What is the first pass costing your firm? Run your numbers
All legal documents Legal

Privacy Policy

Version 1.4 · Effective 21 September 2026

Entity: Solicia AI Pty Ltd (ACN 702 502 903, ABN 68 702 502 903), New South Wales, Australia ("Solicia", "we", "us")

Privacy contact: privacy@solicia.ai

This policy explains how Solicia collects, holds, uses and discloses personal information, and how you can contact us about it. It is written against the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where the Privacy Act 2020 (New Zealand) applies to information about people in New Zealand, we apply this policy consistently with that Act.

It covers four groups of people:

  • visitors to solicia.ai;
  • prospective customers who contact us or request access;
  • users of the Solicia service, who are people invited by a customer organisation; and
  • people who appear in customer data, such as a customer's clients, counterparties, witnesses and correspondents, whose information reaches us inside the documents and emails a customer submits.

1. What Solicia is

Solicia is an AI-assisted legal workflow service. Authorised users at a customer organisation send instructions and documents by email, or work in the dashboard, and the service returns generated work product for review by a qualified person. Where a customer enables it, the Solicia Associate is a standing assistant with its own email address that keeps matter memory and can read mail and documents the customer has connected.

2. Our role for customer data

Content that a customer submits to the service, and the outputs generated for it, are customer data. The customer decides what to submit and why. Solicia processes customer data on the customer's instructions to provide, secure and support the service, under the Customer Terms of Service. If you are a person whose information appears in customer data, the customer organisation is the right first contact for access, correction and complaints, and we will help it respond. We will not use customer data for any purpose other than delivering the service.

3. What we collect

Account information (users). Name, work email address, organisation, role, and authentication data. Passwords are stored only as salted one-way hashes. Multi-factor authentication secrets are stored encrypted. If your organisation uses Microsoft Entra ID sign-in, we receive your verified identity from your organisation's directory.

Customer data. Emails, attachments, instructions, documents, matter information and the outputs we generate. This may contain personal information about anyone mentioned in it, including sensitive information and legally privileged material, which the customer is responsible for having the right to provide.

Connected services (where a user or organisation connects them). If you connect a mailbox, document store or collaboration tool such as Microsoft 365, Google Workspace or Dropbox, we store the access tokens (encrypted) and the scopes you granted, and we read only what the connected feature needs. Where the Associate is enabled and a mailbox is connected, the Associate reads messages in that mailbox to keep matter memory current, within the exclusions your organisation sets.

Operational and security data. Audit logs of activity across the service, including sign-ins, administrative actions, work submitted and delivered, document access, deletions, and any access by Solicia staff across customer boundaries. These logs include timestamps, the acting user, the IP address of the request and technical details of the event. We also record diagnostic logs of AI requests and responses so that we can investigate problems and verify outputs.

Website data. solicia.ai sets no cookies and uses no third-party analytics. It sends a first-party visit beacon to our own Cloudflare Worker that records the page, the approximate location and network operator that Cloudflare derives from the connection, and a hash of the day and IP address that cannot be reversed to the address itself. If you use the Request Access form we collect the name, firm and work email you enter.

Communications. Emails you send us, support requests, and notes of calls and meetings with prospective and current customers.

We do not collect information for advertising, we do not buy personal information, and we do not sell it.

4. Why we collect and use it

  • to provide the service to the customer, including generating outputs, delivering them by email, and keeping matter memory where the Associate is enabled;
  • to secure the service: authentication, fraud and abuse detection, audit, incident investigation and response;
  • to support customers and users and to communicate about the service, including invitations, security notices and service changes;
  • to operate and improve the service using aggregated operational metrics that do not identify a customer, an individual or the substance of a matter;
  • to meet legal obligations and enforce our agreements.

We do not use customer data or personal information to train general-purpose AI models. AI processing runs on the Azure OpenAI Service under Microsoft's data-processing terms for that service, which do not permit Microsoft or OpenAI to train models on it.

We send marketing communications only to people who have asked to receive them, and every such message includes a way to opt out.

5. Who we disclose it to

Subprocessors. Providers that host or process data on our behalf: cloud hosting and storage, AI inference, email delivery, network security and, only where a customer enables web research, a web-search provider. The current list, naming each provider and what it handles, is published at solicia.ai/legal/subprocessors. Customers receive at least 30 days' notice of a material new subprocessor where practicable.

Your organisation. If you are a user, your organisation's administrators can see your account, your activity and the work you submit.

Professional advisers and successors. Lawyers, accountants and insurers under confidentiality, and a successor if Solicia is restructured or sold, on terms that protect the information.

Government and law enforcement. Only where legally required. We verify legal authority, seek to narrow overbroad requests, disclose only what is required, keep a record, and notify the affected customer before disclosure unless we are prohibited from doing so. We do not voluntarily disclose customer data to any government agency.

6. Where information is stored and processed

Customer data at rest is stored in the region assigned to your organisation. For every customer onboarded to date, that region is Australia.

Some processing happens outside that region in a limited and transient way. This can include AI inference within the data zone the region belongs to, encrypted web traffic passing through a global network security and delivery layer, and a sanitised search query sent to a search provider where web research is used. No documents, emails or system access are shared with a search provider, and no customer data is stored outside your region.

Our providers are incorporated in the United States and deliver the service from your region. Customer data is held there, encrypted in transit and at rest, and covered by each provider's data-protection terms, alongside the disclosure policy above. The countries involved for each provider are set out in the subprocessor register.

7. How we protect it

Encryption in transit and at rest; a private network for the database and cache that is not reachable from the internet; per-customer isolation enforced in the application layer; role-based access; multi-factor authentication for all administrative access; audit logging with automated alerting; secrets and dependency scanning in development; backups with tested restores; and a documented incident response process. A fuller description is in our Security and Trust Overview. No system is perfectly secure, and we cannot guarantee that unauthorised access will never occur.

8. How long we keep it

Customer data. For the retention period the customer sets. The default is 365 days from completion of the work; a customer administrator can choose any whole-day period from 0 to 3,650 days, or no scheduled deletion. After a customer's agreement ends we delete customer data from production systems within 30 days of termination or a verified deletion request, unless the law requires us to keep it.

Backups. Deleted content persists in backups and point-in-time recovery for a limited period before expiring on its ordinary cycle. It remains encrypted and subject to the same access controls and confidentiality obligations throughout.

Account information. For as long as the account exists, then for a limited period needed for security, dispute resolution and legal compliance.

Audit and security logs. For a period consistent with our security obligations to customers, then deleted or reduced to aggregated form.

Website beacon records and access requests. For a limited period sufficient to understand interest in the service, then deleted.

9. Access, correction and complaints

You can ask us for access to, or correction of, personal information we hold about you by emailing privacy@solicia.ai. We will respond within 30 days. Where the information sits inside customer data, we will refer your request to the customer organisation and assist it.

If you have a complaint about how we have handled your personal information, contact privacy@solicia.ai first. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (oaic.gov.au). People in New Zealand can also contact the Office of the Privacy Commissioner (privacy.org.nz).

10. Data breaches

If a data breach is likely to result in serious harm to individuals, we notify the affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, and where the New Zealand Act applies, the Office of the Privacy Commissioner. Separately, we notify each affected customer's nominated security contact within 24 hours of becoming aware of an incident that may materially affect the security of its data, regardless of that threshold.

11. Cookies

The dashboard and console use strictly necessary cookies to keep you signed in; they expire when your session ends or after 8 hours. The public website sets no cookies.

12. Children

The service is for use by professionals within customer organisations and is not directed at people under 18.

13. Changes to this policy

We may update this policy. Each version carries a date. We will tell account holders directly about material changes before they take effect.

14. Data from connected Google and Microsoft accounts

Where a user connects a Google account (Gmail, Drive, Calendar) or a Microsoft 365 account (Outlook mail and calendar, SharePoint, OneDrive, Teams), Solicia holds an access token for that account, encrypted, limited to the permissions that user approved, and usable only for the features those permissions serve.

What we do with it. We read the messages, files and calendar entries the connected feature needs to answer the request in front of us or to keep matter memory current, within the exclusions the organisation has set. We write only what a user has asked for: finished work product filed into a folder the user nominates, a prepared reply left in that user's own Drafts folder, or a calendar event the user requested. Solicia has no permission to send mail as a user, and does not request one; a person presses Send. Content we read may be stored inside that customer's own Solicia workspace as part of the matter record, and is handled under this policy like any other customer data.

What we never do with it. We do not transfer it to anyone for advertising, we do not sell it, and we do not use it to train generalised AI or machine-learning models. AI processing runs on the Azure OpenAI Service under terms that do not permit Microsoft or OpenAI to train models on it. No human reads the content of a connected account except with the user's explicit consent, where it is necessary for security purposes (such as investigating abuse or a suspected incident), where the law requires it, or where the data has been aggregated and de-identified for internal operations.

Google Limited Use. Solicia's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting. A user can disconnect a connected account at any time from Solicia → Dashboard → Connectors, which deletes the stored tokens immediately. Access can also be withdrawn from the provider's side — for Google at myaccount.google.com/permissions, and for Microsoft 365 by an administrator in Entra under Enterprise applications. Withdrawing access stops further reading; the matter record already built from what was read is retained and deleted under section 8.

15. Contact

Solicia AI Pty Ltd (ACN 702 502 903, ABN 68 702 502 903), New South Wales, Australia privacy@solicia.ai · paralegal@solicia.ai · security incidents: security@solicia.ai