firstcase resources

Security and compliance

Caller information

For caller information, the law firm is the controller and decides why and how it is processed. firstcase acts as a processor, handling caller information only on the firm's instructions and only to provide the Platform.

Call records may include the caller's name and callback number; the nature and area of the legal matter; urgency and tone indicators; recordings and transcripts; scheduling information; and AI-generated summaries and intake assessments.

Authorized personnel are bound by confidentiality obligations, and access is limited to those who need it to provide the Platform.

Security measures

Measures designed to protect Personal Data include TLS 1.2+ encryption in transit, AES-256 encryption at rest provided by infrastructure providers, encrypted calendar and CRM connection credentials, logical multi-tenant data isolation with row-level security, role-based access controls, access logging, and periodic review of security practices.

No security measures can guarantee absolute security.

AI and caller data

firstcase does not use identifiable Personal Data, including call transcripts and recordings, to train, fine-tune, or develop foundation or general-purpose AI or machine-learning models.

The Platform is a software service, not a law firm; it does not provide legal advice or legal services and does not create an attorney-client relationship between a caller and firstcase.

Recording and notifications

The firm is responsible for determining whether recording is permitted for a call, configuring recording and disclosure settings, and obtaining any consent required from callers.

SMS and email are inherently less secure than the encrypted Platform dashboard.

Retention and incident response

Call recordings are available in the dashboard for 6 months on the Essential plan and 2 years on the Growth plan. Call data is kept for the subscription term unless the firm requests earlier deletion, and is deleted 90 days after cancellation. Billing records are kept for 7 years as required by law.

If a security incident affects Client Personal Data, firstcase will notify the Client without undue delay and within 72 hours, with a written incident report within 14 days.

Data Processing Addendum

A Data Processing Addendum is available for firms that require one.