Data Protection
Security is a prerequisite, not a promise.
Legal research must not become a data protection trap. Three principles define how IURIX handles your queries.
GDPR-compliant AI legal research for lawyers and tax advisors in Austria — with anonymisation before the AI model, EU servers and no training on your queries.
May lawyers and tax advisors use AI with client data?
Professional secrecy holders are bound by the strictest confidentiality — lawyers under § 9(2) RAO (§ 40(3) RL-BA), tax advisors and auditors under § 71 WTBG 2017, notaries under § 37 NO. Under the case law of the Austrian Supreme Court (OGH 4 Ob 77/23m), external IT and cloud service providers are “auxiliary staff” who must be contractually bound to confidentiality — under data protection law the professional remains the controller, IURIX is the processor.
The best protection is not to enter personal client data at all: research works in the abstract, around the legal question — names, case numbers and case references are not needed for it. As an additional layer of protection, IURIX nevertheless automatically removes personal data before the AI model; processing takes place on EU servers; your queries are not used for training; a data processing agreement (DPA) — including the agreement on legally compliant cloud use in law firms under § 40(3) RL-BA — takes effect upon registration. If we become aware of official access (such as a search or seizure), we will inform you without delay — subject to statutory prohibitions — to enable the safeguarding of professional secrecy. This keeps use compatible with your duty of confidentiality and the GDPR.
In detail: Compliance & guarantees for professional secrecy holders.
1. Automatic anonymisation
Before the actual research begins, every query passes through an automatic anonymisation step. Personal data — names, case numbers, addresses, dates of birth — is removed before the query is forwarded to the generative models. The anonymisation step is performed by a European model (Mistral, France) and never leaves the EU.
2. EU server locations
Hosting (Microsoft Azure, Austria East region), API routing (Requesty, Frankfurt), anonymisation (Mistral, France) and downstream inference (Anthropic, OpenAI, Google Vertex AI with EU region) — all components in use process data within the EU. Personal data does not leave the European Economic Area.
3. No training on your queries
Contracts are in place with all sub-processors that exclude training the respective models on your queries. Anonymised queries are stored temporarily on our systems for quality assurance and deleted regularly.
Complete documentation
The full privacy policy lists all sub-processors, processing purposes, data locations and retention periods in detail. The data processing agreement (DPA) pursuant to Art. 28 GDPR is available on the site and applies automatically upon registration.