Privacy Policy
Last updated: 17 August 2026
This policy explains what personal data Juris Cross collects, why, and the choices you have.
1. Who is responsible
Juris Cross is the controller of personal data processed through the platform. If you have any questions, contact us.
2. Data we collect
- Account & profile: name, email, date of birth, phone number, jurisdiction, bar/registration details, practice areas, and the profile photo you provide.
- Usage: mandates you post or apply to, messages metadata, and basic logs needed to run and secure the service.
- Billing: subscription status and limited payment metadata processed by our payment provider (we do not store full card details).
- Verification: if you verify your identity (L1), the check is carried out by our verification provider and we keep only the outcome, a reference and the date — not your identity documents. If you verify your bar registration (L2), we keep the bar records you submit so an administrator can review them.
3. How we use it
- to operate the network — registration, mandate matching by jurisdiction and practice area, and identity masking until a mandate is active;
- to authenticate you (one-time sign-in codes) and keep the platform secure;
- to confirm your identity and check a stated seniority when member verification opens — your date of birth is held for that purpose and is never shown to other members;
- to provide subscriptions and send service notifications; and
- to meet legal and professional-conduct obligations.
4. Sharing
We do not sell personal data. Identifying details of attorneys and firms are masked to other members until a mandate becomes active. We share data only with service providers who help us run the platform (e.g. hosting, email, payments) under appropriate safeguards, or where required by law.
5. Encrypted communications
Mandate messages are encrypted and accessible only to the parties to that mandate. Administrative access is restricted, logged, and used only where legally required.
6. International transfers
Because the network is cross-border, data may be processed in countries other than your own. Where this happens we use appropriate safeguards consistent with applicable law, including the GDPR and KVKK.
7. Retention
Account data — your profile, jurisdiction and practice areas — is kept for as long as your account is active, and afterwards only as long as legal, accounting and professional-conduct obligations require, then deleted or anonymised.
Mandate workspaces have a fixed lifespan. When a mandate is posted, the originator chooses a retention period of one month or one year, measured from the date the mandate closes (completed, cancelled or expired). The applying lawyer sees this period before applying, and it cannot be changed once the mandate is live.
When that period ends:
- the encrypted conversation and every uploaded document are permanently deletedfrom our database and file storage;
- a record of the mandate itself — who the parties were, what was uploaded, approved or declined, and when — is retained without the document contents, so either party can evidence what happened if a dispute arises later; and
- both parties are emailed 30 and 7 days beforehand so nothing needed is lost. You can download your files and export your data at any point before deletion.
8. Documents and third-party data
Documents you upload frequently contain other people's personal data — usually your client's. Before each upload you confirm that you are authorised to share that document and that consent or another lawful basis covers the disclosure. That confirmation is recorded with a timestamp and is visible to the other party to the mandate.
For material you upload, you remain the controller of your client's data and we act as your processor: we store and transmit it on your instruction, we do not use it for any other purpose, and we do not disclose it to anyone outside the mandate except where the law requires. Professional privilege and confidentiality duties remain yours — please share only what the receiving lawyer needs, and redact the rest.
Administrative access to encrypted conversations is restricted to a narrow set of staff, is only used where legally required, requires a stated reason, and is logged with an alert to the platform owner on every access.
On request we will tell you what we hold about you and provide a copy, including the retention period and closing date of each mandate you were a party to.
9. Your rights
Subject to applicable law, you may request access, correction, deletion, or portability of your data, and may object to or restrict certain processing. To exercise these rights, contact us.
10. Cookies
We use a small number of cookies to keep you signed in and to understand usage. See our Cookie Policy for details.
11. Changes
We may update this policy and will notify material changes through the platform or by email.