Confidentiality
Three principles everything else follows from
Privilege comes first
When our specialists answer your phone, they are handling communications that may be privileged or on their way to becoming privileged. We treat every caller conversation as confidential from the first word, whether or not the person ever becomes your client, and whether or not they ever engage a lawyer at all.
Why: privilege is your client’s protection, not ours, and it is not something we get to weigh against convenience. A caller who cannot speak freely to whoever answers your phone cannot give your firm the facts it needs.
The data is your firm’s
Caller records, call recordings, transcripts, notes and the reporting built on them belong to your firm. We hold them to deliver your service. You can have a full export at any time, and if our relationship ends, you take everything with you.
Why: a partner who can hold your client data hostage has leverage over your firm’s decisions, and that is not a healthy basis for a working relationship. Ownership sitting with you removes the question entirely.
We do not monetise your callers
We are paid by law firms for work performed. We do not sell caller data, share it with other firms, pass it to data brokers, or use it to market anything to your prospects.
Why: the moment a service provider earns money from the data rather than the work, every other assurance on this page becomes conditional. Our revenue model is the actual guarantee behind it.
One firm can never see another
Your callers are visible only to the specialists assigned to your firm. There is no shared pool of enquiries, no cross-firm lead list, and no circumstance in which a caller who reached your line is routed to another firm.
Why: we serve many law firms, some of them competitors in the same market. Strict isolation is what makes that possible without ever putting a firm at a disadvantage.
Confidentiality controls
The specific measures behind those principles, and the reason each one exists. Controls without a stated reason tend to be theatre, and they are the first thing to be quietly dropped when a team gets busy.
Named access, not general access
Only the specialists assigned to your firm can see your callers. Access is granted by name to a defined role, reviewed when people join, move or leave, and removed the day someone stops working on your account.
Why we do this: most confidentiality failures are not dramatic breaches. They are an old account that nobody switched off, or a person who kept access after moving to a different team. Access that is granted by name and removed on a schedule closes the gap that actually causes incidents.
Every specialist is vetted and under a confidentiality agreement
Everyone who can hear your callers is screened before they start and works under a written confidentiality agreement covering caller information, firm information and anything learned on a call. Confidentiality is part of induction, not a policy document nobody opens.
Why we do this: your firm’s obligations do not stop at your own staff. When you extend your intake to an outside team, that team has to be held to the standard you would apply to your own employees, in writing, and before the first call.
Isolation between client firms
Records are separated by firm at the system level. A specialist working across more than one account sees each firm’s callers only within that firm’s workspace, and there is no view anywhere that combines them.
Why we do this: we work with firms that compete with each other. Isolation is what lets us do that honestly. It also removes the worst possible failure mode, which is one firm’s enquiry surfacing in front of another firm.
Encryption in transit and at rest
Caller records, recordings and transcripts are encrypted while moving between systems and while stored, using current industry standards.
Why we do this: encryption is what makes the difference between an infrastructure problem and a disclosure of your clients’ information. It is the control that still protects you on the day something else has already gone wrong.
Access logging
Access to caller records is recorded: who opened what, and when. Logs are retained and reviewable.
Why we do this: a control you cannot verify is a promise. Logging is what turns our assurances into something checkable, by us during review and by your firm if you ever need to ask a direct question about a specific record.
Call recording handled to your rules and your state’s
Recording is configured per firm. Where a jurisdiction requires notice or all-party consent, the call flow reflects it. Recordings are stored under the same access controls as everything else, and retention is set with you rather than defaulted by us.
Why we do this: recording rules vary by state, and the consequences of getting them wrong land on your firm, not on your vendor. A provider who treats recording as a switch rather than a legal question is creating a risk you will own.
Controlled working environments
Specialists work from managed environments with device controls, restricted local storage and clear rules about what may be written down, printed or taken out of the workspace.
Why we do this: a perfectly secured system can still be undone by a phone photograph of a screen or a note on a pad. Controlling the environment around the conversation closes the gap that technical controls alone cannot reach.
A short, disclosed list of subprocessors
We use a small number of third-party systems to deliver the service, such as telephony and the case management platforms your firm already uses. We will tell you exactly who they are, and we do not add a new one that touches caller data without telling you.
Why we do this: a confidentiality promise is only as strong as the weakest system in the chain. You cannot assess that chain if you cannot see it, so we make it visible rather than asking you to take our word for it.
Export and deletion on request
You can request a complete export of your firm’s data at any time. On request, or on the end of our engagement, caller data is deleted within a defined window, apart from anything we are legally required to retain, which we will identify.
Why we do this: your obligations to your clients extend to the data your suppliers hold. If you cannot get your data out, or cannot have it deleted when it should be, you cannot meet those obligations, and you are dependent on us to do it for you.
No advertising use of your callers
Caller data is never used to build advertising audiences, and never shared with advertising platforms as an audience list. Where we manage advertising for your firm, we measure results rather than targeting individuals, and we apply the restrictions in Google’s personalized advertising policy that specifically govern sensitive practice areas.
Why we do this: beyond the platform rules, following a person around the internet because they enquired about bankruptcy or a criminal charge can expose something they told your firm in confidence to whoever else uses their device.
Incident response, with you told promptly
We have a defined process for suspected incidents: contain, investigate, notify the affected firm promptly with what we know, and document what changed afterwards.
Why we do this: your firm may have its own notification obligations, and those clocks start whether or not your supplier has finished writing a comfortable summary. Early, factual notice is what lets you meet them.
Reviewed, not assumed
Access lists, training, recording configuration and subprocessors are reviewed on a schedule, and the review date is published at the top of this page.
Why we do this: confidentiality arrangements degrade quietly. Staff change, systems get added, a temporary permission becomes permanent. A scheduled review is what catches that before it becomes an incident.
For your own due diligence
Ask us the hard questions before you sign.
We would rather answer a demanding due diligence process than have a firm discover a gap later. If your firm has a supplier assessment, a professional liability carrier with requirements, or a client with its own standards, send it over.
We can provide a written summary of our controls, a data processing agreement, our subprocessor list, and answers to specific questions about retention, recording and access.
Questions worth asking any intake provider
- Who, by name or role, can see my callers, and how is that reviewed?
- Can a specialist working for another firm see mine?
- Is caller data ever used for anything other than delivering my service?
- Where are recordings stored, for how long, and who decided that?
- What happens to everything if we part company?
- Which third parties touch this data, and will you tell me when that changes?
- If something goes wrong, when and how do I hear about it?
Ask us all seven. A provider who cannot answer them quickly has not thought about it.
Confidentiality is the condition, not the feature.
If there is something your firm needs in writing before you would hand over your phones, ask. We will put it in writing.