1. Introduction & Scope
Legalia ("we," "our," or "us") is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights under the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.
This policy applies to all visitors, registered users, and subscribers of the Legalia platform available at legalia.ph and its associated dashboard (collectively, the "Service").
2. Data We Collect
We collect the following categories of personal information:
- Account information: Full name, email address, and password (stored as a one-way hash) when you register.
- Billing information: Subscription plan, payment status, and billing dates. Card details and payment transactions are processed directly by PayMongo and are not stored on our servers.
- Document inputs: Names, addresses, dates, and other details you supply when generating legal documents through the Service.
- Usage data: Pages visited, features used, document generation counts, and browser/device information collected automatically via server logs and cookies.
- Communications: Content of emails or messages you send to our support team.
3. How We Use Your Data
We use your personal data to:
- Create and manage your account and authenticate your identity.
- Process payments and manage your subscription through PayMongo.
- Generate legal document drafts based on the information you provide.
- Send transactional emails (account confirmation, password reset, billing receipts).
- Improve the Service through aggregated, anonymized analytics.
- Respond to support requests and inquiries.
- Comply with legal obligations under Philippine law.
4. Data Sharing
We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:
- PayMongo: Payment processing. Only the data necessary to complete your transaction is shared.
- AI processing: Document inputs are sent to AI model providers to generate drafts. These providers are contractually prohibited from using your data to train their models.
- Legal compliance: We may disclose data if required by law, court order, or a competent government authority.
- Service continuity: In the event of a business transfer or acquisition, your data may be transferred as part of the transaction, with advance notice to you.
5. Data Retention
We retain your account and billing data for as long as your account remains active and for up to three (3) years after account closure to comply with legal and financial record-keeping obligations. Document inputs and generated drafts are retained for the duration of your subscription and deleted within 90 days of account closure upon request.
6. Your Rights under RA 10173
As a data subject under the Data Privacy Act of 2012, you have the following rights:
- Right to be informed: To know what data we collect and how it is used.
- Right of access: To request a copy of your personal data we hold.
- Right to rectification: To correct inaccurate or incomplete personal data.
- Right to erasure: To request deletion of your personal data, subject to legal retention requirements.
- Right to object: To object to processing of your data for specific purposes.
- Right to data portability: To receive your data in a commonly used, machine-readable format.
- Right to lodge a complaint: To file a complaint with the National Privacy Commission (NPC) if you believe your rights have been violated.
To exercise any of these rights, contact our Data Protection Officer at [email protected]. We will respond within fifteen (15) business days.
7. Cookies
We use essential cookies to maintain your login session and remember your preferences. We do not use third-party advertising or tracking cookies. You may disable cookies in your browser settings, but doing so may prevent certain features of the Service from functioning correctly.
8. Security
We implement reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, or disclosure — including encrypted data transmission (HTTPS), hashed password storage, and access controls limited to authorized personnel. No method of transmission over the internet is completely secure; you use the Service at your own risk.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and notify you by email or via a notice in the Service. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.
10. Contact / Data Protection Officer
For questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
Legalia — Data Protection Officer
Email: [email protected]
Website: https://legalia.ph/