Legal
Privacy Policy
Last updated: 20 March 2026
1. Who we are
Navionra Ltd("Navionra", "we", "us") is the data controller for personal data collected through the Navionra website (navionra.com) and the Navionra legal practice management platform. Our registered office is in London, United Kingdom.
Our Data Protection Officer can be reached at privacy@navionra.com.
2. What data we collect
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email, role, password hash | Authentication and service delivery |
| Organisation data | Firm name, subdomain, subscription plan | Billing and multi-tenancy |
| Usage data | Page views, API calls, feature usage | Service improvement and analytics |
| Document content | Legal documents uploaded by your firm | AI analysis and storage (see §5) |
| Payment data | Billing address, payment method token | Stripe processes card data directly — we never store raw card numbers |
| Support communications | Emails and support tickets | Customer support |
3. Legal basis for processing (UK GDPR)
- Contract performance — providing the Navionra service you have subscribed to.
- Legitimate interests — fraud prevention, security monitoring, product analytics (we balance these against your interests).
- Legal obligation — complying with applicable laws (e.g. retaining billing records).
- Consent — marketing emails (you may opt out at any time).
4. How long we keep your data
- Active accounts: for the duration of your subscription.
- After cancellation: account data retained for 90 days to allow re-activation, then deleted.
- Billing records: 7 years (legal obligation).
- Audit logs: 2 years.
- You may request earlier deletion — see §7.
5. AI processing and your documents
Navionra uses large language models (currently Anthropic Claude) to process documents you upload — for tasks such as summarisation, Q&A, and compliance review.
- We never use your documents to train AI models. Data sent to the Anthropic API is subject to Anthropic's zero-data-retention policy for API customers.
- Document content is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Your documents are stored in the EU by default (Azure UK South or EU West). Enterprise customers may specify UK-only storage.
6. Who we share data with
- Anthropic — AI processing (zero-retention policy applies).
- Stripe — payment processing (PCI-DSS Level 1 certified).
- Microsoft Azure — document storage and infrastructure.
- Onfido / ComplyAdvantage — identity and sanctions screening (Professional plan KYC add-on only, with your explicit configuration).
We never sell personal data. All sub-processors are bound by GDPR-compliant data processing agreements. A full list of sub-processors is available on request.
7. Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion ("right to be forgotten").
- Portability — receive your data in a machine-readable format.
- Restriction / objection — limit or object to certain processing.
- Withdrawal of consent — for consent-based processing (e.g. marketing).
Submit requests to privacy@navionra.com. We respond within 30 days. You also have the right to lodge a complaint with the ICO (ico.org.uk).
8. Cookies
We use only essential cookies required for authentication (session tokens) and security (CSRF tokens). We do not use advertising or tracking cookies. No consent banner is required for strictly necessary cookies.
9. Changes to this policy
We will notify you by email at least 14 days before making material changes. Continued use of the service after that date constitutes acceptance.
10. Contact
For privacy enquiries: privacy@navionra.com
Navionra Ltd, London, United Kingdom