1. Introduction
Welcome to Wansom AI ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our legal AI platform and services (collectively, the "Services").
By accessing or using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.
2. Information We Collect
2.1 Personal Information You Provide
We collect information that you voluntarily provide to us, including:
- Account Information: Name, email address, password, and organization details when you register for an account
- Profile Information: Professional details, jurisdiction, practice areas, and other information you add to your profile
- Communication Data: Information you provide when contacting our support team or communicating with us
- Payment Information: Billing address and payment details (processed securely through third-party payment processors)
2.2 Information Collected Automatically
When you use our Services, we automatically collect:
- Usage Data: Your interactions with the Services, including AI queries, documents uploaded, features used, and time spent
- Device Information: Device type, operating system, browser type, IP address, and unique device identifiers
- Log Data: Server logs including access times, pages viewed, and referring URLs
- Cookies and Similar Technologies: We use cookies, web beacons, and similar tracking technologies to collect information about your browsing activities
2.3 Content and Documents
We collect and store the content you create, upload, or share through our Services, including:
- Legal documents you upload or create
- Chat conversations with our AI assistant
- Projects and workspace data
- Annotations, notes, and comments
2.4 Third-Party Integrations
When you connect third-party services to your account:
- Google Account: With your permission, we access your Google Calendar events, Gmail messages (read-only and draft composition), and basic profile information
- OAuth Tokens: We securely store OAuth tokens to maintain these integrations
- Third-Party Data: Information from integrated services as necessary to provide the requested functionality
3. How We Use Your Information
We use the information we collect to:
- Provide Services: Operate, maintain, and improve our AI-powered legal platform
- Process AI Requests: Analyze your queries and documents to provide AI-generated legal insights, drafts, and recommendations
- Personalization: Customize your experience based on your jurisdiction, practice areas, and usage patterns
- Communication: Send you service-related notifications, updates, security alerts, and support messages
- Analytics: Understand how users interact with our Services to improve functionality and user experience
- Security: Detect, prevent, and address technical issues, fraud, and unauthorized access
- Legal Compliance: Comply with applicable laws, regulations, and legal processes
- Marketing: Send promotional communications about new features, products, and offers (with your consent where required)
4. AI Processing and Data Usage
Our Services utilize artificial intelligence to provide legal assistance. Here's how your data is processed:
- AI Model Processing: Your queries and documents are processed by AI models to generate responses and insights
- Training Data: We do not use your personal documents or queries to train AI models without your explicit consent
- Quality Improvement: We may use aggregated, anonymized data to improve our AI models and Services
- Third-Party AI Providers: We work with trusted AI service providers who process data in accordance with strict confidentiality and security standards
5. Information Sharing and Disclosure
We may share your information in the following circumstances:
5.1 With Your Consent
We share information when you explicitly authorize us to do so, such as when connecting third-party services.
5.2 Service Providers
We engage trusted third-party service providers to perform functions on our behalf, including:
- Cloud hosting and storage providers
- AI and machine learning service providers
- Payment processors
- Email and communication services
- Analytics providers
These providers have access to your information only to perform specific tasks and are obligated to protect your data.
5.3 Organization Members
If you're part of an organization account, certain information may be visible to other members and administrators within your organization.
5.4 Legal Requirements
We may disclose your information if required by law or in response to valid legal processes, including:
- Compliance with legal obligations
- Response to lawful requests from public authorities
- Protection of our rights, property, or safety
- Prevention of fraud or security threats
5.5 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
6. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: Data is encrypted in transit using TLS/SSL and at rest using industry-standard encryption algorithms
- Access Controls: Strict access controls ensure only authorized personnel can access personal data
- Security Monitoring: Continuous monitoring for security threats and vulnerabilities
- Regular Audits: Periodic security audits and assessments
- Secure Authentication: Multi-factor authentication options and secure password requirements
However, no method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as necessary to:
- Provide you with our Services
- Comply with legal obligations
- Resolve disputes and enforce agreements
- Maintain business records
When you delete your account, we will delete or anonymize your personal information within 90 days, except where retention is required by law or for legitimate business purposes.
8. Your Privacy Rights
Depending on your location, you may have the following rights:
- Access: Request access to the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Data Portability: Request a copy of your data in a structured, machine-readable format
- Objection: Object to processing of your personal information
- Restriction: Request restriction of processing in certain circumstances
- Withdraw Consent: Withdraw consent where processing is based on consent
- Opt-Out: Opt-out of marketing communications at any time
To exercise these rights, please contact us at law@wansom.ai. We will respond to your request within 30 days.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable data protection laws.
10. Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
11. Third-Party Links and Services
Our Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
13. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, you have rights under the General Data Protection Regulation (GDPR), including those outlined in Section 8 above. You also have the right to lodge a complaint with your local data protection authority.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:
- Posting the updated policy on our website
- Updating the "Last Updated" date
- Sending you an email notification (for significant changes)
Your continued use of the Services after changes are posted constitutes acceptance of the updated Privacy Policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us: