Skip to content
Legasus
POLICY

Privacy Policy

How Legasus collects, uses, discloses, and protects personal information, and how to exercise your privacy rights.

Effective: Effective April 1, 2026Version: Version 5Jurisdiction: Illinois, USAContact: privacy@legasus.ai

This Privacy Policy explains how AIDAN LLC, doing business as Legasus (“Legasus,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with our websites, business operations, marketing activities, account administration, and services.

A central distinction in this Privacy Policy is whether Legasus is processing information for its own business purposes or on behalf of a Customer such as a law firm.

1. Scope and Our Role

1.1 Information Legasus Controls for Its Own Purposes

This Privacy Policy applies to personal information for which Legasus generally determines the purposes and means of processing, including information about:

  • Website visitors;
  • prospective customers and sales contacts;
  • business contacts;
  • Customer administrators and billing contacts;
  • Authorized Users to the extent information is used for account administration, security, billing, support, or Legasus's own business operations;
  • event attendees;
  • newsletter recipients;
  • job applicants, where applicable; and
  • individuals who communicate directly with Legasus.

Depending on the applicable law, Legasus may act as a “controller,” “business,” or similar responsible entity for this information.

1.2 Customer Data Processed on Behalf of Customers

Law firms and other Customers may use the Services to upload, store, create, analyze, transmit, or otherwise process information concerning their clients, prospective clients, matters, employees, witnesses, experts, healthcare providers, opposing parties, insurers, contacts, or other individuals (“Customer Data”).

For Customer Data, the Customer generally determines why the information is processed and how the Services are used. Legasus processes Customer Data on the Customer's behalf as a service provider, processor, or similar role under the Master Subscription Agreement and Data Processing Addendum.

If you are an individual whose information was submitted to Legasus by a law firm or other Customer, that Customer is generally the appropriate party to contact regarding access, deletion, correction, or other privacy requests. We will assist Customers as required by applicable law and our DPA.

1.3 HIPAA-Regulated Information

Where Legasus processes Protected Health Information on behalf of a Covered Entity or Business Associate under an executed Business Associate Agreement, the BAA and HIPAA govern that processing to the extent applicable. Not every Legasus feature is necessarily designated as HIPAA-eligible.

2. Personal Information We Collect

The categories below describe information we may collect depending on how you interact with us.

2.1 Business and Contact Information

We may collect:

  • name;
  • business email address;
  • business telephone number;
  • employer or firm;
  • title or role;
  • business address if provided;
  • professional profile information;
  • communication preferences; and
  • information included in messages, forms, or meeting requests.

2.2 Account and Identity Information

For users of the Services, we may collect:

  • name and contact information;
  • user ID;
  • username;
  • authentication information;
  • role and permission information;
  • organization affiliation;
  • administrator status;
  • login and authentication events;
  • MFA configuration/status;
  • account-security information; and
  • support history.

Passwords and authentication credentials are handled through appropriate authentication systems and are not intended to be stored in readable form.

2.3 Billing and Transaction Information

We may collect or receive:

  • subscription plan;
  • billing contact;
  • invoice information;
  • payment status;
  • transaction history;
  • tax information; and
  • limited payment-method information from our payment processor.

Payment-card details may be processed directly by payment providers such as Stripe rather than stored by Legasus in full.

2.4 Website and Device Information

We and our providers may automatically collect:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • referring/exit pages;
  • pages viewed;
  • time and date of visits;
  • interactions with Website elements;
  • approximate location derived from IP;
  • advertising identifiers where applicable;
  • cookie and similar technology identifiers;
  • security and fraud signals; and
  • Website performance information.

2.5 Sales, Demo, and Marketing Information

We may collect information about:

  • product interests;
  • requested features;
  • firm size;
  • practice areas;
  • technology environment;
  • sales communications;
  • demo attendance;
  • campaign interactions;
  • event attendance;
  • referral source; and
  • marketing preferences.

2.6 Support and Communications

If you contact us, we may collect the content and metadata of emails, support tickets, chats, calls, meeting notes, and other communications. Where calls or meetings are recorded, we will use recording/transcription subject to applicable law, required notices or consents, and applicable Customer agreements.

2.7 Integration Information

If a Customer connects Google Workspace, Microsoft 365, DocuSign, LexisNexis, or another integration, we may receive identifiers, authorization tokens, account metadata, and Customer Data necessary to provide the enabled integration. The Customer controls whether it enables available integrations and is responsible for having authority to connect applicable accounts.

2.8 Customer Data

Customer Data may include highly sensitive information, depending on a Customer's use, such as:

  • legal matter and case information;
  • client communications;
  • attorney work product;
  • documents and evidence;
  • intake information;
  • contact information;
  • insurance information;
  • medical records and medical information;
  • claims information;
  • financial information relating to a matter;
  • settlement information;
  • litigation and discovery material;
  • witness or expert information;
  • recordings and transcripts;
  • email and calendar content;
  • government identifiers contained in documents; and
  • other personal or sensitive information a Customer elects to process.

Legasus processes Customer Data according to the Customer's instructions, the Customer agreement, the DPA, applicable BAA, and applicable law.

2.9 AI Inputs, Outputs, and Customer-Specific AI Information

When AI-Enabled Features are used, we may process:

  • prompts and instructions;
  • documents or data supplied as context;
  • search queries;
  • generated output;
  • citations and research requests;
  • user feedback on output;
  • workflow instructions;
  • model and feature usage information; and
  • firm-specific preferences, instructions, memory, embeddings, retrieval indexes, or other Customer-Specific AI Configuration where enabled.

Customer Data is not used to train generalized/shared Legasus models except where a Customer enters a separate express written agreement permitting that use. Approved external AI providers are used under business/API arrangements intended to prevent Customer Data from being used to train their generalized models, subject to provider-specific terms and separately disclosed optional feature conditions.

2.10 Information From Third Parties

We may receive information from:

  • Customers;
  • referral partners;
  • professional networks;
  • public business sources;
  • event organizers;
  • service providers;
  • identity/authentication providers;
  • advertising and analytics partners;
  • integrations authorized by Customers; and
  • third-party legal, business, or research databases.

3. How We Use Personal Information

Depending on the context and our role, we may use personal information to:

3.1 Provide and Operate the Services

  • create and administer accounts;
  • authenticate users;
  • provide Customer-requested features;
  • process Customer instructions;
  • enable integrations;
  • provide AI-Enabled Features;
  • support Customer-Specific AI Configuration;
  • maintain and back up systems;
  • provide client-facing portal functionality;
  • process billing; and
  • provide support.

3.2 Secure the Services

  • detect and investigate suspicious activity;
  • prevent fraud, abuse, and unauthorized access;
  • maintain logs;
  • perform vulnerability management;
  • enforce access controls;
  • respond to incidents;
  • protect users, Customers, and systems; and
  • comply with security obligations.

3.3 Improve and Maintain Our Business and Services

We may use Account Data, Usage Data, feedback, and appropriately deidentified or aggregated information to:

  • understand feature use;
  • improve reliability and user experience;
  • develop new functionality;
  • troubleshoot;
  • perform capacity planning;
  • conduct internal research and analytics;
  • improve security; and
  • measure product performance.

We do not use identifiable Customer Data to train generalized/shared Legasus AI models unless a Customer separately and expressly agrees in writing.

3.4 Communications and Support

We may use contact information to:

  • respond to inquiries;
  • provide support;
  • send administrative notices;
  • communicate about security;
  • notify users about product changes;
  • provide account or billing information; and
  • manage the Customer relationship.

Transactional, security, legal, and service communications may be sent even if a person has opted out of marketing where those communications are necessary to provide or protect the Services.

3.5 Marketing

Subject to applicable law, we may:

  • send newsletters and product announcements;
  • invite business contacts to events or demos;
  • advertise Legasus products;
  • measure marketing performance;
  • conduct business-to-business outreach; and
  • use advertising technologies to reach or re-engage prospective customers.

You can unsubscribe from marketing emails through the unsubscribe mechanism in the message or by contacting support@legasus.ai. An opt-out does not stop non-marketing communications.

We may process information to:

  • comply with law, legal process, contractual obligations, and regulatory requirements;
  • exercise or defend legal claims;
  • enforce our agreements;
  • conduct audits;
  • respond to valid government requests;
  • prevent illegal or harmful conduct; and
  • complete corporate transactions subject to appropriate protections.

Where laws such as the GDPR or UK GDPR require a legal basis, Legasus may rely on one or more of the following, depending on the context:

  • performance of a contract;
  • steps taken at your request before entering a contract;
  • compliance with legal obligations;
  • legitimate interests, such as operating, securing, improving, and marketing our business, where those interests are not overridden by applicable rights;
  • consent, where required; and
  • establishment, exercise, or defense of legal claims.

Where Legasus acts as a processor, the Customer is responsible for determining an appropriate legal basis for its processing of Customer Personal Data.

5. How We Disclose Personal Information

We may disclose information in the circumstances below.

5.1 Service Providers and Subprocessors

We use service providers and subprocessors to provide infrastructure, authentication, security, payment processing, communications, analytics, AI inference, voice services, e-signature services, legal research, integrations, monitoring, and support.

Our current Customer Data subprocessors are described on the Legasus Subprocessor List. We require providers that process Customer Data on our behalf to protect it consistent with applicable contractual and legal requirements.

5.2 At Customer Direction

We disclose Customer Data when a Customer enables an integration, instructs us to send information, invites a Client User, authorizes a workflow, or otherwise directs disclosure through the Services.

5.3 Professional Advisers

We may disclose information to attorneys, accountants, auditors, insurers, consultants, and similar professional advisers subject to appropriate confidentiality obligations.

5.4 Corporate Transactions

Information may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, sale of assets, insolvency proceeding, or similar corporate transaction, subject to applicable law and appropriate confidentiality protections.

We may disclose information where we reasonably believe disclosure is required or permitted to:

  • comply with law or valid legal process;
  • respond to a binding order;
  • protect rights, property, or safety;
  • investigate fraud or security incidents;
  • enforce agreements; or
  • prevent unlawful or harmful conduct.

Where legally permitted and reasonably practicable, we may direct governmental requests for Customer Data to the applicable Customer and provide notice before disclosure.

5.6 Advertising and Analytics Partners

For our public Website and marketing activities, we may disclose or make available Website identifiers, device information, cookie identifiers, browsing activity, conversion events, and similar marketing information to analytics and advertising partners such as Google and other partners we use from time to time.

These activities may be considered a “sale,” “sharing,” or targeted advertising under certain privacy laws even though Legasus does not sell personal information for money. Where provided by applicable law, you may opt out through our cookie/privacy controls, recognized browser signals where required, or by contacting us.

We do not sell Customer Data or use identifiable Customer Data from legal matters for cross-context behavioral advertising.

6. Cookies and Similar Technologies

We use cookies, pixels, local storage, tags, and similar technologies for purposes that may include:

  • essential Website operation;
  • security;
  • authentication;
  • preferences;
  • analytics;
  • performance;
  • conversion measurement; and
  • advertising/remarketing.

We currently use or may use technologies supplied by providers such as Google and Cloudflare, together with additional providers identified through our cookie-management interface.

The Legasus Cookie Policy provides additional information. Where required by law, nonessential technologies will be subject to consent or opt-out controls.

7. Artificial Intelligence and Model Providers

7.1 Generalized Model Training

Legasus does not use Customer Data, Customer Content, AI Inputs, or AI Outputs to train generalized/shared Legasus models for unrelated customers unless the Customer separately and expressly agrees in writing.

7.2 Third-Party AI Providers

Some AI-Enabled Features may use approved third-party AI providers such as OpenAI or Anthropic. Legasus uses business/API arrangements intended to prevent Customer Data submitted through the applicable Legasus feature from being used to train the provider's generalized models, subject to provider-specific terms and separately disclosed optional feature conditions.

7.3 Private AI

Some Customers may request a Private AI Configuration. The applicable Order Form or written configuration will define the relevant architecture and commitments.

7.4 Customer-Specific AI Learning

If enabled, Customer-Specific AI Configuration may use Customer-authorized materials to adapt AI functionality specifically for that Customer. Such firm-specific learning is isolated from unrelated customers and is not used to train a generalized/shared model. Administrators may request that such functionality be disabled, reset, or deleted where technically supported, subject to contractual, legal, and backup requirements.

8. Data Security

Legasus maintains administrative, technical, and organizational safeguards designed to protect Customer Data and other personal information. These measures include controls relating to encryption at rest and in transit, multi-factor authentication, role-based access, tenant isolation, audit logging, backups, vulnerability management, penetration testing, secure development/code review, least-privilege access, incident response, business continuity/disaster recovery, and vendor risk management.

Specific contractual security commitments are described in the Security Addendum.

No security program can eliminate all risk, and we cannot guarantee absolute security.

9. Data Location and International Transfers

Legasus is based in the United States and Customer Data is primarily hosted in the United States unless an Order Form or written configuration states otherwise. Our providers may process information in the United States and other jurisdictions as permitted by the applicable agreements.

Where personal data subject to international transfer restrictions is transferred to a jurisdiction that does not provide an applicable adequacy mechanism, we use contractual or other lawful transfer mechanisms as described in the Legasus Data Transfer Addendum, which may include the European Commission Standard Contractual Clauses and UK transfer mechanisms where applicable.

10. Data Retention

10.1 Customer Data

Unless an Order Form, DPA, BAA, or law provides otherwise, Customer Data is generally available for retrieval for up to sixty (60) days following expiration or termination. After that period, Legasus may begin deletion from active systems.

Residual copies may remain in backups, security logs, disaster-recovery systems, or archives until normal retention/rotation cycles expire. Information may also be retained where required for law, security, disputes, audit, legal holds, or enforcement.

10.2 Account, Business, and Marketing Data

We retain Account Data, business records, transaction records, marketing data, and communications for as long as reasonably necessary for the purposes described in this Privacy Policy, including contractual, tax, security, legal, audit, and dispute-resolution needs.

10.3 Deidentified Data

Properly deidentified or aggregated data may be retained where it no longer reasonably identifies an individual, Customer, client, or matter, subject to applicable law and contractual restrictions.

11. Your Privacy Rights

Rights vary by jurisdiction. The rights described below apply where provided by applicable law.

Depending on where you reside and the law that applies, you may have the right to request:

  • confirmation of whether we process your personal information;
  • access to personal information;
  • correction of inaccurate personal information;
  • deletion;
  • portability;
  • restriction of processing;
  • objection to certain processing;
  • withdrawal of consent where processing is based on consent;
  • opt-out of targeted advertising;
  • opt-out of sale or sharing as legally defined;
  • limitations concerning certain sensitive personal information;
  • information about categories of information, sources, purposes, and recipients;
  • review or appeal of a denied privacy request where required; and
  • nondiscrimination for exercising applicable privacy rights.

11.1 Customer-Controlled Data

If your request relates to information a law firm or another Customer placed in Legasus, please contact that Customer first. Legasus may refer your request to the Customer or assist the Customer as required by law and the DPA.

11.2 Requests to Legasus

For information Legasus controls for its own purposes, submit requests to privacy@legasus.ai.

We may need to verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law, subject to verification requirements.

11.3 European Economic Area and United Kingdom

Where the GDPR or UK GDPR applies and Legasus acts as controller, you may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also have the right to lodge a complaint with an applicable supervisory authority.

Where Legasus acts as processor for Customer Data, the applicable Customer is ordinarily the controller and is responsible for responding to requests, with Legasus providing required assistance.

Legasus currently does not represent in this Privacy Policy that it has appointed an EU representative or a Data Protection Officer unless separately stated in an updated notice.

11.4 U.S. State Privacy Rights

Where provided by applicable U.S. state privacy law, residents may have rights to know/access, correct, delete, obtain a copy, opt out of targeted advertising or certain sale/sharing, limit certain sensitive-data processing, and appeal a decision.

Legasus does not sell Customer Data. Some Website advertising activities may constitute “sale” or “sharing” under particular state definitions. Where applicable, use our privacy/cookie controls or contact privacy@legasus.ai to exercise an opt-out right.

We will honor legally recognized opt-out preference signals, such as Global Privacy Control, where required by applicable law and technically applicable to the relevant processing.

12. Marketing Choices

You can opt out of marketing emails by using the unsubscribe link in the message or contacting support@legasus.ai. We may continue to send non-marketing messages regarding accounts, security, transactions, legal notices, support, or service operations.

13. Children

The Services and Website are not intended for individuals under eighteen (18), and Legasus does not knowingly offer accounts to persons under 18.

This age restriction does not necessarily prohibit a Customer from lawfully processing information about a minor in a legal matter where the Customer has appropriate authority and the applicable Service is authorized for that data. Customer remains responsible for lawful processing of such information.

14. Protected Health Information

Legasus may process Protected Health Information only through services/configurations designated as HIPAA-eligible and under a BAA where a BAA is required. The Privacy Policy does not replace or modify an executed BAA.

Legasus is not a healthcare provider and does not provide diagnosis, treatment, clinical advice, medical necessity determinations, or healthcare services.

15. Third-Party Services

The Services and Website may connect to third-party platforms or websites. A third party's privacy practices are governed by its own privacy notice unless it is acting as a Legasus processor subject to Legasus's contractual obligations.

Customers should review terms applicable to optional integrations and third-party licensed content.

16. Corporate Transactions

If Legasus is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, personal information may be transferred as part of that transaction subject to applicable law and confidentiality protections.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The updated policy becomes effective when posted or on a later date stated in the policy, subject to applicable law. We will update the “Last Updated” date and version.

18. Contact Us

Privacy inquiries and requests: privacy@legasus.ai
Legal: legal@legasus.ai
Security: security@legasus.ai
Marketing opt-out/support: support@legasus.ai