AttiFin AI Ltd
Last updated: 7 June 2026
AttiFin AI Ltd respects your right to privacy. This Privacy Policy explains how we collect, use and share information that relates to an identifiable individual ("personal data"), and the rights you have under UK and EU data protection law. It includes our Acceptable Use Policy and our AI Policy at the end.
AttiFin AI Ltd ("AttiFin", "we", "us", "our") provides a secure, UK-focused AI platform that helps legal professionals research, draft and summarise. We are a company registered in England and Wales (company number 16599945), with our registered office at Portland House, c/o Scrumconnect, New Bridge Street, Newcastle upon Tyne, England, NE1 8AP.
This Privacy Policy describes how we process personal data collected through our website at attifin.ai (our "Website"), through the Service, and through other interactions you have with us. It does not apply to Customer Data and Content processed on behalf of our customers, which is governed by our agreement and Data Processing Agreement with that customer.
We may receive information from security partners (e.g. to protect against fraud), marketing and event partners, and analytics providers. We also use publicly available information — such as published judgments, legislation and public filings — to develop and improve our AI platform.
When you complete our "Book a Demo" form or contact our team, we collect the details you submit — typically your name, work email address, company or firm name, job role, phone number (if provided), country, and the content of your message or what you would like to see — together with technical details such as your IP address and the date and time of submission. We use this to respond to you, arrange and run the demo, and, where you have agreed or where we may lawfully do so for business-to-business marketing, to send you related information about AttiFin. Our lawful bases are our legitimate interest in responding to your enquiry and developing our business, and your consent for marketing where required. You can opt out of marketing at any time, and you can reach the team at demo@attifin.ai. We keep demo and enquiry records for [• e.g. 24] months after our last contact with you, unless you become a customer, in which case they are retained under your customer agreement.
We use personal data to:
We may aggregate or anonymise personal data so that you can no longer be identified, and use that data to study and improve the Service. We do not attempt to re-identify it unless required by law.
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases:
| Legal basis | When we rely on it |
|---|---|
| Contract | To set up and maintain your account, provide and support the Service, and process payments. |
| Legal obligation | To meet our legal, tax, accounting and regulatory duties and to respond to lawful requests. |
| Consent | For certain marketing and where else required by law. You can withdraw consent at any time. |
| Legitimate interests | To operate, secure, personalise and improve the Service, to send business-to-business marketing where permitted, to prevent misuse, and to protect our legal rights — balanced against your interests and rights. |
We do not sell your personal data.
AttiFin is built for UK data residency, and Customer Data is hosted in the United Kingdom unless otherwise agreed. Some personal data for which we are the controller may be transferred to, or accessed from, countries outside the UK or European Economic Area (EEA) — for example where a service provider operates elsewhere.
Where we transfer personal data internationally, we rely on an appropriate safeguard recognised under UK and EU law, such as a UK adequacy decision, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, and we take additional measures where needed to protect your data.
We protect personal data using technical and organisational measures designed to reduce the risk of unauthorised access, loss, alteration or disclosure, appropriate to the risk of the processing. AttiFin does not train AI models on Customer Data or Content, and our outputs are designed to support SRA-aligned, citation-backed work. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
We keep personal data for as long as needed for the purposes in this policy — for example to provide the Service under your customer agreement, to meet legal, tax and accounting obligations, and to resolve disputes or enforce our agreements. When we no longer have a legitimate need to process your personal data, we delete or anonymise it, or securely isolate it from further processing until deletion is possible.
We use cookies and similar technologies to operate the Website and Service, remember your preferences, measure performance and (where permitted) support marketing. You can control non-essential cookies through our cookie banner and your browser settings. For more detail, see our Cookie Policy.
Our Website and Service are not directed to anyone under 18 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@attifin.ai and we will take steps to delete it.
Subject to applicable law, you have the right to:
In the UK you can complain to the Information Commissioner's Office (ico.org.uk). In the EEA you can complain to your local data protection authority. We would, however, appreciate the chance to address your concerns first.
We may update this Privacy Policy from time to time to reflect changes in law, technology or our business. When we do, we will update the "last updated" date above and, for significant changes, take appropriate steps to inform you.
For any questions about this policy or to exercise your rights, contact us at privacy@attifin.ai, or write to AttiFin AI Ltd, Portland House, c/o Scrumconnect, New Bridge Street, Newcastle upon Tyne, England, NE1 8AP.
Our Data Protection Officer is Praveen, who can be contacted at praveen@attifin.ai for any data protection questions or to exercise your rights.
↑ Back to topAnnex A
This Acceptable Use Policy forms part of your Terms with AttiFin. Capitalised terms not defined here have the meaning given in the Terms of Service.
You agree not to, and not to allow your users or any third party to, use the Service to:
Break the law or harm others' rights, including to:
Compromise security or integrity, including to:
Misuse the AI, including to:
European Union. If you or your users are in the EU, or use Output in the EU, you also agree not to use the Service to: make decisions about a person's admission or access to education; evaluate learning outcomes or determine the level of education a person can access; or, if you are or act for a judicial authority, to research and interpret facts and the law and apply the law to a concrete set of facts.
↑ Back to topAnnex B
This AI Policy describes AttiFin's approach to developing and deploying artificial intelligence ("AI") in the Service. It is intended to provide transparency about our practices and commitments, including compliance with law, responsible use, data sourcing, our technical and organisational measures, transparency and risk management. We may update it to reflect changes in technology, regulation or best practice, and it should be read alongside our Acceptable Use Policy above.
To the extent applicable to our provision of the Service, we comply with the laws and regulations governing AI, including UK requirements and, where relevant, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689).
We take steps to ensure our staff who operate and develop the AI behind the Service have an appropriate level of AI literacy, and we maintain internal policies for the ethical and responsible use of AI.
We take steps to obtain the rights and licences needed for the data sets used in the Service, and we have procedures to monitor and verify compliance with third-party rights when sourcing data. We do not train our models on your Customer Data or Content.
We implement and maintain measures around the development and provision of the AI, including internal AI governance policies, security measures, testing to monitor accuracy, reliability and suitability of Output, and change-management processes to maintain compliance with applicable law and standards. Every answer is designed to be grounded in verified UK and client sources and to be citable and auditable.
We provide features and information to help you ensure that people who interact with the Service are informed that they are interacting with AI, and that Output is reviewed by a qualified human before it is relied upon.
↑ Back to top