Attifin
Book a Demo
Attifin

AttiFin AI Ltd

Privacy Policy

Last updated: 23 July 2026

AttiFin AI Ltd respects your right to privacy. This Privacy Policy explains how we collect, use and share information that relates to an identifiable individual ("personal data"), and the rights you have under UK data protection law. It includes our Acceptable Use Policy and our AI Policy at the end.

AttiFin AI Ltd ("AttiFin", "we", "us", "our") provides a secure, UK-focused AI platform that helps legal professionals research, draft and summarise. We are a company registered in England and Wales (company number 16599945), with our registered office at Portland House, c/o Scrumconnect, New Bridge Street, Newcastle upon Tyne, England, NE1 8AP.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Controller vs processor. When you use our Service, the documents you upload and the queries and responses generated ("Customer Data" and "Content") are processed by us on behalf of our business customers. For that data we act as a processor and our customer is the controller, so requests about it should go to that customer. This Privacy Policy covers the personal data for which AttiFin is the controller — for example account, website and communications data. Processing of Customer Data is governed by our Data Processing Agreement (see section 13).

Contents

  1. Applicability
  2. Personal data we collect
  3. How we use personal data
  4. Legal bases (UK GDPR)
  5. Special category data
  6. Who we share data with
  7. Data residency & international transfers
  8. Security
  9. Personal data breaches
  10. Data retention
  11. Automated decision-making
  12. Your data protection rights
  13. Data we process for our customers
  14. Cookies
  15. Children
  16. Changes to this policy
  17. How to contact us
  18. Acceptable Use Policy
  19. AI Policy

1Applicability

This Privacy Policy describes how we process personal data collected through our website at attifin.ai (our "Website"), through the Service, and through other interactions you have with us. It does not apply to Customer Data and Content processed on behalf of our customers, which is governed by our agreement and Data Processing Agreement with that customer — see section 13.

2Personal data we collect

Information you give us

  • Account information — when you or your organisation set up and use an account: your name, email address, professional details and experience, language preferences, account credentials, billing details and transaction history.
  • Communication information — when you contact us, request support, respond to a survey or otherwise interact with us: your name, email address, the content of your messages, and your survey responses.
  • Social media information — information you choose to share when you engage with our pages on services such as LinkedIn, X or YouTube.

Information we collect automatically

  • Log data — information your browser or device sends, such as IP address, browser type and the date and time of requests.
  • Usage data — metadata about how you use the Service, such as account identifiers, frequency and duration of use, and which features you interact with. This excludes the contents of your Customer Data and Content.
  • Device information — device name, operating system, identifiers and browser.
  • Cookies and similar technologies — see section 14.

Information from third parties & public sources

We may receive information from security partners (e.g. to protect against fraud), marketing and event partners, and analytics providers. We also use publicly available information — such as published judgments, legislation and public filings — to develop and improve our AI platform.

Single sign-on and file import

If you choose to sign in using a third-party identity provider, we receive only the authentication data needed to identify you — typically your name, email address and a unique account identifier. We do not receive your password, and we do not access any other data held in that account. If you choose to import documents from a connected account, we access only the files you select for import. You can disconnect these integrations at any time.

Demo requests & sales enquiries

When you complete our "Book a Demo" form or contact our team, we collect the details you submit — typically your name, work email address, company or firm name, job role, phone number (if provided), country, and the content of your message — together with technical details such as your IP address and the date and time of submission. We use this to respond to you, arrange and run the demo, and, where you have agreed or where we may lawfully do so for business-to-business marketing, to send you related information about AttiFin. Our lawful bases are our legitimate interest in responding to your enquiry and developing our business, and your consent for marketing where required. You can opt out at any time, and you can reach the team at demo@attifin.ai. We keep demo and enquiry records for 24 months after our last contact with you, unless you become a customer, in which case they are retained under your customer agreement.

3How we use personal data

We use personal data to:

  • provide, maintain, secure and bill for the Service;
  • develop, improve and update the Service and our support;
  • provide customer support and resolve issues;
  • communicate with you, including about your account and (where permitted) marketing;
  • conduct research and understand how the Service is used;
  • detect, prevent and address fraud, misuse and security threats; and
  • comply with our legal obligations and protect our and others' rights.

We do not use Customer Data or Content to train AI models. We may aggregate or anonymise personal data so that you can no longer be identified, and use that data to study and improve the Service. We do not attempt to re-identify it unless required by law.

4Legal bases (UK GDPR)

Where the UK GDPR applies, we rely on the following legal bases under Article 6:

Legal basisWhen we rely on it
ContractTo set up and maintain your account, provide and support the Service, and process payments.
Legal obligationTo meet our legal, tax, accounting and regulatory duties and to respond to lawful requests.
ConsentFor certain marketing, for non-essential cookies, and for optional features that send data to a third party (see section 7). You can withdraw consent at any time, without affecting processing already carried out.
Legitimate interestsTo operate, secure, personalise and improve the Service, to send business-to-business marketing where permitted, to prevent misuse, and to protect our legal rights — balanced against your interests and rights.

5Special category data

The personal data for which AttiFin is the controller — account, website and communications data — does not normally include special category data as defined in Article 9 UK GDPR.

Documents uploaded to the Service by our customers may contain special category data (for example health or criminal-offence information about individuals involved in a legal matter). Where that happens, AttiFin acts as processor and the customer, as controller, is responsible for identifying the Article 9 condition it relies on — commonly Article 9(2)(f), processing necessary for the establishment, exercise or defence of legal claims. Our Terms restrict the submission of special category data except where this is lawful and agreed.

6Who we share data with

We share personal data with the following categories of recipient:

  • Our group — affiliates that help operate our business under appropriate safeguards.
  • Cloud hosting and storage providers — who host the platform and store data on our behalf.
  • AI model providers — who process document extracts and queries to generate answers, summaries and drafts.
  • Search providers — where a customer enables the optional live web-search feature.
  • Identity, single sign-on and file-import providers — where a customer enables those optional integrations.
  • Communications providers — who deliver transactional and service emails.
  • Business operations providers — payment and billing, analytics, security and customer support.
  • Advisers, authorities and regulators — where reasonably necessary to comply with law, respond to lawful requests, enforce our terms, or protect rights, property and safety.
  • Business transfers — in connection with a merger, acquisition, financing or sale of assets, in which case we will notify you where required.
  • Our customers — your organisation may receive information about your account and use of the Service.

Every provider that processes personal data on our behalf acts only on our instructions and is engaged under a written contract imposing data protection obligations equivalent to those we owe our customers, as required by Article 28 UK GDPR.

We do not sell your personal data, and we do not share Customer Data or Content with any third party for their own purposes.

Current list of sub-processors. We do not publish the identity of individual suppliers on this page. Customers and prospective customers can obtain the current list, together with our Data Processing Agreement, by contacting legal@attifin.ai. Under that agreement we give customers advance notice of any intended addition or replacement of a sub-processor, together with an opportunity to object.

7Data residency & international transfers

Our default is UK residency. The AttiFin platform is hosted in the United Kingdom, and all Customer Data — the documents you upload, the queries you run and the content generated — is stored in the UK.

Certain optional features, which a customer chooses to switch on, involve limited personal data being processed outside the UK. Where those features are not enabled, no personal data leaves the UK.

Optional featureWhat is processed outside the UKWhere
Live web searchThe search query only. Personal data is minimised and redacted before the query is sent where technically possible. Uploaded documents are never transferred.United States
Single sign-onAuthentication data — your name, email address and a unique account identifier.EEA, or worldwide depending on the provider you use
Document import from a connected accountOnly the files you select for import.Worldwide depending on the provider you use
Transactional email deliveryYour email address and the content of service messages.EEA
AI inference, where an EEA-hosted model is configuredDocument extracts and queries relevant to the request.EEA

For each of these transfers we rely on an appropriate safeguard recognised under UK law — UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework), the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. Before making a restricted transfer we complete a transfer risk assessment (the "data protection test" under UK law) to satisfy ourselves that the safeguard provides protection consistent with UK standards.

You can obtain details of the safeguards that apply to a particular transfer, including a copy where one is available, by contacting privacy@attifin.ai.

Customers who require strict UK-only processing can disable these optional features; contact us and we will confirm the configuration in writing.

Note for the site owner — delete this box before publishing. When the optional features above are retired or moved to UK-hosted providers, replace the whole of section 7 with: "AttiFin is built for UK data residency. We store and process all personal data covered by this Privacy Policy within the United Kingdom and do not transfer it outside the UK. Our suppliers process this data within the UK. If this changes we will update this policy and put the safeguards required by UK data protection law in place before any transfer takes place."

8Security

We protect personal data using technical and organisational measures appropriate to the risk, as required by Article 32 UK GDPR. These include:

  • Encryption — data is encrypted in transit and at rest;
  • Separation between customers — each customer's documents, conversations and results are logically separated and access-controlled, so one customer cannot access another's data;
  • Access control — role-based permissions, with access limited to those who need it;
  • Key management — encryption keys are centrally managed and rotated on a regular cycle;
  • Monitoring — we monitor for security events and maintain incident response procedures;
  • No model training — Customer Data and Content are never used to train AI models, by us or by our suppliers.

Further detail on our security measures is available to customers and prospective customers under a confidentiality agreement. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9Personal data breaches

We maintain procedures to detect, investigate, record and report personal data breaches.

Where we act as controller, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of a notifiable breach, and will inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

Where we act as processor for a customer, we will notify that customer without undue delay after becoming aware of a personal data breach affecting their data, and will provide the information and cooperation they reasonably need to meet their own obligations.

10Data retention

We keep personal data only for as long as needed for the purposes in this policy. Our standard periods are:

DataRetention
Account and identity dataDuration of the active account, plus a short grace period after closure to allow for recovery.
Uploaded documents, conversations and AI-generated draftsSet by the customer under their own retention policy. Deleted within 30 days of termination unless the customer asks otherwise or we must retain it by law.
Demo and enquiry records24 months after last contact.
Billing and transaction recordsAs required by tax and accounting law, generally six years.
Website log dataA rolling period appropriate to security monitoring, after which it is deleted or anonymised.

When we no longer have a legitimate need to process personal data, we delete or anonymise it, or securely isolate it from further processing until deletion is possible.

11Automated decision-making

The Service is designed to assist qualified professionals, not to replace them. We do not make decisions producing legal or similarly significant effects about individuals based solely on automated processing within the meaning of Article 22 UK GDPR. Our Terms and Acceptable Use Policy require that AI output is reviewed by a qualified human before it is relied upon, and prohibit using output to make decisions materially affecting a person's legal rights without meaningful human review.

12Your data protection rights

Subject to applicable law, you have the right to:

  • be informed about how we use your personal data (this policy);
  • access, correct, update or request deletion of your personal data;
  • object to or restrict our processing of your personal data;
  • request portability of your personal data in a structured, commonly used, machine-readable format;
  • opt out of marketing at any time (use the unsubscribe link in our emails or contact us);
  • withdraw consent where we rely on it, without affecting earlier processing; and
  • complain to a supervisory authority.

We will respond within one month of receiving your request, which we may extend by a further two months for complex requests — we will tell you if that happens. In the UK you can complain to the Information Commissioner's Office (ico.org.uk). We would, however, appreciate the chance to address your concerns first.

13Data we process for our customers

If your personal data appears in documents uploaded to AttiFin by a law firm or other organisation — for example because you are a party, witness or contact in a legal matter — that organisation is the controller and AttiFin is its processor. We process that data only on the customer's documented instructions.

Requests to exercise your rights over that data should be directed to the organisation concerned. If you contact us instead, we will pass your request to the relevant customer without undue delay and assist them in responding. Note that professional obligations of confidentiality and legal professional privilege may affect how such a request is answered.

Our obligations to customers are set out in our Data Processing Agreement, which covers processing on documented instructions, confidentiality, security, sub-processors, assistance with data subject rights, breach notification, deletion or return of data at the end of the contract, and audit rights. Customers can request it at legal@attifin.ai.

14Cookies

We use cookies and similar technologies to operate the Website and Service, remember your preferences, measure performance and (where permitted) support marketing. You can control non-essential cookies through our cookie banner and your browser settings. For more detail, see our Cookie Policy.

15Children

Our Website and Service are not directed to anyone under 18 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@attifin.ai and we will take steps to delete it.

16Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in law, technology or our business. When we do, we will update the "last updated" date above and, for significant changes, take appropriate steps to inform you.

17How to contact us

For any questions about this policy or to exercise your rights, contact us at privacy@attifin.ai, or write to AttiFin AI Ltd, Portland House, c/o Scrumconnect, New Bridge Street, Newcastle upon Tyne, England, NE1 8AP.

Our Data Protection Officer is Praveen, who can be contacted at praveen@attifin.ai for any data protection questions or to exercise your rights.

↑ Back to top

Annex A

Acceptable Use Policy

This Acceptable Use Policy forms part of your Terms with AttiFin. Capitalised terms not defined here have the meaning given in the Terms of Service.

You agree not to, and not to allow your users or any third party to, use the Service to:

Break the law or harm others' rights, including to:

  • violate or compromise the privacy or legal rights of any person;
  • infringe, misappropriate or violate a third party's intellectual property rights;
  • identify an individual from biometric data, or build a biometric database;
  • exploit the vulnerabilities of a person or group based on age, disability or social or economic situation in a way likely to cause harm;
  • evaluate, score or profile individuals based on their social behaviour or personal characteristics; or
  • treat individuals in a detrimental, unfair or discriminatory way.

Compromise security or integrity, including to:

  • introduce viruses, malware, corrupted files or other harmful or deceptive material;
  • interfere with the Service or the systems used to provide it; or
  • disable, circumvent or interfere with any part of the Service.

Misuse the AI, including to:

  • build a product or feature that competes with the Service;
  • provide legal advice based on Output without human review;
  • make automated decisions that materially or detrimentally affect a person's rights without human supervision; or
  • be a substantial factor in decisions about an individual's access to education, employment opportunities, or entitlement to legal services or representation, without meaningful human involvement.

European Union. If you or your users are in the EU, or use Output in the EU, you also agree not to use the Service to: make decisions about a person's admission or access to education; evaluate learning outcomes or determine the level of education a person can access; or, if you are or act for a judicial authority, to research and interpret facts and the law and apply the law to a concrete set of facts.

↑ Back to top

Annex B

AI Policy

This AI Policy describes AttiFin's approach to developing and deploying artificial intelligence ("AI") in the Service. It is intended to provide transparency about our practices and commitments, including compliance with law, responsible use, data sourcing, our technical and organisational measures, transparency and risk management. We may update it to reflect changes in technology, regulation or best practice, and it should be read alongside our Acceptable Use Policy above.

1. Compliance with law

To the extent applicable to our provision of the Service, we comply with the laws and regulations governing AI, including UK requirements and, where relevant, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689).

2. AI literacy & responsible use

We take steps to ensure our staff who operate and develop the AI behind the Service have an appropriate level of AI literacy, and we maintain internal policies for the ethical and responsible use of AI.

3. Data sources

We take steps to obtain the rights and licences needed for the data sets used in the Service, and we have procedures to monitor and verify compliance with third-party rights when sourcing data. We do not train our models on your Customer Data or Content, and our suppliers are contractually prohibited from doing so.

4. Accuracy, bias and technical measures

We implement and maintain measures around the development and provision of the AI, including internal AI governance policies, security measures, testing to monitor the accuracy, reliability and suitability of Output, and change-management processes to maintain compliance with applicable law and standards. Answers are designed to be grounded in verified UK and client sources and to be citable and auditable, so that a reviewer can trace a statement back to its source. AI systems can nonetheless produce inaccurate, incomplete or unrepresentative output, which is why human review is required before Output is relied upon.

5. Transparency and human oversight

We provide features and information to help you ensure that people who interact with the Service are informed that they are interacting with AI, and that Output is reviewed by a qualified human before it is relied upon. The Service supports, and does not replace, the professional judgement of the qualified individual using it.

6. Confidentiality and legal professional privilege

The Service is a closed system: your content is processed within your own tenant, is not used to train models, and is not made available to other customers or to the public. This is designed to support the confidentiality obligations of regulated legal professionals and to avoid the loss of privilege that can follow from entering confidential material into publicly available AI tools. See section 8 of our Terms of Service.

7. Optional features

Some features are switched off by default and process data differently when enabled — in particular the live web-search feature, which sends a search query to an external provider. Where a feature changes how your data is handled, we describe this in the applicable documentation and in section 7 of our Privacy Policy.

↑ Back to top

AI purpose-built for UK legal professionals.
Trained in UK law. Fully compliant with UK data regulations.

© 2026 AttiFin AI Ltd. Registered in England & Wales.

  • Privacy Policy
  • Terms of Service