lawpatch

Privacy notice

Privacy notice

Who processes what, why, and what you can do about it. [legal entity name] is the controller for the data described here.

This notice covers data we process as a controller — the accounts of the people who use Lawpatch. Data we process on a customer’s behalf as a processor — the scan signals and findings belonging to their workspace — is covered by the data processing addendum.

What we process

DataWhyLawful basisRetention
Google account e-mail, display name, account identifierAuthentication, showing who is in a workspace, sending service messagesPerformance of a contract (Art. 6(1)(b) GDPR / KVKK Art. 5(2)(c))Until the account is deleted
Workspace, project and membership recordsRunning the product you signed up forPerformance of a contractUntil the workspace is deleted, then 30 days
Scan metadata and findings (repository-relative paths, line numbers, rule identifiers, analysis)Producing and storing the report you asked forPerformance of a contractUntil deleted by the customer, then 30 days
IP address and request metadataRate limiting, abuse prevention, diagnosing faultsLegitimate interests in keeping the service available and secure (Art. 6(1)(f))Rate-limit counters expire within the hour; hosting logs follow our host's retention
An invited colleague's e-mail addressDelivering the invitation you sentLegitimate interests of the inviting organisationUntil the invitation is claimed or withdrawn

What we deliberately do not process

  • Your source code. Detection runs on your machine. Only derived signals leave it, and secret values are never among them — a matched secret is reported by file and line, never by content. .env files are not read.
  • Advertising or analytics identifiers. There is no advertising network, no tracking pixel and no third-party analytics on this site.
  • Special categories of data. Nothing in the product asks for them and nothing in the pipeline is designed to hold them.

Cookies

We set no advertising or analytics cookies, which is why you are not being asked to consent to any. Signing in stores a Firebase authentication token in your browser’s local storage; it is strictly necessary to keep you signed in and is removed when you sign out.

Automated decisions

Lawpatch produces automated analysis about software, not about people, and it makes no decision that produces legal effects for an individual. The output is a prioritised list for a human to act on.

Sharing and international transfers

We share data only with the sub-processors listed here, each bound by a data processing agreement. Some are outside the EEA, the UK and Türkiye; those transfers rely on the EU Standard Contractual Clauses with the UK Addendum, on the EU-US Data Privacy Framework where the recipient is certified, and on explicit undertakings under KVKK Art. 9 where Turkish data is involved.

Your rights

Under the GDPR, the UK GDPR and KVKK you can ask for access, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. Under the CCPA/CPRA, California residents can ask what we collected, ask us to delete it, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined, and we do not offer financial incentives.

Write to privacy@lawpatch.studio. We answer within 30 days. You can also complain to your supervisory authority — in Türkiye the Kişisel Verileri Koruma Kurumu, in the UK the ICO, and in the EU the authority where you live or work.

Controller and representatives

[legal entity name], [registered address]. An Art. 27 GDPR representative is appointed where one is required.