← Back to yourloya.com
Loya.
Privacy Policy
Loya Legal Inc.  |  yourloya.com  |  app.yourloya.com
Effective date: June 1, 2026  |  Last updated: July 1, 2026

This Privacy Policy explains how Loya Legal Inc., a Delaware corporation located at 16137 Green Tree Blvd, Ste 10 PMB 1034, Victorville, CA 92395, United States (“Loya”, “we”, “us”), collects, uses, discloses and protects personal information when you visit yourloya.com, use the Loya application at app.yourloya.com, contact us, or receive business communications from us (together, the “Service”).

In short: We collect the minimum we need to run an AI contract-review service — your account details, the documents you choose to upload, billing data handled by Stripe, and basic usage logs. Documents are processed by our AI provider under contracts that prohibit training on your content. We do not sell personal information. We separately collect publicly available business contact information for B2B marketing, and you can opt out at any time (Section 3).

1. Who is responsible for your data

Loya Legal Inc. is the controller of personal information described in this Policy (and a “business” under California law). For personal information contained in documents you upload, we act as a processor / service provider on your behalf: you decide what to upload and why, and we process it only on your instructions and as described here.

Contact for privacy matters: info@yourloya.com.

2. Information we collect from you

CategoryExamplesSource
Account dataEmail address, name, company name, role, password or one-time login codes, account settings, language.You, at registration
Customer ContentContracts and other documents you upload, their text and metadata, your comments and instructions, and the AI analysis generated from them. These documents may contain personal information about you, your staff or your counterparties.You, when using the Service
Billing dataPlan, subscription status, billing email, invoices, last four digits and brand of the payment card, billing country. Full card numbers are collected and stored by Stripe, not by us.You / Stripe
Usage and device dataIP address, browser and device type, operating system, pages viewed, features used, timestamps, referring URL, error and security logs.Automatically
CommunicationsMessages you send to support or sales, feedback, survey responses, and records of emails we send you (including delivery and open status).You / our email provider
Cookies and similar technologiesSession and authentication cookies, security cookies, and limited analytics identifiers.Automatically

We do not intentionally collect special categories of data (such as health, biometric or political data) and we ask you not to upload them. We do not knowingly collect personal information from children under 18.

3. Business contact information collected from public sources

To market Loya to other businesses, we also collect a limited set of publicly available business information about companies and their professional representatives — for example: company name, industry, size and location, company website, publicly listed business email addresses and phone numbers, and publicly listed job titles of business contacts. We collect this information from public web pages, public business directories, public company registries and similar public sources, in some cases with the help of third-party data-collection providers (for example, Bright Data Ltd.), and we combine it into a prospect list.

We use this information only to identify businesses that may benefit from Loya and to send them B2B communications about our product. We do not use it for automated decision-making with legal effects, we do not collect data from areas requiring a login, and we do not knowingly collect information about private individuals acting outside a professional capacity.

Legal basis and your choices. Where the GDPR applies, our legal basis is our legitimate interest in promoting a business product to other businesses (Art. 6(1)(f)); where required, we rely on consent instead. Every marketing email contains a one-click unsubscribe link, in line with the CAN-SPAM Act and comparable laws. You may also object to this processing or ask us to delete your details at any time by writing to info@yourloya.com, and we will remove you from our prospect list and add your address to a suppression list so you are not contacted again.

4. How we use information

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Service and billing you); legitimate interests (security, service improvement, B2B marketing); consent (optional cookies and, where required, marketing); and legal obligation (tax and compliance records).

5. AI processing of your documents

When you request an analysis, the relevant text of your document, together with our instructions to the model, is transmitted over an encrypted connection to our AI provider’s API — currently OpenAI, L.L.C. (United States) — which returns the analysis to us. We contract on enterprise/API terms under which:

Automated analysis does not produce legal effects or similarly significant decisions about individuals: it is a drafting and review aid, and the human user decides what to do with it. See the Terms of Service for the limits of AI output.

6. Who we share information with

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose information only to the following categories of recipients:

RecipientPurposeLocation
OpenAI, L.L.C.AI analysis of document textUSA
Render Services, Inc.Application hosting and managed databaseUSA
Vercel Inc.Front-end hosting and content deliveryUSA
Cloudflare, Inc. (R2)Encrypted file storage and network securityUSA / global edge
Stripe, Inc.Payment processing, subscription billing, fraud preventionUSA
Resend / Amazon Web Services (SES)Transactional and marketing email deliveryUSA
Bright Data Ltd.Collection of publicly available business information for B2B marketing (Section 3)Israel / EU / USA
Professional advisersAccountants, auditors and lawyers, under confidentialityUSA

We may also disclose information: (a) to comply with law, a court order or a lawful government request; (b) to enforce our agreements or protect the rights, safety and property of Loya, our users or the public; and (c) in connection with a merger, acquisition, financing or sale of assets, in which case we will notify you and the acquirer will remain bound by this Policy for information already collected.

All subprocessors are bound by written agreements requiring appropriate confidentiality and security measures. A current list is available on request.

7. International transfers

We are based in the United States and our providers are primarily located in the United States. If you access the Service from the European Economic Area, the United Kingdom, Switzerland or another jurisdiction with data transfer restrictions, your information will be transferred to the United States. Where required, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) together with supplementary technical measures such as encryption in transit and at rest. You can request a copy of the relevant transfer mechanism at info@yourloya.com.

8. How long we keep information

DataRetention
Account dataFor the life of the account, then up to 12 months after closure (to handle disputes and reinstatement requests).
Uploaded documents and analysesUntil you delete them, or until 30 days after your account is closed, whichever comes first. Deleted items are removed from backups within a further 30 days.
Billing and tax recordsUp to 7 years, as required by U.S. tax and accounting rules.
Security and access logsUp to 12 months.
Marketing / prospect dataUntil you unsubscribe or object; suppression-list entries are kept indefinitely so we do not contact you again.

9. Security

We use industry-standard safeguards, including TLS encryption in transit, encryption at rest for stored files, access control on a need-to-know basis, one-time-code authentication, isolated production credentials, logging and monitoring, and vendor due diligence. No method of transmission or storage is completely secure; we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and the competent authorities where required by law and without undue delay.

10. Cookies

We use cookies and similar technologies that are strictly necessary to run the Service (session management, authentication, load balancing, security), plus a limited amount of analytics to understand aggregate traffic and diagnose problems. We do not use advertising or cross-site tracking cookies. You can block or delete cookies in your browser settings; strictly necessary cookies cannot be disabled without breaking core functionality. Where required by law, we ask for consent before setting non-essential cookies.

11. Your rights

11.1 If you are in the EEA, the UK or Switzerland

You have the right to access your personal data; to have it corrected or erased; to restrict or object to processing (including direct marketing, at any time); to data portability; and to withdraw consent where processing is based on consent, without affecting prior processing. You may also lodge a complaint with your local supervisory authority.

11.2 If you are a California resident

Under the CCPA/CPRA you have the right to know what personal information we collect, use and disclose; to access a copy of it; to request deletion; to request correction; and to be free from discrimination for exercising these rights. In the past 12 months we have collected the categories described in Sections 2 and 3 (identifiers, commercial information, internet activity, professional information and, within uploaded documents, categories chosen by the customer), for the purposes in Section 4, and disclosed them for business purposes to the recipients in Section 6. We have not sold or shared personal information for cross-context behavioral advertising, and we do not do so with respect to minors under 16. We do not use or disclose sensitive personal information beyond the purposes permitted by section 7027(m) of the CCPA regulations. Residents of other U.S. states with comprehensive privacy laws (for example Virginia, Colorado, Connecticut and Texas) have comparable rights, including the right to appeal a refusal.

11.3 How to exercise your rights

Write to info@yourloya.com from the email address associated with your request, or use the tools in your account. We will verify your identity (usually by confirming control of that email address) and respond within the period required by applicable law — generally 30 days under the GDPR and 45 days under the CCPA, with an extension where permitted. You may use an authorized agent where the law allows; we may ask for proof of authority. Exercising your rights is free unless a request is manifestly unfounded or excessive.

If you are an end user whose data appears inside a document uploaded by one of our customers, please direct your request to that customer; we will assist them as their processor.

12. Third-party links

Our websites may link to third-party sites and services that we do not control. This Policy does not apply to them, and we encourage you to read their privacy notices.

13. Changes to this Policy

We may update this Policy. The “Last updated” date at the top shows the current version. If changes are material, we will notify you by email or through the Service before they take effect. Continued use of the Service after that date means you accept the updated Policy.

14. Contact us

ControllerLoya Legal Inc., a Delaware corporation
Business address16137 Green Tree Blvd, Ste 10 PMB 1034, Victorville, CA 92395, United States
Privacy contactinfo@yourloya.com
Websiteshttps://yourloya.com  ·  https://app.yourloya.com