How Backdocket collects, uses, shares, and protects your data
Last Updated: September 16, 2026
This Privacy Policy explains how Depeltier Technologies, LLC, d/b/a Backdocket.com (“Company,” “we,” “us“) collects, uses, discloses, and safeguards data in connection with the Backdocket platform (the “Services“). This Policy applies to (a) data about our subscribing law firms and their authorized users (“Account Data“), and (b) case, client, and matter data that firms upload or generate within the Services (“Customer Data“).
For Account Data (firm and user account information, billing contacts, login activity), Company acts as the data controller — we determine why and how that data is used to operate and bill for the Services.
For Customer Data (case files, client records, correspondence, and other matter content firms upload), Company acts solely as a data processor / service provider on the firm’s behalf. The subscribing firm controls what Customer Data is submitted, who can access it, and how long it is retained (subject to the retention terms below and the firm’s own subscription).
We do not sell Customer Data or Account Data to third parties, and we never use Customer Data to train or fine-tune AI or machine-learning models.
These are the only third parties that process data on Company’s behalf:
Data Location. All Customer Data and Account Data — including production systems and backups — is stored and processed in Amazon Web Services data centers located in the United States.
The Services can connect to third-party services that the firm licenses under its own accounts, using the firm’s own credentials or API keys. Company does not own, control, or pay for these accounts. When a firm connects one, data flows directly between the firm’s Backdocket environment and the firm’s own account with that provider, under the firm’s direct agreement with that provider — not under this Policy.
Company does not sell or resell AI services. AI features operate only through the firm’s own licensed AI provider account; that provider — not Company — generates AI output and processes the data sent to it.
There is no cross-firm shared pipeline for any of these services: each firm’s provider relationships and data-handling terms are its own, established directly with the providers it selects.
When a firm connects Google Workspace, Backdocket accesses only the Gmail messages, Google Drive files, Google Tasks, and Google Calendar entries that the firm’s users choose to connect to case records, solely to provide the email, document, task, and calendar integration described above. Backdocket’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We disclose Customer Data to third parties only when legally compelled to do so by subpoena, court order, or other valid legal process. If we receive such a demand for a firm’s Customer Data, we will notify the firm promptly — before disclosing, where the law allows — so the firm has the opportunity to object or seek a protective order, and we will disclose only the minimum required to comply.
Customer Data uploaded by firms may include Protected Health Information (PHI) — for example, medical records tied to a personal injury or settlement matter. Where a subscribing firm is itself a Covered Entity under the Health Insurance Portability and Accountability Act (HIPAA), or is a Business Associate of one, Company acts as a Business Associate (or subcontractor Business Associate) with respect to that PHI.
Customer Data is protected by:
Backdocket personnel may access Customer Data, including through direct database access, only as needed to provide customer support, troubleshoot issues, and operate, maintain, and deploy the Services. Product-improvement analysis uses only aggregated or de-identified data. Personnel do not access Customer Data for any other purpose, and are bound by confidentiality obligations to Company. Direct database access by personnel is not separately logged in the application audit trail. Customer Data is never used for marketing or sold to third parties.
If we discover a security incident that resulted in unauthorized access to a firm’s Customer Data, we will notify the affected firm without unreasonable delay — in no event later than seventy-two (72) hours after we confirm the incident, and in no event later than sixty (60) days after discovery — with the information reasonably available to us about the nature of the incident and our response.
Firm administrators can audit user activity, revoke API keys, manage role permissions, and control which third-party integrations are connected — without needing to contact Company. This puts day-to-day data-access governance in the firm’s own hands.
If you are a client of a law firm that uses Backdocket and have questions about your personal information, please contact that firm directly. Backdocket processes that information on the firm’s behalf and will assist the firm in responding to your request.
The Services are intended for use by legal professionals and are not directed to individuals under 18. We do not knowingly collect data directly from children.
We may update this Privacy Policy from time to time. Material changes will be communicated to subscribing firms by email to firm administrators, or by in-app notice, at least thirty (30) days before taking effect.
Questions about this Privacy Policy or Backdocket’s data handling can be directed to legal@backdocket.com.
Depeltier Technologies, LLC d/b/a Backdocket.com — legal@backdocket.com