Privacy Policy
Effective date: April 26, 2026 · GentleCase, Inc.
GentleCase, Inc. ("GentleCase", "we", "us") operates the GentleCase platform — case management software for immigration law firms. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you or your firm uses our service.
1. Information We Collect
Account data. When a firm signs up, we collect contact name, email address, firm name, and billing information.
Client data processed on your behalf. Immigration law firms upload and manage client records including names, dates of birth, nationality, immigration status, government identification numbers (A-Number, passport, SSN), and case documents. This data is processed under your instruction as data controller; GentleCase acts as a data processor.
Usage data. We collect logs of actions taken within the platform (page views, feature usage, session duration) for security auditing and service improvement. Logs are associated with user accounts, not with client PII.
Communications. If you contact us by email or through the platform, we retain those communications to resolve your inquiry.
2. How We Use Your Information
- To provide, operate, and maintain the GentleCase platform.
- To process transactions and send billing-related communications.
- To respond to support requests and improve the service.
- To detect and prevent fraud, abuse, or security incidents.
- To comply with legal obligations.
We do not sell your data or your clients' data. We do not use client PII for marketing or analytics.
3. Data Storage and Security
All data is stored in U.S. Azure regions (East and West). Sensitive fields — SSN, passport numbers, A-Numbers — are encrypted at rest using AES-256 with keys managed in Azure Key Vault. All data in transit is protected by TLS 1.3. Client documents are stored in Azure Blob Storage and delivered via time-limited SAS URLs; files never traverse GentleCase application servers.
Every record change is captured in a tamper-evident audit log that includes user identity, timestamp, and IP address.
4. Data Sharing and Sub-processors
We share data with sub-processors only to operate the service:
- Microsoft Azure — cloud infrastructure and blob storage.
- Stripe — payment processing. Stripe does not receive client PII.
- Postmark — transactional email. Email content does not include client PII.
We do not share data with third parties for advertising or resale.
5. Data Retention
We retain account data for the duration of your subscription plus 90 days after termination, after which it is permanently deleted. Law firms may export all data at any time before account closure. Client data is retained per your firm's configuration, subject to a minimum of 12 months for audit-log purposes.
6. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete personal data we hold about you. To submit a data subject request, email privacy@gentlecase.com. We respond within 30 days.
For GDPR purposes, GentleCase, Inc. is the data processor for client records; the law firm is the data controller. Firms seeking to exercise data subject rights on behalf of a client should use the platform's built-in right-to-deletion workflow or contact us directly.
7. Cookies
The marketing site uses no tracking cookies. The application uses a single session cookie required for authentication; it expires on logout or after 8 hours of inactivity.
8. Children's Privacy
GentleCase is a B2B service intended for use by law firms and their staff. We do not knowingly collect personal information from anyone under 18.
9. Changes to This Policy
We will notify active account holders by email at least 14 days before material changes take effect. Continued use of the service after the effective date constitutes acceptance.
10. Contact
GentleCase, Inc.
privacy@gentlecase.com
This document was last reviewed by GentleCase legal counsel on April 26, 2026.
