Vannus / Catalog / Legora

Legora

Vannus records that this vendor has not disclosed which model it runs. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Determination
Contracts with Legora AB (Sweden), under a governing law that depends on where the customer is based.
Vannus has not established whether a US parent controls this entity, so US reach is not established either way. The US terms do not name the contracting entity.
legora.com · read 2026-07-29
read from terms of service

Collaborative AI for legal work from Legora AB (registration number 559338-6872), Box 7242, 103 89 Stockholm, Sweden, with its technical team based in Sweden.

AI, legal, enterprise
Model provenance

Uses AI; provider not disclosed. Legora's own aOS page describes an agentic harness over LLMs and its privacy policy refers to transmitting queries to 'our AI model provider', but no first-party prose names a model or vendor; the only first-party naming of OpenAI is an isolated table cell on the EU pre-approved sub-processor page. We checked and found no first-party page naming it, so the criterion is excluded from the grade rather than counted against Legora.

Who controls it
Data jurisdictionEuropean Union · a privacy notice ↗
US corporate controlNot disclosed — the vendor's own documents name the contracting entity but do not settle whether a US entity or parent controls it · clause re-checked 17 Sep 2026
Trains on your dataNo — on the vendor's default plan

Training and retention posture varies by plan. What we publish above describes the vendor’s default plan; enterprise, team and API agreements frequently differ, often materially, and a contract can override the published default entirely. Check your own plan and contract before relying on this row.

On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Signals on file
Data jurisdiction
European Union

The vendor's published or catalog-recorded posture — the concrete facts this entry is built from. A full audit verifies each against the vendor's current documentation.

Who else handles your data

Legora publishes a list of the other companies it uses as sub-processors. It lists 27 entries, and some name the same company more than once, under different locations, for different purposes or in more than one of its lists. Each is shown below with the location the vendor lists it under, in the vendor’s own words.

Under 3 of the headings below — “EU”, “United States” and “Asia-Pacific” — Legora prints no sentence saying which customers each list applies to. They are shown under those headings as printed, and nothing more is read into them.

Under its heading “EU”:

Microsoft · EU/EEADeepL (optional) · EU/EEAAWS · EU/EEAGoogle · EU/EEAOpenAI · EU/EEAIntercom · EU/EEALinkup Labs · EUturbopuffer SaaS · EU/EEA

Under its heading “United States”:

Microsoft · USDeepL (optional) · USAWS · USGoogle · USOpenAI · USIntercom · USLinkup Labs · USExa Labs · USturbopuffer SaaS · US

Under its heading “Asia-Pacific”:

Microsoft · AustraliaMicrosoft · EU/APACDeepL (optional) · GermanyAWS · AustraliaAWS · EU/APACGoogle · EU/APACOpenAI · EUIntercom · EU/APACLinkup Labs · EUturbopuffer SaaS · EU

Taken together those entries name at least APAC, Australia, EEA, EU, Germany, US. That is what our place list could match in the vendor’s own words above, so treat it as a floor rather than the whole of it — the entries themselves are the record.

These are other companies, not Legora. Where a sub-processor is listed as operating is a fact about that company. It is not a statement about where Legora keeps your data, which Vannus publishes separately and only from a document in which the vendor says so.

Read from legora.com on 2026-09-19, from the page the vendor titles “Pre-approved Sub-processor - EU”. Every entry above is a verbatim span of that page.

This is the vendor’s own disclosure, reproduced. Vannus has not audited what any of these companies do with your data, and a list can change without notice. Treat it as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Compliance the vendor states
ISO 42001ISO 27001SOC 2GDPR

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this entry is set

Vannus records, from the vendor's own published documents, the legal entity a customer contracts with, the country that entity sits in, and the governing law of its terms — and whether the vendor runs its own model or resells someone else's. Each finding is quoted to its source and dated, or marked not disclosed where the vendor publishes nothing. No paid placements — affiliate status is walled off from the record, enforced by a test in the build. See the methodology →

Related tools we record
Visit Legora ↗ Check your whole stack →