Skip to content

Security & data

Your company's legal record deserves a higher standard of care.

Legal documents contain the agreements, obligations and commercial history that make your company work. Kepta treats that data as customer property, publishes the terms behind its commitments and makes the relevant documents available before you sign.

Four commitments.

Short enough to read, specific enough to hold us to. Each one links to the document where it is written down.

Customer data is not training data

Kepta will not, and will not permit any sub-processor to, use Customer Data to train, fine-tune, evaluate or improve any AI model. Written into both the Terms of Service and the DPA.

Terms of ServiceDPA

Your data stays yours

All right, title and interest in Customer Data remains with you. On termination we return or delete it within 30 days, at your choice.

Terms of Service

Access is intentional

Access, sub-processors and operational responsibility are documented rather than implied. Every third party that touches Customer Data is listed publicly, with 30 days' notice before any change takes effect.

Sub-processors

The promise is contractual

Every commitment on this page is written into an agreement you can read before signature. No NDA needed to read the terms you would sign.

DPATerms of ServicePrivacy Policy

AI is a mechanism, not a blank cheque.

Kepta uses AI only within the data-handling and accountability commitments stated in its customer terms. The system may structure, compare, draft or route repeatable work. It does not eliminate the need for legal judgment, and it does not turn customer data into a training corpus.

The operational answers, as they stand today:

Where data is hosted

kepta.legal is self-hosted on Grasperly Sp. z o.o.'s own server. At launch the only processing outside the EEA is transactional email delivery via Resend (US).

See sub-processors

Which providers process data

The current sub-processor list is public, with entity, purpose and hosting region for each, and 30 days' notice before any change takes effect.

See sub-processors

Whether a model processes your data

At launch, no. Kepta is a marketing website with contact forms; no large language model processes your data. When the platform is engaged, its AI model providers will operate under contractual zero data retention: prompts and outputs processed in-flight and not retained beyond the time strictly necessary to return a response.

AI model providers

Retention

On termination, Customer Data is returned or deleted within 30 days, at your choice.

Read the DPA

Incident notification

Kepta notifies you of a personal-data breach without undue delay and in any case within 36 hours of becoming aware of it, by email to your designated privacy contact. Written into the DPA.

Read the DPA

Support access

At launch, the only data you share with Kepta arrives through the forms on this site and by email to contact@kepta.legal. It is handled under the Privacy Policy.

Read the Privacy Policy

A clear account of who does what.

Kepta makes the delivery path visible: what the system does, what a lawyer reviews and which matters require a different path.

Kepta is a technology-driven legal-services company, not a bar-regulated law firm; our platform does the work and our lawyers review and sign off. Software in front. Lawyers behind.

Read the documents before you need them.

Every document, published before signature. No NDA needed to read the terms you would sign.

Data Processing Agreement

GDPR Article 28-compliant DPA with a hardened no-training clause, 30-day sub-processor notice, and a 36-hour breach window.

Read the DPA

Privacy Policy

How we handle personal data of website visitors, prospects, candidates, and the contact persons at our customers. Customer Data handled under a service engagement is separately governed by the DPA.

Read the Privacy Policy

Sub-processors

The third parties that touch Customer Data: where they host it, what they do, and how to subscribe to changes, with 30 days' notice before any change takes effect.

See sub-processors

Terms of Service

Master terms for engaging Kepta: how services are ordered and delivered, customer-data ownership, no-training commitment, liability, and Polish law / Warsaw venue.

Read the Terms

Acceptable Use Policy

What you may and may not do with the platform, including AI-specific restrictions calibrated to the EU AI Act and Polish bar-association rules.

Read acceptable use

Imprint

The legal entity behind Kepta, its registration details, and how to reach it formally.

See company information

Found a vulnerability?

Email contact@kepta.legal. We accept reports in English and Polish. Good-faith research conducted within the scope described in our security.txt is welcome and will not be the basis for any legal action against the researcher.

Need a security review or a tailored setup?

Procurement questionnaires, DPA questions, a setup that needs different terms: write to us and a person answers.

Talk to Kepta