Legal

Privacy Policy

Nexa Legal — Nexa Core Digital Ltd

Last updated: 1 July 2026Effective date: 1 July 2026
1.

Who We Are

This Privacy Policy is issued by Nexa Core Digital Ltd, a company registered in England and Wales under company number 16911508, with our registered office at 61 Suffolk Road, Ilford, England, IG3 8JG.

We operate the Nexa Legal platform, including the Nexa Legal OS practice management system accessible at nexalegal.cloud and app.nexalegal.cloud, and the Nexa Legal Connect client portal service (collectively, the Platform).

We are registered with the Information Commissioner's Office (ICO). If you have questions about whether your firm needs ICO registration, visit ico.org.uk.

For all data protection enquiries, contact us at: hello@nexalegal.cloud

2.

Who This Policy Applies To

This policy applies to all individuals whose personal data we process, including:

  • Law firm administrators, solicitors, paralegals, and support staff who use the Platform as part of their firm's subscription (Firm Users)
  • Clients of law firms who submit documents or information through the Platform's client portal (End Clients)
  • Visitors to our websites at nexalegal.cloud and app.nexalegal.cloud
  • Individuals who contact us by email, phone, or any other channel
  • Prospective customers who enquire about our products or services

If you are a law firm using our Platform, you act as a Data Controller in respect of your clients' personal data processed through the Platform. We act as your Data Processor for that data. Our Data Processing Agreement, which forms part of our Terms of Service, governs that relationship separately.

3.

Personal Data We Collect

3.1 Data you provide directly

  • Account registration: name, email address, job title, firm name, phone number
  • Firm profile: law firm name, SRA registration number, business address, practice areas
  • Matter data: case names, matter types, client names, matter references, court dates, case notes, workflow stages
  • Solicitor client account: client names, matter references, transaction amounts, payer details, bank statement data uploaded by your firm
  • Documents: any files uploaded to the Platform by your firm or your clients through the client portal
  • Billing: billing contact name, email address, and payment card details which are processed by Stripe — we do not store card numbers directly
  • Communications: emails, support messages, feedback, and enquiries you send us
  • Innovation partner applications: firm details, practice area information, and contact information submitted through nexalegal.cloud/partners

3.2 Data we collect automatically

  • Usage data: pages visited, features used, session duration, actions taken within the Platform
  • Device data: IP address, browser type, operating system, device identifiers
  • Log data: server logs, error reports, performance data, access timestamps
  • Cookies and similar technologies: see Section 11 for full cookie information

3.3 Special category data

The Platform may process special category personal data about your clients — such as health information in personal injury matters, immigration status, financial details, or family circumstances — as part of the case management and document storage functions. We process this data solely on your instruction as Data Controller. We do not use this data for any purpose beyond providing the Platform to your firm.

4.

How We Use Your Personal Data and Our Legal Basis

Providing the Platform and your account

Performance of contract (Article 6(1)(b) UK GDPR)

We must process your data to deliver the service you have subscribed to.

Solicitor client account processing

Performance of contract

We process accounting data on your firm's instruction as Data Processor.

Billing and payment processing

Performance of contract and legitimate interests (Article 6(1)(f))

We process subscription payments and manage accounts.

Customer support

Legitimate interests

We respond to your queries and resolve technical issues.

Security and fraud prevention

Legitimate interests

We protect the Platform and our users from unauthorised access and misuse.

Legal compliance

Legal obligation (Article 6(1)(c))

We comply with applicable laws including UK GDPR, the Data Protection Act 2018, and financial regulations.

Platform improvement

Legitimate interests

We analyse usage patterns to improve features and fix issues. We use anonymised or aggregated data where possible.

Marketing communications

Consent (Article 6(1)(a))

We will only send you marketing emails if you have opted in. You can withdraw consent at any time by clicking unsubscribe in any email or contacting us at hello@nexalegal.cloud.

5.

Who We Share Your Data With

We do not sell your personal data. We do not share it with third parties for their own marketing purposes. We share data only in the following circumstances.

5.1 Service providers

We use carefully selected third-party providers to operate the Platform. Each is bound by a Data Processing Agreement:

SupabaseDatabase storage and file storage. Server region: UK/EU.
RailwayBackend API hosting. Server region: UK/EU.
VercelFrontend hosting. Global CDN for static assets only. No personal data stored on Vercel infrastructure.
Anthropic (Claude API)AI document generation, document automation, and matter intelligence features. Based in the USA. Data transferred under standard contractual clauses. We minimise the personal data sent to the Anthropic API.
StripePayment processing. Stripe Payments Europe Ltd, regulated by the Central Bank of Ireland. Payment card data is processed directly by Stripe under their own privacy policy.
ResendTransactional email delivery for invitation and notification emails. Emails sent from noreply@nexalegal.cloud.

5.2 Legal disclosure

We may disclose personal data where required by law, court order, or regulatory authority — including the ICO, SRA, HMRC, or law enforcement agencies. We will notify you where legally permitted before making such a disclosure.

5.3 Business transfers

If we sell, merge, or transfer all or part of our business, personal data held by us may be transferred to the acquiring entity. We will notify affected users in advance and ensure the receiving entity maintains equivalent data protection standards.

5.4 Development team

Our development team is based in Bangladesh. Team members access the Platform for development and support purposes under strict access controls, confidentiality agreements, and limited-scope credentials. This access is governed by appropriate contractual safeguards and is logged for audit purposes.

6.

Legal Professional Privilege

We acknowledge that data processed through the Platform may be subject to legal professional privilege. We will not access, disclose, or use privileged data except:

  • To provide technical support that you have specifically requested
  • Where required by a binding legal obligation
  • As described in our Data Processing Agreement with your firm

Our team members are required to handle privileged legal data with appropriate care. Access to client matter data is restricted to authorised personnel only and only where necessary to provide support or maintain the Platform.

7.

International Data Transfers

We are committed to keeping your data within the UK or European Economic Area wherever possible. Where data is transferred outside the UK or EEA — for example when using the Anthropic Claude API for AI features — we ensure appropriate safeguards are in place including:

  • Standard Contractual Clauses approved by the ICO
  • The UK International Data Transfer Agreement where appropriate
  • Binding Corporate Rules where applicable

Anthropic, our AI provider based in the USA, processes data under standard contractual clauses. We minimise the personal data sent to Anthropic's API using data minimisation and anonymisation techniques where possible.

8.

How Long We Keep Your Data

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.

Account data for active firmsDuration of subscription plus six months. After six months from cancellation, data is deleted or anonymised on request.
Matter and case dataDuration of subscription plus seven years. This aligns with SRA guidance recommending retention of matter files for six years minimum post-completion.
Solicitor client account recordsSeven years from the date of each transaction. This reflects SRA Accounts Rules 2019 and HMRC requirements for financial records.
Uploaded documentsDuration of subscription plus seven years, aligned with matter file retention requirements.
Billing recordsSeven years in accordance with HMRC requirements.
Support communicationsThree years to assist with resolving recurring issues.
Website usage logsThirteen months in accordance with ICO guidance on web analytics data.
Marketing consent recordsUntil consent is withdrawn plus three years as evidence of the consent basis for processing.

When your firm cancels its subscription we will retain your data for the periods above and then securely delete or anonymise it. You may request earlier deletion subject to our legal retention obligations — see Section 9 for your rights.

9.

Your Rights Under UK GDPR

Under the UK General Data Protection Regulation and the Data Protection Act 2018, you have the following rights:

Right of access

You can request a copy of the personal data we hold about you. This is called a Subject Access Request. We will respond within one calendar month.

Right to rectification

You can ask us to correct inaccurate or incomplete personal data we hold about you.

Right to erasure

You can ask us to delete your personal data where it is no longer necessary, where you withdraw consent, or where we have processed it unlawfully — subject to our legal retention obligations.

Right to restrict processing

You can ask us to pause processing of your data in certain circumstances — for example while you contest its accuracy.

Right to data portability

Where processing is based on consent or contract and carried out by automated means, you can ask us to provide your data in a structured, machine-readable format.

Right to object

You can object to processing based on legitimate interests, including profiling. You can also object at any time to processing for direct marketing purposes.

Rights regarding automated decisions

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects without human review.

Right to withdraw consent

Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, email us at hello@nexalegal.cloud. We will respond within one calendar month of receiving your request. We may ask you to verify your identity before processing your request.

If you are not satisfied with how we handle your request, you have the right to complain to the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113.

10.

How We Protect Your Data

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or disclosure. Our security measures include:

Encryption in transitAll data transmitted between your browser and our servers is encrypted using TLS over HTTPS.
Encryption at restPersonal data stored in our database is encrypted at rest.
Access controlsRole-based access control ensures staff and users can only access data necessary for their role.
Audit loggingAll access to personal data and system events are logged with timestamps and stored securely.
Immutable accounting recordsSolicitor client account entries are append-only and cannot be deleted — providing a tamper-evident audit trail compliant with SRA Accounts Rules 2019.
Staff trainingAll team members with access to personal data receive data protection training and are bound by confidentiality obligations.
Incident responseWe maintain a data breach response procedure and will notify affected users and the ICO within 72 hours of becoming aware of a reportable breach.
Third-party securityWe conduct due diligence on all third-party processors and require them to maintain equivalent security standards under written agreements.

If you become aware of any security vulnerability or potential breach relating to the Platform, please contact us immediately at hello@nexalegal.cloud.

11.

Cookies

We use cookies and similar technologies on our websites. A cookie is a small text file placed on your device when you visit a website.

Strictly necessary cookies

Required for the Platform to function. These include authentication and session management cookies. No consent required.

Analytics cookies

Help us understand how the Platform is used so we can improve it. These require your consent and are activated via our cookie banner.

Preference cookies

Remember your settings and preferences. These require your consent and are activated via our cookie banner.

You can control cookies through your browser settings and our cookie consent banner. Disabling strictly necessary cookies will affect Platform functionality. For more information about cookies, visit allaboutcookies.org.

12.

Children

The Platform is intended for use by legal professionals and law firms. It is not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at hello@nexalegal.cloud and we will delete it promptly.

13.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our processing activities, the law, or our business. When we make material changes we will:

  • Notify all active firm administrators by email at least 14 days before the change takes effect
  • Display a prominent notice within the Platform
  • Update the Last Updated date at the top of this document

Continued use of the Platform after the effective date of any change constitutes acceptance of the updated policy. If you do not agree with a material change, you may cancel your subscription before the effective date.

14.

How to Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or how we handle personal data:

Data Controller: Nexa Core Digital Ltd

Registered address: 61 Suffolk Road, Ilford, England, IG3 8JG

Company number: 16911508

Email: hello@nexalegal.cloud

Website: nexalegal.cloud

We aim to respond to all data protection enquiries within five business days and all formal rights requests within one calendar month.

If you are not satisfied with our response, you may complain to the Information Commissioner's Office:

Website: ico.org.uk

Telephone: 0303 123 1113

Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Nexa Core Digital Ltd · Registered in England and Wales · Company No. 16911508 · nexalegal.cloud

← Back to Nexa Legal