Privacy Policy
How we collect, use, and protect your information.
We do not sell your personal information. Learn about your privacy rights.
This Privacy Policy describes how Bizy Technologies LLC ("Company," "we," "us," or "our") collects, uses, and shares your personal information when you use our Hello JURI platform and services (collectively, the "Service").
1. Information We Collect
1.1 Personal Information You Provide
We collect information you provide directly to us, including:
- Account Information: Name, email address, phone number, profile photo, and password
- Professional Information: Law firm name, firm size, practice areas, jurisdictions, bar numbers
- Case Information: Client names, contact information, case details, court information, opposing party details
- Documents: Legal documents, contracts, briefs, and other files you upload
- Sensitive Matter Data: Some files or matter records may contain privileged, confidential, or sensitive personal information that you choose to submit through the Service
- Payment Information: Billing address and payment method details (processed by third-party payment processors)
- Communications: Emails, support requests, and other communications with us
1.2 Information Collected Automatically
When you access or use the Service, we automatically collect:
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Features used, pages viewed, time spent, click patterns, search queries, and limited product telemetry where enabled
- Advertising Attribution Data: Campaign parameters, referrer and landing page information, advertising click identifiers, and similar measurement data where optional marketing measurement is enabled
- AI Interaction Data: Metadata about AI feature usage (timing, feature type, response quality ratings) for service improvement. Query content is processed transiently to generate responses and is not stored for model training. See our AI Transparency page for details
- Cookies and Similar Technologies: See our Cookie Policy
1.3 Information from Third Parties
We may receive information about you from:
- Authentication Providers: When you sign in using a third-party authentication provider, we receive your name, email, and profile photo
- Integration Partners: Information from third-party services you connect to the Service
2. How We Use Your Information
We use your personal information for the following purposes:
| Purpose | Legal Basis (where GDPR applies) |
|---|---|
| Provide and maintain the Service | Performance of contract |
| Process AI requests and generate responses | Performance of contract |
| Process payments and billing | Performance of contract |
| Send service-related communications | Performance of contract |
| Improve and optimize the Service | Legitimate interest |
| Send marketing communications (with consent) | Consent |
| Measure advertising attribution and paid conversion performance where enabled | Consent where required |
| Detect and prevent fraud and abuse | Legitimate interest |
| Comply with legal obligations | Legal obligation |
3. AI Processing and Your Data
3.1 How AI Uses Your Data
When you use our AI features, your queries and uploaded documents are processed by our AI infrastructure to generate responses. This processing is subject to the following safeguards:
- Your data is not used to train AI providers' general-purpose models unless you or your organization explicitly opt in
- Processing is conducted under data processing agreements with each provider
- We select provider configurations intended for business or professional use
- Data is encrypted in transit while requests are sent to supported providers
3.2 We Do Not Train AI on Your Data
We do not use your personal information or uploaded documents to train general-purpose AI models. Your data is processed to provide you with the Service and is not incorporated into the training data of the AI models we use, except where you or your organization explicitly opts in to help improve our services.
4. How We Share Your Information
4.1 Service Providers
We share information with third-party service providers who perform services on our behalf:
We work with carefully vetted service providers across the following categories to deliver and operate the Service. All providers are bound by data processing agreements or equivalent contractual controls and are required to maintain security measures appropriate to the services they provide:
- Cloud Infrastructure: Secure hosting, storage, and computing services
- AI Processing: Enterprise AI services for document analysis and intelligent features
- Payment Processing: PCI-compliant billing and payment services
- Communications: Transactional email and notification delivery
- Analytics: Usage analytics and product telemetry used to improve the Service, subject to applicable consent settings and deployment configuration
- Advertising and Conversion Measurement: Campaign attribution and conversion measurement services, including Google Ads where enabled. Paid conversion reporting may include campaign identifiers, transaction metadata, and hashed first-party contact data used for measurement
4.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., subpoenas, court orders).
4.3 Business Transfers
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. In such an event, we will ensure that the acquiring entity is bound by privacy protections at least as protective as those described in this policy, or we will notify you and provide you with the opportunity to delete your data before the transfer is completed.
4.4 With Your Consent
We may share your information with third parties when you have given us your consent to do so.
5. Your Privacy Rights
5.1 For All Users
You have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request that we correct inaccurate or incomplete information
- Deletion: Request that we delete your personal information
- Export: Request an export of your data in a portable format
- Opt-out: Opt-out of marketing communications
5.2 For California Residents (CCPA/CPRA)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the following additional rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected
- Right to Delete: Request deletion of your personal information (subject to certain exceptions)
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell your personal information. For information about opting out of targeted advertising cookies, see our Cookie Policy
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Categories of Personal Information Collected (CCPA)
- • Identifiers (name, email, IP address)
- • Professional or employment-related information
- • Commercial information (payment history, subscription details)
- • Internet or electronic network activity
- • Geolocation data
5.3 For EU/UK Residents (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right to Access: Request access to your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing based on legitimate interests
- Right to Object to Automated Decision-Making: Contest decisions made solely by automated means
5.4 For Data Subjects in the Philippines
Where the Philippine Data Privacy Act of 2012 and its implementing rules apply, you may have the right to be informed, object, access, correct, erase or block certain personal data, seek data portability where applicable, and lodge a complaint with the National Privacy Commission (NPC).
- Right to Be Informed: Understand how and why your personal data is processed
- Right to Access and Rectification: Request access to and correction of personal data we hold about you
- Right to Erasure or Blocking: Request deletion, suspension, or blocking where permitted by law
- Right to Object: Object to certain processing activities where the law gives you that option
- NPC Complaint Right: You may contact the National Privacy Commission if you believe your privacy rights have been violated
5.5 How to Exercise Your Rights
To exercise your privacy rights, you may:
- Email us at legal@hellojuri.com
- Use the privacy settings in your account dashboard
- Write to us at the address listed in Section 11 below
We aim to respond within 30 days where GDPR applies, within 45 days where CCPA/CPRA applies, or within the time required by other applicable law.
6. Data Retention
We retain your personal information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy:
- Active Accounts: Personal information is retained while your account is active
- Terminated Accounts: After account termination, we retain your data for 90 days to allow for retrieval, after which it is permanently deleted
- Financial Records: Payment and billing information is retained for 7 years for tax and accounting purposes
- Legal Holds: We may retain data longer if required by law or legal process
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Encryption: AES-256 encryption at rest; TLS 1.3 encryption in transit
- Access Controls: Role-based access controls and multi-factor authentication
- Security Assessments: Regular security audits and vulnerability assessments
- Incident Response: Documented incident response procedures
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33). We will notify affected individuals without undue delay where the breach is likely to result in high risk. Where Philippine law applies, we will also follow applicable notification obligations to the National Privacy Commission and affected data subjects.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. When we transfer personal data from the European Economic Area (EEA), UK, or Switzerland to the US, we use Standard Contractual Clauses (SCCs) or other approved transfer mechanisms to ensure adequate protection. Where Philippine law applies, we use contractual, technical, or other safeguards that are intended to support lawful cross-border processing.
9. Children's Privacy
The Service is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For material changes, we will provide additional notice (e.g., email notification).
11. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Bizy Technologies LLC
Email: legal@hellojuri.com
Address: 30 N Gould St Ste R, Sheridan, WY 82801, United States
12. Privacy Contact
For privacy questions, including requests from EU, UK, or Philippine data subjects, contact legal@hellojuri.com.