initioby Slipstream

PRIVACY POLICY

Initio

A Product of Slipstream Automation LLC

Effective Date: August 31, 2026

1. Introduction and Scope

This Privacy Policy ("Policy") describes how Slipstream Automation LLC, an Oregon limited liability company ("Company," "Slipstream," "we," "us," or "our"), collects, uses, stores, discloses, and protects information in connection with the Initio client intake automation platform (the "Service").

This Policy applies to: (a) subscribing attorneys and law firms who use the Service ("Subscribers"); (b) the prospective and current clients of Subscribers whose personal information is collected, processed, or transmitted through the Service ("End-Clients"); and (c) other individuals whose names a Subscriber records in or uploads to the Service for conflict-screening purposes, including individuals who have never interacted with the Service and have no relationship with the Company ("Recorded Parties"). This Policy is incorporated into and governed by the Initio Terms of Service.

By subscribing to or using the Service, Subscribers acknowledge and agree to the practices described in this Policy. Subscribers are responsible for informing their End-Clients about the collection and processing of their information through the Service and for providing End-Clients with access to this Policy or a comparable notice as required by Applicable Law.

2. Definitions

Capitalized terms used in this Policy have the meanings assigned to them in the Initio Terms of Service, unless otherwise defined herein. Additional definitions applicable to this Policy include:

"Automatically Collected Data" means information collected through automated means in connection with the Service, including but not limited to log data, device information, IP addresses, browser type, and usage analytics.

"Cookies" means small data files placed on a device by a web server, used to store preferences, session information, or tracking identifiers.

"Processing" means any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

3. Data Controller and Processor Roles

3.1 Subscriber as Data Controller

For the purposes of applicable data protection laws, the Subscriber is the Data Controller with respect to End-Client Data. The Subscriber determines the purposes and means of processing End-Client Data and is responsible for ensuring that such processing complies with all Applicable Law, including obtaining any necessary consents or providing required notices to End-Clients.

3.2 Slipstream as Data Processor

Slipstream Automation LLC acts as a Data Processor with respect to End-Client Data, processing such data solely on behalf of and in accordance with the documented instructions of the Subscriber, as further specified in the Data Processing Agreement. Slipstream does not determine the purposes or means of processing End-Client Data independently.

3.3 Slipstream as Data Controller

Slipstream Automation LLC acts as a Data Controller with respect to: (a) Subscriber account and billing information; (b) information provided by Subscribers during onboarding; and (c) Aggregated Data as defined in the Terms of Service.

4. Information We Collect

4.1 Subscriber Information

We collect the following information directly from Subscribers in connection with account creation, onboarding, and billing:

  1. (a)Full name and professional title;
  1. (b)Law firm name and business address;
  1. (c)Email address and phone number;
  1. (d)Bar admission number and licensing jurisdiction(s);
  1. (e)Billing and payment information;
  1. (f)Practice area(s) and service preferences; and
  1. (g)Authentication credentials and session data managed by our authentication provider (Clerk).

4.2 End-Client Personal Information

Through the Service's automated intake workflows, the following categories of End-Client Personal Information may be collected on behalf of Subscribers:

  1. (a)Full name;
  1. (b)Email address;
  1. (c)Phone number;
  1. (d)Mailing address;
  1. (e)Date of birth;
  1. (f)Marital status, spouse information, and dependent/children information;
  1. (g)Description of legal matter, including facts and circumstances relevant to the potential representation;
  1. (h)Financial information relevant to the legal matter or fee arrangements;
  1. (i)Health and medical information, including information relevant to personal injury, family law, or other practice areas where such information is pertinent;
  1. (j)Information specific to the End-Client's case type and the Subscriber's practice area, including but not limited to family law, estate planning, and personal injury matters;
  1. (k)Engagement letter content and electronic signature data collected through our document generation provider (PandaDoc); and
  1. (l)Any other information voluntarily provided by the End-Client through the intake process.

4.3 Automatically Collected Data

When End-Clients or Subscribers interact with web-facing components of the Service (such as intake forms or scheduling pages), the following categories of information may be automatically collected as a consequence of standard web-server operation by our hosting Sub-Processors (Vercel and Render):

  1. (a)IP address;
  1. (b)Browser type and version;
  1. (c)Device type and operating system;
  1. (d)Referring URL and pages visited; and
  1. (e)Date, time, and duration of visit.

Analytics on Public Marketing Pages. The Company uses PostHog to measure aggregate traffic on the public marketing pages of initio.legal (such as the home, product, and pricing pages). As configured by the Company, this measurement is cookieless and anonymous: it sets no cookies, creates no persistent identifier, does not store IP addresses, performs no cross-site or cross-device tracking, and reports only aggregate statistics such as page views, referring sites, campaign parameters, approximate location, and browser and device type. Analytics data is processed and stored by PostHog in the United States. No End-Client Personal Information and no Subscriber account information is collected by, or transmitted to, this marketing measurement.

Product Analytics on Authenticated Surfaces. The Company also uses PostHog to understand how Subscribers use the authenticated surfaces of the Service (the onboarding flow, the attorney dashboard, and the setup guide). These usage analytics are associated with the Subscriber's account and cover the Subscriber's own use of the Service, such as the pages visited and features used. They do not include session recording, keystroke or input capture, or the content of any form field, and no End-Client Personal Information is collected by, or transmitted to, the analytics service.

Analytics measurement of any kind runs on no surface used by End-Clients: it is not loaded on intake forms, inquiry forms, or scheduling pages. Apart from the analytics described in this Section 4.3, the Service does not deploy any third-party analytics tools or interaction-tracking instrumentation. If the Company adds further analytics tooling to the Service, or extends analytics to any additional surface of the Service, the Company will update this Section 4.3 and Section 14 (Cookies) before the tooling is deployed.

4.4 Recorded Party Information

The Service includes a conflict-screening feature that matches the names of incoming prospective clients against a list of parties associated with the Subscriber's practice. To operate that feature, the Service stores a record for each such party, consisting of: (a) the party's name; (b) a normalized form of that name used for matching; (c) a role, which is one of client, prospect, adverse party, or related party; (d) an optional relationship label (for example, opposing party, spouse, or prior attorney); and (e) internal references recording how the record entered the Service.

No other information about a Recorded Party is stored. These records contain no email address, telephone number, mailing address, date of birth, or description of any legal matter.

Recorded Party records enter the Service in four ways: (a) a Subscriber uploads a list of names directly, by pasting it into the Service's Parties page; (b) the Service records the parties named on an intake form when a prospective client submits one; (c) the Service records the client when a matter is created; and (d) Company personnel may perform a one-time population of a Subscriber's party list from records that Subscriber already holds in the Service.

Records created under (a) and (d) may include individuals who have never contacted the Company, never submitted information to the Service, and have no relationship with the Company — including a Subscriber's former clients and parties adverse to a Subscriber's clients. Recorded Party records are stored separately for each Subscriber and are never used to screen on behalf of any other Subscriber.

5. How We Collect Information

We collect information through the following methods:

Intake Forms: End-Client Personal Information is collected through automated intake forms completed by End-Clients as part of the Subscriber's client intake process.

Email Communications: The Service sends and receives automated email communications on behalf of Subscribers via our email provider (Resend). Information contained in these communications is processed as part of the intake workflow.

Scheduling: When End-Clients book consultation appointments through the Service, scheduling information is collected and processed via our self-hosted scheduling platform (Cal.com).

Payment Processing: When applicable, payment information is collected and processed through our payment Sub-Processor (Confido Legal). Retainer and fee payments are routed directly to the Subscriber's designated IOLTA trust account. Slipstream does not hold, manage, or have access to trust account funds. Slipstream does not directly store credit card numbers or bank account information.

Document Generation: Engagement letters and related documents are generated and executed through our document Sub-Processor (PandaDoc). This includes the collection of electronic signature data from both Subscribers and End-Clients.

Onboarding and Account Management: Subscriber information is collected directly from Subscribers during onboarding consultations and ongoing email communications.

Automated Collection: Automatically Collected Data may be gathered through server logs, cookies, or similar technologies when individuals interact with web-facing components of the Service.

6. Purpose of Processing and Lawful Bases

6.1 Purposes

We process information for the following purposes:

  1. (a)To provide, operate, and maintain the Service on behalf of Subscribers;
  1. (b)To automate client intake workflows, including lead capture, communication, scheduling, document generation, and payment processing;
  1. (c)To generate AI-powered communications (including automatically sent inquiry response emails) and intake analysis summaries on behalf of Subscribers (see Section 7A);
  1. (d)To communicate with Subscribers regarding their account, service updates, and support;
  1. (e)To process payments and manage billing;
  1. (f)To comply with Applicable Law and respond to legal process;
  1. (g)To detect, prevent, and address fraud, security incidents, and technical issues;
  1. (h)To generate Aggregated Data for product improvement, analytics, and benchmarking; and
  1. (i)To enforce our Terms of Service and protect the rights, property, and safety of the Company, Subscribers, and End-Clients; and
  1. (j)To screen the names of prospective clients against the parties recorded for a Subscriber, in order to identify potential conflicts of interest for that Subscriber's review.

6.2 Lawful Bases for Processing

To the extent required by Applicable Law, our processing of Personal Information is based on one or more of the following lawful bases:

Performance of a Contract: Processing is necessary for the performance of our agreement with Subscribers (the Terms of Service and DPA).

Legitimate Interests: Processing is necessary for the legitimate interests of the Company or Subscribers, including the provision of the Service, fraud prevention, and security, where those interests are not overridden by the data subject's rights.

Legal Obligation: Processing is necessary for compliance with a legal obligation to which the Company is subject.

Consent: Where required by Applicable Law, processing is based on the data subject's consent, which may be withdrawn at any time.

7. Sub-Processors and Third-Party Services

The Service relies on the following third-party Sub-Processors to perform specific functions. Each Sub-Processor processes End-Client Data only as necessary to provide its designated function on behalf of the Subscriber, except for the two services this table identifies as processing no End-Client Data at all — Stripe, which processes the Company's own subscription-billing information, and PostHog, which measures traffic on the Company's public marketing pages and Subscribers' own use of the Service:

Sub-ProcessorFunctionData AccessedPrivacy Policy
SupabaseDatabase hosting (Postgres with Row Level Security)All application data, multi-tenant isolated via firm-level scopinghttps://supabase.com/privacy
ClerkAuthentication and session managementSubscriber credentials, session tokenshttps://clerk.com/legal/privacy-policy
StripeSubscription billing (card processing, customer accounts, invoicing, refunds)Subscriber billing identifiers, payment-method metadata (cardholder name, last 4 digits, expiration via Stripe Elements — no full card number stored by the Company), subscription and invoice recordshttps://stripe.com/privacy
ResendTransactional email deliveryEmail addresses, names, message contenthttps://resend.com/legal/privacy-policy
Confido LegalIOLTA-compliant payment processing for End-Client retainer and fee paymentsPayment amounts, payer names, trust account routing datahttps://gravitylegal.com/privacy-policy
PandaDocDocument generation and e-signaturesEngagement letter content, signer names, signature datahttps://www.pandadoc.com/privacy-notice/
Cal.com (self-hosted on Company-controlled Render infrastructure)Scheduling and appointment bookingNames, email, phone, appointment datahttps://cal.com/privacy
AWS (Amazon S3)Document and file storageMatter documents, generated fileshttps://aws.amazon.com/privacy/
Anthropic (Claude API)AI text processing (see Section 7A)Inquiry text, intake form datahttps://www.anthropic.com/legal/privacy and https://www.anthropic.com/legal/commercial-terms
RenderAPI server hosting (data in transit and in process memory; no application data at rest)API traffic, server logshttps://render.com/privacy
VercelFrontend hosting (CDN) — static assets only, no personal information at restWeb request logs from intake form and dashboard page loadshttps://vercel.com/legal/privacy-policy
PostHogAggregate traffic measurement on public marketing pages and product-usage analytics on authenticated Subscriber surfaces (cookieless as configured; no cross-site tracking; processed and stored in the US)No End-Client Data — anonymous aggregate marketing statistics (page views, referring sites, campaign parameters) and Subscriber usage events; IP addresses are not storedhttps://posthog.com/privacy

We require each Sub-Processor to process Personal Information in accordance with appropriate data protection standards. The table above is current as of the Effective Date of this Privacy Policy; Sub-Processors may be added or replaced from time to time, in which case this Section 7 will be updated and Subscribers will be notified of material changes in accordance with Section 20. A complete list of current Sub-Processors is also maintained in Annex C of the Data Processing Agreement.

7A. Artificial Intelligence Processing

The Service uses artificial intelligence (currently Anthropic's Claude) to perform specific automated functions on behalf of Subscribers:

(a) Inquiry Response Generation. When a prospective End-Client submits an inquiry through a Subscriber's intake form, the Service uses AI to generate a personalized email response and sends it to the prospective End-Client automatically on the Subscriber's behalf, without per-message Subscriber review. The AI processes the inquiry text, including the prospective client's name, contact information, and description of their legal matter, to produce a contextually relevant response.

(b) Intake Analysis. When an End-Client completes a full intake form, the Service uses AI to generate a consultation preparation summary for the Subscriber. The AI processes the submitted intake data — which may include legal matter details, financial information, family information, and health information — to produce an analytical brief highlighting key case considerations, potential conflicts, and strategic notes. Where the conflict-screening feature described in Section 4.4 identifies a potential match, the matched Recorded Party's name, role, and relationship label are included in the information transmitted to the AI provider as part of this analysis. A Recorded Party's name is transmitted to the AI provider only where it matches a name on a submitted intake form; names that do not match are not transmitted.

Data Handling: Data transmitted to the AI provider is used solely for the purpose of generating the requested output. The Service uses the Anthropic Claude API under Anthropic's Commercial Terms of Service, which provide that Anthropic will not train its models on inputs or outputs submitted through the API. Under Anthropic's published data-retention terms for commercial API use, inputs and outputs are deleted from Anthropic's systems within thirty (30) days by default, except where longer retention is required to enforce Anthropic's usage policy (for example, content flagged for a suspected policy violation may be retained for up to two years) or to comply with legal obligations. Subscribers should be aware that End-Client Data is transmitted to a third-party AI provider as part of the Service and should account for this in their own client disclosures.

Automation and Subscriber Oversight: Some AI-generated content is sent automatically. The inquiry response email described in (a) is generated and sent to the prospective End-Client by the Service without per-message Subscriber review. The intake analysis summary described in (b) is provided to the Subscriber and is not communicated to End-Clients by the Service. The Subscriber is responsible for configuring and supervising these automated workflows, for the content of any templates and settings the Subscriber controls, and for reviewing, editing, and approving any AI-generated content before the Subscriber relies upon it.

Subscriber Consent Responsibility: The Subscriber, as the attorney and Data Controller, is solely responsible for obtaining any End-Client informed consent that the Subscriber's rules of professional conduct or Applicable Law require before representation information is input into a generative AI tool, and for independently confirming that the AI provider's terms satisfy the Subscriber's obligations. The disclosures in this Section 7A are informational and do not satisfy or substitute for that consent or vetting duty.

8. Data Storage and Security

8.1 Storage

End-Client Data is stored in cloud-hosted database and storage infrastructure managed by our Sub-Processors. Primary data storage is provided by Supabase (database) and Amazon Web Services S3 (documents and files). All primary data storage is located within the United States.

8.2 Security Measures

We implement and maintain commercially reasonable technical and organizational measures designed to protect Personal Information against unauthorized access, disclosure, alteration, or destruction. These measures include:

  1. (a)Encryption of data in transit using TLS/SSL protocols;
  1. (b)Encryption of data at rest where supported by Sub-Processors;
  1. (c)Multi-tenant data isolation enforced at the database level using row-level security policies, ensuring that each Subscriber's data is logically separated and inaccessible to other Subscribers;
  1. (d)Access controls limiting data access to authorized personnel on a need-to-know basis;
  1. (e)Authentication and session management via Clerk, an industry-standard authentication provider;
  1. (f)Structured error logging and monitoring of system access and data processing activities; and
  1. (g)Regular review of Sub-Processor security practices and certifications.

Detailed technical and organizational measures are set forth in Annex B of the Data Processing Agreement.

8.3 No Absolute Security

While we strive to protect Personal Information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security and are not liable for unauthorized access that occurs despite our commercially reasonable security measures.

9. Data Retention and Deletion

9.1 Retention Periods

End-Client Data is retained for the duration of the Subscriber's active subscription to provide the Service. Subscriber account and billing information is retained for as long as necessary to provide the Service and comply with legal, tax, and accounting obligations. Payment records may be retained for up to seven (7) years to satisfy tax and audit requirements.

9.2 Deletion Upon Cancellation

Upon termination of the Subscriber's subscription, the Subscriber has thirty (30) days to request retrieval of their End-Client Data by contacting the Company at admin@slipstream.works (the "Data Retrieval Period"). Following the end of the Data Retrieval Period — or upon earlier written deletion request from the Subscriber — the Company will delete all End-Client Data from its systems and the systems of its Sub-Processors within thirty (30) days, subject to Section 9.4 (Legal Holds), Section 9.5 (Identifiers Retained After Refund), and Section 9.6 (Deferred External-Service Cleanup).

At launch, the Company does not run an automated retention or deletion process; deletion is initiated and tracked manually by Company personnel upon request. Operator discipline is required to honor the thirty-day commitment in this Section 9.2.

9.3 Anonymization

Where technically feasible, the Company may anonymize End-Client Data rather than deleting it, provided that the resulting data is irreversibly de-identified and cannot be used to identify any individual. Anonymized data is not considered Personal Information and may be retained and used in accordance with Section 9.4 of the Terms of Service.

Notwithstanding the foregoing, the Company may retain Personal Information as necessary to comply with legal obligations, resolve disputes, enforce agreements, or as otherwise required by Applicable Law.

9.5 Identifiers Retained After Refund

If the Subscriber's firm has received a refund of subscription fees under Section 5.5 of the Terms of Service, the Company retains, indefinitely and after deletion of End-Client Data under Section 9.2, a minimal set of identifiers associated with the original subscription. These identifiers are: (a) the email address of the firm owner (the attorney who signed the firm up to the Service); (b) the authentication-account identifier issued to the firm owner by the Company's authentication Sub-Processor (Clerk); and (c) the firm record, marked as refund-banned. The Company uses these identifiers solely to enforce the prohibition on re-subscription set forth in Section 5.5(b)(iv) of the Terms of Service. The Company does not use these identifiers to contact the former firm owner, to deliver marketing communications, or for any other purpose.

The Company's position is that this retention is permitted under Section 9.4 (legal holds and the enforcement of agreements) and under the corresponding exceptions to deletion in the Oregon Consumer Privacy Act and the CCPA/CPRA, which allow a controller to retain Personal Information as reasonably necessary to enforce its agreements and resolve disputes. Accordingly, a right-to-deletion request from a former firm owner under Section 10 will be honored as to all other Personal Information but will receive a documented partial denial as to the three identifiers listed above, citing Section 9.4 and the enforcement-of-agreement basis. The retention is limited to the minimum data necessary to enforce the one-refund-per-firm policy.

9.6 Deferred External-Service Cleanup

At launch, the Company's deletion process under Section 9.2 covers End-Client Data stored in the Company's primary data systems (Supabase, Amazon S3) and Sub-Processors that the Company can deprovision through an automated pathway. The following Sub-Processor data is not auto-deleted on subscription termination at launch and is cleaned up manually on a deferred basis: (a) the Subscriber's scheduling user account and any associated appointment records held in the Company's self-hosted Cal.com instance; and (b) the Subscriber's partner account and any associated payment records held by Confido Legal. The Company will deprovision both on written request to admin@slipstream.works as part of the Section 9.2 deletion process.

9.7 Retention of Recorded Party Information

Recorded Party records are retained for the duration of the Subscriber's active subscription. A Subscriber may delete any individual Recorded Party record, or an entire uploaded batch of them, from the Service's Parties page at any time; deletion removes the record and is written to the Subscriber's audit trail.

Recorded Party records are not automatically deleted when a Subscriber's subscription terminates. They are covered by the same manual deletion process described in Section 9.2, on the same basis and within the same timeframes, subject to Section 9.4 (Legal Holds).

10. Data Subject Rights

Depending on your jurisdiction and applicable law, you may have certain rights with respect to your Personal Information. The rights described below are provided in accordance with the Oregon Consumer Privacy Act (OCPA), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and the General Data Protection Regulation (GDPR) to the extent applicable.

10.1 Rights Under OCPA (Oregon Residents)

If you are an Oregon resident, you have the right to: (a) confirm whether we are processing your Personal Information; (b) access your Personal Information; (c) correct inaccuracies in your Personal Information; (d) delete your Personal Information; (e) obtain a copy of your Personal Information in a portable format; and (f) opt out of the processing of your Personal Information for purposes of targeted advertising, the sale of Personal Information, or profiling in furtherance of decisions that produce legal or similarly significant effects.

10.2 Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the right to: (a) know what categories and specific pieces of Personal Information we have collected about you; (b) request deletion of your Personal Information; (c) request correction of inaccurate Personal Information; (d) opt out of the sale or sharing of your Personal Information (we do not sell Personal Information as defined under the CCPA/CPRA); (e) limit the use and disclosure of sensitive Personal Information; and (f) not be discriminated against for exercising your privacy rights.

10.3 Rights Under GDPR (EEA/UK Residents)

To the extent that the GDPR applies, data subjects have the right to: (a) access; (b) rectification; (c) erasure; (d) restriction of processing; (e) data portability; (f) object to processing; and (g) not be subject to automated decision-making, including profiling, that produces legal or similarly significant effects. Data subjects also have the right to lodge a complaint with a supervisory authority.

10.4 End-Client Rights

Because Slipstream acts as a Data Processor with respect to End-Client Data, End-Clients who wish to exercise their data subject rights should direct their requests to the relevant Subscriber (the Data Controller). Slipstream will cooperate with Subscribers to facilitate the exercise of End-Client rights in accordance with the Data Processing Agreement.

10.5 Recorded Party Rights

The Subscriber determines which individuals are recorded as parties and for what purpose, and is the Data Controller with respect to Recorded Party information. A Recorded Party who wishes to exercise the rights described in Section 10 should direct the request to the relevant Subscriber. Where a Recorded Party contacts the Company directly, the Company will refer the request to the relevant Subscriber and will cooperate with the Subscriber in responding to it, in accordance with the Data Processing Agreement.

11. How to Exercise Your Rights

To exercise any of the rights described in Section 10, please submit a request by contacting us at:

Email: admin@slipstream.works

Mail: Slipstream Automation LLC — mailing address available on request; contact admin@slipstream.works.

We will verify your identity before processing any request. Verification may require you to provide additional information to confirm your identity. We will respond to verified requests within the timeframes required by Applicable Law (generally forty-five (45) days under OCPA and CCPA/CPRA, and thirty (30) days under GDPR, subject to permitted extensions).

You may designate an authorized agent to make a request on your behalf. Authorized agents must provide proof of authorization and we may require the requestor to verify their identity directly with us.

Appeals. If we decline to take action on your request, we will inform you of the reason without undue delay. You may appeal that decision by replying to our determination or by contacting us at admin@slipstream.works with the subject line "Privacy Request Appeal." We will respond to your appeal in writing within forty-five (45) days of receipt, explaining the action taken or the reasons for not taking action. If we deny your appeal, we will provide you with a method to contact the Oregon Attorney General to submit a complaint (consumer privacy complaints may be submitted through the Oregon Department of Justice at https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/ or by calling the DOJ Consumer Hotline at 1-877-877-9392) and, where applicable, the relevant regulator in your state of residence.

12. Cross-Border Data Transfers

The Service is operated from the United States and is intended for use by Subscribers located in the United States. End-Client Data is primarily processed and stored within the United States.

Some Sub-Processors may process data in or transfer data to locations outside the United States. Where data is transferred outside the jurisdiction in which it was collected, we implement appropriate safeguards, which may include Standard Contractual Clauses, adequacy determinations, or other transfer mechanisms recognized under Applicable Law.

13. Children's Privacy

The Service is not directed at children under the age of thirteen (13). We do not knowingly collect Personal Information from children under 13. If the Service collects information about a minor in the context of a legal matter (e.g., in a family law or custody proceeding), such information is collected by the Subscriber in their capacity as the child's legal representative or as part of a representation involving the child's interests, and the Subscriber is responsible for ensuring compliance with the Children's Online Privacy Protection Act (COPPA) and other Applicable Law.

If we become aware that we have collected Personal Information from a child under 13 without appropriate authorization, we will take steps to delete such information promptly.

14. Cookies and Tracking Technologies

The Service uses cookies and similar technologies on web-facing components only to the extent strictly necessary for the basic functionality of the Service. As of the Effective Date of this Privacy Policy, this is limited to:

Strictly Necessary Cookies: Required for the basic functionality of web-facing components, including session management and authentication (cookies set by the Company's authentication Sub-Processor, Clerk) and cookies set by the Company's hosting Sub-Processors (Vercel and Render) for routing and reliability.

The analytics measurement described in Section 4.3 is cookieless. PostHog, as configured by the Company, sets no cookie, writes no persistent identifier to the browser, and stores nothing on the device between visits — on the public marketing pages and the authenticated surfaces alike. It therefore adds nothing to the strictly-necessary category above, and no standalone Cookie Policy is required at this time.

Accordingly, the Service does not use analytics cookies or tracking cookies, does not use cookies for targeted advertising, and does not participate in any cross-site advertising or behavioral-targeting network. If the Company adds analytics or tracking cookies to the Service in the future, the Company will update this Section 14 and Section 4.3 before the additions take effect, and will publish a standalone Cookie Policy at that time. Subscribers and End-Clients may manage cookie preferences through their browser settings; disabling strictly-necessary cookies will limit functionality of web-facing components and may prevent the Service from operating correctly.

15. Do Not Track Signals

Some web browsers transmit "Do Not Track" (DNT) signals. There is currently no industry consensus on how to respond to DNT signals. The Service does not currently alter its data collection or use practices in response to DNT signals, and the analytics measurement described in Section 4.3 — on the public marketing pages and the authenticated surfaces alike — likewise does not respond to DNT signals. If a uniform standard for responding to DNT signals is adopted, we will update this Policy accordingly.

16. Attorney-Client Privilege and Legal Data

The Company acknowledges that End-Client Data processed through the Service may include information protected by attorney-client privilege, work product doctrine, or other legal protections afforded to communications between attorneys and their clients or prospective clients.

The Company has implemented the following safeguards to protect potentially privileged information:

  1. (a)All End-Client Data is treated as confidential regardless of whether it has been formally designated as privileged;
  1. (b)Access to End-Client Data is restricted to authorized personnel with a legitimate need-to-know;
  1. (c)The Company does not review, analyze, or make independent use of the substantive content of End-Client Data, except as necessary to provide the Service (including AI processing as described in Section 7A) or as required by Applicable Law;
  1. (d)The Company will notify the Subscriber promptly if it receives any third-party request or legal process seeking disclosure of End-Client Data, to the extent permitted by law; and
  1. (e)The Company will cooperate with the Subscriber in asserting applicable privileges in response to such requests.

The Subscriber retains sole responsibility for determining which information is privileged and for asserting applicable privileges.

17. Health-Related Information

Subscribers who practice in areas such as personal injury, family law, or workers' compensation may collect health-related information from End-Clients through the intake process. The Company acknowledges that such information may be present in End-Client Data and treats all health-related information with the same confidentiality protections applied to all End-Client Data as described in this Policy and the Data Processing Agreement.

Subscribers who are subject to HIPAA or who regularly process Protected Health Information should consult with healthcare compliance counsel regarding their obligations.

The Company does not offer a HIPAA Business Associate Agreement and does not hold itself out as a Business Associate. As a condition of using the Service, each Subscriber represents and warrants that it is not a HIPAA covered entity or business associate, or that, if it is, it will not transmit, store, or otherwise route Protected Health Information (as defined under HIPAA) through the Service unless and until the Company has executed a separate written Business Associate Agreement with the Subscriber. The Subscriber is solely responsible for ensuring that its use of the Service is consistent with this representation.

18. ABA Model Rule 1.6 Compliance

The Service is designed to support Subscribers' compliance with their professional obligations to protect client confidentiality under ABA Model Rule 1.6 (Confidentiality of Information), as adopted or modified by the Subscriber's licensing jurisdiction.

ABA Model Rule 1.6, Comment [18], recognizes that attorneys must make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. ABA Formal Opinion 477R further addresses an attorney's ethical obligations when transmitting client information electronically.

The Company supports these obligations through: (a) commercially reasonable encryption of data in transit and at rest; (b) multi-tenant data isolation at the database level; (c) access controls and personnel confidentiality obligations; (d) Sub-Processor management with data protection requirements; (e) breach notification within seventy-two (72) hours of confirmation; and (f) cooperation with Subscribers in responding to data subject requests and privilege assertions.

Subscribers remain solely responsible for determining whether the Service's security measures satisfy their specific ethical obligations under applicable rules of professional conduct in their licensing jurisdiction(s).

19. Breach Notification

In the event of a data breach affecting End-Client Data or Subscriber information, the Company shall:

  1. (a)Investigate the incident promptly upon becoming aware of it;
  1. (b)Notify affected Subscribers via email within seventy-two (72) hours of confirming that a breach has occurred;
  1. (c)Provide Subscribers with sufficient information to understand the nature and scope of the breach, including the categories of data affected and the approximate number of individuals affected, to the extent known;
  1. (d)Describe the measures taken or proposed to be taken to address the breach and mitigate its effects; and
  1. (e)Cooperate with Subscribers in complying with any notification obligations the Subscriber may have under Applicable Law.

The Company's breach notification obligations are further detailed in the Data Processing Agreement.

20. Changes to This Policy

The Company reserves the right to modify this Privacy Policy at any time. Material changes will be communicated to Subscribers via email at least thirty (30) days prior to the effective date. For material changes that affect the processing of End-Client Data, we will seek affirmative acknowledgment from Subscribers before the changes take effect. Non-material changes (including typographical corrections, formatting, and clarifications that do not alter the substance of any provision) may be made without prior notice.

The "Effective Date" at the top of this Policy indicates the date of the most recent revision. Continued use of the Service after the effective date of any non-material modification constitutes acceptance of the revised Policy.

21. Contact Information

If you have questions about this Privacy Policy, wish to exercise your data subject rights, or have concerns about our data practices, please contact us at:

Slipstream Automation LLC

Mailing address available on request — contact admin@slipstream.works.

General and Privacy Inquiries: admin@slipstream.works