Security
Last updated:
This page describes how UT Chart works. It is not legal advice.
Where your data is stored
Transcripts you upload, the chart items extracted from them, and your account details are held in Amazon Web Services object storage. The storage region is set out below, and encryption is covered in its own section.
Access is granted per case rather than firm-wide: a matter is visible to its owner, the collaborators explicitly added to it, and your firm’s Owner and Admin users, not to everyone at your firm. Who those roles are, and what their oversight access covers, is set out in the next section.
Transcripts and account data are stored in Amazon Web Services object storage. The storage region for a given deployment is set in that deployment’s configuration.
Who can reach it
A case can be opened by three groups: its owner, the collaborators explicitly added to it, and firm administrators. Belonging to your firm’s UT Chart account does not by itself open a case outside those three relationships.
Collaborators are added and removed by the case’s owner or by a firm administrator — the same two-way rule the Terms of Use state. A firm administrator does not need to be added to a case to manage who else is on it.
Firm administrators are the members holding the Owner or Admin role on your firm’s account — the same roles that manage your firm’s billing and seats. That role carries oversight access to every case in the firm, by role alone, independent of who owns or was added to any particular case. We say this plainly because it is a real access path, not an edge case: an Owner or Admin can open any case at your firm without being its owner or a named collaborator.
If a case owner leaves the firm, a firm administrator can move ownership of that case to another member as part of removing the departing member’s access, and any collaborators already on the case keep the access they had. Because administrator oversight access does not depend on ownership, the case remains reachable by the firm from the moment the owner departs, whether or not that handover happens immediately.
TempusLexit staff do not access case content as a matter of course. Staff access to the platform is limited to what operating the service requires and to investigating a fault a firm has reported.
Encryption
We do not offer or require customer-supplied encryption keys. Where encryption is applied, the keys are managed by us and by our storage provider, not by a key your firm holds and must safeguard separately.
What applies in transit and at rest is stated below.
The application does not terminate TLS itself; what protects a connection to it depends on how a deployment is fronted. We will state the transport protections that apply here once the production deployment is verified.
Encryption of stored files is a property of the storage service a deployment points at, not something we set on each object we write. We will state what applies here once the production storage configuration is verified.
AI processing
UT Chart uses an AI model to draft the wording of chart entries. What is sent, and to whom, is set out below.
What is sent is always the same and always limited: the question and answer text of individual chart items. The full transcript is never sent, and the uploaded PDF is never sent.
| Option | Where it goes | What is sent | Whose account |
|---|---|---|---|
| Off | None | Nothing leaves the platform | — |
| AI assistance we operate | Google (Gemini) | Question and answer text of individual chart items | TempusLexit Inc. |
AI wording assistance is optional. Your firm can turn it off, in which case no transcript text is sent to an AI provider.
AI wording assistance currently uses the provider we operate, described below. Support for supplying your own provider key is planned.
Whether excerpts sent for wording drafts may be used to improve the provider’s models depends on the service tier in use. We will state our position here once that is settled.
| Name | Purpose | Data reached | Location |
|---|---|---|---|
| Amazon Web Services | Hosting and object storage | Transcripts, account data | Region set in the deployment configuration |
| SMB Operations Inc. | Infrastructure operations management | Transcripts, account data | Canada |
| AI wording drafts (Gemini), on the AI assistance we operate | Question and answer text of individual chart items. Never the full transcript or the PDF. | Outside Canada | |
| Stripe | Billing | Account and payment data. No transcripts. | Outside Canada |
SMB Operations Inc. The AWS account holding transcripts is owned by SMB Operations Inc., a separate legal entity providing operations management services to TempusLexit Inc. TempusLexit Inc. remains accountable for the data; SMB Operations Inc. acts as a service provider on its behalf, not as a joint controller.
Retention and deletion
We keep your transcripts and the charts built from them for as long as your firm’s account is active. A matter can run for years, so there is no fixed timer on active data — we hold it for as long as it is needed for the purpose you gave it to us for, and no longer.
Two clocks do apply.
- A case you delete: 30 days — recoverable from the deleted items bin for this period — what happens to the stored transcript file at the end of it is stated immediately below
- After your subscription ends: {{RETENTION_POST_TERMINATION_DAYS}} — your data is kept at least this long so you can export it
Deleting a case moves it to a deleted-cases area, where your firm can restore it for the period stated above. We will state here what happens to the underlying transcript file at the end of that period once we have verified that behaviour in the production environment.
If something goes wrong
If we confirm a breach affecting your firm’s data, we assess whether it creates a real risk of significant harm to an individual — the standard PIPEDA sets — or, under Quebec law, a risk of serious injury. Where it does, we notify your firm, the Office of the Privacy Commissioner of Canada and, where Quebec privacy law requires it, the Commission d’accès à l’information du Québec, on the timeline the applicable law sets. Where it does not, we notify your firm and record the incident.
We keep a record of breaches, confirmed or not, so a pattern is visible even when a single incident looks minor on its own.
If you suspect a problem — unexpected access to a case, a security bug, or anything that looks wrong — report it using the contact details in the section below. We would rather look into a false alarm than have a real one go unreported.
Contacting us
Questions about this page, a suspected breach, or a request about your firm’s data go to our privacy officer, named below along with the mailing address of record.
- Privacy officer: {{PRIVACY_OFFICER}}
- Privacy email: {{PRIVACY_EMAIL}}
- Mailing address: {{REGISTERED_ADDRESS}}