IFTI.AI

Privacy Policy

Last updated: 30 June 2026

We keep this policy under regular review; the version published here is the one that currently applies to your use of the Service.

IFTI.AI (“IFTI”, “we”, “us”, or “our”) provides a software platform that helps UK law firms manage client intake, compliance, matter management, and client communication. This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with the IFTI.AI platform available at os.ifti.ai (the “Service”).

1. Controller and Processor Roles

The Service is used by regulated law firms. In most cases the law firm that operates its workspace is the data controller for personal data relating to its own clients and matters, and IFTI acts as a data processor on that firm's behalf under a Data Processing Agreement.

For personal data relating to firm users themselves (the solicitors and staff who log in and administer accounts), and for platform operation, security, and billing, IFTI acts as a data controller.

The platform is operated by IFTI AI Ltd, a company registered in England & Wales. The law firm delivering legal services to you through the platform is the controller of your client and matter data. Our data protection contact is privacy@ifti.ai.

2. Data We Collect

Depending on how the Service is used, we collect and process the following categories of personal data:

  • Account data: name, email address, firm name, SRA number, role, and authentication identifiers.
  • Client personal data: names, contact details, and case/matter information entered or uploaded by the firm about its clients.
  • Messages and communications: the content and metadata of messages sent and received through the platform, including messages exchanged over the WhatsApp Business Platform, SMS, and email.
  • Identity & compliance data (KYC/AML): identity documents, proof-of-address documents, verification results, and related records used for Know Your Client and Anti-Money-Laundering checks.
  • Audio, notes & intake content: AI-assisted intake responses, call/voice notes, transcripts, and file attachments provided by clients or staff.
  • Usage & diagnostic data: log files, IP address, device/browser type, pages accessed, and error/diagnostic events used to operate and secure the Service.
  • Billing data: subscription and invoice records. Payment card details are handled by our payment processor (Stripe) and are not stored by us.

3. How We Use Personal Data

  • Providing, operating, and maintaining the Service under the firm's subscription.
  • Automating client intake and generating AI-assisted drafts, summaries, and notes for review by a qualified professional.
  • Carrying out KYC/AML identity verification and compliance checks on behalf of the firm.
  • Sending and receiving client communications (including via WhatsApp, SMS, and email) on behalf of the firm.
  • Authenticating users, maintaining security, preventing fraud, and keeping audit logs.
  • Sending transactional messages (e.g. invoices, system alerts, password resets).
  • Improving the Service through aggregated and anonymised usage analytics.
  • Complying with legal, regulatory, and professional obligations.

4. Lawful Bases (UK GDPR)

We rely on one or more of the following lawful bases under the UK GDPR:

  • Contract: processing necessary to provide the Service under the subscription agreement.
  • Legal obligation: compliance with AML regulations, record-keeping, and other statutory duties.
  • Legitimate interests: securing the platform, preventing fraud, and improving the Service (balanced against individuals' rights).
  • Consent: where required, for example certain messaging channels or optional marketing (which can be withdrawn at any time).

Where the firm is the controller, the firm is responsible for establishing the lawful basis for processing its clients' personal data. Special category data (such as certain identity data) is processed only where an appropriate UK GDPR condition applies.

5. WhatsApp & Meta Data Handling

The Service can send and receive messages on behalf of the firm using the WhatsApp Business Platform operated by Meta Platforms, Inc. When a client messages the firm on WhatsApp, or the firm messages a client, that message content and the associated metadata (such as phone number and timestamps) are transmitted through and processed by Meta in order to deliver the message, in accordance with Meta's own terms and privacy policy.

We use these messages solely to enable communication between the firm and its clients through the platform — for example intake, updates, and compliance requests. We do not use WhatsApp message content for advertising, and we do not sell it. Message content is stored within the firm's workspace so the firm can maintain an accurate record of client communications. Clients can stop receiving WhatsApp messages at any time by telling the firm or by not replying; standard WhatsApp controls (such as blocking a business) also apply. Meta's processing of messages on its platform is governed by Meta's WhatsApp Business terms and privacy policy.

6. Sub-processors

We do not sell personal data. We share data only with trusted sub-processors that help us operate the Service, each bound by an appropriate data processing agreement:

  • Supabase — database, storage, and cloud infrastructure.
  • Clerk — user authentication and account management.
  • Anthropic (and other AI model providers) — AI-assisted intake, drafting, and analysis features.
  • Twilio — SMS and messaging delivery.
  • Meta Platforms — WhatsApp Business messaging.
  • Stripe — subscription billing and payment processing.
  • Resend — transactional email delivery.

This list may be updated as the Service evolves. A current sub-processor list can be requested from privacy@ifti.ai.

7. International Transfers

Some sub-processors operate outside the UK or EEA. Where personal data is transferred internationally, we rely on appropriate safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, as applicable.

8. Data Retention

We retain account and matter data for the duration of the firm's subscription and for a limited period afterwards to allow data export and to meet legal obligations. Compliance and audit records (including AML records) may be retained for the periods required by law — typically several years. Where no legal retention obligation applies, data can be deleted earlier on request. See our Data Deletion Instructions for how to request deletion.

9. Security

We implement appropriate technical and organisational measures, including encryption in transit and at rest, role-based access controls, row-level security, audit logging, and regular reviews. No method of transmission or storage is entirely secure, and we cannot guarantee absolute security, but we take reasonable steps to protect personal data.

10. Your Rights

Under UK GDPR, individuals have the right to:

  • Access the personal data held about them.
  • Rectify inaccurate or incomplete data.
  • Erase personal data (“right to be forgotten”) where legally permitted.
  • Restrict or object to processing.
  • Data portability — receive data in a machine-readable format.
  • Withdraw consent at any time where processing relies on consent.

Because the firm is usually the controller of client data, requests about a client's matter are normally directed to the firm, and IFTI will assist the firm in fulfilling them. To exercise any right, contact privacy@ifti.ai. You may also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email or in-app notice. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

For privacy queries, contact our data protection team at privacy@ifti.ai.