Privacy Policy
Last updated: August 2026
1. Who We Are
DeepBlueLegal is a Caribbean legal practice management platform operated by Deep Blue Legal Ltd (Company No. 17455155), registered in England & Wales. References to “DeepBlueLegal”, “we”, “us”, or “our” in this policy refer to Deep Blue Legal Ltd.
If you have questions about this policy or how we handle your data, contact us at hello@deepbluelegal.com.
2. What Data We Collect
We collect only what we need to provide the platform. This includes:
- Account information — your name, email address, and firm details (firm name, country, address, phone).
- Matter data — client names, matter titles, types, descriptions, notes, time entries, documents, and associated emails you choose to sync.
- Research queries — the text of legal research questions you submit, and the AI-generated responses returned.
- Billing information — subscription tier, billing cycle, and payment status. Card details are held by Stripe directly — we never see or store raw card numbers.
- Usage data — pages visited, features used, and basic technical information (browser, device type, IP address) used to maintain and improve the platform.
- Gmail data — if you connect a Gmail account, we access your email threads solely to match them to your matters. We read only what you explicitly authorise through Google’s OAuth consent flow.
3. How We Use Your Data
- To provide, maintain, and improve the DeepBlueLegal platform.
- To process your research queries through our AI research engine.
- To send transactional emails — account invitations, payment receipts, subscription alerts. We do not send marketing email without your explicit consent.
- To detect and prevent abuse or unauthorised access.
- To comply with legal obligations.
We do not sell your data to third parties. We do not use your matter data, research queries, or client information for any purpose other than operating the platform for your firm.
4. Third-Party Processors
We use the following sub-processors to deliver the platform. Each is bound by appropriate data processing agreements:
- Supabase — database, file storage, and authentication. Your firm’s data is stored in Supabase’s managed Postgres infrastructure.
- Anthropic — powers the AI legal research engine. Research query text is sent to Anthropic’s API to generate responses. Anthropic’s API usage policy prohibits training models on API data.
- OpenAI — generates embeddings used to index and search the legal corpus. Query text is sent to OpenAI’s embeddings API.
- Stripe — payment processing and subscription management. Stripe handles all card data under PCI-DSS compliance.
- Resend — transactional email delivery (account invites, payment notifications).
- Vercel — application hosting and global CDN. The platform is deployed on Vercel’s infrastructure.
- Google — Gmail OAuth integration for inbox-to-matter email sync, used only where you explicitly connect a Gmail account.
5. Confidentiality and AI
All matter data, client information, and research queries you enter are treated as strictly confidential. We operate on the understanding that this information is subject to legal professional privilege and attorney-client confidentiality obligations.
Your data is never used to train AI models. Research queries sent to Anthropic and OpenAI are processed under API agreements that prohibit using API inputs for model training. We do not use your matter data or client information internally to fine-tune or train any AI system.
6. Data Retention
We retain your data for as long as your account is active. If you close your account and request deletion, we will delete your firm’s data within 90 days of that request. Some data may be retained longer where required by law or for legitimate fraud-prevention purposes.
Research query history is retained within your account to support multi-turn research sessions. You can delete individual research sessions from within the platform at any time.
7. Security
We apply industry-standard security measures including:
- Encryption in transit (TLS) and at rest for all stored data.
- Row-level data isolation — every query is scoped to your firm’s data; no firm can access another’s records.
- Service-role authentication for all administrative data access, with no public RLS exposure.
- Access controls — platform admin access is restricted to authorised personnel only.
No system is perfectly secure. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.
8. Your Rights
Depending on where you are located, you may have the following rights in relation to your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion — request that we delete your personal data (subject to retention obligations).
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
UK and EU users have these rights under the UK GDPR and EU GDPR respectively. Barbados users have rights under the Data Protection Act, Cap. 308D. To exercise any right, contact us at hello@deepbluelegal.com.
9. Cookies
We use minimal cookies. The platform sets session cookies required for authentication — these are strictly necessary and cannot be disabled without breaking the service. We do not use advertising cookies or cross-site tracking cookies. Analytics, where used, is privacy-preserving and does not identify individual users.
10. Governing Law
Given the cross-jurisdictional nature of DeepBlueLegal — operated from the United Kingdom and serving Caribbean jurisdictions — this policy is intended to comply with the laws of Barbados (Data Protection Act, Cap. 308D) and England & Wales (UK GDPR, Data Protection Act 2018). Where there is a conflict, the law most protective of user rights will be applied.
11. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by a notice within the platform at least 30 days before the change takes effect. The “Last updated” date at the top of this page always reflects the current version.
12. Contact
Questions, requests, or complaints about this policy should be sent to: hello@deepbluelegal.com.
We aim to respond to all data rights requests within 30 days.