Privacy Policy

Effective Date: 2026‑10‑20
Last Updated: 2026‑10‑20
‍
1. Introduction

LawPro.ai (“we,” “our,” or “us”) is committed to protecting the privacy, security, and confidentiality of personal information and Protected Health Information (“PHI”). This Privacy Policy describes how we collect, use, disclose, and safeguard information in accordance with the Health Insurance Portability and Accountability Act (HIPAA), the HIPAA Security and Privacy Rules, the SOC 2 Trust Services Criteria (2022), and applicable federal and state privacy laws. By accessing or using our services, you acknowledge and accept the practices described in this Privacy Policy.
‍
2. Information We Collect

We collect only the information necessary to operate, secure, and improve our services:
Personal Information — Name, email address, phone number, business contact details, and account credentials. Protected Health Information — Individually identifiable health information provided by customers, law firms, or authorized partners in connection with case management or related services. Technical and Usage Data — IP address, device identifiers, browser type, session metadata, audit logs, and security telemetry used for authentication, fraud prevention, and system performance. Customer‑Submitted Content — Files, documents, and case materials uploaded to the platform. We do not collect PHI for marketing or advertising purposes.
‍
3. How We Use Your Information

We use information strictly for legitimate business, operational, and compliance purposes, including:
Delivering, maintaining, and improving our products and services. Supporting customer operations, including case management, technical support, and workflow automation. Meeting legal, regulatory, and contractual obligations, including HIPAA, SOC 2, and state privacy laws. Ensuring platform security, including access control, threat detection, audit logging, and incident response. Training and quality assurance, using de‑identified or aggregated data only. We apply HIPAA’s Minimum Necessary Standard to all PHI access and processing.
‍
4. Data Sharing and Disclosure

We do not sell, rent, or license personal information or PHI. We may disclose information only to:
Authorized personnel who require access to perform their job duties and are bound by confidentiality and security obligations. Business associates and subcontractors who perform services on our behalf under HIPAA‑compliant Business Associate Agreements (BAAs). Regulators, auditors, or law enforcement when disclosure is required by law, subpoena, or regulatory mandate. Security and compliance partners conducting penetration tests, audits, or threat‑monitoring activities under strict confidentiality.All disclosures follow HIPAA’s Minimum Necessary Standard.
‍
5. Data Security

We maintain administrative, technical, and physical safeguards that meet or exceed HIPAA and SOC 2 requirements, including:
Encryption of data in transit (TLS 1.2+) and at rest (AES‑256). Role‑based access controls, MFA, and least‑privilege authorization.Continuous monitoring, audit logging, and automated threat detection.Incident response procedures, including evidence preservation and chain‑of‑custody controls.Independent third‑party audits, penetration testing, and vulnerability management aligned with NIST and SOC 2.

6. Your Rights


Depending on your jurisdiction and relationship with LawPro.ai, you may have the right to:
Access, correct, or delete your personal information. Restrict or object to certain types of processing. Request a copy of your data in a portable format. Receive disclosures about how your information is used and shared. Submit HIPAA‑related requests, including accounting of disclosures. Requests can be submitted to privacy@lawpro.ai.
‍
7. Data Retention

We retain PHI and personal data only for as long as required to fulfill the purpose for which it was collected or to comply with legal, regulatory, and contractual obligations.
PHI is retained for a minimum of six years under HIPAA unless a longer period is required by law or contract. After the retention period, data is securely deleted, destroyed, or de‑identified using NIST‑approved methods.

‍8. Breach Notification

If a breach occurs that compromises the privacy or security of PHI or personal data, we will notify affected individuals, customers, and regulators in accordance with:
HIPAA Breach Notification Rule (45 CFR §§ 164.400–414) Applicable state data‑breach notification lawsContractual obligations with covered entities and business associates. Notifications will be made without unreasonable delay.
‍
9. Updates to This Policy

We may update this Privacy Policy to reflect changes in our practices, technologies, or legal requirements.
Material changes will be posted on our website. Where required by law, we will provide direct notice or obtain consent before changes take effect.

‍10. Contact Information

For questions, concerns, or privacy‑related requests, contact:

Unlock the Legal AI platform of the future, today.