Privacy Policy
Who we are
BizLegal AI (bizlegal-ai.com) provides regulatory research, compliance tools and the checkout for every BizLegal AI product. It is operated by BizLegal AI, registered in Israel, at Diamonds Exchange, Tuval 23, Ramat Gan, Israel ("we", "us"). We are the controller of the personal data described here.
Privacy contact: [email protected]. Data protection lead: the BizLegal AI privacy team. EU representative: not appointed. UK representative: not appointed.
When a business customer uploads data about other people for us to process on its behalf, the customer is the controller and we act as its processor under the Data Processing Agreement at /legal/dpa.
What we collect
- Contact details you give us: name, email address, company and the message or form you submit.
- Order and billing records: the product bought, amount, payment method type and payment status. Card and wallet details are handled by the payment provider; we never see full card numbers.
- Technical data: IP address, browser type and pages requested, kept in server and security logs.
- Your consent choices: which optional categories you allowed, when, and the policy version.
- Account data: the email you sign in with and the settings and records you keep in your dashboard.
- Documents and files you upload for analysis, and the results we produce from them.
- Text you submit to an AI feature, and the output it produced for you.
Why we use it, and the legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the product or report you asked for, and support you | Contract |
| Take payment, keep invoices and tax records | Contract; legal obligation |
| Send receipts, confirmations and service notices | Contract |
| Send newsletters or product updates you signed up for (double opt-in) | Consent |
| Count page views with cookieless analytics | Consent |
| Record partner referrals | Consent |
| Keep the service secure, prevent abuse and fraud | Legitimate interests |
| Improve our tools from aggregated, non-identifying usage | Legitimate interests |
| Comply with law and answer lawful requests | Legal obligation |
We do not sell personal data and we do not share it for cross-context behavioural advertising. We do not use your data for automated decisions that have legal or similarly significant effects on you.
AI processing
Some features send the text or documents you submit to an AI model provider listed below to produce an analysis. Whether a provider may use submitted content to improve its models: it depends on the provider and the plan, and some free tiers we use for drafting may use submitted content to improve their models, so do not submit content you are not allowed to share with a third-party AI provider. AI output can be wrong, and every AI result on our sites is labelled as AI-generated.
Who we share it with
We share personal data only with the service providers (processors) below, who act on our instructions, and with authorities when the law requires it.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Website hosting and serverless functions | Request data (IP address, user agent), form submissions in transit |
| Cloudflare | DNS, content delivery, bot protection (Turnstile), email routing, web analytics | Request data, IP address, bot-check signals |
| Supabase | Database and sign-in for some products | Account, order and product records |
| Neon | Database for leads, orders, consent records and usage logs | Lead, order and consent records |
| Hetzner | Server that runs scheduled research and content jobs | Lead and research records processed by those jobs |
| PayPal | Card and PayPal payments and subscriptions | Name, email, payment and billing details |
| NOWPayments | Cryptocurrency payments | Email, order and payment details |
| Payoneer | Bank-transfer payments | Payer and payment details |
| Resend | Transactional email (receipts, reports, confirmations) | Email address and message content |
| Plausible Analytics | Cookieless website analytics, only after analytics consent | Page views and referrers; no cookies, no personal profile |
| Google (Gemini API) | AI model that drafts or analyses content | Text submitted for analysis |
| OpenRouter | AI model routing | Text submitted for analysis |
| Ollama Cloud | AI model hosting | Text submitted for analysis |
| NVIDIA (API catalog) | AI model hosting | Text submitted for analysis |
| Anthropic | AI model used as a budgeted fallback for paid deliverables | Text submitted for analysis |
| Firecrawl | Fetching public web pages for scans and research | Public URLs submitted for a scan |
International transfers
Several providers process data outside your country, including in the United States. Where data leaves the EEA or the UK, we rely on the European Commission's adequacy decision for Israel and, for providers in other countries, the EU Standard Contractual Clauses. You can ask [email protected] for a copy of the safeguards.
How long we keep it
- Account and billing records: 7 years after the last transaction, as Israeli tax and bookkeeping rules require.
- Lead, enquiry and newsletter records: 24 months after your last interaction with us, or until you unsubscribe or ask us to delete them.
- Uploaded documents and their results: 30 days after the report is produced, unless you ask us to delete them sooner.
- Security and server logs: 90 days.
- Consent records: for as long as we must be able to show your choice.
Your rights (GDPR and UK GDPR)
- Access: ask for a copy of the personal data we hold about you.
- Correction: ask us to fix data that is wrong or incomplete.
- Deletion: ask us to delete your data, unless we must keep it by law (for example tax records).
- Portability: receive the data you gave us in a common machine-readable format.
- Objection and restriction: object to processing based on legitimate interests, including all direct marketing, or ask us to pause processing while a complaint is checked.
- Withdraw consent: change your cookie choice at any time with "Cookie settings" in the footer; withdrawal does not affect processing before it.
- Complaint: lodge a complaint with your local data protection authority.
Send a request to [email protected]. We answer within one month and may ask you to confirm your identity first.
California residents (CCPA/CPRA)
California residents have the right to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for using these rights.
We do not sell or share personal information as those terms are defined in the CCPA, and we do not use sensitive personal information beyond what the law permits. The categories we collect are the ones listed under "What we collect", from the sources described there, for the purposes in the table above. To use a right, write to [email protected]; an authorised agent may act for you with your written permission.
Security
We use encryption in transit, access controls limited to the people and systems that need the data and the encryption at rest our hosting and database providers apply. No system is perfectly secure; if a breach affects your data we will tell you and the authorities as the law requires.
Children
Our services are for businesses and adults. We do not knowingly collect data from children under 16.
Cookies
See the cookie policy at /cookies for every cookie and storage item we use. Optional ones stay off until you allow them.
Changes
We will post any change here with a new effective date, and ask for consent again where the change requires it. Effective date: 2 October 2026.