What we collect
- Account: name, email, timezone, sign-in events (time, IP address, approximate city, device).
- Clients: the case type, urgency, language and party names you give at booking; payment through our processor (we never see full card numbers); ratings you give.
- Attorneys: bar admissions, EOIR number, education, practice areas, languages, rate, biography, photo, phone, address, insurance status, sworn disciplinary declarations, and evidence you submit on request.
- Calendar: if you connect Google Calendar, we read busy/free times and write consultation events. Tokens are encrypted at rest and you can disconnect at any time.
Identity verification and biometric data
Attorneys verify their identity with Didit, a third-party provider, by photographing a government ID and taking a selfie. Didit compares the face on the ID to the selfie. Proxenos Legal does not receive or store the selfie or any facial geometry. We receive and keep the outcome (pass or fail), the name and document type read from the ID, the issuing country and expiry, and the date. Attorneys give explicit written consent before verification starts, and that consent is recorded. Didit's own privacy policy governs its handling and retention. We keep the outcome for as long as the attorney is listed and for 3 years after, to meet our verification obligations.
What we do not do
We do not sell personal information. We do not record consultations. We do not read attorney notes in the ordinary course; they are encrypted at rest. We do not run advertising on the platform.
Who sees what
An attorney sees the booking details you give and the names you list for the conflict check. A client sees the attorney's public profile. Proxenos Legal staff see what is needed to verify attorneys, operate the service and investigate reports. Service providers (video, email, payments, identity verification, calendar) receive only what their function needs.
Your choices
You can update your name, timezone and photo on your profile, disconnect calendars, and ask us to delete your account by emailing privacy@proxenos.legal. Some records are kept after deletion where the law or our verification obligations require it (for example, payment records and attorney verification outcomes).
Security
Sessions are cookie-based, HttpOnly and SameSite. Uploads are checked by content. Sensitive tokens and attorney notes are encrypted at rest with keys held by the server. Every administrative action is logged with who, when and from where.
