Privacy policy
How we handle personal data.
This policy explains how Esheria, Inc. collects, uses, shares, protects, and retains personal data across our website, products, developer tools, and customer relationships.
Who we are
Esheria, Inc. is a Delaware corporation. For website, marketing, account administration, billing, product analytics, security, and customer relationship data, Esheria acts as a data controller.
For personal data that customers upload, submit, generate, or process through Esheria workspaces, LexChat, LegalOS, or the API, Esheria generally acts as a data processor on the customer's instructions.
Applicable corporate, privacy, and vendor-review materials are available during procurement or trust review.
Scope
This Privacy Policy applies to visitors to esheria.ai and related websites; users of LexChat, LegalOS, Esheria API, CLI, MCP tools, docs, dashboards, and workspaces; prospects, customers, partners, suppliers, and event contacts; and people who contact us for support, sales, privacy, legal, or security matters.
Customer agreements and our Data Processing Agreement may provide additional terms for customer-controlled data.
Personal data we collect
Depending on how you interact with Esheria, we may collect account and identity data; contact and sales data; service usage data; Customer Content; billing data; security data; website and cookie data; and support or correspondence data.
Customer Content may include documents, uploads, matter context, instructions, comments, generated outputs, workspace records, and API inputs submitted by customers or users.
Payment card details may be handled by payment processors and are not stored directly by Esheria. We do not knowingly collect more personal data than is necessary for the relevant purpose.
Sources of personal data
We collect personal data from you directly; your employer, organisation, workspace administrator, or customer account owner; your use of the service; integrations or systems connected to Esheria; payment, email, hosting, observability, support, security, and analytics providers; and public or professional sources where relevant to legitimate business contact or legal data workflows.
Why we use personal data
We use personal data to provide, operate, secure, and support the service; create and manage accounts, workspaces, API tokens, and access controls; deliver LexChat, LegalOS, API, CLI, MCP, research, workflow, and legal data features; process customer instructions, prompts, uploads, and workspace activity; maintain security and audit logs; process payments and billing; communicate with you; improve product quality and safety; comply with legal obligations; and enforce our terms.
Legal bases
Where a legal basis is required, we rely on contract, legitimate interests, consent, legal obligation, and customer instructions.
Contract supports service delivery and account management. Legitimate interests support security, product improvement, support, marketing, abuse prevention, and business operations. Consent applies to optional analytics and certain marketing choices. Legal obligation applies to tax, accounting, regulatory, security, and legal requirements. Customer instructions apply when Esheria processes personal data as a processor under the DPA.
AI and model processing
Esheria uses AI systems to support legal research, legal operations, regulatory workflows, document processing, classification, retrieval, and other product features.
Customer prompts, uploads, matter context, and workspace data are not used to train foundation models.
Where Esheria uses model providers to process customer inputs or outputs, we use enterprise or zero-retention model endpoints where applicable and apply contractual, technical, and access controls designed to protect customer data.
AI-generated outputs should be reviewed by appropriate human users before being relied on for legal advice, client-facing advice, filings, regulatory submissions, or high-impact decisions.
When we share personal data
We may share personal data with workspace administrators and authorised users within your organisation; service providers and sub-processors; professional advisers, auditors, insurers, and legal advisers; regulators, courts, public authorities, or law enforcement where required by law; counterparties in a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate safeguards; and other parties where you instruct us or give consent.
We do not sell personal data. We do not run behavioural advertising. We do not share customer prompts, uploads, or matter context with advertising networks.
Sub-processors
We use a limited number of vetted sub-processors to provide the service. Sub-processors are reviewed for security, confidentiality, data protection, and operational need.
Our current sub-processor list is available through the trust pack or on request from privacy@esheria.ai.
International transfers and data residency
Esheria operates with a primary AWS region in Frankfurt and offers data residency options for qualifying LegalOS and enterprise customers, including Kenya residency and other deployment paths where agreed.
Personal data may be processed in the United States, Kenya, the European Union, the United Kingdom, or other locations where Esheria or its sub-processors operate.
Where personal data is transferred across borders, we use appropriate safeguards such as data processing agreements, standard contractual clauses, equivalent contractual safeguards, technical controls, and vendor due diligence.
Security
Esheria maintains technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, and disclosure.
Security measures include encryption in transit, encryption at rest, role-based access controls, audit logs, access reviews, production access controls, monitoring, vendor review, and incident response procedures.
Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, including to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support audit requirements.
Account and workspace data is generally retained for the life of the account or customer relationship and then for a limited legal, audit, and operational period. Customer Content is retained according to the customer agreement, workspace settings, and DPA. Billing and tax records are retained for legally required accounting and tax periods. Security logs and audit records are retained for security, investigation, and compliance needs. Marketing data is retained until you opt out or the data is no longer needed. Cookie consent records are retained for consent management and audit purposes.
Your rights
Subject to applicable law, you may have rights to access, correct, delete, object to, restrict, withdraw consent for, or request portability of certain personal data. You may also have the right to complain to a data protection authority.
To exercise rights, contact privacy@esheria.ai. We may need to verify your identity and authority before responding.
If you are an end user of an Esheria customer workspace, we may refer your request to the customer where the customer controls the data.
Marketing choices
You can opt out of marketing emails by using the unsubscribe link or contacting us. We may still send non-marketing service, security, legal, billing, or account communications.
Children
Esheria is designed for professional and organisational use. It is not intended for children, and we do not knowingly collect personal data from children.
Changes to this policy
We may update this Privacy Policy from time to time. We will update the effective date and provide reasonable notice of material changes where appropriate.
Contact
Privacy questions and data-subject requests: privacy@esheria.ai.
Legal questions: legal@esheria.ai.