Privacy Policy - Vienna Legal Technology (2026)

This policy describes how Vienna Legal Technology Corporation (“Vienna Legal Technology,” “we,” or “us”) collects, uses, and shares information.

Effective Date: March 4, 2026

Last Updated: August 6, 2026

This Privacy Policy explains how Vienna Legal Technology ("Vienna Legal Technology," "we," "us," or "our") collects, uses, shares, and protects information when you use our websites, applications, and related services (collectively, the "Services").

If you connect third-party services (such as Gmail or Zoom), additional terms in this policy apply to the data accessed through those integrations.

Important: Vienna Legal Technology provides software services and is not a law firm. We do not provide legal advice or legal representation. Use of the Services does not create an attorney-client relationship.

1. Information We Collect

We collect the following categories of information depending on how you use the Services:

  • Account and Contact Information: Name, email address, phone number, organization/firm name, billing contact information, and account credentials.
  • Workspace / Matter Content: Information you submit to the Services, such as prompts, notes, drafts, uploaded documents, filings, docket PDFs, and other content you choose to store in a matter workspace.
  • Product Inputs: Depending on the Vienna workspace you use (e.g., civil operations, criminal, startups & VC, or in-house), you may input matter information, governance documents, or other content relevant to the workflow.
  • Usage and Device Data: Log data and analytics such as IP address, device identifiers, browser type, operating system, pages/screens viewed, timestamps, and crash/diagnostic data.
  • Payment Information: If you purchase a paid plan, payment details are processed by our payment processor(s) (e.g., Stripe). We receive limited billing metadata (e.g., subscription status and last four digits) but do not store full payment card numbers.
  • Cookies and Similar Technologies: Cookies or similar technologies used to operate the Services (e.g., authentication), remember preferences, and measure performance.
  • Connected Services Data (e.g., Google/Gmail, Zoom): If you connect third-party services, we may access limited data from those services as described in Section 6 (Google User Data / Gmail) and Section 7 (Zoom Meetings Integration Data).

2. How We Use Information

We use information to:

  • Provide, operate, and maintain the Services (including creating and managing workspaces/matters).
  • Process your requests and provide customer support.
  • Improve and secure the Services (including troubleshooting, testing, and preventing fraud/abuse).
  • Personalize features and settings you enable (e.g., notification preferences).
  • Comply with legal obligations and enforce our agreements.

Marketing communications (if any) are opt-in where required and you can opt out at any time.

We do not use Google user data (Gmail-derived data) for marketing, advertising, or analytics.

3. AI Processing and Human Verification

Some features use automated processing (including AI/LLM-assisted features) to generate drafts, summaries, checklists, or workflow suggestions based on content you provide.

Outputs may be incomplete, inaccurate, or outdated. You are responsible for verifying facts, citations, deadlines, and filings before acting on any output.

Human access to customer content is restricted. Our personnel do not routinely review your workspace content. Limited access may occur only when necessary to provide support at your request, investigate security incidents or abuse, or comply with law.

We do not use Customer Content to train models that are made generally available to others. Where we use third-party AI providers, we configure them (where available) to not train on your Customer Content.

4. Cookies and Analytics

We use cookies and similar technologies for authentication, security, and basic analytics. You can manage cookies through your browser settings; disabling cookies may affect functionality.

5. How We Share Information

We do not sell your personal information. We may share information with:

  • Service Providers: Vendors that help us operate the Services (e.g., hosting, storage, security, analytics, and payment processing). They may process data only on our instructions and for the purpose of providing services to us.
  • Legal and Safety: When we believe disclosure is necessary to comply with law or legal process, protect rights and safety, investigate fraud/security issues, or enforce our agreements.
  • Business Transfers: In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.

We do not share Gmail-derived data with advertisers, marketing partners, or data brokers.

6. Google User Data (Gmail) - Limited Use Disclosures

If you connect your Google account, we access Gmail data only as necessary to provide the court-email ingestion features you enable. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

OAuth scopes requested

  • gmail.readonly
  • gmail.metadata

What we access

  • Email message metadata (sender, recipient, subject, timestamps, message IDs, and thread identifiers).
  • Email message content limited to court-related emails you designate or that match configured court-mail filters (e.g., electronic filing notices).
  • Attachments associated with court-related emails (e.g., ECF/CM/ECF or PACER PDFs).

Why we access it (purpose limitation)

  • Automatically ingest court emails into your matter workspace.
  • Extract docket documents and metadata from attachments.
  • Update matter timelines, filings, and deadlines based on court communications.
  • Improve ingestion accuracy and reliability (e.g., filtering/parsing).

We do not use Gmail data for marketing, advertising, analytics, profiling, or resale.

Minimization and human access

  • We use metadata-first identification wherever feasible to minimize content access.
  • No human routinely reads inboxes. Limited access may occur only for support at your request, security investigation, or legal compliance.

Storage and security

  • If you enable ingestion, we may store imported emails/attachments and derived metadata in our secure Amazon Web Services (AWS) cloud infrastructure to provide the Service.
  • Data is encrypted in transit and at rest; access is restricted via role-based controls.

Sharing

  • We do not sell Google user data and do not share Gmail data except with infrastructure providers strictly necessary to operate the Service (e.g., AWS hosting/storage and security providers) or as required by law.

Retention, deletion, and revocation

  • You may revoke access at any time via Google Account settings.
  • You may delete imported Gmail-derived data inside the platform (subject to any retention settings you configure).
  • Upon account deletion, we delete Gmail-derived content and attachments within 30 days, unless we must retain it to comply with law or a valid legal hold.
  • After revocation, we stop accessing Gmail; previously imported data remains until deleted or purged under your retention settings.

7. Zoom Meetings Integration Data

Connecting Zoom is optional. If you choose to connect a Zoom account, we access Zoom data only as necessary to create and manage meetings for the matters and events you schedule inside the Services. Our use of information received from Zoom APIs is limited to providing and improving those scheduling features.

OAuth scopes requested

  • user:read:user
  • meeting:read:meeting
  • meeting:write:meeting

What we access and store

  • Basic Zoom profile details used to identify the connected account: your Zoom user ID, Zoom account ID, display name, and the email address associated with the Zoom account.
  • Meeting records that the Services create or read on your behalf, such as the meeting ID, topic, start time, duration, and join URL, so the meeting can be attached to the correct matter and event.
  • Connection status metadata (when the connection was created or last refreshed, and any error state) so we can show you whether the integration is working.

What we do not access

  • We do not access, store, or process meeting recordings, transcripts, chat messages, or audio or video content.
  • We do not join, monitor, or record your meetings, and we do not read meetings that the Services did not create or that you did not associate with a matter.
  • We do not use Zoom data for marketing, advertising, profiling, or resale, and we do not share it with advertisers or data brokers.

Storage and security

  • Zoom OAuth access and refresh tokens are stored in a dedicated managed secrets store, separately from application records, and are never exposed to the browser.
  • Connection records and meeting metadata are stored in our secure Amazon Web Services (AWS) infrastructure, encrypted in transit and at rest, with access restricted by role-based controls.

Retention, deletion, and revocation

  • You may disconnect Zoom at any time from the Conferencing integrations screen in the Services. Disconnecting deletes the stored tokens and the connection record, and we immediately stop accessing your Zoom account.
  • You may also revoke access at any time from the Installed Apps section of the Zoom App Marketplace, which has the same effect.
  • Meeting metadata already attached to a matter remains with that matter until you delete it or it is purged under your retention settings. Upon account deletion, Zoom-derived data is deleted within 30 days unless we must retain it to comply with law or a valid legal hold.

8. Data Retention and Deletion

We retain information only for as long as reasonably necessary to provide the Services, maintain security, comply with legal obligations, resolve disputes, enforce agreements, and support legitimate business operations.

Retention may vary by feature, account type, workspace configuration, legal hold requirements, and customer instructions. Some enterprise plans may support configurable retention schedules.

Data Deletion Requests

You may request deletion of your personal information, account data, workspace content, matter data, uploaded documents, imported email data, Gmail-derived data, or other Customer Content by contacting us at privacy@juristai.org.

Please include:

  • The email address associated with your Vienna account.
  • Your organization or firm name, if applicable.
  • The workspace, matter, or case name, if applicable.
  • The categories of data you want deleted.
  • Whether you are requesting account deletion, workspace deletion, matter deletion, imported Gmail data deletion, or deletion of specific files/content.

We may need to verify your identity and authority before completing the request. For organization or firm accounts, we may also need confirmation from the account owner, administrator, or authorized representative.

Unless a shorter period is required by law, Vienna Legal Technology will acknowledge deletion requests within 5 business days and will complete verified deletion requests within 30 days, unless retention is required for legal compliance, security, fraud prevention, dispute resolution, billing records, contractual obligations, or a valid legal hold.

Deleted data is removed from active production systems after the request is verified and processed. Residual copies may remain in encrypted backups and disaster recovery systems until those backups expire under our standard backup retention cycle, unless earlier deletion is technically feasible.

For Gmail-derived data, you may also revoke Vienna Legal Technology’s access at any time through your Google Account settings. Revocation stops future access to Gmail data, but previously imported data remains subject to this deletion procedure unless deleted separately.

9. Security

We implement administrative, technical, and physical safeguards designed to protect information. No system is 100% secure, and we cannot guarantee absolute security.

10. Your Choices and Rights

Depending on your location, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@juristai.org.

We may need to verify your identity before processing the request. Verification may include confirming control of the account email address, confirming workspace or organization membership, or requesting additional information reasonably necessary to confirm authority.

You may request:

  • Access to personal information associated with your account.
  • Correction of inaccurate account or contact information.
  • Deletion of personal information, Customer Content, uploaded files, workspace data, matter data, imported email data, or Gmail-derived data.
  • Export of certain account or workspace data, where technically feasible.
  • Revocation of connected third-party integrations, including Google/Gmail access.

Deletion requests are handled according to the Data Retention and Deletion procedure in Section 8.

California residents: we do not sell or share personal information for cross-context behavioral advertising.

EU/UK residents: we process personal data based on performance of a contract, legitimate interests, consent where required, and legal obligations.

11. International Transfers

If you access the Services from outside the United States, your information may be transferred to and processed in the United States or other jurisdictions where we or our service providers operate.

12. Children’s Privacy

The Services are not directed to children under 13 (or older where required by law). We do not knowingly collect personal information from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the Services or by email.

14. Contact Us

If you have questions or requests regarding privacy, contact:

Vienna Legal Technology Corporation
101 Washington Ave Suite 221B
Grand Haven, MI 49417
United States