Este documento está disponible solo en inglés, y la versión en inglés es el texto vigente.
Privacy Policy
Effective date: September 10, 2026
Last updated: September 10, 2026
Esqase, Inc. ("Esqase," "we," "us," or "our") operates a legal practice management platform. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you access or use our Service, including app.esqase.com and all associated sub-domains and applications, and when you visit our marketing website at esqase.com.
This Privacy Policy is referenced in, and incorporated by reference into, our Terms of Service, which is the agreement that governs your use of the Service. It is a notice, not a contract. Where we rely on your consent for a particular use of your information, we ask for it separately and you can withdraw it at any time without affecting what we did before you withdrew it.
1. Scope
This Privacy Policy applies to:
- Firm Users: attorneys, staff members, and administrators who create accounts and use the Service to manage their legal practice.
- Clients and Contacts: individuals whose information is entered into the Service by a Firm (e.g., potential clients, existing clients, contacts).
- Visitors: individuals who visit our marketing website at esqase.com.
- Participants in Public-Facing Features: individuals who interact with a Firm through the Service's public applications, including document signing and document sharing at docs.esqase.com, appointment booking, intake forms, and payment pages. Our Terms of Service calls these individuals External Users.
When you sign a document through our eSignature feature, the Service captures your identity details, IP address, timestamp, and device information to create the signature record. This information, like other information you submit through Public-Facing Features, is processed on behalf of the Firm you are interacting with.
2. Our Roles: Controller and Processor
Esqase acts in two distinct roles depending on the information involved.
2.1 Esqase as Data Controller
We are the data controller for:
- Account data: registration and profile information for Firm Users.
- Billing data: subscription and payment records for your Esqase account.
- Website visitor data: information collected on esqase.com, including analytics data.
- Public-page security data: the access, security, and abuse-protection information described in Section 3.7, which we collect about anyone who visits a page a Firm shares with its clients.
- Product usage analytics: information about how Firm Users navigate and use the Service (for example, which features are used and which lifecycle events occur), which we analyze to understand adoption and improve the platform.
- Marketing and support data: your marketing preferences and your communications with our team.
This Privacy Policy governs our processing of that information.
2.2 Esqase as Data Processor
For Client Data (information a Firm enters into or collects through the Service about its clients, contacts, and matters), Esqase acts as a data processor and the Firm acts as the data controller. Our Data Processing Agreement governs that relationship.
Important: If your information was entered into the Service by a law firm (for example, you are a client or contact of a Firm that uses Esqase), that Firm decides how your information is used. Please direct privacy questions and requests about that information to the Firm. See Section 11.6 for how we handle requests we receive directly.
3. Information We Collect
3.1 Information You Provide
- Account information: Your name (including any prefix and suffix you record), the email address you sign in with, and your password, which we store only as a hash. If you complete your profile later, we also hold the profile photo you upload, the contact channels you record such as a mobile or office number, and the postal addresses you record.
- Firm information: Your Firm's name, size, country, timezone, and currency, and, if you choose to tell us, the software your Firm used before and how you heard about us. Your Firm also records its own contact channels and addresses.
- Subscription and billing: Payment method information processed by our payment provider (Stripe). We do not store full card numbers.
- User Content: All data, documents, notes, messages, and other content you upload or create in the Service, including client contact details, matter information, billing records, documents, and calendar events.
- Communications: Messages you send to our support team.
- Preferences: Settings, notification preferences, and customizations you configure.
- Authentication and security data: If you turn on two-factor authentication, the shared secret for your authenticator app or the one-time codes we email you, and the recovery codes issued to you. We also record sign-in and sign-out events, and the device and network details described in Section 3.2.
3.2 Information We Collect Automatically
- Usage data: Pages visited, features used, actions taken, timestamps, and session duration.
- Device and technical data: IP address, browser type, operating system, device identifiers, and referring URLs.
- Log data: Server logs, error reports, and crash data.
- Abuse-protection signals: When you use our applications, including the public pages a Firm shares with its clients, Google reCAPTCHA Enterprise runs invisibly through Firebase App Check and receives device and interaction signals from your browser so we can tell genuine traffic from automated abuse. It returns a short-lived token that our systems check; it does not identify you to us.
- Push notification tokens: If you allow desktop or browser notifications, we store the notification token your browser or device issues, along with its platform, so we can deliver the notifications you have turned on. Turning notifications off in your browser or in your notification preferences stops us using it.
- Cookies and similar technologies: See Section 7 (Cookies and Tracking Technologies) below.
3.3 Information from Your Firm and Other Sources
- Your Firm: When a Firm invites you as a member, its administrators provide your name and email address so we can set up your account. Firms also provide the information they hold about their clients and contacts; we process that information on the Firm's behalf as described in Section 2.2.
- OAuth providers: If you connect Google (Gmail, Google Calendar, Google Meet), Microsoft (Outlook, Outlook Calendar, Microsoft Teams), or Zoom, we receive your basic account identity and the permissions you authorize. We access these accounts only to provide the features you enable, and you can disconnect them at any time from your Integrations page. What each connection permits differs by provider, and the difference matters: Gmail is send-only, while a connected Outlook mailbox carries both send and read permission so that replies to email you sent from Esqase are recorded against the matter or lead they belong to. Section 3.5 describes the Google permissions and Section 3.6 the Microsoft and Zoom permissions.
- Payment processors: We receive transaction confirmations and payment status from Stripe.
3.4 Analytics on Our Website and Product
We use PostHog to understand how our marketing website at esqase.com and our product applications are used. It records:
- Page views: a single pageview event per page you navigate to, plus a page-leave event when you leave a page. Page addresses and titles are sanitized so they carry no record identifiers or content.
- Product events: a curated set of feature and lifecycle events (for example, a matter being created, an invoice being sent, or an integration being connected). We record only events we have chosen to measure; we do not automatically capture every click, and we never send matter titles, client names, document names or contents, message text, search queries, or form answers.
- Device and browser data: browser type, operating system, referring pages, and approximate location derived from your IP address.
When a Firm User is signed in to the dashboard, we identify their analytics session with their name, business email address, firm name, and firm location, and with internal identifiers and role flags that tell us which firm and which member an action belongs to, so we can understand how firms adopt and use Esqase. We also record non-identifying attributes of the Firm itself, such as its country, time zone, billing currency, and size. In addition to the events captured in the browser, our backend captures certain server-side events on your behalf, such as billing and subscription events confirmed by our payment provider's webhooks and document-completion events; these are attributed to the responsible Firm User.
The public pages a Firm shares with its clients (booking, document signing, document sharing, intake forms, and payment pages) stay anonymous. We do not identify clients or contacts on those surfaces and do not collect their name, email, or phone number for analytics.
Automatic tracking is deliberately limited. Each navigation is counted exactly once, and PostHog session replay is off by default; where we have expressly enabled it, all text and form inputs are fully masked so recordings never capture client matters, documents, or their contents. Analytics data is processed in the United States. We do not use third-party advertising cookies. See Section 7 and our Cookie Policy for more detail.
3.5 Google User Data and Limited Use
If you connect a Google account, Esqase requests the permissions for the connection you turn on, and uses them only for the purposes described below. Each connection is made by an individual member, is never shared with the rest of the Firm, and can be disconnected at any time from the Integrations page in Esqase.
What we access, and why:
- Gmail (send): to send the client email you compose in Esqase from your own Gmail account. This is send-only. Esqase does not read your Gmail mailbox, and does not request permission to do so.
- Google Calendar: to create, update, and read calendar events so the events you create in Esqase stay in step with your calendar.
- Google Meet: to create a meeting space and read its join link when you schedule a meeting in Esqase.
- Basic account identity (email address, profile, OpenID): to identify which Google account is connected and to display it on your Integrations page.
How we handle it: Google user data is used only to provide the features described above at your direction. We do not sell it, use it for advertising, or use it to develop, train, or improve generalized artificial intelligence or machine learning models. No human at Esqase reads your Google user data except with your explicit consent, to resolve a support request you raise, where required by law, or where necessary for security purposes such as investigating abuse. Access tokens are held under the safeguards described in Section 9 (Security), and disconnecting a Google account revokes Esqase's access to it.
Limited Use: Esqase's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Esqase's use of information received from Google Workspace APIs will adhere to the Google Workspace user data and developer policy, including its Limited Use requirements.
3.6 Microsoft and Zoom User Data
Microsoft and Zoom connections work the same way as the Google connections described above: each connection is made by an individual member, is never shared with the rest of the Firm, and can be disconnected at any time from the Integrations page.
What we access, and why:
- Microsoft Outlook (send and read): to send the client email you compose in Esqase from your own Outlook address, and, on a schedule, to check that mailbox for replies to messages you sent from Esqase so that a client's reply is recorded on the matter or lead the conversation belongs to. Esqase looks for replies to messages Esqase sent on your behalf; it does not present your wider mailbox in Esqase and does not copy it.
- Microsoft Outlook Calendar: to create, update, and read calendar events so the events you create in Esqase stay in step with your calendar.
- Microsoft Teams: to create an online meeting and read its join link when you schedule a meeting in Esqase.
- Zoom: to create a Zoom meeting and read its join link when you schedule a meeting in Esqase, and to identify which Zoom account is connected.
- Basic account identity: to identify which account is connected and to display it on your Integrations page.
How we handle it: this data is used only to provide the features above at your direction. We do not sell it, use it for advertising, or use it to develop, train, or improve artificial intelligence or machine learning models. Disconnecting an account ends Esqase's access to it.
3.7 Information We Collect from External Users
External Users are the clients, signers, form submitters, payers, and booking invitees who reach a Firm through the Public-Facing Features. Almost everything an External User submits is Client Data: the Firm controls it, and Esqase processes it on the Firm's behalf under Section 2.2. That includes the answers you give on an intake form, the details you enter when you book, the files you attach as proof of payment, and the signature record described in Section 1.
A narrow set of information about External Users is handled by Esqase as a controller, because it exists to keep the pages working and safe rather than to serve any one Firm:
- Access and security data: IP address, browser and device details, and request logs.
- Strictly necessary cookies: the anonymous per-browser marker that recognizes a returning visitor, the short-lived marker that remembers you unlocked a protected link, and the marker that carries a completed booking or payment across the redirect to its confirmation page. Each is listed, with its lifetime, in our Cookie Policy.
- Abuse protection signals: the device signals Google reCAPTCHA Enterprise collects through Firebase App Check to tell a person from an automated script.
- Email link verification: where a Firm protects a link with a one-time email sign-in, the record that the link was verified.
We do not identify External Users in analytics. On booking pages, signing pages, intake forms, and payment pages we do not collect your name, email address, or phone number for analytics. To ask about the information a Firm holds about you, contact the Firm. See Section 11.6.
3.8 Artificial Intelligence Used in the Service
Two parts of the Service send content to artificial intelligence models operated by Google Cloud (Vertex AI). Both run to provide the Service to your Firm, and neither builds anything for anyone else.
- Search indexing. When a record is created or changed, the Service sends a short text summary of that record to Google's text embedding model to build the numeric index that powers search. That summary can include the text of the record itself: a contact's name, contact details, and address; a matter title; the body of a note or comment; an activity, invoice, or transaction description; an event or task title; and the subject and body of an email logged against a matter or lead. For a document written in the Esqase editor, it includes the document's name, its description, and the first part of its text. What you type into search is sent the same way, so that the search can be matched against the index.
- AI document indexing. For files uploaded to the Service, the Service sends the file to a Google Gemini model to produce a short description of what the file is about, which is then indexed for search. A Firm Owner can turn this off for the whole Firm under Settings, then Profile, in the Data section. Turning it off stops new and updated files from being sent. It does not delete descriptions already produced, and it does not stop the search indexing described above, which search requires in order to work. A Firm that accepts a Business Associate Agreement or the data processing agreement we publish for the Firm's country has this switched off for the whole Firm at the moment it accepts, and a Firm Owner must turn it back on deliberately. A personal injury case carries a second switch of its own, which starts off for every Firm, so a file on a personal injury matter is sent only when both switches are on.
How this content is handled. Google processes this content as our service provider under the Google Cloud terms, which restrict Google from using it to train or fine-tune its models. Esqase does not use Client Data or User Content to train any artificial intelligence or machine learning model, our own or a third party's. This content is not used for advertising, is not disclosed to other Firms, and remains subject to the same access controls and tenant isolation as the record it came from. For Firms in the United States, this processing takes place in the United States, and a Firm's records themselves are stored in the United States whatever the Firm's country. Section 2.5 of our Data Processing Agreement states the regions used for a Firm in another country.
No decisions are made about you. These models produce search indexes and descriptions. They do not make decisions about you or about your matters. See Section 4.3.
3.9 Categories of Personal Information, Sources, Purposes, and Retention
This section is the notice at collection required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and it also serves readers under other state privacy laws. It describes the personal information Esqase collects as a controller, meaning for its own purposes. It does not describe Client Data, which a Firm controls and Esqase processes on the Firm's behalf under Section 2.2 and our Data Processing Agreement; for Client Data, the Firm's own privacy notice governs.
We disclose each category below only to the service providers described in Section 5.1, and only for the purposes stated there. We do not sell any category of personal information, and we do not share any category for cross-context behavioral advertising.
| Category (CCPA term) | What it is, and where it comes from | Why we collect it | How long we keep it |
|---|---|---|---|
| Identifiers | Name, sign-in email address, account and Firm identifiers, IP address, device identifiers. From you at registration, from your Firm's administrator when it invites you, and automatically when you use the Service. | Create and operate your Account, authenticate you, secure the Service, and communicate with you. | For as long as your Account exists, then 30 days for recovery, then removed. See Section 8. |
| California Customer Records information | The contact channels and postal addresses you add to your profile, your Firm's contact details and addresses, and payment records. From you and, for payment status, from Stripe. | Operate the Service, bill your Subscription, and let your colleagues reach you. | Profile details for as long as your Account exists. Billing and tax records for the period tax and accounting law requires after the Subscription ends. |
| Sensitive personal information: account log-in credentials | Your sign-in email with your password (stored only as a hash), your two-factor authentication secret, your emailed one-time codes, and your recovery codes. From you. | Authenticate you and protect your Account. We use and disclose this only to provide and secure the Service, which are purposes the CCPA and CPRA permit without a right to limit. | For as long as your Account exists, then removed with the Account. Emailed one-time codes expire in minutes. |
| Commercial information | Your plan, seat count, Subscription status, invoices, and payment history. Generated by your use of the Service and confirmed by Stripe. | Bill your Subscription, apply seat changes, and handle disputes. | For the period tax and accounting law requires. |
| Internet or other electronic network activity | Pages visited, the curated product events described in Section 3.4, session duration, browser and operating system, referring pages, server logs, error reports. Collected automatically. | Operate and secure the Service, and understand how firms adopt it. | Product analytics for no longer than we need it to understand and improve the Service, and deleted for a Firm User on a verified deletion request. Server and security logs for the period needed to investigate incidents and meet legal obligations. |
| Geolocation data (approximate) | A coarse location derived from your IP address, and the country your Firm records. Collected automatically or provided by you. | Fraud and abuse prevention, and understanding where firms use Esqase. | With the analytics or log record it belongs to. |
| Visual information | The profile photo you choose to upload. From you. | Show who did what inside your Firm. | For as long as your Account exists. |
| Professional or employment-related information | Your Firm's name and size, the software your Firm used before, and how you heard about us, recorded during firm setup. From you. | Set up your Firm, size your Subscription, and understand how firms find us. | For as long as the Firm exists. |
| Audio, electronic, or similar information | The content of the messages you send our support team. From you. | Answer your question and improve our support. | For as long as needed to resolve the request and keep a record of it, then removed. |
| Inferences | We do not create profiles about you or draw inferences about your preferences or characteristics. | Not applicable. | Not applicable. |
We do not collect biometric information, protected classification characteristics, education information, or precise geolocation as a controller.
4. How We Use Your Information and Our Legal Bases
4.1 Purposes
We use the information we collect to:
- Provide the Service: Operate, maintain, and improve the platform, including document management, matter tracking, billing, scheduling, and communication features.
- Process transactions: Manage your Subscription and payment.
- Authenticate users: Verify your identity. Firm Users sign in with an email address and password and confirm their email with a one-time code, and may add two-factor authentication. People who use the public pages a Firm shares with them verify their email address through a one-time sign-in link, or enter a password the Firm has set on the link.
- Send notifications: Deliver in-app and push notifications about activity relevant to your account, as configured in your preferences.
- Support: Respond to questions, troubleshoot issues, and provide technical assistance.
- Security: Detect, investigate, and prevent fraudulent transactions, abuse, and security incidents.
- Product improvement: Analyze aggregated usage patterns to improve the Service. We do not sell Client Data, and we do not use Client Data or User Content to train artificial intelligence or machine learning models, our own or anyone else's. Section 3.8 describes the artificial intelligence the Service uses to index your records for search.
- Legal compliance: Meet our obligations under applicable law.
- Communications: Send important account-related notices, product updates, and (with your consent) promotional content. See Section 6 (Marketing Communications).
4.2 Legal Bases for Processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases.
| Purpose | Legal bases |
|---|---|
| Providing, maintaining, and improving the Service | Performance of a contract |
| Processing subscriptions and payments | Performance of a contract; compliance with legal obligations |
| Authenticating users and securing the Service | Performance of a contract; legitimate interests (security and fraud prevention) |
| Sending notifications and account-related notices | Performance of a contract |
| Responding to support requests | Performance of a contract; legitimate interests (communicating with you effectively) |
| Product improvement and website analytics | Legitimate interests (understanding and improving how the Service and our website are used) |
| Marketing communications | Consent, which you may withdraw at any time |
| Legal compliance | Compliance with legal obligations |
4.3 Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you.
5. How We Share Your Information
We do not sell your personal information. We share information only as described below.
5.1 Service Providers (Subprocessors)
We work with trusted third-party providers who process information on our behalf to operate the Service. Our key providers include:
| Provider | Purpose | Location |
|---|---|---|
| Google LLC (Google Cloud) | Cloud infrastructure: application runtime (Cloud Run), background jobs (Cloud Functions), database (Cloud SQL for PostgreSQL), file storage (Cloud Storage), secret store (Secret Manager), the network perimeter application requests pass through (Cloud Load Balancing, Cloud Armor, and Cloud CDN, which caches static assets only and never a signed-in response), and logging (Cloud Logging) | US |
| Google LLC (Firebase) | Sign-in (Identity Platform), the real-time signals that tell an open page that something it is showing has changed (Firestore), push notification delivery (Firebase Cloud Messaging), and verification that a request comes from a genuine Esqase application (App Check) | US |
| Google LLC (Vertex AI) | Artificial intelligence models used for search indexing and document descriptions (Section 3.8) | US; Google's European region for EEA and UK Firms, and Google's Australian region for AU and NZ Firms |
| Google LLC (reCAPTCHA Enterprise, through Firebase App Check) | Bot and abuse protection on our applications and public pages | US |
| Cloudflare, Inc. | Name resolution for our domains, and delivery of and protection for our marketing website at esqase.com. Our applications reach Google Cloud's load balancer directly | US (global network) |
| Stripe, Inc. | Payment processing and subscription billing | US |
| Resend, Inc. | Transactional (system) email delivery, including messages we send to your clients on your behalf | US |
| Google LLC (Gmail, Calendar, Meet APIs) | Email, calendar, and meeting integration (when enabled by a user) | US |
| Microsoft Corporation (Outlook, Outlook Calendar, Teams APIs) | Email, calendar, and meeting integration (when enabled by a user) | US |
| Zoom Communications, Inc. | Meeting link integration (when enabled by a user) | US |
| PostHog, Inc. | Product and marketing analytics (esqase.com and the Service) | US |
PostHog receives technical data such as IP address, device, and browser from our applications and from the public pages a Firm shares with its clients. It never receives matter titles, client names, document names or contents, message text, search terms, or form answers.
The authoritative and continuously maintained list of the providers that process Client Data on a Firm's behalf, with the purpose and location of each, is published at esqase.com/subprocessors. We give Firms at least 14 days' written notice before we add or replace one, as described in Section 6.3 of our Data Processing Agreement, and you can subscribe to those notices at legal@esqase.com.
5.2 Public-Facing Features
When you use Public-Facing Features (for example document sharing, document signing, booking, intake forms, and payment pages), limited information may be visible to your clients or other recipients you designate. You control what is shared and with whom.
5.3 Legal Requirements
We may disclose information if required by law, court order, or regulatory authority, or where necessary to protect the rights, safety, or property of Esqase, our users, or others.
5.4 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, information may be transferred to the successor entity, subject to equivalent privacy protections.
5.5 With Your Consent
We will share information with third parties when you have given us explicit consent to do so.
6. Marketing Communications
- What we send: With your consent, we may send email about Esqase product news, new features, and offers we believe are relevant to your practice.
- Opting out: Every marketing email includes an unsubscribe link and our postal address. You can opt out at any time, and we will stop sending you marketing email within 10 business days of your request, as the CAN-SPAM Act requires. You can also contact us at legal@esqase.com to update your preferences.
- Transactional messages continue: Account, billing, security, and other service notices are not marketing messages and will continue for as long as you have an account.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service and understand how it is used. In summary:
- Strictly necessary cookies handle session management, authentication, and security (including the
__Host-sessioncookie) and cannot be switched off in our systems. - Functional storage is device storage rather than cookies. The software libraries our applications are built on use it to hold application configuration, an installation identifier for your browser, your push notification registration, cross-tab idle-timeout coordination, and short-lived security tokens.
- Analytics cookies (including PostHog's
ph_*entries) help us understand how firm staff use the Service and how visitors use our website, so we can improve them. Analytics on the public pages a Firm shares with its clients stays anonymous.
We do not use third-party advertising cookies, and we do not sell data to ad networks. You can manage cookies through your browser settings; disabling strictly necessary cookies may prevent the Service from functioning correctly.
Our website and applications are directed at customers in the United States and in the other countries described in Section 20 of our Terms of Service, and we do not currently present a cookie consent banner. If you are in the European Economic Area or the United Kingdom and you would rather we did not set analytics cookies, block them in your browser as described in our Cookie Policy, or write to us at legal@esqase.com and we will confirm what we hold and delete it.
For a detailed list of the cookies we use, their purposes and lifetimes, and how to manage them, see our Cookie Policy.
8. Data Retention
To determine how long to keep personal information, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, and applicable legal requirements. In practice:
- We retain your information for as long as your account is active and as necessary to provide the Service.
- If you delete your personal account: your Account is suspended and recoverable for 30 days. Signing back in during that window cancels the deletion. After 30 days, your Account and your personal profile information are permanently removed and your email address is freed. Work you created inside a Firm, such as notes, time entries, and documents, stays with that Firm as part of its records, because it belongs to the Firm and not to you. If you want that work removed, ask the Firm.
- If you deactivate your personal account: your Account, profile, and personal information are kept and your Firm memberships are dropped. Signing back in restores the Account. Nothing is deleted by deactivating.
- If your Firm's Subscription lapses: the Firm keeps full access for 30 days, and after that the dashboard is paused. A paused Firm's data is retained and is not deleted. The Firm Owner can still export the Firm's records or delete the Firm.
- If your Firm's account is terminated or the Firm is deleted: we retain the Firm's data for 30 days to allow recovery, then delete or anonymize it in our active systems.
- Backups: backup copies may persist for up to 90 days after deletion before being purged.
- We retain records required for legal, tax, or audit purposes for the periods required by applicable law.
- We retain product usage analytics only for as long as we need it to understand and improve the Service, and we delete the analytics associated with a Firm User on a verified account-deletion request.
- De-identified or aggregated data may be retained indefinitely. Where we hold de-identified information, we maintain and use it only in de-identified form, we take reasonable measures to prevent it from being connected back to you, we do not attempt to re-identify it, and we contractually require anyone we give it to do the same.
9. Security
We maintain a security program aligned to SOC 2 and ISO 27001, with controls that are continuously monitored. Our technical and organizational measures include:
- Encryption in transit (TLS). The database and the file storage are encrypted at rest with keys managed by the cloud platform, and two-factor authentication seeds and document share tokens are additionally encrypted by us at the application layer, with AES-256-GCM, before they are stored.
- Role-based access controls enforced in the database itself. Row level security is enabled and forced on every table, and our applications connect as a database role that cannot bypass it.
- Strict tenant isolation to prevent cross-firm data access: every record carries the identity of the Firm that owns it, and that identity is checked in the database on every read and every write.
- Audit logging of all significant data access and modifications.
- Two-factor authentication (authenticator app or emailed one-time code, with single-use recovery codes) available to every firm user, and a firm owner can require it for every member of the firm.
- Sessions verified on the server on every request, subject to both an absolute lifetime and an idle timeout.
- Security monitoring and incident response procedures.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at legal@esqase.com with the subject line "Account security." To report a security vulnerability, follow the process in Section 7 of our Acceptable Use Policy.
If something goes wrong. If we confirm a security incident affecting personal information we hold as a controller, we will notify affected individuals and any regulator that must be told, without undue delay and within the time the applicable law requires. Where the affected information is Client Data, the Firm is its controller: we notify the Firm as set out in Section 8 of our Data Processing Agreement, and the Firm decides what its own clients are told.
10. International Data Transfers
We are based in the United States and operate our infrastructure through Google Cloud in the United States. Our Service is offered to customers located in the United States and in the other countries described in Section 20 of our Terms of Service. For customers in the United States all processing, including the artificial intelligence processing described in Section 3.8, takes place in the United States, and Section 2.5 of our Data Processing Agreement states the regions used for a Firm in another country. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.
Where required by law, we rely on approved transfer mechanisms, including Standard Contractual Clauses for transfers from the EEA and the UK International Data Transfer Agreement or Addendum for transfers from the United Kingdom.
11. Your Rights and Choices
Depending on where you are located, you may have the following rights regarding your personal information:
11.1 General Rights (All Users)
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information, subject to legal retention obligations.
- Portability: Request your data in a machine-readable format. Firm Users can export their Firm's core records from the Service directly, and we will assemble anything the self-service export does not cover.
- Objection / Restriction: Object to or restrict certain processing.
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
11.2 California and Other U.S. State Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the right to:
- Know what personal information we collect, use, and disclose.
- Delete personal information we hold about you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA and CPRA. We have never done so. We use no advertising or cross-site tracking technology, and our analytics providers act as our service providers under written terms that prohibit them from using the information for their own purposes.
- Limit the use and disclosure of sensitive personal information. We do not use or disclose sensitive personal information for purposes other than providing the Service.
- Non-discrimination: We will not discriminate against you for exercising any of these rights.
You may submit a request yourself or through an authorized agent. We will verify your identity, and an agent's authority, before acting on a request.
Other U.S. states. Residents of other states that have enacted a comprehensive consumer privacy law, including Colorado, Connecticut, Texas, and Virginia, have comparable rights, which generally include confirming whether we process personal data about you, accessing it, correcting it, deleting it, obtaining a portable copy, and opting out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. Esqase does not carry out targeted advertising, does not sell personal data, and does not profile you in that way, so in those respects there is nothing to opt out of. Where a state law requires opt-in consent before processing sensitive data, we obtain it.
Appealing our decision. If we decline to act on your request, we will tell you why. You may appeal by replying to our response or by writing to legal@esqase.com with the subject line "Privacy request appeal." We will review the appeal and respond in writing within 45 days, explaining our decision. If we deny the appeal, we will give you the contact details for your state attorney general so that you can submit a complaint. California residents may also complain to the California Privacy Protection Agency at cppa.ca.gov.
11.3 European Economic Area and United Kingdom (GDPR/UK GDPR)
If you are in the EEA or UK, you have additional rights including the right to lodge a complaint with your local supervisory authority. Our lawful bases for processing are described in Section 4.2 and include performance of a contract (providing the Service), compliance with legal obligations, our legitimate interests (security, fraud prevention, product improvement), and consent where applicable.
11.4 Additional Rights in Your Country
Where the law of the country you are in provides rights in addition to those described above, we honor them, and the country-specific terms that state those rights are published at esqase.com/legal.
Data Protection Officer. Esqase has designated a Data Protection Officer. You may contact the Data Protection Officer, Kristoffer Bello, at legal@esqase.com with the subject line "Data Protection Officer," or by post at the address in Section 15.
11.5 Do Not Track and Opt-Out Preference Signals
Some browsers transmit Do Not Track (DNT) signals or opt-out preference signals such as Global Privacy Control (GPC). We do not sell or share personal information and do not use third-party advertising cookies, so there is no sale or sharing to opt out of. Our product analytics tool is also configured to honor a Do Not Track signal: where your browser sends one, it collects no analytics about your session and sets no analytics identifier. The Do Not Track signal is deprecated and is no longer sent by every browser, so treat this as a best-effort measure rather than a guarantee. Where applicable law treats an opt-out preference signal as a valid request to opt out of the sale or sharing of personal information, we honor it accordingly.
11.6 Exercising Your Rights
To exercise any of the rights above, email legal@esqase.com with the subject line "Privacy request," or write to the postal address in Section 15. We will acknowledge your request promptly and respond within the period the applicable law allows: 45 days under most U.S. state privacy laws, and one month under the GDPR and UK GDPR. Where the law permits and your request is complex or you have made several, we may extend the period once and will tell you why before the first period ends. We may need to verify your identity before we act, and we will ask only for what is needed to do that, which is usually confirmation of the email address on the account. Making a request is free, unless it is manifestly unfounded or excessive, in which case we will tell you before we charge anything or decline.
Important: If your personal information was entered into the Service by a Firm (for example, you are a client or contact of a law firm that uses Esqase), please direct your request to that Firm, which controls that information. If we receive such a request directly, we will notify the Firm and assist it in responding, as provided in our Data Processing Agreement.
12. Children's Privacy
The Service is built for licensed attorneys, law firms, legal professionals, and their staff. Under our Terms of Service, you must be at least 18 years old to hold an Account.
We do not direct the Service or our marketing website at children, and we do not knowingly collect personal information from a child under 13. If we learn that we have collected personal information from a child under 13, we delete it promptly. We do not sell or share the personal information of any consumer we know to be under 16, as those terms are defined under the CCPA and CPRA.
A Firm may enter information about a minor into the Service as part of a matter, for example in a family law or guardianship case. That information is Client Data: the Firm is its controller, decides how it is handled, and is responsible for any consent its own law requires. Requests about that information should be directed to the Firm. See Section 11.6.
13. Links to Third-Party Services
The Service may contain links to or integrations with third-party websites and services (for example Google, Microsoft, Zoom, and Stripe). This Privacy Policy does not apply to those services. We encourage you to review their privacy policies before sharing information with them.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice in the Service at least 14 days before the changes take effect. The updated Privacy Policy applies from its effective date. Where a change requires your consent under applicable law, we will ask for it before the change applies to you. We keep the previous version of this Privacy Policy available on request at legal@esqase.com so that you can identify which version applied on a given date.
15. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy, please contact:
Esqase, Inc.
Attention: Privacy Team
2810 N Church St STE 89268
Wilmington, DE 19802, United States
legal@esqase.com
Privacy requests. To exercise a right described in Section 11, email legal@esqase.com with the subject line "Privacy request," or write to the postal address above. For product help that is not a privacy request, contact support@esqase.com.
Country-specific rights. See Section 11.4 and the country-specific terms published at esqase.com/legal.
EEA and United Kingdom. Write to the postal address above or to legal@esqase.com.
If you need this Privacy Policy or a privacy request handled in an accessible format, email support@esqase.com and we will assist. See our Accessibility Statement.