Privacy Policy

Last Updated: August 24, 2026

1. Scope and Our Role

This Policy explains how CaseActive LLC ("CaseActive," "we," "us") handles personal information.

We act in two different capacities, and the distinction matters.

As a service provider. When a law firm uses CaseActive, the firm's client and case information is entered and controlled by the firm. We process that information on the firm's instructions in order to provide the Service. The firm decides what is collected, how long it is kept, and who may see it. In this Policy we call that information Customer Data, and the firm is the controller.

If you are a client of a law firm using CaseActive, please contact your law firm about your information. They control it. We will forward any request we receive directly to them.

As a controller. We separately collect information about the firms and individuals who create accounts, visit our website, and contact us. In this Policy we call that Account and Website Data, and we determine how it is used.

2. Information We Collect

2.1 Account and Website Data

CategoryExamples
Account informationFirm name, your name, work email, role, credentials
Billing informationPlan, billing contact, transaction history. Full card details are held by our payment processor, not by us
Usage informationPages viewed, features used, session timestamps, device and browser type, IP address
Support informationCorrespondence with our team
Marketing informationInformation you submit through forms on our website

2.2 Customer Data

Entered by law firms and their clients. Depending on how a firm configures the Service, this may include client and claimant names, contact details and preferred language; case records, statuses, and internal notes; messages, feed posts, and comments between firm and client; uploaded documents, including medical records, police reports, and photographs; intake form responses; executed electronic signatures and signed documents; invoices and payment status; and video call recordings where the firm enables recording.

Customer Data may include Protected Health Information. See Section 6.

3. How We Use Information

Account and Website Data is used to provide and administer the Service, process payments, provide support, secure our systems, communicate about the Service, understand how the Service is used, and comply with legal obligations.

Customer Data is used only to provide the Service to the firm that controls it, and as that firm instructs.

We do not sell personal information. We do not use Customer Data for advertising. We do not use Customer Data to develop, train, or improve our products or any machine learning model. Content submitted to AI drafting features is processed by Amazon Bedrock and is not used to train foundation models.

4. Legal Bases for Processing

Where the UK or EU GDPR applies, we rely on:

  • Contract — to provide the Service to firms that have subscribed
  • Legitimate interests — to secure our systems, prevent fraud, understand usage, and market to business contacts, balanced against their rights
  • Consent — for optional cookies and certain marketing communications
  • Legal obligation — where processing is required by law

For Customer Data, the controlling firm determines the legal basis.

5. Disclosure and Subprocessors

We do not sell personal information and we do not disclose it except as set out here.

5.1 Subprocessors

We use the following third parties to provide the Service. Each is bound by contractual confidentiality and data-protection obligations.

SubprocessorPurposeData processedLocation
Amazon Web Services, Inc.Cloud hosting, storage, content delivery, and backupsAll Customer Data and Account DataUnited States
Amazon Web Services, Inc.SMS delivery for notifications and login codesRecipient phone number, message contentUnited States
Amazon Web Services, Inc.AI drafting of feed posts, replies, and tasks (Amazon Bedrock)Case content submitted for draftingUnited States
Google LLCEmail delivery for notifications and transactional messagesRecipient email address, message contentUnited States
Google LLCAutomated translation of client-facing contentText content submitted for translationUnited States
Google LLCWebsite analyticsWebsite usage data, IP address. No Customer DataUnited States
Zoom Communications, Inc.Video calling and call recordingAudio, video, and recordingsUnited States
Stripe, Inc.Payment processing and subscription billingBilling contact and transaction data. Card details go directly to StripeUnited States

We will give notice of new subprocessors at caseactive.com/subprocessors, and firms may object where required by their agreement with us.

5.2 Other Disclosures

We may disclose information to professional advisers under confidentiality obligations; in connection with a merger, acquisition, or sale of assets, subject to this Policy; where required by law, court order, or valid legal process; and to protect our rights, our users' safety, or the integrity of the Service.

Where we receive a legal demand for Customer Data, we will notify the controlling firm before disclosure unless prohibited by law, so the firm may assert privilege or other objections.

6. Protected Health Information

Personal injury and mass tort matters routinely involve medical records, so Customer Data may include Protected Health Information as defined at 45 C.F.R. § 160.103.

6.1 Our Role. Where a firm uses the Service to create, receive, maintain, or transmit PHI and we have executed a Business Associate Agreement with that firm, we act as a business associate under HIPAA. The BAA governs our handling of PHI and controls over this Policy in the event of conflict.

6.2 Use and Disclosure. We use and disclose PHI only as permitted by the BAA, as required by law, and as necessary for the proper management of our operations. We do not use PHI for marketing and we do not sell PHI.

6.3 Safeguards. We maintain administrative, physical, and technical safeguards as required by the HIPAA Security Rule, including encryption of PHI in transit and at rest, role-based access controls enforced server-side, and access logging.

6.4 Subcontractors. Any subcontractor that creates, receives, maintains, or transmits PHI on our behalf is required to agree in writing to restrictions at least as protective as those in our BAA, consistent with 45 C.F.R. § 164.308(b) and § 164.502(e).

6.5 Breach Notification. We will report to the affected firm any use or disclosure of PHI not permitted by the BAA, and any breach of unsecured PHI, without unreasonable delay and within the timeframes required by 45 C.F.R. § 164.410.

6.6 Access, Amendment, and Accounting. We will make PHI available to the controlling firm as necessary for it to meet its obligations under 45 C.F.R. §§ 164.524, 164.526, and 164.528.

6.7 Transmission Channels. SMS is not encrypted end to end across carrier networks. Notifications sent by SMS are limited to generic alerts, and case content remains accessible only after authenticated sign-in.

7. International Transfers

Our infrastructure is located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.

The Service is offered in a number of languages so that law firms can serve clients who do not read English. Language availability is a product feature and is not an offer of the Service in any particular country. Our customers are law firms practising in the United States.

Where the GDPR applies to a transfer, we rely on Standard Contractual Clauses.

8. Retention and Deletion

Account and Website Data is retained for as long as your account is active and for twelve (12) months afterwards, or longer where required by tax, accounting, or other legal obligations.

Customer Data is retained for as long as the controlling firm's account is active. Cancelling a subscription does not delete Customer Data.

A firm may permanently delete its Hub and all associated data from within account settings. Deletion is irreversible. Data may persist in encrypted backups for up to thirty (30) days, after which it is removed.

A firm may request an export of its Customer Data at any time, including after cancellation, by contacting hello@caseactive.com. We will provide it within ten (10) business days.

9. Security

We maintain safeguards appropriate to the sensitivity of the information we hold, including:

  • Encryption of data in transit and at rest
  • Role-based access controls enforced on the server rather than in the interface
  • Hosting on Amazon Web Services in the United States
  • No standing access by CaseActive personnel to the production database. Our team works against a development environment. Where resolving a support issue requires access to a firm's Hub, we request the firm's permission first.
  • Passwordless client authentication using a one-time code delivered by email or SMS

No system is perfectly secure, and we cannot guarantee absolute security.

We do not currently hold a SOC 2 report.

10. Your Rights

If you are a client of a law firm using CaseActive, contact that firm. They control your information. We will forward requests we receive to them.

If your information is Account and Website Data, and depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your information, to object to processing, and to withdraw consent.

California residents may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined under the CCPA. You will not be discriminated against for exercising these rights.

To exercise any right, contact privacy@caseactive.com. We will respond within the timeframe required by applicable law. We may need to verify your identity.

If you are in the EEA or UK, you may also lodge a complaint with your supervisory authority.

11. Cookies and Analytics

We use cookies and similar technologies for essential site function, to remember your preferences, and to understand website usage through Google Analytics.

You can accept or reject non-essential cookies through our cookie banner. Analytics do not run until you accept.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect their information for our own purposes. Customer Data may relate to minors where a firm represents a minor claimant. In that case the firm is the controller and is responsible for any consents required.

13. Changes to This Policy

We may update this Policy. Material changes will be notified by email or within the Service at least thirty (30) days before taking effect. We will update the "Last Updated" date whenever this Policy changes.

14. Contact

Privacy enquiries:privacy@caseactive.com

Security enquiries:security@caseactive.com

Legal notices:legal@caseactive.com

General enquiries:hello@caseactive.com

CaseActive LLC

1912 Capitol Avenue, Suite 500

Cheyenne, WY 82001, United States