Superforms ("Superforms", "we", "us") provides guided client-intake software to law firms. This policy explains what data we handle, how, and the choices you have. It covers two very different kinds of data, and the distinction matters:
When a firm sends an intake, clients submit answers (which may include personal, financial, or family information the firm chooses to ask for). We store this to deliver it to the firm, and we process it only to provide the service and on the firm's instructions. The firm is responsible for the lawful basis to collect it and for its clients' rights.
We do not sell personal data, and we do not use client intake content to train models.
We use a small set of vendors to run the service. Each is bound by its own data-protection terms:
Data is encrypted in transit (TLS) and at rest. Each firm's data is isolated from every other firm's. Access to production data is limited to what is needed to operate the service.
We keep data for as long as a firm's account is active or as needed to provide the service. A firm can request deletion of its data; on account termination we delete or return firm and client intake data within a commercially reasonable period, unless retention is required by law.
We share data only with the sub-processors above, with a firm's chosen integrations at the firm's direction, and where required by law. We do not sell data.
Firms that need one can request a Data Processing Agreement (DPA) covering our processing of client intake data on their behalf.
Our vendors may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards.
For firm account data, you may request access, correction, or deletion. For client intake data, requests from a client should be directed to the firm (the controller); we will assist the firm as its processor.
We will update this policy as the service evolves and change the date above. Material changes will be communicated to firms.