Privacy Notice
Last updated: 5 September 2026
This Privacy Notice explains how Thomas & Le Limited (“ezra”, “we”, “us ” or “our”) collects, uses and protects personal data in connection with the website at ezralaw.ai (the “Site ”) and, where a firm connects a calendar account to Ezra, Google Calendar and Microsoft 365 / Outlook data. It is issued in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) as applied in Malta, and the UK GDPR where applicable.
1. Data controller
The data controller responsible for your personal data is:
Thomas & Le Limited
Level 3, Suite 3243, Tower Business Centre
Triq IT-Torri
Swatar
Birkirkara
BKR 4013
Malta
Company Registration No. C113416
Email: support@ezralaw.ai
2. What personal data we collect
We collect only the minimum personal data necessary to operate the Site and respond to you:
- Contact data — if you email us (for example at support@ezralaw.ai to request early access), we receive your name, email address and any information you choose to include in your message.
- Technical data — our hosting provider and network infrastructure automatically record basic technical information when you visit the Site, including your IP address, user agent, referring URL and timestamps. This is used for security, troubleshooting and to ensure the Site is available.
- Cookies — we load Google Tag Manager so we can see how the Site is used. GTM and any tags it loads may set cookies. We do not use them for advertising. Cloudflare may also set a strictly necessary security cookie. See section 7.
- Calendar data (Google Calendar and Microsoft 365 / Outlook) — when a lawyer or firm administrator connects their Google or Microsoft account to Ezra, we access calendar events and free/busy information, including event titles, times, attendees and the identifiers needed to create or update a booking. See section 4.
3. Why we use your personal data, and our lawful basis
- To respond to you (contact data) — lawful basis: our legitimate interests in answering enquiries and operating our business, or the taking of steps prior to entering into a contract where you request one.
- To keep you informed about early access (contact data) — lawful basis: consent, where you have asked us to follow up with product updates. You can withdraw consent at any time by emailing us.
- To operate and secure the Site (technical data) — lawful basis: our legitimate interests in keeping the Site available, preventing abuse and protecting our systems.
- To comply with law — lawful basis: legal obligation, where we are required to retain or disclose information by applicable law.
- To book consultations and run the AI notetaker (calendar data) — lawful basis: performance of a contract with the firm, and the connecting user’s consent given when they authorise Google or Microsoft. A user can withdraw that consent by disconnecting the integration (section 4).
4. Google Calendar and Microsoft Outlook
Ezra uses a connected Google Calendar or Microsoft 365 / Outlook calendar for two features only:
- Booking. Ezra reads free/busy on the connected calendar, offers consultation slots that are actually free, and creates, updates or cancels those events on that calendar.
- AI notetaker. When a booked meeting starts, Ezra’s notetaker joins from that calendar event, records with consent, and drafts an attendance note and time entry. A fee earner approves before anything is filed.
We do not sell calendar data. We do not use it for advertising. We do not use it to train general-purpose AI models. This connection does not read Gmail, Google Drive, Outlook mail or OneDrive.
Ezra’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to provide or improve the booking and notetaker features described on this Site.
A connected user can disconnect Google or Microsoft from Ezra at any time in the product’s integrations settings. They can also revoke access from their Google Account (third-party apps with account access) or their Microsoft account (apps and services that can access your data).
OAuth tokens are stored only to keep the connection working, and are deleted when it is disconnected. Event details needed to run a booking or notetaker session are kept while the connection is active and for as long as the resulting matter file requires them; they are not kept for marketing.
5. Who we share your personal data with
We do not sell your personal data. We share personal data only with trusted service providers who process it on our behalf under written contracts, including:
- Cloudflare, Inc. — Website hosting, content delivery and security. Processed in United States, with global edge locations.
- Resend — Transactional email for the request-access form. Processed in United States.
- Professional advisors and regulators — where required (for example, auditors, lawyers, or in response to a lawful request from a competent authority).
Processors used to run the Ezra application for a firm are set out in that firm’s DPA and named on request for a DPIA. They are not listed in this notice.
6. International transfers
Our hosting and email providers (Cloudflare, Inc. and Resend) are based in the United States, with data processed on infrastructure that may include EU and US regions. Where a lawyer connects Google Calendar or Microsoft 365 / Outlook (section 4), those providers may also process that calendar data outside the EEA. Where personal data is transferred outside the European Economic Area (EEA), we rely on appropriate safeguards recognised under the GDPR, such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
7. Cookies and similar technologies
We load Google Tag Manager so we can measure how the Site is used. GTM and any tags it loads may set cookies. We do not use them for advertising. Cloudflare may also set a strictly necessary security cookie. You can block cookies in your browser.
8. How long we keep your personal data
- Email correspondence — retained for up to 24 months after the last interaction, unless a longer period is required to comply with law or to establish, exercise or defend legal claims.
- Server and security logs — retained for up to 30 days, and longer only where needed to investigate an incident.
- Calendar connection tokens — retained only while the Google or Microsoft connection is active, then deleted.
9. Your rights
Under the GDPR, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate or incomplete personal data;
- request erasure of your personal data in certain circumstances;
- restrict or object to our processing of your personal data;
- receive your personal data in a portable format where processing is based on consent or contract;
- withdraw consent at any time, where our processing is based on consent;
- lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at support@ezralaw.ai. We will respond within the time limits required by law (usually one month).
10. Supervisory authority
If you are unhappy with how we handle your personal data, you have the right to complain to the Office of the Information and Data Protection Commissioner in Malta:
Office of the Information and Data Protection Commissioner (IDPC)
Level 2, Airways House
High Street, Sliema SLM 1549
Malta
Website: https://idpc.org.mt
You may also complain to the supervisory authority in the EU member state where you live or work.
11. Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. These include TLS encryption for the Site, restricted administrative access, and least-privilege access controls for our service providers. No transmission over the internet is, however, ever completely secure.
12. Children
The Site is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to this notice
We may update this Privacy Notice from time to time. The current version will always be available at ezralaw.ai/privacy with the date of last update shown above. Material changes will be highlighted on the Site or communicated directly where appropriate.
14. Contact
Questions about this Privacy Notice or how we handle personal data can be sent to support@ezralaw.ai.