Legal posture
Privacy
LEGERIS's privacy posture in detail — what we collect, how we use it, how we protect it, and the explicit “no training on client data” disclosure.
Last reviewed 26 July 2026
Section 01
Scope of this notice
This Privacy Notice explains how LEGERIS handles personal data and business data submitted through the public marketing site and the LEGERIS audit platform.
It is written for buyers, operators, finance teams, vendors, and reviewers who need a clear view of what is collected, why it is processed, and how the data is protected.
Section 02
Data we collect
We may collect contact details, company details, messages submitted through the contact form, scheduling metadata, support correspondence, account information, invoice files, contract excerpts, audit evidence, and system metadata needed to operate the service.
We do not ask users to submit consumer payment-card data, protected health information, or unrelated personal records to the audit workflow.
Section 03
Audit documents and evidence
Audit documents may include invoices, purchase orders, contracts, delivery records, rate cards, and supporting evidence provided for review. These materials are processed to extract facts, compare evidence, produce findings, and support reviewer decisions.
LEGERIS treats submitted audit evidence as customer-controlled material. We do not sell it or use it for unrelated advertising purposes.
Section 04
How we use data
We use data to provide the service, validate audit evidence, operate support workflows, respond to inquiries, improve reliability, secure the platform, and maintain defensible records of service activity.
Where the platform uses AI-assisted extraction or interpretation, deterministic controls remain responsible for final structured financial truth.
Section 05
No training on client data
Client invoice data, contract data, audit findings, and uploaded evidence are never used to train, fine-tune, or otherwise improve any AI model.
Section 06
Legal bases and lawful grounds
Where LEGERIS processes personal data, it relies on the lawful bases set out in Article 6 of the UK GDPR: performance of a contract (and taking steps at your request before entering a contract), compliance with a legal obligation, our legitimate interests in operating, securing, and improving the service (balanced against your rights), and consent where consent is the appropriate basis.
For customers and data subjects outside the United Kingdom, equivalent lawful-basis frameworks under applicable local data-protection law apply. Where LEGERIS acts as a processor of personal data on a customer’s behalf, the customer is the controller and determines the lawful basis; LEGERIS processes only on the customer’s documented instructions under a data processing agreement.
Section 07
Service providers and subprocessors
LEGERIS uses service providers for hosting, storage, document processing, email delivery, scheduling, security, and AI-assisted document workflows. We use provider agreements intended to restrict processing to service delivery and security purposes.
Named subprocessor details are available through the trust and security review process by contacting security@legeris.ai.
Section 08
Retention
We retain data for as long as needed to provide the service, meet legal and security obligations, resolve disputes, enforce agreements, and maintain auditability of customer-directed workflows.
Platform retention defaults and deletion workflows may vary by contract, workspace configuration, and legal hold requirements.
Section 09
Security controls
LEGERIS applies technical and organizational controls intended to protect submitted evidence, including encryption in transit, access control, role-aware handling, and operational monitoring.
No internet-delivered service can guarantee absolute security, but security concerns and responsible disclosures should be directed to security@legeris.ai.
Section 10
International processing
LEGERIS may process data in jurisdictions where we or our service providers operate. Where personal data is transferred outside the United Kingdom to a country without UK adequacy regulations, we rely on an appropriate transfer mechanism — the ICO International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK Addendum — supported by a transfer risk assessment and appropriate technical and organisational safeguards.
Enterprise customers may request details of the specific processing regions and transfer mechanisms applicable to their engagement before signing, by contacting security@legeris.ai.
Section 11
Privacy rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. Enterprise customers may need to route certain requests through their workspace administrator or contracting entity.
Privacy requests may be sent to privacy@legeris.ai, and security-related data-processing questions may be sent to security@legeris.ai.
Section 12
Changes to this notice
We may update this Privacy Notice as the product, legal requirements, and operating model evolve. Material changes will be reflected on this page with an updated review date.
Questions about this notice may be sent to legal@legeris.ai.
Privacy requests
For privacy access, deletion, correction, or data-processing questions, use the dedicated privacy mailbox.