Privacy Policy

How we handle your data and what it means for you

Last Updated: January 16, 2026

Table of Contents

Look, nobody really reads these things from start to finish - we get it. Jump to what matters to you:

Introduction

Alright, let's talk privacy. As a tech law firm, we know exactly how important your data is - we spend half our time helping clients protect theirs. So yeah, we take this seriously.

This policy covers Morphic Lattice Legal's website and how we handle any info you share with us. We've tried to make it readable (not the usual legal jargon marathon), but it's still comprehensive because, well, we're lawyers and we can't help ourselves.

The Bottom Line

We collect what we need to serve you as clients, we don't sell your data to anyone, and we follow PIPEDA and privacy best practices. If you want more details, keep reading.

By using our website or services, you're agreeing to this policy. If something doesn't sit right with you, reach out - we'd rather talk it through than have you uncomfortable.

Information We Collect

Here's what we gather and why we need it:

Information You Give Us Directly

When you fill out a contact form, call us, or become a client, we'll collect:

  • Name and contact details (email, phone number, address)
  • Company information if you're reaching out on behalf of a business
  • Details about your legal needs or questions
  • Any documents or files you share with us
  • Payment and billing information when you hire us

Client-Attorney Privilege

Once you're a client, everything you tell us is protected by solicitor-client privilege. That's not just a policy thing - it's a fundamental legal protection we can't breach even if we wanted to.

Info We Collect Automatically

Like pretty much every website out there, we automatically collect some technical stuff:

  • IP address and general location data
  • Browser type and device information
  • Pages you visit and how long you stick around
  • Referring websites (where you came from)
  • Time and date of visits

This helps us understand how people use the site and where we can improve things.

Technical Collection Methods

We use standard web technologies to collect this data:

  • Cookies: Small files stored on your device (more on this below)
  • Server Logs: Our hosting provider keeps logs of requests made to our servers
  • Analytics Tools: We use privacy-focused analytics to understand site traffic
  • Form Analytics: We track which forms get abandoned so we can make them less annoying

How We Use Your Data

We're not in the business of hoarding data just because. Here's what we actually do with it:

Primary Uses

  • Providing Legal Services: Kind of the whole point - we need your info to help you
  • Communication: Responding to inquiries, sending updates, scheduling meetings
  • Billing & Accounting: Sending invoices, processing payments, maintaining financial records
  • Legal Compliance: Meeting our professional obligations and regulatory requirements

Secondary Uses

  • Improving our website and user experience
  • Sending relevant legal updates or newsletters (only if you've opted in)
  • Understanding which of our services are most needed
  • Preventing fraud and maintaining security

Marketing Communications

We won't bombard you with emails. If we send newsletters or updates, there's always an unsubscribe link. One click and you're out - no questions asked, no hurt feelings.

Data Sharing & Disclosure

We don't sell your data. Period. But there are some situations where we might need to share it:

Service Providers

We work with trusted third parties who help us run our practice:

  • Cloud storage providers (for secure document management)
  • Email and communication platforms
  • Payment processors and accounting software
  • Web hosting and IT security services

All of these folks are bound by contracts that require them to keep your data secure and not use it for their own purposes.

Legal Obligations

Sometimes the law requires us to disclose information:

  • Court orders or subpoenas
  • Law enforcement requests (where legally required)
  • Regulatory compliance requirements
  • Prevention of fraud or illegal activity

We'll always verify the legitimacy of such requests and, where possible, let you know before disclosing anything.

Business Transfers

If Morphic Lattice Legal were ever sold, merged, or restructured (not planning on it, but you never know), your information would likely be transferred as part of that transaction. Any new owner would be bound by this privacy policy unless they give you notice and opportunity to opt out.

Security Measures

We're a tech law firm, so we practice what we preach when it comes to data security:

Technical Safeguards

  • SSL/TLS encryption for all data transmitted through our website
  • Encrypted storage for sensitive documents and communications
  • Regular security audits and vulnerability assessments
  • Multi-factor authentication for accessing client data
  • Firewall protection and intrusion detection systems

Organizational Measures

  • Strict access controls - staff only see what they need to
  • Regular training on privacy and security best practices
  • Confidentiality agreements with all team members
  • Incident response procedures if something goes wrong

No System Is Perfect

We do everything we reasonably can to protect your data, but let's be real - no online system is 100% secure. If we ever experience a breach that affects your information, we'll let you know promptly and tell you what happened and what we're doing about it.

Your Rights

Under PIPEDA and general Canadian privacy law, you've got rights. Here's what you can do:

Access & Correction

You can ask to see what personal information we have about you and request corrections if something's wrong. Just reach out and we'll get you a copy.

Withdrawal of Consent

You can withdraw consent for us to use your data at any time (subject to legal and contractual restrictions). For example, you can opt out of marketing emails instantly.

Data Portability

Want your data in a format you can take elsewhere? We'll provide it in a commonly used format when feasible.

Deletion

You can ask us to delete your personal information. We'll do so unless we have a legal obligation to keep it (like financial records for tax purposes or litigation files).

Response Time

We'll respond to requests within 30 days, as required by PIPEDA. If we need more time, we'll let you know why and when you can expect a response.

Filing a Complaint

If you're not happy with how we've handled your privacy concerns, you can file a complaint with the Office of the Privacy Commissioner of Canada. We'd rather resolve things directly, but that option's always there.

Data Retention

We don't keep your data forever just for kicks. Here's our general approach:

Client Files

We're required to keep client files for a minimum period under Law Society rules (typically 7-10 years after a matter closes). After that, we'll securely destroy files unless there's a specific reason to keep them longer.

Financial Records

Tax laws require us to keep financial records for at least 7 years. Can't get around that one.

Marketing & Communications

If you've subscribed to our newsletter or updates, we'll keep that data until you unsubscribe or ask us to delete it.

Website Analytics

We typically keep analytics data for 26 months, then it gets automatically deleted.

Third-Party Services

Our website might link to other sites or use third-party services. We've vetted the ones we use, but once you leave our site, you're subject to their privacy policies, not ours.

Services We Use

  • Google Workspace for email and productivity tools
  • Secure document sharing platforms for client files
  • Payment processors for online billing
  • Analytics services to understand site usage

All of these are based in Canada or have adequate safeguards for cross-border data transfers.

Cross-Border Data Transfers

Some of our service providers might store data on servers outside Canada. When that happens, your data could be subject to foreign laws (like US surveillance laws). We try to minimize this and use providers with strong privacy protections, but it's something to be aware of.

Changes to This Policy

We'll update this policy from time to time as our practices evolve or laws change. When we make significant changes, we'll let you know by:

  • Updating the "Last Updated" date at the top
  • Posting a notice on our website
  • Sending an email to current clients (for major changes)

We'll give you reasonable notice before any changes take effect. If you continue using our services after the changes, that means you're cool with the updated policy.

Questions or Concerns?

If you've got questions about this privacy policy or how we handle your data, don't hesitate to reach out. We'd rather answer questions upfront than deal with concerns later.

Privacy Officer Contact

Morphic Lattice Legal

Suite 1840, 100 King Street West
Toronto, ON M5X 1C7

(416) 555-8742

contact@morphiclattice.info

Please include "Privacy Inquiry" in the subject line so we can route it properly.

PIPEDA Compliant
Canadian Privacy Law
GDPR Ready
EU Data Protection
SSL Secured
Encrypted Connections