PRIVACY POLICY

Rev: 20260731

Our Commitment to Privacy

Your privacy and the security of your legal case data are paramount to us. This Privacy Policy sets out the basis on which any personal data we collect from you, that you provide to us, or that is provided to us by a subscriber to our services will be processed by Brevort River Studios, LLC (and its subsidiaries) (“BRS”), also known as Prima.Law. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.

ARTIFICIAL INTELLIGENCE & CASE REVIEW AI DATA PRIVACY

Prima Law incorporates an integrated “Case Review AI” feature designed to assist legal practitioners with automated document summarization, case analysis, form handling, and legal workflow management.

1. Information Processed by Case Review AI

When an Authorized User utilizes Case Review AI, the following categories of data may be processed:

  • User Inputs & Prompts: Direct text queries, instructions, or search prompts entered into the AI assistant interface.

  • Selected Case Documents & Content: Text from case files, court forms, client emails, or internal notes specifically selected or uploaded by the user for AI analysis or drafting.

2. How We Use & Protect AI Data

  • Zero Model Training Guarantee: All AI functionality is powered by enterprise-tier infrastructure (Google Cloud / Gemini Enterprise). We strictly guarantee that your prompts, case data, uploaded documents, and AI-generated outputs are NEVER used by BRS, Google, or any third party to train, retrain, fine-tune, or improve public, foundational, or commercial Large Language Models (LLMs) or artificial intelligence algorithms.

  • Data Isolation: All interactions with Case Review AI take place within an isolated enterprise tenant environment. Your firm’s data is never exposed to or accessible by other subscribers, external parties, or public AI networks.

  • Encryption Standards: Content processed by Case Review AI is encrypted in transit using TLS 1.3 and at rest using AES-256 enterprise-grade encryption.

3. Authorized AI Sub-Processors

We engage Google Cloud Platform (Gemini Enterprise) as a restricted AI sub-processor. Google acts solely as a data processor bound by enterprise contractual commitments to process data strictly to execute the immediate Case Review AI function on your firm’s behalf.

GOOGLE INTEGRATION (GMAIL API)

This section explains how Prima Law – Legal Case Management accesses, uses, stores, protects, and shares Google user data obtained through Google API Services, in full compliance with the Google API Services User Data Policy, including all Limited Use requirements.

1. Types of Google User Data We Access

Our application uses OAuth 2.0 so each user can connect their own Gmail account. We only access the data strictly required for our legal case management workflows:

  • a) email: User’s primary email address.

  • b) profile: First and last name.

  • c) Gmail Read-Only ([https://www.googleapis.com/auth/gmail.readonly](https://www.googleapis.com/auth/gmail.readonly)):[https://www.googleapis.com/auth/gmail.readonly](https://www.googleapis.com/auth/gmail.readonly) We access:

    • Messages and threads (messageId, threadId)

    • Headers: From, To, Cc, Bcc, Subject, timestamps

    • Technical headers: Message-ID, In-Reply-To, References, conversationId

    • Body content (HTML or text)

    • Attachment metadata and content when selected by the user

    • Gmail history data (historyId)

    • We do not modify, delete, or move emails inside Gmail.

  • d) Gmail Send ([https://www.googleapis.com/auth/gmail.send](https://www.googleapis.com/auth/gmail.send)):[https://www.googleapis.com/auth/gmail.send](https://www.googleapis.com/auth/gmail.send) Used exclusively to send emails on behalf of the authenticated user:

    • Sender

    • Recipients chosen by the user

    • Subject and body

    • User-selected attachments

    • Sent message identifiers (messageId, threadId)

2. How We Use Gmail Data

  • a) Authentication & Identification: We use email and profile data to identify the user within the tenant, link the Gmail account, and display their name in the interface. We do not use this data for advertising or analytics.

  • b) Reading and Synchronizing Emails (gmail.readonly):gmail.readonly

    • Purpose: Provide communication traceability for contacts and legal cases.

    • Processing: Receive Gmail → Pub/Sub notifications; fetch messages from Gmail; process headers, body, and user-selected attachments; match to contacts and cases; store metadata and content; rebuild full conversation threads.

  • c) Sending Emails (gmail.send):gmail.send

    • Purpose: Allow attorneys to send emails directly from a case.

    • Processing: User drafts the email; we generate the MIME message; send via Gmail API; store a copy for thread continuity.

    • We do not send marketing or automated emails.

3. Data Sharing

We do not sell, share, or disclose Gmail data to external third parties. Email content, attachments, metadata, and tokens are never used for advertising or profiling. We fully comply with Google API Services – Limited Use.

4. Token and Security Management

  • All data is encrypted in transit (HTTPS) and at rest.

  • Tokens are encrypted, isolated, and never shared with third parties.

  • If access is revoked, we stop Gmail access, revoke tokens, and stop Pub/Sub processing.

GOOGLE INTEGRATION (GOOGLE CALENDAR API)

This section explains how Prima Law – Legal Case Management accesses, uses, stores, protects, and shares Google user data obtained through Google Calendar API Services, in compliance with the Google API Services User Data Policy, including all Limited Use requirements.

1. Types of Google Calendar User Data We Access

Our application uses OAuth 2.0 so each user can connect their own Google account. We only access the data strictly required for calendar scheduling and case management workflows:

  • a) email: User’s primary email address.

  • b) profile: First and last name.

  • c) Calendar Free/Busy: Availability information (free/busy time blocks).

  • d) Calendar Events: We may access and/or manage, only as needed by the user:

    • Events data: title, start/end time, timezone, description, location, attendees (if applicable)

    • Calendar metadata: calendarId, calendar name, timezone

    • Timestamps/IDs required for syncing (eventId, updated time)

We do not use Google Calendar data for advertising, we do not sell it, and we do not access more data than necessary. Users can disconnect Google access at any time.

SUBSCRIBERS, CLIENTS, OR CUSTOMERS’ INFORMATION

Your database is encrypted and for the subscriber to access it, the subscriber password is required. Subscriber (you) may initiate a request to recover your password. Prima.Law and BRS cannot provide access to your data without your password. If it becomes necessary for BRS to review your tenancy in Prima.Law, BRS will maintain confidentiality and will not share any resulting information we are given access to, incidentally or otherwise. You will also be responsible for immediately changing your password to maintain the security of your data.

Information divulged by the subscriber to BRS during sales or support calls, conferences, or screen shares will remain confidential.

GENERAL DATA COLLECTION & PROCESSING

What Information Do We Collect?

We may collect and process the following data about you:

  • Information you give us: You may give us information about you by filling in forms on our site www.Prima.Law (our site) or by corresponding with us by phone, e-mail, or otherwise. This includes information you provide when you register to use our site, subscribe to our service, participate in any discussion boards, forums, or other social media functions on our site or enter a competition, promotion, or survey and when you report a problem with our site. The information you give us may include your name, address, e-mail address, and phone number, financial and credit card information, personal description, and photograph. We also store the Content that you upload or provide to the Service to provide you with the features and functionality of the Service.

  • Information we receive from other sources: We may receive information about you from individuals or corporate entities which are subscribers to our service (‘Subscribers’) where you are to be designated a user of our service. We may receive information about you if you use any of the other websites we operate or the other services we provide. We are also working closely with third parties (including, for example, subcontractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them, subject to your agreements with them.

Automatic Anonymous Information

When you visit our site, we collect certain technical and routing information about your computer. For example, we log environmental variables such as browser type, operating system and CPU speed, and the Internet Protocol (IP) address of your originating Internet Service Provider, to try to bring you the best possible service. We also record search requests and results to try to ensure the accuracy and efficiency of our search engine. We use your IP address to track your use of the site, including pages visited and the time spent on each page. We collect this information and use it to measure the use of this website and to improve its content and performance. All of the information that is automatically submitted to us by your browser is considered anonymous information. To the extent we share such information with third parties, it is not traceable to any particular user and will not be used to contact you.

Cookies, Tracking Technologies, and Analytics/Log Files

We use cookies for content personalization, analytics/performance, functional purposes, as well as the ability to access secure areas of our site. Users can control the use of cookies at the individual browser level. If you reject cookies, you may still use our site, but your ability to use some features or areas of our site may be limited.

Technologies such as cookies, beacons, tags, and scripts are used by BRS and our marketing partners, affiliates, or analytics or online customer support service providers. These technologies are used in analyzing trends, administering the site, tracking users’ movements around the site, and gathering demographic information about our user base as a whole. We may receive reports based on the use of these technologies by these companies on an individual as well as aggregated basis.

Log Files: As is true of most websites, we gather certain information automatically and store it in log files. This information may include internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and/or clickstream data. We may combine this automatically collected log information with other information we collect about you. We do this to improve services we offer you, to improve marketing, analytics, or site functionality.

How Do We Use Information We Collect?

We collect personally identifiable information only for providing the services you request, generating statistical studies, conducting marketing research, improving products and services, sending you surveys, and notifying you of new products and any other changes to our site or services that may affect you. When you submit personally identifiable information to us, you understand that you are agreeing to allow us to access, store, and use that information for those purposes. We will not sell or give any personally identifiable information to any third parties.

We may be required by law enforcement or judicial authorities to provide personally identifiable information to the appropriate governmental authorities. If requested by law enforcement or judicial authorities, we will provide this information on receipt of the appropriate documentation. We may also release information to law enforcement agencies or other third parties if we feel it is necessary to protect the safety and welfare of our personnel or to enforce our terms of use. BRS may use the Prima.Law software and platform to show you advertisements relevant to your practice for additional services by trusted partners.

Opt-Out Policy

If at any time you do not wish to receive offers and e-mails from us, we ask that you tell us. You may remove your name from our mailing list by sending us an e-mail addressed to [email protected] and indicating in the subject line “No Offers or E-mail.”

SECURITY, RETENTION, AND USER RIGHTS

1. Security & Storage

We operate secure data networks protected by industry-standard firewall and password protection systems. Our security and privacy policies are periodically reviewed and enhanced as necessary, and only authorized individuals have access to the personally identifiable information provided by our users. All user data, including email metadata, message bodies, attachments, and AI processing inputs, is stored exclusively in secure data centers located within the United States. We do not, however, guarantee that unauthorized, inadvertent disclosure will never occur. Questions regarding data security or compliance can be sent to [email protected].

2. Transfer of Customer Information

Customer lists and information are properly considered assets of a business. Accordingly, if we merge with another entity or if we sell our assets to another entity, our customer lists and information, including personally identifiable information you have provided us, would be included among the assets that would be transferred.

3. Data Retention and Deletion

Subscribers can request the permanent deletion of their data by contacting us at [email protected]. Data deletion will be processed within 30 days of the request. Our data retention policy specifies that we will hold onto data for as long as the account is active. If an account is dormant, data will be retained for a period of up to 24 months before it is securely deleted. Backups may temporarily retain encrypted fragments for disaster recovery only.

4. User Rights: Access, Export, and Deletion

Users or tenant administrators may request:

  • Deletion of email threads or case files

  • Removal of Gmail/Calendar integrations

  • Permanent deletion of AI session outputs and history

  • Full tenant data deletion

  • Export of data in JSON or common database format

Requests: [email protected] (Processed within 30 days).

5. Compliance with CCPA

Our data practices comply with the California Consumer Privacy Act (CCPA). Users have the right to request the deletion of their personal data, know how their data is being used, and opt out of any data sharing via request to [email protected]. Our policies stated above ensure full transparency and user control over personal information.

6. Changes to Our Privacy Policy

Any significant updates or changes to our privacy policy will be communicated through email or a portal notification after login inside the Prima.Law platform, including plain-language summaries of what has changed.

For questions or privacy concerns: Email: [email protected]

Copyright © 2026 Brevort River Studios, LLC PrivacyPolicy | TermsOfService | Immigration Info