iLiLawForms
DocumentsHow it worksHosted policiesPricing
Sign inGet started
DocumentsHow it worksHosted policiesPricing
Sign in

Legal

Privacy Policy

Last updated August 3, 2026

How iLawForms handles personal information about you, our customer. If you are looking for how we handle data belonging to your users, that is the Data Processing Addendum — the difference is explained in two different roles.

Contents

  1. The short version
  2. Two different roles — and which one this page is about
  3. What we collect, where it comes from, and why
  4. Cookies and similar technologies
  5. Who we share it with
  6. International transfers
  7. How long we keep it
  8. How we protect it
  9. Your rights — EEA, UK and Switzerland
  10. Your rights — California
  11. Your rights — other US states
  12. Automated decision-making
  13. Children
  14. How to exercise your rights
  15. Changes to this policy
  16. Who we are, and how to contact us

The short version

  • We collect what we need to run the product: your account, your answers, your documents, your billing, and the technical records needed to keep it secure and working.
  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We run no advertising, and there is no ad-tech in the product.
  • Our analytics are self-hosted and cookieless. Our error tracker is self-hosted and strips credentials and personal data before an event is stored.
  • We never load an analytics or tracking script onto a hosted policy page. Those pages belong to our customers’ visitors, and putting a tracker there would create the exact defect the product exists to prevent.
  • You can access, correct, export or delete your data — see how to exercise your rights.

The rest of this page is the detail. It is written to satisfy Articles 13 and 14 of the GDPR and the UK GDPR, and the notice requirements of the California Consumer Privacy Act as amended by the CPRA, and it doubles as the California Notice at Collection.

Two different roles — and which one this page is about

iLawForms handles personal data in two distinct capacities, and confusing them is the most common way a policy like this becomes misleading.

As a controller — this page

For information about you, our customer: your account, your questionnaire answers, your billing, your use of the product. We decide why and how that data is processed, so we are the controller and this Privacy Policy governs it.

As a processor — the DPA

For information about your own users that passes through features we operate for you — consent records from your cookie banner, privacy rights requests submitted to you, and the contents of a scan of your site — you decide why and how, so you are the controller and we are your processor. That processing is governed by the Data Processing Addendum, not by this page.

If you are a visitor to a website that uses iLawForms, and you want to know how your data is handled, the policy you need is that website’s own. We hold the record on their instruction and cannot answer for their practices.

What we collect, where it comes from, and why

Each row is a category we actually hold, with its source, the purpose it serves, and — for readers in the EEA and UK — the legal basis under Article 6 that the processing relies on.

Categories of personal information collected, their source, purpose and legal basis
CategoryWhat it includesSourcePurposeLegal basis
AccountName, email address, whether the address is verified, profile image URL, and a hashed password (or, if you use social sign-in, the provider's account identifier and tokens).YouTo create and secure your account, and to sign you in.Contract
Organisation and membershipOrganisation name and identifier, your role in it, and the email addresses of people you invite.YouTo let more than one person work on the same documents, with the right permissions.Contract
Session and deviceSession identifier, IP address, browser user-agent string, and sign-in and expiry timestamps.Automatically, when you sign inTo keep you signed in, to show you your active sessions, and to detect account takeover and abuse.Contract; legitimate interests (security)
Business and site detailsSite name, domain, business legal name and contact email for each site you add.YouTo generate documents that name your business correctly and to publish them at your URL.Contract
Questionnaire answersThe structured facts your answers produce, and the documents rendered from them, including every published version.YouTo generate, host and version your documents. Versions are immutable because a policy's history is the point of keeping it.Contract
BillingStripe customer and subscription identifiers, the price you are on, subscription status, and renewal dates. We do not receive or store your card number, expiry or security code.You, via StripeTo take payment, to work out what your plan includes, and to keep tax and accounting records.Contract; legal obligation (tax records)
Email recordsRecipient address, message type, delivery status and provider message identifier for the emails we send you.AutomaticallyTo prove a required notice — such as a policy-change email or a rights-request verification link — was actually sent.Contract; legitimate interests (record-keeping)
Error diagnosticsStack traces, the URL and route where an error occurred, and browser and platform details. Cookies, credentials, tokens and query-string secrets are stripped before the report leaves the server, and user email and IP address are excluded by default.Automatically, when something breaksTo find and fix faults.Legitimate interests (keeping the service working)
Product analyticsPage views and referrers, collected without cookies and without a cross-site identifier. Not collected on hosted policy pages at all.AutomaticallyTo understand which parts of the product are used.Legitimate interests (product improvement)
Bot protectionA challenge result from Cloudflare Turnstile on sign-in, sign-up, password reset and public rights-request forms.AutomaticallyTo stop automated abuse of forms that send email or create accounts.Legitimate interests (security)
Support correspondenceWhat you write to us, and our replies.YouTo answer you, and to keep a record of what was agreed.Contract; legitimate interests
Administrative audit logA record of actions taken on your account by our staff, with who did what and when.AutomaticallySo that staff access to customer data is accountable and reviewable.Legitimate interests (accountability); legal obligation

Where we rely on legitimate interests

Where the basis above is legitimate interests, our interest is in keeping the service secure, available and improving. We have weighed that against your interests and rights in each case, and limited the processing accordingly — which is why error reports are scrubbed of credentials and default to excluding your email and IP address, and why analytics are cookieless and never individual-level. You can object to processing on this basis at any time: see your rights.

What we do not collect

We do not collect payment card numbers, government identifiers, biometric data, precise geolocation, or special category data under Article 9. We do not buy personal data from data brokers, and we do not enrich your record from third-party sources.

If you do not provide it

Account and billing details are necessary to provide the Service; without them we cannot give you an account. Everything else is optional, and declining it only limits the corresponding feature.

Cookies and similar technologies

We set a small number of strictly necessary cookies — a session cookie so you stay signed in, and Cloudflare Turnstile’s bot-protection storage. We do not set advertising cookies, and our analytics are cookieless.

Each item, its purpose and its lifetime is listed in the Cookie Policy.

Who we share it with

We do not sell personal information, and we have not sold or shared it for cross-context behavioural advertising in the preceding twelve months — including the personal information of anyone we know to be under 16. We do not disclose personal information to third parties for their own marketing.

We disclose personal information only:

  • To service providers who process it on our behalf, under contract, for the purposes we set. Every one is named on the Sub-processors page, with what it does and where it operates.
  • Within your own organisation. Other members of an organisation you join can see the sites, answers, documents and requests belonging to it. Owners and admins can also see membership and billing.
  • To professional advisers — accountants, auditors, lawyers, insurers — where they need it and are bound by confidentiality.
  • Where the law requires it, or to establish, exercise or defend legal claims. We review every request, refuse those that are overbroad or improper, and will tell you before disclosing your data unless we are legally prohibited from doing so.
  • In a merger, acquisition, financing or sale of assets, in which case we will give notice and the acquirer remains bound by commitments no weaker than these.

Anything you publish is public by definition: a hosted document at policies.ilawforms.com is served to anyone with the link, including the business details you chose to put in it.

International transfers

iLawForms is based in the United States, and our infrastructure and sub-processors are located in the United States and the European Union. If you are in the EEA, the UK or Switzerland, using the Service means your personal data is transferred to the United States.

For those transfers we rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum issued under section 119A of the UK Data Protection Act 2018, and the Swiss adaptations where relevant. We have carried out a transfer impact assessment and apply supplementary measures — encryption in transit and at rest, minimisation of the data transferred, and a published policy of challenging overbroad government requests.

A copy of the clauses relied on for a particular transfer is available on request from privacy@ilawforms.com.

How long we keep it

We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires.

Retention period by category of data
DataRetention
Account and organisation recordsFor as long as your account is open, then 30 days after you delete it.
SessionsUntil they expire or you sign out; expired sessions are purged.
Questionnaire answers and documentsFor as long as your account is open. Published versions are retained for the life of the account because their immutability is what makes the version history evidential.
Billing and tax recordsSeven years from the transaction, as US tax record-keeping requires. This survives account deletion.
Email delivery records24 months.
Error diagnostics90 days.
Product analyticsAggregated; no individual-level record is retained.
Administrative audit logSeven years.
BackupsEncrypted backups are retained for 35 days on a rolling cycle. Deleted data persists in a backup until that backup ages out.

Where we must keep a record for legal reasons after you have asked us to delete something — a tax record, for example — we restrict it so that it is retained but no longer used.

How we protect it

Data is encrypted in transit with TLS and at rest. Passwords are stored as salted hashes, never in a recoverable form. Access to production data is limited to staff who need it, is authenticated individually, and is written to an audit log. Error reports are scrubbed of credentials, cookies and tokens before they leave the process, and IP addresses in consent records are stored as salted hashes rather than as addresses.

The full list of measures is on the Security page. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant supervisory authority as required by law.

Your rights — EEA, UK and Switzerland

If the GDPR or the UK GDPR applies to you, you have the right to:

  • Access — get confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have your data deleted where one of the Article 17 grounds applies.
  • Restriction — have processing limited while a dispute about accuracy or legitimate interests is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format, and have it sent to another controller where technically feasible.
  • Object — object to processing based on legitimate interests, and object to direct marketing at any time, absolutely.
  • Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing already carried out.
  • Complain — to your supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority in your country of residence, work, or where the issue arose. We would rather you came to us first, but you are not required to.

Representatives

Our representative in the European Union under Article 27 of the GDPR is [to be confirmed before launch]. Our representative in the United Kingdom under Article 27 of the UK GDPR is [to be confirmed before launch]. You may contact either instead of us on any matter relating to our processing of your personal data.

Your rights — California

This section applies to California residents and is our Notice at Collection under the CCPA as amended by the CPRA. The categories of personal information we collect, the purposes, and the retention periods are set out above; the statutory categories map as follows.

Statutory categories of personal information under California law
CategoryCollectedDetail
A. IdentifiersYesName, email address, IP address, account and organisation identifiers.
B. Customer records (Cal. Civ. Code §1798.80(e))YesName and email address. Payment card details are handled by Stripe and never reach us.
C. Protected classificationsNoWe do not collect race, religion, age, sex, disability or similar characteristics.
D. Commercial informationYesWhich plan you bought, when, and your subscription history.
E. Biometric informationNo—
F. Internet or network activityYesPages viewed, referrer, browser and platform, and error diagnostics.
G. Geolocation dataCoarse onlyApproximate location may be inferred from an IP address. We do not collect precise geolocation.
H. Sensory dataNo—
I. Professional or employment informationLimitedOnly your role within your own organisation on iLawForms.
J. Education informationNo—
K. InferencesNoWe do not build profiles or draw inferences about you.
L. Sensitive personal informationYes — credentials onlyYour account log-in credentials. Used solely to authenticate you, which is a purpose exempt from the right to limit under §1798.121.

No sale, no sharing

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in California law. Because we do not, there is no “Do Not Sell or Share My Personal Information” link to offer — and a link that led nowhere would be worse than its absence. We honour the Global Privacy Control signal regardless, and treat it as an opt-out of any future sale or sharing.

Sensitive personal information

The only sensitive personal information we collect is your account log-in credentials, and we use them solely to authenticate you and secure your account. That is a purpose listed in §1798.121(a) as not requiring an offer of the right to limit, so we do not offer one. We do not use or disclose sensitive personal information to infer characteristics about you.

Your rights

As a California resident you have the right to:

  • know what personal information we collect, use, disclose and retain, and to receive a copy;
  • delete personal information we hold about you, subject to the statutory exceptions;
  • correct inaccurate personal information;
  • opt out of sale or sharing — which, as above, we do not do;
  • limit the use of sensitive personal information — which, as above, does not arise; and
  • not be discriminated against for exercising any of these rights. We do not deny service, charge different prices, or provide a lower quality of service because you exercised a right.

Authorised agents

You may use an authorised agent. We will ask for written proof of authorisation and, unless the agent holds a valid power of attorney, we will verify your identity directly with you.

Shine the Light

California Civil Code §1798.83 lets residents ask about disclosures to third parties for their direct marketing. We make none, but you may confirm that at privacy@ilawforms.com.

Your rights — other US states

Residents of other US states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and Florida — have broadly similar rights to access, correct, delete and port their personal data, and to opt out of targeted advertising, sale and profiling. Rather than administering a different standard per state, we extend the rights described in this policy to every US resident who asks, and we honour opt-out preference signals such as the Global Privacy Control. Where a state law gives you a right to appeal a refusal, you may appeal by replying to our decision; we will respond in writing within 45 days and tell you how to contact your state Attorney General if you remain dissatisfied.

Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling. Document generation is automated, but it is a deterministic function of the answers you give: the same answers always produce the same document, nothing is inferred about you, and no decision is made about you.

Children

The Service is for business use and is not directed at children. We do not knowingly collect personal information from anyone under 18, and we do not knowingly sell or share the personal information of anyone under 16 — we do not do either for anyone. If you believe a child has given us personal information, write to privacy@ilawforms.com and we will delete it.

How to exercise your rights

Email privacy@ilawforms.com from the address on your account, telling us what you want. Some things — exporting your documents, correcting your details, deleting your account — you can also do yourself in the product, which is faster.

Verification

We verify a request before acting on it, because acting on an unverified request is itself a data breach. Usually that means confirming control of the account email. For deletion or a copy of everything we hold, we may ask for more. We will not ask for more information than the request needs.

Timing and cost

We respond within one month under the GDPR and UK GDPR, and within 45 days under California law, each extendable once where the request is complex — we will tell you if we need the extension and why. There is no charge, unless a request is manifestly unfounded or excessive, in which case we will explain the fee before doing anything.

If we refuse

We will tell you why, and what you can do about it — including your right to complain to a supervisory authority or state Attorney General.

Changes to this policy

We update this policy when our practices change. The date at the top always shows the current version. If a change materially affects how we use personal data you have already given us, we will tell you by email before it takes effect, and where the law requires consent we will ask for it rather than assume it.

Who we are, and how to contact us

The controller of the personal data described in this policy is [to be confirmed before launch], trading as iLawForms, organised under the laws of the State of Florida, United States.

  • Privacy: privacy@ilawforms.com
  • Security and breach reports: security@ilawforms.com
  • Post: [to be confirmed before launch]
  • EU representative (GDPR Art. 27): [to be confirmed before launch]
  • UK representative (UK GDPR Art. 27): [to be confirmed before launch]

We have not appointed a Data Protection Officer, having assessed that Article 37 does not require one: our core activities do not consist of large-scale regular and systematic monitoring, or of large-scale processing of special category data. Privacy questions go to the address above and are handled by someone with the authority to act on them.

Questions about this document can be sent to privacy@ilawforms.com, or by post to iLawForms, [to be confirmed before launch].

iLiLawForms

Compliance documents generated from a questionnaire, hosted at a stable URL, and updated when the law changes.

Product

  • Documents
  • How it works
  • Hosted policies
  • Pricing

Coverage

  • EU (GDPR)
  • UK (UK GDPR)
  • California (CCPA/CPRA)

Account

  • Sign in
  • Create an account

Company

  • About
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Cookies
  • Legal Disclaimer
  • Acceptable use
  • Refunds
  • Data Processing Addendum
  • Sub-processors
  • Security
  • All legal documents

iLawForms is not a law firm and does not provide legal advice. Documents generated here are a starting point, not a substitute for advice from a qualified lawyer in your jurisdiction.

© 2026 iLawFormsCoverage at launch: EU · UK · California