Privacy Policy — Trial Commander
Effective Date: September 1, 2026 Last Updated: September 1, 2026
⚠ LEGAL REVIEW REQUIRED — Template drafted to Florida and federal privacy standards. Require counsel review covering FL Stat. § 501.171, Florida Bar Rule 4-1.6(e), and applicable data-protection law before publication.
1. Who We Are
Trial Commander ("Service") is operated by Navarro Hernandez, P.L. ("we," "us," "our"). This Privacy Policy describes how we collect, use, store, and disclose information in connection with the Service.
Controller and Processor Roles:
- For Customer Data (client information, matter details, time entries, trust records), the law firm customer is the data controller and we act as the data processor.
- For Account Data (user account info, billing info), we are the controller.
See our Data Processing Agreement for details on our obligations as a data processor.
2. Information We Collect
2.1 Information You Provide
Account Information:
- Firm name, address, email, phone
- Attorney name, Florida Bar number, role
- Authentication credentials (managed by Clerk)
- Billing information (managed by Stripe — we never see credit card numbers)
Customer Data (entered by you into the Service):
- Client information (name, contact info, case details)
- Matter information (court, judge, case number, strategy notes)
- Time entries, invoices, payments
- Trust account transactions and reconciliations
- Documents you upload (fee agreements, exhibits, pleadings)
2.2 Information Collected Automatically
Usage Data:
- IP address, browser type, device type
- Pages visited, features used, time spent
- Performance metrics (page load times, errors)
Audit Log Data:
- Records of significant actions (who, what, when) for compliance and security. Does NOT include entity content (narratives, notes), only metadata.
Cookies and Similar:
- Session cookies (required for authentication — managed by Clerk)
- Preference cookies (remember UI settings)
- No advertising or third-party tracking cookies
2.3 Information from Third Parties
- Clerk (authentication): email address, MFA status
- Stripe (billing): subscription status, payment history metadata
3. How We Use Information
We use information to:
- Provide, maintain, and improve the Service
- Process transactions (subscription billing, feature access)
- Send transactional emails (invitations, invoices, payment failures)
- Respond to support requests
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations (tax records, court orders)
- Send product updates and service announcements (not marketing, which requires separate opt-in)
We do NOT:
- Sell Customer Data or Account Data
- Use Customer Data to train machine learning models
- Share Customer Data for advertising purposes
- Access Customer Data except as necessary to provide support (with your authorization), investigate abuse, or comply with law
4. AI Features and Third-Party Processors
When you use AI features (fee petition drafting, AI assistant, legal research), relevant data is sent to Anthropic, Inc. via the Claude API.
Under our Zero Data Retention (ZDR) tier agreement with Anthropic:
- Customer Data sent to Claude is processed to generate responses
- Anthropic does NOT retain the data after the response is generated
- Anthropic does NOT use your data to train models
- The data is not accessible to Anthropic employees or third parties
See our AI Disclosure for full detail.
Other Third-Party Processors:
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Clerk | Authentication | User identity, credentials | USA |
| Stripe | Payment processing | Billing info, payment methods | USA |
| Anthropic | AI features | Matter data sent to AI (ZDR) | USA |
| Postmark | Transactional email | Recipient email, subject, body | USA |
| Sentry | Error monitoring | Stack traces, request metadata (PII-scrubbed) | USA |
| Cloudflare R2 / AWS S3 | File storage | Uploaded documents (encrypted) | USA |
| Upstash | Rate limiting | IP addresses, user IDs (hashed) | USA |
| Microsoft Azure | Hosting and database | All Customer Data (encrypted at rest) | USA (East US 2 — Virginia) |
All processors are contractually obligated to protect Customer Data. See DPA for the full list of sub-processors.
5. Data Security
We implement industry-standard security practices:
Technical:
- TLS 1.2+ for all data in transit
- AES-256 encryption at rest (database + field-level for privileged data)
- Passwordless and multi-factor authentication options
- Role-based access control with least privilege
- Tamper-evident audit log with Merkle-chain integrity
- Automated daily backups with tested restore procedure
- Security headers (HSTS, CSP, X-Frame-Options)
- Rate limiting and abuse prevention
- Regular security updates and dependency scanning
- Annual third-party security audit
Administrative:
- Background checks on employees with production access
- Principle of least privilege for employee access
- Mandatory security training
- Incident response plan with 72-hour notification commitment
Physical:
- SOC 2 compliant hosting (Microsoft Azure)
6. Data Retention
See Terms of Service § 8 for retention schedule.
Summary:
- Customer Data: retained during active subscription + 30 days post-cancellation
- Backups: up to 90 days after deletion
- Audit logs: up to 7 years
- Account/billing data: as required for tax and financial compliance (typically 7 years)
7. Your Rights
7.1 As a Law Firm Customer
You can at any time:
- Access your data via the Service
- Correct inaccuracies in your Account Data
- Export your data (time records, trust records, matter data)
- Delete your data (via account cancellation)
7.2 As a Client User (Client Portal)
You can:
- View your own matter information, invoices, and trust balance
- Contact your attorney's firm for corrections or deletions
- Request your information be transferred to a different firm (via your attorney)
7.3 Privacy Rights by Jurisdiction
Florida residents — We comply with FL Stat. § 501.171 (data breach notification) and Florida Bar Rule 4-1.6(e) (attorney confidentiality).
California residents — Under CCPA, you have rights to know, delete, correct, and opt out of sale. We do not sell personal information.
EEA/UK residents — Under GDPR/UK GDPR, you have rights of access, rectification, erasure, restriction, portability, and objection. Our lawful basis is contractual necessity (for account data) and legitimate interest (for security data). Contact privacy@trialcommander.com to exercise rights.
8. Security Incidents
If we experience a data breach affecting your information, we will:
- Notify affected customers within 72 hours of confirmation
- Provide details about the scope, data affected, and remediation
- Assist you in your own breach-notification obligations under FL Stat. § 501.171 or other applicable law
These steps follow our documented internal incident response plan.
9. Children
The Service is not intended for use by anyone under 18. We do not knowingly collect information from minors. If you believe a minor has provided information to us, contact privacy@trialcommander.com for removal.
10. International Transfers
Trial Commander is hosted in the United States. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S. For EEA/UK users, we rely on Standard Contractual Clauses (SCCs) where applicable.
11. Changes to This Policy
We may update this Privacy Policy on 30 days' notice. Material changes require customer opt-in; minor changes take effect automatically.
12. Contact
- Privacy Requests: privacy@trialcommander.com
- Security Issues: security@trialcommander.com
- General Support: support@trialcommander.com
- Postal: Navarro Hernandez, P.L., 66 West Flagler St, 6th Floor, Miami, FL 33130
Template version 1.0 — requires counsel review before publication.