Privacy Policy
Last updated:
This page describes how UT Chart works. It is not legal advice.
Who we are
TempusLexit Inc. is the organisation accountable for the personal information described in this policy. It is incorporated in the jurisdiction stated below. This policy is written to meet the requirements of the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec’s Law 25.
Our privacy officer is responsible for our compliance with this policy and is the person to contact with a question, a request, or a complaint about your personal information. Their contact details, and our mailing address of record, are below.
- Incorporated in: {{INCORPORATION_JURISDICTION}}
- Privacy officer: {{PRIVACY_OFFICER}}
- Privacy email: {{PRIVACY_EMAIL}}
- Mailing address: {{REGISTERED_ADDRESS}}
What we collect
We collect the following categories of personal information:
- Account data. Your name, email address, firm name, and role within your firm’s account.
- Transcripts and chart data. The discovery transcript PDF you upload, and the chart items — undertakings, under advisements, and refusals — that our system extracts from it, together with the wording drafted for each one.
- Sign-in records. When you sign in we record that a session was created and when it expires, the time of your most recent sign-in, and a count of failed sign-in attempts, which we use to lock an account after repeated failures. We do not record the IP address, the device, or the location a sign-in came from.
- Billing data. Payment and subscription details, held by Stripe, our payment processor, rather than by us.
We do not ask for, and do not want, any material beyond the transcript you choose to upload.
Why we collect it
We use personal information for the following purposes, and no others:
- to provide the service your firm has signed up for;
- to build the chart from the transcript you upload;
- to draft suggested wording for chart entries;
- to authenticate accounts and secure the platform;
- to bill your firm for its subscription; and
- to diagnose and fix faults your firm reports.
We do not use transcripts to train any model of ours, and we do not sell or disclose personal information for marketing purposes.
AI processing
UT Chart uses an AI model to draft suggested wording for chart entries. What is sent, and to whom, is set out below.
What is sent is always limited to the question and answer text of individual chart items. The full transcript is never sent, and the uploaded PDF is never sent. The draft wording the model returns is a suggestion: it is presented for review and is not applied to your chart until someone at your firm approves it.
| Option | Where it goes | What is sent | Whose account |
|---|---|---|---|
| Off | None | Nothing leaves the platform | — |
| AI assistance we operate | Google (Gemini) | Question and answer text of individual chart items | TempusLexit Inc. |
AI wording assistance is optional. Your firm can turn it off, in which case no transcript text is sent to an AI provider.
AI wording assistance currently uses the provider we operate, described below. Support for supplying your own provider key is planned.
Whether excerpts sent for wording drafts may be used to improve the provider’s models depends on the service tier in use. We will state our position here once that is settled.
Transfers outside Quebec and Canada
Some personal information leaves Canada, and leaves Quebec, as part of how the service works.
On the AI assistance we operate, the excerpts sent for wording drafts are processed by Google, outside Canada. Stripe processes billing data outside Canada.
Quebec’s Law 25 requires a privacy impact assessment before personal information is disclosed outside Quebec. That requirement applies to each of the transfers described above.
Third parties who process data for us
The table below lists the third parties who process personal information on our behalf, and what each one can reach. PIPEDA and Quebec’s Law 25 require us to hold each of them to contractual protections for the personal information they process for us. The list changes only with notice to your firm.
| Name | Purpose | Data reached | Location |
|---|---|---|---|
| Amazon Web Services | Hosting and object storage | Transcripts, account data | Region set in the deployment configuration |
| SMB Operations Inc. | Infrastructure operations management | Transcripts, account data | Canada |
| AI wording drafts (Gemini), on the AI assistance we operate | Question and answer text of individual chart items. Never the full transcript or the PDF. | Outside Canada | |
| Stripe | Billing | Account and payment data. No transcripts. | Outside Canada |
SMB Operations Inc. The AWS account holding transcripts is owned by SMB Operations Inc., a separate legal entity providing operations management services to TempusLexit Inc. TempusLexit Inc. remains accountable for the data; SMB Operations Inc. acts as a service provider on its behalf, not as a joint controller.
How long we keep it
We keep your firm’s transcripts and the charts built from them for as long as your firm’s account is active. There is no fixed timer on active data — a matter can run for years, and we hold it for as long as it is needed for the purpose you gave it to us for, and no longer.
Two clocks apply once that need ends, set out below.
- A case you delete: 30 days — recoverable from the deleted items bin for this period — what happens to the stored transcript file at the end of it is stated immediately below
- After your subscription ends: {{RETENTION_POST_TERMINATION_DAYS}} — your data is kept at least this long so you can export it
Deleting a case moves it to a deleted-cases area, where your firm can restore it for the period stated above. We will state here what happens to the underlying transcript file at the end of that period once we have verified that behaviour in the production environment.
How we protect it
How transcripts and chart data are protected in transit and at rest is stated below. Access to a matter is controlled per case; who can reach a case, and how that is enforced, is set out in detail on our Security page, which this policy does not repeat.
Our staff’s access to the platform is limited to what operating the service requires. No safeguard is absolute. These measures reduce the risk of unauthorized access; they do not make it impossible.
The application does not terminate TLS itself; what protects a connection to it depends on how a deployment is fronted. We will state the transport protections that apply here once the production deployment is verified.
Encryption of stored files is a property of the storage service a deployment points at, not something we set on each object we write. We will state what applies here once the production storage configuration is verified.
Transcripts and account data are stored in Amazon Web Services object storage. The storage region for a given deployment is set in that deployment’s configuration.
Your rights
You have the following rights over the personal information we hold about you:
- Access. You can ask what personal information we hold about you.
- Correction. You can ask us to correct information that is inaccurate or incomplete.
- Withdrawal of consent. Where we rely on your consent, you can withdraw it, subject to legal or contractual restrictions.
- Deletion. You can ask us to delete personal information we hold about you, subject to the same restrictions.
- Complaint. You can complain about how we handle personal information.
Quebec’s Law 25 adds two further rights: to be informed of any decision made about you through the exclusive use of automated processing, and to receive, in a structured and commonly used technical format, the computerized personal information you have provided to us — data portability.
To exercise any of these rights, contact our privacy officer using the details in the first section of this policy. We respond within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada or, for matters governed by Quebec law, the Commission d’accès à l’information du Québec.
Whose data this is
The firm is our customer. The transcript it uploads was not created by us and is not about us: it concerns the firm’s client, and it frequently names witnesses, opposing parties, and other third parties who have no relationship with TempusLexit and never agreed to send us anything.
The firm decides who within it may see a matter. Case access follows the model described on our Security page: a case is reachable by its owner, the individuals the firm explicitly adds to it, and the firm’s Owner and Admin users, by role alone. We do not decide who at the firm sees a case, and we do not grant access to anyone outside those groups.
If someone named in a transcript — a witness, an opposing party, anyone other than the firm itself — contacts us about that transcript, we route the request to the firm rather than act on it ourselves. The firm holds the professional relationship with that person; we do not, and we are not in a position to verify who they are or what they are entitled to.
Breaches
If we confirm a breach involving personal information, we assess whether it creates a real risk of significant harm to an individual — the standard PIPEDA sets — or, under Quebec law, a risk of serious injury. Where it does, we notify your firm, the Office of the Privacy Commissioner of Canada and, where Quebec law requires it, the Commission d’accès à l’information du Québec, on the timeline the applicable law sets. Where it does not, we notify your firm and record the incident.
We keep a record of every breach we investigate, confirmed or not, so a pattern is visible even where a single incident looks minor on its own.
If you suspect a problem — unexpected access to a matter, a security issue, or anything that looks wrong — contact our privacy officer using the details in the first section of this policy. We would rather look into a false alarm than have a real one go unreported.
Changes to this policy
We may update this policy from time to time. Where a change is material, we notify your firm before it takes effect.
The date at the top of this policy is the date it was last updated, and that date governs which version applies.