Privacy Policy Overview
This privacy policy explains how JurisYFlow collects, processes and stores personal data in the course of providing enterprise legal operations and compliance services. The policy uses practical scenarios and case-based examples to clarify typical processing activities, legal bases, and customer rights. JurisYFlow operates from Rue du Village 54, 1874 Champéry, Switzerland and applies principles relevant to Swiss data protection law and applicable international standards where relevant.
Definitions
The following definitions clarify terms used throughout this policy. Each definition is illustrated by an example scenario from enterprise legal operations to make its application concrete and practical.
- Personal data means any information relating to an identified or identifiable natural person. Example scenario: when a contract manager uploads a supplier contact card (name, email, phone) into JurisYFlow for approval workflows, that information is personal data.
- Processing covers any operation performed on personal data, such as collection, storage, consultation, disclosure and deletion. Example scenario: automated redaction of personal identifiers in contract archives is processing.
- User refers to individuals who interact with JurisYFlow services, including corporate clients' employees, legal counsels, and authorized third parties. Example: an in-house lawyer using JurisYFlow to run compliance reports.
- Service means the legal operations and compliance platform and related professional services provided by JurisYFlow through JurisYFlow.click, including contract lifecycle management, compliance dashboards and advisory projects.
- Cookies are small data files placed on devices to enhance functionality and analytics. Example: a session cookie that preserves a user's authenticated state while they review a contract in a multi-step approval flow.
We collect personal data directly from users, automatically during platform use, and from third parties when necessary. Below we list typical categories with case-based explanations to illustrate why each is needed in legal operations contexts.
User-provided Data
Data submitted directly by users for onboarding, collaboration and service delivery. Practical cases: uploading contract documents, entering contact details for counterparties, or configuring compliance rules.
- Identity and contact details: names, job titles, corporate email addresses and telephone numbers used to route approvals and notify stakeholders during contract workflows.
- Corporate identifiers and contract metadata: company registration numbers, client IDs, contract value, effective dates and other fields required for regulatory reporting and audit trails.
- Uploaded documents and attachments: scanned contracts, NDAs, regulatory filings and supporting documents necessary for contract review, redlining and compliance checks.
- User configuration and preferences: role assignments, approval matrix settings and notification preferences to ensure proper access and workflow behavior in enterprise scenarios.
- Communications content: messages, comments and annotations added to matters or contracts to maintain an audit history and facilitate collaborative legal operations.
- Verification materials: where required for enhanced compliance, users may submit identity verifications or proof of authority for contract signatories in specific case procedures.
Automatically Collected Data
When users interact with JurisYFlow, we collect certain data automatically to operate the service, improve performance and secure accounts. Examples below show how metadata supports compliance reporting and incident contribute.
- Usage and interaction logs: timestamps of actions, documents accessed, user session durations used to reconstruct approval sequences during audits or disputes.
- Device and browser information: IP addresses, device type, browser version and language settings used to detect anomalous access patterns and support secure access controls.
- Performance metrics and error logs: system telemetry to identify and remediate issues affecting legal workflows and to refine integrations with client systems.
- Authentication data: hashed passwords, multi-factor authentication vouchers and related security metadata necessary to protect accounts and limit unauthorized access.
- Analytics and aggregated insights: anonymized usage metrics and feature adoption statistics used to improve product features relevant to compliance teams.
- Location metadata: coarse geolocation derived from IP for risk-scoring in cross-border access scenarios and to support region-specific compliance obligations.
Data Obtained from Third Parties
We may receive personal data from trusted third-party providers, integration partners and public registers to enrich legal records or verify corporate information in concrete case scenarios.
- Integration partners: client HR or procurement systems that provide employee or supplier records to populate JurisYFlow workflows and reduce manual entry in contract onboarding.
- Public registers and corporate databases: company registry extracts used to verify counterparty legal status during due diligence tasks.
- Service providers: identity verification services, e-signature providers and document scanners that process limited personal data to complete onboarding or signing steps.
Purposes of Processing
We process personal data to deliver core features of our legal operations platform, to meet regulatory obligations and to assist clients in compliance tasks. Each purpose is illustrated with a practical case to show real-world application.
- Platform delivery and account management: enable user accounts, administer roles and maintain access control. Case: provisioning a compliance officer with reviewer rights for a collection of contracts.
- Contract lifecycle management: store, analyze and track contract status and metadata to support renewals, obligations and risk assessments. Case: automated renewal alerts for vendor contracts with high regulatory impact.
- Compliance monitoring and reporting: generate reports and alerts for regulatory deadlines, audit trails and compliance KPIs. Case: quarterly compliance scorecards used by in-house legal to prepare board reports.
- Fraud prevention and security: detect unusual access patterns and contribute incidents to protect client data and ensure continuity of legal operations.
- Customer support and dispute resolution: respond to client inquiries and contribute issues using logs and correspondence records to resolve operational disputes.
- Improvement and analytics: analyze anonymized usage to refine workflows and product features that ease compliance tasks across enterprise clients.
- Legal obligations and enforcement: process data necessary to comply with court orders, legal processes or mandatory regulatory requests in specific case contribute.
- Integrations and third-party services: share limited data with authorized providers to execute e-signatures, identity checks and document conversions as part of operational scenarios.
Legal Bases for Processing
We rely on appropriate legal bases to process personal data. Below are typical bases applied in legal operations contexts, each illustrated with a scenario to clarify when it applies.
- Performance of a contract: processing necessary to provide our services to a client. Example: storing contract documents and sending renewal notifications required by an SLA.
- Legal obligation: processing to comply with laws or regulatory requirements. Example: retaining audit logs for a period mandated by business regulatory rules.
- Legitimate interests: where processing supports secure operation and fraud prevention, balanced against individual rights. Example: monitoring login anomalies to protect confidential contract data.
- Consent: when explicit consent is required for non-essential processing such as marketing communications or cookies beyond necessary functionality; consent scenarios are clearly documented and revocable.
GDPR and Cross-border Considerations
Although JurisYFlow is based in Switzerland, we describe how GDPR principles are applied when processing data of EU data subjects or when operating cross-border workflows. Case examples demonstrate practical compliance steps.
- Lawful basis documentation: we record applicable legal bases for processing activities that involve EU resident data in alignment with GDPR record-keeping practices.
- Data subject rights handling: procedures for access, rectification, erasure and portability are implemented with documented response scenarios for client and user requests.
- Data protection by design: example case where we implemented role-based access and minimization for a multinational client's contract repository to reduce exposure of sensitive identifiers.
- Data processing agreements: standardized agreements and clauses are used with processors to ensure required contractual protections in cross-border processing situations.
- Impact assessments: we conduct data protection impact assessments for higher-risk projects, illustrated by a scenario analyzing automated clause extraction across multiple jurisdictions.
- Supervisory cooperation: we assist clients and respond to lawful requests from competent authorities in a documented, case-oriented manner while protecting confidentiality and legal privileges where applicable.
Cookies and Similar Technologies
JurisYFlow uses cookies and related technologies to deliver, secure and measure our services. Below we explain types, categories and how cookies are managed with scenario-based examples.
We use essential session cookies for authentication, persistent cookies for user preferences, and analytics cookies to measure feature usage. Example: an essential cookie keeps a user logged in during a multi-step approval.
Categories include essential (required for platform operation), performance/analytics (usage metrics) and optional marketing cookies which are subject to consent before activation.
Users can manage cookie preferences via the cookie banner and browser settings. Practical guidance: how to disable non-essential cookies while retaining core workflow functionality in JurisYFlow.
For full details, see the JurisYFlow Cookie Policy on JurisYFlow.click/cookie-policy and follow the guided scenarios for managing consent in enterprise deployments.
Data Sharing and Disclosure
We share personal data only as necessary to provide services, comply with law, or with explicit client instructions. Each sharing type is explained with a representative case to show typical recipients and purposes.
- Service providers and processors: e-signature platforms, identity verification vendors and secure cloud hosting used to perform contract signing and storage in a client-authorized workflow.
- Clients and their authorized representatives: sharing contract records or compliance reports with client stakeholders under role-based access for operational needs.
- Regulators and law enforcement: disclosure in response to lawful requests or to meet mandatory reporting obligations during an contribute scenario.
- Professional advisors: auditors or external counsel engaged by JurisYFlow or our clients to examine records as part of an enterprise compliance audit.
- Business transfers: in the event of a merger, acquisition or sale of assets, select data necessary for business continuity and transition, handled under due diligence safeguards.
- Aggregated or anonymized data: aggregated metrics shared for benchmarking and product improvement where individual identities are not reasonably identifiable.
International Data Transfers
Cross-border data transfers may occur when clients or processors operate in multiple jurisdictions. Transfers are governed by appropriate safeguards, documented in processing agreements and based on case-specific assessments.
Safeguards include standard contractual clauses, binding corporate rules where applicable, and documented risk assessments; an example case describes transfer of contract metadata to a UK-based analytics provider under SCCs.
Data Retention
We retain personal data for the time necessary to provide services, meet contractual and legal obligations, and allow for legitimate business needs. Retention periods are tied to use-case scenarios to explain practical retention choices.
Account data and essential records: retained for the duration of the client relationship plus an archival period aligned with contractual and regulatory requirements, illustrated by a client retention scenario after project completion.
Communications and annotations: retained to preserve audit trails and dispute resolution records for a period proportionate to the underlying contractual obligations and legal risks.
Access and system logs: kept for security monitoring and incident contribute for a defined retention window (case example: 24 months for forensic reconstruction in compliance reviews), then aggregated or deleted.
Deletion and anonymization: upon termination of service or expiry of retention periods we delete or irreversibly anonymize data unless legal obligations require continued retention; an obsolescence scenario explains the workflow and verification checks.
Security Measures
JurisYFlow implements technical and organizational measures to protect personal data in line with the sensitivity of legal operations use cases. Security practices are described through concrete controls and incident response scenarios.
- Access control and encryption: role-based access, MFA and encryption of data at rest and in transit to protect contract repositories and sensitive compliance records.
- Operational safeguards: secure development practices, regular vulnerability scanning, logging and monitoring to detect and respond to anomalies in real-world incident simulations.
- Organizational measures: staff training, contractual confidentiality obligations and least-privilege access policies illustrated by a case where rapid role revocation was required during a personnel change.
User Rights
Individuals have rights regarding their personal data. We provide practical instructions and case-based timelines for exercising each right, including how requests are validated and processed in enterprise contexts.
- Right of access: request a copy of personal data held about you. Scenario: a compliance officer requests access to their activity logs to validate approval history.
- Right to rectification: request correction of inaccurate data. Scenario: updating an employee's role and contact details to ensure accurate routing in approval workflows.
- Right to erasure: request deletion where retention is no longer necessary and no overriding legal obligations exist. Scenario: removal of a personal contact after contract termination, subject to archival constraints.
- Right to restriction: request temporary limitation of processing. Scenario: restricting access to certain historical contract records while a dispute is contribute.
- Right to data portability: receive a machine-readable copy of personal data where processing is based on consent or contract. Scenario: exporting a user's contract-related metadata for migration to an internal system.
- Right to object and automated decision-making: object to processing based on legitimate interests and request human review of automated outcomes used in compliance scoring, as detailed in an objection handling case.
- Right to withdraw consent for processing where processing is based on consent — we will cease processing for the specified purpose upon receipt of withdrawal, subject to other lawful bases for processing.
- Right to lodge a complaint with the competent Swiss data protection authority if you consider that our processing of your personal data conflicts with applicable law; we provide facts and contact details to support such a complaint.
How to exercise your privacy rights
To exercise your rights under applicable Swiss data protection law (access, rectification, deletion, restriction, portability, objection, withdrawal of consent), submit a request to our data protection team at JurisYFlow using the contact details below. Include a clear description of the requested action and sufficient information to identify the data concerned (examples and case references are helpful to speed processing). We may request identity verification for sensitive requests.
We aim to acknowledge receipt of rights requests within 7 business days and to provide a substantive response within 30 calendar days. For complex requests or where additional verification is required, we will notify you of any reasonable extension and the reasons for it.
Marketing communications and choices
JurisYFlow may send regulatory updates, product news, and invitations to events relevant to legal operations and compliance. Communications are tailored to your expressed interests and previous interactions. Marketing emails include clear descriptions of the topics and the option to change preferences. We use case-based segmentation so you receive only relevant material based on roles, industry scenarios, and expressed needs.
To stop receiving promotional emails, use the unsubscribe link in any marketing email or contact [email protected] with the subject 'Unsubscribe'. We will process unsubscribe requests within five business days. Transactional messages related to existing contracts or service alerts may still be sent unless you also request their cessation.
Children's privacy
JurisYFlow does not target services to children and does not knowingly collect personal data from persons under 16 without appropriate parental consent. If we become aware of such collection, we will take prompt steps to delete the data. For scenarios where minors may be involved (for example in certain training or internship programmes), we require documented parental or guardian consent and appropriate verification.
Third-party links and services
Our website and services may reference or link to third-party providers, industry tools, and external regulatory sites. Those links are provided for convenience; JurisYFlow is not responsible for the privacy practices or content of third parties. In practical cases where JurisYFlow integrates third-party workflow tools, we document the data flows, processors involved, and contractual safeguards in our internal compliance logs and make summaries available on request.
Changes to this privacy policy
We review and update our privacy policy to reflect operational changes, new legal obligations, or improvements to our processes. Material changes will be published on JurisYFlow.click with the revision date and a short summary of what changed; for clients with active agreements we also communicate relevant changes by email. Example scenario: if a new analytics integration is introduced, we will publish a case note describing the data types shared, retention, and mitigation measures.
Contact for privacy queries
For privacy questions, data subject requests, or to request more information on our processing practices, contact: JurisYFlow Data Protection Team, Rue du Village 54, 1874 Champéry, Switzerland; email: [email protected]; phone: +41767608779. Business ID: CHE-015.293.256. Include details of relevant cases or examples to help us respond efficiently.
- +41767608779
- [email protected]
- Rue du Village 54, 1874 Champéry, Switzerland