Casenta Legal ← One Step Back
Privacy · Confidentiality · Security

Your legal data deserves serious protection.

Casenta Legal is designed for legal work, where confidentiality, controlled access, evidentiary integrity and responsible handling of personal information are not optional. Security and privacy are built into the platform’s structure.

Encrypted at rest Uploaded documents and extracted document content are protected using industry-standard encryption at rest.
Role-based permissions Access is controlled according to user role and matter assignment.
Human-controlled AI AI proposals do not automatically become established Case Map material.
Auditable workflows Review decisions and key matter actions are designed to remain traceable.
Casenta Legal privacy principle: Casenta Legal does not sell client data, does not turn legal files into an advertising asset, and does not use them to train AI models. Client data exists to run the Casenta Legal service, not to be monetised elsewhere.
Privacy Commitment Security APPs & GDPR AI & Matter Data Access Controls Cookies Retention Rights & Complaints Security Incidents Contact

1. Our Privacy Commitment

Casenta Legal is a legal matter intelligence and case-management platform. The platform may process information contained in legal files, correspondence, evidence, contracts, pleadings, reports, images and other documents uploaded by authorised users.

We recognise that this information may be confidential, commercially sensitive, privileged, personal, or otherwise subject to professional and legal obligations. Casenta Legal is therefore designed around data minimisation, controlled access, traceability and purpose-limited processing.

Casenta Legal does not treat uploaded legal material as public content. Matter information is intended to remain available only to authorised users within the relevant organisation and matter workflow, subject to the permissions configured for that account.

2. Security by Design

Casenta Legal uses layered technical and organisational controls intended to protect the confidentiality, integrity and availability of platform data.

How Casenta Legal protects document content at rest. Uploaded source documents and extracted document segments are encrypted using industry-standard encryption. Casenta Legal's secure, cryptographically protected search index supports targeted retrieval of encrypted document content without storing the indexed document text in plaintext. When an authorised workflow needs the underlying content, the Casenta Legal application decrypts it in memory for that processing. This is application-level encryption at rest; it should not be described as end-to-end encryption because Casenta Legal must be able to decrypt authorised content in order to provide document analysis, review and retrieval functions. The specific technical measures used may be updated over time as Casenta Legal's security architecture evolves.

No internet-connected system can truthfully promise absolute security. Casenta Legal therefore describes security as a continuing risk-management obligation rather than making an unrealistic guarantee that a system can never be compromised.

3. Australian Privacy Principles & GDPR

Casenta Legal is an Australian company and, in handling personal information, is designed to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), which are the primary privacy law applicable to Casenta Legal's operations. Casenta Legal is also designed to support organisations that need to handle personal data in accordance with the principles of the EU and UK General Data Protection Regulation, and the equivalent New Zealand and UK frameworks, where those laws apply to a particular organisation or matter.

Our privacy approach is based on principles including:

Where an organisation uploads client or matter data to Casenta Legal, that organisation will commonly determine the legal purpose for processing that data. Depending on the circumstances and applicable law, Casenta Legal may act as a service provider, processor or APP entity in relation to that information.

4. AI Processing & Legal Matter Data

Casenta Legal uses artificial intelligence to assist with document analysis and extraction, issue identification, evidence organisation, matter questioning, findings, and controlled matter synthesis.

AI output is not automatically treated as established truth. Casenta Legal has been designed around a human-review model:

AI proposes. Humans establish. This separation is a core Casenta Legal safeguard for legal work and helps reduce the risk of unreviewed AI output being mistaken for verified evidence or a legal conclusion.

Where third-party AI or infrastructure providers are used to deliver functionality, Casenta Legal will seek to configure and contract with those providers in a manner appropriate to confidential professional use and applicable privacy obligations.

5. Access, Teams & Confidentiality

Casenta Legal organisations can contain multiple users with different responsibilities. Access should be granted on a need-to-know basis.

Organisations remain responsible for choosing appropriate users, assigning appropriate permissions and protecting login credentials.

6. Information We May Process

Depending on how Casenta Legal is used, information may include:

7. How Information Is Used

Casenta Legal may process information to:

Casenta Legal does not use confidential matter documents for unrelated advertising, does not sell legal matter data to data brokers or anyone else, and does not use Customer Data to train artificial intelligence models.

8. Service Providers & Subprocessors

Casenta Legal may rely on specialist hosting, email, security, database, infrastructure and AI service providers to deliver parts of the service.

Where a provider processes personal information on behalf of Casenta Legal, appropriate confidentiality, security and data-processing arrangements should be used in accordance with the nature of the service and applicable law.

Where cross-border processing occurs, Casenta Legal will seek to use appropriate contractual and legal safeguards where required, such as standard contractual clauses or an equivalent recognised transfer mechanism and will have regard to Australian Privacy Principle 8 (cross-border disclosure) in addition to any applicable GDPR transfer requirements.

9. Cookies & Website Analytics

The Casenta Legal website and platform use only cookies and similar technologies that are strictly necessary for authentication, security and core functionality, unless a specific feature states otherwise. Casenta Legal does not use third-party advertising or cross-site tracking cookies. Where analytics are used to understand aggregate product usage, Casenta Legal will seek to use privacy-conscious tools and will not use analytics data to build individual advertising profiles.

10. Data Retention & Deletion

Legal information often has legitimate retention requirements. Casenta Legal, therefore, does not apply a single automatic deletion period to every type of matter information.

Information may be retained while an organisation maintains an active account, while a matter remains operational, where required for audit or legal purposes, or for a reasonable period necessary to provide and protect the service.

Organisations should apply their own professional, regulatory, litigation-hold and records-management obligations when deciding what information should be retained or deleted. On termination of an account, Customer Data is handled in accordance with the export and deletion timeframes set out in the Casenta Legal Terms of Use, unless a separate written agreement states otherwise.

11. Privacy Rights & Complaints

Depending on applicable law and the circumstances, individuals may have rights concerning their personal information, including rights to request access, correction, deletion, restriction, objection or portability.

Where Casenta Legal processes information on behalf of a law firm or other organisation, requests concerning client or matter data may need to be directed to that organisation, because it may be the party responsible for determining how and why the information is processed.

If you have a complaint about how Casenta Legal handles personal information, you can contact privacy@casenta.legal. Casenta Legal will acknowledge and seek to resolve complaints within a reasonable period. If you are not satisfied with Casenta Legal's response, and the complaint concerns information subject to Australian law, you may raise it with the Office of the Australian Information Commissioner (OAIC). Individuals in the EU or UK may have equivalent rights to complain to their local data protection authority.

12. Security Incidents

If Casenta Legal becomes aware of a security incident affecting protected information, the incident should be investigated promptly, contained where possible, documented and handled in accordance with applicable contractual and legal notification obligations.

Where a security incident is likely to result in serious harm to affected individuals, Casenta Legal will assess its notification obligations under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth) and equivalent notification obligations under other applicable law, and will notify the Office of the Australian Information Commissioner and affected individuals or organisations where required. Where Casenta Legal processes data on behalf of an organisation as a service provider, Casenta Legal will notify the affected organisation without undue delay so that the organisation can meet its own notification obligations.

Users should promptly notify Casenta Legal if they believe their account credentials, organisation access, or matter information may have been compromised.

13. Professional Responsibility

Casenta Legal supports legal professionals but does not replace professional judgment. Organisations and users remain responsible for determining whether information may lawfully be uploaded, how it should be used, who should have access, and what may ultimately be relied upon in professional work.

Users should take particular care with legally privileged, court-restricted, protected, highly sensitive or regulated information and comply with their applicable professional and confidentiality duties.

14. Changes to This Policy

This Privacy & Security Policy may be updated as Casenta Legal’s functionality, infrastructure, or legal obligations evolve. The current version will be published on the Casenta Legal website.

Last updated: 15 September 2026

Privacy & Security Contact

Questions about privacy, data protection or platform security can be directed to privacy@casenta.legal.

Please include sufficient information for us to identify the relevant account, organisation or matter without sending unnecessary confidential material by email.