Privacy Policy

Last updated: June 2026

1. Who we are

Legal Leaf ("we", "us", "our") is a software platform that enables law firms and solicitors to manage group litigation cases, including claimant onboarding, identity verification, and document collection. We are the data controller for the personal data we process through this platform.

If you have any questions about this policy or how we handle your data, contact us at: privacy@legalleaf.io

2. What data we collect

We collect and process the following categories of personal data:

  • Identity data: name, date of birth, national identity number, and government-issued identification documents
  • Contact data: email address, phone number, postal address
  • Financial data: loan account details, mortgage information, and related financial records submitted as part of a legal claim
  • Document data: any documents you upload to the platform as part of your case, including signed letters of authority
  • Account data: username, password (stored in hashed form), account preferences
  • Usage data: IP address, browser type, pages visited, and activity logs for security and service improvement purposes

3. Why we collect it and our legal basis

We process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):

  • Contract performance: to provide you with the Legal Leaf service you have signed up to use, including claimant onboarding and document management
  • Legal obligation: to carry out identity verification (KYC) in accordance with applicable anti-money laundering and legal compliance requirements
  • Legitimate interests: to maintain the security of our platform, prevent fraud, and improve our service
  • Consent: where we ask for your consent specifically, such as for marketing communications — you may withdraw consent at any time

4. How we share your data

We do not sell your personal data. We may share it with:

  • The law firm managing your case: your solicitor or legal representative has access to your case data as the party responsible for your legal matter
  • Identity verification providers: we use third-party KYC services to verify your identity. These providers process your identity documents under their own privacy policies
  • Document signing providers: e-signature functionality is provided by a third-party service that processes your signed documents on our behalf
  • Infrastructure providers: our hosting and database providers process data on our behalf under data processing agreements
  • Legal or regulatory authorities: where required by law or court order

5. Data retention

We retain your personal data for as long as necessary to provide our service and comply with our legal obligations. For active cases, data is retained for the duration of the legal proceedings plus a period of 7 years to meet standard legal record-keeping requirements. You may request deletion of your account at any time subject to any overriding legal obligation to retain the data.

6. Your rights under GDPR

If you are based in the European Economic Area or the United Kingdom, you have the following rights:

  • Access: request a copy of the personal data we hold about you
  • Rectification: request correction of inaccurate or incomplete data
  • Erasure: request deletion of your data where we no longer have a lawful basis to retain it
  • Restriction: request that we limit how we use your data in certain circumstances
  • Portability: receive your data in a structured, machine-readable format
  • Objection: object to processing based on our legitimate interests

To exercise any of these rights, email us at privacy@legalleaf.io. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority — in Ireland this is the Data Protection Commission (dataprotection.ie).

7. International data transfers

We store data on servers located within the European Economic Area. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements.

8. Cookies

We use strictly necessary cookies to keep you logged in and maintain your session. We do not use advertising or tracking cookies. You can control cookies through your browser settings.

9. Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, and regular security reviews.

10. Changes to this policy

We may update this privacy policy from time to time. We will notify you of significant changes by email or by a notice on the platform. The date at the top of this page reflects when it was last updated.