CASENGINE Privacy Policy
Code Engines Software LLC — trading as CASENGINE
Version 3.0 · Effective 15 September 2026 · Supersedes the policy last modified 19 December 2023 · Published at https://casengine.app/privacy-policy/ where each version is retained
1. About this policy
1.1 Code Engines Software LLC (“CASENGINE”, “Code Engines”, “we”, “our” or “us”) is a limited liability company licensed in Dubai (mainland) under trade licence number 800700. We provide a legal practice and legal operations platform to law firms, in-house legal departments, corporates and government entities.
1.2 This policy explains what personal information we collect, why we collect it, who we share it with, where we keep it and what rights you have. It also explains how we use cookies and similar technologies.
1.3 This policy applies to the casengine.app website and its subdomains, our mobile applications, and the CASENGINE service in its hosted form. Section 19 explains how it applies to on-premise deployments, which are treated differently.
1.4 Where you are a lawyer, employee or client of an organisation that subscribes to CASENGINE, please read Section 2 first. It explains why, for most of the information about you held in CASENGINE, your own organisation — not CASENGINE — decides what happens to it.
2. The two different roles we play
2.1 This is the most important section of this policy, because our obligations differ depending on which role we are in.
2.2 Where we are the controller. For some information we decide why and how it is processed. This covers the information we hold about our own customers and prospective customers: account and billing details, the contact details of administrators and users, enquiries you send us, support correspondence, and information collected automatically when you visit our website. This policy governs that information in full.
2.3 Where we are the processor. When a subscribing organisation uses CASENGINE, it uploads and creates records about its own clients, matters, cases, documents, hearings, invoices and time entries. We call this Content. The subscribing organisation is the controller of that Content. We process it only on that organisation’s instructions and only to provide, secure, maintain and support the service. We do not decide what goes into it, how long it is kept, or who may see it.
2.4 What this means for you in practice. If you are a client of a law firm that uses CASENGINE and you want to see, correct or delete information the firm holds about you, you must contact that firm. We cannot act on such a request ourselves, because the information is not ours to release or amend. If you contact us, we will refer you to the firm and, where appropriate, tell the firm you have been in touch. Section 14 explains this further.
2.5 The full terms governing our role as processor, including our security obligations, our sub-processors, breach notification and deletion on termination, are set out in Section 19 of our Terms and Conditions. A subscribing organisation may request that section as a standalone Data Processing Agreement.
2.6 Government entities. Where a subscribing organisation is a UAE government entity, the UAE PDPL does not apply to its Content (Article 2(2) of that law). We process that Content under our contract with the entity and under any government data policy it requires us to follow, and Section 8 and clause 6.5 apply to it in full.
3. The laws we apply
3.1 We apply UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, once issued, its Executive Regulations.
3.2 Where a subscriber or an individual is subject to them, we also have regard to the DIFC Data Protection Law No. 5 of 2020, the ADGM Data Protection Regulations 2021, the Saudi Personal Data Protection Law, India’s Digital Personal Data Protection Act 2023 and Singapore’s Personal Data Protection Act 2012.
4. What we collect and why
4.1 Information you give us
Name, job title, organisation, email address, telephone and mobile number, postal address, and the content of enquiries, demonstration requests and support tickets. We use it to respond to you, to set up and administer your account, to provide support, to invoice you and to maintain our business records. Under the UAE PDPL we process this information because it is necessary to perform our contract with you or to take the steps you ask for before entering into one (Article 4(9)), or to meet our legal obligations (Article 4(10)); otherwise we rely on your consent. Where you are in the DIFC or the ADGM, we may also rely on our legitimate interest in responding to enquiries and running our business.
4.2 Information collected automatically
IP address, approximate location derived from it, device and browser type, operating system, pages visited, referring page, dates and times of access, and application error reports (the page you were on, your user identifier and technical details of the error). We use it to keep the service secure and available, to diagnose faults, to detect misuse, and to understand how the website and product are used. Security, availability and fault-diagnosis processing is necessary to perform our contract with subscribing organisations and to meet our obligations to keep personal data secure under Articles 7 and 20 of the UAE PDPL. Analytics and advertising processing takes place only with your consent, given through the cookie settings on our website. Where you are in the DIFC or the ADGM, we may also rely on our legitimate interest in security and service quality.
4.3 Account security and audit information
Sign-in events, IP address and browser used at sign-in, acceptance of our Terms, changes to permissions, and records of support access. We use it to protect accounts, to investigate incidents and to demonstrate compliance. Our basis is the performance of our contract with the subscribing organisation and our legal obligations, including the security obligations in Articles 7 and 20 of the UAE PDPL.
4.4 Content — where we act as processor
Records that a subscribing organisation creates or uploads: leads, clients, matters, cases, parties, hearings, documents, tasks, time entries, expenses, invoices and communications. We process this only on the subscribing organisation’s instructions, as described in Section 2.3 and Section 19 of the Terms.
4.5 Information from other sources
We may receive your details from an organisation that subscribes to CASENGINE and designates you as a user or as a registered client; from our partners and resellers; and, where you submit an enquiry through an advertisement, from the advertising platform concerned — for example a Google Ads lead form, which passes us the name and contact details you entered. We use those details to respond to your enquiry, and for marketing only with your consent.
5. Sensitive personal information and KYC
5.1 The client onboarding, know-your-customer and document management features may be used by a subscribing organisation to store identity documents (passports, national identity documents, residence permits and trade licences) and, in some matters, information that the law treats as sensitive, such as health, criminal-record or family information in a litigation file.
5.2 We act only as processor for that information. The subscribing organisation is responsible for having a lawful basis to collect and keep it, and for collecting no more than it needs. We do not use it for any purpose of our own.
6. Artificial intelligence
6.1 Some features of CASENGINE use machine learning and large language models. These include the CASY assistant, document reading and extraction, optical character recognition, semantic search, chronology generation, entity resolution, grounded question answering, summarisation, drafting assistance and compliance checking. We call the data submitted to them Input and the material they generate Output.
6.2 Who processes it. Input and Output are processed using Microsoft Azure services, namely the Azure OpenAI Service, Azure AI Search and Azure AI Document Intelligence. We do not send Input or Output to any artificial intelligence provider other than Microsoft Azure.
6.3 We do not train models on your data. Neither we nor Microsoft use Input or Output to train, retrain, fine-tune or otherwise improve any foundation or general-purpose model. Input and Output are not shared with OpenAI.
6.4 Human review. Our personnel do not read Input or Output except where you or a user submits feedback, a support request or a defect report that refers to it, or where we are required by law to do so.
6.4A Abuse monitoring by Microsoft. Separately from clause 6.4, Microsoft operates abuse monitoring on the Azure OpenAI Service. Under Microsoft’s standard terms, prompts and generated content may be kept by Microsoft for up to thirty (30) days so that abusive or harmful use can be detected and prevented, and content flagged by that process may be reviewed by authorised Microsoft staff. This is done by Microsoft, not by us, and the content is not used to train any model. We are seeking Microsoft’s approval for modified abuse monitoring with zero data retention. If that approval is granted, this retention and review will stop applying and we will update this policy.
6.4B If you cannot accept this. A subscribing organisation that is unable to accept the retention described in clause 6.4A may switch AI features off for its whole account, in which case nothing is sent to the Azure OpenAI Service at all. The rest of the service is unaffected.
6.5 Where the processing happens. Azure OpenAI processing is performed in the Microsoft Azure UAE North region where regional capacity permits. Where regional capacity is unavailable, a request may be served by Microsoft’s global or multi-region model deployments, which may process Input outside the United Arab Emirates. Databases containing Content remain in the UAE North region at all times. We will offer a UAE-only option once Microsoft provides regional capacity for it. Where that option is available, a subscribing organisation that requires all AI processing to stay in the United Arab Emirates may elect it through its account settings or by writing to us; a request that cannot then be served in the UAE will fail rather than be routed elsewhere, and no credits are used for a request that is never sent. Until the option is available, an organisation that needs all AI processing to stay in the UAE should leave AI features switched off. Section 8 explains the safeguards that apply.
6.6 Output is not advice. Output is generated automatically, may be inaccurate or incomplete, and does not constitute legal or other professional advice. It must be reviewed by a suitably qualified person before it is relied upon.
6.7 Your control. AI features are switched off by default. They can be switched on only by an administrator of the subscribing organisation, who must first accept the AI disclosure shown in the service on the organisation’s behalf, and they can be switched off again at any time. They are metered using prepaid AI credits and stop working when the credit balance is exhausted.
6.8 No automated decisions about you. We do not use AI features to make decisions about individuals that have legal or similarly significant effects. Where a subscribing organisation uses Output in its own decisions about you, that organisation is responsible for the human review that Article 18 of the UAE PDPL requires.
7. Who we share information with
7.1 Core service providers. These process information for every subscriber and cannot be switched off: Microsoft Azure, for hosting, database and storage; the Azure OpenAI Service, Azure AI Search and Azure AI Document Intelligence, for AI features; and Microsoft (Microsoft Graph / Exchange Online) for sending email; and Sentry (Functional Software, Inc.), which receives application error reports so that we can find and fix faults. Those reports include your IP address, your user identifier, the page you were on and technical details of the error, and Sentry is hosted outside the United Arab Emirates.
7.2 Optional integrations. These receive information only if a subscribing organisation chooses to switch the relevant integration on. Each is disabled by default: Microsoft SharePoint, Outlook, Teams and Entra ID / Active Directory, Dropbox, DocuSign, Intuit QuickBooks, and Twilio together with Meta Platforms (WhatsApp). WhatsApp messages are sent through the Firm’s own Twilio account and delivered onward by Meta; the message carries the recipient’s telephone number and whatever the Firm includes in the message template, such as a name, a matter reference or a hearing date. Before an integration is enabled, the service identifies the provider and the categories of data that will be sent to it.
7.3 Others. We may share information with our professional advisers, with payment providers and, in respect of website and marketing information only, with analytics and advertising providers such as Google (Google Analytics and Google Ads). We never share Content with any advertising provider. We may disclose information where we are required to do so by law, by a court or by a regulator, and in connection with a merger, acquisition or sale of our business, in which case we will notify affected subscribers.
7.4 We do not sell personal information, and we do not use Content for advertising or for any commercial purpose of our own.
7.5 The current list of our service providers is published at https://casengine.app/sub-processors/. We give subscribing organisations at least thirty (30) days’ notice before adding or replacing a core service provider, as set out in Clause 19.4B of the Terms.
8. Where information is stored, and transfers abroad
8.1 Content, including databases, documents and backups, is hosted in Microsoft Azure in the UAE North region and is not moved outside the United Arab Emirates.
8.2 Information leaves the United Arab Emirates only in three situations: where AI capacity requires a request to be served by Microsoft’s global or multi-region deployments, as described in clause 6.5; where a subscribing organisation enables an integration that sends data to that provider; and where application error reports are sent to Sentry, as described in clause 7.1.
8.3 Those transfers are made under the data protection terms of Microsoft or the relevant provider, which include standard contractual clauses, and are limited to what is necessary to provide the service. For information covered by the UAE PDPL we rely on Article 23(1)(a) of that law pending its Executive Regulations. Where a subscribing organisation is established in the DIFC or the ADGM, or is subject to the Saudi Personal Data Protection Law, further transfer terms may be required by its own law and we will enter into them with the organisation on request. Website and marketing information may also be processed by analytics providers outside the United Arab Emirates.
8.4 We state this distinction deliberately, because the two are often confused: where your data is stored and where it is processed are different questions. Storage stays in the UAE. AI processing stays in the UAE whenever regional capacity allows, and we disclose that it may not always be possible.
9. When our people can see Content
9.1 Our personnel do not read Content in the ordinary course of business. Two different kinds of access exist and we describe both, because describing only the first would be misleading.
9.1A Support access to the application. Where access is needed to resolve a support request or a defect, it is granted through the support-access mechanism built into the service. That mechanism requires approval, is authenticated by a one-time passcode, is limited in duration, and is recorded in an audit log that the subscribing organisation’s administrator can review.
9.1B Administrative access to infrastructure. A small number of named staff hold administrative access to the servers, databases and file storage that run the service, because a hosted platform cannot be operated, secured, backed up or restored without it. That access is limited to a named list of individuals kept within our information security management system, every account on that list uses multi-factor authentication, and the list is reviewed periodically with each review recorded. It is not used to read Content except where necessary for a specific operational or support reason, and everyone holding it is bound by confidentiality obligations. Our security management system is aligned to ISO/IEC 27001.
9.2 We do not use either kind of access to read Content for our own purposes, to develop products, or for marketing.
9.3 We will not access Content for any other purpose, except where we are required to do so by law or where a regulator with authority over a subscribing organisation makes a lawful request under Clause 6.1 of the Terms.
10. Email and calendar integration
10.1 Where a subscribing organisation connects a mailbox or calendar, we process the messages, attachments and entries needed to file them against the correct client or matter. That data is Content and is governed by Section 2.3.
10.2 Credentials for connected mailboxes are stored encrypted and are used only to perform the integration the organisation has enabled. An administrator can disconnect a mailbox at any time.
10.3 Where an organisation connects its own mailbox, email is sent and read through that organisation’s own email provider under its own agreement with that provider. That provider is not our sub-processor.
11. How long we keep information
11.1 Content is kept for as long as the subscription lasts. On termination it is made available for download for thirty (30) calendar days and is then irreversibly deleted, or deleted earlier if the administrator instructs us in writing. Retrieval is not conditional on any outstanding payment.
11.2 While a subscription is live, records and documents that a user deletes are marked as deleted, become inaccessible to users, and are excluded from search and from AI features, but are kept in the organisation’s database until termination so that they can be restored on request and related records stay intact. If an organisation’s account owner writes to us naming particular records or documents, we permanently delete or irreversibly anonymise them, together with any data AI features derived from them, within thirty (30) days.
11.2A On termination, once the thirty (30) day retrieval period has passed, we delete the organisation’s entire database, its stored files and its search index in full, and we will confirm that in writing on request.
11.3 Backups are retained for ninety (90) days and are then overwritten. The application audit trail is kept for the life of the subscription and deleted with the organisation’s database on termination.
11.4 Account, billing and correspondence records are kept for as long as we need them for the relationship and afterwards for as long as required by tax, accounting and limitation rules.
12. Security
12.1 Content is encrypted in transit and at rest. Each subscribing organisation’s data is held in a separate database rather than in shared tables, so no user of one organisation can reach another organisation’s data. We treat that boundary as absolute. We operate authentication controls, logging and monitoring, and we review our measures periodically.
12.1A Within a subscribing organisation, who can see what is determined by the roles and permissions that organisation configures. If it grants a user administrative rights, that user will be able to see data across its account. That is the organisation’s decision to make, not ours.
12.2 Further detail is published at https://casengine.app/security/casengineappsecurity.pdf
12.3 No transmission over the internet is ever completely secure. Where you hold a password for the service, you are responsible for keeping it confidential and for not sharing it.
13. Personal data breaches
13.1 If a breach affects Content, we notify the subscribing organisation without undue delay and in any event within seventy-two (72) hours of becoming aware of it. If we do not yet have the full picture within that time, we tell them what we know, say what is still being investigated, and follow up as more is established, rather than waiting until the investigation is finished.
13.2 If a breach affects information for which we are the controller, we notify the UAE Data Office (or the federal authority that succeeds it) as Article 9 of the UAE PDPL requires, we notify you where the breach would prejudice the privacy or confidentiality of your information, and we notify any other competent authority where the law requires it.
14. Your rights
14.1 Subject to the conditions in applicable law, you may ask us to give you access to the personal information we hold about you; correct it if it is wrong; delete it; restrict how we use it; provide it in a portable form; object to our using it, including for direct marketing; or object to a decision about you based solely on automated processing. Where we rely on your consent, you may withdraw it at any time without affecting what we did before you withdrew it.
14.2 Please send requests to privacy@codengines.com. We will respond within the period the applicable law requires and, in any event, within thirty (30) days.
14.3 Requests about Content. If your information sits in CASENGINE because a law firm, company or government entity put it there, that organisation controls it and you must direct your request to them. If you send it to us, we will not act on it ourselves; we will refer you to the organisation and help them respond. We are not permitted to release or change another organisation’s client records.
14.4 We do not charge for responding, unless a request is manifestly unfounded or excessive.
15. Cookies and similar technologies
15.1 We use cookies that are strictly necessary to operate the service and keep it secure; cookies that remember your preferences; and analytics cookies that help us understand how the website and product are used. Where required, we may also use advertising cookies.
15.2 Strictly necessary cookies are set without consent because the service cannot function without them. Preference, analytics and advertising cookies are set only where you consent, and you may withdraw consent at any time through your browser settings. The cookies we use, their purpose and how long they last are listed at https://casengine.app/cookies/.
15.3 Blocking some cookies will affect how parts of the website and service work.
16. Marketing, testimonials and publicity
16.1 We may send you information about our products and services where you have consented to receive it. Every marketing message contains an unsubscribe link, and you may opt out at any time by writing to privacy@codengines.com.
16.2 We publish customer names, logos, testimonials and case studies only with the organisation’s permission, and that permission may be withdrawn at any time by writing to privacy@codengines.com. We will stop using the material within thirty (30) days of being asked.
17. Links to other websites
17.1 Our website and application may link to sites we do not operate. This policy does not apply to them, and we are not responsible for their privacy practices. Please read their policies before providing information to them.
18. Children
18.1 CASENGINE is a business service intended for professional adults. We do not knowingly collect information directly from children under 18. We recognise that a subscribing organisation may hold information about minors within Content — for example in family or estate matters — and that organisation is the controller of it.
19. On-premise deployments
19.1 Where CASENGINE is licensed for installation in an organisation’s own data centre, Content is held in that organisation’s environment and not in ours. That organisation is responsible for its security, backup and retention, and we have no access to it except where it grants us support access under Section 9.
19.2 AI features in an on-premise deployment require outbound connectivity to the Microsoft Azure services in clause 6.2. Where an organisation does not permit that connectivity, the AI features are unavailable.
20. How to contact us
20.1 For any privacy question, or to exercise a right, write to privacy@codengines.com.
20.2 Our Data Protection Officer, who also acts as Grievance Officer for the purposes of India’s Digital Personal Data Protection Act 2023 and as our contact for the purposes of Singapore’s Personal Data Protection Act 2012, is:
Saleh Alobedili
Data Protection Officer, Code Engines Software LLC
Office 216, Dubai Chambers New Extension, Dubai, United Arab Emirates
21. Complaints
21.1 If you are unhappy with how we have handled your information, please contact us first so we can try to resolve it.
21.2 You may also complain to the competent authority. In the United Arab Emirates this is the UAE Data Office or the federal authority that succeeds it. In the DIFC it is the Commissioner of Data Protection; in the ADGM it is the Office of Data Protection; in Saudi Arabia it is the Saudi Data and Artificial Intelligence Authority. In India or Singapore you may complain to the regulator in that jurisdiction.
22. Changes to this policy
22.1 We may update this policy. Where a change materially affects how we use personal information, we will give notice by email or within the service before it takes effect.
22.2 Each version carries a version number and an effective date, and the current version is published at the URL at the head of this policy.