Privacy notice
Complaints & AML keeps a law firm's complaints register and its anti-money-laundering records. The firm is the controller of its clients' data; we process it on the firm's instructions. This notice describes what the software actually does today, not what it might do later.
Who is responsible
Data controller for this service: Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions about your data: privacy@vitersoft.com. For the records a firm keeps here about its own clients, that firm is the controller and we are its processor.
What is stored
- The firm's name, SRA number and settings, and the name, e-mail address and role of each user.
- Matter references and client initials — not client names or addresses while the pilot flag is on.
- Complaint records: dates, categories, the client's concerns as the firm typed them, and the letters.
- AML records: the firm-wide risk assessment, matter risk assessments, source of funds, training, audits.
- An append-only log of who changed what, which the firm needs to show an inspector.
A risk assessment can record that a client is a politically exposed person, and a complaint can describe somebody's health. That is special category data under Article 9 of the UK GDPR, and it is one reason the pilot asks for initials only.
How long
Each firm sets its own retention period, six years by default. AML records are not removed earlier than the period the Money Laundering Regulations require after the end of a client relationship — a figure the firm confirms rather than one we assume. A firm can export everything at any time, and its owner can delete the firm and every record it holds from the settings screen — that takes effect at once and leaves nothing behind for us to recover.
Who else sees it
- Cloudflare, Inc. (USA and EU) — runs the application. The worker is pinned to the EU region.
- Supabase (EU, Frankfurt) — the database. Only our server can read it; the public keys hold no rights at all.
- Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (trading as Brevo) — sends sign-in links and deadline reminders. Reminders name references and initials, never a client's name and never what a complaint is about. Brevo puts an invisible image in every letter it sends, so it registers when a letter is opened and from roughly where. We do not ask for that, do not look at it and cannot switch it off per message — measured 19.09.2026, both documented switches were tried. The sign-in link itself is not rewritten and does not go through Brevo.
- PostHog (EU, Germany) — counts how the tool is used: numbers and categories, no personal data, no firm names.
No language model is used. The letters and the assessments are assembled by code from what the firm typed, and the “rephrase” feature described in the specification is switched off. Where any recipient processes data outside the UK or the EEA, the transfer is covered by Standard Contractual Clauses.
Cookies
One: the sign-in cookie, which holds the firm and the person and nothing else. The analytics are configured without cookies and without local storage, so there is no banner to click.
Your rights
A firm can export a copy of everything it holds here, correct it, or delete the whole account itself. Anyone can complain to the Information Commissioner's Office (ico.org.uk). Where the data is about a firm's client, that firm answers the request and we help it do so.