Document PRV-01
Privacy Policy
How Latitude handles information about the people who use this website and who work at our clients. Your documents — the agreements you upload and the playbook inferred from them — are governed separately; see Data Processing.
Effective 16 August 2026
1. Scope, and an important distinction
This policy covers information about you as a visitor to uselatitude.co.uk, someone who submits a request, or a named user at a client firm or carrier. It is about business contact data and website analytics.
It does not cover client data. Medical records, claim files and the work product derived from them are processed under an engagement and a data processing agreement, as set out in the Data Processing document. Where the two appear to conflict on client data, the engagement terms and the DPA control.
2. What we collect
Information you give us. When you submit a request we collect your name, work email address, organisation, role, organisation type, and the caseload, case management system and free-text detail you choose to provide.
Information we collect automatically. Standard server logs (IP address, user agent, requested path, timestamp) and privacy-preserving page analytics. We run no advertising trackers and do not sell or share data for cross-context behavioural advertising.
Information from your firm. If your organisation becomes a client, we receive the account details needed to provision access — typically name, work email, role, and the permissions your administrator assigns.
3. Why we use it
- To evaluate and respond to your request.
- To provide, secure and support the service for your organisation.
- To run conflict checks at engagement and on each new matter.
- To meet legal, regulatory and contractual obligations.
- To understand, in aggregate, which parts of this website are useful.
We rely on legitimate interests for business-contact processing, contract performance for service provision, and legal obligation where retention is mandated. Where consent is the basis — optional analytics in jurisdictions requiring it — you may withdraw it at any time without affecting prior processing.
4. Who we share it with
Service providers processing on our behalf under written terms: hosting, error monitoring, email delivery and customer relationship management. Each is bound to confidentiality and to processing only on our instructions. The current list is on the Subprocessors page.
Regulators, auditors and legal counsel where we are compelled.
An acquirer, in a merger, acquisition or asset sale — with notice to you, and this policy continuing to apply until superseded.
We do not sell personal information and have not done so in the preceding twelve months.
5. International transfers
Where personal data leaves its country of origin we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision. Clients with data-residency requirements should raise them during contracting; regional processing is agreed in the order form rather than assumed here.
6. How long we keep it
Requests that do not become engagements: 24 months, then deleted.
Account and contact records: for the life of the client relationship, plus the period our contractual and statutory duties require.
Conflict-check records: retained for as long as necessary to run future conflict checks reliably, which is a longer period and is a professional necessity rather than a preference.
Server logs: 90 days in hot storage.
7. Your rights
Depending on where you live you may have the right to access, correct, delete, port, restrict or object to our processing of your personal information, and to complain to a supervisory authority.
Write to privacy@uselatitude.co.uk and we will respond within the period your law allows. We will verify your identity before acting.
If your request concerns data processed on behalf of a client firm — for example, a process owner recorded against one of its controls — we route it to that firm, which is the controller. We cannot action it directly.
8. Automated processing
Latitude uses artificial intelligence, including language models, to read records and draft documents. Where that processing involves client data it is governed by the engagement terms and the DPA, not by this policy.
No decision producing a legal or similarly significant effect about any individual is made solely by automated means. The system produces drafts and supporting evidence; a licensed attorney reviews, decides and signs. Where the UK or EU GDPR applies you retain the Article 22 rights in any event.
Personal information collected through this website is not used to train any model.
9. Security
Encryption in transit and at rest, role-based access control, least-privilege internal access, per-client segregation, audit logging, and background checks for personnel with production access. The full posture, including its current limits, is on the Trust page.
No system is perfectly secure. Where a breach affects your personal information we will notify you and the relevant authority within the timeframes our obligations require.
10. Changes and contact
We will post any material change here and update the effective date. Where the change is significant and we hold your contact details, we will tell you directly.
Latitude — privacy@uselatitude.co.uk. A postal address and the identity of our data protection officer will be listed here once entity details are finalised.
Pre-launch notice. These documents are drafted as realistic scaffolding for a RegTech vendor and have not been reviewed by counsel — which matters more than usual for a company selling to lawyers. Entity details, postal address, data protection officer and the subprocessor roster are placeholders pending incorporation. Do not rely on them as executed legal terms.