Jurisimus — Privacy Policy (DRAFT)
STATUS: DRAFT — NOT IN FORCE. NOT LEGAL ADVICE. Prepared 2026-07-11 for review by Thai counsel before publication. PDPA-shaped (Personal Data Protection Act B.E. 2562 (2019)). A Thai version is required for publication; plan doc:
../legal-readiness-plan-2026-07-11.md. Placeholders in[BRACKETS].
Effective date: [DATE] · Version: [v1.0]
This Privacy Policy explains how [COMPANY] ("Jurisimus", "we") collects, uses, discloses, and protects personal data when we act as a data controller — that is, for visitors to our websites, demo requesters, and the accounts, billing, and usage data of our customers.
Your firm's client data is different. Where a customer law firm submits data about its own clients to the Service (matters, documents, communications), the firm is the data controller and Jurisimus processes that data only as a data processor on the firm's instructions, under the Data Processing Addendum — not under this Policy. Individuals whose data is contained in a firm's matter files should direct requests to that firm.
1. Who we are
[COMPANY], registered in Thailand at [ADDRESS]. Contact: [privacy@jurisimus.com].
Data protection contact / DPO status: [DPO NOT YET APPOINTED — contact above; revisit trigger
logged in docs/deferred-decisions.md].
2. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Demo-request and contact data | name, firm, email, phone, message | you (landing page, in-person demos) |
| Account data | name, email, role, organization membership | you / your firm's admin |
| Billing data | invoicing details, payment method tokens (never full card numbers — held by Stripe), transaction history | you / Stripe |
| Usage and device data | log data, IP address, browser/device info, feature usage events, AI-usage metering (token counts and costs — not chat content for analytics) | automatic |
| Cookies and similar technologies | see the Cookie Policy | automatic, with consent where required |
| Communications | support requests, emails, LINE messages you send us | you |
We do not intentionally collect sensitive personal data (PDPA § 26) as a controller. Sensitive data inside customer matter files is processed only as processor per the box above.
3. Purposes and legal bases (PDPA)
| Purpose | Legal basis |
|---|---|
| Providing and operating the Service; account management | contract performance (§ 24(3)) |
| Responding to demo requests; running scheduled demos | contract performance / legitimate interest (§ 24(5)) |
| Billing, invoicing, tax compliance | contract performance; legal obligation (§ 24(6)) |
| Security, fraud prevention, abuse monitoring, audit logs | legitimate interest (§ 24(5)) |
| Product analytics (cookie-based) | consent (§ 19) — via the cookie banner, withdrawable at any time |
| Marketing communications | consent — separate, never bundled with these terms |
| Establishing or defending legal claims | legitimate interest / legal obligation |
We do not sell personal data. We do not use personal data or customer content to train AI models.
4. Disclosure and subprocessors
We share personal data only with service providers under contract (hosting — AWS; database — Supabase; payments — Stripe; authentication — WorkOS; AI model providers — OpenAI, Anthropic (API terms: no training on our data); email — AWS SES; messaging — LINE; webhooks — Svix; analytics — PostHog [self-hosted/EU/US — confirm]; error monitoring — Sentry), with professional advisors, or where required by law. The current subprocessor list is maintained at [SUBPROCESSOR PAGE URL].
5. Cross-border transfers
Our infrastructure is currently hosted in [AWS us-east-1 (United States) / Supabase (REGION)].
Personal data is therefore transferred outside Thailand. We protect such transfers with appropriate
safeguards under PDPA § 28–29, including contractual data-protection obligations with each
provider. [PENDING DECISION: migration of production hosting to AWS Asia Pacific (Bangkok)
ap-southeast-7 — tracked in docs/deferred-decisions.md; update this section when decided.]
6. Retention
- Demo-request data: [24] months after last contact, then deleted or anonymized.
- Account data: for the life of the account and [90] days after deletion, except as required for legal/tax obligations (accounting records: per Revenue Code requirements).
- Billing records: [10] years (tax law).
- Logs and security data: [12] months.
- Consent records (cookie/marketing): [5] years from withdrawal, as evidence of compliance.
- Terms-acceptance and contract evidence (acceptance events, acknowledgments, signed instruments): [10] years after the applicable customer contract terminates (organization-scoped records) or [10] years after account deletion (account-scoped acknowledgments), on the legal basis of establishment and defence of legal claims. These records are retained even if the related account is deleted; they preserve only the identity details needed as evidence.
7. Security
Encryption in transit (TLS) and at rest; database-level tenant isolation (row-level security); role-based access control; audit logging; session-revocation and breach-containment procedures; access to production data restricted to authorized personnel with a need to know. Details: [TRUST PAGE URL].
8. Your rights (PDPA §§ 30–36)
You may request: access and a copy; rectification; erasure or anonymization; restriction; portability; objection; and withdrawal of consent (withdrawal does not affect prior processing). Contact [privacy@jurisimus.com]. We respond within 30 days. You may also lodge a complaint with the Personal Data Protection Committee (PDPC) — https://www.pdpc.or.th.
9. Data breach notification
We notify the PDPC of notifiable breaches within 72 hours of becoming aware, and affected data subjects where the breach is likely to result in high risk, per PDPA § 37(4).
10. Children
The Service is not directed to children and we do not knowingly collect children's data.
11. Changes
Material changes will be announced in the product and/or by email before taking effect, with the version and effective date updated above.