Privacy Policy
Last updated: October 10, 2026
At Attorly, we take your privacy seriously. This privacy policy explains how we collect, use, and protect your personal information in accordance with GDPR and applicable data protection laws.
Our role as controller and processor
Attorly has two roles under the GDPR depending on the data type. For account information (name, email, billing details, usage logs, support messages), Getia AS acts as a data controller and determines the purposes and means of processing. For documents, drafts, and other content you upload to perform legal work ("Customer Content"), Getia AS acts as a data processor on behalf of you or your organization; a Data Processing Agreement governs that relationship and is available at /dpa.
What we collect
We collect: (a) identifying and account data (name, email, password hash, organization, workspace roles, chosen language); (b) billing data (country, VAT number where applicable, subscription status, trial status, invoice history — full card details are held by Stripe, not Attorly); (c) Customer Content you upload (documents, drafts, notes, timeline events, research); (d) technical data necessary to operate the service (IP address, session cookies, audit logs of significant actions); (e) communications you send to support. We do not collect sensitive special-category data unless it appears in Customer Content, in which case we process it solely as instructed by you.
How we use data
We process your data to: (a) deliver the service (GDPR Art. 6(1)(b), contract); (b) meet legal obligations such as tax and accounting (Art. 6(1)(c)); (c) send transactional emails about your account, billing, and critical service updates (Art. 6(1)(b) and (f)); (d) secure the service and prevent abuse (Art. 6(1)(f), legitimate interest); (e) understand how the website and the service are used, through the analytics described in our Cookie Policy, only with your consent (Art. 6(1)(a)); and (f) send marketing communications where we have your consent (Art. 6(1)(a)), which you can withdraw at any time. Customer Content is processed by our AI subprocessors (listed on the Subprocessors page) solely to deliver the output you request. We do not use Customer Content to train our own or any third-party AI models.
How long we keep data
Account data is retained while your account is active. On account closure, we delete account and Customer Content within 30 days, except where longer retention is required by law or needed to resolve disputes. Invoices and payment records are retained for the minimum period required by the applicable tax and bookkeeping laws of your jurisdiction (typically 5–10 years; Getia AS as a Norwegian company must retain them for at least 5 years from the end of the financial year). Failed payment and fraud-prevention logs are retained for up to 12 months. Audit logs of administrative and admin-panel actions are retained for 2 years (Art. 32 security). Analytics data is retained in aggregated, de-identified form. Full retention schedule is published in our Data Processing Agreement.
Data Security
We use industry-standard encryption and security controls. Customer Content and sensitive fields are encrypted at rest using authenticated encryption (AES-256-GCM); we support bring-your-own-key (BYOK) encryption on applicable plans. All network traffic is encrypted in transit with TLS 1.2 or higher. Access to production data is limited to named engineers, multi-factor-authenticated, and fully audited. We run continuous automated vulnerability scanning and follow responsible disclosure procedures; report security issues to security@attorly.ai.
Data Sharing and International Transfers
We never sell your personal data. We share it only with subprocessors that are necessary to deliver the service, under written data processing agreements that mirror our commitments to you. The current list is published at /subprocessors and updated at least 30 days before any material change. Transfers to subprocessors outside the EEA are covered by Standard Contractual Clauses (SCCs), the EU–US Data Privacy Framework where applicable, or another lawful transfer mechanism, together with supplementary measures such as encryption and access controls (Schrems II).
Word, Outlook and Google Docs add-ins
Attorly offers three add-ins: Attorly AI Legal Assistant for Microsoft Word, Attorly AI Email Assistant for Microsoft Outlook and Attorly AI for Google Docs. Each one connects to your Attorly account, and content leaves the host application only when you use one of its features, limited to what that feature needs. In Word, that is the text of the open document or of your selection when you run a review, ask a question, run a playbook or benchmark, or save a clause, and the values you enter when you fill a template. In Outlook, it is the open email (its subject, sender and body) when you summarize it or draft a reply, and the email with its recipients and the attachments you select when you save it to Attorly. Attorly AI for Google Docs can access only the document it is open in and does not send document text to Attorly: it sends the document ID, which library clauses you insert and the outcomes and notes you record. Text sent for an AI feature is processed by the AI subprocessors listed on our Subprocessors page solely to return the result to you, and is not stored in your account. Emails, attachments and clauses you choose to save are stored as Customer Content, encrypted at rest, and retained as described under How long we keep data. The add-ins keep a sign-in token in the host application, which signing out removes. Content handled through the add-ins is never used to train AI models.
Your rights
Under the GDPR and comparable data-protection laws you have the right to access, rectify, delete, port, and restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw any consent you have given. You can exercise most of these rights directly from your account settings (export data, close account). For any other request, or if you are not satisfied with our response, contact privacy@attorly.ai — we respond within 30 days. You also have the right to lodge a complaint with the data protection authority in your country of residence (for example Datatilsynet in Norway, IMY in Sweden, Datatilsynet in Denmark, the ICO in the UK, CNIL in France, the BfDI in Germany, or the FTC for US residents). You can find your local authority via edpb.europa.eu or the relevant national portal.
Children
Attorly is a B2B legal platform and is not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@attorly.ai and we will delete it.
Changes to this Policy
We may update this privacy policy. For material changes we will notify you by email and in-product at least 30 days before the change takes effect. For clarifications, typos, or updates required by law, we may make the update immediately.
Contact Information
For privacy questions, contact privacy@attorly.ai. Controller: Getia AS, org. no. 926 610 198, Tromsøgata 5C, 0565 Oslo, Norway. We typically respond within 30 days. We have not appointed a Data Protection Officer as we are not required to do so under GDPR Art. 37, but privacy@attorly.ai reaches the person responsible for data protection at Getia AS.
Questions about privacy?
Contact us if you have questions about how we process your personal data.