Privacy Policy#
Version 2.0
Last updated: September 24, 2026
Welcome to TensorCase. This Privacy Policy applies to everyone who uses the TensorCase platform and associated applications and integrations (the Services), everyone who visits www.tensorcase.com and its subpages (the Site), and everyone who interacts with us in other ways, including prospective customers, event and webinar attendees, and individuals who apply for roles with us.
It does not apply to third-party applications and services that a customer connects to the Services, or to any other third-party product or business. Those are governed by their own terms and privacy notices.
By using the Services or the Site, you agree to the collection and use of personal information as described in this Policy.
1. Our two roles, and which parts of this Policy apply to you#
TensorCase handles personal information in two distinct capacities. Which one applies determines who is accountable to you and how you exercise your rights.
When we act as a processor. Organisations subscribe to the Services under a written agreement (the Customer Agreement) and operate their own instance of the platform (the Customer Instance). The subscribing organisation (the Customer) decides what information is loaded into its Customer Instance, who may access it, and how long it is kept. Everything a Customer or its authorised users submit to, generate in, or store within the Services is Customer Data.
For Customer Data, the Customer is the controller and TensorCase is the processor. We process Customer Data only on the Customer’s documented instructions, as set out in the Customer Agreement and our Data Processing Addendum (DPA). Where the Customer is itself a processor for another organisation, such as a law firm acting for a client, we act as a sub-processor.
When we act as a controller. We determine the purposes and means of processing for the information we collect about our own business relationships: account and billing records, Site visitors, sales and marketing contacts, support enquiries, event registrations, operational telemetry, and job applicants. We call this Business Data, and this Policy is our notice to you for it. Section 2.2 defines the categories of Business Data we use throughout this Policy.
Where Customer Data or Business Data relates to an identified or identifiable natural person and is protected under applicable data protection law, we refer to it as Personal Data.
What this means in practice. If an organisation has loaded information about you into a Customer Instance, your rights in that information run against that organisation, not against us. If you contact us about it, we will forward your request to the relevant Customer.
2. Personal information we collect#
2.1 Customer Data (processor)#
Customer Data is submitted by Customers and their authorised users. Its categories are determined by the Customer. We do not control, review or curate the content of Customer Data. Our processing of it is governed by the Customer Agreement and the DPA.
2.2 Business Data categories (controller)#
The categories below are used consistently throughout this Policy.
| Category | What it includes | Source |
|---|---|---|
| Account Information | Name, business email address, telephone number, job title, employer, domain, account identifiers and credential references, subscription and transaction history | You, or the Customer that provisions your account |
| Billing Information | Billing contact and address, invoice and payment records, and references to a payment method held by our payment processor. Card and bank details are collected and held by that processor, not by TensorCase | The Customer, and our payment processor |
| Authentication Data | Login and session events, multi-factor authentication status, single sign-on identifiers, and access audit records. Where you sign in through an identity provider, that provider shares your name and email address and, in some configurations, your profile picture and language preference | You, your identity provider |
| Communication Information | Support enquiries and tickets, survey responses, event and webinar registration and attendance records, questions asked during sessions, and the contents of messages you send us | You |
| Log Data | IP address, browser type and settings, request date and time, and the page visited before the Site or Services | Automatic |
| Usage Data | Account identifiers, features used, session duration, frequency of use, volume and type of queries submitted, and error, latency and availability events. Our product analytics tooling is configured not to capture case content, document content or matter data | Automatic |
| Device Information | Device type and name, operating system, device and application identifiers, device settings, and crash data | Automatic |
| Cookie Data | Cookie and similar technology identifiers, as described in section 3 | Automatic |
| Integration Data | The identity of third-party services a Customer connects, and the account identifiers and metadata those services share with us. We do not receive or store passwords for connected services | The connected service, at the Customer’s direction |
| Marketing Information | Business contact details, role and organisation, records of your engagement with our emails, content and events, and business information about organisations, industries and campaign performance received from partners and data providers | You, our partners, data providers, publicly available sources |
| Candidate Information | Information you provide when you apply for a role with us, such as your CV, contact details and references | You |
We also derive an approximate location from your IP address in order to route requests, apply regional settings and detect anomalous access. Approximate location forms part of Log Data.
2.3 Information we receive from others#
Business information about organisations, industries, Site visitors and marketing campaign performance is received from partners, affiliates and data providers and forms part of Marketing Information. We combine it with the Business Data we already hold to keep our records accurate and our outreach relevant.
3. Cookies and similar technologies#
We use cookies, pixels, tags and similar technologies on the Site and, in a limited way, within the Services.
What cookies are. Cookies are small text files placed on your device. Session cookies are deleted when you close your browser. Persistent cookies remain until they expire or you delete them. First-party cookies are set by us. Third-party cookies are set by others.
How we use them.
- Strictly necessary. Authentication, session integrity, load balancing, security and abuse detection. These cannot be switched off without breaking the Services.
- Preferences. Language, communication preferences, saved settings and recording your cookie choices so you are not asked repeatedly.
- Performance and analytics. Understanding how the Site and Services are used, diagnosing errors and measuring availability and latency, so we can improve them.
What we do not do. We do not use advertising, remarketing, behavioural profiling or visitor de-anonymisation technologies, and we do not share Site or Services data with advertising networks or with any third party for advertising, marketing or commercial profiling purposes.
Your choices. Where required by law, we present a cookie notice that lets you accept or reject non-essential cookies, and you can change that choice at any time through the cookie settings link on the Site. You can also block or delete cookies through your browser settings, though parts of the Site and Services may stop working. Cookie choices are specific to the browser and device on which you make them.
Do Not Track. The Site does not currently respond to browser Do Not Track signals. We do honour the Global Privacy Control where applicable law requires it, as described in section 10.2.
4. How we use personal information, and our legal bases#
The table below sets out what we do with Business Data as controller, which categories each purpose uses, and, where the UK GDPR or EU GDPR applies, the legal basis we rely on. Where we rely on legitimate interests we state the interest, and you may request a copy of the balancing assessment using the contact details in section 15.
Our processing of Customer Data is governed by the Customer Agreement, the DPA and the Customer’s instructions, not by this section. The Customer is responsible for identifying its own lawful basis.
| Purpose | Categories used | Legal basis |
|---|---|---|
| Providing, maintaining and supporting the Services and the Site, and administering accounts, provisioning and de-provisioning | Account Information, Authentication Data, Communication Information, Log Data, Usage Data, Device Information, Cookie Data, Integration Data | Performance of a contract with you or your organisation. Where you are associated with a Customer rather than a party yourself, our legitimate interest in delivering and administering the Services under our agreement with that Customer, and the Customer’s interest in receiving them |
| Billing, invoicing, collections and financial record-keeping | Account Information, Billing Information, Communication Information | Performance of a contract. Compliance with a legal obligation for tax, accounting and audit records |
| Authentication, access control and audit logging | Account Information, Authentication Data, Log Data, Device Information | Performance of a contract. Our legitimate interest, and that of our Customers, in restricting access to a platform holding investigation material to the people entitled to it, and in producing a reliable access record |
| Security monitoring, threat detection, incident response, and fraud and abuse prevention | Account Information, Authentication Data, Log Data, Usage Data, Device Information | Legitimate interests. Our interest, and that of our Customers, in protecting the confidentiality and integrity of a platform holding investigation material, and in detecting misuse before it causes harm. Compliance with a legal obligation where a specific obligation applies |
| Diagnosing errors, monitoring availability and performance, and improving the Services, including through aggregated and de-identified analysis of Business Data | Account Information, Log Data, Usage Data, Device Information, Communication Information | Legitimate interests. Our interest in understanding how the Services perform in use, in fixing defects, and in developing the product, and our Customers’ interest in a reliable platform |
| Service, technical and administrative communications, including security notices, changes to terms and changes to sub-processors. These form part of the Services and cannot be opted out of while you hold an account | Account Information, Communication Information | Performance of a contract. Compliance with a legal obligation where the notice is one the law requires |
| Responding to enquiries and providing customer support | Account Information, Communication Information, Usage Data, Log Data, Device Information | Performance of a contract. Our legitimate interest in responding to those who contact us |
| Marketing communications to business contacts, including newsletters, product updates, event invitations and educational content, and measuring engagement with them | Account Information, Marketing Information, Communication Information, Cookie Data, Usage Data | Legitimate interests in promoting our business to professional audiences, or your consent where applicable law requires it. You may opt out at any time, and we will stop |
| Running events, webinars and educational sessions, and following up with attendees | Account Information, Communication Information, Marketing Information | Performance of a contract where you have registered. Our legitimate interest in promoting our business and improving our programme |
| Recruitment | Candidate Information, Communication Information | Steps taken at your request prior to entering a contract. Our legitimate interest in identifying and evaluating candidates for open roles |
| Establishing, exercising or defending legal claims, responding to lawful requests, and meeting regulatory obligations | Any category, limited to what the request or obligation requires | Compliance with a legal obligation. Our legitimate interest in protecting our legal position, our personnel and our property |
| Corporate transactions, including diligence for a merger, acquisition, financing or sale of assets | Account Information, Billing Information, Marketing Information, Usage Data | Legitimate interests. Our interest in making decisions that allow the business to develop, and in conducting such transactions with adequate information |
Where we have aggregated or de-identified Business Data so that it is no longer reasonably capable of being associated with an identified or identifiable person, we may use it for any lawful business purpose. We do not attempt to re-identify it unless the law requires us to. We do not aggregate, de-identify or anonymise Customer Data for our own purposes.
5. AI processing and model training#
The Services use AI to help users search evidence, draft, summarise and analyse.
No training on customer data. We do not use Customer Data to train, fine-tune or improve any machine learning or AI model, whether our own or a third party’s. This is a flat prohibition in our DPA, not a default setting or an opt-out, and we impose the same restriction on our AI sub-processors by contract.
Limits on our AI providers. None of our AI providers uses customer content to train its models. The current list of AI sub-processors is published at https://www.tensorcase.com/subprocessors and forms part of our DPA.
No automated decisions with legal effect. We do not use Customer Data or Business Data to make decisions producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 of the UK GDPR and EU GDPR. Outputs generated by the Services are drafts and analytical aids presented to a human user, who decides what to do with them. A Customer remains responsible for how its personnel use those outputs, and for any Article 22 assessment arising from its own decision-making.
6. How we share and disclose personal information#
Within the Customer Instance. Because of how the Services work, Customer Data, Account Information and Authentication Data are visible to the Customer’s authorised users according to the roles and permissions the Customer configures. We also make Account Information, Usage Data and Log Data available to the Customer that administers your account.
Sub-processors and service providers. We engage third parties to provide cloud infrastructure, AI processing, authentication, product analytics, payment processing, communications and similar services. Depending on the service, these recipients receive Customer Data or categories of Business Data. Each is bound by a written agreement imposing data protection and confidentiality obligations, including the prohibition on model training. Our current list of sub-processors is published at https://www.tensorcase.com/subprocessors and forms part of our DPA.
Third-party services a Customer connects. A Customer may enable integrations with services such as document repositories, email, messaging and collaboration tools. When enabled, Customer Data and Integration Data are shared with those services as directed. They are not operated by us and apply their own privacy practices.
Corporate affiliates. We may share Business Data with our parents, subsidiaries and affiliates, which are bound by this Policy.
Professional advisers. Lawyers, auditors, accountants, bankers and insurers receive Account Information, Billing Information and, where relevant to their engagement, other categories, as necessary for the services they provide to us.
Corporate transactions. In connection with a merger, acquisition, financing, reorganisation, insolvency, sale of assets or similar transaction, or steps in contemplation of one, personal information may be disclosed or transferred subject to appropriate confidentiality arrangements.
Law enforcement and government authorities. If a law enforcement or government agency asks us for Customer Data, we will attempt to redirect the agency to the Customer, and may provide the Customer’s basic contact details for that purpose. If we are compelled to disclose, we will give the Customer reasonable notice and cooperation so that it can seek a protective order or other remedy, unless we are legally prohibited from doing so. We do not disclose Customer Data to any law enforcement or government agency voluntarily.
To protect rights and safety. To establish, exercise or defend legal claims, enforce our agreements, or investigate and prevent fraud, abuse or security incidents.
Aggregated or de-identified data. We may disclose aggregated or de-identified Business Data for any lawful purpose.
With your consent. Where you have asked us to, or agreed that we may.
What we do not do. We do not sell Personal Data, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws. We do not disclose Customer Data, Usage Data, Log Data or Cookie Data to advertising networks or marketing providers.
7. Retention#
Customer Data. Retained and deleted in accordance with the Customer Agreement and the DPA. Retention and deletion settings within the Services are under the Customer’s control.
Business Data. Retained for as long as necessary for the purposes described in this Policy, and afterwards as needed to comply with legal obligations, resolve disputes and enforce our agreements. Where we no longer have a business need or legal reason to hold Personal Data, we delete or anonymise it.
8. International transfers#
TensorCase is headquartered in the United States and operates as a fully remote company. Personal information may be transferred to and processed in countries other than the one in which you are located, including the United States, whose data protection laws may differ from those of your country. Customer Data is stored in the region selected by the Customer, and the locations where it is processed are set out in the Customer Agreement and our sub-processor list.
Transfer mechanisms. We rely on the following, according to the transfer:
- Adequacy. Transfers of Personal Data from the European Economic Area to the United Kingdom are made under the European Commission’s adequacy decision for the United Kingdom. We rely on that decision while it remains in force, and will move the affected transfers onto Standard Contractual Clauses if it lapses or is withdrawn.
- Standard Contractual Clauses. Transfers of Personal Data from the United Kingdom or the European Economic Area to the United States, or to any other country without an adequacy decision, are made under the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum.
- Derogations. In limited cases we may rely on a derogation under Article 49, principally where a transfer is necessary for the establishment, exercise or defence of legal claims.
What we do not rely on. We do not rely on the EU-U.S. Data Privacy Framework or the UK Extension to it.
Representatives. We have appointed representatives under Article 27 of the UK GDPR and Article 27 of the EU GDPR. Their details are in section 15.
9. Security#
We maintain administrative, technical and physical safeguards designed to protect personal information against unauthorised access, loss, disclosure and alteration. Our security practices are described at trust.tensorcase.com. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your rights#
10.1 European Economic Area and United Kingdom#
You have the following rights in relation to Personal Data for which we are the controller:
- Access. To be told whether we process your Personal Data and, if so, to receive a copy together with information about the purposes, categories, recipients, retention periods and sources.
- Rectification. To have inaccurate Personal Data corrected and incomplete data completed.
- Erasure. To have your Personal Data deleted in the circumstances the law provides.
- Restriction. To have our processing restricted in the circumstances the law provides.
- Portability. To receive Personal Data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection. To object to processing based on our legitimate interests. Where you object to direct marketing, we will stop without exception and without weighing anything.
- Withdrawal of consent. Where we rely on your consent, to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out beforehand, or processing carried out on another lawful basis.
- Automated decision-making. Not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. As set out in section 5, we do not make such decisions.
- Complaint. To lodge a complaint with a supervisory authority, in particular in the country of your residence or place of work or where the alleged infringement occurred. We would appreciate the chance to address your concerns first.
There is no charge for exercising these rights. We respond within one month, extendable by a further two months where the request is complex or numerous, in which case we will tell you within the first month.
If your Personal Data is in Customer Data, these rights run against the Customer that controls the relevant Customer Instance, not against us.
Our representatives. TensorCase has no establishment in the United Kingdom or the European Union, and has designated a representative under Article 27 in each. Their details are in section 15.
Our UK representative, LS Law Limited, is the contact point in the United Kingdom for data subjects exercising their rights under the UK GDPR and for the Information Commissioner’s Office. It will acknowledge your correspondence and pass it to us.
Our EU representative, TwoBridge Legal, may be addressed in addition to or instead of us, by supervisory authorities and by data subjects, on all issues relating to our processing of personal data subject to the EU GDPR. It is the contact point for the Irish Data Protection Commission and any other competent supervisory authority.
Neither representative makes data protection decisions on our behalf, accepts liability on our behalf, or acts as a controller or processor of the personal data we process. Contacting a representative does not limit your right to complain to a supervisory authority, and does not affect any legal action you may bring against TensorCase itself.
Supervisory authorities. In the United Kingdom the supervisory authority is the Information Commissioner’s Office. In the EEA it is the supervisory authority of your Member State. Because we have no establishment in the European Union, no single lead supervisory authority applies to our processing and the one-stop-shop mechanism does not apply.
10.2 United States#
Residents of US states with comprehensive consumer privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others, have rights in relation to Personal Data for which we are the business or controller. Subject to the exemptions and verification requirements each law provides, you may:
- Know and access. Request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it, and obtain a copy.
- Correct. Request correction of inaccurate personal information.
- Delete. Request deletion of personal information we have collected about you.
- Port. Obtain a copy in a portable, machine-readable format, or have it transmitted to a recipient of your choice where technically feasible.
- Opt out of targeted advertising, sale and profiling. We do not sell personal information, share it for cross-context behavioural advertising, or engage in profiling in furtherance of decisions producing legal or similarly significant effects. There is accordingly nothing to opt out of, but we honour Global Privacy Control signals where applicable law requires it.
- Non-discrimination. Exercise these rights without being denied service or receiving a different level of service.
Sensitive personal information. We do not collect sensitive personal information as defined under the CCPA for our own purposes as a business. Where sensitive personal information appears in Customer Data, we process it solely as a service provider on the Customer’s instructions, and we do not retain, use or disclose it for any purpose other than performing the Services, do not sell or share it, and do not combine it with personal information from other sources.
Appeals. If we decline to act on your request, you may appeal by writing to us at the address in section 15 with enough information to verify your identity, identify the original request and explain the basis of your appeal. We will respond within 60 days. If we deny your appeal, you may contact your state Attorney General.
California. The categories of personal information we collect, the purposes, and the categories of recipients are set out in sections 2, 4 and 6. We verify requests using the information associated with your account, including your email address, and may require government identification. You may designate an authorised agent to act for you.
11. Notice to authorised users of a Customer Instance#
Where access to the Services is provided to you through an organisation, that organisation administers the Customer Instance and controls the accounts and data within it. Administrators can access and change information in your account, configure retention, export data, and restrict or terminate your access. We are not responsible for the privacy or security practices of that organisation. For questions about how it uses the Services, refer to its own policies or contact it directly.
12. Age limitations#
The Services and the Site are intended for business use and are not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18 as a controller. If we learn that we have, we will delete it.
13. Links to other websites#
The Services and the Site link to websites and services we do not operate. We do not control them and are not responsible for their content or privacy practices.
14. Changes to this Policy#
We may update this Policy as our business, the Services or the law change. We will post the updated Policy on this page with a new version number and effective date. Where a change materially alters your privacy rights, we will provide additional notice, such as by email or through the Services. Changes take effect when posted. If you disagree with a change, you should stop using the Services and the Site, and contact the relevant Customer if you wish to request removal of Personal Data under its control.
15. Contact us#
For any question about this Policy, our practices, or to exercise your rights:
Email: privacy@tensorcase.com
Security matters: security@tensorcase.com
Post
TensorCase Inc. (registration number 10073146)
28 Geary Street, Suite 650 #73
San Francisco, CA 94108
United States
UK representative (Article 27, UK GDPR)
LS Law Limited (company number 09638924)
167-169 Great Portland Street, 5th Floor
London W1W 5PF
United Kingdom
info@lslawservices.com
EU representative (Article 27, EU GDPR)
TwoBridge Legal (Law Society of Ireland Firm No. F11474)
Office 2, Shantraud
Killaloe, Co. Clare, V94 VC4A
Republic of Ireland
enquiries@twobridge.legal
We respond within the timeframe required by applicable law.
Need help? Contact us at support@tensorcase.com