The Hammer Lex (“The Hammer Lex,” “we,” “us,” or “our”) is a practice management platform for law firms operated by The Hammer Lex LLC. We respect your privacy and are committed to protecting the personal information you share with us. This Privacy Policy applies to hammerlex.com and the related applications, dashboards, and services we provide (together, the “Services”).
1.Information we collect
We collect the following categories of information:
Information you provide directly
- Account & profile data — name, work email, phone number, firm or organization name, role, password, and timekeeper rates.
- Billing data — subscription plan, billing contact, and partial payment details (such as card brand and last four digits). Full card numbers are handled by our payment processor and are not stored on our servers (see Payment processing).
- Staff & HR data — where the platform’s staff module is used, profiles, skills, banking details, and time-off requests entered by your firm.
- Communications — information you submit through contact forms, demo requests, support tickets, and email.
Customer Data your firm submits
- Client & matter records, intake and conflict-check inputs, time entries, invoices, expenses, calendar/deadline data, and documents (such as retainers, pleadings, and motions). This may include information about your firm’s clients and other third parties.
Information from accounts you choose to connect
- Connected calendar data — if you connect a Google or Microsoft calendar, we receive the email address of the connected account and the events on that account’s primary calendar (title, description, start and end time, and attendee list) so the platform can suggest time entries and write your matter deadlines back to your calendar. See Connected calendar accounts for exactly what we access and how you revoke it.
Information collected automatically
- Usage & device data — IP address, browser and device type, pages viewed, features used, referring URLs, and timestamps.
- Cookies & similar technologies — see Cookies & tracking.
2.How we use information
We use personal information to:
- Provide, operate, secure, and maintain the Services;
- Create and manage accounts and authenticate users;
- Process subscriptions, payments, and renewals, and prevent fraud;
- Respond to inquiries, demo requests, and support tickets;
- Send service and administrative messages, and—where permitted—product updates you can opt out of;
- Monitor, analyze, and improve performance, reliability, and features;
- Comply with legal obligations and enforce our agreements.
We do not sell personal information, and we do not use Customer Data to train AI models or for our own marketing.
3.Legal bases for processing
Where the EU/UK GDPR applies, we rely on these legal bases: performance of a contract (to provide the Services), legitimate interests (to secure and improve the Services and prevent fraud), consent (for certain cookies and marketing, which you may withdraw), and legal obligation (to meet tax, accounting, and other requirements).
4.How we share information
We share information only as described here:
- Service providers (sub-processors) who process information on our behalf under contract. Current categories and providers include:
| Purpose | Provider |
|---|---|
| Payment processing | Stripe, Inc. |
| Application hosting, storage & key management | Microsoft Azure (Microsoft Corporation) |
| Marketing website hosting | Bluehost (Newfold Digital, Inc.) |
| Transactional & service email | Azure Communication Services (Microsoft Corporation) |
| Website analytics | Google Analytics 4 (Google LLC) and Microsoft Clarity (Microsoft Corporation) — marketing site only |
| Customer support | Handled directly by our team over email; no third-party helpdesk platform is used. |
- Legal & safety — when required by law, subpoena, or to protect the rights, safety, and property of The Hammer Lex, our users, or others.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
- With your direction — for example, when your firm grants client-portal access or exports data.
5.Payment processing
Payments are processed by Stripe. When you subscribe, your payment card information is collected and processed directly by Stripe under its own terms and privacy policy; we receive limited information such as a transaction confirmation, card brand, expiration, and the last four digits. We do not store full card numbers. Stripe’s handling of your data is governed by the Stripe Privacy Policy.
6.Connected calendar accounts (Google & Microsoft)
The platform can connect to your Google Calendar or Microsoft Outlook calendar so that meetings become suggested time entries and matter deadlines are written back to your calendar. This connection is optional and off by default. It is created only when an individual user clicks “Connect” in Settings → Calendar Integration and completes the provider’s own consent screen. Your firm’s administrators cannot enable it on your behalf.
What we request and why
| Permission requested | Why we need it |
|---|---|
.../auth/calendar.events.owned (Google) | Read events on your primary calendar to propose time entries, and create or update events for the matter deadlines the platform generates for you. |
.../auth/userinfo.email (Google) | Display which account is connected, so you can tell one connected calendar from another. |
Calendars.Read, Calendars.ReadWrite, User.Read, offline_access (Microsoft) | The same read, write-back, account-identification, and background-refresh functions for Outlook. |
We request the narrowest permission each provider offers for this purpose. On Google we deliberately use calendar.events.owned rather than the broader calendar or calendar.events scopes: we only ever read and write events on the connected account’s own primary calendar, and never access calendar lists, sharing permissions, settings, or any other calendar.
What we do with it
- Use. Calendar data is used only to deliver the features described above to you and your firm. We do not use it for advertising, we do not sell it, we do not transfer it to third parties, and we do not use it to train or improve any artificial-intelligence or machine-learning model.
- Storage. Access and refresh tokens are encrypted at rest in our database. Event details are stored only as far as needed to create and de-duplicate the resulting time entries and deadline records.
- Human access. No employee reads your calendar content. Access by our personnel is limited to named engineers acting on an explicit support request from you, or where required to resolve a security incident or to comply with law.
- Retention and deletion. Disconnecting a calendar in Settings → Calendar Integration permanently deletes the stored connection record and its encrypted tokens from our database. Time entries and deadlines already created from calendar events remain in your firm’s records, because they are part of your firm’s billing and matter history.
- Revoking access. You can revoke our access at any time, independently of us, at myaccount.google.com/permissions (Google) or myapps.microsoft.com (Microsoft).
7.Customer Data & your firm
For information your firm uploads about its clients, matters, and staff, your firm is the controller and we are the processor. We process that Customer Data only to provide the Services and per your firm’s documented instructions. If you are an individual whose data appears in the platform because a law firm uses our Services (for example, a client of that firm), please direct privacy requests to that firm; we will assist the firm in responding. Firms that require a formal Data Processing Agreement (DPA) can request one at support@hammerlex.com.
8.Data retention
We retain personal information for as long as your account is active and as needed to provide the Services, then for the period required to meet legal, tax, accounting, and dispute-resolution obligations. Customer Data is retained according to your firm’s subscription and is deleted or returned on request after termination, subject to legal holds and backup cycles.
9.How we protect information
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, role-based access controls, and least-privilege access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your information, we will notify you and any regulators as required by law.
10.Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of California (CCPA/CPRA) may request access to and deletion of personal information and may opt out of any “sale” or “sharing” of personal information—note that we do not sell personal information. To exercise any right, contact us at support@hammerlex.com. We will not discriminate against you for exercising these rights, and we may need to verify your identity before responding.
11.Cookies & tracking
We use cookies and similar technologies in two distinct places, and they are not the same:
- Strictly necessary — the platform (app.hammerlex.com). Cookies that keep you signed in, maintain your session, and protect against cross-site request forgery. These are required for the platform to work and cannot be switched off. We do not run advertising or third-party analytics trackers inside the platform.
- Analytics — the marketing website (hammerlex.com). Our public website uses Google Analytics 4 (measurement ID
G-9GSN6SG4TM) and Microsoft Clarity (project IDy0fqzojmve) to understand which pages and features visitors find useful. Google Analytics sets Google’s_gacookies and records page views, referring URLs, approximate location derived from a truncated IP address, and device and browser type. Clarity analyzes interactions such as page visits, clicks, scrolling, and navigation through reconstructed session views and heatmaps. Microsoft states that Clarity masks sensitive content by default and masks input-box content; see its masking documentation. We do not use these tools to build advertising audiences, and neither runs on the platform itself. For more information about Clarity’s privacy practices, see Microsoft Clarity’s privacy page.
You can control cookies through your browser settings; disabling strictly necessary cookies will prevent you from signing in. To opt out of Google Analytics specifically, install Google’s browser opt-out add-on, or use a browser or extension that blocks analytics trackers.
12.International transfers
We are based in the United States and may process information in the U.S. and other countries where we or our service providers operate. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers of personal information.
13.Children’s privacy
The Services are intended for businesses and professionals and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
14.Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after an update means you accept the revised policy.
15.Contact us
If you have questions or requests about this policy or your personal information, contact:
The Hammer Lex LLC
Email: support@hammerlex.com