Privacy policy
Effective 7 September 2026. Last amended 16 September 2026.
elmdocs is a workspace for legal work: law firms, in-house teams, and anyone whose work involves legal documents. They put their files in it, so most of what it holds is personal information about people who never use it: a firm's clients, a business's counterparties, the other side of a negotiation, witnesses in a chronology. This policy explains what elmdocs collects, where it goes, how long it stays, and what you can ask us to do about it. It is written for the people who use elmdocs and for the people whose information a firm has put in it.
In this policy, the Service means the elmdocs website, the iPhone and iPad app, the Word, Excel, PowerPoint and Outlook add-ins, and the servers behind them. Personal Information has the meaning given to it in the Privacy Act 1988 (Cth). We are bound by that Act and by the Australian Privacy Principles made under it, and this policy is our statement of how we comply with Australian Privacy Principle 1.
By using the Service you agree to the collection, use and disclosure of information as this policy describes. If you do not agree with it, do not use the Service. Questions and requests go to admin@elmdocs.com.
Who is responsible
For a firm's client files, the firm is the one that decides what goes in and who sees it, and elmdocs holds it on the firm's behalf. If you are a firm's client and want to know what the firm holds about you, ask the firm. For the details of the people who sign in, the account itself, elmdocs is responsible, and this policy is our commitment to you.
What we collect
Your account
Your work email address, your name if you give one, and the firm you belong to, which is worked out from your email domain. Sign-in is passwordless: we email you a six-digit code, so we keep the secret that generates those codes but never a password. Firms that use single sign-on send us your identity from their own identity provider instead, and we keep only the identifier it gives us. For each sign-in we record when it happened, the device or browser it came from, and its network address, so you can see your active sessions and end one you do not recognise.
Your firm's work
Everything a firm puts in: clients and matters, documents and every version of them, conversations with the assistant, review tables, chronologies, precedents, intake forms and the answers to them, negotiation rooms and the documents exchanged in them, emails and attachments filed from Outlook, and the signatures collected on documents. Some of this arrives from outside the firm. A client who fills in an intake form, or the other party in a negotiation, gives us their name, email address and whatever they upload, and we hold it under the firm's matter.
The Word, Excel, PowerPoint and Outlook add-ins
The Office add-ins put elmdocs inside the programs a firm already uses, signed in with the same account. The Word add-in (which also runs in Excel and PowerPoint) opens elmdocs documents in the program and sends the document you are working on, and the edits you accept, back to the firm's matter; it reads nothing else on your computer. The Outlook add-in reads the message you have open, its subject, sender, recipients, body and attachments, only when you open the add-in on that message and choose a matter for it. The message becomes a conversation with the assistant, so its text goes to the AI model as described below, and the attachments you select are filed under the matter. It does not read your mailbox in the background, keep a copy of any message you did not send to a matter, or send mail on your behalf. Outlook grants it mailbox permission because that is the only permission level under which an add-in can read attachments.
A record of what was done
elmdocs keeps an audit trail: who opened, changed, shared or deleted what, and when. Firm administrators can see it for their firm, and you can see your own. We also count the assistant's usage per person so firms can manage it; those counts do not include the content.
Log data
Each audited request records the network address it came from, the browser or app that made it (its user-agent string), the method and path requested, the response status, how long it took, and the time it happened. We use this to operate and secure the Service, to investigate faults, to detect abuse, and to give you and your firm's administrators a truthful record of what was done. This per-request detail is kept for 365 days, after which it is folded into daily counts per person and per kind of event and the detailed rows are deleted. Our servers also produce ordinary operational logs, which we keep only as long as we need them to run the Service.
What we do not collect
There is no advertising, no analytics service and no tracking anywhere on the website or in the apps: no advertising or analytics cookies, no third-party trackers, no advertising identifier, and no profiling of you. The iPhone and iPad app asks for no device permissions; it reads a document only when you choose it in the Files picker, and keeps a copy of documents you open in its cache for offline viewing.
Cookies
A cookie is a small file a website stores in your browser. Every cookie elmdocs sets is our own and is there to make the Service work; none is used to track you, here or anywhere else. They are:
- A session cookie that keeps you signed in, for up to thirty days. It cannot be read by scripts in the page and is not sent with requests from other sites.
- A companion cookie holding your email address, so the page can show who is signed in. It is readable by the page, and the server never accepts it as proof of who you are.
- A session cookie for the Office add-ins, which carries the same sign-in as the first. It exists because Microsoft hosts the add-ins inside a frame, and the ordinary session cookie is deliberately never sent in one.
- For someone visiting a guest link, a client filling in an intake form, or a party to a negotiation, a cookie scoped to that link alone, which expires with it.
- During single sign-on, a short-lived cookie holding the one-time values that prove the sign-in that comes back is the one your browser started. It is discarded as soon as the sign-in completes.
Your browser can refuse or delete these, but the Service cannot keep you signed in without the first of them, and refusing it means you cannot use elmdocs.
How we use it
To run the service: to file, show, search, compare and version the firm's work, to let the right people see it, and to send the emails the service needs, sign-in codes, invitations to a negotiation, a request to sign, and notices about assistant usage. We do not use your information for marketing, and we do not sell or rent it.
The assistant is the reason most people use elmdocs, and it works by sending the relevant content to an AI model. When you ask it about a document, the document and your question go to the model; when you ask a research question, the passages of legislation and case law it found go with it. That content is used to answer you and for nothing else.
Who else handles it
We use a small number of service providers, each for one job, and we share with them only what that job needs.
- AI models. Anthropic's Claude, through Anthropic's API, under commercial terms that do not allow the provider to train on your content. A firm may bring its own credentials instead, either an Anthropic key, or Amazon Web Services credentials for Bedrock, which defaults to the Sydney region, in which case the content goes to the firm's own account with that provider and is processed wherever that account runs. We store such credentials encrypted and never return them to anyone, including the firm that supplied them.
- Document storage. Documents and their rendered copies are stored with Backblaze in the United States. The database holding everything else, accounts, clients and matters, conversations with the assistant, and the audit trail, runs on our own servers, which are also in the United States.
- Email. SendGrid delivers the emails the service sends. It receives the address and the message.
- Electronic signing. When a firm sends a document for signature, the document and the signers' names and email addresses go to DocuSign, and the signed document comes back.
- Legal research sources. Legislation and case law come from the official Australian publishers. Nothing of yours is sent to them; we fetch public documents from them.
Each of these providers may handle Personal Information only to perform the task we have engaged it for. To the extent permitted by law they are bound not to disclose it, and not to use it for any other purpose, including their own. Where a provider is overseas, we take the steps that are reasonable in the circumstances to ensure it handles the information consistently with the Australian Privacy Principles, as Australian Privacy Principle 8 requires.
We disclose Personal Information to nobody else unless the law requires or authorises it, in which case we will tell the firm concerned unless we are prohibited from doing so.
Where it goes
The United States. Documents are stored there with Backblaze, the database runs on our own servers there, and the AI processing happens there unless your firm supplies its own provider credentials, in which case it happens wherever that account is. The Privacy Act 1988 (Cth) and the Australian Privacy Principles govern how we handle your information wherever it is held; this section is about where it physically sits, which is a separate question and one firms ask.
Australia-only residency, a firm's documents and its AI processing both kept in Sydney, is not currently available. If your firm needs it, ask us.
How long we keep it
A client file is the firm's record, and Australian practice rules require a firm to keep it for years after a matter closes. So the firm sets a retention period for each client or matter, and a closed matter and everything in it is destroyed when that period runs out. Nothing in a live matter is destroyed because a person leaves.
When a person leaves a firm, their access is disabled straight away. Their name stays on the work they did, because the firm's file has to say who did what, and their personal details are removed once the firm's retention period has run. Sign-in codes expire within minutes; sessions expire after thirty days or when you end them; the detailed audit record is kept for 365 days as described above.
Where we hold Personal Information that we no longer need for any purpose for which it may be used or disclosed, and we are not required by law or by a court or tribunal order to retain it, we take the steps that are reasonable in the circumstances to destroy it or to ensure it is de-identified.
Keeping it safe
Everything travels over TLS. Documents are encrypted at rest by the storage providers. Each firm's data is separated from every other firm's in the database itself, not only in the application, and every request is checked against the matter's access list. On the phone, your sign-in token lives in the device keychain and cannot be read by other apps. If a data breach is likely to cause serious harm, we will notify the people affected and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
We take the steps that are reasonable in the circumstances to protect Personal Information from misuse, interference and loss, and from unauthorised access, modification and disclosure. No method of transmission over the internet and no method of electronic storage is completely secure, however, and we cannot guarantee absolute security.
Access to your information
Most of it you can reach yourself, without asking us. From the Account screen you can see and correct your account details, see your active sessions and end any of them, and download everything your account holds as a single archive.
You may also request access to the Personal Information we hold about you at any time, using the contact details below. We will acknowledge your request promptly and tell you when we will provide the information. If we refuse access, we will give you a written notice setting out our reasons (unless the law allows us not to give them) and how you may complain about the refusal. We do not charge you for making a request; we may recover our reasonable costs of giving access, and we will tell you what those are before we incur them.
You can ask us to delete your account. We will disable it and remove your personal details, subject to the firm's retention obligations for its files, a client file is the firm's record, and we cannot destroy the firm's record at the request of one person named in it. If you are a firm's client and want access to what a firm holds about you, the request goes to the firm, because the firm decides what its file contains; we will help the firm meet it.
Correcting your information
We seek to ensure that the Personal Information we hold is accurate, up-to-date, complete and, when we use or disclose it, relevant. Where we believe that information we hold is inaccurate, out-of-date, incomplete, irrelevant or misleading, we will take reasonable steps to correct it, and, if you ask us to, and it is reasonable and practicable, to notify that correction to anyone we have given the incorrect information to.
If you believe information we hold about you should be corrected, you may ask us to correct it, using the contact details below. If we do not agree that a correction is required we are not obliged to make it; instead we will give you a written notice setting out our reasons (unless the law allows us not to give them) and how you may complain about the refusal. You may also ask us to associate with the information a statement that you consider it inaccurate, out-of-date, incomplete, irrelevant or misleading, and we will take reasonable steps to make that statement apparent to anyone who reads the information. We do not charge you for making a correction request, for correcting information, or for associating a statement with it.
Enquiries and complaints
If you have an enquiry, concern or complaint about this policy, about how we have handled your Personal Information, or about our compliance with the Privacy Act 1988 (Cth) or the Australian Privacy Principles, write to admin@elmdocs.com. We usually respond in writing within thirty days, unless we need further information from you before we can.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner: by telephone on 1300 363 992, by email at enquiries@oaic.gov.au, or online at oaic.gov.au.
Links to other sites
The Service links out to material published elsewhere: a piece of legislation or a judgment, and the sources cited in an assistant's answer, open on the official Australian publisher's own site. Signing happens on DocuSign's site as well, when a firm sends a document for signature, DocuSign emails the signers and they sign there, not here. Those sites are not operated by us. We have no control over, and take no responsibility for, their content or their privacy practices, and this policy does not apply to them. Read their own policies before giving them your information.
Children
elmdocs is a professional tool for lawyers and is not offered to anyone under eighteen.
Changes
We review this policy regularly and may amend it from time to time. The current version is always the one on this page, and the effective and amendment dates at the top change with it. Where an amendment materially affects how your information is handled, we will tell firm administrators by email before it takes effect.
Contact us
For any question about this policy, about the Personal Information we hold, or to make a request or a complaint under it, write to admin@elmdocs.com.