Privacy Policy
Last updated: March 30, 2026. This policy describes how Legience by Bostoneo Solutions LLC collects, uses, and protects your personal information.
1. Information We Collect
1.1 Information You Provide
When you create an account, contact us, or use our platform, we collect information you voluntarily provide, including:
- Account Information: Name, email address, firm name, bar number, professional title, and billing information.
- Case Data: Case details, client information, documents, notes, billing entries, and other data you enter into the platform.
- Communications: Messages you send through the platform, support requests, and feedback.
- Payment Information: Credit card and billing details processed securely through Stripe. We do not store full credit card numbers on our servers.
1.2 Information Collected Automatically
When you use our platform, we automatically collect:
- Usage Data: Pages visited, features used, time spent, and actions taken within the platform.
- Device Information: Browser type, operating system, IP address, and device identifiers.
- Cookies: See our Cookie Policy for details on how we use cookies and similar technologies.
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Legience platform and its features.
- Process payments and manage your account.
- Send transactional communications (account verification, billing notices, security alerts).
- Provide customer support and respond to your requests.
- Analyze platform usage to improve features and user experience.
- Comply with legal obligations, including Massachusetts 201 CMR 17.00.
3. How We Protect Your Information
We implement robust security measures to protect your data:
- Encryption: AES-256 encryption at rest and TLS encryption in transit for all connections.
- 201 CMR 17.00: Our security practices are designed to meet the requirements of Massachusetts Standards for the Protection of Personal Information.
- US-Only Data Residency: All data stored in AWS US-East. No offshore processing.
- Role-Based Access: Configurable permissions ensure users only access data relevant to their role.
- Audit Logs: Comprehensive logs of access, modification, and export actions across the platform.
4. AI and Your Data
AI Data Protection: When you use LegiSearch™, LegiDraft™, or LegiLyze™:
- AI queries are processed through AWS Bedrock, which operates under our AWS Business Associate Agreement (BAA) with encryption at rest and in transit.
- Your data is never used to train, fine-tune, or improve any AI model.
- AI conversation history is stored in our database to provide continuity features. You can delete conversations at any time from within the platform.
- We do not share your data with AI providers for any purpose other than processing your requests.
5. Data Sharing
We do not sell your personal information. We share data only with:
- Service Providers: Stripe (payments), BoldSign (e-signatures), Twilio (SMS), and AWS (hosting and AI processing via Bedrock) — each bound by applicable service agreements and data protection terms.
- Legal Requirements: When required by law, subpoena, or court order.
- Your Direction: When you explicitly authorize sharing (e.g., sending documents to clients via the Client Portal).
6. Data Retention and Deletion
We retain your data for as long as your account is active. Upon account termination:
- Your data is preserved for 90 days to allow reactivation or data export.
- After 90 days, all data is permanently and irreversibly deleted.
- You may request immediate deletion at any time by contacting privacy@legience.com.
7. Your Rights
You have the right to:
- Access, correct, or delete your personal information.
- Export your data in standard formats (CSV, PDF).
- Opt out of non-essential communications.
- Request information about how your data is processed.
8. Massachusetts Residents
If you are a Massachusetts resident, you have additional rights under applicable state laws Chapter 93H and 201 CMR 17.00, including the right to know what personal information we hold about you and the right to request deletion.
9. Children's Privacy
Legience is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or in-platform notification at least 30 days before the changes take effect.
11. Contact Us
For privacy-related questions or requests:
- Email: privacy@legience.com
- Mail: Bostoneo Solutions LLC, Malden, MA 02148