Privacy Policy

Last updated: 8 July 2026

Judicialx ("we", "us") provides case management software for law firms. This policy explains what personal data we collect, why we process it, and your rights under the Nigeria Data Protection Regulation (NDPR).

Data we collect

  • Account data: name, email, password hash, profile image, session metadata.
  • Firm and case data: organization name, case titles, parties, tasks, documents, chat messages, drafts, and audit events you create in the product.
  • AI usage metadata: provider, model, token counts, and latency — we do not store prompt text in audit logs.
  • Billing data: subscription status and Paystack customer references (card data is handled by Paystack).

Why we process data

We process data to provide the service, secure accounts, send transactional email (invites, reminders), bill subscriptions, improve reliability, and comply with law.

Retention

  • AI call metadata: 90 days, then automatically purged.
  • Chat messages, agent runs, and audit events on closed cases: case lifetime plus one year, then purged.
  • Account data: retained while your account is active; anonymized on deletion request.

Subprocessors

We use the following subprocessors to deliver the service:

  • AWS Textract — OCR for uploaded documents
  • Anthropic — large language model inference
  • OpenAI — text embeddings for search
  • Cloudflare R2 — encrypted object storage
  • Paystack — subscription billing
  • Resend — transactional email
  • Vercel — web application hosting

See our Data Processing Agreement for firm-facing processor terms and the full subprocessor appendix.

Data residency

PostgreSQL is hosted in the region selected at provision time. Cloudflare R2 and Vercel use global infrastructure; LLM providers process requests in the United States. We disclose regions to design partners during onboarding.

Your rights

  • Export: download a JSON bundle of your data from Settings → Privacy.
  • Deletion: request account deletion from Settings → Privacy. We anonymize your profile and remove memberships; firm case data you created may remain attributed to an anonymized user ID for audit integrity.
  • Access and correction: contact us to update inaccurate account data.

Data Protection Officer

Contact our DPO at dpo@judicialx.com.

Children

Judicialx is a B2B product for law firms and is not directed at children.

Changes

We will post material changes on this page and update the "Last updated" date.