acceptance.

12. Contact

LexBridge FZ-LLC

Data Protection Officer: privacy@lexbridge.io

General enquiries: hello@lexbridge.io