Privacy policy

Negotiated

Effective Date: 22 September 2026

Spurgin Law Offices LLC (“Spurgin,” “we,” “us” or “our”), an Arizona limited liability company provides Negotiated, a non-disclosure agreement review platform available at negotiated.spurginlawoffices.com (the “Service”). You may contact us about this policy, or to exercise any right described in it, at advait@spurginlawoffices.com.

This policy applies to the Service. It does not govern Spurgin’s legal practice generally, which is subject to our engagement letters and to the professional obligations of the jurisdictions in which we are admitted.

1. Personal information we collect, and where it comes from

1.1 Information collected when you sign in

Access to the Service is restricted to our own attorneys and staff, whose accounts we allowlist in advance. They sign in using Google Sign-In with their work email address. Google then provides us with the account holder’s name, email address and Google account identifier, and we match the account on Google’s permanent account identifier rather than on the email address. The sign-in flow requests identity information only; it does not grant us access to the contents of any Google account, and we do not receive or store any Google password.

The Service does not offer public registration, and no account can be created by the person who will use it.

1.2 Information from a connected mailbox

Where a Spurgin work mailbox is connected to the Service, and only after a separate authorisation distinct from sign-in, the Service reads that mailbox to identify incoming agreements and file their attachments to the matter they belong to. We read message metadata, message bodies and attachments for that purpose. The mailboxes concerned are Spurgin’s own work accounts. The authorisation is granted by us for those accounts and may be revoked at any time.

1.3 Documents and matter content

The Service processes the agreements and related materials uploaded to it or received into a connected mailbox, together with the markups and redlines it generates. These documents routinely contain personal information, including the names and contact details of signatories, advisers and named employees.

1.4 Usage records

We record the actions taken in the Service, together with timestamps and the account responsible, and we keep server logs containing IP address, browser type and request details.

1.5 Cookies

The only cookies the Service sets are strictly necessary: a session cookie that keeps you signed in, and short-lived cookies used to complete the sign-in exchange securely. The Service sets no third-party cookies and uses no analytics, advertising or tracking technologies.

1.6 Where the information comes from

We collect information directly from the account holder when they sign in, and automatically from their use of the Service. The personal information contained in documents is obtained from our clients, from counterparties and their advisers, and from the documents themselves. The categories concerned are names, business contact details and professional roles.

2. How we use personal information

We use personal information for the following purposes, and for no others:

  • to authenticate account holders and maintain their accounts;

  • to process the documents in a matter and generate the reviews, markups and redlines the Service produces;

  • to maintain and improve the Service, by monitoring performance, diagnosing faults and correcting errors;

  • to keep the Service secure, by detecting misuse, investigating incidents and maintaining audit records; and

  • to meet our professional and legal obligations, including the record-keeping required of a law firm, and to establish or defend legal claims.

3. Model development

The Service uses machine-learning models to classify issues in an agreement and to propose revisions. Those models are developed from Spurgin’s own corpus of historical work product.

Documents processed through the Service are not used to train or fine-tune our models. They are analysed in order to produce the review and the outputs you receive, and for no other purpose. The same applies to material obtained from a connected mailbox, which is excluded from the datasets used for model development.

Analysis and model development run on infrastructure we control. No third-party artificial intelligence provider receives your content, and the resulting models are used only to operate the Service.

4. Who we disclose personal information to

We do not sell personal information and we do not disclose it for advertising. We disclose it to the following categories of recipient:

  • identity and authentication providers, for the sign-in described in section 1.1 and the mailbox access described in section 1.2;

  • cloud infrastructure, compute and storage providers, who host the Service and the material processed through it;

  • operational monitoring providers, who receive system events and identifiers but not document content;

  • our clients and the advisers acting for them, in respect of the matters they are party to; and

  • courts, regulators, our professional advisers and our insurers, where we are required to disclose or where disclosure is necessary to establish or defend legal claims.

Each provider processes personal information on our instructions and under contractual confidentiality and security obligations. We will assert legal professional privilege and client confidentiality wherever they apply.

5. How long we keep personal information

We keep personal information for between one and three years, measured from the closure of the matter it relates to or from the closure of the account, whichever is later. We may keep it for longer where a professional or regulatory record-keeping obligation requires it, or where it is needed to establish or defend a legal claim. When a retention period ends, we delete the information or irreversibly anonymise it.

6. California privacy rights

This section applies to California residents and is provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act.

6.1 Notice at collection

We collect the categories of personal information described in section 1: identifiers, being name, email address, account identifier and IP address; internet and network activity, being usage and log records; professional and employment-related information, being role and organisation; and the contents of documents and, where a mailbox is connected, of electronic communications. The sources are set out in section 1.6, the purposes in section 2 and the retention period in section 5. In the preceding twelve months we disclosed each of these categories of personal information for a business purpose to the categories of recipient listed in section 4.

6.2 We do not sell or share personal information

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. We do not knowingly collect or sell the personal information of anyone under sixteen years of age.

6.3 Sensitive personal information

We do not collect sensitive personal information in order to infer characteristics about you, and we use any such information that reaches us incidentally in the contents of a document only to provide the Service. We therefore do not offer a separate right to limit its use, because we do not use it for any purpose that right restricts.

6.4 Your California rights

Subject to the exceptions the statute allows, you have the right to know what personal information we have collected, its sources, the purposes for which we collected it and the categories of recipient to whom we disclose it; to obtain a copy of the specific pieces of personal information we hold about you; to have it corrected if it is inaccurate; to have it deleted; and not to be discriminated against for exercising any of these rights.

To exercise a right, please contact us at advait@spurginlawoffices.com. We will verify your identity by confirming your control of the email address associated with the account, or by other means proportionate to the sensitivity of the request. You may use an authorised agent, in which case we will ask for written proof of authority.

Where the information forms part of a legal matter, our duty of confidentiality to our client may prevent us from disclosing or deleting it at a third party’s request, and where we act on a client’s instructions we may need to refer a request to that client.