Security & data
Your company's legal record deserves a higher standard of care.
Legal documents contain the agreements, obligations and commercial history that make your company work. Kepta treats that data as customer property, publishes the terms behind its commitments and makes the relevant documents available before you sign.
Four commitments.
Short enough to read, specific enough to hold us to. Each one links to the document where it is written down.
Customer data is not training data
Kepta will not, and will not permit any sub-processor to, use Customer Data to train, fine-tune, evaluate or improve any AI model. Written into both the Terms of Service and the DPA.
Your data stays yours
All right, title and interest in Customer Data remains with you. On termination we return or delete it within 30 days, at your choice.
Access is intentional
Access, sub-processors and operational responsibility are documented rather than implied. Every third party that touches Customer Data is listed publicly, with 30 days' notice before any change takes effect.
The promise is contractual
Every commitment on this page is written into an agreement you can read before signature. No NDA needed to read the terms you would sign.
AI is a mechanism, not a blank cheque.
Kepta uses AI only within the data-handling and accountability commitments stated in its customer terms. The system may structure, compare, draft or route repeatable work. It does not eliminate the need for legal judgment, and it does not turn customer data into a training corpus.
The operational answers, as they stand today:
Where data is hosted
kepta.legal is self-hosted on Grasperly Sp. z o.o.'s own server. At launch the only processing outside the EEA is transactional email delivery via Resend (US).
Which providers process data
The current sub-processor list is public, with entity, purpose and hosting region for each, and 30 days' notice before any change takes effect.
Whether a model processes your data
At launch, no. Kepta is a marketing website with contact forms; no large language model processes your data. When the platform is engaged, its AI model providers will operate under contractual zero data retention: prompts and outputs processed in-flight and not retained beyond the time strictly necessary to return a response.
Retention
On termination, Customer Data is returned or deleted within 30 days, at your choice.
Incident notification
Kepta notifies you of a personal-data breach without undue delay and in any case within 36 hours of becoming aware of it, by email to your designated privacy contact. Written into the DPA.
Support access
At launch, the only data you share with Kepta arrives through the forms on this site and by email to contact@kepta.legal. It is handled under the Privacy Policy.
A clear account of who does what.
Kepta makes the delivery path visible: what the system does, what a lawyer reviews and which matters require a different path.
Kepta is a technology-driven legal-services company, not a bar-regulated law firm; our platform does the work and our lawyers review and sign off. Software in front. Lawyers behind.
Read the documents before you need them.
Every document, published before signature. No NDA needed to read the terms you would sign.
Data Processing Agreement
GDPR Article 28-compliant DPA with a hardened no-training clause, 30-day sub-processor notice, and a 36-hour breach window.
Privacy Policy
How we handle personal data of website visitors, prospects, candidates, and the contact persons at our customers. Customer Data handled under a service engagement is separately governed by the DPA.
Sub-processors
The third parties that touch Customer Data: where they host it, what they do, and how to subscribe to changes, with 30 days' notice before any change takes effect.
Terms of Service
Master terms for engaging Kepta: how services are ordered and delivered, customer-data ownership, no-training commitment, liability, and Polish law / Warsaw venue.
Acceptable Use Policy
What you may and may not do with the platform, including AI-specific restrictions calibrated to the EU AI Act and Polish bar-association rules.
Imprint
The legal entity behind Kepta, its registration details, and how to reach it formally.
Found a vulnerability?
Email contact@kepta.legal. We accept reports in English and Polish. Good-faith research conducted within the scope described in our security.txt is welcome and will not be the basis for any legal action against the researcher.
Need a security review or a tailored setup?
Procurement questionnaires, DPA questions, a setup that needs different terms: write to us and a person answers.