Privacy Policy

Last updated: 26 maggio 2026

1. Data Controller

The Data Controller for the personal data collected through the edit.legal platform (hereinafter, the “Platform” or the “Service”) is:

Ludwig S.r.l.s.
VAT No.: 06332200829
Registered office: Italy
Privacy contact: the contact form

For any question regarding the processing of personal data, you may contact the Controller via the contact form.

2. Types of Data Collected

The Platform collects different categories of personal data, both provided directly by the User and collected automatically during the use of the Service.

2.1 Data provided voluntarily by the User

  • Registration and identification data: first name, last name, email address, mobile phone number (for identity verification via SMS).
  • Professional data: bar association membership, registration number, specializations, court of reference, law firm name.
  • Payment data: payment method data (credit card, bank details) is collected and processed directly by our third-party payment processor, acting as an independent data controller for transaction management. Ludwig S.r.l.s. does not store complete payment instrument data.
  • Uploaded content: documents, briefs, contracts, and any other files uploaded to the Platform by the User.
  • AI assistant conversation content: questions, instructions, and messages exchanged with the artificial intelligence system integrated into the Platform.
  • Support communications: messages, reports, and requests sent to customer support.

2.2 Data collected automatically

  • Browsing data: IP address, browser type and version, operating system, device type, screen resolution, browser language, pages visited, referring URL, date and time of access.
  • Platform usage data: features used, frequency and duration of sessions, interface interactions, searches performed, documents consulted.
  • Cookies and similar technologies: technical cookies, analytics cookies, and preference cookies. For more details, please refer to our Cookie Policy.
  • Server log data: automatic records of requests made to our servers, including timestamp, HTTP method, response code, and processing time.

2.3 Data not collected

The Platform does not intentionally collect special categories of personal data under Article 9 of the GDPR (data relating to health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, sex life, or sexual orientation). Should such data be contained in documents uploaded by the User, processing will occur solely for the provision of the Service and under the full responsibility of the User.

3. Processing Methods and Location

3.1 Processing methods

Personal data is processed using electronic and digital tools, with logic strictly related to the purposes indicated in this Policy and, in any case, in a manner that ensures the security, integrity, and confidentiality of the data, in compliance with the organizational, physical, and technical measures required by applicable legislation.

Data is processed exclusively by personnel authorized by the Controller who have received appropriate operational instructions on personal data protection, as well as by third parties appointed as Data Processors pursuant to Article 28 of the GDPR.

3.2 Security measures

The Controller adopts appropriate technical and organizational measures to protect personal data from unauthorized access, loss, destruction, or alteration, including:

  • Encryption of data in transit (TLS/SSL) and at rest (AES-256).
  • Logical data isolation for each workspace and user account.
  • Role-based access control systems (RBAC).
  • Continuous monitoring and logging of system access.
  • Regular backup procedures with encrypted storage.
  • Periodic review of security policies and infrastructure updates.
  • Pseudonymisation via cryptographic hashing of personal identifiers (e.g. email addresses) appearing in operational logs for security or anti-fraud purposes, where compatible with the underlying purpose.

3.3 Location of processing

Personal data is processed at the Controller’s operational offices and at the data centers of the technology service providers used for the provision of the Service. The primary infrastructure relies on data centers located in the European Union. For information on data transfers outside the EU, please refer to Section 6 of this Policy.

4. Purposes of Processing and Legal Basis

The User’s personal data is processed for the following purposes, each based on a specific legal basis under Article 6 of Regulation (EU) 2016/679 (GDPR):

4.1 Registration and authentication

Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Registration data (email, first name, last name, phone number) is necessary to create and manage the User’s account, authenticate their identity through email magic links and SMS phone verification, and enable access to the Platform. Providing this data is a contractual requirement; failure to do so will prevent registration and use of the Service.

4.2 Service delivery and AI features

Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Data is processed to provide the Platform’s features, including case law research, legal drafting, contract analysis, and interaction with the AI assistant. Content sent by the User to the AI system is processed by third-party AI models solely to generate the requested responses. Uploaded documents are analyzed, indexed, and stored to enable semantic search and information retrieval.

4.3 Customer support

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) for responding to User requests; legitimate interest of the Controller (Art. 6(1)(f) GDPR) for analyzing support communications to improve support quality.
Support communication data is processed to respond to User requests, resolve technical issues, and — within the limits of the Controller’s legitimate interest — improve the quality of the support provided.

4.4 Commercial and promotional communications

Legal basis: User consent (Art. 6(1)(a) GDPR).
With the User’s explicit and optional consent, contact data may be used to send commercial communications about new features, offers, events, and informational content. Consent may be withdrawn at any time without affecting the lawfulness of processing before withdrawal, by using the unsubscribe link in each communication or by writing to the contact form.

4.5 Statistical analysis and Service improvement

Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Usage and browsing data, in aggregate and, where possible, anonymized form, is processed to analyze Platform usage patterns, identify areas for improvement, optimize performance, and develop new features. The Controller’s legitimate interest lies in the continuous improvement of the Service. The User may object to this processing under Article 21 of the GDPR.

4.6 Tax and accounting obligations

Legal basis: legal obligation (Art. 6(1)(c) GDPR).
Data relating to economic transactions and billing is processed to comply with Italian and European tax and accounting regulations, including electronic invoicing and mandatory bookkeeping.

4.7 Security and fraud prevention

Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Log data, IP addresses, and access data are processed to ensure Platform security, prevent and detect fraud, abuse, unauthorized access, and violations of the Terms and Conditions. The Controller’s legitimate interest lies in protecting the technological infrastructure and User data.

5. Data Recipients

The User’s personal data may be disclosed to the following categories of recipients, acting as Data Processors under Article 28 of the GDPR (unless otherwise indicated), on the basis of specific Data Processing Agreements (DPAs):

  • Cloud infrastructure and CDN service providers: for Platform hosting, content distribution, and protection against cyber attacks, with primary data centers located in the European Union.
  • Artificial intelligence service providers: for processing requests sent to the AI assistant. Data is transmitted in pseudonymized form and used exclusively to generate responses; it is not used for AI model training.
  • Statistical analysis and product analytics providers: for aggregate measurement of Platform usage and identification of usability issues. These tools (specifically Microsoft Clarity for behavioural session recording and Cloudflare Web Analytics for first-party cookieless statistics) are described in detail in the Cookie Policy. Clarity session recording takes place subject to User consent; Cloudflare Web Analytics does not install cookies and collects only aggregate, anonymized data.
  • Payment processor: for managing economic transactions and subscriptions. The payment processor acts as an independent controller for payment instrument data.
  • Email communication service providers: for sending transactional emails (registration confirmations, authentication magic links, Service notifications) and, where authorized, commercial communications.
  • Phone verification service providers: for sending verification codes via SMS as part of the authentication process.
  • Storage (object storage) service providers: for secure storage of documents uploaded by Users, with infrastructure located in the European Union.
  • Professional advisors: accountants, legal consultants, and auditors, to the extent strictly necessary for compliance with legal and accounting obligations.
  • Public authorities: judicial, tax, or supervisory authorities, exclusively in cases required by law and upon legitimate request.

The Controller does not sell, transfer, or share Users’ personal data with third parties for their direct marketing purposes. An updated list of Data Processors is available upon request by writing to the contact form.

6. Data Transfers Outside the European Union

The Controller primarily uses providers that process personal data within the European Union or the European Economic Area (EEA). However, some technology service providers may process or access personal data from countries outside the EU/EEA.

In such cases, data transfers are carried out in compliance with Chapter V of the GDPR and guaranteed by one or more of the following mechanisms:

  • Adequacy decisions of the European Commission under Article 45 of the GDPR, certifying an adequate level of data protection in the third country of destination.
  • Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) of the GDPR, supplemented where necessary by additional technical and organizational measures in accordance with EDPB recommendations.
  • EU-U.S. Data Privacy Framework (DPF), for transfers to the United States to certified organizations, in accordance with the European Commission’s adequacy decision of 10 July 2023.

The User may request information about the specific safeguards applied to data transfers by writing to the contact form.

7. Data Retention Period

Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected, in compliance with the principles of data minimization and storage limitation under Article 5 of the GDPR. Below are the retention periods for each category:

  • Account and contractual data: for the duration of the contractual relationship and for a period of 10 (ten) years following termination, in compliance with Italian tax and accounting retention obligations (Art. 2220 Italian Civil Code, Presidential Decree 600/1973).
  • User-generated content (documents, AI conversations): until account deletion by the User. Following deletion, content will be removed within 30 (thirty) days, except for backup retention of up to 90 (ninety) days.
  • Data processed based on consent (commercial communications): until withdrawal of consent by the User.
  • Analytics and browsing data: for a maximum period of 26 (twenty-six) months from collection.
  • Security logs and anti-fraud data: for a maximum period of 12 (twelve) months from the event recording.
  • Customer support data: for the duration of the contractual relationship and for a period of 2 (two) years following termination, for the management of potential disputes.

At the end of the indicated retention periods, personal data will be securely deleted or irreversibly anonymized.

8. Data Subject Rights

In accordance with Articles 15 to 22 of Regulation (EU) 2016/679 (GDPR), the User, as a data subject, may exercise the following rights at any time:

  • Right of access (Art. 15 GDPR): obtain confirmation of the existence of processing of their personal data and receive a copy thereof, as well as information about purposes, data categories, recipients, and retention period.
  • Right to rectification (Art. 16 GDPR): obtain correction of inaccurate personal data or completion of incomplete data.
  • Right to erasure (Art. 17 GDPR): obtain deletion of their personal data in the cases provided by law (e.g., when data is no longer necessary for the purposes of processing or when consent has been withdrawn).
  • Right to restriction of processing (Art. 18 GDPR): obtain restriction of processing in the cases provided by law (e.g., when the User contests the accuracy of the data).
  • Right to data portability (Art. 20 GDPR): receive their personal data in a structured, commonly used, and machine-readable format, and transmit it to another controller without hindrance, where the processing is based on consent or contract performance and is carried out by automated means.
  • Right to object (Art. 21 GDPR): object at any time to the processing of their personal data based on the Controller’s legitimate interest, on grounds relating to their particular situation. In the case of objection to processing for direct marketing purposes, processing shall cease immediately.
  • Right to withdraw consent (Art. 7(3) GDPR): withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

To exercise the above rights, the User may send a written request to the contact form. The Controller will respond to the request within 30 (thirty) days of receipt, extendable by a further 60 (sixty) days for particularly complex requests, with prior notification to the User of the reasons for the extension.

The User also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) if they believe that the processing of their personal data violates the GDPR.

9. Processing of Professional Activity Data

The Platform is intended for legal professionals and therefore collects and processes data relating to the User’s professional qualification, such as:

  • Bar association membership.
  • Bar registration number.
  • Any recognized specializations.
  • Court of reference.
  • Law firm name.

Such data is processed for the purpose of verifying the User’s professional identity, customizing the Service based on practice area, and ensuring compliance with the Platform’s terms of use, which reserve the Service for legal professionals and persons authorized by them. The legal basis is performance of a contract (Art. 6(1)(b) GDPR) and the Controller’s legitimate interest (Art. 6(1)(f) GDPR) in ensuring the Service is used by authorized users.

10. Artificial Intelligence and Automated Processing

10.1 AI system operation

The Platform integrates generative artificial intelligence models provided by reputable third-party providers. These models are used to offer features for case law research assistance, legal drafting, document analysis, and responses to legal questions.

10.2 Data transmitted to AI models

User requests (prompts, document texts, questions) are transmitted to AI model providers solely to generate responses. The transmitted data:

  • Is not used for training AI models. Contracts with third-party providers expressly prohibit the use of User data for model training or fine-tuning.
  • Is not retained by AI providers beyond the time strictly necessary to generate the response, except for legal obligations applicable to the provider itself.
  • Is transmitted in pseudonymized form, without direct association to the User’s identity.

10.3 AI output disclaimer

Content generated by artificial intelligence is solely informational and instrumental in nature. AI assists the legal professional but in no way replaces the professional judgment of the lawyer. Generated results may contain inaccuracies, errors, or outdated information. The User is required to independently verify all information generated by the system before using it in their professional activity.

10.4 Profiling

The Platform does not carry out profiling within the meaning of Article 22 of the GDPR (decisions based solely on automated processing that produce legal effects or significantly affect the data subject). Any Service personalization (e.g., search suggestions relevant to the User’s practice area) is based on preferences expressed by the User and aggregate analysis of usage patterns, without producing legal effects or significantly affecting the User.

11. Cookies

The Platform uses technical, analytics, and preference cookies. For detailed information on the types of cookies used, their purposes and durations, how to manage preferences, and applicable legal bases, please refer to our Cookie Policy.

12. Changes to This Policy

The Controller reserves the right to amend this Policy at any time, giving adequate notice to Users. Material changes will be communicated via notification within the Platform and/or by email to the email address associated with the User’s account, with at least 15 (fifteen) days’ prior notice before the changes take effect.

Continued use of the Platform after the changes take effect constitutes acceptance of the updated Policy. If the User does not wish to accept the changes, they may exercise their rights under Section 8 or cease using the Service.

13. Definitions and Legal References

  • Personal data: any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
  • Processing: any operation or set of operations performed on personal data (Art. 4(2) GDPR).
  • Data Controller: the natural or legal person that determines the purposes and means of processing (Art. 4(7) GDPR).
  • Data Processor: the natural or legal person that processes personal data on behalf of the Controller (Art. 4(8) GDPR).
  • Data Subject: the natural person to whom the personal data relates (Art. 4(1) GDPR).
  • GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
  • Italian Privacy Code: Legislative Decree No. 196 of 30 June 2003, as amended by Legislative Decree No. 101 of 10 August 2018.
  • Garante: the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), the Italian supervisory authority under Article 51 of the GDPR.

14. Microsoft Word Add-in

The edit.legal Microsoft Word Add-in (the “Add-in”) allows the use of the Platform directly within Microsoft Word. This section supplements the foregoing provisions regarding data processing in the context of the Add-in, which is distributed via Microsoft AppSource.

14.1 Data collected via the Add-in

When the User uses the Add-in, in addition to the data described in Section 2, the following data may be processed:

  • Document content: portions of the Word document text on which the User performs analysis, drafting or AI-assistance actions. Such portions are transmitted temporarily to AI model providers (Section 10.2) to generate the User-requested response. Document content is not retained after processing, except as strictly necessary for the conversational-history features within the Service.
  • Microsoft 365 identity: when the User signs in via Microsoft Single Sign-On (call toOffice.auth.getAccessToken), the Add-in receives a JWT token containing the User’s email address, Entra ID unique identifier (oid) and Microsoft tenant identifier (tid). Such data is used solely to authenticate the User on the Platform and to link the Microsoft account to the corresponding edit.legal account. Permissions requested are limited to the base profile (Microsoft GraphUser.Read); no access is requested to OneDrive, SharePoint, Outlook, Calendar or any other Microsoft 365 resource.
  • Add-in usage metadata: interaction events (taskpane opens, AI function invocations, error outcomes). Such metadata is collected on Cloudflare Analytics Engine for operational monitoring and Service improvement, in line with Sections 4.5 and 4.7.

14.2 Data NOT collected by the Add-in

The Add-in does NOT access or transmit to the Controller:

  • The entire document content unless explicitly requested by the User. Only portions selected by the User or required by the invoked function are sent to AI model providers.
  • Documents other than the one currently open in Microsoft Word, files on OneDrive/SharePoint, mailbox contents, calendar, or other Microsoft 365 resources.
  • Browsing history, operating-system screenshots, or content of other applications in use.

14.3 Distribution via Microsoft AppSource

The Add-in is distributed through Microsoft AppSource. Installation entails acceptance of the terms of use applicable to Microsoft AppSource. Distribution via AppSource does not entail any transfer of personal data to Microsoft beyond what is described in Microsoft’s policies applicable to the AppSource service (for example, installation metadata and platform telemetry collected by Microsoft as an autonomous controller).

14.4 Subscription and billing

The Add-in is free to install. Certain advanced features require a paid subscription managed directly by the Controller through the Stripe payment service provider (Section 5). Microsoft does not intervene in the payment process and does not receive subscription-related data, except as may be publicly displayed in the offer’s listing on AppSource.

14.5 Uninstallation

The User may uninstall the Add-in at any time via Microsoft Word settings (Insert → My Add-ins → Remove). Uninstalling the Add-in does not automatically delete the edit.legal account or associated data; to delete the account, the User must exercise the right of erasure described in Section 8.

Last updated: May 2026