Trust Center / Privacy

Privacy terms for operational case data.

A structured privacy policy for workspace records, collaboration data, support communications, billing metadata, and controlled AI-assisted processing.

Legal

Privacy Policy

This policy explains who is responsible for personal data in Caseflow and Family Portal, what we process, why we process it, where it goes, and how to exercise privacy rights.

Last updated: August 28, 2026

1. Scope and Our Privacy Roles

This Privacy Policy applies to the Caseflow website, professional workspace, installable web app, Family Portal, support channels, and related services (together, the Service). It covers account holders, workspace members, invited collaborators, family contributors, support contacts, website visitors, and people whose information is included in customer or family content.

For account administration, direct billing, security, product communications, public support, and website operations, the Caseflow service provider identified in the applicable order, invoice, or Legal Notice acts as controller. For case files, investigation records, client information, family-project content, and other material submitted by an organization, the customer generally acts as controller and Caseflow acts as processor under the customer’s instructions. Customers are responsible for giving required notices and establishing a lawful basis for that content.

2. Personal Data We Process

Depending on the features used, we process:

  • Account and identity data: name, email, authentication identifiers, profile photo, organization, role, professional details, language, preferences, and verification or recovery information.
  • Customer and family content: cases, investigations, contacts, tasks, notes, messages, correspondence, email and fax content, documents, evidence, financial and billing records, inheritance and estate records, family relationships, stories, photographs, recordings, and family-book material.
  • Sensitive content: information in professional or family records may reveal health, ethnicity, religion, political views, trade-union membership, sex life or orientation, biometric or genetic information, criminal allegations or convictions, children’s data, financial information, or other confidential matters. We do not require these categories unless the selected workflow needs them.
  • Collaboration and sharing data: invitations, roles, permissions, access grants, public-link settings, task assignments, Caseflow Connect posts, comments, direct messages, delivery status, and audit history.
  • Integration and communication data: OAuth tokens, mailbox settings, email metadata and attachments, fax numbers and transmissions, accounting connection metadata, WhatsApp delivery metadata, push-subscription endpoints, support requests, and replies.
  • Billing data: plan, billing cycle, storage add-ons, customer and subscription IDs, invoices, transaction status, billing address, tax information, and limited payment metadata. Card data is handled by the payment provider and is not stored directly by Caseflow.
  • Device, usage, and security data: IP address, timestamps, session and login events, browser and device information, feature use, diagnostic events, consent or preference state, App Check/reCAPTCHA signals, and local app state used for security and reliability.
  • AI data: prompts, selected case fields, permitted document excerpts or uploads, extracted text, audio submitted for transcription or speech features, generated output, model and token metadata, redaction status, confirmation records, and safety or audit metadata.

3. Where Data Comes From

We receive data from you; your employer, organization, project owner, or collaborators; people who communicate with a connected mailbox, fax number, support channel, or shared link; configured integrations; service providers; and automatically from devices and use of the Service. Customers may also import records from files or third-party systems.

4. Purposes and Legal Bases

  • Contract: to create accounts, provide workspaces, process files, enable collaboration, deliver Family Books, administer subscriptions, and provide requested support or integrations.
  • Legitimate interests: to secure and improve the Service, prevent abuse, understand performance, communicate operational information, defend legal claims, and administer our business, balanced against affected rights.
  • Legal obligations: to maintain tax and accounting records, respond to valid legal process, meet security and compliance duties, and protect rights and safety.
  • Consent: where required for device access, optional communications, non-essential storage, or particular processing. Consent can be withdrawn without affecting earlier lawful processing.
  • Customer instructions: when we process customer content as a processor. The customer determines the lawful basis, including any Article 9 or Article 10 GDPR condition for sensitive or criminal-offence data.

5. AI-Assisted Processing

Caseflow offers clearly identified AI-assisted features, including Copilot Bob, document intelligence, indexing and retrieval, extraction, summaries, drafting, transcription, speech, and proposed actions. An authorized user initiates these features. Caseflow validates access, selects or prepares relevant context, sends the request through backend services, and returns an assistive output for human review.

Caseflow does not use AI output to make solely automated decisions that produce legal or similarly significant effects on people. Generated material may be incomplete or wrong and must be checked against source records. High-risk or write-capable actions supported by the product require confirmation and remain the user’s professional responsibility.

OpenAI currently states that API data is not used to train its models by default unless the customer opts in. Standard API processing may include abuse-monitoring retention for up to 30 days, and some API features can retain application state. Caseflow does not promise zero retention or regional processing unless the relevant deployment and contract expressly provide it.

6. Recipients and Disclosures

We do not sell personal data or use customer content for cross-context behavioral advertising.

  • Authorized workspace members, invited collaborators, family contributors, assignees, public-link recipients, or Caseflow Connect participants according to the permissions and sharing choices in use.
  • Infrastructure, authentication, storage, security, communications, payment, AI, document-processing, and support providers listed on the Subprocessors page.
  • Customer-directed integration providers such as email, accounting, fax, messaging, or OAuth services when an authorized user connects or uses them.
  • Professional advisers, auditors, insurers, authorities, or courts where necessary to meet obligations, protect rights, or respond to valid legal process.
  • A successor or transaction participant in a merger, financing, reorganization, sale, or similar event, subject to appropriate confidentiality safeguards.

7. International Transfers

The Service uses providers and infrastructure in more than one country. Core Firebase and Cloud Functions workloads are currently configured in the United States, while some email infrastructure is configured in the European Union. Optional providers may process data in other regions.

Where EEA, UK, or Swiss personal data is transferred to a country without an adequacy decision, the relevant exporter uses an approved transfer mechanism where required, such as Standard Contractual Clauses, the UK addendum or equivalent safeguards, together with technical and organizational measures. Data residency is not guaranteed unless expressly stated in an order or deployment record.

8. Retention and Deletion

We retain account and customer content while needed to provide the Service and as directed by the customer or project owner. After deletion or account closure, limited copies may remain temporarily in backups, security records, transaction records, or legal holds until their applicable cycles or obligations expire.

Caseflow AI audit metadata uses a 30-day default engineering retention setting unless an approved deployment setting changes it. Saved AI outputs follow the lifecycle of the record where the user saves them. Provider-side retention follows the provider configuration and contract.

Billing, tax, fraud-prevention, dispute, and security records may be retained for statutory or limitation periods. Customers should export required records before closing an account. Deletion requests remain subject to legal obligations, other people’s rights, and the customer’s controller responsibilities.

9. Security

We use risk-based safeguards designed to protect confidentiality, integrity, and availability. Current controls include authenticated and role-aware access, backend authorization, revoked-token verification on sensitive routes, App Check/reCAPTCHA for supported public flows, upload type and content validation, permission-checked short-lived document links, scoped sharing, audit records, and controlled AI retrieval. No online service can guarantee absolute security.

10. Your Rights and Choices

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; opt out of certain communications; and complain to a competent supervisory authority. You may also ask for information about relevant AI-assisted processing.

  • If your data is in a customer workspace or family project, contact that customer or project owner first; Caseflow will assist them as required.
  • Account owners can use available export and account-closure controls or contact support.
  • We may verify identity and authority before acting, and lawful exceptions may apply.
  • You may complain to the authority where you live or work or where the alleged infringement occurred. EEA users may identify their authority through the European Data Protection Board’s authority directory.

11. Children and Family Records

Accounts are for adults and authorized professional users, not children. Family projects and case files may contain information about minors only where the submitting adult or customer has authority and an appropriate lawful basis. Project owners should limit access and avoid publishing sensitive information about living relatives without permission.

12. Changes and Contact

We may update this policy when the Service, providers, or law changes. We will update the date above and provide additional notice where required. Material changes do not reduce contractual data-protection commitments without following the applicable agreement.

For rights requests, privacy questions, security reports, or AI data-handling concerns, use the public Support page or the in-app Support Center.

Caseflow public contact: Atul Goel · Wittenkamp 24, 22307 Hamburg, Germany · +49-15560061837 · info@caseflow.my.