Privacy policy

Last updated: 01.09.2026

1. Introduction and Scope

This Privacy Policy explains how Jurisdixio (“Jurisdixio,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal data in connection with the Jurisdixio platform, website, applications, and related services (the “Platform”). This Policy is drafted with reference to Egypt’s Personal Data Protection Law No. 151 of 2020 (the “PDPL”) and its Executive Regulations issued under Minister of Communications and Information Technology Decree No. 816 of 2025 (the “Executive Regulations”).

This Policy applies to personal data we process as a Controller (in particular, data relating to registered Users and their Accounts) and describes our role as a Processor with respect to Client Data that Users and Firms upload to the Platform in the course of legal practice, as further described in Section 3.

This Policy should be read together with our Terms and Conditions of Use. Capitalized terms not defined here have the meaning given to them in the Terms and Conditions.

2. Definitions

“Personal Data” means any data relating to an identified or identifiable natural person (a “Data Subject”), whether directly or indirectly identifiable.

“Sensitive Personal Data” means Personal Data revealing categories such as health, criminal record, financial data, religious beliefs, or other categories treated as sensitive under the PDPL and Executive Regulations, which are subject to heightened protection and licensing requirements.

“Processing” means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transmission, or erasure.

“Controller” means the entity that determines the purpose and means of Processing Personal Data. “Processor” means the entity that Processes Personal Data on behalf of, and under the instructions of, a Controller.

“Cross-Border Transfer” means the transfer, storage, or circulation of Personal Data outside the Arab Republic of Egypt, by any means, including storage on servers located outside Egypt.

“Client Data” means Personal Data relating to a User’s or Firm’s own clients that is uploaded to, or generated within, the Platform in the course of legal practice. “PDPC” means Egypt’s Personal Data Protection Center, the supervisory authority established under the Ministry of Communications and Information Technology.

3. Who We Are; Controller and Processor Roles

3.1 In relation to Account and registration data — your name, contact details, login credentials, billing information, and usage data — Jurisdixio acts as the Controller.

3.2 In relation to Client Data that a User or Firm uploads to, or processes through, the Platform in connection with their own clients’ legal matters, Jurisdixio acts as a Processor, and the User or Firm acts as the Controller. Users and Firms are responsible for ensuring they have a valid legal basis, including any necessary consents from their own clients, before uploading Client Data to the Platform, and for complying with their own obligations as Controllers under the PDPL and any other applicable law.

3.3 Our contact details are: legal@jurisdixio.com

4. Personal Data We Collect

Account data: name, email address, phone number, professional role, language preference, and firm affiliation.

Billing data: billing name, address, and payment-related information processed through our payment processor.

Usage data: log-in activity, feature usage, Credit consumption, and device/browser information.

Content you provide: documents, case information, correspondence, and other materials you upload or generate using the Platform, which may include Client Data belonging to your own clients.

Communications: support tickets, feedback, and correspondence with us.

5. Legal Basis for Processing: Consent

Under Article 2 of the PDPL, Personal Data may not be collected, Processed, disclosed, or made available by any means except with the explicit consent of the Data Subject, or where otherwise permitted by law. By creating an Account and using the Platform, you provide your explicit consent to the Processing of your Personal Data as described in this Policy. Where we rely on a legal basis other than consent (for example, performance of our contract with you, or compliance with a legal obligation), we will identify that basis at the point of collection.

6. How We Use Personal Data

We use Personal Data to: provide, operate, and maintain the Platform; process transactions and manage billing and Credits; provide AI-assisted features, subject to the human-review requirements described in our Terms and Conditions; communicate with you about your Account and the Services; provide customer support; detect and prevent fraud, abuse, and security incidents; comply with legal obligations; and, where you have separately consented, for marketing and publicity purposes as described in our Terms and Conditions.

7. AI Processing and Sub-Processors

7.1 Certain features of the Platform use artificial intelligence models provided by third-party sub-processors, currently including Anthropic, OpenAI, and Google. When you use these features, relevant Personal Data or Client Data may be transmitted to these providers to generate AI Output, as described in our Terms and Conditions.

7.2 We also use third-party service providers for infrastructure, hosting, email delivery, and similar functions. A current list of material sub-processors is available on request from legal@jurisdixio.com, and we will notify Users of material changes to this list where required by law.

8. Sharing of Personal Data

Within a Firm, Personal Data and Client Data are shared among Authorized Users in accordance with the Firm’s own role-based access configuration on the Platform. We share Personal Data with the sub-processors described in Section 7, with professional advisers and service providers under confidentiality obligations, and where required by law, regulation, or a valid legal process. We do not sell Personal Data.

9. Data Retention and Deletion

We retain Personal Data for as long as necessary to provide the Platform and for legitimate business, legal, or regulatory purposes, consistent with the PDPL’s requirement that data not be retained longer than necessary for the purpose for which it was collected.

If you request deletion of your Account, we apply a thirty (30) day grace period during which deletion may be cancelled. Following that period: purely personal account data is permanently deleted; and Personal Data embedded in matters, documents, or other work product that may be subject to independent retention obligations (including our own recordkeeping obligations, and any professional or regulatory retention obligations applicable to you as a legal practitioner) is de-identified and preserved in anonymized form rather than deleted outright, consistent with our data retention and integrity obligations. Firm-owned records remain with the Firm in accordance with our Terms and Conditions and are not deleted merely because an individual User leaves the Firm.

10. Data Security

We implement administrative, technical, and physical safeguards designed to protect Personal Data, including role-based access controls, encryption in transit, database-level access controls (row-level security) segmenting data by Firm and by individual workspace, and logging of access to sensitive records. No system is completely secure, and we cannot guarantee absolute security.

11. Your Rights as a Data Subject

Subject to the PDPL and its Executive Regulations, you have the right to: be informed of the Processing of your Personal Data; access your Personal Data; request correction of inaccurate Personal Data; withdraw your consent at any time (which may limit or end your ability to use the Platform); object to Processing that contradicts the purpose for which your consent was given; request deletion of your Personal Data, subject to Section 9; and lodge a complaint with the PDPC.

To exercise these rights, contact us using the details in Section 17. We will respond within the timeframe required by applicable law.

12. Sensitive Personal Data

Where the Platform is used to process Sensitive Personal Data (as defined in Section 2), additional safeguards and, where required by the PDPL, specific licensing apply. Users and Firms uploading Sensitive Personal Data as Client Data remain responsible for ensuring they have an adequate legal basis to do so under applicable law and professional conduct rules.

13. Children’s Data

The Platform is intended for use by legal professionals and is not directed at, or knowingly used to collect Personal Data from, children. If we become aware that we have inadvertently collected Personal Data from a child in violation of applicable law, we will take steps to delete it.

14. Cookies and Similar Technologies

We use cookies and similar technologies to operate the Platform; your use of the Platform constitutes your continuous acceptance for us to use cookies and similar technologies to operate the Platform.

15. Data Breach Notification

In the event of a Personal Data breach, we will notify the PDPC within seventy-two (72) hours of becoming aware of the breach, and will notify affected Data Subjects within three (3) working days thereafter where required by the PDPL and its Executive Regulations, or as otherwise required by applicable law.

16. Changes to This Policy

We may update this Policy from time to time. We will provide notice of material changes by email or in-Platform notice. Continued use of the Platform after the effective date of such material changes constitutes acceptance of the revised Policy.

17. Contact Us and Complaints

Questions or requests regarding this Policy or your Personal Data may be directed to: legal@jurisdixio.com

This document is drafted in English. The Arabic translation is provided for convenience only; in the event of any conflict or inconsistency, the English version prevails.