Privacy Policy
Effective [EFFECTIVE DATE] · Last updated [DATE]
This Privacy Policy explains how [LEGAL ENTITY NAME] (“DIRK,” “we,” “us”) collects, uses, discloses, and protects information in connection with the DIRK legal-operations platform (the “Service”). DIRK is provided to law firms and legal professionals (“Firms”). We treat the information entrusted to us with the seriousness the legal profession demands.
Who controls the data. When a Firm uses DIRK to manage its clients and matters, the Firm is the controller of that client information and DIRK acts as a service provider (processor) on the Firm’s behalf and under its instructions. If you are a client of a Firm that uses DIRK, please direct privacy requests to that Firm.
1. Information we collect
Information you provide
- Account & firm information — names, email addresses, phone numbers, role, and firm details used to create and administer accounts.
- Matter & client information — the case, contact, calendar, task, document, time, and billing information a Firm enters into or generates within DIRK. This may include sensitive personal information about the Firm’s clients.
- Communications — messages, call summaries, and correspondence you route through or record in DIRK.
Information from connected services
With your authorization, DIRK connects to third-party services you choose to link, and accesses data from them to provide the Service. These may include Google Workspace (Gmail, Google Calendar, Google Drive), practice-management systems such as Clio, and telephony/messaging providers. See Section 3 (Google user data) for specifics on Google.
Information collected automatically
- Usage & device data — log data, IP address, browser/device type, and actions taken in the Service, used for security, reliability, and support.
2. How we use information
- To provide, operate, secure, and improve the Service.
- To power DIRK’s assistant features — surfacing deadlines, drafting documents from your templates and data, summarizing communications, and proposing actions for your review.
- To authenticate users, enforce per-firm isolation, maintain an audit trail, and prevent abuse.
- To provide customer support and communicate with you about the Service.
- To comply with legal obligations.
We do not sell your data, and we do not use the contents of your matters, client data, or Google user data to train generative-AI models.
3. Google user data
If you connect a Google account, DIRK requests only the access needed to deliver features you enable. With your consent DIRK may access:
- Gmail — to read, organize, draft, and (on your approval) send email tied to your matters.
- Google Calendar — to read and manage hearings, appointments, and deadlines.
- Google Drive — to access and file documents you associate with a matter.
We use Google user data solely to provide and improve these user-facing features at your direction. We do not sell Google user data, do not use it for advertising, and do not use it to train generalized AI models.
Limited Use disclosure. DIRK’s use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data Policy, including the
Limited Use requirements.
4. How we share information
- Service providers / subprocessors — infrastructure and processing partners under contract, including cloud hosting (Render), AI processing (Anthropic, OpenAI), and the connected services you authorize (e.g., Google, Clio, telephony providers).
- Within your Firm — with authorized users of your Firm’s account.
- Legal & safety — when required by law, or to protect rights, safety, and the integrity of the Service.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
We do not sell personal information or share it for cross-context behavioral advertising.
5. Data retention
We retain information for as long as a Firm’s account is active and as needed to provide the Service, then delete or de-identify it within a commercially reasonable period, except where longer retention is required by law.
6. Security
We use technical and organizational safeguards designed to protect information, including per-firm data isolation, encryption in transit, access controls, and audit logging.
7. Your choices & rights
- Access & correction — you may access and update account information within the Service.
- Disconnect — you may revoke DIRK’s access to a connected service at any time (for Google, at myaccount.google.com/permissions).
- Export & deletion — Firms may request export or deletion of their data by contacting us.
- Depending on your location, you may have additional rights (e.g., under the GDPR or CCPA/CPRA).
8. Children
The Service is intended for legal professionals and is not directed to children under 18.
9. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new effective date.
10. Contact us
Questions or requests: privacy@dirklegal.com, or [LEGAL ENTITY NAME], [MAILING ADDRESS].