Legal

Privacy Policy

Effective Date: January 1, 2026 · Last Updated: January 1, 2026

Lextiff ("Lextiff," "we," "our," or "us") is a cloud-based legal practice management platform developed and operated by Canvas Chrome Designs.

This Privacy Policy explains how we collect, use, disclose, protect, retain, and otherwise process personal information when you access or use:

  • the Lextiff website;
  • the Lextiff web application;
  • mobile applications;
  • customer support services;
  • integrations;
  • APIs;
  • communications with us.

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.

1. Scope

This Privacy Policy applies to:

  • visitors to www.lextiff.com;
  • registered users;
  • attorneys;
  • paralegals;
  • law firms;
  • administrative staff;
  • firm owners;
  • prospective customers;
  • individuals contacting our support team.

This Privacy Policy does not apply to third-party services that integrate with Lextiff.

Those providers maintain their own privacy policies.

2. Definitions

For purposes of this Privacy Policy:

Personal Information means information that identifies, relates to, describes, or can reasonably be associated with an individual.

Customer means the law firm or organization subscribing to Lextiff.

Customer Data means all information uploaded by Customers into the Services.

Protected Health Information (PHI) has the meaning assigned under HIPAA where applicable.

Processing means collecting, storing, organizing, transmitting, analyzing, modifying, deleting, or otherwise handling information.

3. Information We Collect

Depending upon how you interact with Lextiff, we may collect the following categories of information.

A. Account Information

  • Name
  • Email address
  • Phone number
  • Password (encrypted)
  • Organization name
  • Job title
  • Office address
  • User role
  • Subscription information

B. Authentication Information

When you sign in, we may collect:

  • login timestamps
  • authentication logs
  • IP address
  • browser type
  • operating system
  • session identifiers
  • device identifiers
  • multi-factor authentication events

C. Customer Data

Our Customers may upload information including:

  • client names
  • contact information
  • legal documents
  • pleadings
  • medical records
  • photographs
  • contracts
  • invoices
  • settlement information
  • trust accounting information
  • notes
  • uploaded files
  • communications
  • calendar events
  • tasks
  • case histories

Customer Data belongs to the Customer.

D. Payment Information

Subscription payments are processed through authorized third-party payment processors.

Lextiff does not store complete payment card information.

Depending upon your payment method, we may receive:

  • billing status
  • invoice history
  • payment confirmations
  • subscription status
  • limited billing information

E. Usage Information

We may automatically collect:

  • browser type
  • operating system
  • device type
  • screen resolution
  • language settings
  • pages visited
  • feature usage
  • clicks
  • session duration
  • referral URLs
  • crash reports
  • performance metrics

F. Cookies and Similar Technologies

Lextiff uses cookies and similar technologies to:

  • authenticate users;
  • maintain sessions;
  • remember preferences;
  • improve performance;
  • analyze usage;
  • enhance security.

Cookies may be essential for the proper operation of the Services.

4. How We Use Information

We use information to:

  • provide the Services;
  • authenticate users;
  • create Accounts;
  • process subscriptions;
  • provide customer support;
  • maintain security;
  • detect fraud;
  • improve performance;
  • develop new features;
  • monitor system health;
  • comply with legal obligations;
  • respond to support requests;
  • communicate product updates;
  • send security notifications;
  • administer the Services.

We do not sell Customer Data.

We do not use Customer Data for advertising.

We do not use Customer Data to build marketing profiles.

5. Legal Bases for Processing

Where required by applicable law, we process personal information on one or more of the following legal bases:

  • performance of a contract;
  • compliance with legal obligations;
  • legitimate business interests;
  • protection of vital interests;
  • consent, where required by law.

6. Customer Data Ownership

Customer Data remains the property of the Customer.

Lextiff does not claim ownership of Customer Data.

We process Customer Data solely for the purpose of operating and supporting the Services in accordance with our agreements with the Customer.

7. How We Share Information

Lextiff does not sell Personal Information or Customer Data.

We do not rent, trade, or otherwise disclose Customer Data for advertising or marketing purposes. We may disclose information only in the following circumstances:

A. Service Providers

We may share information with carefully selected third-party service providers that perform services on our behalf, including:

  • cloud infrastructure providers;
  • data hosting providers;
  • email delivery providers;
  • SMS and communication providers;
  • payment processors;
  • authentication providers;
  • monitoring and logging providers;
  • customer support platforms;
  • analytics providers.

These providers may access Personal Information only to the extent reasonably necessary to perform services for Lextiff and are contractually required, where applicable, to protect the information they process.

B. Legal Requirements

We may disclose information where we reasonably believe disclosure is necessary to:

  • comply with applicable law;
  • comply with court orders or subpoenas;
  • respond to lawful governmental requests;
  • enforce our Terms of Service;
  • investigate fraud or security incidents;
  • protect the rights, safety, or property of Lextiff, our Customers, or others.

Where legally permitted, we may notify the affected Customer before disclosing Customer Data.

C. Business Transactions

If Lextiff or Canvas Chrome Designs is involved in a merger, acquisition, financing, corporate reorganization, or sale of assets, Personal Information and Customer Data may be transferred as part of that transaction, subject to appropriate confidentiality obligations and applicable law.

D. With Customer Direction

We may disclose Customer Data when expressly instructed or authorized by the Customer, including through integrations, exports, or user-initiated sharing.

8. Artificial Intelligence Features

Lextiff does not currently offer AI-assisted features. Should such features be introduced in the future, this section will govern their use, and Customers will be notified in accordance with Section 21 (Changes to This Privacy Policy).

9. Protected Health Information (HIPAA)

Some Customers may choose to use Lextiff to process information that constitutes Protected Health Information ("PHI") under HIPAA.

Lextiff is designed with security and privacy safeguards intended to support Customers' compliance efforts. However, Customer remains responsible for determining whether HIPAA applies to its use of the Services.

Where required by applicable law and agreed by the parties, Lextiff and the Customer may execute a separate Business Associate Agreement ("BAA").

Nothing in this Privacy Policy shall itself constitute a Business Associate Agreement.

Customer remains responsible for:

  • obtaining all required authorizations and consents;
  • ensuring lawful collection and disclosure of PHI;
  • complying with HIPAA and other applicable healthcare privacy laws.

10. Data Security

Protecting Customer information is a core component of the Services.

Lextiff implements commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Information and Customer Data from unauthorized access, disclosure, alteration, or destruction.

Depending on the Services used, these safeguards may include:

  • encrypted communications using TLS;
  • encryption of data at rest where applicable;
  • role-based access controls;
  • strong authentication mechanisms;
  • password hashing using industry-accepted algorithms;
  • audit logging;
  • infrastructure monitoring;
  • vulnerability management;
  • backup and disaster recovery procedures;
  • secure software development practices;
  • access controls for personnel with a legitimate business need.

Despite these measures, no system can guarantee absolute security. Customers should also implement appropriate safeguards within their own organizations, including strong passwords, multi-factor authentication where available, user access management, and endpoint security.

11. Data Retention

We retain Personal Information and Customer Data only for as long as reasonably necessary to:

  • provide the Services;
  • comply with legal obligations;
  • resolve disputes;
  • enforce agreements;
  • maintain security;
  • perform backup and disaster recovery functions.

Upon termination of a Customer's subscription, Customer Data will be retained for a limited period to allow export or retrieval, after which it may be permanently deleted from active systems in accordance with our data retention procedures.

Encrypted backup copies may persist for a limited period before being overwritten or securely deleted in accordance with operational backup schedules.

12. International Data Transfers

Lextiff may process or store Personal Information using infrastructure located in one or more jurisdictions. Where Personal Information is transferred across national borders, Lextiff will take reasonable measures designed to ensure that such transfers comply with applicable data protection laws and are protected through appropriate contractual, organizational, or technical safeguards where required.

13. Your Privacy Rights

Depending on your location and applicable law, you may have certain rights regarding your Personal Information, including the right to:

  • access the Personal Information we maintain about you;
  • request correction of inaccurate information;
  • request deletion of certain Personal Information;
  • request restriction of processing in certain circumstances;
  • object to certain processing activities where permitted by law;
  • request a copy of Personal Information in a portable format where applicable;
  • withdraw consent where processing is based on consent.

Requests may be submitted using the contact information provided at the end of this Privacy Policy.

We may request reasonable information to verify the identity and authority of the individual making the request before fulfilling it.

14. Cookies and Similar Technologies

Lextiff uses cookies, local storage, pixels, and similar technologies ("Cookies") to operate, secure, and improve the Services.

Cookies help us:

  • authenticate users;
  • maintain secure sessions;
  • remember preferences;
  • improve website functionality;
  • understand usage trends;
  • measure platform performance;
  • enhance security.

Some Cookies are essential for the operation of the Services and cannot be disabled without affecting functionality.

Where required by applicable law, we will obtain consent before placing non-essential Cookies on your device.

Additional information regarding our use of Cookies is available in our Cookie Policy.

15. Analytics

Lextiff may use analytics technologies to understand how visitors and Customers use the Services.

Analytics information may include:

  • pages viewed;
  • navigation paths;
  • browser information;
  • device information;
  • operating system;
  • session duration;
  • feature usage;
  • error reports;
  • performance metrics.

Analytics data helps us improve platform performance, reliability, security, and user experience.

Where practicable, analytics information is aggregated or de-identified.

16. Marketing Communications

We may send Customers communications relating to:

  • account administration;
  • billing;
  • security alerts;
  • product announcements;
  • maintenance notifications;
  • new features;
  • educational resources;
  • company news.

You may opt out of receiving promotional marketing communications at any time by following the unsubscribe instructions contained within such communications.

Certain operational, billing, legal, or security-related communications are necessary for the operation of the Services and cannot be opted out of while maintaining an active account.

17. Children's Privacy

The Services are intended solely for use by businesses and legal professionals.

Lextiff does not knowingly collect Personal Information directly from children under the age of thirteen (13), or any higher minimum age required by applicable law.

If we become aware that Personal Information has been collected directly from a child in violation of applicable law, we will take reasonable steps to delete such information.

18. California Privacy Rights

If you are a California resident, you may have certain rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), subject to applicable exemptions.

Depending on applicable law, these rights may include:

  • the right to know what Personal Information is collected;
  • the right to request deletion of certain Personal Information;
  • the right to request correction of inaccurate Personal Information;
  • the right to limit the use of certain sensitive Personal Information where applicable;
  • the right to receive equal service and pricing regardless of exercising privacy rights.

Lextiff does not sell Personal Information as that term is defined under the CCPA.

Lextiff does not knowingly share Personal Information for cross-context behavioral advertising.

California residents may exercise applicable rights by contacting us using the information provided below.

19. European Economic Area (EEA), United Kingdom, and Switzerland

Individuals located within the European Economic Area (EEA), the United Kingdom, or Switzerland may have additional rights under applicable data protection laws, including the General Data Protection Regulation (GDPR) and the UK GDPR.

Where applicable, such rights may include:

  • access;
  • correction;
  • deletion;
  • restriction of processing;
  • objection to processing;
  • data portability;
  • withdrawal of consent where consent is the legal basis for processing.

Individuals also have the right to lodge a complaint with their applicable supervisory authority.

20. Do Not Track

Some web browsers include a "Do Not Track" ("DNT") feature.

Because there is currently no universally accepted standard governing DNT signals, Lextiff does not currently respond differently to browser-based DNT requests. If an industry standard for responding to DNT signals becomes established and legally required, we may revise our practices accordingly.

21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes in applicable law;
  • new platform features;
  • changes in business operations;
  • security improvements;
  • technology developments.

When material changes are made, we will provide notice through one or more of the following methods:

  • email;
  • in-application notification;
  • publication on the Lextiff website.

The "Last Updated" date at the beginning of this Privacy Policy will also be revised.

Continued use of the Services following the effective date of the revised Privacy Policy constitutes acknowledgment of the updated Privacy Policy.

22. Contact Us

Questions, requests, or concerns regarding this Privacy Policy or our privacy practices may be directed to:

Privacy Team

Lextiff

Email: privacy@lextiff.com

Website: https://www.lextiff.com

If you are submitting a request relating to your privacy rights, please include sufficient information to allow us to verify your identity and process your request.

23. Operated by Canvas Chrome Designs

Lextiff is developed, owned, and operated by Canvas Chrome Designs, a technology company specializing in secure cloud software, workflow automation, and digital solutions for modern businesses.

Canvas Chrome Designs is committed to maintaining appropriate administrative, technical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of Personal Information and Customer Data processed through the Services.

Privacy inquiries: privacy@lextiff.com

Support: support@lextiff.com