This Privacy Policy explains how Lawyer Office ("Lawyer Office", "we", "us") handles personal data when you use the Lawyer Office platform: the website https://lawyeroffice.me, the web application at each office's address (for example office.lawyeroffice.me), and the Lawyer Office apps for Android and iOS (together, the "Service").
1. Who is responsible for your data
The Service is used by law offices ("Offices") to manage their work. Two situations must be distinguished:
- Data that an Office enters about its clients, lawsuits, hearings, documents and finances ("Office Data") belongs to that Office. The Office decides what it records and why, and is responsible for it as data controller. We process Office Data only on the Office's behalf and on its instructions, to provide the Service.
- Data about the Office's account, its users, and its subscription (for example the users' names, e-mail addresses and login settings, and the Office's invoices and payments) is processed by Lawyer Office as data controller, to run the Service.
If you are a client of a law office and have a question about your data, please contact that office first. We will help the office answer your request.
2. Data we collect
2.1 Account and user data
- Name, e-mail address, phone number, role and permissions within the Office, preferred language and profile picture.
- Security data: the password (stored only as a one-way hash), the two-factor authentication secret and recovery codes, the device PIN (stored as a hash), and the Google account identifier if you link Google Sign-In.
- Device data needed for notifications: the push notification token, the platform (Android, iOS or browser) and the app version.
2.2 Office Data
Everything the Office records in the Service: clients and their contact details, lawsuits and their parties, hearings, appointments, tasks, documents, fees, payments, expenses and the phone directory. This may include sensitive information protected by professional secrecy. We do not use Office Data for any purpose other than providing the Service to the Office.
2.3 Subscription and billing data
The Office's name, address (subdomain), bar number, the owner's contact details, the subscription plan, invoices and payments. Online card payments are processed by Stripe: we never receive or store your full card number.
2.4 Technical data
IP addresses, date and time of requests, browser or device type, and error logs, kept to secure and operate the Service. Inside each Office, an audit log records which user created, changed or deleted which record, and when.
2.5 This website
This website does not use advertising or analytics cookies and has no user accounts. When you contact us through the contact form, your message opens in WhatsApp or in your e-mail application, and nothing is stored on the website. We receive only what you choose to send us.
3. How we use data
- To provide the Service: authentication, storing and displaying Office Data, reminders, notifications, printing and exports.
- To secure the Service: detecting abuse, blocking repeated wrong PINs or passwords, keeping audit logs and backups.
- To manage subscriptions: invoices, payment records, and e-mails before the subscription ends.
- To support you: answering your questions and fixing problems you report.
- To send service announcements about the platform (for example maintenance or new features). We do not send advertising from third parties.
The legal bases are the performance of our contract with the Office, our legitimate interest in running a secure service, compliance with legal obligations, and, where required, consent.
We do not sell personal data, we do not use it for advertising, and we do not use Office Data to train artificial intelligence models.
4. Google services
An Office may choose to connect a Google account. Depending on what it enables, the Service requests the following access:
- Google Sign-In (
openid,email): to let a user sign in with the Google account they linked. - Google Drive (
drive.file): to create the Office's folders and store the documents uploaded in the Service, and to delete those files on request. - Google Drive, read only (
drive.readonly), only when this option is enabled on the platform: to list and download the files the Office adds directly in its Lawyer Office folders from Google Drive, so that they appear in the client's file. The Service only lists the folders it created; it doesn't change these files and doesn't read the rest of the Drive. - Google Calendar (
calendar): to keep the Office's hearings and appointments in the calendar the Service creates, in both directions: the Service adds, updates and removes the events, and reads the changes the Office makes to that calendar. The Service doesn't read the Office's other calendars.
Lawyer Office's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide these features, is not transferred to others except as needed to provide the Service or required by law, is not used for advertising, and is not read by people except with the Office's consent, for security reasons, or to comply with the law.
The Office can disconnect Google at any time from its settings in the Service, or from its Google account's security page. Documents already stored in the Office's Drive remain in the Office's Drive.
5. Service providers
We use carefully selected providers who process data on our behalf, only to the extent needed:
- Server hosting and network providers (servers, DNS, protection against attacks).
- Google (Drive, Calendar and Sign-In when the Office enables them, and Firebase Cloud Messaging for push notifications) and Apple (push notifications on iOS).
- Stripe, for online card payments.
- An e-mail delivery provider, for password resets, reminders and subscription e-mails.
We may also disclose data when required by law or by a court order, or to protect the rights and safety of our users and of the Service. In that case, and where permitted, we inform the Office concerned first.
These providers may process data in countries other than Lebanon. We only work with providers that offer appropriate protection for personal data.
6. Security
- Each Office has its own separate database. Access tokens are tied to one Office and rejected by any other.
- All connections use HTTPS encryption. Passwords and PINs are stored as one-way hashes.
- Two-factor authentication, device PINs locked after five wrong tries, and Face ID on iOS.
- Role-based permissions, an audit log of changes, and daily backups.
No system is perfectly secure. If a personal data breach affects an Office, we will inform it without undue delay, together with the measures taken.
7. How long we keep data
- While the subscription is active, and during the read-only period after it ends, we keep the Office Data so that the Office can consult and renew.
- When an Office asks to close its account, we provide an export of its data on request, then delete its database and the documents stored on our servers within 30 days. Backups are overwritten within a further 30 days. Documents stored in the Office's own Google Drive are not deleted by us.
- If an Office does not renew for 12 months after its subscription ended, we may delete its data after notifying the owner by e-mail at least 30 days in advance.
- Invoices and payment records are kept as long as required by accounting and tax law.
8. Deleting a user account
A user can ask the owner or an administrator of the Office to delete their account, or write to us at [email protected] from the e-mail address of the account. We delete the account within 30 days, including its login data, PINs, linked Google account and push tokens. The user's name may remain in the Office's audit log and on records they created, because these belong to the Office's professional archive.
9. Your rights
Subject to the applicable law, including Lebanese Law No. 81 of 2018 on Electronic Transactions and Personal Data, you may ask to access, correct or delete your personal data, to object to its processing, and to receive a copy of it. Users can change most of their own data directly in their profile. For Office Data, requests are handled with the Office concerned. To exercise your rights, write to [email protected]. We answer within 30 days.
10. Children
The Service is intended for law professionals and is not directed at people under 18. We do not knowingly collect data from children as users of the Service.
11. Changes to this policy
We may update this policy when the Service or the law changes. The date at the top shows the latest version. For important changes, we inform Office owners by e-mail or in the Service before the changes take effect.
12. Contact
For any question about this policy or your data: [email protected], phone and WhatsApp +961 71 250 928.