← Back to Diract

Privacy Policy

Diract · Last updated: 31 August 2026

1. Overview

Diract (we, us) provides a configurable business and practice management platform used by organisations across a range of industries (the Service). This policy explains what personal information we collect through the Service, how we use it, who we share it with, and the choices and rights available to you. It applies to the organisations that hold an account with us (Customers), the individuals they authorise to use the Service (Users), and, where a Customer’s own client or counterparty data passes through the Service, those individuals (Client Data subjects). For Client Data, though, the Customer is generally the party responsible for that data, and we act as its service provider. See clause 7 for how that split works.

2. Information We Collect

Account and User information

Name, work email address, phone number, role, and authentication details for each User; the Customer’s organisation details and billing and subscription information.

Content you put into the Service

Records in whichever tables a Customer has configured, which may include matter, property, entity, customer and job records, together with documents, precedents, notes, tasks, calendar entries, financial and trust accounting records, and any other Content a Customer or User enters into or generates within the Service, which may include Client Data about a Customer’s own clients or counterparties.

Integration data

Where a Customer or User connects a third-party account (Gmail, Microsoft Outlook/Teams, OneDrive/SharePoint, WhatsApp Business), we access the data needed to provide that Integration. For example, that includes email metadata and content for messages a User assigns to a matter, calendar events, messages sent through a connected WhatsApp Business number, and, where a Customer's administrator has linked a SharePoint document library, the files in it and, for supported file types, text extracted from them, limited in each case to what the Integration is described as doing at the time it is enabled.

Biometric information (Face ID)

If a Customer enables Face ID and a staff member chooses to enrol, a numeric description of their face generated from a device camera, not a photograph. See clause 3 for how this category is handled specifically.

Precise location information (Geo Lock)

If a Customer enables app-based check-in with Geo Lock, the device's precise (GPS-based) location at the moment a staff member checks in. See clause 4 for how this category is handled specifically.

AI interaction data

Prompts, uploaded documents, and generated output when a User uses an AI Feature, together with metadata about that use (which feature, when, and by which User) for the purposes described in clause 6.

Usage and device information

Log data, IP address, approximate location derived from IP address (used, among other things, to show you the most relevant part of this page and our Terms), browser and device type, and how you interact with the Service, collected automatically. This is separate from, and much less precise than, the GPS-based location described above.

3. Biometric Information (Face ID)

Face ID is opt-in twice over: it is only available at all if a Customer's administrator turns it on for their organisation, and, even then, only if an individual staff member separately chooses to enrol. Enrolling captures a mathematical description of the person's face, not a photograph or video, which the Service compares against a newly generated description each time that person checks in, to recognise them; the underlying camera image is not itself retained.

We treat this as sensitive biometric information. We retain an enrolment until a staff member removes it themselves (available to them at any time from within the Service) or a Customer's administrator removes it on their behalf. Turning Face ID off at the company level stops it being offered to anyone new, but does not by itself delete an enrolment already on file; if a Customer wants existing enrolments deleted as well, its administrator can remove them, or ask us to. A Customer that enables Face ID is responsible for giving its own staff any notice, and obtaining any consent, that the workplace surveillance, privacy or biometric information laws applicable to it require. See clause 11 of our Terms of Service.

4. Precise Location Information (Geo Lock)

If a Customer enables both app-based check-in and Geo Lock, the Service asks the User's browser or device for their precise, GPS-based location at the moment they check in, and compares it against a location their Customer's administrator has configured, to confirm the check-in happened within an allowed distance. We store that location together with the check-in record. We do not collect a User's precise location at any other time, continuously, or in the background. This is a separate, much more precise data point than the approximate, IP-derived location mentioned in clause 2.

This location data is visible only to the Customer's own administrators, as part of their staff attendance records, and is never shared outside the Customer's own Account. A Customer that enables Geo Lock is responsible for giving its staff any notice that the employee-monitoring, surveillance or privacy laws applicable to it require. See clause 11 of our Terms of Service.

5. How We Use Information

  • To provide, maintain, and secure the Service, including authenticating Users and enforcing access controls between Customers;
  • To operate the features a Customer has enabled, including AI Features, Face ID, Geo Lock, and third-party Integrations;
  • To communicate with Customers and Users about the Service, including support, security notices, and material changes;
  • To bill and collect payment for the Service, and to let a Customer manage or cancel its own subscription;
  • To detect, investigate and prevent fraud, abuse, and security incidents;
  • To improve the Service, including, where a Customer has not opted out where an opt-out is offered, using de-identified or aggregated data to improve AI Features; and
  • To comply with our own legal obligations.

6. AI Processing and Third-Party AI Providers

What is sent, and why

When a User uses an AI Feature (for example, precedent drafting assistance, document summarisation, or cross-reference checking), the relevant Content is sent to Diract’s own infrastructure and, to generate the requested output, to the third-party AI model provider or providers configured for that feature. As at the date of this policy, that may include Anthropic and Together AI, or their successors; we will update this policy if the providers we use for a given feature materially change.

How those providers may use it

Those providers act as our sub-processors: they process Content solely to return a response to the request that sent it, under contractual terms that prohibit using it to train their own general-purpose models, and do not retain it beyond what is needed to provide the response and meet their own legal obligations (for example, short-term abuse-monitoring retention).

No automated decisions with legal effect

We do not use AI Features to make a decision about an individual that produces legal or similarly significant effects without a human involved. AI Feature output is a drafting or analysis aid for a User, who remains responsible for reviewing it before it is relied on or acted on. See clause 5 of our Terms of Service.

7. Client Data: Who is Responsible

Where Content includes Client Data about a Customer’s own clients or counterparties, the Customer determines what is collected and why (it is the controller, in EU/UK GDPR terms), and Diract processes it only as the Customer’s service provider (processor), on the Customer’s instructions as reflected in how it configures and uses the Service. If you are a client or counterparty of one of our Customers and have a question about your own data held in the Service, please contact that organisation directly rather than Diract, since we are not able to action a request from someone we cannot verify is authorised on the relevant account.

8. Data Sharing and Disclosure

We do not sell personal information. We share information only:

  • within a Customer’s own Account, with the other Users that Customer authorises;
  • with sub-processors who host, process, or support the Service on our behalf (infrastructure hosting, AI model providers as described in clause 6, email and messaging delivery, payment processing, and bot detection as described in clause 11), under contracts that limit their use of it to providing that support;
  • with a third-party platform a Customer or User has connected via an Integration, to the extent that Integration requires;
  • where required by law, legal process, or to protect the rights, property or safety of Diract, our Customers, or others; and
  • in connection with a merger, acquisition, or sale of assets, subject to the acquiring party continuing to honour this policy for information already collected.

9. Data Storage, Security and International Transfers

Content is stored using Supabase (PostgreSQL), hosted on cloud infrastructure that may be located outside your own country, including in the United States. Where personal information is transferred internationally, we take steps required by applicable law to protect it in transit and at the destination (for example, standard contractual clauses for transfers subject to GDPR/UK GDPR). We use technical and organisational measures, including encryption in transit, access controls scoped per Customer, and authentication safeguards, appropriate to the sensitivity of the information involved (including the biometric and location information described in clauses 3 and 4), but no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Data Retention

We retain Content for as long as a Customer’s Account is active, and for a reasonable period after termination to allow export and to meet legal, accounting, or dispute-resolution requirements, after which it is deleted or de-identified. Account and billing records may be retained longer where required by tax, corporate, or professional record-keeping law. Biometric and precise location information have their own, generally shorter, retention approach: see clauses 3 and 4.

You can delete your account at any time from within the Service, including from the mobile app under More, or by contacting us. Deleting an account removes your profile and personal information, removes any biometric enrolment you have made, and revokes your access to every workspace you belong to.

Where you are a member of a Customer’s workspace, Content you created inside that workspace belongs to that Customer and is dealt with under clause 7 rather than removed by your own account deletion. This is so that one person leaving does not delete their employer’s records.

11. Cookies and Analytics

We use strictly necessary cookies to keep you signed in and to remember basic preferences (such as your chosen theme), and limited first-party analytics to understand how the Service and our public pages are used. We do not use third-party advertising cookies.

To protect sign-in, account creation, password reset and our public forms from automated abuse, we use Cloudflare Turnstile. It runs in the background on those pages, in most cases with nothing shown on screen, and processes a small set of technical signals from your browser, such as your IP address, user agent, a TLS fingerprint of the connection, and the site key of the page you are on. Cloudflare states that it cannot directly identify an individual from those signals, and they are not used for advertising or cross-site tracking. Cloudflare acts as our service provider when it runs that check on our behalf, and as its own controller when it uses the same signals to improve its bot detection. For detail, see Cloudflare’s Turnstile Privacy Addendum, which supplements its Privacy Policy.

12. Your Rights

Depending on where you are, you have certain rights over your personal information. Select your region below. This doesn’t change which rights you have, only which section is shown first.

If you are a California resident, the CCPA/CPRA and similar state privacy laws (where applicable) give you the right to know what personal information we have collected about you, to request its deletion, to correct inaccurate information, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined in applicable law. Several US states also give you specific rights over biometric information (clause 3); we do not collect it unless your employer has enabled Face ID and you have separately chosen to enrol. You will not be discriminated against for exercising these rights.

To exercise any of these rights, contact privacy@diract.io. You can also remove your own Face ID enrolment directly from within the Service at any time, without needing to contact us. We may need to verify your identity, and your authority on the relevant Account, before actioning any other request.

13. Children's Privacy

The Service is intended for use by business professionals and is not directed at children. We do not knowingly collect personal information from children.

14. Google API Services User Data Policy

Diract’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Gmail data accessed via the Service is used only to provide and improve the specific Gmail-related features a Customer has enabled, is not used for advertising, and is not transferred to third parties except as necessary to provide those features, to comply with the law, or as part of a business transfer as described in clause 8, and never to train general-purpose AI/ML models.

15. Microsoft Graph (OneDrive/SharePoint) Data Use

Where a Customer's own Microsoft 365 administrator connects OneDrive/SharePoint, they grant Diract's own registered Microsoft application organisation-wide permission to read and write files. A Customer never shares a password or its own credentials with us to do this, and its administrator can revoke this consent at any time from its own Microsoft 365 admin centre. We access only the specific document library that Customer's administrator has linked, use it only to provide the file-browsing, drafting and AI-search features the Customer has enabled, and do not use it to train general-purpose AI/ML models.

16. Changes to this Policy

We may update this policy from time to time. Where a change is material, we will give reasonable notice before it takes effect (for example, by email or an in-app notice).

17. Contact

For privacy-related enquiries, contact privacy@diract.io.