Privacy Policy
1. About this policy
This Privacy Policy explains how Platfirm AI Pty Ltd collects, uses, shares, stores, and protects personal data in connection with Legal Hotline in the United Kingdom.
The UK GDPR applies to organisations outside the UK that offer goods or services to individuals in the UK.
2. Controller
For the purposes of UK data protection law, the controller is:
Platfirm AI Pty Ltd
ABN 24 679 859 744
Email: privacy@legal-hotline.com
3. Personal data we collect
We may collect:
- name;
- phone number;
- email address;
- city, postcode, or general location;
- UK jurisdiction;
- area of law;
- urgency;
- matter description;
- court, tribunal, agency, Home Office, police, or other deadlines you provide;
- transcripts, summaries, form submissions, SMS, and emails;
- booking preferences;
- payment status and transaction metadata;
- IP address, device, browser, pages viewed, cookies, and analytics data.
Your enquiry may include special category data or criminal offence data if you choose to provide it.
UK GDPR requires organisations processing special category data to identify both an Article 6 lawful basis and a separate Article 9 condition, and criminal-offence data has additional rules.
4. How we use personal data
We use personal data to:
- provide legal information through the AI assistant;
- identify jurisdiction and area of law;
- generate transcripts, summaries, and classifications;
- respond to enquiries;
- connect you with a legal professional if requested and available;
- manage bookings, payments, and refunds;
- improve quality, safety, accuracy, and reliability;
- prevent fraud, misuse, and abuse;
- comply with legal obligations;
- handle complaints, disputes, and privacy requests.
5. Lawful bases
We rely on one or more of the following lawful bases:
- contract — to provide services you request;
- legitimate interests — to operate, secure, improve, and administer Legal Hotline;
- consent — where required, including certain cookies and optional marketing;
- legal obligation — where we must comply with law;
- vital interests — in rare circumstances involving immediate risk of serious harm.
For special category data, where processed, we rely on an applicable UK GDPR Article 9 condition, such as explicit consent or establishment, exercise, or defence of legal claims, depending on the context.
6. AI processing
Your enquiry may be processed by AI systems to generate responses, summaries, classifications, and operational notes.
We do not permit AI providers to use your identifiable legal enquiry to train public models unless we tell you and obtain any required consent.
AI outputs may be inaccurate or incomplete and should not be treated as legal advice.
7. Call transcripts and recordings
Unless we tell you otherwise at the start of a call, we do not retain audio recordings.
We may create and retain transcripts, summaries, classifications, and call metadata.
If we record calls in the future, we will tell you before recording and explain the purpose.
8. Sharing personal data
We may share personal data with:
- independent UK legal professionals, where you request a callback or consultation;
- telecommunications, SMS, email, hosting, database, speech-to-text, text-to-speech, AI, security, analytics, and payment providers;
- professional advisers, insurers, auditors, and dispute-resolution providers;
- regulators, courts, law enforcement, or government bodies where required or permitted by law;
- successors if our business is sold, transferred, or restructured.
9. International transfers
Platfirm AI Pty Ltd is based in Australia. Your personal data may be processed in Australia, the United States, Canada, the United Kingdom, and other countries where our providers operate.
Where UK GDPR international transfer rules apply, we use an appropriate transfer mechanism, such as adequacy regulations, an international data transfer agreement, standard contractual clauses with UK addendum, or another lawful safeguard.
The ICO states that restricted transfers must be covered by UK adequacy regulations, appropriate safeguards, or an exception.
10. Cookies
We use cookies and similar technologies for security, session management, functionality, analytics, and service improvement.
Non-essential cookies will only be used where permitted by law and, where required, with consent.
The ICO’s PECR guidance requires clear cookie information and a consent mechanism for cookies that are not strictly necessary.
11. Retention
We keep personal data only as long as reasonably necessary.
Indicative retention periods:
- enquiry transcripts and summaries: up to 24 months unless needed longer;
- booking and payment records: up to 7 years;
- legal-professional matching records: up to 7 years;
- technical logs: usually up to 12 months;
- cookie consent records: for an appropriate period;
- de-identified analytics: indefinitely.
UK privacy notices should explain purposes, retention periods, and who personal data is shared with.
12. Your UK data protection rights
Subject to conditions and exceptions, you may have rights to:
- be informed;
- access your personal data;
- rectify inaccurate data;
- erase data;
- restrict processing;
- data portability;
- object to processing;
- object to direct marketing;
- rights relating to automated decision-making.
The ICO summarises these rights under the UK GDPR.
13. How to exercise rights
Email: privacy@legal-hotline.com
We may need to verify your identity before responding.
We will respond within the timeframe required by UK data protection law.
14. Complaints
You may complain to us at privacy@legal-hotline.com.
You also have the right to complain to the UK Information Commissioner’s Office.
15. Security
We use reasonable technical and organisational measures designed to protect personal data.
No system is completely secure.