Legal

Privacy Policy

Last updated: 20 March 2026

1. Who we are

Navionra Ltd("Navionra", "we", "us") is the data controller for personal data collected through the Navionra website (navionra.com) and the Navionra legal practice management platform. Our registered office is in London, United Kingdom.

Our Data Protection Officer can be reached at privacy@navionra.com.

2. What data we collect

CategoryExamplesPurpose
Account dataName, email, role, password hashAuthentication and service delivery
Organisation dataFirm name, subdomain, subscription planBilling and multi-tenancy
Usage dataPage views, API calls, feature usageService improvement and analytics
Document contentLegal documents uploaded by your firmAI analysis and storage (see §5)
Payment dataBilling address, payment method tokenStripe processes card data directly — we never store raw card numbers
Support communicationsEmails and support ticketsCustomer support

3. Legal basis for processing (UK GDPR)

  • Contract performance — providing the Navionra service you have subscribed to.
  • Legitimate interests — fraud prevention, security monitoring, product analytics (we balance these against your interests).
  • Legal obligation — complying with applicable laws (e.g. retaining billing records).
  • Consent — marketing emails (you may opt out at any time).

4. How long we keep your data

  • Active accounts: for the duration of your subscription.
  • After cancellation: account data retained for 90 days to allow re-activation, then deleted.
  • Billing records: 7 years (legal obligation).
  • Audit logs: 2 years.
  • You may request earlier deletion — see §7.

5. AI processing and your documents

Navionra uses large language models (currently Anthropic Claude) to process documents you upload — for tasks such as summarisation, Q&A, and compliance review.

  • We never use your documents to train AI models. Data sent to the Anthropic API is subject to Anthropic's zero-data-retention policy for API customers.
  • Document content is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Your documents are stored in the EU by default (Azure UK South or EU West). Enterprise customers may specify UK-only storage.

6. Who we share data with

  • Anthropic — AI processing (zero-retention policy applies).
  • Stripe — payment processing (PCI-DSS Level 1 certified).
  • Microsoft Azure — document storage and infrastructure.
  • Onfido / ComplyAdvantage — identity and sanctions screening (Professional plan KYC add-on only, with your explicit configuration).

We never sell personal data. All sub-processors are bound by GDPR-compliant data processing agreements. A full list of sub-processors is available on request.

7. Your rights

Under UK GDPR, you have the right to:

  • Access — request a copy of personal data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion ("right to be forgotten").
  • Portability — receive your data in a machine-readable format.
  • Restriction / objection — limit or object to certain processing.
  • Withdrawal of consent — for consent-based processing (e.g. marketing).

Submit requests to privacy@navionra.com. We respond within 30 days. You also have the right to lodge a complaint with the ICO (ico.org.uk).

8. Cookies

We use only essential cookies required for authentication (session tokens) and security (CSRF tokens). We do not use advertising or tracking cookies. No consent banner is required for strictly necessary cookies.

9. Changes to this policy

We will notify you by email at least 14 days before making material changes. Continued use of the service after that date constitutes acceptance.

10. Contact

For privacy enquiries: privacy@navionra.com
Navionra Ltd, London, United Kingdom