Legal
Privacy Policy
Last updated: August 3, 2026
Legal Risk Alert ("we", "our", "us") respects your privacy. This Policy explains what personal data we collect, how we use it, and the rights you have under laws such as Canada's PIPEDA and the EU/UK GDPR.
What data we collect — at a glance
- ✅ Account: name, email, organization (optional), hashed password.
- ✅ Learning: course progress, quiz scores, certificates earned.
- ✅ Compliance Audit: the answers and evidence notes you submit, and the reports generated from them.
- ✅ Document Vault: the documents you upload, their labels and metadata, and access logs.
- ✅ Technical: IP address, device, browser, pages visited.
- ✅ Communications: messages you send us.
- ✅ Payment metadata (from Stripe): transaction ID, amount, currency, status, billing name, email, country, card brand, and last 4 digits of the card.
- ❌ What we do NOT store: your full card number, CVV, expiry date, bank account details, or any other financial credentials. Those are entered directly into Stripe's secure checkout and never reach our servers.
- ❌ What we never do: sell your data, read your vault documents for advertising, or use your documents or audit submissions to train AI models.
1. Data we collect
- Account data: name, email, organization (optional), password hash.
- Learning data: course progress, quiz scores, certificates earned.
- Compliance Audit data: your questionnaire answers, any context or evidence notes you add, generated reports, and the Report IDs and checksums used to verify them.
- Document Vault data: files you upload, filenames, labels, categories, expiry dates and other metadata you enter, plus a log of who accessed or changed what and when.
- Technical data: IP address, device, browser, pages visited.
- Communications: messages you send us through forms or email.
2. How we use your data
- To provide and improve the Services and your learning experience.
- To issue certificates and track progress.
- To generate, deliver, and verify your Compliance Audit reports, and to run the 30-minute virtual consult if you book one.
- To store and organise your Document Vault files, and — only where you have activated Vault Assist and granted consent — to let our team file documents for you.
- To send essential service emails (account, security, course updates).
- With your consent, to send marketing emails — you can unsubscribe anytime.
- To comply with legal obligations and protect against fraud or abuse.
We do not use your vault documents or audit submissions to train AI models, and we do not use them for advertising.
3. Legal bases (GDPR/UK GDPR)
- Performance of a contract (delivering the Services you signed up for).
- Legitimate interests (security, product improvement).
- Consent (marketing emails, optional cookies).
- Legal obligation (tax, accounting, lawful requests).
4. Sharing
We share data only with:
- Trusted service providers (hosting, authentication, analytics, email delivery) under contract.
- Authorities, when required by law.
- A successor entity in the event of a merger or acquisition.
We do not sell your personal data.
5. Payment information
All payments on Legal Risk Alert are processed by Stripe, a PCI-DSS Level 1 certified payment provider. Your card number, CVV, and bank account details are entered directly into Stripe's secure checkout — they never touch Legal Risk Alert's servers, and we cannot see or store them.
From Stripe, we receive only what we need to fulfil your order and meet tax and accounting obligations:
- Transaction ID, amount, currency, and status.
- Billing name, email, and country.
- Card brand and the last 4 digits (for receipts and dispute handling).
Stripe's handling of your payment data is governed by its own privacy notice — stripe.com/privacy. Transaction records we hold are retained only as long as required by applicable tax and accounting law.
6. Compliance Audit submissions and reports
Your questionnaire answers and evidence notes are stored to your account so you can resume, re-download, and compare assessments over time. Reports are generated as watermarked PDFs held in private storage and served through expiring links; each carries a Report ID and checksum so a recipient can verify authenticity without us disclosing the report's contents. Audit content is treated as confidential, is not used for advertising, and is not used to train AI models.
7. Document Vault confidentiality and staff access
- Vault files are held in private storage, encrypted in transit and at rest, and are not publicly addressable. Vault access requires an additional step-up PIN that we cannot see or recover.
- Access is limited to you, people you explicitly grant access to, organization admins for Organization vault records, and our staff acting under an explicit Vault Assist consent grant or where strictly necessary to operate or secure the service.
- Vault Assist: our team can only access your vault after you activate the plan and grant consent from inside the vault, within the scope and period you choose. Every access and filing action is written to an audit log you can review, showing the staff member, file, and timestamp. You can revoke the grant at any time, which immediately ends future staff access.
- Documents you forward for filing are deleted from our intake mailbox once they have been filed into your vault.
- Staff with any access are bound by confidentiality obligations. We do not read your documents for advertising, do not sell them, and do not use them to train AI models.
- Keep your originals. We store a copy of your documents to make them easy to access and manage. That copy does not replace your original documents or other backups, and you should not delete or destroy other copies simply because they are stored here.
8. Unlawful content and legal process
We do not proactively scan or inspect vault contents. Where we receive a credible report or a valid legal order we may suspend access, preserve the material and related logs, inspect only what is necessary, disclose it to law enforcement, regulators, or a court where legally required or where there is a risk of serious harm, and remove it. We narrow requests to the minimum data required and notify the affected account holder unless legally prohibited or where notice would prejudice an investigation.
9. International transfers
Data may be processed in Canada, the United States, or the EU. Where required, we use appropriate safeguards such as Standard Contractual Clauses.
10. Retention
We keep account data while your account is active and for a reasonable period afterward to comply with legal, accounting, and reporting obligations. You can request deletion at any time (see Your rights).
- Audit submissions and reports: kept while your account is active, then only as long as needed for tax, accounting, and dispute-handling obligations.
- Vault documents: kept until you delete them or close your account. Deleted files age out of backups on our normal backup cycle and cannot be restored after account closure.
- Vault access and assist logs: retained for security and accountability even after the related file is deleted.
- We may retain specific material longer where we are legally required to preserve it.
11. Security
We use encryption in transit and at rest, hashed passwords, role-based access, private storage for vault files and audit reports, access logging, and audited infrastructure. No system is perfectly secure; please use a strong, unique password and keep your Vault PIN confidential.
Where vault files live. Documents you upload are not held on LRA office equipment or personal devices. They are stored in a private, access-controlled cloud storage bucket operated by our infrastructure provider on enterprise cloud infrastructure, are not publicly addressable, and are released only through short-lived signed links issued for each authorised view or download. Every upload, download, share, handover, and Vault Assist action is recorded in an audit trail.
Uploads and malware. Uploads are checked on our servers for format and safety: we accept PDF, Word, Excel, PowerPoint, text, CSV and common image files only, within your plan's per-file size limit, and reject executables, scripts, archives, macro-enabled Office files, and files whose contents do not match their name. We do not scan, read, or virus-check the contents of your documents, so please run your own anti-virus software before uploading and after downloading files.
12. Your rights
Depending on where you live, you may have the right to:
- Access, correct, or delete your data.
- Restrict or object to processing.
- Receive a copy of your data (portability).
- Withdraw consent at any time.
- Lodge a complaint with your data protection authority.
To exercise any right, contact us. We will respond within applicable legal timeframes.
13. Cookies
We use essential cookies to keep you signed in and a limited set of analytics cookies to understand usage. You can control cookies through your browser settings.
14. Children
The Services are not directed to children under 16 and we do not knowingly collect their data.
15. Changes
We may update this Policy. Material changes will be communicated by email or through the Services.
16. Contact
Privacy questions? Contact us.
See also our Terms of Service and Policies & Procedures.