Privacy policy

Last updated 30 August 2026

Legal Workspace is a practice management application for law firms. This policy explains what the application stores, where it is stored, who else can see it, and what happens to information reached through an account you connect to it.

Two different relationships are described here. A firm that subscribes to Legal Workspace decides what is put into it and why: for the matter files, documents and client information inside a workspace, the firm is the controller and we process on its instructions. For the account you use to sign in, and for information you connect to the workspace yourself, this policy describes what we do directly.

What the application stores

  • Your account. Name, work email address, the organization you belong to, your role in it, and a hashed password. Sign-in times and the device a session was established from are kept as part of the security record.
  • Firm content. Matters, clients, documents and their versions, tasks, deadlines, internal messages and comments — whatever the firm puts in.
  • An audit trail. Who did what, to which record, and when. This is a deliberate feature rather than a by-product: a firm asked later to account for access to a file needs the record to still exist, so audit entries are not deleted when the records they describe are.
  • Credentials for connected services, encrypted at rest. The tokens themselves are never returned by any endpoint and never reach the browser.

Where it is stored

The application and its database run on servers in Nuremberg, Germany. Uploaded files and document versions are held in object storage operated by Cloudflare. Outbound email is sent through Cloudflare. Data is not moved outside these services except as described under assistance below.

Google Drive and other connected accounts

You can connect your own Google account to the workspace. Doing so is yours to do and yours to undo, and it is not visible to your colleagues: an administrator can see that a connection exists and can revoke it, and cannot read what is inside it.

We request the https://www.googleapis.com/auth/drive scope. We ask for it rather than a narrower one because firms point the application at folders that already exist in their Drive, and because a document brought into a matter can later be written back to its source — neither of which the narrower scopes permit.

What happens to what we reach through it:

  • Browsing and opening a file does not copy it. When you look through your drive in the application, each listing and each file you open is fetched from Google at that moment, shown to you, and discarded. Nothing is written to our storage and nothing is indexed.
  • Google decides what you can see. The request is made with your own authorization, so a folder you cannot open in Drive is one this application cannot open either. No permission inside the workspace changes that.
  • A copy is made only when you ask for one. Bringing a file into a matter is a separate, deliberate action. From that point a copy is stored with the firm’s other documents, is visible to whoever works that matter, and is governed by this policy in the same way as a file uploaded directly. It is a snapshot: it does not track later changes in your drive, and changes to it are not written back.
  • Disconnecting stops all of it. The stored authorization is revoked with Google and deleted here. Copies already brought into a matter remain, because they are the firm’s records.

Legal Workspace’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it except as needed to provide the features described here, and we do not allow humans to read it except with your explicit permission, to resolve a problem you have reported to us, for security purposes, or where the law requires it.

Assistance

The application includes an assistant. When a member uses it, the text of the question and the content of the documents needed to answer it are sent to the model provider the firm has configured — Anthropic, OpenAI or Google — or to a provider the member has connected with their own credential. Retrieval is bounded by what that member is already permitted to read. A firm can restrict which providers may be used, and can require that a provider be one that retains nothing.

How long it is kept

Firm content is kept for as long as the firm keeps its workspace, subject to any retention policy the firm sets and to any legal hold it applies. A deleted document is removed from view immediately and erased from storage by a scheduled process. Audit entries outlive the records they describe, for the reason given above.

Your rights

You can ask for a copy of what we hold about you, ask for it to be corrected, or ask for it to be deleted. Where the information belongs to a firm’s workspace we will refer the request to that firm, which decides what happens to its own records. Write to admin@pulbsolutions.com.

Changes

If this policy changes in a way that affects what we do with your information, we will say so in the application before the change takes effect rather than only revising this page.