Privacy Policy
Last updated: August 10, 2026
This policy explains who we are, what personal data we collect when you use Upclytics, why we collect it, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and equivalent laws. We have written this policy in plain language; defined legal terms have their meanings under the GDPR.
1. Who we are (controller and contact)
Upclytics is operated by Futurist IP ("we", "us"), a company incorporated in Ontario, Canada. We are the controller of personal data processed in connection with the Upclytics service at upclytics.com.
For any privacy question or to exercise your data-protection rights, write to us at contact@upclytics.com. The same address reaches our internal data-protection contact (we have not appointed a formal Data Protection Officer at this stage; the role is informally held by our founding team and we will appoint a DPO if and when we cross the GDPR thresholds that require one).
2. Personal data we collect
Account data. When you create an account we collect your email address, your name, the firm or organisation you give us, your language preference, and (if you sign in with a password) a password that is hashed and stored by our authentication provider. We never see your password in plain text.
Contact-form data. When you submit our contact form we collect the name, email, topic, and message you provide, plus the IP address and User-Agent string of the request for fraud prevention.
Server logs. We do not run our own servers. Our hosting and database providers generate request logs (timestamp, URL, response status, IP address, User-Agent) to operate their platforms, and delete them automatically on short retention schedules. We do not export or keep copies of these logs.
Court-record data. The case data, party data, judge data, and decisions surfaced in the product are sourced from public registries (see section 3). They may include personal data of parties, representatives, and judges; we treat that data as already public for the purpose for which it was published, court transparency.
Usage data. We record which pages are visited, the language, the site that referred you, and a coarse country, so we can see how the product is used. If you are signed in, this is linked to your account, but we do not record which specific case, party, firm or judge you opened. If you are not signed in, we use a cookieless identifier that changes every day and cannot follow you between days. This usage record contains no IP address and no browser user-agent.
No third-party tracking. Upclytics does not use third-party analytics, advertising trackers, or cross-site cookies. The usage measurement described above is our own, stays on our systems, and is never shared with an advertising network.
3. Public-record data we process
The product analyzes case, decision, party, judge, and representative information made available through public court and patent registries. We extract, structure, and aggregate that data; we do not collect personal data about case parties, judges, or representatives beyond what those public sources make available.
Court records may incidentally include personal data of categories protected under Article 9 GDPR (for example, health-related information disclosed in pharmaceutical disputes). To the extent such data appears in records we process, we rely on Article 9(2)(e) — data manifestly made public by the data subject through the court record — and Article 9(2)(f) — processing necessary for the establishment, exercise, or defence of legal claims. We do not actively extract or index special categories of data.
4. Lawful basis for processing
Account data: performance of the contract you enter into with us when you create an account (Article 6(1)(b) GDPR), and our legitimate interest in operating, securing, and improving the service (Article 6(1)(f) GDPR).
Contact-form data: your consent in submitting the form (Article 6(1)(a) GDPR), and our legitimate interest in responding to inquiries (Article 6(1)(f) GDPR).
Server logs: our legitimate interest in operating, debugging, and securing the service (Article 6(1)(f) GDPR).
Court-record data: our legitimate interest in providing analytics over public court information that is already published (Article 6(1)(f) GDPR), balanced against the data subjects' interest in court transparency, which is the very purpose for which the data was published.
Usage data: our legitimate interest in understanding how the product is used so we can operate and improve it (Article 6(1)(f) GDPR).
Marketing emails: only with your separate, explicit opt-in consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
5. How we use your data
We use account data to authenticate you, provide access to the product, and send service-related transactional email (account confirmation, password reset, security notifications, and billing notices). We use contact-form data to respond to your inquiry. We use server logs to operate, secure, and improve the service. We use usage data to understand which parts of the product are used.
We do not use your account data, your inquiries, or your activity in the product to train machine-learning models, profile you, or sell to third parties.
6. Recipients and subprocessors
We share personal data with a small number of carefully selected service providers (subprocessors) who process it on our behalf under written data-processing agreements. These cover database/authentication, hosting/CDN, transactional email, and payments.
We will notify registered users of material changes to our subprocessor arrangements at least 30 days before the change takes effect. The current list of subprocessors is available on request at contact@upclytics.com.
We do not sell personal data and we do not share it with third parties for their own marketing.
7. International transfers
Some of our subprocessors are based in the United States. Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, on the recipient's certification under the EU–US Data Privacy Framework. The location and applicable transfer mechanism for each subprocessor is available on request at contact@upclytics.com.
8. How long we keep your data
Account data: for as long as your account is active. If you delete your account, we keep your account record in a deactivated state for 30 days to allow recovery of accidental deletions, then permanently delete it from primary storage. Backups containing the deleted record are overwritten on the normal backup-rotation schedule (no longer than 90 days from deletion).
Contact-form submissions: for up to 24 months from submission, then deleted, unless they relate to an ongoing customer relationship in which case they are kept under the account-data rules above.
Server logs: held by our hosting and database providers on their own short retention schedules and deleted automatically. We do not keep copies.
Usage data: kept for as long as we operate the service, because it is how we understand which parts of the product are used.
Where we are required by law to retain data longer (for example tax records), we retain it only for the duration of that legal obligation and only for that purpose.
Newsletter data: we no longer offer a newsletter signup. Any remaining subscriber record is kept only as a suppression record so the address is not mailed again, or deleted on request.
9. Your rights under the GDPR
You have the right to: access the personal data we hold about you; correct inaccurate data (rectification); erase your data (subject to lawful retention obligations); restrict processing; object to processing based on legitimate interest; receive your data in a structured, commonly used, machine-readable format (data portability); and, where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, email contact@upclytics.com. We will respond within one calendar month of receipt; if your request is complex we may extend that period by up to two further months and will tell you why.
There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive.
10. Right to lodge a complaint
If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with a supervisory authority — typically the data-protection authority in your EU/EEA country of residence, place of work, or place of the alleged infringement. We would appreciate the chance to address your concern first by email, but you do not have to contact us before going to the authority.
11. No automated decision-making
We do not subject you to decisions based solely on automated processing — including profiling — that produce legal effects on you or similarly significantly affect you. The aggregations and summaries shown in the product are statistical reporting on public court information; they do not make decisions about individuals.
12. Cookies and similar technologies
We use a small set of cookies, all of them strictly necessary or functional. We do not use any analytics, advertising, or third-party tracking cookies, and we therefore do not show a cookie consent banner.
Strictly necessary cookies (no consent required): the session cookies that keep you signed in, and a short-lived cookie set only while you reset your password. Without these you cannot use the gated parts of the service.
Functional cookies (no consent required under EU guidance for strict UX preference): the NEXT_LOCALE cookie that remembers whether you prefer the English or German version of the site.
No other cookies are set by upclytics.com.
13. French-seated judge anonymization
Judges who sit only at French local divisions are anonymized in our display, in line with French judicial-protection conventions, even though the underlying public records use their names. Multi-division judges are shown by name. This is a display choice, not a data-collection choice — the underlying name is in the public record and we re-publish it for non-French-only judges.
14. Children's data
Upclytics is a B2B legal-research product not directed at children. We do not knowingly collect personal data from anyone under sixteen years old. If you believe a minor has registered, please write to us and we will delete the account.
15. Representation in the EU and UK
We are established in Canada, not in the EU or the UK. Where the GDPR or the UK GDPR requires a controller outside those territories to designate a representative, we keep that requirement under review against our processing and will designate one where it applies. EU and UK residents can reach us directly at contact@upclytics.com on any data-protection matter, with the response times set out in section 9, and may complain to their local supervisory authority as described in section 10.
16. Security
We follow industry-standard security practices: TLS 1.2+ in transit, encryption at rest for the database, hashed passwords, an audited authentication library, and regular dependency updates. No system is perfectly secure. If you discover a vulnerability, please report it confidentially to contact@upclytics.com — we will acknowledge within three business days.
17. Changes to this policy
If we materially change this policy, we will notify registered users by email at least 30 days before the change takes effect, and we will update the "last updated" date at the top of this page. Continued use of the service after the change constitutes acceptance of the updated policy.
18. Contact
Controller: Futurist IP (Ontario, Canada), operating under the brand Upclytics. Privacy and DPO contact: contact@upclytics.com. For data-subject rights, security disclosures, or any privacy question, write to that address.
19. Security incidents and breach notification
We maintain a security-incident response process. In the event of a personal-data breach likely to result in a risk to your rights or freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 GDPR). Where the breach is likely to result in a high risk to your rights or freedoms, we will also notify affected users without undue delay (Article 34 GDPR). You can report suspected security issues to contact@upclytics.com.