Data We Process
Lightfield processes data submitted to or connected with the legal intake platform, including:
- Account and team profile information.
- Legal intake requests, comments, attachments, operational metadata, and audit events.
- Connected mailbox or integration metadata needed to ingest and route legal requests.
- Product analytics and diagnostic events used to operate and improve the service.
Lightfield may process legally privileged, confidential, personal, or commercially sensitive information when customers submit it through intake requests, emails, attachments, or integrations.
How We Use Data
We use data to:
- Provide legal intake, triage, assignment, status tracking, and related workflow features.
- Authenticate users and enforce tenant isolation.
- Maintain audit logs, security logs, and operational reliability.
- Detect abuse, investigate incidents, and comply with legal obligations.
- Improve product quality using aggregated or minimized analytics.
We do not sell customer data.
Google API Limited Use
If a customer connects Gmail or another Google API integration, Lightfield's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide user-facing legal intake and workflow functionality requested by the customer, such as reading legal-request messages, syncing request status, and retrieving attachments selected by authorized users. Lightfield does not use Google user data for advertising, does not sell Google user data, and does not allow humans to read Google user data except for security, support, legal, or compliance purposes with customer authorization or as required by law.
AI Processing
Lightfield may use AI service providers to classify, summarize, or route legal intake content. AI processing is limited to providing Lightfield functionality and should be governed by customer contract terms, vendor DPAs, and provider settings that prohibit training on customer data where applicable.
Security
Lightfield uses access controls, audit logging, encryption in transit, encryption at rest, tenant-scoped authorization, session revocation, and secure development controls to protect customer data. Security incidents are handled under the incident response plan.
Retention and Deletion
Customer data is retained according to the Data Classification and Retention Policy. Authorized administrators can request or initiate organization export and deletion. Some records may be retained as required for security, legal, audit, backup, or compliance purposes.
Subprocessors
Lightfield may use vendors such as hosting, database, analytics, email, AI, monitoring, and productivity providers to deliver the service. Vendor risk reviews and DPAs are tracked under the Vendor and Third-Party Risk Policy.
Contact
Privacy requests and security reports can be sent to security@trylightfield.ai.