Privacy policy
A beta draft. This is not a signable contract and not a data processing agreement (DPA); the registered legal entity is not published yet.
Data questions: privacy@avokata.com. Security: security@avokata.com.
What this is
avokata gives a lawyer’s AI assistant tools to search Lithuanian legal acts and court practice, read provisions with exact references, follow citations and run workflows. The corpus is public. About you we keep only what an account needs and the text you choose to put in matter profiles or workflows.
We offer no search by person, we do not sell personal data, and we do not use it to train models.
Query text: what we do not keep
The text of a search or tool question is not stored. We record that a tool ran, when, how long it took, how many results came back, which quota it used, and a one-way digest of the arguments. Your words cannot be recovered from the digest: it exists only to recognise repeated calls.
That is deliberate: a lawyer’s question can reveal case strategy. Keeping queries would turn the usage log into a diary of every user’s research.
From the usage log we count, in aggregate, how many distinct people used the service in the last 7 and 30 days. A caller without an account is counted by a salted one-way hash of the network address; only the totals leave the service, and our own testing and monitoring calls are left out.
Trying it without an account
Without an account you can search legal acts and court practice a few times a day. For that path:
- the search question text is not stored, as above;
- no account is created; matter profiles, workflows and reading documents need you to connect;
- the daily limit uses a one-way hash of the network address, held in server memory only; we never store the address itself, and it cannot be recovered from the hash;
- the counter resets at midnight UTC and when new server software is deployed.
What we keep and why
| Data | Why | How long |
|---|---|---|
| Email, firm name (optional), working language | The account and signing in | Until you delete the account |
| API keys (as hashes) | Authentication | Until you revoke the key or delete the account |
| Sessions | Binding a connection to the account | Until they expire |
| Usage metadata: tool, time, quota, digest, duration | Quotas and reliability | While the account exists; after deletion the account id is cleared and there is no text |
| Matter profiles: the question, provisions and notes you enter | To continue your work | Until you delete the matter or the account; the deliberate exception to “we do not keep queries” |
| Workflows you wrote | Your work | Until you delete them or the account |
| Followed provisions | Notices about new practice | Until you remove them or delete the account |
| Feedback: only what you send with the feedback tool (the text, optional context and reply address, the tool) and the sending account (or a one-way hash without one) | Fixing errors; emailed to our team | 24 months, deleted with the account or sooner on request |
| Messages from us: replies to your feedback, questions about it and service notices, with whether you read them | The inbox in your account | 12 months, deleted with the account; without an account, service notices only, for 14 days |
| Newsletter | If you subscribe | Until you unsubscribe |
We email you only when we reply to your own feedback (you can turn that off), never marketing. We keep no copy of a statute or ruling under your name, only pointers into the public corpus.
Where the data lives
Servers and nightly backups: Hetzner in Germany (EU). Network edge, DNS and email: Cloudflare. Connections are encrypted (HTTPS); data on disk and in backups is encrypted.
Who on our side can read matter data
There is no admin console. Profiles and workflows are reachable only through your connection. In normal operation we do not read matter text. If you ask for help, we open only what your question needs.
Server and application logs
Containers write server and application logs (start-up, errors, health checks) to the host; they rotate (about 30 MB per service). Search and tool question text is not written to the logs.
Log access is limited to the people who run the infrastructure, on a need-to-know basis (outages, a report to the security address, abuse). There is no console for browsing users’ research. If you contact us about a specific incident, we look only at the lines about it.
Deletion
Ask your assistant to call request_deletion, or write to privacy@avokata.com. You get a confirmation link; confirming deletes the account and every attached record in one step, with no undo. Call counts remain, with no account id and no text. For one matter: delete_matter. Export: export_account_data.
Incidents
If we learn of a personal-data breach that may affect your account, we tell you at the account’s email address without undue delay. Reports: security@avokata.com.
Your rights
You can ask for access, correction, deletion, restriction or portability, or object to processing. Write to privacy@avokata.com; we answer within one month. You may complain to your supervisory authority.
Purposes and legal bases
We process personal data to run avokata: accounts, API keys, quotas, the matter profiles and workflows you deliberately save, support and security reports. The Lithuanian law corpus is public and is not your personal data.
Under the GDPR we rely on performance of a contract (Article 6(1)(b)) for the account; legitimate interests (Article 6(1)(f)) for security, abuse prevention, aggregated reliability measurement and the trial without an account; consent (Article 6(1)(a)) where we ask for it explicitly, such as the newsletter.
Recipients and transfers outside the EEA
Infrastructure providers process data on our behalf; the list: sub-processors. Primary hosting and backups are in Germany (EU). Cloudflare runs a global network; where data leaves the EEA we rely on appropriate safeguards such as the Standard Contractual Clauses.
Cookies
The site uses strictly necessary cookies and cookieless analytics only. Details: cookies.
Business customers
Enterprise terms, a signable DPA and the registered legal entity are not published during the beta. When they are, business customers will receive updated notices before any contractual processing.