FirmForms

Privacy Policy

Last updated: 4 August 2026

Plain-language note. FirmForms is in early access. This policy explains what we collect and why. It is a starting point and not legal advice; have counsel review it before you rely on it.

This Privacy Policy explains how FirmForms ("we", "us") handles personal data when firms use FirmForms (the "Service"). It covers two kinds of people: the firm users who hold an account, and the firm's clients who receive and sign engagement letters.

Our role

For the firm's own account data, we are the data controller. For the firm's client data (names, emails, letter content, signatures) that a firm puts into the Service, the firm is the controller and we are the processor, acting on the firm's instructions to provide the Service.

What we collect

CategoryExamples
Firm account dataEmail address, name, firm name, plan.
Engagement contentEngagement-letter text, client name and email you enter, engagement status.
Signature dataSigner name, IP address, timestamp, consent, user agent, and the sealed signed PDF (audit trail).
Technical dataLog data, approximate location from IP, session cookie.

How we use it

We do not sell personal data, and we do not use your engagement content or client data to train advertising or unrelated models.

Service providers (subprocessors)

We use a small number of vendors to run the Service:

ProviderPurpose
Amazon Web Services (Lightsail, US)Application and database hosting.
CloudflareDNS, CDN, and TLS for our websites.
ResendSending transactional email.
PolarSubscription billing (when paid plans are live).

Cookies

We use a single essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.

Data retention

We keep account and engagement data for as long as your account is active. Signed documents are retained so you have a record. You can delete engagements or your account; when you delete your account we delete or anonymise your data within a reasonable period, except where we must retain it to comply with law.

Security

Data is encrypted in transit (TLS). We restrict access, store the minimum needed, and take reasonable technical and organisational measures. No method of transmission or storage is perfectly secure, and during early access our controls are still maturing; do not upload data more sensitive than the Service is intended for.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, or to object to certain processing. Firm users can exercise these in-product or by contacting us. If you are a firm's client, please contact the firm that sent you the letter; we will assist that firm as its processor.

International transfers

The Service is hosted in the United States. If you access it from elsewhere, your data will be transferred to and processed in the US.

Children

The Service is for businesses and is not directed to children under 16. We do not knowingly collect their data.

Changes

We may update this policy; material changes will be posted here with a new date and, where appropriate, emailed.

Contact

Privacy questions or requests: [email protected].