Privacy Policy
Last Updated: March 1, 2026
1. Introduction
This Privacy Policy describes how Lenhac Limited ("we", "us", or "our") collects, uses, and protects your information when you use Sisu by Lenhac ("the Application", "Sisu"), our law firm management system.
Sisu by Lenhac is developed and operated by Lenhac Limited, a technology company registered in Kenya. By using our Application, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, and organization details when you create an account.
- Client Data: Information about your law firm's clients that you enter into the system, including names, contact details, and case information.
- Case Information: Legal matter details, documents, notes, and other case-related data you store in the Application.
- Financial Data: Invoice details, payment records, and billing information managed through the Application.
2.2 Information from Google Services
When you connect your Google account to Sisu, we access the following data based on the permissions you grant:
Google Calendar Access
Scopes: auth/calendar, auth/calendar.events
What we access:
- Your calendar list to identify which calendars to sync with
- Calendar events to display your schedule within Sisu
- Ability to create, modify, and delete events for court dates, client meetings, and deadlines
What we DO NOT do:
- We do not read personal events unrelated to your legal practice
- We do not share your calendar data with third parties
- We do not store your calendar data permanently - it is accessed in real-time
Gmail Send Access
Scope: auth/gmail.send
What we access:
- Ability to send emails on your behalf to clients and other parties
- This includes case updates, invoice deliveries, meeting confirmations, and document sharing
What we DO NOT do:
- We cannot and do not read your emails
- We cannot access your inbox, sent folder, or any existing emails
- We do not store copies of emails sent through the Application
- We only send emails when you explicitly initiate the action within Sisu
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Operate and maintain the Sisu application, including client management, case tracking, and scheduling features.
- Calendar Synchronization: Sync court dates, deadlines, and appointments between Sisu and your Google Calendar.
- Email Communications: Send emails to your clients on your behalf when you initiate such actions within the Application.
- Notifications: Send you reminders about deadlines, court dates, and important case milestones.
- Improve the Service: Analyze usage patterns to improve functionality and user experience.
- Customer Support: Respond to your inquiries and provide technical assistance.
4. Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encryption: All data is encrypted in transit using TLS/SSL and at rest using AES-256 encryption.
- Access Controls: Strict access controls ensure only authorized personnel can access system infrastructure.
- Secure Infrastructure: Our application is hosted on secure cloud infrastructure with regular security audits.
- Data Isolation: Each law firm's data is logically isolated from other users.
Your Google authentication tokens are stored securely and are only used to access the specific Google services you have authorized. We never store your Google password.
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share data only in the following circumstances:
- With Your Consent: When you explicitly authorize us to share information.
- Service Providers: With trusted third-party service providers who assist in operating our application (e.g., cloud hosting), bound by confidentiality agreements.
- Legal Requirements: When required by law, court order, or governmental authority.
- Protection of Rights: To protect our rights, privacy, safety, or property, or that of our users.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide you services. If you close your account, we will delete or anonymize your data within 90 days, except where we are required to retain it for legal or regulatory purposes.
Google OAuth tokens are retained only while your Google account is connected. When you disconnect your Google account or revoke access, these tokens are immediately deleted from our systems.
7. Your Rights and Choices
You have the following rights regarding your data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Revoke Google Access: Disconnect your Google account at any time through your Sisu account settings or through your Google Account permissions.
- Export: Request an export of your data in a portable format.
8. Google API Services User Data Policy
Sisu by Lenhac's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only request access to the Google services necessary to provide the features described in this policy.
- We do not use Google user data for advertising purposes.
- We do not sell Google user data to third parties.
- We do not use Google user data for purposes unrelated to the core functionality of Sisu.
9. Children's Privacy
Sisu by Lenhac is designed for use by legal professionals and law firms. Our Application is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically for any changes.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us: