Data Protection & Security
How LitAgent PI UK handles personal data under UK GDPR and the Data Protection Act 2018 (England & Wales).
1. Complete data residency
All original documents, medical reports, claimant PII, case data, extractions and analysis outputs remain entirely within the firm's own deployment environment. No identifiable data ever leaves the firm's infrastructure — this is an architectural guarantee, not a configuration option.
| Data | Stored | Leaves the firm? |
|---|---|---|
| Original medical reports (PDFs) | Firm's own deployment | Never |
| Extracted text (PII-redacted) | Firm's own database | Never |
| Claimant names, NI number, DOB, addresses | Firm's own database | Never |
| Case data, analyses, comparators | Firm's own database | Never |
| AI request to Anthropic Claude | Anthropic API (US) | Anonymised — zero PII |
2. PII is stripped before any AI processing
The only external communication is to the Anthropic Claude API, which receives pseudonymised text after multiple layers of PII scrubbing. What reaches the AI contains no names, no National Insurance numbers, no dates of birth (converted to age), no addresses, no phone numbers, no UK postcodes and no NHS numbers. Medical facts and legal parameters are transmitted without direct identifiers. Anthropic does not use API data for model training and retains it for a maximum of 30 days.
Example of what the AI receives: "The claimant sustained a Grade II whiplash injury with an 18-month recovery period. MRI confirmed C5/C6 disc protrusion. Age at incident: 42."
Case data held on LitAgent servers is archived after 12 months of inactivity and fully anonymised after 24 months — at which point analysis outputs, medical facts, and all case content are permanently scrubbed.
3. Our role under UK GDPR
LitAgent PI UK operates as a data processor under UK GDPR Article 28. The instructing law firm is the data controller. Processing is carried out only on the controller's documented instructions, governed by a written Data Processing Agreement.
4. Session & access security
- Authentication tokens in httpOnly cookies (invisible to JavaScript — XSS-resistant), SameSite + Secure flags.
- Role-based access control — firm-scoped isolation; aggregate views restricted to management roles.
- 15-minute inactivity timeout, server-side session revocation, and an administrator kill-switch for instant incident response.
- Immutable audit trail — every AI operation records model, prompt version (hashed), token count and guideline version for full reproducibility.
5. Registration & jurisdiction
- Regime: UK GDPR + Data Protection Act 2018; jurisdiction England & Wales (SRA-regulated firms).
- ICO registration: pending (to be completed before processing live client data).
- Sub-processor: Anthropic (AI) — receives pseudonymised text only (direct identifiers removed; no training on API data).
This statement summarises the platform's data-protection architecture for prospective firms and underwriters. It is not legal advice. © LitAgent PI UK.