Legal
Privacy Policy
Last updated: October 6, 2026
StatuteFlow handles sensitive material — tenancy disputes, money owed, names and addresses. This policy is written to the GDPR standard worldwide, because that is the strictest practical benchmark, and it names exactly which vendors touch your data and for how long.
1. Who We Are (Controller)
StatuteFlow Inc., 4700 Ocean Drive, Suite 210, Burlingame, CA 94010, United States (“StatuteFlow”, “we”) is the controller for personal data processed through this Service. Privacy questions: [email protected]. For EU/EEA and UK representatives and complaints, see the EU Compliance Notice.
2. Personal Data We Collect
We keep collection minimal and tied to a function you can point at in the product:
- Account data — name, email address, hashed password, role, subscription state.
- Case facts you enter — names and addresses of tenants, owners and subcontractors, rent and contract amounts, arrears, dates and descriptions of disputes or works. This is third-party personal data: you supply it as controller, we process it on your instruction.
- Generated documents and their citation sets, stored in your account history.
- Billing data — plan, amounts, timestamps, processor tokens and last-four card metadata. Full card numbers never reach us.
- Usage analytics — page views, interaction events, conversion funnel steps, coarse device/browser/country information collected by our own first-party analytics system. We do not embed third-party trackers, and analytics is excluded from profiling decisions that produce legal effects.
- Support and communications — emails you send us and our responses.
3. Why We Process It (Purposes) and the Legal Basis
Under GDPR Article 6 (for users outside the EU we apply the same grid as our internal standard):
- Performance of the contract — account operation, statute retrieval, document generation, preview, unlock, delivery packets, billing and refunds (Art. 6(1)(b)).
- Legitimate interests — product analytics and improvement, fraud and abuse prevention, service security, business communications to existing customers (Art. 6(1)(f); balancing documented in our records).
- Consent — marketing emails and non-essential cookies, each revocable anytime without affecting the service (Art. 6(1)(a)).
- Legal obligation — tax records, lawful requests from competent authorities, sanction screening (Art. 6(1)(c)).
4. AI Processing of Your Case Facts
Generating a document sends the case facts and a retrieved statute excerpt to our model provider to produce the notice text. Outputs are validated against the citation set before you see them. We do not use your personal case facts to train third-party foundation models, and provider agreements prohibit retention beyond processing. Where a generation can be completed with templates only, we prefer that path.
5. Sub-processors
We share data with a short list of processors under written data-processing agreements. A current list, including any additions announced at least 14 days before use, is available from [email protected]; you may object to a new sub-processor on reasonable grounds.
- Cloud hosting and managed PostgreSQL (encryption at rest, EU region option) — infrastructure.
- Stripe Payments — card acquiring and receipts; PayPal — wallet payments.
- OpenAI — large-language-model generation for notice drafting.
- Transaction email provider — receipts and security notices.
6. International Transfers
StatuteFlow is US-based, so data created in the EU/EEA or UK is transferred to the United States. We rely on the EU-US Data Privacy Framework for certified recipients, and Standard Contractual Clauses with a documented transfer impact assessment where the DPF does not apply. Payments stay with Stripe's EU entities for EU card processing wherever available.
7. How Long We Keep Data
Account data: while the account is open, then 30 days to honour re-registration requests, then anonymised or deleted. Case facts and documents: retained while the case exists and deleted within 90 days of account deletion, except where a legal hold applies. Billing records: 10 years (tax statute of limitations). Analytics aggregates: 24 months; raw event rows older than 90 days are aggregated away. Backups rotate on a 35-day cycle, so deleted data disappears from backups within that window.
8. Your Rights (and Third Parties' Rights)
You can access, correct, export and delete your personal data from account settings, or by writing [email protected]; we respond within 30 days. You can restrict or object to legitimate-interests processing, and withdraw consent anytime.
A person whose details appear in your case (a tenant, owner or subcontractor) can ask us to review and remove their data from a document set: send the case reference and your relationship to [email protected] — we will notify the account holder and act within 30 days where the request is plausible.
EU/EEA and UK data subjects may complain to their supervisory authority; UK users also have the ICO route. We do not make decisions producing legal effects based solely on automated processing — every generated document is previewed and chosen by you.
10. Security
Transport is TLS 1.2+ everywhere. Passwords are bcrypt-hashed; sessions are httpOnly, SameSite=Lax cookies. The database enforces per-account ownership checks on every query path; administration interfaces require an admin role and sit behind a separate application. Rate limiting and idempotency keys guard billing endpoints. We review sub-processor security annually and report material incidents to affected users without undue delay (and within 72 hours for GDPR-notifiable events).
11. Children
The Service is not directed to anyone under 18, because generating tenancy and lien documents requires legal capacity. We do not knowingly collect children's data; discovering any leads to prompt deletion.
12. Changes to This Policy
Material changes are announced in the app and by email 14 days ahead for subscribers. The header date records the last revision; historic versions are archived and available on request.