LF LevelField.io
Sign in Request a demo
Legal

Privacy policy

How LevelField handles personal data and client material. Written to be read, not to be survived.

Version4.2 Effective01 Jun 2026 GovernsAll regions
We never train on your data No client document, prompt, or output is used to train or fine-tune any model, ours or a vendor's.
You choose the region Data is processed and stored in the region you select per practice group, and does not leave it.
You set retention Retention windows are yours to configure, down to immediate deletion on matter close.

This policy explains what LevelField collects when you use our website and platform, how we treat the client material you upload, and what you can require of us.

1. Who we are

LevelField Technologies, Inc. is a Delaware corporation with offices in New York, London, and Singapore. For customers in the EEA and UK, LevelField Technologies Ltd acts as data controller for account data and as processor for client material.

2. What we collect

We collect three categories of information, and nothing beyond them.

CategoryPurposeBasis Account dataProvisioning, billing, supportContract Usage logsAudit trail, reliabilityLegitimate interest Client materialDelivering the serviceProcessor for you

3. Client material

Documents, matters, correspondence, and anything else you upload remain yours. We process them only to deliver the service to you, under your instructions, in the region you select. We do not sell them, we do not disclose them to a third party except the sub-processors listed below, and we do not use them to train or improve any model.

Privilege

Client material may be privileged. Our staff cannot read it: support access requires a time-boxed, logged grant from an administrator in your workspace, and every such grant appears in your audit log.

4. How we use it

Account data supports provisioning, billing, and support. Usage logs produce your audit trail and let us keep the service reliable. Aggregate, non-identifying metrics inform capacity planning; they cannot be traced to a matter, a document, or a person.

5. Sub-processors

We publish a current list of sub-processors and give thirty days' notice before adding one. Each is bound by written terms no less protective than this policy, and each is region-scoped to match your selection.

6. Retention

You configure retention. The default is the life of the account plus thirty days; you may set immediate deletion on matter close, or a longer window where a regulator requires it. Deletion is irreversible and covers backups within thirty-five days.

7. Security

Encryption in transit and at rest, tenant isolation, SSO and SCIM, matter-level access control, and ethical walls enforced at the index rather than the interface. We hold SOC 2 Type II and ISO 27001, and we will share the report under NDA.

8. Your rights

Depending on where you are, you may request access, correction, deletion, portability, or restriction of your personal data, and you may object to processing based on legitimate interest. Where we act as processor, we will refer your request to the customer who controls the workspace and assist them in responding.

9. Changes

Material changes are notified to workspace administrators at least thirty days before they take effect, with a summary of what changed. Prior versions remain available on request.

10. Contact

Our Data Protection Officer can be reached at privacy@levelfield.io, or by post at 120 Broadway, Floor 28, New York, NY 10271. For EEA and UK matters, write to our London office at 42 Bevis Marks, London EC3A 7JB.

Need the DPA or the SOC 2 report? Both are available under NDA, usually the same business day. Request documents