Effective Date: September 12, 2026
Last Updated: September 12, 2026
This Privacy Policy is designed to give you maximum transparency and control over your personal data. It exceeds the baseline requirements of most privacy laws worldwide, including the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), Brazil's LGPD, Canada's PIPEDA, Singapore's PDPA, and other applicable data protection frameworks.
1. Who We Are
"MARV," "we," "us," or "our" refers to the MARV holding company and its regional operating entities (each a "MARV Entity"), which together provide the MARV legal artificial intelligence platform and related services (the "Services"). Depending on your location, the MARV Entity responsible for processing your personal data as controller may differ, in accordance with our regional data-residency architecture described in Section 9. Contact details for the relevant controller are available on request via the contact methods in Section 15.
This Policy applies to all users of our website, applications, APIs, and Services (collectively, the "Platform"), including visitors, registered users, legal professionals, enterprise clients, and any individuals whose data is processed through the Platform.
2. Our Privacy Principles
We commit to the following principles, which govern every decision we make about your data:
Data minimization — we collect only what is strictly necessary to provide the Services.
Purpose limitation — we use your data only for the purposes disclosed to you, never for undisclosed secondary purposes.
No sale of personal data — we do not sell, rent, or trade your personal data to third parties, ever.
No advertising-based monetization — we do not use your personal data, documents, or communications to serve targeted advertising.
Encryption by default — your data is encrypted in transit and at rest at all times.
Data residency by design — data originating in a given jurisdiction is stored and processed within that jurisdiction or region wherever legally required or technically feasible.
Human oversight of AI — outputs from our AI systems that could affect your legal rights are subject to human review pathways and are never presented as a substitute for licensed legal advice.
Retention discipline — we retain personal data only as long as necessary and delete or anonymize it thereafter.
Radical transparency — we disclose, in plain language, what we collect, why, with whom we share it, and how you can control it.
3. Personal Data We Collect
We collect the categories of personal data described below. We collect data directly from you, automatically through your use of the Platform, and, in limited cases, from third parties.
3.1 Information You Provide Directly
Account and identity data: name, email address, phone number, business name, job title, professional credentials (e.g., bar admission number), and password (stored only as a salted cryptographic hash).
Verification and identity-assurance data: government-issued identification documents, biometric identifiers (e.g., facial geometry used for liveness/identity verification), and identity-verification results, collected only where required for account security, fraud prevention, regulatory compliance (including know-your-customer and anti-fraud obligations), or where you opt into identity-verified features.
Payment and billing data: billing address and payment method details, which are processed by PCI-DSS-compliant third-party payment processors; we do not store full payment card numbers.
Content you submit: documents, case materials, correspondence, queries, and other content you upload or input into the Platform ("Customer Content").
Communications data: messages, support tickets, survey responses, and feedback you send us.
Recordings and transcripts: audio, video, or transcript data generated during calls, consultations, or interactions you affirmatively consent to record, subject to applicable wiretap and recording-consent laws in your jurisdiction.
3.2 Information Collected Automatically
Device and technical data: IP address, browser type, operating system, device identifiers, and general (non-precise) location inferred from IP address.
Usage data: pages visited, features used, timestamps, session duration, click-path data, and error logs.
Cookies and similar technologies: as described in Section 8.
3.3 Information From Third Parties
Identity-verification providers, sanctions/watchlist screening providers, professional licensing databases, and, where you connect them, third-party integrations you authorize (e.g., calendar or document-storage tools), each disclosed at the point of connection.
3.4 Special and Sensitive Categories
Where we process special categories of data under GDPR (e.g., biometric data for identification purposes) or "sensitive personal information" under CPRA, we do so only with a valid legal basis — ordinarily your explicit consent or a legal obligation — and we apply heightened security and access controls described in Section 10.
3.5 Children
The Platform is not directed to individuals under 18, and we do not knowingly collect personal data from children. If we learn we have collected data from a child in violation of this Policy, we will delete it promptly. Parents or guardians who believe we have inadvertently collected a child's data should contact us via Section 15.
4. Why We Use Your Data (Purposes and Legal Bases)
PurposeExamplesGDPR Legal BasisProvide and operate the ServicesAccount creation, authentication, delivering AI-generated legal work productContract necessityIdentity and fraud verificationBiometric liveness checks, sanctions screening, KYCLegal obligation / ConsentSecurityDetecting and preventing fraud, abuse, and unauthorized accessLegitimate interest (documented balancing test on file)Customer supportResponding to inquiries and resolving issuesContract necessityLegal and regulatory complianceResponding to lawful requests, record-keeping obligations, UPL (unauthorized-practice-of-law) safeguardsLegal obligationService improvementAggregated, de-identified analytics on feature usageLegitimate interestCommunicationsService notices, security alerts, and — only with your opt-in — marketingContract necessity / Consent
We do not use Customer Content to train foundation models made available to other customers or the public, and we do not use Customer Content for any purpose beyond delivering the Services to you, unless you explicitly opt in to a clearly disclosed program and can withdraw at any time.
5. AI Processing and Automated Decision-Making
Because MARV provides AI-assisted legal work product, we apply the following additional safeguards, consistent with the EU AI Act and international best practice:
No solely automated decisions with legal effect. We do not subject you to decisions that produce legal effects or similarly significantly affect you based solely on automated processing without meaningful human involvement, and you may always request human review of an AI-assisted output that affects you.
No unauthorized practice of law. AI outputs are informational and do not constitute legal advice or replace review by a licensed attorney where required by law.
Model training boundaries. Your Customer Content is not used to train general-purpose or third-party AI models absent your explicit, revocable consent.
Explainability. On request, we will provide a general description of the logic, significance, and consequences of automated processing that materially affects you, to the extent legally required and technically feasible without compromising trade secrets or system security.
Bias and quality controls. We maintain testing and human-oversight processes intended to identify and mitigate discriminatory or materially inaccurate outputs.
6. Sharing and Disclosure of Personal Data
We disclose personal data only in the following limited circumstances, and never for advertising or data-broker purposes:
Service providers ("processors"): cloud hosting, identity verification, payment processing, customer support tooling, and analogous vendors, each bound by a data processing agreement requiring confidentiality, security, and use limited strictly to our instructions.
Professional advisors: our own auditors, insurers, and legal counsel, under confidentiality obligations.
Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality commitments and, where required by law, advance notice to you and continuity of this Policy's protections.
Legal and safety obligations: to comply with a valid legal process (subpoena, court order, regulatory demand), to protect the rights, property, or safety of MARV, our users, or the public, or to detect, prevent, or address fraud and security issues. We scrutinize every such request, disclose the minimum necessary, and — unless legally prohibited (e.g., under a gag order) — will notify you before disclosure.
With your direction: when you affirmatively direct us to share data with a named third party (e.g., co-counsel, opposing counsel, a court filing system).
We do not sell or share personal data for cross-context behavioral advertising, as those terms are defined under CPRA, and we do not have actual knowledge that we sell or share the personal data of minors under 16.
7. International Data Transfers and Residency
EU/EEA and UK data. Personal data originating in the EU/EEA or UK is stored, processed, and key-managed within the EU/EEA or UK by the applicable regional MARV Entity. Any transfer outside that region relies on an approved mechanism — Standard Contractual Clauses (2021 EU SCCs / UK IDTA), an adequacy decision, or binding corporate rules — together with a documented transfer impact assessment and supplementary technical measures (e.g., end-to-end encryption with region-local key custody) where required.
Other regions. Where data localization laws apply (e.g., certain requirements under China's PIPL or similar frameworks), we structure processing through in-region entities and infrastructure consistent with those requirements.
Sub-processor transparency. We maintain a current list of sub-processors and their processing locations, available on request, and we provide advance notice of any new sub-processor with a right to object.
8. Cookies and Tracking Technologies
Strictly necessary cookies (e.g., authentication, load balancing, security) are used without consent as permitted by law, since the Platform cannot function without them.
Functional, analytics, and (if applicable) marketing cookies are set only after you provide affirmative opt-in consent through our cookie preference center, except where a jurisdiction permits opt-out instead.
You can withdraw or modify consent at any time through the cookie preference center or your browser settings, and we honor recognized opt-out signals such as Global Privacy Control (GPC) as a valid CCPA/CPRA opt-out request.
We do not use third-party advertising cookies or pixels for cross-site tracking.
9. Data Security
We implement technical and organizational measures designed to meet or exceed industry standards, including:
Encryption in transit (TLS 1.2+) and at rest (AES-256 or stronger).
Role-based access controls and the principle of least privilege, with heightened controls (including additional authentication and logging) around biometric and identity-verification data.
Network segmentation, intrusion detection, and continuous security monitoring.
Regular independent security assessments and penetration testing.
Employee and contractor confidentiality obligations and security training.
A documented incident-response plan, including notification of affected individuals and regulators without undue delay, and in any event within 72 hours of becoming aware of a qualifying breach where required by GDPR, or within the timeframe required by applicable law.
No system is perfectly secure, and we cannot guarantee absolute security, but we continuously invest in improving our safeguards.
10. Data Retention and Deletion
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, satisfy legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements.
Account data is retained for the life of your account and deleted or anonymized within 90 days of account closure, absent a legal hold or retention obligation.
Identity-verification and biometric data is retained only as long as necessary for the verification purpose and any legally mandated retention period, and is deleted thereafter — biometric templates are, where technically feasible, deleted immediately after verification rather than retained.
Recordings and transcripts are retained per the retention schedule disclosed to you at the time of recording and deleted or anonymized once that purpose expires.
Backups containing residual personal data are purged on a rolling schedule consistent with our backup retention policy, not to exceed 12 months.
On verified deletion requests, we delete personal data within statutory timeframes (see Section 11), except where retention is required by law (e.g., financial recordkeeping) or necessary to establish, exercise, or defend legal claims.
11. Your Privacy Rights
Subject to applicable law and verification of your identity, you have the right to:
Access the personal data we hold about you and receive a copy in a portable format.
Rectify inaccurate or incomplete personal data.
Erase ("right to be forgotten") your personal data, subject to legal retention exceptions.
Restrict or object to processing, including processing based on legitimate interest, and to opt out of any automated decision-making with legal or similarly significant effects.
Data portability for data you provided to us, in a structured, commonly used, machine-readable format.
Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
Opt out of sale or sharing of personal data (we do not sell or share personal data, so this right is exercised by default) and limit use of sensitive personal information under CPRA.
Non-discrimination — we will not deny you the Services, charge different prices, or provide a different level of service because you exercised a privacy right.
Lodge a complaint with your local supervisory or data protection authority (e.g., an EU/EEA Data Protection Authority, the UK ICO, or your state Attorney General) at any time.
How to exercise your rights. Submit a request through the contact methods in Section 15. We will verify your identity using a proportionate method before acting on the request. We will acknowledge receipt promptly and respond within:
30 days (extendable by 60 days for complex requests) under GDPR/UK GDPR;
45 calendar days (extendable by 45 days) under CCPA/CPRA;
the applicable statutory timeframe under other regimes (e.g., 15 days under LGPD).
Authorized agents. You may designate an authorized agent to submit requests on your behalf, subject to verification.
12. Your Choices and Controls
Marketing communications: opt out at any time via the unsubscribe link in any marketing email or through your account settings.
Cookie preferences: manage via the cookie preference center described in Section 8.
Account and content controls: access, export, or delete Customer Content directly within the Platform where technically supported, or via a request under Section 11.
Notification preferences: manage non-essential notifications through account settings; security and legal notices cannot be disabled.
13. Third-Party Links and Integrations
The Platform may link to or integrate with third-party websites, tools, or services (e.g., calendar, document storage, or e-signature providers you choose to connect). This Policy does not apply to those third parties, and we encourage you to review their privacy policies before sharing data with them. We disclose material third-party integrations at the point you enable them and only share the data necessary for that integration to function.
14. Changes to This Policy
We may update this Policy to reflect changes in our practices, technology, legal requirements, or for other operational reasons. If we make material changes, we will provide advance notice — through the Platform, email, or another reasonable method — before the changes take effect, and, where required by law, we will obtain your renewed consent. The "Last Updated" date at the top of this Policy indicates when it was last revised. We encourage you to review this Policy periodically.
15. Contact Us
To exercise your privacy rights, ask a question about this Policy, or report a concern:
Privacy inquiries and data subject requests: privacy@marv.ai
Data Protection Officer / EU Representative (for GDPR-related inquiries): dpo@marv.ai
Security concerns or suspected breach reports: security@marv.ai
Postal address and the identity of the specific MARV Entity acting as controller for your region: available on request via the email addresses above.
You also have the right to lodge a complaint directly with your local data protection or privacy regulator at any time, without first contacting us, although we welcome the opportunity to address your concerns directly.