Legal documents and policies
The agreements and policies that govern how firms use Legasus and how we handle their data. Each document lists its effective date and version, so your team always knows which one applies.
Agreements
The contract between your firm and Legasus, and the terms that sit beside it. The Master Subscription Agreement is the core agreement. The Product-Specific Terms, the Service Level & Support Policy, and the API & MCP Developer Terms add rules for particular features, plans, and programmatic access. The Website Terms of Use cover our public website only.
- AGREEMENT
Master Subscription Agreement
The agreement between your firm and Legasus covering access, Customer Data, AI features, fees, confidentiality, liability, and termination.
Effective Version 6
- TERMS
Product-Specific Terms
Additional terms for specific features, including AI agents, legal research, voice and recording, e-signature, the client portal, and API access.
Effective Version 4
- POLICY
Service Level & Support Policy
How Legasus measures availability, schedules maintenance, and prioritizes support where your plan or Order Form includes an SLA.
Effective Version 4
- TERMS
API & MCP Developer Terms
The terms for approved API, MCP, webhook, and other programmatic access to Legasus, including credentials, scopes, rate limits, and security.
Effective Version 4
- TERMS
Website Terms of Use
The rules for using the Legasus website, public resources, demo forms, and website chat, separate from the subscription agreement.
Effective Version 4
Acceptable use and AI
The conduct rules for everyone who uses Legasus, and the rules for its AI features. Both acceptable use policies are incorporated into the Master Subscription Agreement. The disclaimer explains that Legasus is not a law firm and why AI output needs review by a qualified professional.
- POLICY
General Acceptable Use Policy
The conduct rules for everyone using Legasus, covering security, spam, fraud, client data, client portal sharing, and enforcement.
Effective Version 4
- POLICY
AI Acceptable Use Policy
The rules for Legasus AI features: human review, prohibited uses, evidence and court filings, voice and synthetic media, and model extraction.
Effective Version 4
- DISCLAIMER
AI & Professional Services Disclaimer
What Legasus AI is and isn't: Legasus is not a law firm, AI output can be wrong, and a qualified professional must review it before it's relied on.
Effective Version 4
Privacy
What personal information Legasus collects, how we use and protect it, and how to exercise your privacy rights. The Cookie Policy covers the cookies and similar technologies on our websites and how to manage your choices.
- POLICY
Privacy Policy
How Legasus collects, uses, discloses, and protects personal information, and how to exercise your privacy rights.
Effective Version 5
- POLICY
Cookie Policy
The cookies and similar technologies used on Legasus websites, what they collect, and how to manage your choices.
Effective Version 4
Data protection
For procurement reviews and firms with clients or staff abroad: the terms under which we process Customer Personal Data for your firm, the transfer mechanisms for data leaving the EEA, UK, or Switzerland, and the providers that may process Customer Data on our behalf.
- ADDENDUM
Data Processing Addendum
How Legasus processes Customer Personal Data on your firm's behalf: instructions, security, subprocessors, incidents, audits, and deletion.
Effective Version 4
- ADDENDUM
Data Transfer Addendum
The transfer mechanisms for Customer Personal Data leaving the EEA, UK, or Switzerland, including the Standard Contractual Clauses.
Effective Version 4
- REGISTRY
Subprocessor List
The third-party providers that may process Customer Data on Legasus's behalf, what each one does, and where processing happens.
Effective Version 8
Security and compliance
How Legasus protects Customer Data. The Security Addendum sets out the measures we maintain, the Security & Trust Overview summarizes them for reviewers, the HIPAA notice explains when a BAA is available, and the Responsible Disclosure Policy explains how to report a vulnerability.
- ADDENDUM
Security Addendum
The administrative, technical, and organizational measures Legasus maintains to protect Customer Data, from encryption to incident response.
Effective Version 4
- OVERVIEW
Security & Trust Overview
A public summary of how Legasus protects legal data: access controls, encryption, audit logging, AI data handling, HIPAA, and SOC 2 status.
Last updated Version 4
- NOTICE
HIPAA & Protected Health Information Notice
How Legasus supports firms that handle protected health information, including BAA availability and which configurations are HIPAA-eligible.
Last updated Version 4
- POLICY
Responsible Disclosure & Vulnerability Reporting Policy
How to report a suspected security vulnerability to Legasus, what good-faith research looks like, and what to expect after you report.
Effective Version 4
Questions about a document?
Email the team that owns it. Include the document name and your firm so your note reaches the right person.
Legal
Questions about the agreements and policies, formal legal notices, and reports of suspected abuse under the Acceptable Use Policy.
legal@legasus.aiPrivacy
Privacy requests and questions, the DPA and subprocessors, and requests for a Business Associate Agreement.
privacy@legasus.aiSecurity
Report a suspected vulnerability under the Responsible Disclosure Policy, or a security incident or concern.
security@legasus.aiSupport
Account and support questions, the Service Level & Support Policy, developer access, and marketing opt-outs.
support@legasus.aiSecurity overview
How Legasus protects firm and client data, for teams reviewing us alongside these documents.
Read the security overview