Privacy Policy
Last Updated: January 15, 2025
ClaireAI, Inc. ("ClaireAI," "we," "us," or "our") is committed to protecting the privacy and security of the law firms we serve ("Clients") and the individuals who communicate with those firms ("Callers").
This Privacy Policy describes how we collect, use, and safeguard information when you use our AI-powered intake platform. By using our Service, you agree to the collection and use of information in accordance with this policy.
Core Principle: We distinguish between data we collect as a "Controller" (e.g., your law firm's billing info) and data we process as a "Service Provider" (e.g., your potential client's case details). We process Caller Data solely on your behalf.
1. Information We Collect
1.1 Information from Law Firms (Controller Data)
When you register for ClaireAI, we collect information necessary to establish your account:
- Business Identifiers: Firm name, authorized representative name, business address, email, and phone number.
- Financial Data: Payment card details or bank account information (processed securely via Stripe).
- Configuration Data: CRM API keys, calendar credentials, and conflict check databases.
1.2 Information from Callers (Processor Data)
On behalf of our Clients, we collect information from Callers during intake interactions:
- Personal Identifiers: Name, phone number, and email address.
- Legal Inquiry Data: Descriptions of legal issues, incident dates, and case-specific details.
- Communications: Audio recordings and AI-generated transcripts of intake calls.
1.3 Automatically Collected Data
We collect technical data to ensure Service stability and security:
- Log Data (IP address, browser type, timestamps).
- Telephony Metadata (Call duration, originating number, carrier information).
2. How We Use Your Information
2.1 Use of Law Firm Data
We use your business information to:
- Provide, maintain, and bill for the Service.
- Authenticate your access to the platform.
- Notify you of service updates, security alerts, and administrative messages.
2.2 Use of Caller Data (AI & Service Delivery)
We process Caller Data strictly to perform the intake function on your behalf. Specific uses include:
- **Real-time Intake:** Transcribing audio and extracting relevant case details using AI models.
- **Integration:** Syncing intake summaries to your connected CRM or Case Management Software.
- **Conflict Checking:** Comparing Caller details against your provided conflict database.
AI Training Policy: ClaireAI does NOT use your confidential Client Data or Caller Data to train our foundational Large Language Models (LLMs) for general public use. We may use anonymized and aggregated data to refine our internal intake logic and improve system accuracy, but strictly in a manner that cannot be reverse-engineered to identify you or your clients.
3. Biometric Information Disclaimer
While ClaireAI records audio of intake calls, we do not collect, capture, store, or otherwise process "Biometric Identifiers" or "Biometric Information" (such as voiceprints used for identification purposes) as defined by applicable laws, including the Illinois Biometric Information Privacy Act (BIPA) or the Texas Capture or Use of Biometric Identifier Act (CUBI).
4. Data Sharing and Disclosure
4.1 Third-Party Sub-Processors
We engage trusted third-party vendors to support our infrastructure. These vendors are contractually bound to confidentiality and data security standards at least as stringent as those set forth herein:
- Cloud Infrastructure: AWS / Google Cloud (Data hosting and computation).
- Telephony: Twilio (Voice connectivity).
- Payment Processing: Stripe (Billing).
4.2 Legal Requirements
We may disclose information if required by law, subpoena, or court order. We will attempt to notify you of such requests unless prohibited by law, to give you an opportunity to seek a protective order.
5. Data Security
We employ enterprise-grade security measures designed to protect data from unauthorized access, exfiltration, or destruction:
- Encryption: Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access Control: Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) for internal staff.
- Audits: Regular security assessments and penetration testing.
6. Data Retention
We retain Caller Data only for as long as instructed by the Law Firm or as necessary to provide the Service. You may configure retention policies (e.g., auto-deletion after 90 days) within your account settings. Upon contract termination, we provide a grace period for data export, followed by permanent deletion.
7. Your Rights (CCPA, GDPR, and State Laws)
7.1 Rights of Law Firms (Controllers)
As a user of our platform, you have the right to access, rectify, download, or delete your business data at any time via the ClaireAI dashboard.
7.2 Rights of Callers (Data Subjects)
If you are a Caller who has interacted with ClaireAI, please note that we process your data on behalf of a specific Law Firm. To exercise your rights (access, deletion, correction) under CCPA, GDPR, or other privacy laws, please contact the Law Firm you called directly. We will assist the Law Firm in fulfilling these requests as a Data Processor.
8. Attorney-Client Privilege
ClaireAI provides the technical infrastructure for intake. However, the formation of an attorney-client relationship and the attachment of privilege are legal determinations governed by the laws of your jurisdiction. We implement security measures designed to protect the confidentiality of these communications, but we do not offer legal advice regarding privilege.
9. International Data Transfers
ClaireAI is based in the United States. If you use our Service from the EEA, UK, or Switzerland, you acknowledge that data will be transferred to the US. We rely on the Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs) to ensure adequate protection for such transfers.
10. Changes to this Policy
We may update this policy to reflect changes in law or our technical infrastructure. Material changes will be communicated via email to the address associated with your account prior to taking effect.
11. Contact Us
If you have questions about this Privacy Policy or our security practices, please contact our Privacy Team:
ClaireAI, Inc.
Attn: Privacy Officer
600 SW 3rd Ave
Miami, FL 33130
Email: info@theclaireai.com
Phone: +1 (954) 997-0065
ClaireAI