top of page

Data Security and Confidentiality

Legal work depends on trust. LexPhil treats every client document, communication, and project record as confidential and uses documented procedures to protect information throughout the engagement—from receipt and assignment to delivery, retention, and deletion.

Confidentiality by Default

Our lawyers, paralegals, and authorized personnel are bound by confidentiality obligations. Client information is used only for the assigned project and is not disclosed, copied, or retained for unrelated purposes.

We do not use client documents for advertising, demonstrations, portfolio samples, or personnel training without the client’s express permission.

Restricted Access

Access is limited to personnel assigned to the client or project on a need-to-know basis. Each authorized user must use an individually assigned company account protected by multi-factor authentication.

Being part of LexPhil does not automatically give a person access to every client matter. Permissions are reviewed when projects begin, when assignments change, and when personnel leave a project or the company.

Controlled Document Handling

Client files are maintained in approved, access-controlled systems. LexPhil preserves original documents, maintains organized working and reviewed versions, and releases only authorized deliverables through approved channels.

Client information may not be stored or transmitted through personal email, personal cloud storage, unapproved messaging applications, shared accounts, or unauthorized removable media. Local downloads and printed copies are minimized and must be securely deleted or destroyed when no longer required.

Protected Devices and Accounts

Personnel accessing client files must use authorized devices protected by strong authentication, device encryption, automatic screen locking, current security updates, and malware protection.

Account activity and file-sharing permissions may be reviewed to identify improper access, downloading, copying, deletion, or external sharing.

Responsible Use of Technology

Client materials are not submitted to public or unapproved artificial-intelligence systems. Any AI-assisted work must be permitted by the client, performed through an approved tool, and independently evaluated and verified by a qualified LexPhil lawyer.

Technology supports our work; it does not replace professional judgment, confidentiality, or human quality control.

Privacy and Data Minimization

LexPhil collects and processes only the information reasonably necessary to perform the engagement, administer the client relationship, comply with applicable requirements, and protect legitimate legal and business interests.

Clients may provide instructions concerning access, processing, storage, transfer, retention, deletion, and the use of particular systems. Where a client’s requirements are stricter than our standard procedures, the agreed client requirements will control.

Retention and Deletion

Client documents are retained only for the period required by the service agreement, client instructions, applicable law, or legitimate recordkeeping requirements.

At the end of the applicable period, documents are securely returned, archived, deleted, or destroyed in accordance with the agreed procedure. LexPhil does not retain client files indefinitely merely because electronic storage is available.

Responding to a Suspected Data Incident

LexPhil maintains a documented process for responding to suspected loss, misdirection, unauthorized access, disclosure, alteration, or deletion of client information.

When a credible incident is identified, LexPhil takes appropriate steps to:

  1. Contain the incident and prevent further access or disclosure;

  2. Secure affected accounts, devices, links, and files;

  3. Preserve relevant records and activity evidence;

  4. Determine the information and parties affected;

  5. Mitigate potential harm and restore secure operations;

  6. Document the incident and corrective actions; and

  7. Notify affected clients and authorities when required by contract or applicable law.

 

Personnel are required to report suspected incidents immediately and are prohibited from concealing or privately resolving them.

Our Commitment

No technology can eliminate every possible risk. LexPhil therefore relies on multiple safeguards: restricted access, secure accounts, protected devices, controlled file handling, confidentiality agreements, personnel training, documented oversight, and prompt incident response.

Our objective is simple: to handle every client document with the care, discipline, and confidentiality expected of a professional legal services organization.

Privacy Policy

LexPhil Legal Support Services (“LexPhil,” “we,” “our,” or “us”) respects your privacy and is committed to handling personal information responsibly, securely, and transparently.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit [website address], communicate with us, request information, or engage our legal support services.

1. Scope of This Policy

This Privacy Policy applies to:

  • Visitors to our website

  • Prospective and existing clients

  • Representatives and employees of client organizations

  • Attorneys, law firms, vendors, and professional partners

  • Individuals who communicate or otherwise interact with LexPhil

Client documents and personal information processed by LexPhil on behalf of a client may also be governed by a service agreement, confidentiality agreement, data-processing agreement, or the client’s written instructions. If those terms conflict with this Privacy Policy, the applicable agreement shall control with respect to that client information.

 

2. Who We Are

LexPhil provides legal documentation and support services through Philippine lawyers, trained paralegals, and other authorized personnel.

For personal information collected through our website and ordinary business activities, LexPhil generally acts as the personal information controller.

 

When we process personal information solely on behalf of a law firm, attorney, corporate legal department, or another client, LexPhil may act as a personal information processor or service provider and process the information according to the client’s documented instructions.

3. Personal Information We Collect

Depending on how you interact with us, we may collect the following categories of information.

 

Information You Provide

 

You may provide us with:

  • Your name, email address, telephone number, and mailing address

  • Your job title, law firm, company, or professional affiliation

  • Information submitted through contact, inquiry, or consultation forms

  • Communications, instructions, feedback, and correspondence

  • Billing, invoicing, and transaction information

  • Information necessary to evaluate or perform requested services

  • Documents and files submitted for review, drafting, research, or organization

  • Information required for conflict checks, client verification, and compliance

  • Any other information you voluntarily provide

 

Please do not submit confidential, privileged, or sensitive client information through a general website contact form. Contacting LexPhil or submitting an inquiry does not, by itself, establish an attorney-client relationship or service-provider relationship. Confidential materials should be transmitted only after appropriate engagement, confidentiality, conflict-checking, and security arrangements have been established.

 

Information Collected Automatically

 

When you use our website, we or our authorized service providers may automatically collect:

  • Internet Protocol address

  • Browser and device type

  • Operating system

  • Pages viewed and links selected

  • Referring website

  • Date, time, and duration of visits

  • General geographic location derived from technical information

  • Cookie identifiers and similar website-usage information

  • Information concerning website errors, security events, and performance

 

Information From Other Sources

We may receive information from:

  • Referrals and professional contacts

  • Client organizations and their authorized representatives

  • Publicly available professional or business sources

  • Payment, identity-verification, or fraud-prevention providers

  • Vendors and service providers supporting our operations

 

4. How We Use Personal Information

We may use personal information to:

  • Respond to inquiries and communicate with you

  • Evaluate prospective engagements and conduct conflict checks

  • Prepare proposals, quotations, and service agreements

  • Provide and manage requested legal support services

  • Process documents according to client instructions

  • Maintain client and business records

  • Administer subscriptions, Service Units, billing, and payments

  • Verify identity, authority, and professional affiliations

  • Protect confidential information and maintain security

  • Detect, investigate, and prevent fraud, misuse, or security incidents

  • Improve our website, services, procedures, and client experience

  • Send service-related notices and administrative communications

  • Send marketing communications where permitted by law

  • Comply with legal, regulatory, contractual, and professional obligations

  • Establish, exercise, or defend legal claims

  • Enforce our agreements and protect our rights

 

Where applicable, we process personal information based on consent, performance of a contract, compliance with legal obligations, protection of legitimate interests, or another lawful basis recognized by applicable law.

5. Client Documents and Legal Information

Documents handled by LexPhil may contain personal, sensitive, confidential, proprietary, or legally privileged information.

We process client materials only for the agreed service purpose and according to the applicable contract and client instructions. Access should be limited to personnel who require the information to perform, supervise, secure, or administer the assignment.

Clients remain responsible for determining whether they have the authority, consent, or other lawful basis necessary to disclose personal information to LexPhil. Clients are also responsible for satisfying any professional obligations concerning client consent, privilege, confidentiality, cross-border processing, and outsourced legal support.

6. Cookies and Similar Technologies

Our website may use cookies and similar technologies to:

  • Maintain website functionality

  • Remember user preferences

  • Understand website usage

  • Measure website performance

  • Detect security threats

  • Improve content and navigation

Where required, we will request consent before placing nonessential cookies. You may manage available cookie choices through our cookie banner or browser settings.

Disabling certain cookies may affect website functionality.

7. How We Disclose Personal Information

We may disclose personal information to:

  • LexPhil lawyers, paralegals, employees, and authorized personnel

  • Cloud hosting, storage, email, communications, and information-technology providers

  • Security, fraud-prevention, and professional advisers

 

Service providers may access personal information only to perform authorized functions and are expected to handle it consistently with their contractual and legal obligations.

LexPhil does not sell personal information for monetary consideration. LexPhil does not disclose personal information for cross-context behavioral advertising unless this practice is clearly disclosed and any legally required choice is provided.

8. International and Cross-Border Processing

LexPhil operates in the Philippines and may serve clients located in other countries. Personal information provided to us may therefore be transferred to or processed in the Philippines and in other locations where our authorized service providers operate.

 

Where required, we use contractual, organizational, and other appropriate measures intended to maintain a level of protection consistent with applicable law and the sensitivity of the information.

 

Clients transmitting personal information across national borders remain responsible for identifying any transfer restrictions or additional safeguards applicable to their matters.

9. Data Security

We use reasonable and appropriate organizational, physical, and technical measures intended to protect personal information against:

  • Unauthorized access or disclosure

  • Accidental or unlawful loss

  • Improper use or alteration

  • Destruction or damage

  • Other unauthorized processing

These measures may include access controls, confidentiality obligations, authentication procedures, secure communication methods, staff training, incident-response procedures, and vendor-management controls, as appropriate to the information and risks involved.

 

No method of transmission, storage, or security is completely risk-free. We cannot guarantee absolute security, but we will take reasonable steps to prevent and respond to security incidents.

10. Data Retention

We retain personal information only for as long as reasonably necessary to:

  • Fulfill the purpose for which it was collected

  • Perform our contractual obligations

  • Maintain business and professional records

  • Comply with legal, regulatory, accounting, and tax requirements

  • Resolve disputes and enforce agreements

  • Establish, exercise, or defend legal claims

  • Follow applicable client instructions

 

Retention periods may differ according to the information’s nature, sensitivity, purpose, contractual requirements, and applicable law.

When personal information is no longer required, we will take reasonable steps to delete, destroy, anonymize, or securely dispose of it.

11. Your Privacy Rights

Depending on your location and the applicable law, you may have the right to:

  • Be informed about the processing of your personal information

  • Request access to your personal information

  • Request correction of inaccurate or incomplete information

  • Object to or restrict certain processing

  • Request deletion, erasure, or blocking of information

  • Withdraw consent where processing is based on consent

  • Request a portable copy of certain information

  • Opt out of certain marketing communications

  • Lodge a complaint with an appropriate privacy authority

  • Exercise other rights provided by applicable law

These rights may be subject to legal limitations, professional obligations, privilege, record-retention requirements, and verification of your identity and authority.

To exercise a privacy right, contact us at [privacy email address]. Please describe your request and the information involved. We may request additional information reasonably necessary to verify your identity.

 

12. Marketing Communications

Where permitted, we may send information about LexPhil’s services, updates, or professional content.

You may unsubscribe from promotional emails by using the unsubscribe link in the message or contacting us at [email address]. Even after opting out of marketing, you may continue to receive necessary service, billing, security, or administrative communications.

 

13. Third-Party Websites

Our website may contain links to websites operated by third parties. LexPhil does not control and is not responsible for the privacy, security, content, or practices of third-party websites.

We encourage you to review the privacy policies of any third-party website you visit.

14. Children’s Privacy

Our website and services are intended for legal professionals, businesses, and adults. They are not directed to children under 18 years of age.

 

We do not knowingly collect personal information directly from children through the website. If we learn that information was collected from a child without appropriate authorization, we will take reasonable steps to delete it.

15. Automated Decision-Making

LexPhil does not use personal information collected through its website to make decisions producing legal or similarly significant effects based solely on automated processing.

If this practice changes, we will provide any notice and choices required by applicable law.

16. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our services, practices, technology, or legal obligations.

The revised policy will be posted on this page with an updated “Last Updated” date. Material changes may also be communicated through another appropriate method.

 

17. Contact Us

Questions, concerns, requests, or complaints concerning this Privacy Policy or our handling of personal information may be directed to:

LexPhil Legal Support Services
Legal Entity: Lexphil Outsourcing, Inc.
Email: info@lexphil.com

 

Individuals may also have the right to contact or lodge a complaint with the privacy or data-protection authority having jurisdiction over their personal information.

bottom of page