← Back to the home page

Service operator

Marcin Działowski
ul. Dziewanny 25/2, 20-539 Lublin
Poland
Registration or tax reference: NIP 8171929600
Email: support@mylegaldocsai.co.uk

Privacy Notice

Effective date: 21 July 2026.

1. Controller and contact

The operator identified on this page is the controller for the processing described here. Privacy requests and complaints may be sent to support@mylegaldocsai.co.uk.

2. Information processed

Depending on use, the service may process names, contact details, matter descriptions, uploaded documents, extracted text, generated documents, order and checkout references, payment status, delivery and revision records, consent choices, security logs, support correspondence and technical device or browser information.

3. Special-category and criminal-offence information

Legal documents may contain health information, racial or ethnic origin, political or religious information, trade-union information, sexual-life or orientation information, biometric identifiers, allegations, convictions, offences or proceedings. Customers must upload only information necessary for the requested document. Processing requires both an Article 6 basis and, where applicable, an additional condition under Article 9, Article 10 and the Data Protection Act 2018. The live processing record must identify the condition actually relied on; this Notice does not treat consent as a universal basis.

4. Purposes

Processing supports pre-contract document identification and pricing, contract performance, file extraction, drafting, official-source research, quality control, payment, delivery, revision, fraud prevention, service security, error investigation, support, accounting, legal obligations and the establishment, exercise or defence of legal claims.

5. Lawful bases

Depending on the activity, processing may be necessary for steps requested before entering a contract, performance of a contract, compliance with a legal obligation, legitimate interests or a recognised legitimate interest provided by law, or consent for optional analytics. Legitimate-interest processing is used only after assessing necessity and the effect on individuals. Processing must be limited to what is necessary.

6. Automated processing

Automated systems may extract text, classify a possible document route, identify missing information, research official sources, generate drafts and apply quality checks. The service does not make a binding court, employment, credit, insurance or public-authority decision about the customer. A customer may report an error or request a correction through support.

7. Providers and recipients

Providers may include Railway for hosting, OpenAI for supported model processing, Stripe for payment, Brevo for transactional email and—only after the applicable privacy choice—Google Analytics and Microsoft Clarity. Other recipients may include advisers, auditors, insurers, competent authorities or dispute-resolution bodies where lawfully necessary. The live provider configuration determines the actual processing chain.

8. International transfers

Where information is transferred outside the United Kingdom, the controller must use an available lawful transfer mechanism and assess the protection in the destination and provider configuration. Measures may include adequacy regulations, approved contractual safeguards and supplementary technical or organisational controls. Customers should avoid uploading unnecessary sensitive data.

9. Retention

Matter files, extracted text and generated outputs use short operational retention and scheduled deletion unless a longer period is necessary for an active order, correction, complaint, dispute, security incident or legal claim. Payment, accounting, consent, fraud, support and security records may be retained for longer where necessary or legally required. Provider logs and backups may follow separate limited cycles. Retention must be documented and reviewed rather than kept indefinitely by default.

10. Security

Controls include access limitation, transport encryption, upload validation, private order identifiers, short-lived links, provider separation, retention controls, logging and error monitoring. No internet service can guarantee absolute security. A suspected breach is assessed and notified where data-protection law requires.

11. Individual rights

Applicable rights may include access, rectification, erasure, restriction, objection, portability, withdrawal of consent and rights relating to qualifying automated decisions. A request may be limited by an exemption, the rights of another person or a legal obligation. Identity, authority and scope may need to be verified.

12. Data-protection complaints

A person may complain directly to support@mylegaldocsai.co.uk about the handling of personal information. The complaint will be acknowledged within 30 days, appropriate enquiries will be made without undue delay, progress information will be provided where appropriate and the outcome will be communicated without undue delay. This process reflects section 164A of the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025.

13. Information Commissioner's Office

A person may also complain to the Information Commissioner's Office. The ICO will commonly expect the concern to have been raised with the controller first. Contacting the controller does not remove the right to approach the ICO or another competent supervisory authority.

14. Children

The paid service is not designed for children to purchase independently. A responsible adult should manage a matter involving a child and minimise the child's personal information.

15. Legal framework and changes

This Notice reflects the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 and changes made by the Data (Use and Access) Act 2025, including the complaints requirements in force from 19 June 2026. It may be updated when processing, providers or legal requirements change.