LEGAL
Privacy Policy
Last Updated: August 2026
1. Introduction
This Privacy Policy describes how Moritz Law, which does business as Moritz (“Moritz,” “we,” “us,” or “our”), handles personal information in connection with moritzlegal.com (the “Site”), our client platform at app.moritzlegal.com (the “Platform”), our intake and matter-submission forms, and related services (together, the “Services”). The Platform is operated for us by technology service providers engaged under written confidentiality and security obligations consistent with our professional responsibilities.
2. Relationship to Other Documents
Our Terms of Service govern use of the Services. If you have accepted an engagement agreement or engagement letter with Moritz (an “Engagement Agreement”), that agreement controls over this Policy with respect to your matters and the content of your representation.
3. Two Categories of Information
We process (a) “Site, Intake, and Platform Data”: information about visitors, prospective clients, and account users, which is governed by this Policy and applicable privacy laws; and (b) “Client Matter Content”: information provided in the course of a representation, which is governed by the rules of professional conduct, our duty of confidentiality, and the applicable Engagement Agreement. Where a privacy right conflicts with our professional-responsibility obligations, the latter controls.
4. Information We Collect
We collect:
Information you provide, such as name, email, company, billing and payment information, and the contents of forms, matters, and communications
Information collected automatically, such as IP address, device and browser data, cookies, and Platform usage telemetry
Information from third parties, such as conflict-check sources, public records, and co-counsel
Where a matter requires it, information that may be sensitive under applicable law
Sensitive information contained in client materials is handled as Client Matter Content.
5. How We Use Information
We use Site, Intake, and Platform Data to operate, secure, and improve the Services; to run conflicts checks and evaluate prospective engagements; to provide legal services and administer engagements; to process payments and billing; to communicate with you, including service and marketing messages (you may opt out of marketing at any time); to detect and prevent fraud and abuse; to comply with law, court orders, and professional obligations; and as described in Section 6.
6. Artificial Intelligence
We use artificial intelligence and machine-learning tools to operate, secure, and improve the Services and to assist in delivering legal services under attorney supervision. We may use Site, Intake, and Platform Data to develop, train, and improve these tools; if you are not a client, you may opt out of that use by emailing privacy@moritzlegal.com. Our use of Client Matter Content, including for AI development, is governed by the applicable Engagement Agreement.
We do not use AI tools to make decisions that produce legal or similarly significant effects about you without meaningful human review.
7. De-identified Information
We may create de-identified information from the information we hold, using measures designed so that it cannot reasonably be used to identify any individual, business, or matter. De-identified information is not personal information, and we may use, disclose, and license it for any lawful purpose, including research and the development, evaluation, and improvement of technology and professional tools.
We maintain and use de-identified information solely in de-identified form, we do not attempt to re-identify it except as permitted by law to test our de-identification processes, and we contractually require recipients of de-identified information to commit to the same.
8. How We Disclose Information
We disclose information to:
Service providers that host, operate, and support the Services under confidentiality and security obligations
Co-counsel and other professionals engaged on your matters
Counterparties, courts, and others as necessary to provide legal services on your instructions
Recipients of legal process, after asserting applicable privileges and protections where we properly may
Parties to a merger, acquisition, or sale of our practice, subject to professional-responsibility obligations
Others where necessary to protect rights and safety
Others with your direction or consent
We do not sell your personal information, as “sell” is defined in the California Consumer Privacy Act, and we do not “share” it for cross-context behavioral advertising.
9. International Transfers
We are located in the United States, and information we collect is processed there and in other jurisdictions where our providers and co-counsel operate. Where required, transfers from the EEA, the United Kingdom, or Switzerland are made under Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism.
10. Your Privacy Rights
Depending on where you reside, you may have rights to access, correct, delete, restrict, or receive a copy of your personal information, to object to certain processing, to withdraw consent, and to complain to a supervisory or other regulatory authority.
Where the EU or UK GDPR applies, we process personal information on the lawful bases of contract performance, legitimate interests, legal obligation, consent, and the establishment, exercise, or defense of legal claims.
California and other U.S. state residents may exercise the rights their statutes provide, including to know, access, correct, and delete personal information, without discrimination; because we do not sell or share personal information, no opt-out is required.
To exercise rights, email privacy@moritzlegal.com; we will verify your identity before acting.
These rights are limited where honoring them would conflict with our professional-responsibility obligations, including our duties of confidentiality and file retention owed to clients.
11. Retention
We retain Site and intake data for up to twenty-four (24) months, or longer where needed for security, conflicts checking, or legal claims, and then delete or de-identify it. Client files and trust-account records are retained as required by the rules of professional conduct and our retention policy, as described in the applicable Engagement Agreement.
12. Cookies
We use strictly necessary cookies for authentication, session management, and security, and analytics cookies to understand how the Services are used. Where law requires prior consent, non-essential cookies are not set until you consent through the cookie banner, and you may withdraw consent through Site preferences or your browser. We do not respond to “Do Not Track” signals.
13. Security
We maintain technical, administrative, and physical safeguards appropriate to the sensitivity of the information we handle, including encryption, access controls, audit logging, vendor diligence, and personnel training, and we support multi-factor authentication for Platform accounts. No system is completely secure. Where a breach notification is required by applicable law, we will provide it.
14. Children
The Services are intended for adults and business users. We do not knowingly collect personal information from anyone under 18 through the Site or our intake forms; if you believe we have, contact privacy@moritzlegal.com and we will delete it.
15. Third-Party Services
The Services may link to or rely on third-party websites and services governed by their own privacy notices. We are not responsible for their practices.
16. Changes to This Policy
We may update this Policy by posting a revised version with a new “Last Updated” date, with additional notice of material changes where required. Material changes affecting Client Matter Content will be communicated consistent with our professional responsibilities.
17. Contact
Moritz Law, 455 Market St, Ste 1940, PMB 320349, San Francisco, California 94105-2448
Privacy inquiries and rights requests: privacy@moritzlegal.com
General inquiries: legal@moritzlegal.com
EU representative: Euverify Ltd, Cork, Ireland; UK representative: Euverify Ltd, London, United Kingdom; both reachable at gdpr@euverify.com
