backdocket
  • Features
  • Solutions

    I need to…

    • Find An Easier-To-Use Software
    • Improve Communication
    • Get All My Documents in One Place
    • Better Manage My Case Tracking
    • Offer Outstanding Customer Service
  • About
  • Pricing
  • Blog
  • Contact

Backdocket Privacy Policy

How Backdocket collects, uses, shares, and protects your data

1. Scope

Last Updated: September 16, 2026

This Privacy Policy explains how Depeltier Technologies, LLC, d/b/a Backdocket.com (“Company,” “we,” “us“) collects, uses, discloses, and safeguards data in connection with the Backdocket platform (the “Services“). This Policy applies to (a) data about our subscribing law firms and their authorized users (“Account Data“), and (b) case, client, and matter data that firms upload or generate within the Services (“Customer Data“).

2. Our Role: Processor vs. Controller

For Account Data (firm and user account information, billing contacts, login activity), Company acts as the data controller — we determine why and how that data is used to operate and bill for the Services.

For Customer Data (case files, client records, correspondence, and other matter content firms upload), Company acts solely as a data processor / service provider on the firm’s behalf. The subscribing firm controls what Customer Data is submitted, who can access it, and how long it is retained (subject to the retention terms below and the firm’s own subscription).

3. Categories of Data We Process

CategoryExamplesSource
Account & User DataName, work email, role, firm affiliation, hashed password, MFA statusProvided at signup / by firm admin
Customer DataCase records, documents, claim/settlement figures, medical records, correspondence, ledger and trust-fund entries uploaded by the firmUploaded/generated by firm within the Services
Activity & Audit DataURL/endpoint accessed, IP address, browser/user agent, timestamp, trace IDGenerated automatically for every user action
AI Usage DataPer-call token counts by provider, model, and call typeGenerated when a firm uses AI features
Communications DataEmails, text messages, and merged documents generated from and tied to a case recordGenerated by firm users within the Services
Billing DataSubscription plan, seat count, payment status (not full card numbers)Processed via Braintree
Website DataStandard web analytics and functionality cookies on backdocket.combackdocket.com visitors

4. How We Use Data

  • To provide, operate, secure, and support the Services (including authentication, permissioning, and the audit trail).
  • To bill for the Subscription via our payment processor.
  • To investigate security incidents and enforce firm-scoped data isolation.
  • To provide customer support.
  • To improve the Services, using only aggregated or de-identified data.
  • To comply with legal obligations.

We do not sell Customer Data or Account Data to third parties, and we never use Customer Data to train or fine-tune AI or machine-learning models.

5. How We Share Data

Company Subprocessors

These are the only third parties that process data on Company’s behalf:

SubprocessorPurposeData Involved
Amazon Web Services (AWS)Cloud hosting infrastructure for production systemsAll Customer Data and Account Data (hosted, encrypted)
Braintree (a PayPal service)Subscription payment processingBilling/payment data (Company does not store full card numbers)

Data Location. All Customer Data and Account Data — including production systems and backups — is stored and processed in Amazon Web Services data centers located in the United States.

Customer-Connected Services

The Services can connect to third-party services that the firm licenses under its own accounts, using the firm’s own credentials or API keys. Company does not own, control, or pay for these accounts. When a firm connects one, data flows directly between the firm’s Backdocket environment and the firm’s own account with that provider, under the firm’s direct agreement with that provider — not under this Policy.

ServicePurposeConnected How
Microsoft 365 / Google WorkspaceEmail and document integrationFirm’s own account via OAuth
QuickBooksAccounting integrationFirm’s own account via OAuth
DocuSignE-signature integrationFirm’s own account via OAuth
TwilioSMS text messagingFirm’s own Twilio account and credentials
Anthropic / OpenAI / Azure OpenAIAI featuresFirm’s own API key and provider agreement

Company does not sell or resell AI services. AI features operate only through the firm’s own licensed AI provider account; that provider — not Company — generates AI output and processes the data sent to it.

There is no cross-firm shared pipeline for any of these services: each firm’s provider relationships and data-handling terms are its own, established directly with the providers it selects.

Google API Services

When a firm connects Google Workspace, Backdocket accesses only the Gmail messages, Google Drive files, Google Tasks, and Google Calendar entries that the firm’s users choose to connect to case records, solely to provide the email, document, task, and calendar integration described above. Backdocket’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Legal Disclosures

We disclose Customer Data to third parties only when legally compelled to do so by subpoena, court order, or other valid legal process. If we receive such a demand for a firm’s Customer Data, we will notify the firm promptly — before disclosing, where the law allows — so the firm has the opportunity to object or seek a protective order, and we will disclose only the minimum required to comply.

6. HIPAA — Business Associate Status

Customer Data uploaded by firms may include Protected Health Information (PHI) — for example, medical records tied to a personal injury or settlement matter. Where a subscribing firm is itself a Covered Entity under the Health Insurance Portability and Accountability Act (HIPAA), or is a Business Associate of one, Company acts as a Business Associate (or subcontractor Business Associate) with respect to that PHI.

  • AWS Business Associate Agreement. Our infrastructure runs on Amazon Web Services, and we maintain a signed Business Associate Agreement (BAA) with AWS covering the hosting environment for Customer Data.
  • Minimum Necessary / Permitted Use. We access and process PHI within Customer Data only as necessary to provide, secure, and support the Services, or to de-identify it as permitted by the Subscription Agreement, and we do not use PHI for any other purpose without the firm’s authorization.
  • Business Associate Terms Are Built In. The Backdocket Subscription Agreement includes Business Associate terms that apply automatically to any subscribing firm that is a Covered Entity or Business Associate — no separate agreement or signature is required. A firm that nonetheless requires a standalone signed agreement may request one from legal@backdocket.com.
  • Breach Notification. In the event of a breach of unsecured PHI, Company will notify the affected firm without unreasonable delay — in no event later than seventy-two (72) hours after confirming the breach, and in no event later than sixty (60) days after discovery, as required by HIPAA’s Breach Notification Rule.
  • Subprocessor Flow-Down. Where a subprocessor may process PHI (currently, AWS for hosting), Company maintains appropriate agreements requiring that subprocessor to protect PHI consistent with HIPAA.

7. Data Security

Customer Data is protected by:

  • Firm-scoped multi-tenant data isolation enforced at every API endpoint, including AI access.
  • Role-based and field-level access control, including private-claim restrictions.
  • Multi-factor authentication and firm-scoped, independently revocable API keys.
  • An audit trail of Authorized User actions within the application (URL, IP address, browser, timestamp, trace ID).
  • Encryption of data in transit (HTTPS) and at rest using industry-standard encryption.
  • Optional BackVault on-premises data custody: a continuously-synchronized, read-only replica of the firm’s data on infrastructure the firm controls. The firm is responsible for securing its own BackVault infrastructure and the data once delivered to it.

Backdocket Personnel Access

Backdocket personnel may access Customer Data, including through direct database access, only as needed to provide customer support, troubleshoot issues, and operate, maintain, and deploy the Services. Product-improvement analysis uses only aggregated or de-identified data. Personnel do not access Customer Data for any other purpose, and are bound by confidentiality obligations to Company. Direct database access by personnel is not separately logged in the application audit trail. Customer Data is never used for marketing or sold to third parties.

Security Incident Notification

If we discover a security incident that resulted in unauthorized access to a firm’s Customer Data, we will notify the affected firm without unreasonable delay — in no event later than seventy-two (72) hours after we confirm the incident, and in no event later than sixty (60) days after discovery — with the information reasonably available to us about the nature of the incident and our response.

8. Data Retention

  • During the Subscription: Customer Data is retained for as long as the firm’s Subscription is active, subject to the firm’s own deletion actions within the Services.
  • After the Subscription Ends: Customer Data is retained for one (1) year after the Subscription ends — whether by cancellation or by non-payment — during which the firm may re-subscribe and have its data restored, and an export of Customer Data is available on written request to support@backdocket.com. After one year, Customer Data is deleted from Company’s production systems. A firm may request earlier deletion at any time by written notice to support@backdocket.com; deletion is completed within thirty (30) days, confirmed in writing on request, and is irrevocable. Firms using BackVault retain their own independently-synced copy regardless of this schedule.
  • Data Portability: During an active Subscription, a firm can maintain a continuously-synchronized, independent copy of its complete dataset on its own infrastructure through BackVault, which is included in the Subscription at no additional cost.
  • Account Data: Retained for the life of the account and for one (1) year after the Subscription ends, except that billing records are kept as long as required for tax and accounting purposes.
  • Activity Audit Logs: Retained for ninety (90) days.
  • AI Usage Logs: Per-call token usage records are retained for twenty-four (24) months.
  • Backups: Full backups are taken nightly and transaction logs are captured every minute. Backups are retained for three (3) days and overwritten thereafter, so data deleted from production ages out of backups within three days.

9. Firm Administrator Controls

Firm administrators can audit user activity, revoke API keys, manage role permissions, and control which third-party integrations are connected — without needing to contact Company. This puts day-to-day data-access governance in the firm’s own hands.

10. Clients of Subscribing Firms

If you are a client of a law firm that uses Backdocket and have questions about your personal information, please contact that firm directly. Backdocket processes that information on the firm’s behalf and will assist the firm in responding to your request.

11. Children’s Privacy

The Services are intended for use by legal professionals and are not directed to individuals under 18. We do not knowingly collect data directly from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to subscribing firms by email to firm administrators, or by in-app notice, at least thirty (30) days before taking effect.

13. Contact Us

Questions about this Privacy Policy or Backdocket’s data handling can be directed to legal@backdocket.com.


Depeltier Technologies, LLC d/b/a Backdocket.com — legal@backdocket.com

  • Home
  • Features
  • About
  • Pricing
  • Support
  • Blog
  • Contact
backdocket

All elements of this website are copyrighted materials for cj Advertising, LLC, or backdocket ©2026

  • View Our Privacy Policy
  • Terms of Service