Privacy Policy

At PageLightPrime, we understand that law firms and legal departments entrust us with highly confidential and business-critical information. Protecting that information is fundamental to our business and our commitment to our customers.

This Privacy Policy explains how PageLightPrime collects, uses, stores, protects, and discloses personal information when you visit our website, use our software and services, communicate with us, or otherwise interact with PageLightPrime.

This Privacy Policy applies to:

  • The PageLightPrime website
  • The PageLightPrime Legal Practice Management Platform
  • Mobile applications (if applicable)
  • Customer support services
  • Product demonstrations and trial environments
  • Marketing communications
  • Events, webinars, and training
  • Any other services that reference this Privacy Policy

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.

Privacy Highlights

The following summary is provided for convenience only. Please read this entire Privacy Policy for complete details.

You Own Your Data

Your organization retains ownership of all Customer Data stored or processed using the PageLightPrime platform. PageLightPrime does not claim ownership of your documents, emails, matters, contacts, invoices, or other Customer Content.

We Do Not Sell Personal Information

PageLightPrime does not sell Customer Data or personal information to third parties.

Built on Microsoft 365

PageLightPrime is designed to operate within your Microsoft 365 environment whenever possible. Customer documents are typically stored in the customer’s Microsoft SharePoint Online tenant rather than on PageLightPrime-managed storage.

Enterprise Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption, secure authentication, role-based access controls, audit logging, and continuous monitoring.

Customer Control

Customers determine:

  • who can access their information
  • user permissions
  • document access
  • retention policies
  • matter security
  • workflow permissions
  • Microsoft 365 security settings

AI Features

Where AI-powered capabilities are available, PageLightPrime is designed to process only customer-authorized information necessary to provide requested functionality. Customer information is not used to train public artificial intelligence models unless expressly authorized by the customer.

Privacy Rights

Depending on your location, you may have the right to:

  • Access your information
  • Correct inaccurate information
  • Delete personal information
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent where applicable

1. Scope

This Privacy Policy applies to personal information collected by PageLightPrime through:

  • our website
  • software applications
  • customer portals
  • demonstrations
  • technical support
  • implementation services
  • professional services
  • webinars
  • marketing activities
  • customer communications

This Privacy Policy does not apply to third-party websites or services that may be linked from our Services.

2. Definitions

For purposes of this Privacy Policy:

  • Customer means the law firm, legal department, government agency, corporation, or other organization that licenses PageLightPrime.
  • Customer Data means all electronic information, documents, emails, contacts, matters, invoices, financial information, time entries, metadata, and other information submitted to the Services by or on behalf of a Customer.
  • Personal Information means information that identifies, relates to, describes, or can reasonably be associated with an identified or identifiable individual, as defined under applicable privacy laws.
  • Processing means any operation performed on Personal Information, including collection, recording, organization, storage, retrieval, use, disclosure, transmission, deletion, or destruction.
  • Services means the PageLightPrime software, website, applications, APIs, integrations, professional services, support services, and related offerings.

3. Information We Collect

The information we collect depends on how you interact with PageLightPrime.

A. Information You Provide

When using our Services, you may provide information such as:

  • Name
  • Business email address
  • Telephone number
  • Company name
  • Job title
  • Office address
  • Billing information
  • User account credentials
  • Microsoft 365 tenant information
  • Support requests
  • Training registrations
  • Webinar registrations
  • Product feedback
  • Communications with PageLightPrime

B. Customer Data

Customers may upload or create information including:

  • Legal matters
  • Contacts
  • Clients
  • Documents
  • Emails
  • Calendars
  • Tasks
  • Notes
  • Court information
  • Time entries
  • Expenses
  • Invoices
  • Trust accounting records
  • Financial transactions
  • Custom metadata
  • Workflow information
  • Matter history
  • Audit records

C. Information Collected Through Integrations

When authorized by a Customer, PageLightPrime may access information from integrated Microsoft 365 services, including:

  • Microsoft SharePoint Online
  • Microsoft Outlook
  • Microsoft Exchange Online
  • Microsoft Teams
  • Microsoft Word
  • Microsoft Excel
  • Microsoft OneDrive
  • Microsoft Entra ID

Access to Microsoft 365 data is limited to the permissions granted by the Customer and is used solely to provide requested functionality.

D. Website Information

When you interact with our website, we may collect information including:

  • Name
  • Email address
  • Company
  • Country
  • Phone number
  • Product interests
  • Demo requests
  • Contact forms
  • Newsletter subscriptions
  • Event registrations

4. Customer Content

PageLightPrime recognizes that Customer Content is among the most sensitive information managed by our customers.

Accordingly:

  • Customers retain ownership of all Customer Content.
  • PageLightPrime does not acquire ownership rights in Customer Content.
  • Customer Content is processed only to provide the Services requested by the Customer.
  • Access to Customer Content is restricted to authorized personnel with a legitimate business need, such as providing technical support, resolving service issues, implementing requested features, or complying with applicable law.
  • PageLightPrime does not use Customer Content for advertising purposes.
  • PageLightPrime does not sell Customer Content.
  • Customer Content is handled in accordance with applicable contractual commitments, confidentiality obligations, and data protection laws.

Where technically feasible, customer documents remain within the customer’s Microsoft 365 environment, enabling customers to maintain control over document storage, permissions, retention, and governance.

5. Information We Collect Automatically

When you access our website or use the Services, certain information may be collected automatically to help us operate, secure, maintain, and improve our Services.

Depending on your configuration and applicable law, this information may include:

Device Information

  • Device type
  • Operating system
  • Browser type and version
  • Screen resolution
  • Language preferences
  • Time zone
  • Device identifiers

Log Information

We automatically generate system logs that may include:

  • IP address
  • Login and logout timestamps
  • Authentication events
  • User activity logs
  • Error reports
  • Performance metrics
  • Diagnostic information
  • API usage
  • Audit events

These logs help us:

  • Detect security incidents
  • Troubleshoot technical issues
  • Improve system reliability
  • Monitor service availability
  • Meet compliance obligations
  • Maintain audit trails where required

Usage Information

We may collect information regarding how users interact with our Services, including:

  • Features accessed
  • Navigation paths
  • Session duration
  • Search activity
  • Configuration preferences
  • Workflow usage
  • System performance metrics

Usage analytics are used to improve product functionality, enhance user experience, and identify opportunities for service improvements.

6. Cookies and Similar Technologies

Our website uses cookies and similar technologies to provide, secure, and improve our Services.

Cookies are small text files placed on your device that enable websites to recognize your browser and remember certain information.

We may use the following categories of cookies:

Essential Cookies

These cookies are necessary for the operation of our website and cannot be disabled without affecting functionality.

Examples include:

  • Authentication
  • Security
  • Session management
  • Load balancing
  • User preferences

Performance and Analytics Cookies

These cookies help us understand how visitors interact with our website by collecting information such as:

  • Pages visited
  • Time spent on pages
  • Navigation patterns
  • Referral sources
  • Device information
  • Browser information

Analytics information is used in aggregate to improve website performance and user experience.

Functional Cookies

Functional cookies remember user preferences such as:

  • Preferred language
  • Regional settings
  • Accessibility preferences
  • User interface customization

Marketing Cookies

Where permitted by applicable law, marketing cookies may be used to:

  • Measure campaign effectiveness
  • Understand visitor interests
  • Improve marketing communications

These cookies are used only where appropriate consent has been obtained.

Managing Cookies

Most web browsers allow users to:

  • Delete cookies
  • Block cookies
  • Receive notification before cookies are stored
  • Configure cookie preferences

Disabling certain cookies may affect website functionality.

7. How We Use Information

PageLightPrime processes personal information only for legitimate business purposes and in accordance with applicable law.

We may use personal information to:

Deliver Our Services

  • Create customer accounts
  • Authenticate users
  • Manage subscriptions
  • Provide legal practice management functionality
  • Synchronize Microsoft 365 data
  • Process transactions
  • Deliver requested features

Customer Support

We use information to:

  • Respond to support requests
  • Diagnose technical issues
  • Resolve service interruptions
  • Provide implementation assistance
  • Deliver customer training
  • Improve customer experience

Product Improvement

Information may be used to:

  • Improve existing features
  • Develop new functionality
  • Monitor performance
  • Enhance usability
  • Detect software defects
  • Improve reliability

Where practical, product improvement activities use aggregated or de-identified information.

Security

Information is processed to:

  • Detect fraud
  • Prevent unauthorized access
  • Monitor suspicious activity
  • Investigate security incidents
  • Protect customer environments
  • Enforce our agreements

Communications

We may communicate with users regarding:

  • Product updates
  • Security notifications
  • Service announcements
  • Account administration
  • Support cases
  • Billing matters
  • Training opportunities
  • Feature releases

Where required by law, users may opt out of marketing communications while continuing to receive important service-related notices.

Legal Compliance

We may process information where necessary to:

  • Comply with applicable laws
  • Respond to lawful requests from governmental authorities
  • Enforce contractual rights
  • Protect the rights, safety, and security of our customers, employees, and the public

8. Legal Bases for Processing (GDPR and UK GDPR)

Where the General Data Protection Regulation (GDPR) or UK GDPR applies, PageLightPrime processes personal information on one or more of the following legal bases:

Contractual Necessity

Processing necessary to provide requested Services, including:

  • Account administration
  • User authentication
  • Technical support
  • Subscription management
  • Professional services

Legitimate Interests

Processing necessary for our legitimate interests, including:

  • Improving our Services
  • Preventing fraud
  • Protecting network security
  • Maintaining service reliability
  • Developing new features
  • Customer relationship management

We balance these interests against the rights and freedoms of individuals.

Legal Obligation

Processing required to comply with applicable legal obligations, including:

  • Financial reporting
  • Tax requirements
  • Regulatory compliance
  • Court orders
  • Lawful government requests

Consent

Where required by applicable law, we rely on consent for activities such as:

  • Marketing communications
  • Certain cookies and tracking technologies
  • Optional product features

Individuals may withdraw consent at any time where processing is based on consent.

9. Artificial Intelligence (AI) Features

PageLightPrime may offer AI-powered capabilities designed to enhance productivity, document management, legal workflows, and knowledge retrieval.

Examples may include:

  • Document summarization
  • Matter insights
  • Intelligent search
  • Document classification
  • Workflow recommendations
  • Metadata suggestions
  • Natural language queries
  • Draft generation

Responsible Use of AI

PageLightPrime is committed to responsible AI practices.

Accordingly:

  • AI features operate only on information authorized by the Customer.
  • Customers control whether AI-enabled functionality is available to their users.
  • Customer Data is processed solely for the purpose of delivering requested AI functionality.
  • Customer Data is not used to train publicly available AI models without the Customer’s explicit authorization.
  • AI-generated content should be reviewed by qualified professionals before reliance or publication.
  • Customers remain responsible for reviewing legal work product generated with AI assistance.

We continually evaluate AI technologies to promote security, accuracy, transparency, and compliance with applicable laws and professional obligations.

10. Sharing of Personal Information

PageLightPrime values the confidentiality of customer information. We do not sell Customer Data or personal information to third parties.

We disclose personal information only as described in this Privacy Policy or as instructed by our Customers.

We may share information with the following categories of recipients.

Service Providers

We engage carefully selected third-party service providers to perform services on our behalf. These providers are contractually obligated to protect personal information and may process information only for the purposes specified by PageLightPrime.

Depending on the Services used, these providers may include:

  • Cloud infrastructure providers
  • Identity and authentication providers
  • Customer support platforms
  • Payment processors
  • Email delivery services
  • Website hosting providers
  • Analytics providers
  • Security monitoring providers
  • Backup and disaster recovery providers
  • Artificial intelligence service providers authorized by the Customer

Service providers are granted access only to the information reasonably necessary to perform their services.

Microsoft 365 Services

PageLightPrime integrates with Microsoft 365 services, including SharePoint Online, Microsoft Teams, Outlook, Exchange Online, OneDrive, Microsoft Word, Microsoft Excel, and Microsoft Entra ID.

When a Customer enables these integrations, information is processed in accordance with the permissions granted by the Customer and Microsoft’s applicable terms and privacy commitments.

Customer Instructions

As a processor or service provider, PageLightPrime processes Customer Data only on behalf of and in accordance with the documented instructions of the Customer.

Customers determine:

  • Which users may access Customer Data
  • Which integrations are enabled
  • Data retention policies
  • Security configurations
  • User permissions
  • Sharing settings

Legal Requirements

We may disclose personal information where we believe such disclosure is necessary to:

  • Comply with applicable law or regulation
  • Respond to a lawful subpoena, court order, or governmental request
  • Protect the rights, property, or safety of PageLightPrime, our Customers, or others
  • Investigate suspected fraud or security incidents
  • Enforce our agreements

Where legally permitted, we will make reasonable efforts to notify affected Customers before disclosing Customer Data.

Business Transactions

If PageLightPrime is involved in a merger, acquisition, financing, corporate reorganization, or sale of assets, personal information may be transferred as part of that transaction.

Any successor organization will remain subject to obligations that are materially consistent with this Privacy Policy unless otherwise permitted by law.

11. International Data Transfers

PageLightPrime provides services to Customers located in multiple countries.

Accordingly, personal information may be transferred to, processed in, or accessed from jurisdictions outside the country in which it was originally collected.

Where required by applicable law, we implement appropriate safeguards for international transfers, including:

  • Standard Contractual Clauses (SCCs), where applicable
  • Contractual commitments with service providers
  • Technical and organizational security measures
  • Data processing agreements
  • Other lawful transfer mechanisms recognized under applicable privacy laws

Where Customers deploy PageLightPrime within their own Microsoft 365 tenant, Customer Data may remain within the geographic region selected by the Customer, subject to Microsoft 365 service availability and configuration.

12. Information Security

Protecting confidential legal and business information is fundamental to PageLightPrime.

We maintain a comprehensive information security program designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Our security program includes administrative, technical, and physical safeguards appropriate to the nature of the information we process.

Security measures may include:

Identity and Access Management

  • Microsoft Entra ID integration
  • Role-based access control (RBAC)
  • Least-privilege access principles
  • Multi-factor authentication support
  • Secure password requirements
  • Session management controls

Encryption

We employ encryption technologies designed to protect information:

  • During transmission using industry-standard TLS encryption
  • At rest using modern encryption standards where applicable

Monitoring and Auditing

To support security and compliance, we maintain logging and monitoring capabilities that may include:

  • Authentication events
  • Administrative actions
  • System activity logs
  • Audit trails
  • Security alerts
  • Performance monitoring

Infrastructure Security

Depending on the deployment model, security controls may include:

  • Secure cloud infrastructure
  • Network segmentation
  • Firewall protections
  • Vulnerability management
  • Security patching
  • Malware protection
  • Backup and disaster recovery procedures

Employee Access

Access to Customer Data is limited to authorized personnel who require access to perform their job responsibilities.

Personnel with access to Customer information are subject to confidentiality obligations and receive appropriate security and privacy training.

Customer Responsibilities

Customers also play an important role in protecting information.

Customers are responsible for:

  • Managing user permissions
  • Protecting authentication credentials
  • Enabling multi-factor authentication where available
  • Configuring Microsoft 365 security settings
  • Managing retention policies
  • Reviewing user access regularly

13. Data Retention

PageLightPrime retains personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, and provide the Services.

Retention periods vary depending on the type of information and applicable legal requirements.

Factors considered include:

  • The nature of the information
  • Customer instructions
  • Contractual obligations
  • Regulatory requirements
  • Applicable statutes of limitation
  • Operational requirements
  • Security and audit needs

When a Customer terminates the Services, Customer Data will be retained, returned, or securely deleted in accordance with the applicable agreement, customer instructions, and legal obligations.

Backup copies may be retained for a limited period where necessary for disaster recovery, legal compliance, or security purposes before being securely deleted in accordance with established retention schedules.

14. Microsoft 365 Data Residency and Customer Control

PageLightPrime is designed to operate natively within the Microsoft 365 ecosystem. Unlike many traditional Software-as-a-Service (SaaS) legal applications, PageLightPrime is architected to leverage the Customer’s existing Microsoft 365 environment for document storage, identity management, collaboration, and governance.

Customer-Controlled Document Repository

Where configured by the Customer, legal documents and related files are stored within the Customer’s Microsoft SharePoint Online environment rather than in a proprietary PageLightPrime document repository.

This approach allows Customers to maintain direct control over:

  • Document ownership
  • Data residency
  • Microsoft 365 security policies
  • Retention and disposition policies
  • Microsoft Purview compliance features
  • Microsoft 365 audit logs
  • Backup and recovery capabilities available within Microsoft 365
  • User and group permissions
  • Information governance policies

Microsoft Entra ID Authentication

PageLightPrime integrates with Microsoft Entra ID for user authentication and identity management.

Customers manage user identities, authentication policies, conditional access policies, and multi-factor authentication through their Microsoft 365 environment.

Customer Data Governance

Customers remain responsible for configuring and managing governance settings within their Microsoft 365 tenant, including:

  • Data retention policies
  • Sensitivity labels
  • Information barriers
  • Data loss prevention (DLP) policies
  • eDiscovery configurations
  • Legal holds
  • Records management policies
  • Conditional Access policies

PageLightPrime respects these Microsoft 365 governance controls where applicable.

Geographic Data Residency

Where Customer Data is stored within the Customer’s Microsoft 365 tenant, the geographic location of that data is determined by the Customer’s Microsoft 365 configuration and Microsoft’s available regional hosting options.

Customers may choose Microsoft 365 data residency options that align with their legal, regulatory, and business requirements.

Administrative Control

Customers retain administrative control over their Microsoft 365 environment, including user access, security policies, document permissions, and compliance configurations.

PageLightPrime accesses Customer Data only as necessary to provide the Services and only with the permissions authorized by the Customer.

15. Customer Confidentiality

PageLightPrime recognizes that many Customers are law firms, corporate legal departments, government agencies, and other organizations that manage confidential, privileged, or sensitive information.

Accordingly, we are committed to maintaining the confidentiality of Customer Data.

We implement policies and procedures designed to limit access to Customer Data to authorized personnel who require such access to perform their assigned responsibilities.

Our personnel are subject to confidentiality obligations and receive training regarding the proper handling of confidential information.

Except as required by law or authorized by the Customer, PageLightPrime does not disclose Customer Data to third parties.

16. Data Protection by Design

PageLightPrime considers privacy and security throughout the design, development, and operation of our Services.

Our engineering and operational practices are intended to support principles of data protection by design and by default, including:

  • Collection of only the information reasonably necessary to provide the Services
  • Role-based access to administrative functions
  • Secure software development practices
  • Logging and audit capabilities
  • Encryption of data in transit and, where applicable, at rest
  • Regular review of security controls
  • Ongoing evaluation of privacy risks during product development

We continually assess our privacy and security practices to address evolving technologies, legal requirements, and customer expectations.

17. Artificial Intelligence and Responsible Innovation

PageLightPrime may provide artificial intelligence (AI) features to assist Customers with legal practice management, document processing, workflow automation, knowledge retrieval, analytics, and productivity.

We are committed to the responsible use of AI.

Unless otherwise agreed with the Customer:

  • AI capabilities process Customer Data solely to provide the requested functionality.
  • Customer Data is not used to train publicly available AI models.
  • Customers control whether AI features are enabled for their organization.
  • Customers remain responsible for reviewing AI-generated content before relying upon it for legal, financial, or business decisions.
  • AI-generated responses may contain inaccuracies and should not be considered legal advice.

PageLightPrime continues to evaluate emerging AI technologies to improve productivity while maintaining appropriate safeguards for privacy, confidentiality, and information security.

Privacy Policy Header
📅
Effective Date

August 3, 2023

🔄
Last Updated

February 13, 2026