1. Our Privacy Commitment
Casenta Legal is a legal matter intelligence and case-management platform. The platform may process information contained in legal files, correspondence, evidence, contracts, pleadings, reports, images and other documents uploaded by authorised users.
We recognise that this information may be confidential, commercially sensitive, privileged, personal, or otherwise subject to professional and legal obligations. Casenta Legal is therefore designed around data minimisation, controlled access, traceability and purpose-limited processing.
2. Security by Design
Casenta Legal uses layered technical and organisational controls intended to protect the confidentiality, integrity and availability of platform data.
- Authenticated access: platform functions require authenticated user access.
- Role-based permissions: functionality is restricted according to authorised user roles.
- Matter assignment controls: matter access can be limited to the users involved in a matter.
- Organisation separation: Casenta Legal queries and permissions are designed to keep organisation data logically separated.
- Secure transport: information is encrypted in transit, using industry-standard transport security, while travelling between the user's browser and Casenta Legal.
- Encryption at rest: uploaded source documents and extracted document segments are protected with industry-standard authenticated encryption while they are stored by Casenta Legal.
- Authenticated decryption: encrypted document content is decrypted by the Casenta Legal application only when required for authorised processing, review or retrieval.
- Secure document indexing: Casenta Legal uses a secure, cryptographically protected search index for encrypted document segments, allowing relevant material to be located without storing the indexed document text in plaintext.
- Password protection: passwords are stored using secure password hashing rather than plain-text storage.
- CSRF protection: sensitive account and matter actions use request-validation controls.
- Auditability: important review and matter actions are recorded so that human decisions can be traced.
- Controlled invitation flow: team members are invited using time-limited secure invitation tokens.
No internet-connected system can truthfully promise absolute security. Casenta Legal therefore describes security as a continuing risk-management obligation rather than making an unrealistic guarantee that a system can never be compromised.
3. Australian Privacy Principles & GDPR
Casenta Legal is an Australian company and, in handling personal information, is designed to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), which are the primary privacy law applicable to Casenta Legal's operations. Casenta Legal is also designed to support organisations that need to handle personal data in accordance with the principles of the EU and UK General Data Protection Regulation, and the equivalent New Zealand and UK frameworks, where those laws apply to a particular organisation or matter.
Our privacy approach is based on principles including:
- Lawfulness, fairness and transparency in the handling of personal information.
- Purpose limitation — data should be processed for legitimate Casenta Legal and legal work purposes.
- Data minimisation — users should upload and retain information that is relevant to the matter and service.
- Accuracy — Casenta Legal provides human-review workflows so AI proposals can be corrected, accepted or rejected.
- Storage limitation — information should not be retained indefinitely where there is no legal, contractual or operational reason to keep it.
- Integrity and confidentiality — access and technical controls are used to reduce unauthorised access, alteration or disclosure.
- Accountability — review activity and controlled workflows are intended to help organisations demonstrate responsible processing.
4. AI Processing & Legal Matter Data
Casenta Legal uses artificial intelligence to assist with document analysis and extraction, issue identification, evidence organisation, matter questioning, findings, and controlled matter synthesis.
AI output is not automatically treated as established truth. Casenta Legal has been designed around a human-review model:
- AI may propose an Issue, Proposition or Evidence item.
- An authorised human reviewer can edit, accept, reject or mark material as needing investigation.
- Only accepted/human-reviewed material should become established Case Map intelligence.
- Matter Position synthesis is intended to use the reviewed Case Map rather than silently creating new evidence.
Where third-party AI or infrastructure providers are used to deliver functionality, Casenta Legal will seek to configure and contract with those providers in a manner appropriate to confidential professional use and applicable privacy obligations.
5. Access, Teams & Confidentiality
Casenta Legal organisations can contain multiple users with different responsibilities. Access should be granted on a need-to-know basis.
- Organisation Owners and authorised Team Admins can manage team access.
- Lawyers and investigators can be assigned to matters relevant to them.
- Users can be deactivated when they leave an organisation or no longer require access.
- Pending invitations can be cancelled or reissued.
- Permissions limit which users can perform sensitive actions such as reviewing AI proposals, managing users or generating matter intelligence.
Organisations remain responsible for choosing appropriate users, assigning appropriate permissions and protecting login credentials.
6. Information We May Process
Depending on how Casenta Legal is used, information may include:
- account and organisation information;
- usernames, business email addresses and access roles;
- matter names, references, client details and party information;
- documents and information uploaded to a legal matter;
- document text extracted for analysis;
- human-reviewed Case Map intelligence;
- AI questions, findings and Matter Position snapshots;
- deadlines, tasks, notes and matter activity;
- technical information reasonably required for security, authentication and operation of the service.
7. How Information Is Used
Casenta Legal may process information to:
- provide and operate the platform;
- authenticate users and manage authorised access;
- process and analyse documents at the user's request;
- maintain the Case Map and associated source relationships;
- provide Ask Casenta Legal, Findings and Matter Position functionality;
- send service, invitation, security or deadline notifications;
- maintain security, diagnose errors and prevent misuse;
- maintain audit and activity records;
- comply with applicable law and legitimate legal obligations.
8. Service Providers & Subprocessors
Casenta Legal may rely on specialist hosting, email, security, database, infrastructure and AI service providers to deliver parts of the service.
Where a provider processes personal information on behalf of Casenta Legal, appropriate confidentiality, security and data-processing arrangements should be used in accordance with the nature of the service and applicable law.
Where cross-border processing occurs, Casenta Legal will seek to use appropriate contractual and legal safeguards where required, such as standard contractual clauses or an equivalent recognised transfer mechanism and will have regard to Australian Privacy Principle 8 (cross-border disclosure) in addition to any applicable GDPR transfer requirements.
9. Cookies & Website Analytics
The Casenta Legal website and platform use only cookies and similar technologies that are strictly necessary for authentication, security and core functionality, unless a specific feature states otherwise. Casenta Legal does not use third-party advertising or cross-site tracking cookies. Where analytics are used to understand aggregate product usage, Casenta Legal will seek to use privacy-conscious tools and will not use analytics data to build individual advertising profiles.
10. Data Retention & Deletion
Legal information often has legitimate retention requirements. Casenta Legal, therefore, does not apply a single automatic deletion period to every type of matter information.
Information may be retained while an organisation maintains an active account, while a matter remains operational, where required for audit or legal purposes, or for a reasonable period necessary to provide and protect the service.
Organisations should apply their own professional, regulatory, litigation-hold and records-management obligations when deciding what information should be retained or deleted. On termination of an account, Customer Data is handled in accordance with the export and deletion timeframes set out in the Casenta Legal Terms of Use, unless a separate written agreement states otherwise.
11. Privacy Rights & Complaints
Depending on applicable law and the circumstances, individuals may have rights concerning their personal information, including rights to request access, correction, deletion, restriction, objection or portability.
Where Casenta Legal processes information on behalf of a law firm or other organisation, requests concerning client or matter data may need to be directed to that organisation, because it may be the party responsible for determining how and why the information is processed.
12. Security Incidents
If Casenta Legal becomes aware of a security incident affecting protected information, the incident should be investigated promptly, contained where possible, documented and handled in accordance with applicable contractual and legal notification obligations.
Where a security incident is likely to result in serious harm to affected individuals, Casenta Legal will assess its notification obligations under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth) and equivalent notification obligations under other applicable law, and will notify the Office of the Australian Information Commissioner and affected individuals or organisations where required. Where Casenta Legal processes data on behalf of an organisation as a service provider, Casenta Legal will notify the affected organisation without undue delay so that the organisation can meet its own notification obligations.
Users should promptly notify Casenta Legal if they believe their account credentials, organisation access, or matter information may have been compromised.
13. Professional Responsibility
Casenta Legal supports legal professionals but does not replace professional judgment. Organisations and users remain responsible for determining whether information may lawfully be uploaded, how it should be used, who should have access, and what may ultimately be relied upon in professional work.
Users should take particular care with legally privileged, court-restricted, protected, highly sensitive or regulated information and comply with their applicable professional and confidentiality duties.
14. Changes to This Policy
This Privacy & Security Policy may be updated as Casenta Legal’s functionality, infrastructure, or legal obligations evolve. The current version will be published on the Casenta Legal website.
Last updated: 15 September 2026
Privacy & Security Contact
Questions about privacy, data protection or platform security can be directed to privacy@casenta.legal.
Please include sufficient information for us to identify the relevant account, organisation or matter without sending unnecessary confidential material by email.
← One Step Back