Privacy Policy
How iLawForms handles personal information about you, our customer. If you are looking for how we handle data belonging to your users, that is the Data Processing Addendum — the difference is explained in two different roles.
The short version
- We collect what we need to run the product: your account, your answers, your documents, your billing, and the technical records needed to keep it secure and working.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We run no advertising, and there is no ad-tech in the product.
- Our analytics are self-hosted and cookieless. Our error tracker is self-hosted and strips credentials and personal data before an event is stored.
- We never load an analytics or tracking script onto a hosted policy page. Those pages belong to our customers’ visitors, and putting a tracker there would create the exact defect the product exists to prevent.
- You can access, correct, export or delete your data — see how to exercise your rights.
The rest of this page is the detail. It is written to satisfy Articles 13 and 14 of the GDPR and the UK GDPR, and the notice requirements of the California Consumer Privacy Act as amended by the CPRA, and it doubles as the California Notice at Collection.
Two different roles — and which one this page is about
iLawForms handles personal data in two distinct capacities, and confusing them is the most common way a policy like this becomes misleading.
As a controller — this page
For information about you, our customer: your account, your questionnaire answers, your billing, your use of the product. We decide why and how that data is processed, so we are the controller and this Privacy Policy governs it.
As a processor — the DPA
For information about your own users that passes through features we operate for you — consent records from your cookie banner, privacy rights requests submitted to you, and the contents of a scan of your site — you decide why and how, so you are the controller and we are your processor. That processing is governed by the Data Processing Addendum, not by this page.
If you are a visitor to a website that uses iLawForms, and you want to know how your data is handled, the policy you need is that website’s own. We hold the record on their instruction and cannot answer for their practices.
What we collect, where it comes from, and why
Each row is a category we actually hold, with its source, the purpose it serves, and — for readers in the EEA and UK — the legal basis under Article 6 that the processing relies on.
| Category | What it includes | Source | Purpose | Legal basis |
|---|---|---|---|---|
| Account | Name, email address, whether the address is verified, profile image URL, and a hashed password (or, if you use social sign-in, the provider's account identifier and tokens). | You | To create and secure your account, and to sign you in. | Contract |
| Organisation and membership | Organisation name and identifier, your role in it, and the email addresses of people you invite. | You | To let more than one person work on the same documents, with the right permissions. | Contract |
| Session and device | Session identifier, IP address, browser user-agent string, and sign-in and expiry timestamps. | Automatically, when you sign in | To keep you signed in, to show you your active sessions, and to detect account takeover and abuse. | Contract; legitimate interests (security) |
| Business and site details | Site name, domain, business legal name and contact email for each site you add. | You | To generate documents that name your business correctly and to publish them at your URL. | Contract |
| Questionnaire answers | The structured facts your answers produce, and the documents rendered from them, including every published version. | You | To generate, host and version your documents. Versions are immutable because a policy's history is the point of keeping it. | Contract |
| Billing | Stripe customer and subscription identifiers, the price you are on, subscription status, and renewal dates. We do not receive or store your card number, expiry or security code. | You, via Stripe | To take payment, to work out what your plan includes, and to keep tax and accounting records. | Contract; legal obligation (tax records) |
| Email records | Recipient address, message type, delivery status and provider message identifier for the emails we send you. | Automatically | To prove a required notice — such as a policy-change email or a rights-request verification link — was actually sent. | Contract; legitimate interests (record-keeping) |
| Error diagnostics | Stack traces, the URL and route where an error occurred, and browser and platform details. Cookies, credentials, tokens and query-string secrets are stripped before the report leaves the server, and user email and IP address are excluded by default. | Automatically, when something breaks | To find and fix faults. | Legitimate interests (keeping the service working) |
| Product analytics | Page views and referrers, collected without cookies and without a cross-site identifier. Not collected on hosted policy pages at all. | Automatically | To understand which parts of the product are used. | Legitimate interests (product improvement) |
| Bot protection | A challenge result from Cloudflare Turnstile on sign-in, sign-up, password reset and public rights-request forms. | Automatically | To stop automated abuse of forms that send email or create accounts. | Legitimate interests (security) |
| Support correspondence | What you write to us, and our replies. | You | To answer you, and to keep a record of what was agreed. | Contract; legitimate interests |
| Administrative audit log | A record of actions taken on your account by our staff, with who did what and when. | Automatically | So that staff access to customer data is accountable and reviewable. | Legitimate interests (accountability); legal obligation |
Where we rely on legitimate interests
Where the basis above is legitimate interests, our interest is in keeping the service secure, available and improving. We have weighed that against your interests and rights in each case, and limited the processing accordingly — which is why error reports are scrubbed of credentials and default to excluding your email and IP address, and why analytics are cookieless and never individual-level. You can object to processing on this basis at any time: see your rights.
What we do not collect
We do not collect payment card numbers, government identifiers, biometric data, precise geolocation, or special category data under Article 9. We do not buy personal data from data brokers, and we do not enrich your record from third-party sources.
If you do not provide it
Account and billing details are necessary to provide the Service; without them we cannot give you an account. Everything else is optional, and declining it only limits the corresponding feature.
International transfers
iLawForms is based in the United States, and our infrastructure and sub-processors are located in the United States and the European Union. If you are in the EEA, the UK or Switzerland, using the Service means your personal data is transferred to the United States.
For those transfers we rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum issued under section 119A of the UK Data Protection Act 2018, and the Swiss adaptations where relevant. We have carried out a transfer impact assessment and apply supplementary measures — encryption in transit and at rest, minimisation of the data transferred, and a published policy of challenging overbroad government requests.
A copy of the clauses relied on for a particular transfer is available on request from privacy@ilawforms.com.
How long we keep it
We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires.
| Data | Retention |
|---|---|
| Account and organisation records | For as long as your account is open, then 30 days after you delete it. |
| Sessions | Until they expire or you sign out; expired sessions are purged. |
| Questionnaire answers and documents | For as long as your account is open. Published versions are retained for the life of the account because their immutability is what makes the version history evidential. |
| Billing and tax records | Seven years from the transaction, as US tax record-keeping requires. This survives account deletion. |
| Email delivery records | 24 months. |
| Error diagnostics | 90 days. |
| Product analytics | Aggregated; no individual-level record is retained. |
| Administrative audit log | Seven years. |
| Backups | Encrypted backups are retained for 35 days on a rolling cycle. Deleted data persists in a backup until that backup ages out. |
Where we must keep a record for legal reasons after you have asked us to delete something — a tax record, for example — we restrict it so that it is retained but no longer used.
How we protect it
Data is encrypted in transit with TLS and at rest. Passwords are stored as salted hashes, never in a recoverable form. Access to production data is limited to staff who need it, is authenticated individually, and is written to an audit log. Error reports are scrubbed of credentials, cookies and tokens before they leave the process, and IP addresses in consent records are stored as salted hashes rather than as addresses.
The full list of measures is on the Security page. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant supervisory authority as required by law.
Your rights — EEA, UK and Switzerland
If the GDPR or the UK GDPR applies to you, you have the right to:
- Access — get confirmation of whether we process your data, and a copy of it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where one of the Article 17 grounds applies.
- Restriction — have processing limited while a dispute about accuracy or legitimate interests is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format, and have it sent to another controller where technically feasible.
- Object — object to processing based on legitimate interests, and object to direct marketing at any time, absolutely.
- Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing already carried out.
- Complain — to your supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority in your country of residence, work, or where the issue arose. We would rather you came to us first, but you are not required to.
Representatives
Our representative in the European Union under Article 27 of the GDPR is [to be confirmed before launch]. Our representative in the United Kingdom under Article 27 of the UK GDPR is [to be confirmed before launch]. You may contact either instead of us on any matter relating to our processing of your personal data.
Your rights — California
This section applies to California residents and is our Notice at Collection under the CCPA as amended by the CPRA. The categories of personal information we collect, the purposes, and the retention periods are set out above; the statutory categories map as follows.
| Category | Collected | Detail |
|---|---|---|
| A. Identifiers | Yes | Name, email address, IP address, account and organisation identifiers. |
| B. Customer records (Cal. Civ. Code §1798.80(e)) | Yes | Name and email address. Payment card details are handled by Stripe and never reach us. |
| C. Protected classifications | No | We do not collect race, religion, age, sex, disability or similar characteristics. |
| D. Commercial information | Yes | Which plan you bought, when, and your subscription history. |
| E. Biometric information | No | — |
| F. Internet or network activity | Yes | Pages viewed, referrer, browser and platform, and error diagnostics. |
| G. Geolocation data | Coarse only | Approximate location may be inferred from an IP address. We do not collect precise geolocation. |
| H. Sensory data | No | — |
| I. Professional or employment information | Limited | Only your role within your own organisation on iLawForms. |
| J. Education information | No | — |
| K. Inferences | No | We do not build profiles or draw inferences about you. |
| L. Sensitive personal information | Yes — credentials only | Your account log-in credentials. Used solely to authenticate you, which is a purpose exempt from the right to limit under §1798.121. |
No sale, no sharing
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in California law. Because we do not, there is no “Do Not Sell or Share My Personal Information” link to offer — and a link that led nowhere would be worse than its absence. We honour the Global Privacy Control signal regardless, and treat it as an opt-out of any future sale or sharing.
Sensitive personal information
The only sensitive personal information we collect is your account log-in credentials, and we use them solely to authenticate you and secure your account. That is a purpose listed in §1798.121(a) as not requiring an offer of the right to limit, so we do not offer one. We do not use or disclose sensitive personal information to infer characteristics about you.
Your rights
As a California resident you have the right to:
- know what personal information we collect, use, disclose and retain, and to receive a copy;
- delete personal information we hold about you, subject to the statutory exceptions;
- correct inaccurate personal information;
- opt out of sale or sharing — which, as above, we do not do;
- limit the use of sensitive personal information — which, as above, does not arise; and
- not be discriminated against for exercising any of these rights. We do not deny service, charge different prices, or provide a lower quality of service because you exercised a right.
Authorised agents
You may use an authorised agent. We will ask for written proof of authorisation and, unless the agent holds a valid power of attorney, we will verify your identity directly with you.
Shine the Light
California Civil Code §1798.83 lets residents ask about disclosures to third parties for their direct marketing. We make none, but you may confirm that at privacy@ilawforms.com.
Your rights — other US states
Residents of other US states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and Florida — have broadly similar rights to access, correct, delete and port their personal data, and to opt out of targeted advertising, sale and profiling. Rather than administering a different standard per state, we extend the rights described in this policy to every US resident who asks, and we honour opt-out preference signals such as the Global Privacy Control. Where a state law gives you a right to appeal a refusal, you may appeal by replying to our decision; we will respond in writing within 45 days and tell you how to contact your state Attorney General if you remain dissatisfied.
Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling. Document generation is automated, but it is a deterministic function of the answers you give: the same answers always produce the same document, nothing is inferred about you, and no decision is made about you.
Children
The Service is for business use and is not directed at children. We do not knowingly collect personal information from anyone under 18, and we do not knowingly sell or share the personal information of anyone under 16 — we do not do either for anyone. If you believe a child has given us personal information, write to privacy@ilawforms.com and we will delete it.
How to exercise your rights
Email privacy@ilawforms.com from the address on your account, telling us what you want. Some things — exporting your documents, correcting your details, deleting your account — you can also do yourself in the product, which is faster.
Verification
We verify a request before acting on it, because acting on an unverified request is itself a data breach. Usually that means confirming control of the account email. For deletion or a copy of everything we hold, we may ask for more. We will not ask for more information than the request needs.
Timing and cost
We respond within one month under the GDPR and UK GDPR, and within 45 days under California law, each extendable once where the request is complex — we will tell you if we need the extension and why. There is no charge, unless a request is manifestly unfounded or excessive, in which case we will explain the fee before doing anything.
If we refuse
We will tell you why, and what you can do about it — including your right to complain to a supervisory authority or state Attorney General.
Changes to this policy
We update this policy when our practices change. The date at the top always shows the current version. If a change materially affects how we use personal data you have already given us, we will tell you by email before it takes effect, and where the law requires consent we will ask for it rather than assume it.
Who we are, and how to contact us
The controller of the personal data described in this policy is [to be confirmed before launch], trading as iLawForms, organised under the laws of the State of Florida, United States.
- Privacy: privacy@ilawforms.com
- Security and breach reports: security@ilawforms.com
- Post: [to be confirmed before launch]
- EU representative (GDPR Art. 27): [to be confirmed before launch]
- UK representative (UK GDPR Art. 27): [to be confirmed before launch]
We have not appointed a Data Protection Officer, having assessed that Article 37 does not require one: our core activities do not consist of large-scale regular and systematic monitoring, or of large-scale processing of special category data. Privacy questions go to the address above and are handled by someone with the authority to act on them.