Claire Legal Malta - Privacy Notice

Status: staging draft, not final public policy

What Claire Is

Claire Legal Malta is a Codex plugin/MCP assistant for Malta and EU legal/regulatory research, drafting support, obligation registers, and human-review handoffs. It is not a public web user portal.

Data Processed

Claire processes prompts, tool arguments, OAuth account identifiers, tenant identifiers, entitlement status, support requests, draft work-product metadata, audit events, and submitted source references needed to operate the requested tool.

Sensitive Data Boundary

Confidential uploads and saved matter files remain restricted until DPIA, retention, and security approvals are complete. Users should minimize personal data and avoid submitting unnecessary special-category, criminal-offence, migration, health, employment, family, or financial information.

Storage and Tenancy

Authenticated work product follows tenant-scoped processing and tenant-scoped storage. Raw MCP bearer tokens, Google client secrets, admin tokens, connector credentials, and credential JSON are not stored in the repository. Audit logs store operational metadata and evidence references rather than broad raw prompts.

Account Controls

Authenticated users can request account export at /account/export and can submit a deletion request at /account/deletion-request. Deletion is human-reviewed because legal, professional, audit, billing, and security records may be subject to retention duties.

External Services

Google OAuth is used for login once configured. Cloudflare hosts the Worker, D1 database, and R2 work-product storage. Advanced institutional connectors require approved data-access basis, connector credential custody evidence, and smoke-test evidence before public go-live.

Professional Boundary

Codex plugin/MCP assistance only: draft legal/regulatory research and work-product support for authenticated users, with advanced workflows restricted to vetted institutional tenants. No public web user portal, final legal advice, client acceptance, conflict clearance, filing, authority contact, STR/SAR, payment, or external delivery.

Policy Pack

Delivery surface: Codex plugin/MCP only. Public web user portal: none.