LitAgent PI UK← Home

Data Protection & Security

How LitAgent PI UK handles personal data under UK GDPR and the Data Protection Act 2018 (England & Wales).

1. Where your data is held

Your firm's data — original documents, medical reports, claimant details, extracted text, analyses and reports — is held on a dedicated LitAgent server in the European Union (Hetzner, Helsinki, Finland; ISO 27001-certified data centre). Transfers from the UK to the EU are covered by the UK's adequacy regulations. Each firm's data is isolated from every other firm's by design; no user can see another firm's cases.

Encrypted backups are taken nightly and stored off-site within the EU (Hetzner Storage Box), encrypted before they leave the server, and restore-tested quarterly (last drill: 18 August 2026).

DataWhere it is storedLeaves LitAgent's EU server?
Original documents (PDFs, images)Your firm's isolated area of the LitAgent EU serverOnly as encrypted backups (EU)
Extracted text (pseudonymised) and the name key that reverses itYour firm's isolated area of the LitAgent EU serverOnly as encrypted backups (EU)
Claimant names, NI numbers, dates of birth, addressesYour firm's isolated area of the LitAgent EU serverNever
Case data, analyses, comparators, settlement reportsYour firm's isolated area of the LitAgent EU serverOnly as encrypted backups (EU)
The text sent to the AI modelAnthropic (processing routed across Anthropic's regions; stored in the US for up to 30 days)Pseudonymised text only — no real names or direct identifiers

2. What leaves the server, and what does not

Three things leave the server, and nothing else:

  1. Pseudonymised text to the AI model (Anthropic Claude). Before any text is sent, people's names — claimant, medical experts, witnesses, police officers, lawyers — are replaced with role-based stand-ins such as "Doctor 1", and National Insurance numbers, dates of birth (converted to age), addresses, postcodes, phone numbers and email addresses are removed. NHS numbers are also removed on clinical negligence files. The AI model never receives a real name. Real names are restored in your report from a key held only in your firm's area of the database; that key is never sent to the model. Anthropic does not use API data to train its models and retains API data for a maximum of 30 days.
  2. Encrypted backups to EU storage, as above.
  3. Monitoring alerts (service up/down, certificate expiry) sent by email to LitAgent. These contain no case data.

Pseudonymised data is still personal data under UK GDPR; we treat it as such. What reaches the AI is, for example:

"The claimant sustained a Grade II whiplash injury with an 18-month recovery period. MRI confirmed C5/C6 disc protrusion. Age at incident: 42."

3. Retention

Cases inactive for 12 months are archived. Cases inactive for 24 months are anonymised: the claimant's name, all document text and every analysis output are permanently removed, leaving only a non-identifying record that the case existed. This runs automatically every night. Your firm's administrator can also anonymise any case on request at any time.

4. Roles under UK GDPR

LitAgent PI UK acts as a data processor under UK GDPR Article 28. The instructing firm — a law firm or an insurer — is the data controller. Processing is carried out only on the controller's documented instructions, governed by a written Data Processing Agreement.

Sub-processors:

  • Anthropic (AI model) — receives pseudonymised text only; no training on API data; retention as stated above.
  • Hetzner Online GmbH (hosting and encrypted backup storage, EU; ISO 27001).

No other third party receives personal data.

5. Security controls

  • Authentication tokens in httpOnly cookies (invisible to page scripts), with SameSite and Secure flags; all traffic over TLS.
  • Role-based, firm-scoped access; aggregate views restricted to management roles.
  • 15-minute access-token life with server-side revocation, and an administrator kill-switch for instant incident response.
  • Account lockout after repeated failed logins; password change enforced on first login.
  • Append-only audit trail — every AI operation records the model, a hash of the prompt version, the token count and the guideline edition, so every figure can be traced to what produced it.
  • Nightly automated scan of application logs for personal data; nightly backup; daily automated health and drift checks.

6. Registration & jurisdiction

  • Regime: UK GDPR and the Data Protection Act 2018; jurisdiction England & Wales.
  • ICO registration: pending — to be completed before any live client data is processed.

This statement summarises the platform's data-protection architecture for prospective firms, insurers and underwriters. It is not legal advice. © LitAgent PI UK.