1. Introduction
JurisFlow respects the privacy of individuals whose personal data is processed through its website, applications, software and related services.
This Privacy Policy explains how JurisFlow collects, uses, stores, protects, discloses and otherwise processes personal data when individuals access or use the JurisFlow platform.
JurisFlow is a legal technology and legal practice management platform designed to assist lawyers, law firms, legal departments and other authorised users in managing legal matters, clients, documents, schedules, tasks, communications and related professional activities.
Because JurisFlow may be used to process information concerning lawyers, employees, clients, prospective clients, witnesses, opposing parties, court personnel and other individuals, privacy and data security are fundamental to the operation of the Platform.
This Privacy Policy should be read together with the JurisFlow Terms and Conditions of Use and any applicable Data Processing Agreement or subscription agreement.
By accessing or using JurisFlow, you acknowledge that you have read and understood this Privacy Policy.
2. Who we are
For purposes of this Privacy Policy, "JurisFlow", "we", "us" and "our" refer to the operator of the JurisFlow platform.
JurisFlow may act in different capacities depending upon the nature of the personal data being processed.
Where JurisFlow determines the purposes and means of processing personal data for its own business purposes, it may act as a Data Controller within the meaning of applicable Nigerian data protection law.
Where JurisFlow processes personal data solely on the documented instructions of a law firm, legal department or other subscribing organisation, JurisFlow may act as a Data Processor.
The relevant law firm, legal department or organisation may therefore remain responsible for determining the lawful purpose and means of processing client or matter-related personal data uploaded to the Platform.
The precise allocation of responsibilities may be further defined in an applicable Data Processing Agreement.
3. Applicable data protection law
JurisFlow processes personal data in accordance with applicable data protection legislation and regulatory requirements.
For users and data subjects in Nigeria, the principal legislation governing the processing of personal data is the Nigeria Data Protection Act 2023, together with applicable regulations, directives, guidelines and other instruments issued by the Nigeria Data Protection Commission (NDPC).
The Nigeria Data Protection Act establishes the regulatory framework for the protection of personal data and the rights of data subjects in Nigeria.
Where JurisFlow processes personal data subject to the data protection laws of another jurisdiction, JurisFlow will apply the relevant requirements to the extent applicable.
4. Information we collect
Depending on how you interact with JurisFlow, we may collect different categories of personal data. These may include:
4.1 Identity Information
This may include:
- full name;
- title;
- professional designation;
- date of birth where required;
- photograph or profile image where voluntarily provided;
- professional registration information; and
- other information used to establish identity.
4.2 Contact Information
This may include:
- email address;
- telephone number;
- postal address;
- business address;
- organisation details; and
- other contact information.
4.3 Account Information
When you create a JurisFlow account, we may collect:
- username;
- account credentials;
- organisation information;
- user role;
- subscription information;
- account preferences;
- authentication information; and
- account status.
Passwords should be stored using appropriate security mechanisms and should not ordinarily be accessible to JurisFlow personnel in readable form.
4.4 Professional Information
Where relevant, JurisFlow may process:
- law firm information;
- professional position;
- practice area;
- professional qualifications;
- bar or professional registration details;
- work history;
- department;
- role within an organisation; and
- information necessary to administer access to the Platform.
4.5 Client and Matter Information
Users may voluntarily enter information concerning clients, prospective clients, witnesses, opposing parties and other persons involved in legal matters. Such information may include:
- names;
- contact details;
- identification information;
- matter descriptions;
- case numbers;
- court information;
- transaction information;
- communications;
- documents;
- legal correspondence;
- deadlines;
- court dates;
- instructions; and
- other information relevant to the legal matter.
The User or subscribing organisation remains responsible for determining whether it has an appropriate lawful basis and authority to process such information.
4.6 Documents and Files
JurisFlow may process documents uploaded by Users, including:
- contracts;
- pleadings;
- affidavits;
- court processes;
- legal opinions;
- correspondence;
- witness statements;
- evidence;
- client instructions;
- transaction documents;
- reports;
- invoices; and
- other legal or business records.
4.7 Usage and Technical Information
When you access JurisFlow, we may automatically collect information concerning your interaction with the Platform, including:
- IP address;
- device type;
- browser type;
- operating system;
- login information;
- access times;
- session information;
- pages and features accessed;
- error logs;
- security events; and
- other technical information.
4.8 Transaction and Billing Information
Where you subscribe to paid Services, we may process information necessary to administer payment and billing.
Payment-card or other financial information may be processed directly by third-party payment providers where applicable.
JurisFlow may receive limited transaction information from such providers for purposes including payment confirmation, reconciliation, fraud prevention and account administration.
5. Information we do not require
JurisFlow does not intentionally require Users to provide sensitive personal information unless such information is necessary for the provision of a particular Service or is lawfully processed through a User's legal practice.
Users should not upload personal information to JurisFlow merely because it is technically possible to do so.
Where sensitive personal data is necessary for a legal matter, the User or subscribing organisation remains responsible for ensuring that its processing is lawful and appropriate.
6. How we collect personal data
We may obtain personal data:
- directly from you;
- from your law firm or organisation;
- from an authorised account administrator;
- through information entered into the Platform;
- through documents uploaded to the Platform;
- through correspondence with JurisFlow;
- through your use of the website or application;
- through cookies and similar technologies;
- from payment providers;
- from authentication providers;
- from service providers; or
- from other lawful sources.
Where personal data concerning a third party is uploaded by a User, the User is responsible for ensuring that the processing and disclosure of that information to JurisFlow are lawful.
7. Purposes for which we process personal data
JurisFlow may process personal data for purposes including:
- creating and administering User accounts;
- providing the JurisFlow Services;
- managing subscriptions;
- authenticating Users;
- managing access permissions;
- storing and organising legal information;
- facilitating matter management;
- facilitating document management;
- providing calendar and scheduling functionality;
- sending reminders and notifications;
- providing customer support;
- maintaining security;
- detecting and preventing fraud and abuse;
- monitoring system performance;
- maintaining and improving the Platform;
- investigating technical problems;
- processing payments;
- complying with legal obligations;
- responding to lawful requests from public authorities;
- protecting the rights and property of JurisFlow and its Users; and
- communicating important information concerning the Services.
Where required by law, JurisFlow will identify an appropriate lawful basis for processing.
8. Lawful basis for processing
JurisFlow will process personal data only where there is a lawful basis for doing so.
Depending upon the circumstances, the lawful basis may include:
- consent;
- performance of a contract;
- compliance with a legal obligation;
- protection of vital interests;
- performance of a task carried out in the public interest where applicable; or
- legitimate interests, where recognised by applicable law and where those interests are not overridden by the rights and interests of the data subject.
The appropriate lawful basis will depend upon the nature and circumstances of the processing.
Where processing is based on consent, the data subject may withdraw consent subject to applicable legal limitations and the consequences of withdrawal.
9. Client data processed through JurisFlow
JurisFlow recognises that law firms and legal practitioners may use the Platform to process confidential client information.
Where a law firm or other organisation uploads client information to JurisFlow, the organisation ordinarily determines the purposes for which that information is processed.
JurisFlow will process such information only as necessary to provide the Services and in accordance with the applicable contractual and data-processing arrangements.
JurisFlow does not use a law firm's Client Data for unrelated commercial purposes merely because the information is stored on the Platform.
10. Legal professional confidentiality
JurisFlow recognises the special nature of information generated or received in the course of legal practice.
JurisFlow will implement appropriate organisational and technical measures designed to restrict access to Client Data.
However, responsibility for professional confidentiality remains with the lawyer or law firm.
Users must ensure that:
- they upload information lawfully;
- appropriate access permissions are established;
- former employees and personnel are removed from accounts when necessary;
- confidential documents are not unnecessarily shared; and
- the use of JurisFlow complies with applicable professional obligations.
JurisFlow's role as a technology provider does not replace the professional confidentiality obligations of a legal practitioner.
11. Data retention
JurisFlow retains personal data only for as long as reasonably necessary for the purpose for which it was collected or processed, subject to applicable legal, contractual, regulatory and operational requirements.
Different categories of information may therefore have different retention periods.
Information may be retained for purposes including:
- providing continuing Services;
- maintaining account records;
- meeting contractual obligations;
- complying with legal obligations;
- resolving disputes;
- preventing fraud;
- maintaining security records; and
- establishing, exercising or defending legal claims.
When personal data is no longer required, JurisFlow will take reasonable steps to delete, anonymise or otherwise securely dispose of it, subject to applicable retention obligations.
12. Data storage
Personal data may be stored on infrastructure operated by JurisFlow or its authorised service providers.
Depending upon the architecture of the Platform, data may be stored or processed within or outside Nigeria.
Where personal data is transferred outside Nigeria, JurisFlow will implement applicable safeguards required by Nigerian data protection law and other applicable legislation.
13. International data transfers
Where JurisFlow transfers personal data across national borders, it will do so in accordance with applicable data protection requirements.
International transfers may occur where necessary for:
- cloud hosting;
- technical support;
- security;
- data backup;
- payment processing;
- software infrastructure;
- customer support; or
- other legitimate business purposes.
Where required, JurisFlow will implement appropriate legal, contractual or technical safeguards governing the transfer.
14. Service providers and third parties
JurisFlow may engage carefully selected third-party service providers to support the operation of the Platform.
Such providers may provide services including:
- cloud hosting;
- database infrastructure;
- payment processing;
- email delivery;
- SMS or communication services;
- authentication;
- security monitoring;
- analytics;
- customer support;
- backup services; and
- other technical infrastructure.
JurisFlow will require appropriate contractual and security safeguards from relevant service providers where required by applicable law.
Third-party service providers may process personal data only to the extent necessary to perform their authorised functions.
15. Disclosure of personal data
JurisFlow may disclose personal data where reasonably necessary:
- to provide the Services;
- to authorised Users;
- to the organisation that administers an account;
- to service providers;
- to payment processors;
- to professional advisers;
- to competent regulatory authorities;
- to law enforcement agencies where lawfully required;
- to courts or tribunals pursuant to lawful process;
- to protect the rights, safety or property of JurisFlow or another person; or
- where otherwise permitted or required by law.
JurisFlow will not ordinarily sell Client Data to third parties.
17. Analytics
JurisFlow may use analytics tools to understand how Users interact with the Platform.
Analytics may assist JurisFlow in:
- identifying technical problems;
- understanding feature usage;
- improving user experience;
- monitoring performance;
- detecting unusual activity; and
- improving the reliability of the Platform.
Where analytics involve personal data, JurisFlow will process that information in accordance with applicable data protection requirements.
18. Account administrators and employer access
Where you use JurisFlow through a law firm, company or other organisation, an authorised administrator may have access to information associated with your organisational account.
Such access may include:
- account information;
- matter assignments;
- documents;
- tasks;
- calendar entries;
- activity records; and
- other information made available according to the organisation's configured permissions.
The organisation is responsible for determining appropriate access rights among its Users.
JurisFlow is not responsible for an organisation's internal access-control decisions where those decisions are made through authorised administrative functions.
19. Data security
JurisFlow takes reasonable technical and organisational measures designed to protect personal data against:
- unauthorised access;
- unauthorised disclosure;
- loss;
- destruction;
- alteration;
- misuse; and
- other unlawful or unauthorised processing.
Security measures may include:
- authentication controls;
- role-based access;
- encryption where appropriate;
- logging and monitoring;
- backup procedures;
- security testing;
- access restrictions;
- incident-management procedures; and
- staff security controls.
Security measures may change as technology and threats evolve.
No method of electronic storage or transmission can guarantee absolute security.
20. Personal data breaches
JurisFlow maintains procedures for identifying, assessing and responding to suspected personal data breaches.
Where a breach occurs, JurisFlow will take reasonable steps to:
- contain the incident;
- assess the nature and extent of the breach;
- protect affected information;
- investigate the cause;
- implement remedial measures; and
- make notifications where required by applicable law.
Where JurisFlow processes information on behalf of a law firm or other organisation as a Data Processor, notification and cooperation obligations may be governed by the applicable Data Processing Agreement.
21. Your rights as a data subject
Subject to applicable law and relevant exceptions, data subjects may have rights including:
- the right to be informed about processing;
- the right to request access to personal data;
- the right to request correction of inaccurate personal data;
- the right to request deletion or erasure in appropriate circumstances;
- the right to object to certain processing;
- the right to request restriction of processing;
- the right to data portability where applicable;
- the right to withdraw consent where processing is based on consent;
- the right to lodge a complaint with the competent supervisory authority; and
- rights relating to automated decision-making where applicable.
The NDPC expressly identifies these categories of data-subject rights under the Nigeria Data Protection Act.
These rights are not absolute and may be subject to statutory exceptions, competing legal obligations, legal claims, confidentiality requirements and other lawful restrictions.
22. How to exercise your rights
A data subject wishing to exercise a privacy right may contact JurisFlow through the privacy contact details provided in this Privacy Policy.
A request should contain sufficient information to enable JurisFlow to:
- identify the requester;
- understand the request;
- locate the relevant information; and
- respond appropriately.
JurisFlow may request reasonable information necessary to verify the identity of the requester before disclosing or modifying personal data.
The NDPC currently provides a data-subject access request mechanism under sections 34 to 38 of the NDP Act and states that requests should ordinarily receive a response within the applicable statutory period.
Where a request concerns Client Data controlled by a law firm or other organisation, JurisFlow may refer the request to the relevant organisation where that organisation is the appropriate Data Controller.
23. Children's data
JurisFlow is principally intended for legal professionals, law firms, legal departments and other authorised professional Users.
JurisFlow does not knowingly seek to collect children's personal data for unrelated commercial purposes.
Where information concerning a child is legitimately processed as part of a legal matter, such processing may occur where the User or subscribing organisation has a lawful basis for doing so and complies with applicable legal requirements.
Users must exercise particular care when uploading information concerning children or other vulnerable persons.
24. Automated processing and artificial intelligence
JurisFlow may introduce automated or artificial intelligence-assisted functionality. Such functionality may include:
- document classification;
- information extraction;
- search;
- summarisation;
- workflow suggestions;
- document analysis;
- matter organisation; or
- other productivity functions.
Where such functionality processes personal data, the processing will be subject to applicable data protection requirements.
JurisFlow will not represent that automated or AI-generated outputs are inherently accurate.
Users must independently review material generated by automated systems before relying upon it in legal or other consequential matters.
Where applicable law gives data subjects rights relating to solely automated decision-making, JurisFlow will respect those rights.
25. Marketing communications
JurisFlow may send service-related communications necessary for the administration and operation of an Account.
Where permitted by law, JurisFlow may also send promotional or marketing communications concerning its products or Services.
Users may unsubscribe from marketing communications through the mechanism provided in the relevant communication.
Unsubscribing from marketing communications will not ordinarily prevent JurisFlow from sending essential administrative, security, transactional or legal notices.
26. Direct marketing and third-party disclosure
JurisFlow will not ordinarily provide Client Data to third parties for independent direct-marketing purposes.
Where personal data is used for marketing, JurisFlow will comply with applicable legal requirements concerning consent, objection and other data-subject rights.
27. Data minimisation
JurisFlow seeks to process personal data that is adequate, relevant and reasonably necessary for the purposes for which it is processed.
Users should avoid uploading personal information that is unnecessary for the relevant legal matter or Platform function.
28. Accuracy of personal data
JurisFlow seeks to maintain accurate personal data within information under its control.
Users are responsible for maintaining the accuracy of information they enter into the Platform.
Where you discover that information held by JurisFlow is inaccurate, you may request correction in accordance with applicable law.
29. Your responsibilities
Users are responsible for:
- providing accurate information;
- maintaining account security;
- using appropriate access permissions;
- ensuring that uploaded information may lawfully be processed;
- respecting client confidentiality;
- complying with professional obligations;
- maintaining appropriate independent records where necessary; and
- notifying JurisFlow of suspected security incidents.
30. Privacy of client data
A law firm's use of JurisFlow does not automatically make JurisFlow the Data Controller of the firm's client information.
Where JurisFlow processes information solely on behalf of a law firm or organisation, the relevant contractual arrangement may establish JurisFlow as a Data Processor.
The law firm or organisation may therefore remain responsible for:
- determining the purpose of processing;
- establishing an appropriate lawful basis;
- providing privacy information to its clients;
- responding to data-subject requests where appropriate;
- determining appropriate retention periods; and
- ensuring compliance with professional and statutory obligations.
31. Legal requests and disclosure
JurisFlow may disclose personal data where required by a valid legal obligation, court order, regulatory requirement or other lawful process.
Where legally permissible, JurisFlow may notify the relevant User or organisation before disclosure.
JurisFlow may decline to provide advance notice where doing so would violate law, interfere with an investigation or create a security or legal risk.
32. Corporate transactions
If JurisFlow undergoes a merger, acquisition, restructuring, financing, sale of assets or other corporate transaction, personal data may be transferred as part of the transaction where legally permissible.
Any such transfer will remain subject to applicable confidentiality and data protection requirements.
33. Links to third-party websites
JurisFlow may contain links or integrations to third-party websites and services.
JurisFlow is not responsible for the privacy practices of independent third parties.
Users should review the privacy policies of third-party services before providing personal information to them.
34. Changes to this privacy policy
JurisFlow may update this Privacy Policy from time to time to reflect:
- changes in law;
- regulatory requirements;
- changes to the Platform;
- new Services;
- changes in data-processing practices;
- security developments; or
- other legitimate operational requirements.
The revised Privacy Policy will be published through the Platform or JurisFlow website.
The "Last Updated" date will indicate the date on which the Privacy Policy was most recently revised.
Where a change materially affects the rights or expectations of data subjects, JurisFlow will provide additional notice where required.
35. Contact and privacy enquiries
Questions, requests or complaints concerning the processing of personal data should be directed to the JurisFlow privacy team:
JurisFlow Privacy Team Email: hello@jurisflow.ng Website: http://www.jurisflow.ng Postal Address: No. 59 Brade Way, Jalingo, Taraba State, NigeriaWhere JurisFlow has appointed a Data Protection Officer, enquiries may also be directed to the designated Data Protection Officer through the contact details published by JurisFlow.
36. Complaints
If you believe that JurisFlow has processed your personal data unlawfully or has failed to respect your applicable privacy rights, you should first contact JurisFlow so that the matter can be investigated and addressed.
Nothing in this Privacy Policy prevents a data subject from exercising any right to complain to or seek a remedy from the Nigeria Data Protection Commission or another competent supervisory authority.
The NDPC identifies itself as Nigeria's data protection authority and provides mechanisms for privacy complaints and data-subject requests.
37. Governing law
This Privacy Policy shall be interpreted in accordance with the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023, to the extent applicable.
Where mandatory data protection legislation of another jurisdiction applies to a particular processing activity, the relevant mandatory requirements shall also apply.
38. Acceptance
By creating an account, accessing or using JurisFlow, you acknowledge that you have had the opportunity to review this Privacy Policy.
Where applicable law requires consent to a particular processing activity, JurisFlow will obtain such consent through an appropriate mechanism.
Continued use of JurisFlow does not constitute consent where applicable law requires a separate and affirmative consent mechanism.