MyLawOffice
Privacy Policy
Last updated: 6 July 2026
Who we are
MyLawOffice is a workspace for lawyers operated by Alpha Tech Solutions ("we", "us"). This policy explains what personal data we collect through the MyLawOffice website and applications, why we collect it, who we share it with — including the third-party AI provider that powers the AI assistant — and the rights you have over it.
Data we collect
We collect the following categories of data:
- Account details: first and last name, email address and phone number, provided when you register. Your password is stored only as a secure hash.
- Workspace content: the clients, cases, documents, notes, deadlines, document templates, calendar entries and AI chat history you store in MyLawOffice. This content is encrypted on your device before it reaches us, and only you hold the key that can read it.
- Organisational fields: so the apps can sort your records and send you reminders, a small set of structured fields is stored in readable form — the dates and times of deadlines and calendar entries, client details such as date of birth, gender, marital status and identity-document type and validity dates, and technical details such as file sizes.
- Messages you send us through the contact form or by email.
- Technical and security data: IP address, browser and device type, a name and identifier for each device you sign in from, sign-in history and trusted-device status, used to keep your account secure.
- Crash reports: if an app encounters an error, it sends us a report with the app version, operating system, device model and identifier, language, the technical error details, and the IP address of the submission. Crash reports can also be sent before you sign in, in which case they are anonymous.
- AI usage statistics: the number of AI requests you make and the amount of text processed (token counts) — not the content itself.
AI assistant and third-party AI processing
MyLawOffice includes an optional AI assistant that drafts legal documents. When you use it, the request you type, the history of that AI conversation and any case context you choose to attach are sent to our server in readable form (protected in transit by encryption) and forwarded to OpenAI, our AI provider, which generates the response. This is the only feature in which workspace content leaves end-to-end encryption — and only the excerpts you explicitly include in the conversation.
We do not keep your requests, the attached context or the generated documents on our servers; we record only usage counters (number of requests and token counts). Your AI chat history is stored and synced across your devices end-to-end encrypted, like the rest of your workspace.
OpenAI processes this data as our service provider under its API terms, which do not permit it to use the data to train its models; it may retain the data for a limited period to monitor for abuse. Processing may take place outside the European Economic Area, in which case the transfer is protected by the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism.
If you never use the AI assistant, none of your data is sent to any AI provider.
How we use your data
We use your data only to:
- Provide and operate the service, including authentication, email verification, two-factor authentication and synchronisation between your devices.
- Generate AI documents when you request them, as described above.
- Send you service emails, such as verification links, security codes and account notices.
- Respond to support requests and messages you send us.
- Diagnose and fix crashes and errors in the applications.
- Protect the service against abuse, fraud and unauthorised access.
- Measure how the public website is used — only with your consent through the cookie banner.
- Comply with our legal obligations.
Legal bases
We process your data under the General Data Protection Regulation (GDPR) on the basis of the performance of our contract with you (operating your account and the features you invoke, including the AI assistant), our legitimate interest in keeping the service secure and reliable (security logs, crash reports), your consent (website analytics cookies), and compliance with our legal obligations. Where we rely on consent, you can withdraw it at any time.
Security and encryption
Your workspace content is protected with end-to-end, post-quantum encryption (ML-KEM-768): the private key is generated once, delivered only to you, and is never stored on our servers — which also means we cannot recover it for you. Passwords are stored only as secure hashes, two-factor secrets are stored encrypted, and access to your account is additionally protected by email verification and optional two-factor authentication.
Sharing your data
We do not sell your personal data and we do not share it with third parties for advertising. We use a small number of service providers strictly to operate the platform, each processing data only on our instructions:
- OpenAI (USA): generates the responses of the AI assistant, as described above.
- Amazon Web Services (S3, EU region — Stockholm): stores your documents in their encrypted form.
- Mailjet: delivers our service emails.
- Cloudflare Turnstile: protects our public forms against automated abuse.
- Google Analytics and Cookiebot: website usage statistics and consent management on the public site, activated only if you accept the corresponding cookies.
Data retention
We keep your data only for as long as it is needed:
- Accounts that are not email-verified within 24 hours of registration are deleted automatically.
- You can delete your account yourself at any time from your account settings. A deleted account can be restored by signing back in within 30 days (we send reminders before the deadline); after that, the account and its entire workspace — including stored files — are permanently erased.
- Sign-in sessions, device records and access tokens expire automatically and are purged when they go unused.
- Crash reports are kept to analyse faults; when your account is deleted they are unlinked from you and retained only as anonymous technical data.
- Data-export downloads are single-use and expire within one hour of being prepared.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you and receive a copy of it (data portability). You can export your full workspace from your account settings; because your content is end-to-end encrypted, the export requires the private-key file that was delivered to you.
- Correct inaccurate data, directly from your profile settings.
- Have your data erased, by deleting your account.
- Object to or restrict certain processing.
- Lodge a complaint with your supervisory authority — in Greece, the Hellenic Data Protection Authority (dpa.gr).
Contact
For any question about this policy or your personal data, contact us through the contact form on our website or via alpha-tech-solutions.gr.