Skip to content

Trust center

Kept also means: your data.

How Kepta handles the documents you trust it with, and the contracts that back every commitment. Published in full, readable before you sign anything. Software in front, lawyers behind: our platform does the work and one of our lawyers reviews and signs off on every deliverable; every data promise is written into a contract you can read on this site.

Kepta is a technology-driven legal-services company, not a bar-regulated law firm; our platform does the work and our lawyers review and sign off; regulated activities are performed by qualified adwokaci and radcowie prawni.

What we put in writing

Self-hosted, not in a third-party cloud.

kepta.legal is self-hosted on Grasperly's own server. At launch the only processing outside the EEA is transactional email delivery via Resend (US); the current sub-processors and their transfer basis are listed on our sub-processors page.

Never used to train AI models.

Kepta will not, and will not permit any sub-processor to, use Customer Data to train, fine-tune, evaluate, or improve any AI model. Written into both the Terms of Service and the DPA.

No AI touches your data at launch.

At launch, Kepta is a marketing website with contact forms; no large language model processes your data. When the platform is engaged, its AI model providers will operate under contractual zero data retention: prompts and outputs processed in-flight and not retained beyond the time strictly necessary to return a response.

Your data stays yours.

All right, title, and interest in Customer Data remains with you. On termination we return or delete it within 30 days, at your choice.

The contracts behind it

Every document, published before signature. No NDA needed to read the terms you would sign.

Data Processing Agreement

GDPR Article 28-compliant DPA with a hardened no-training clause, 30-day sub-processor notice, and a 36-hour breach window.

Read the DPA

Sub-processors

The third parties that touch Customer Data: where they host it, what they do, and how to subscribe to changes, with 30 days' notice before any change takes effect.

See sub-processors

Privacy Policy

How we handle personal data of website visitors, prospects, candidates, and the contact persons at our customers. Customer Data handled under a service engagement is separately governed by the DPA.

Read the privacy policy

Terms of Service

Master terms for engaging Kepta: how services are ordered and delivered, customer-data ownership, no-training commitment, liability, and Polish law / Warsaw venue.

Read the terms

Acceptable Use Policy

What you may and may not do with the platform, including AI-specific restrictions calibrated to the EU AI Act and Polish bar-association rules.

Read the AUP

Imprint

The legal entity behind Kepta, its registration details, and how to reach it formally.

See the imprint

Found a vulnerability?

Email contact@kepta.legal. We accept reports in English and Polish. Good-faith research conducted within the scope described in our security.txt is welcome and will not be the basis for any legal action against the researcher.