Privacy Policy
Effective date: To be set on adoption
Draft. This document is a working draft prepared for review by counsel and has not yet been adopted. Its terms may change before it takes effect.
This Privacy Policy explains how Goolean Tech (“Goolean”, “we”, “us”) collects, uses and shares information in connection with the SuitPilot website, the SuitPilot Portal, the SuitPilot applications and the edge node and desktop agent software (together, the “Service”).
1. Two kinds of data
The Service handles two categories of information, and we treat them differently.
- Account data is information about our customers and their users: firm name, user names and email addresses, roles, authentication records, billing details, support correspondence and usage records. Goolean is the controller of this data.
- Customer Data is the content our customers process with the Service: case files, debtor information, documents, financial and bank records, and court filings. The customer is the controller of this data and Goolean acts on the customer’s instructions as a processor, under the Terms of Service.
2. Where Customer Data is processed
The Service is built so that Customer Data remains on the customer’s own systems wherever possible. Applications reach case files, documents and bank records through an edge node installed inside the firm, over a signed connection, and read and write that data in place. The iRedact desktop agent processes documents locally and reports page counts, not page content, to the Service.
Some Customer Data is necessarily transmitted to or held briefly by the cloud components of the Service in order to display it to a user or coordinate a job: for example, a document rendered in the browser during attorney review, an AI-generated summary of case notes, candidate addresses shown in the skip-trace workbench, or the metadata of an e-filing run. Bank connectivity for RemitIQ uses Plaid; Plaid’s own privacy policy governs the customer’s interaction with Plaid, and Goolean does not receive or store online-banking credentials.
3. Account data we collect
- Information you provide at signup and in the Portal: firm name, names, work email addresses, phone numbers, roles.
- Authentication data: password hashes, multi-factor authentication secrets, session records, and identifiers received from Microsoft Entra ID when a customer enables single sign-on.
- Billing data: token purchases, wallet balance and usage, auto-recharge settings, receipts and the Stripe customer identifier. Card numbers are entered directly on Stripe’s hosted checkout, saved by Stripe, and never received by Goolean.
- Usage and audit records: which user used which application and when, token consumption, job outcomes, and administrative actions.
- Technical data: IP address, browser and device information, and server logs generated when the website or Service is used.
- Correspondence: messages sent through the contact form or to support.
4. How we use account data
- To provide, secure and support the Service, including authentication, entitlement and audit.
- To sell and meter tokens, run auto-recharge when the customer has enabled it, and issue receipts.
- To respond to enquiries and provide customer support.
- To monitor performance, diagnose problems and improve the Service.
- To send service notices, such as security alerts, changes to terms and billing reminders.
- To comply with legal obligations and enforce our agreements.
We do not sell account data or Customer Data, and we do not use Customer Data to train machine-learning models for other customers.
5. Sharing
We share account data only with:
- Service providers who process it on our behalf, such as our hosting provider, Stripe for payments and Plaid for bank connectivity, under contracts that restrict their use of the data.
- Professional advisers, and authorities where required by law or to protect the rights and safety of Goolean, our customers or others.
- A successor in the event of a merger, acquisition or sale of assets, subject to this policy.
6. Security
We use technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit, signed and scoped requests between cloud applications and edge nodes, per-application role-based access, multi-factor authentication for users, and audit logging. No system is perfectly secure; customers should enable MFA for all users and protect the systems on which edge node and desktop agent software runs.
7. Retention
Account data is retained for as long as the customer has an account and for a limited period afterwards to meet legal, accounting and dispute-resolution obligations. Configuration and account data is made available for export for thirty days after termination and then deleted. Customer Data held on the customer’s own systems is not affected by termination of the Service.
8. Cookies
The marketing website sets no analytics or advertising cookies and loads no third-party scripts. The Portal and applications use cookies strictly to maintain an authenticated session.
9. Your rights
Depending on where you are located, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. Users of a customer’s account should direct requests about Customer Data to that customer; requests about account data can be sent to us through the contact form.
10. International transfers
Account data is processed in the region in which the Service is hosted, to be specified on adoption. Where data is transferred across borders we rely on appropriate safeguards required by applicable law.
11. Children
The Service is intended for business use and is not directed to children under 16.
12. Changes
We may update this policy. Material changes will be notified to account administrators by email or in the Portal before they take effect.
13. Contact
Privacy questions can be sent through the contact form. A postal address and designated privacy contact will be added on adoption.