Empowering legal professionals and legal technologists to effectively manage the risks of AI development and use through ISO frameworks
In order to manage the whole range of risks (data privacy, cybersecurity, accuracy, intellectual property) arising from AI, your team needs a robust yet comprehensible framework. ISO/IEC 42001:2023 will greatly simplify and clarify your team's AI risk management efforts. It is the only certifiable international standard on responsible AI, applicable globally and well-aligned with important regulations and frameworks like the EU AI Act and NIST AI Risk Management Framework.
Complimentary 45-minute briefings designed to educate in-house legal teams, law firms and legal technology companies on AI risk management and to assess compatibility of ISO frameworks with the team's legal workflows
Live virtual workshops conducted for in-house legal teams, law firms and legal technology companies, at all three levels:
1. Employee awareness
2. Implementation of the AI management system
3. Internal audit of the AI management system
AVAILABLE IN Q4 2026.
On-demand courses licensable to in-house legal teams, law firms and legal technology companies, at all three levels:
1. Employee awareness
2. Implementation of the AI management system
3. Internal audit of the AI management system
A legal AI risk management edtech company, LAIRisk’s mission is to empower legal professionals and technologists to effectively address risks arising from the development and use of AI - specifically by understanding, applying and getting certified under ISO frameworks.LAIRisk (previously branded as singuLAWrity) is a Microsoft for Startups partner (Level 3) and is registered in both Singapore and the European Union - both signatories of the EU-Singapore Digital Trade Agreement.
European Union (Estonia) legal entity:
Singulawrity OÜ
Registry Code: 17127242
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia
Singapore legal entity:
Singulawrity Pte. Ltd.
UEN: 202207374G
Address: 77 High Street, #10-12B, High Street Plaza, Singapore 179433
Matthew Seet is the author of 4 books published/forthcoming by both legal and technology publishers, including the complete 3-book trilogy on the ISO 27001/27701/42001 trifecta published/forthcoming by Springer Nature (Apress), and The Risks of Artificial Intelligence in Law to be published by Globe Law and Business and distributed by Simon & Schuster.Matthew obtained his Master’s in International Law from the Graduate Institute of International and Development Studies in Geneva on a Swiss Government Scholarship, and is certified as an Artificial Intelligence Governance Professional (IAPP), ISO/IEC 42001:2023 Artificial Intelligence Management Systems Lead Auditor, ISO/IEC 27001:2022 Information Security Management Systems Lead Auditor and ISO 31000:2018 Lead Risk Manager.Matthew was formerly an international law lecturer at the National University of Singapore where he taught law for 7 years. His human rights writings have been published in the Cambridge Law Journal, Journal of International Criminal Justice, Citizenship Studies and International Journal of Refugee Law, cited in the Financial Times, and awarded the 2017 Foundation for the Development of International Law in Asia Prize for Young Scholars.Matthew also recently served as the board secretary of Sandbox, managing all legal and compliance matters of this Switzerland-registered global community of over 1600 entrepreneurs and creators, and previously conducted research on human rights and data privacy at the Office of the United Nations High Commissioner for Refugees headquarters in Geneva for over a year, and represented Switzerland in the Philip C. Jessup International Law Moot Court Competition.
Privacy PolicyLast updated: 14 March 2026IntroductionLAIRisk ("we," "our," or "us") is registered in both the European Union and Singapore. It is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or provide your information through our landing page. It also outlines your rights under applicable data protection laws.Information We CollectWe collect the following personal information when you voluntarily provide it to us:
- First Name
- Email address
- Company name
- Professional title
- Country of operation
- Any additional information you choose to provide (e.g. phone number)
- Technical data (IP address, browser type, device information)
- Usage data (pages visited, time spent on pages)How We Use Your InformationWe use your personal information for the following purposes:
- To send you updates about legal AI risk management.
- To provide you with information about our training courses and other relevant products.
- To communicate with you about our services, including responding to inquiries
- To improve our services, website, and customer support based on user feedback
- To comply with legal obligations and resolve disputes, if necessary
- To detect and prevent fraud or security breachesRecipients of Your Data:Your personal data may be shared with the following categories of recipients:
- Service Providers: Cloud hosting providers (Amazon Web Services - EU Region), Email service providers (SendGrid - EU Region), Learning Management System providers (LearnDash - EU Region), Payment processors (Stripe - EU Region)
- Professional Advisers: Legal advisors, Accountants, Auditors
- Authorities: Government bodies when required by law, Regulatory authorities, Law enforcement agencies when legally requiredLegal Basis for Processing:We process your personal data on the following legal grounds:
- Your Consent (Article 6(1)(a) GDPR): For sending marketing communications and placing non-essential cookies on your device. You may withdraw your consent at any time.
- Performance of a Contract (Article 6(1)(b) GDPR): When you purchase our courses, we process your information to fulfill our contractual obligation to provide you with access to the course materials and certification.
- Legitimate Interests (Article 6(1)(f) GDPR): We process data to improve our services, maintain security, and manage customer relationships, as we have a legitimate interest in running our business efficiently and securely. We have balanced our interests against your rights and freedoms.
- Compliance with a Legal Obligation (Article 6(1)(c) GDPR): We process financial data to comply with tax and accounting laws.Data RetentionWe maintain different retention periods for different types of personal data.
- Contact Information - 3 years - - Customer service and marketing
- Course Progress - 5 years - Certification verification
- Financial Records - 7 years - Legal requirement
- Technical Logs - 90 days - Security monitoring
- Marketing Preferences - Until opt-out - Ongoing communicationThese retention periods are reviewed annually to ensure we are not holding data longer than is necessary.After these periods, we will either:
Securely delete your data using industry-standard deletion protocols
Anonymize your data by removing all identifying information
Aggregate your data for analytical purposesYour Rights Under GDPRYou have the following rights regarding your personal data:
- Right to access your personal data
- Right to rectification of inaccurate or incomplete data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaintTo exercise these rights, please email our data protection officer whose details are included below.International Data TransfersWe transfer data to the following countries outside the EEA:
United States: Data is transferred to service providers such as AWS and SendGrid. We ensure protection through the use of EU Standard Contractual Clauses (SCCs) and supplementary measures.
Singapore: Used for backup storage. We ensure protection through the implementation of robust security measures and contractual clauses that align with GDPR principles, in the spirit of the EU-Singapore Digital Trade Agreement.
Switzerland: Used for analytics. Data transfers are protected under the European Commission's adequacy decision for Switzerland.Data Security and Breach ProceduresWe implement comprehensive security measures:Technical Measures:
- 256-bit encryption for data in transit and at rest
- Multi-factor authentication
- Regular security patching
- Intrusion detection systems
- Regular penetration testingOrganizational Measures:
- Regular staff training on data protection
- Access control based on need-to-know
- Regular security audits
- Documented security proceduresBreach Response:
- Detection within 24 hours
- Internal assessment within 48 hours
- Notification to authorities within 72 hours if required
- Affected user notification within 72 hours if high risk
- Post-incident analysis and improvement implementationAutomated Decision MakingWe engage in the following automated processing:
- Course progress tracking
- Certification eligibility assessment
- Learning path recommendationsYou can request human intervention, express your point of view, and contest any
automated decisions by contacting our Data Protection Officer.Cookies and Similar TechnologiesOur website uses cookies and similar tracking technologies to ensure the best experience on our site. These technologies include cookies, pixel tags, and web beacons. Here's a detailed explanation of the types of cookies we use and how you can manage them:Types of Cookies We Use:A. Essential Cookies
Purpose: Enables core website functionality, such as security, session management, and accessibility. Cannot be disabled.
Duration: Session-based cookies that expire when you close your browser.
Required?: Yes.B. Analytics Cookies
Purpose: Helps us understand how visitors interact with our website by collecting and reporting information anonymously.
Duration: 90 days
Required?: No.C. Marketing Cookies
Purpose: Used to track visitors across websites to display relevant and engaging ads.
Duration: 180 days
Required?: No.How We Use Cookies:We use cookies for the following purposes:
- To ensure website functionality: Some cookies are essential to ensure the website operates properly. For example, they help us maintain your session, remember preferences, and protect the security of the website.
- To collect performance and analytics data: Cookies allow us to analyze user behavior and improve the website’s performance based on how visitors use it.
- To deliver personalized content and marketing: Cookies enable us to provide more tailored experiences, including personalized ads and content based on user behavior and preferences.Managing Cookies:You can control and manage cookies using your browser settings. Most browsers allow you to refuse cookies or delete existing ones. The process depends on the browser you are using, but the following links provide instructions on how to manage cookies in popular browsers:
- Google Chrome
- Mozilla Firefox
- Safari
- Microsoft EdgePlease note that blocking or deleting cookies may affect your experience on our site, and certain features may not work as intended.Cookie Duration:
- Session cookies: These are temporary and are deleted when you close your browser.
- Persistent cookies: These cookies remain on your device for a specified period or until you manually delete them.Supervisory AuthorityYou have the right to lodge a complaint with a data protection authority in your country.Changes to This Privacy PolicyWe will notify you of significant updates by email or through a prominent notice on our
website.Contact Us:Legal Entity (EU - Estonia):
Singulawrity OÜ
Registry Code: 17127242
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, EstoniaLegal Entity (Singapore):
Singulawrity Pte. Ltd.
UEN: 202207374G
Address: 77 High Street, #10-12B, High Street Plaza, Singapore 179433Data Protection Officer:
Matthew Seet, Founder and Director
[email protected]Response Times:General queries: 2 business days
- Data subject requests: 30 days
- Breach notifications: 72 hours
- Complaint responses: 5 business days