Legal

Privacy Policy

Last updated: October 5, 2026

This Privacy Policy explains how Rose Tech HQ ("we," "us") handles personal information in connection with our website and the Legal By Rose platform (the "Service").

Data that law firms and their users submit into the platform about their clients and matters ("Customer Data") is processed on the firm's behalf. For that data we act as a service provider/processor, and our handling is governed by the customer agreement and any data processing agreement with the firm. This Policy focuses on information we control directly, such as website visitors and account administrators.

1. Information we collect

  • Information you provide: when you request access, book a demo, contact us, or create an account — such as name, work email, firm name, role, and messages.
  • Account and usage information: authentication events, settings, and actions taken in the Service, maintained for security, support, and audit.
  • Automatically collected information: device, browser, and log data, and limited cookies needed to operate the site and keep you signed in.

2. Cookies

We use a small number of cookies and similar technologies that are necessary to provide the site and the Service (for example, to keep you signed in). We aim to minimize non-essential tracking. Where required, we present choices for non-essential cookies.

3. How we use information

  • To provide, secure, support, and improve the Service.
  • To communicate with you about access requests, your account, and service matters.
  • To maintain audit trails and detect, prevent, and respond to security and abuse.
  • To comply with legal obligations and enforce our terms.

We do not sell personal information, and we do not use Customer Data to train generative AI models for other customers.

4. How we share information

  • Service providers/subprocessors that help us operate the Service (for example, hosting, email delivery, and payment processing), under appropriate confidentiality and data-protection terms.
  • Legal and safety: where required by law or to protect rights, safety, and the integrity of the Service.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.

5. Data retention

We retain personal information for as long as needed to provide the Service and for legitimate business, security, and legal purposes. Customer Data is retained and deleted according to the customer agreement.

6. Security

We maintain administrative, technical, and organizational safeguards designed to protect information, including tenant isolation, encryption in transit, access controls, and audit logging. See our Trust Center for current details and compliance status. No method of transmission or storage is completely secure.

7. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, or restrict the processing of your personal information, and to object or withdraw consent. To exercise these rights, contact privacy@legalbyrose.com. Where we process Customer Data on behalf of a firm, we will direct requests to that firm.

8. International transfers

We operate primarily in the United States. If information is transferred across borders, we take steps to provide appropriate safeguards consistent with applicable law.

9. Children's privacy

The Service is intended for professional use by adults and is not directed to children under 18. We do not knowingly collect personal information from children.

10. Changes to this Policy

We may update this Policy from time to time. We will post changes here with an updated date and, where appropriate, provide additional notice.

11. Contact

Privacy questions or requests: privacy@legalbyrose.com. Rose Tech HQ, [Mailing address for legal notices].