§ Legal
Privacy Policy
What we hold, why we hold it, who else sees it and how to make us stop.
The three answers most people want. Your case documents are stored encrypted, and are sent to our AI provider only to produce the analysis you asked for. We do not sell them, publish them, or share them with anyone else. You can delete a matter, and its documents, at any time, and deletion removes the files from disk rather than hiding them.
Clause 1Who we are
Rank First Technologies Private Limited, CIN U58201PB2026PTC068900, of F-542, Phase 8A, Sector 75, Mohali, Punjab 140308, India, operates Litora UK.
For privacy questions write to privacy@litorauk.com. Complaints can be sent to complaints@litorauk.com.
This policy is written to meet the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Clause 2Controller and processor
The distinction matters here more than it does on most services, so it is worth being exact.
- We are the controller of your account data
- Your name, email, organisation, billing details and how you use the platform. We decide why and how that is processed.
- We are a processor of your case material
- The documents you lodge against a matter belong to you and, usually, describe your clients. You decide what goes in and why. We process it on your instructions, to produce the analysis you asked for, and for nothing else.
If you need a data processing agreement for your own compliance file, ask us at privacy@litorauk.com and we will provide one.
Clause 3What we collect
| Category | What it includes |
|---|---|
| Account | Name, email address, password (stored only as a bcrypt hash), organisation name and type, role, telephone number and bar or roll number where you give one. |
| Authentication | Session records, sign-in timestamps, IP address at sign-in, two-factor secret (encrypted), recovery codes (hashed). |
| Billing | Wallet top-ups and the bank-transfer references you give us, wallet ledger entries, invoices, billing address and tax identifiers. We never receive card or bank login details. |
| Case material | Documents you upload, matter titles, party names, notes, and everything the analysis derives from them. |
| Usage | Which features were used, how many agents were run, token counts used to charge your wallet, and error logs. |
| Technical | IP address, browser and device type, and timestamps, kept in server logs. |
| Correspondence | What you send us through the contact form or by email, and our replies. |
Clause 4Case material specifically
Case files routinely contain other people's personal data, and often sensitive categories of it: health information, criminal allegations, financial details, family circumstances. We treat the whole of a matter as sensitive by default rather than trying to classify it.
- Documents are encrypted in transit and at rest.
- They are readable only within the matter they were lodged against, by users of your organisation who have been given access to it.
- They are not indexed for search across organisations, not aggregated, and not analysed for any purpose of our own.
- Our staff do not read them as a matter of routine. See clause 8.
Whether you are permitted to upload a given client's material, and whether doing so affects privilege in your jurisdiction, is a matter for you and your own advisers. We have set out the facts here so that you can decide on an accurate basis.
Clause 5Why we process it
- To create and run your account, and to authenticate you.
- To perform the analysis you instruct: reading documents, running agents, producing reports.
- To take payment, issue invoices, charge AI usage to your wallet and maintain the wallet ledger.
- To provide support when you ask for it.
- To keep the platform secure, detect abuse and enforce rate limits.
- To meet our legal, accounting and tax obligations.
- To improve the platform — using aggregate usage statistics, never the content of your matters.
Clause 6Lawful basis
Where data protection law requires a lawful basis, ours are: performance of our contract with you (running the account and the analysis); our legitimate interests (security, abuse prevention, aggregate product improvement), balanced against your rights; legal obligation (tax and accounting records); and consent, where we ask for it and only for what we asked.
For case material we act on your instructions as processor, and your own lawful basis for holding that material is the one that governs.
Clause 7The AI provider
The analysis is performed by a third-party large language model provider. To produce it, the relevant portions of your matter are transmitted to that provider over an encrypted connection.
What the provider does with what it receives is set by the provider's own terms, not by us. We link to them rather than restate them, because they can change and because an undertaking given on another company's behalf is not one we could honour. Read them before you send anything you could not send to a third party at all.
What we can commit to is our side: we do not sell your material, we do not publish it, and we send it to no party other than the provider that reads it for you.
The identity of the current provider and its published data policy are available on request, and are listed in the data processing agreement.
Clause 8Who else we share with
We do not sell personal data. We share it only with:
- Our AI provider
- As described in clause 7, to perform the analysis.
- Our hosting provider
- Which stores the application and its data.
- Our bank
- Which receives your bank-transfer top-ups. We never receive your bank login details.
- Our email provider
- To deliver verification, reset and notification emails.
- Professional advisers
- Accountants and lawyers, where necessary and under a duty of confidence.
- Authorities
- Where we are legally compelled. Where we are lawfully able to tell you first, we will.
- A successor
- If the business is transferred, subject to the same protections. You would be told.
Our own staff access case material only where you have asked us to investigate a specific problem, where it is strictly necessary to keep the platform running, or where we are compelled by law. Every such access is written to the audit log.
Clause 9International transfers
We are established in India, and our AI provider and some infrastructure providers are established in other countries, including the United States. Personal data you give us is therefore transferred out of the United Kingdom.
Where data is transferred from the UK we rely on a lawful transfer mechanism under the UK GDPR — UK adequacy regulations where they apply, or the ICO's International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, with a transfer risk assessment. If you need the specifics for your own compliance assessment, ask and we will give them to you.
Clause 10How long we keep it
| Data | Retention |
|---|---|
| Case documents and matters | Until you delete them. Deleted matters are removed from live systems immediately and purged from backups within 30 days. |
| Account data | For as long as the account is open, then 90 days after closure. |
| Billing records and invoices | 6 years from the end of the financial year, to meet accounting and tax record requirements. |
| Wallet ledger | 6 years, because it forms part of the billing record. |
| Audit and security logs | 12 months. |
| Server and error logs | 90 days. |
| Support correspondence | 24 months. |
Clause 11How we protect it
Encryption in transit and at rest; passwords stored as bcrypt hashes and never recoverable; two-factor authentication available on every account; access to a matter restricted by role within your organisation; document storage placed outside the web root and blocked from direct URL access; every significant action written to an audit log; rate limiting and lockout on authentication. The security statement sets this out in more detail.
No system is perfectly secure, and we do not claim otherwise. What we can say is what we actually do.
Clause 12Your rights
Depending on where you are, you may have the right to: obtain a copy of your data; correct it; delete it; restrict or object to processing; receive it in a portable format; withdraw consent where consent was the basis; and complain to a supervisory authority.
Exercise any of them by writing to privacy@litorauk.com. We respond within 30 days. We may ask you to verify your identity first, which is a protection for you rather than an obstacle.
Where a request concerns case material for which you are the controller and we are the processor, we will act on your instruction rather than deciding the question ourselves.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk or on 0303 123 1113. We would appreciate the chance to deal with your concern first.
Clause 13Cookies
We use the small number of cookies necessary to keep you signed in and to protect forms against cross-site request forgery. We do not use advertising cookies and we do not run third-party trackers. See the cookie policy.
Clause 14Children
The platform is not for anyone under 18 and we do not knowingly collect their data as account holders. Case material may of course concern minors; it is handled with the same protections as all other case material, and you remain responsible for the lawfulness of uploading it.
Clause 15If something goes wrong
If a personal data breach occurs that is likely to result in a risk to affected people, we will notify the relevant authority within the period the law requires, and tell affected customers without undue delay. We will tell you what happened, what data was involved, what we have done and what you should do.
To report a suspected vulnerability or breach, write to security@litorauk.com. We will not pursue researchers who act in good faith and give us a reasonable opportunity to fix the problem.
Clause 16Changes to this policy
We may update this policy. Material changes are notified by email to account holders at least 14 days before they take effect, and the date at the top of this page always shows the current version.
ContactHow to reach us about this document
Access requests, deletion requests, data processing agreements and anything else about privacy.
- By email
- privacy@litorauk.com
- By post
- Rank First Technologies Private Limited (incorporated in India, CIN U58201PB2026PTC068900)
F-542, Phase 8A, Sector 75, Mohali, Punjab 140308, India - Complaints
- How to complain — complaints@litorauk.com
This document is governed by the law of England and Wales, and the courts referred to in the terms of service have exclusive jurisdiction over any dispute arising from it.