Platform
Legal CRM Leads, intake & matters in one place AI Agents Agents that run the routine work Automation Automate firm operations end to end For Solo Lawyers Run a full firm solo For Small Firms Grow without the back office
Features Security
Blog
All Business Insights
A laurel wreath of 20 golden stars among hundreds of faint ones - the 20 firms selected from 450+ applications
Cohort 1 Is Full: What 450+ Applications Tell Us About Small Firms and AI Aug 8, 2026 · 5 min read
US lawyers by firm size: solo, small, midsize and Big Law, with AI-adoption data
US Lawyers by Firm Size: 2026 Statistics (Solo, Small, Midsize, Big Law) Jun 19, 2026 · 5 min read
Earn
Affiliate program Earn 15-20% of every firm you refer Solution partners Custom terms for distributors
Sign in Try for free Try for free

Privacy Policy

Effective date: August 5, 2026

At Referent, protecting the confidentiality of the people and matters our customers work with is central to what we do. This Privacy Policy explains, in detail, how AI LAWTECH sp. z o.o. (“Referent”, “we”, “us”, “our”) collects, uses, shares, stores and protects personal data, and the rights available to you under the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable national law including the Polish Act on the Protection of Personal Data. It applies to our website at referent.law, our application at app.referent.law, and to intake forms and related services we provide (together, the “Service”).

  1. Summary

Referent is a legal practice management platform with AI features, built for law firms and independent lawyers. We act as a controller for data about our website visitors and account holders, and as a processor for the client and matter data that firms place into the Service, including data collected through intake forms.

In short: we use personal data to provide and secure the Service; we ask for your consent before setting analytics cookies; AI assists our users but never decides anything about you on its own; for customers in the EU and the UK we process personal data within the European Economic Area, other than a limited text-to-speech function processed in the US under appropriate safeguards; we do not sell personal data; and we do not allow AI providers to train their models on your data. Full detail is below.

  1. Who is responsible for your data

2.1. Controller. AI LAWTECH sp. z o.o., Henryka Sienkiewicza 36/5, 26-600 Radom, Poland. NIP: 9482639603. Email for all privacy matters: privacy@referent.law.

2.2. Establishment and lead supervisory authority. Referent is established in Poland. Our lead supervisory authority for the GDPR is the Polish data protection authority (UODO, Section 15). Because we are established in the EU, we are not required to appoint an EU representative under Article 27 GDPR.

2.3. Data protection contact. We have appointed a person responsible for data protection questions. You can reach them at privacy@referent.law.

  1. The two roles we play

Because of how the Service works, we handle personal data in two distinct roles, and it matters which one applies.

Controller. For personal data about our website visitors, prospective customers, and the lawyers and staff who register and use a Referent account, we determine why and how the data is processed. This Policy governs that processing.

Processor. When a user uploads client files, matter documents, emails or other content into the Service, or when an intake form collects information from a firm’s prospective client, the law firm is the controller and Referent is its processor. We process that data only on the firm’s documented instructions, under a Data Processing Agreement. The firm’s own privacy notice applies to that data. Section 11 explains what this means for intake respondents and the people whose data appears in matters.

  1. Definitions

4.1. “Personal data” means any information relating to an identified or identifiable individual.

4.2. “Processing” means any operation performed on personal data.

4.3. “Controller” and “processor” have the meanings given in the GDPR.

4.4. “Special categories of data” means data revealing health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, sex life or sexual orientation, and (treated with equivalent care) data on criminal convictions and offences.

4.5. “Sub-processor” means a third party we engage to process personal data on our behalf.

  1. The personal data we collect, why, and on what legal basis

We collect only what we need. The tables below set out, for each group of people, what we collect, why, the legal basis under Article 6 GDPR, and how long we keep it (see also Section 12).

5.1 Website visitors, enquirers and prospective customers

This section covers people who visit our website, contact us, engage with us on social media, or subscribe to our updates - including those who are not (yet) Referent users.

DataPurposeLegal basisRetention
Technical data (IP address, device and browser type, pages viewed, referrer)Operate, secure and troubleshoot the websiteLegitimate interest, Art. 6(1)(f)6 months
Analytics data collected via cookiesUnderstand and improve the websiteConsent, Art. 6(1)(a)Per the Cookie Policy
Enquiry and correspondence data: your name, contact details and the content of your communications when you reach us through our contact form, by email, through a messenger, by sending an offer or proposal, or by phoneRespond to you, evaluate and pursue a possible business relationship, and keep a recordSteps prior to a contract, Art. 6(1)(b); legitimate interest, Art. 6(1)(f)6 months after our last contact; if a contract results, contract term + 6 months
Online-meeting data (audio and, where used, transcripts of calls with us)Hold and document meetings conducted onlineLegitimate interest, Art. 6(1)(f)6 months
Social-media data: your handle, public profile information and the content of interactions when you engage with our accounts, for example on LinkedIn, Instagram, X/Twitter, Facebook or Telegram (this list is not exhaustive)Respond to you and manage our social-media presenceLegitimate interest, Art. 6(1)(f); consent where applicable6 months
Newsletter and marketing-contact data (email, name, preferences)Send you the newsletter and marketing communications you asked forConsent, Art. 6(1)(a)Until you unsubscribe / withdraw consent

Where a meeting with us is held online, we may use transcription tools, and we make participants aware when a call is being transcribed.

5.2 Account holders (lawyers and firm staff)

DataPurposeLegal basisRetention
Registration and profile data (name, work email, phone, organisation, role)Create and administer your account; provide the ServicePerformance of a contract, Art. 6(1)(b)Contract term + 6 months
Authentication data (credentials, session and trusted-device tokens)Log you in securely; protect the accountPerformance of a contract; legitimate interest in security, Art. 6(1)(f)Session / short-lived tokens
Usage and product-analytics dataOperate, secure and improve the ServiceLegitimate interest, Art. 6(1)(f); consent where set via cookies6 months
Support communicationsProvide support; keep recordsLegitimate interest; performance of a contractContract term + 6 months
Billing and transaction data of the subscribing firmManage the subscription and paymentsPerformance of a contract, Art. 6(1)(b); legal obligation (accounting), Art. 6(1)(c)5 years (Polish tax and accounting law)

We do not intentionally collect special categories of data about our account holders. Users may enter such data as part of matter content; that content is handled under our processor role (Section 11), not for our own purposes.

5.3 Data we do not process for our own purposes

Client files, matter documents, emails, calendar entries and intake responses that firms place into the Service are processed under our processor role, on the firm’s instructions. We do not use that content for our own purposes, and we do not use it, or allow our providers to use it, to train generative AI models (Section 7).

  1. Cookies and similar technologies

We use strictly necessary cookies to run the Service, and analytics cookies only with your consent. How consent is obtained and withdrawn, and the full list of cookies, are set out in our separate Cookie Policy. Under Polish law (Prawo komunikacji elektronicznej) non-essential cookies are set only after you consent.

  1. Artificial intelligence: how we use it and how we keep it accountable

The Service uses artificial intelligence, including large language models, to assist lawyers with tasks such as drafting, summarisation, classification, transcription, optical character recognition and search. We treat AI as a serious compliance area and apply the following commitments.

AI assists; it does not decide. AI features support the user; a lawyer always reviews and decides. The Service does not make decisions producing legal or similarly significant effects about any individual on a solely automated basis (see Section 10 on Article 22 GDPR). You can modify, reject or regenerate AI-assisted output.

Transparency (Article 50 EU AI Act). We make clear when you are interacting with AI, and AI-generated content is identifiable as such.

AI providers and locations. To produce a result, relevant content may be sent to the AI sub-processors listed in Section 8 for processing (for example, text for drafting, a file for OCR, audio for transcription). For customers in the EU and the UK, this AI processing takes place within the EEA using EU-region enterprise deployments, except for text-to-speech processing via xAI, which is carried out in the US under the safeguards described in Section 8 and Section 9.

We do not use AI model providers based in China.

No training on your data. We contractually prohibit our AI providers from using your data, or the content processed through the Service, to train or improve their general-purpose models. We do not place client content into any training dataset.

Logging of AI calls. For each connection to an AI service we record the provider, processing location and model version, so that the flow of data is auditable.

Quality access by our team. Where our technical staff need to review data to maintain and improve the quality of the Service, this is done on a least-privilege, just-in-time basis, logged, and under confidentiality obligations. By default our staff work with redacted traces and aggregated metrics rather than raw client content, and we never build a training dataset from client content.

  1. Who we share personal data with (recipients and sub-processors)

We share personal data with service providers (“sub-processors”) who process it on our behalf, strictly to provide the Service. We select them with due care, we bind them by written contract to data-protection obligations at least equivalent to ours, and we remain responsible to you for their processing.

Our sub-processors:

Sub-processorFunctionProcessing locationTransfer safeguard
Google Cloud PlatformHosting, database, object storageEU (europe-west1, Belgium)Within EEA
CloudflareDNS, CDN, edge securityGlobal edge network (may include processing outside the EEA)SCC where applicable
PostHogProduct and website analyticsUS or EU Cloud optionWithin EEA or SCC (+ DPF where certified)
NangoOAuth token management and API proxy (Google/Microsoft)US or EU optionWithin EEA or SCC (+ DPF where certified)
OpenAIAI generation, transcription (speech-to-text), embeddingsEU-region deployment for EU/UK; otherwise USSCC (+ DPF where certified)
Mistral AIOptical character recognitionEU (France)Within EEA
xAIText-to-speechUSSCC (+ DPF where certified)
TurbopufferVector search index (embeddings)US or EU optionWithin EEA or SCC (+ DPF where certified)
E2BIsolated execution environments for AI agentsUS or EU optionWithin EEA or SCC (+ DPF where certified)
ResendTransactional email (verification, notifications)US or EU optionWithin EEA or SCC (+ DPF where certified)

We may also disclose personal data where required to comply with a legal obligation or a lawful request from a public authority, to establish, exercise or defend legal claims, to enforce our agreements, or in connection with a merger, acquisition or reorganisation, always with appropriate safeguards. Where we are legally compelled to disclose data, we will, where lawful, notify the affected customer first.

An up-to-date list of sub-processors is available on request at privacy@referent.law, and we notify customers of material changes to the list.

  1. International transfers of personal data

We take a region-based approach and are transparent about it.

  • Customers in the EU and the UK. We process personal data within the European Economic Area, other than a limited text-to-speech function processed in the US under the safeguards described below.
  • Customers in other regions. Personal data may be processed outside the EEA, including in the United States, by the sub-processors listed in Section 8.

Where personal data is transferred outside the EEA (or the UK), we ensure an adequate level of protection using at least one of the following mechanisms:

  • the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) - our primary mechanism, and the corresponding UK International Data Transfer Addendum for UK transfers;
  • the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), where the recipient is certified, used as a supplementary mechanism;
  • a European Commission adequacy decision, where one applies;
  • where none of the above is available, a derogation under Article 49 GDPR (for example your explicit consent).

We assess the risk of each transfer (a transfer impact assessment) and apply additional technical and contractual safeguards where needed. You have the right to ask for more information about these safeguards, to receive a copy of the relevant Standard Contractual Clauses, and to object to transfers of your data outside the EEA (which may limit access to some features). Contact privacy@referent.law.

  1. Automated decision-making and profiling

We do not subject you to decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). AI features in the Service assist our users; a qualified lawyer reviews outputs and makes decisions.

  1. Intake forms and data handled on behalf of law firms

When you complete an intake form or provide information to a law firm through Referent, or when a lawyer places client and matter data into the Service, the law firm is the controller of that data and Referent acts as its processor. In that case:

  • the law firm decides why and how the data is used, and its own privacy notice applies;
  • we process the data only on the firm’s instructions to provide the Service, which may include AI-assisted processing and the international transfers described above;
  • to exercise your rights over that data, contact the relevant law firm; we will assist the firm and route to it any request we receive directly;
  • separately, and only to run and secure the intake service and prevent misuse, we process a minimal amount of data as our own controller, on the basis of our legitimate interest (Art. 6(1)(f)).

Law firms using Referent are responsible for giving the people whose data they process the information required by Articles 13-14 GDPR, including that their data may be processed using AI and transferred as described here. We provide firms with model information text and sub-processor details to support this.

  1. How long we keep personal data

We keep personal data only for as long as necessary for the purposes described in this Policy. To set retention periods we consider the amount, nature and sensitivity of the data, the potential risk of harm, the purposes, and our legal obligations.

As a general rule:

  • data we process to provide the Service under a contract (such as account, profile and support data) is kept for the contract term plus six (6) months;
  • data that may be relevant for tax or accounting inspections (such as billing and transaction records) is kept for five (5) years, as required by Polish tax and accounting law;
  • other data (such as website enquiries and correspondence, online-meeting records, social-media interactions and marketing data) is kept for six (6) months from the last communication, unless you withdraw consent earlier or a shorter period applies;
  • website and product analytics are kept for the periods stated in the Cookie Policy.

When you ask us to delete your personal data, or when data reaches the end of its retention period, we remove it from the live Service without undue delay. Copies held in our encrypted backups are then cycled out and overwritten within 60 days. Where we act as a processor, data is deleted or returned on the firm’s instruction on termination, and copies held by our AI and infrastructure sub-processors are removed in line with their enterprise retention policies, which do not exceed the term of our agreement.

  1. How we keep personal data secure

We implement appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the risks and the nature of the data. These include, as applicable: encryption of data in transit (HTTPS/TLS) and at rest; application-level encryption of particularly sensitive credentials (for example email connection passwords); role-based access control, session tokens, and multi-factor / trusted-device authentication; separation of the production environment from development and testing; logging and auditing of access to and operations on personal data; regular backups held in the EEA; internal privacy and security policies, privacy-by-design and by-default, and staff confidentiality obligations and training; fraud- and abuse-detection mechanisms operating on system logs and identifiers; selection and review of sub-processors against recognised security standards (e.g. ISO 27001, SOC 2). We are pursuing SOC 2 certification.

No system is completely secure, but we work continuously to protect personal data and to detect, investigate and respond to incidents. Where a personal data breach is likely to result in a risk to your rights, we will notify the competent authority within 72 hours and, where required, affected individuals, in line with Articles 33-34 GDPR.

  1. Your rights

Subject to the conditions and exceptions in applicable law, you have the following rights in relation to your personal data. Where we act as a processor (Section 11), please direct requests to the relevant law firm; we will assist.

Access (Art. 15). To be told whether we process your data and to receive a copy of it, together with information about the processing.

Rectification (Art. 16). To have inaccurate data corrected and incomplete data completed.

Erasure (Art. 17). To have your data deleted where, for example, it is no longer necessary, you withdraw consent, or you successfully object.

Restriction (Art. 18). To have processing limited in certain circumstances, for example while you contest the accuracy of the data.

Portability (Art. 20). To receive data you provided, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means.

Objection (Art. 21). To object, on grounds relating to your situation, to processing based on our legitimate interests, and to object at any time to processing for direct marketing.

Withdraw consent (Art. 7(3)). Where processing is based on consent, to withdraw it at any time, without affecting processing carried out before withdrawal. You can unsubscribe from marketing emails using the link in each message.

Not to be subject to solely automated decisions (Art. 22). As explained in Section 10, we do not carry out such decision-making.

To exercise any of these rights, email privacy@referent.law. We may ask you to verify your identity. We respond within the period required by law, generally one (1) month, which may be extended for complex requests. Exercising your rights is free unless a request is manifestly unfounded or excessive.

  1. Complaints

If you believe our processing of your personal data infringes data-protection law, we would like the chance to address it first - please contact privacy@referent.law. You also have the right to lodge a complaint with a supervisory authority.

  • Poland (our lead authority): Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland. Phone: +48 22 531 03 00 · Email: kancelaria@uodo.gov.pl · Web: uodo.gov.pl
  • United Kingdom: Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. Helpline: 0303 123 1113 · Web: ico.org.uk

You may also complain to the supervisory authority in your EU country of residence or work.

  1. Children

The Service is intended for professional use by adults and is not directed to children. We do not knowingly collect personal data from anyone under 18.

  1. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or the law. We will post the updated version here with a new effective date and, where changes are significant, take reasonable steps to notify you (for example by email or an in-Service notice).

  1. How to contact us

Privacy matters: privacy@referent.law
Controller: AI LAWTECH sp. z o.o., Henryka Sienkiewicza 36/5, 26-600 Radom, Poland

Turn your law firm AI-native

©2026 Referent. All rights reserved.

Explore

  • The AI-native law firm
  • Blog
  • MCP server
  • Switching guides
  • Alternatives
  • Comparisons
  • Rankings
  • Changelog
  • Status

Socials

  • YouTube
  • LinkedIn
  • X

Company

  • About
  • Security
  • Affiliate program
  • Partners

For users

  • Privacy Policy
  • Terms of Use
  • Cookie Policy
  • DPA

By clicking “Accept All”, you agree to the storing of cookies on your device to enhance site navigation and analyze site usage. Website analytics measure the website, not your practice. We measure visits to referent.law and do not observe, profile or analyze the work you do inside Referent. See Cookie Policy.

Privacy Preference Center

Cookie preferences

When you visit our website, we may store or retrieve information in your browser, mostly in the form of cookies. This information may relate to you, your preferences or your device, and is used primarily to make the site work as you expect. It does not usually identify you directly, but it allows us to provide a more personalized experience.

Referent is a legal practice management platform, and we treat confidentiality as a core commitment. You decide which categories of cookies you allow. Strictly necessary cookies are required for the site to function and cannot be switched off; all other categories are set only with your consent. Select a category below to learn more and change our default settings. Blocking certain categories may affect how the site works and which services we can offer.

For details on how we process personal data, see our Cookie Policy and Privacy Policy, which form part of our Terms of Service.

Controller: AI LAWTECH sp. z o.o., Henryka Sienkiewicza 36/5, 26-600 Radom, Poland (NIP 9482639603). General: contact@referent.law · Privacy: privacy@referent.law

Always active

These cookies are required for referent.law and the Referent application to function and cannot be switched off. They are set in response to actions that amount to a request for a service, signing in, keeping your session active, protecting your account and our systems against fraud and abuse, submitting forms, and saving your cookie preferences. You can block them in your browser, but parts of the site and the application will stop working.

These cookies enable the website to provide enhanced functionality and personalization. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly.

These cookies help us understand how visitors use referent.law - which pages are most and least popular, where traffic comes from, and how people move around the site, so we can improve it. This data is used for our own analytics reporting and is never linked to the client information held in your Referent workspace. If you do not allow these cookies, we cannot measure or improve site performance.

These cookies may be set by our advertising partners to measure the performance of our campaigns and to show you Referent advertising on other websites. They rely on identifiers unique to your browser and device, which qualify as personal data under the GDPR. If you do not allow them, we cannot measure which campaigns bring visitors to our site, and the Referent advertising you see elsewhere will be less relevant to you.