Privacy Policy
Effective date: August 5, 2026
At Referent, protecting the confidentiality of the people and matters our customers work with is central to what we do. This Privacy Policy explains, in detail, how AI LAWTECH sp. z o.o. (“Referent”, “we”, “us”, “our”) collects, uses, shares, stores and protects personal data, and the rights available to you under the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable national law including the Polish Act on the Protection of Personal Data. It applies to our website at referent.law, our application at app.referent.law, and to intake forms and related services we provide (together, the “Service”).
- Summary
Referent is a legal practice management platform with AI features, built for law firms and independent lawyers. We act as a controller for data about our website visitors and account holders, and as a processor for the client and matter data that firms place into the Service, including data collected through intake forms.
In short: we use personal data to provide and secure the Service; we ask for your consent before setting analytics cookies; AI assists our users but never decides anything about you on its own; for customers in the EU and the UK we process personal data within the European Economic Area, other than a limited text-to-speech function processed in the US under appropriate safeguards; we do not sell personal data; and we do not allow AI providers to train their models on your data. Full detail is below.
- Who is responsible for your data
2.1. Controller. AI LAWTECH sp. z o.o., Henryka Sienkiewicza 36/5, 26-600 Radom, Poland. NIP: 9482639603. Email for all privacy matters: privacy@referent.law.
2.2. Establishment and lead supervisory authority. Referent is established in Poland. Our lead supervisory authority for the GDPR is the Polish data protection authority (UODO, Section 15). Because we are established in the EU, we are not required to appoint an EU representative under Article 27 GDPR.
2.3. Data protection contact. We have appointed a person responsible for data protection questions. You can reach them at privacy@referent.law.
- The two roles we play
Because of how the Service works, we handle personal data in two distinct roles, and it matters which one applies.
Controller. For personal data about our website visitors, prospective customers, and the lawyers and staff who register and use a Referent account, we determine why and how the data is processed. This Policy governs that processing.
Processor. When a user uploads client files, matter documents, emails or other content into the Service, or when an intake form collects information from a firm’s prospective client, the law firm is the controller and Referent is its processor. We process that data only on the firm’s documented instructions, under a Data Processing Agreement. The firm’s own privacy notice applies to that data. Section 11 explains what this means for intake respondents and the people whose data appears in matters.
- Definitions
4.1. “Personal data” means any information relating to an identified or identifiable individual.
4.2. “Processing” means any operation performed on personal data.
4.3. “Controller” and “processor” have the meanings given in the GDPR.
4.4. “Special categories of data” means data revealing health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, sex life or sexual orientation, and (treated with equivalent care) data on criminal convictions and offences.
4.5. “Sub-processor” means a third party we engage to process personal data on our behalf.
- The personal data we collect, why, and on what legal basis
We collect only what we need. The tables below set out, for each group of people, what we collect, why, the legal basis under Article 6 GDPR, and how long we keep it (see also Section 12).
5.1 Website visitors, enquirers and prospective customers
This section covers people who visit our website, contact us, engage with us on social media, or subscribe to our updates - including those who are not (yet) Referent users.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Technical data (IP address, device and browser type, pages viewed, referrer) | Operate, secure and troubleshoot the website | Legitimate interest, Art. 6(1)(f) | 6 months |
| Analytics data collected via cookies | Understand and improve the website | Consent, Art. 6(1)(a) | Per the Cookie Policy |
| Enquiry and correspondence data: your name, contact details and the content of your communications when you reach us through our contact form, by email, through a messenger, by sending an offer or proposal, or by phone | Respond to you, evaluate and pursue a possible business relationship, and keep a record | Steps prior to a contract, Art. 6(1)(b); legitimate interest, Art. 6(1)(f) | 6 months after our last contact; if a contract results, contract term + 6 months |
| Online-meeting data (audio and, where used, transcripts of calls with us) | Hold and document meetings conducted online | Legitimate interest, Art. 6(1)(f) | 6 months |
| Social-media data: your handle, public profile information and the content of interactions when you engage with our accounts, for example on LinkedIn, Instagram, X/Twitter, Facebook or Telegram (this list is not exhaustive) | Respond to you and manage our social-media presence | Legitimate interest, Art. 6(1)(f); consent where applicable | 6 months |
| Newsletter and marketing-contact data (email, name, preferences) | Send you the newsletter and marketing communications you asked for | Consent, Art. 6(1)(a) | Until you unsubscribe / withdraw consent |
Where a meeting with us is held online, we may use transcription tools, and we make participants aware when a call is being transcribed.
5.2 Account holders (lawyers and firm staff)
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Registration and profile data (name, work email, phone, organisation, role) | Create and administer your account; provide the Service | Performance of a contract, Art. 6(1)(b) | Contract term + 6 months |
| Authentication data (credentials, session and trusted-device tokens) | Log you in securely; protect the account | Performance of a contract; legitimate interest in security, Art. 6(1)(f) | Session / short-lived tokens |
| Usage and product-analytics data | Operate, secure and improve the Service | Legitimate interest, Art. 6(1)(f); consent where set via cookies | 6 months |
| Support communications | Provide support; keep records | Legitimate interest; performance of a contract | Contract term + 6 months |
| Billing and transaction data of the subscribing firm | Manage the subscription and payments | Performance of a contract, Art. 6(1)(b); legal obligation (accounting), Art. 6(1)(c) | 5 years (Polish tax and accounting law) |
We do not intentionally collect special categories of data about our account holders. Users may enter such data as part of matter content; that content is handled under our processor role (Section 11), not for our own purposes.
5.3 Data we do not process for our own purposes
Client files, matter documents, emails, calendar entries and intake responses that firms place into the Service are processed under our processor role, on the firm’s instructions. We do not use that content for our own purposes, and we do not use it, or allow our providers to use it, to train generative AI models (Section 7).
- Cookies and similar technologies
We use strictly necessary cookies to run the Service, and analytics cookies only with your consent. How consent is obtained and withdrawn, and the full list of cookies, are set out in our separate Cookie Policy. Under Polish law (Prawo komunikacji elektronicznej) non-essential cookies are set only after you consent.
- Artificial intelligence: how we use it and how we keep it accountable
The Service uses artificial intelligence, including large language models, to assist lawyers with tasks such as drafting, summarisation, classification, transcription, optical character recognition and search. We treat AI as a serious compliance area and apply the following commitments.
AI assists; it does not decide. AI features support the user; a lawyer always reviews and decides. The Service does not make decisions producing legal or similarly significant effects about any individual on a solely automated basis (see Section 10 on Article 22 GDPR). You can modify, reject or regenerate AI-assisted output.
Transparency (Article 50 EU AI Act). We make clear when you are interacting with AI, and AI-generated content is identifiable as such.
AI providers and locations. To produce a result, relevant content may be sent to the AI sub-processors listed in Section 8 for processing (for example, text for drafting, a file for OCR, audio for transcription). For customers in the EU and the UK, this AI processing takes place within the EEA using EU-region enterprise deployments, except for text-to-speech processing via xAI, which is carried out in the US under the safeguards described in Section 8 and Section 9.
We do not use AI model providers based in China.
No training on your data. We contractually prohibit our AI providers from using your data, or the content processed through the Service, to train or improve their general-purpose models. We do not place client content into any training dataset.
Logging of AI calls. For each connection to an AI service we record the provider, processing location and model version, so that the flow of data is auditable.
Quality access by our team. Where our technical staff need to review data to maintain and improve the quality of the Service, this is done on a least-privilege, just-in-time basis, logged, and under confidentiality obligations. By default our staff work with redacted traces and aggregated metrics rather than raw client content, and we never build a training dataset from client content.
- Who we share personal data with (recipients and sub-processors)
We share personal data with service providers (“sub-processors”) who process it on our behalf, strictly to provide the Service. We select them with due care, we bind them by written contract to data-protection obligations at least equivalent to ours, and we remain responsible to you for their processing.
Our sub-processors:
| Sub-processor | Function | Processing location | Transfer safeguard |
|---|---|---|---|
| Google Cloud Platform | Hosting, database, object storage | EU (europe-west1, Belgium) | Within EEA |
| Cloudflare | DNS, CDN, edge security | Global edge network (may include processing outside the EEA) | SCC where applicable |
| PostHog | Product and website analytics | US or EU Cloud option | Within EEA or SCC (+ DPF where certified) |
| Nango | OAuth token management and API proxy (Google/Microsoft) | US or EU option | Within EEA or SCC (+ DPF where certified) |
| OpenAI | AI generation, transcription (speech-to-text), embeddings | EU-region deployment for EU/UK; otherwise US | SCC (+ DPF where certified) |
| Mistral AI | Optical character recognition | EU (France) | Within EEA |
| xAI | Text-to-speech | US | SCC (+ DPF where certified) |
| Turbopuffer | Vector search index (embeddings) | US or EU option | Within EEA or SCC (+ DPF where certified) |
| E2B | Isolated execution environments for AI agents | US or EU option | Within EEA or SCC (+ DPF where certified) |
| Resend | Transactional email (verification, notifications) | US or EU option | Within EEA or SCC (+ DPF where certified) |
We may also disclose personal data where required to comply with a legal obligation or a lawful request from a public authority, to establish, exercise or defend legal claims, to enforce our agreements, or in connection with a merger, acquisition or reorganisation, always with appropriate safeguards. Where we are legally compelled to disclose data, we will, where lawful, notify the affected customer first.
An up-to-date list of sub-processors is available on request at privacy@referent.law, and we notify customers of material changes to the list.
- International transfers of personal data
We take a region-based approach and are transparent about it.
- Customers in the EU and the UK. We process personal data within the European Economic Area, other than a limited text-to-speech function processed in the US under the safeguards described below.
- Customers in other regions. Personal data may be processed outside the EEA, including in the United States, by the sub-processors listed in Section 8.
Where personal data is transferred outside the EEA (or the UK), we ensure an adequate level of protection using at least one of the following mechanisms:
- the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) - our primary mechanism, and the corresponding UK International Data Transfer Addendum for UK transfers;
- the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), where the recipient is certified, used as a supplementary mechanism;
- a European Commission adequacy decision, where one applies;
- where none of the above is available, a derogation under Article 49 GDPR (for example your explicit consent).
We assess the risk of each transfer (a transfer impact assessment) and apply additional technical and contractual safeguards where needed. You have the right to ask for more information about these safeguards, to receive a copy of the relevant Standard Contractual Clauses, and to object to transfers of your data outside the EEA (which may limit access to some features). Contact privacy@referent.law.
- Automated decision-making and profiling
We do not subject you to decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). AI features in the Service assist our users; a qualified lawyer reviews outputs and makes decisions.
- Intake forms and data handled on behalf of law firms
When you complete an intake form or provide information to a law firm through Referent, or when a lawyer places client and matter data into the Service, the law firm is the controller of that data and Referent acts as its processor. In that case:
- the law firm decides why and how the data is used, and its own privacy notice applies;
- we process the data only on the firm’s instructions to provide the Service, which may include AI-assisted processing and the international transfers described above;
- to exercise your rights over that data, contact the relevant law firm; we will assist the firm and route to it any request we receive directly;
- separately, and only to run and secure the intake service and prevent misuse, we process a minimal amount of data as our own controller, on the basis of our legitimate interest (Art. 6(1)(f)).
Law firms using Referent are responsible for giving the people whose data they process the information required by Articles 13-14 GDPR, including that their data may be processed using AI and transferred as described here. We provide firms with model information text and sub-processor details to support this.
- How long we keep personal data
We keep personal data only for as long as necessary for the purposes described in this Policy. To set retention periods we consider the amount, nature and sensitivity of the data, the potential risk of harm, the purposes, and our legal obligations.
As a general rule:
- data we process to provide the Service under a contract (such as account, profile and support data) is kept for the contract term plus six (6) months;
- data that may be relevant for tax or accounting inspections (such as billing and transaction records) is kept for five (5) years, as required by Polish tax and accounting law;
- other data (such as website enquiries and correspondence, online-meeting records, social-media interactions and marketing data) is kept for six (6) months from the last communication, unless you withdraw consent earlier or a shorter period applies;
- website and product analytics are kept for the periods stated in the Cookie Policy.
When you ask us to delete your personal data, or when data reaches the end of its retention period, we remove it from the live Service without undue delay. Copies held in our encrypted backups are then cycled out and overwritten within 60 days. Where we act as a processor, data is deleted or returned on the firm’s instruction on termination, and copies held by our AI and infrastructure sub-processors are removed in line with their enterprise retention policies, which do not exceed the term of our agreement.
- How we keep personal data secure
We implement appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the risks and the nature of the data. These include, as applicable: encryption of data in transit (HTTPS/TLS) and at rest; application-level encryption of particularly sensitive credentials (for example email connection passwords); role-based access control, session tokens, and multi-factor / trusted-device authentication; separation of the production environment from development and testing; logging and auditing of access to and operations on personal data; regular backups held in the EEA; internal privacy and security policies, privacy-by-design and by-default, and staff confidentiality obligations and training; fraud- and abuse-detection mechanisms operating on system logs and identifiers; selection and review of sub-processors against recognised security standards (e.g. ISO 27001, SOC 2). We are pursuing SOC 2 certification.
No system is completely secure, but we work continuously to protect personal data and to detect, investigate and respond to incidents. Where a personal data breach is likely to result in a risk to your rights, we will notify the competent authority within 72 hours and, where required, affected individuals, in line with Articles 33-34 GDPR.
- Your rights
Subject to the conditions and exceptions in applicable law, you have the following rights in relation to your personal data. Where we act as a processor (Section 11), please direct requests to the relevant law firm; we will assist.
Access (Art. 15). To be told whether we process your data and to receive a copy of it, together with information about the processing.
Rectification (Art. 16). To have inaccurate data corrected and incomplete data completed.
Erasure (Art. 17). To have your data deleted where, for example, it is no longer necessary, you withdraw consent, or you successfully object.
Restriction (Art. 18). To have processing limited in certain circumstances, for example while you contest the accuracy of the data.
Portability (Art. 20). To receive data you provided, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means.
Objection (Art. 21). To object, on grounds relating to your situation, to processing based on our legitimate interests, and to object at any time to processing for direct marketing.
Withdraw consent (Art. 7(3)). Where processing is based on consent, to withdraw it at any time, without affecting processing carried out before withdrawal. You can unsubscribe from marketing emails using the link in each message.
Not to be subject to solely automated decisions (Art. 22). As explained in Section 10, we do not carry out such decision-making.
To exercise any of these rights, email privacy@referent.law. We may ask you to verify your identity. We respond within the period required by law, generally one (1) month, which may be extended for complex requests. Exercising your rights is free unless a request is manifestly unfounded or excessive.
- Complaints
If you believe our processing of your personal data infringes data-protection law, we would like the chance to address it first - please contact privacy@referent.law. You also have the right to lodge a complaint with a supervisory authority.
- Poland (our lead authority): Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland. Phone: +48 22 531 03 00 · Email: kancelaria@uodo.gov.pl · Web: uodo.gov.pl
- United Kingdom: Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. Helpline: 0303 123 1113 · Web: ico.org.uk
You may also complain to the supervisory authority in your EU country of residence or work.
- Children
The Service is intended for professional use by adults and is not directed to children. We do not knowingly collect personal data from anyone under 18.
- Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices or the law. We will post the updated version here with a new effective date and, where changes are significant, take reasonable steps to notify you (for example by email or an in-Service notice).
- How to contact us
Privacy matters: privacy@referent.law
Controller: AI LAWTECH sp. z o.o., Henryka Sienkiewicza 36/5, 26-600 Radom, Poland