Privacy Policy

Last updated: August 12, 2026

This Privacy Policy describes how CaseHive Inc. (“CaseHive,” “we,” “us,” or “our”) collects, uses, and shares information in connection with the CaseHive marketing website (the “Website”) and, at a high level, how we approach information in connection with the CaseHive legal work platform (the “Platform”).

CaseHive is an AI-native legal work platform for law firms and legal teams. It integrates with Microsoft 365. Customer legal documents and related content are designed to remain in the customer’s Microsoft 365 tenant through SharePoint Embedded.

This policy is intended for Website visitors, prospective customers, and other business contacts. If your organization has a customer agreement with CaseHive, that agreement—including any data processing terms—governs Platform customer content and controls if it conflicts with this policy on that subject.

This Website and the Platform are not a law firm, do not provide legal advice, and do not create an attorney-client relationship with you.


1. Scope

This policy covers:

  • Visitors to the Website
  • People who request a demo, contact us, or otherwise submit information through the Website
  • High-level practices relevant to customer and user information on the Platform

This policy does not:

  • Cover third-party websites or services we do not control, including Microsoft 365
  • Replace a customer’s own privacy notices to its clients, employees, or other data subjects
  • Authorize CaseHive to use a law firm’s client confidential information for CaseHive’s own marketing

2. Information we collect

Information you provide

When you use the Website, you may provide:

  • Contact and inquiry details, such as name, email address, company or firm name, role or team size, how you heard about us, and the content of your message
  • Demo or sales correspondence, including information you share in follow-up email or meetings
  • Preferences, such as cookie or analytics choices

Do not submit confidential client files, privileged communications, or other sensitive matter materials through Website forms. Use the Platform and your organization’s Microsoft 365 environment for that content, under your customer agreement.

Information collected automatically

When you visit the Website, we and our service providers may automatically collect:

  • Device and log information, such as IP address, browser type, operating system, referring URL, pages viewed, timestamps, and approximate general location derived from IP address
  • Cookie and similar technology data, as described in Section 5
  • Consent and site preferences stored in your browser (for example, your cookie choice and theme preference)

Platform information (customers)

If your organization uses the Platform, CaseHive may process:

  • Account and workspace information, such as user names, business email addresses, roles, and configuration needed to operate the service
  • Application metadata required to provide matter-centric workflows, permissions, and product functionality
  • Customer content, including legal documents, email, and other matter materials that customers choose to use with CaseHive

Customer legal documents and related content are designed to remain in the customer’s Microsoft 365 tenant through SharePoint Embedded. CaseHive also maintains application-level metadata and other Platform data as required to operate the product. We do not claim that all CaseHive data resides in Microsoft 365.


3. How we use information

We use Website information to:

  • Operate, maintain, and improve the Website
  • Respond to demo requests, contact submissions, and other inquiries
  • Communicate about CaseHive products, events, or updates where permitted by law (you may opt out of marketing emails)
  • Understand how the Website is used, if you consent to analytics
  • Detect, prevent, and investigate fraud, abuse, and security issues
  • Comply with law and enforce our terms

We use Platform information to:

  • Provide, secure, and support the Platform for the customer
  • Authenticate users and administer access
  • Improve reliability, support, and product functionality consistent with the customer agreement
  • Meet legal, security, and operational requirements

We do not use Website or Platform information to provide legal advice.


4. Legal bases (where applicable)

Where data-protection law requires a legal basis, we rely on one or more of the following:

  • Legitimate interests, such as operating the Website, responding to business inquiries, securing our services, and understanding aggregated Website usage
  • Consent, where required—for example, optional analytics cookies, or marketing communications where consent is required
  • Contract, including taking steps at your request before entering a contract (such as a demo discussion) and performing a customer agreement
  • Legal obligation, where we must retain or disclose information

5. Cookies and similar technologies

We use cookies and similar technologies, including browser local storage, for:

  • Essential / strictly necessary uses, such as storing your cookie preference and supporting basic Website functionality. These are always on.
  • Analytics (optional), to help us understand how the Website is used. Analytics is off by default until you accept cookies or enable analytics in Cookie Preferences.

You can change your choice at any time using Cookie Preferences in the Website footer.

We do not currently require analytics in order to use the Website. If you decline analytics, essential functionality still works.

We do not use the Website to run advertising cookies or to sell your personal information.


6. How we share information

We do not sell personal information.

We may share information with:

  • Service providers that host the Website, provide infrastructure, communications, security, or (if enabled) analytics, under contractual confidentiality and use limitations
  • Professional advisors, such as lawyers, bankers, or auditors, where needed
  • Authorities, when required by law, legal process, or to protect rights, safety, or security
  • A successor in connection with a merger, financing, or sale of assets, subject to appropriate protections

We do not share customer legal documents from the Platform for CaseHive’s own advertising.

Microsoft processes customer Microsoft 365 content under Microsoft’s terms and the customer’s Microsoft 365 tenancy. CaseHive does not control Microsoft’s independent privacy practices.


7. Customer legal content, confidentiality, and professional responsibility

CaseHive is built for law firms and legal teams. That creates heightened expectations around confidentiality.

  • Customer content stays with the customer’s tenant. Legal documents and related content used with the Platform are designed to remain in the customer’s Microsoft 365 tenant through SharePoint Embedded.
  • You remain responsible for your professional obligations. Customers are responsible for their own compliance with attorney-client privilege, work-product protection, ethics rules, client confidentiality, conflict checking, and record-retention requirements.
  • Do not treat CaseHive as your counsel. Use of the Website or Platform does not make CaseHive your lawyer or create privilege between you and CaseHive.
  • Limit what you send through the Website. Website forms are for business inquiries, not client-matter intake or document production.
  • Access is the customer’s to govern. Platform access should be limited by the customer through its identity, authorization, and Microsoft 365 controls.

If AI features process customer content, that processing is intended to provide the functionality the customer requests. Specific AI processing, subprocessors, and any model-training practices applicable to customer content will be described in the customer agreement or product documentation when those details are established. This policy does not authorize use of customer legal documents for CaseHive marketing.


8. Retention

We retain Website inquiry and communications data for as long as needed to respond to you, manage our business relationship, and meet legal, tax, security, and accounting requirements, then delete or de-identify it when we no longer need it.

Consent preferences remain in your browser until you clear site data or change your choice.

Platform retention of customer content is primarily controlled by the customer’s Microsoft 365 environment and the customer agreement. CaseHive retains application metadata only as needed to operate, secure, and support the Platform and to meet legal obligations.


9. Security

We use commercially reasonable administrative, technical, and organizational measures designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Platform security is designed around Microsoft 365 identity and tenant-resident customer content. Formal certifications (for example, SOC 2 or ISO 27001) are not claimed in this policy unless CaseHive has separately confirmed they are in place.


10. International transfers

CaseHive may process information in the United States and in other countries where we or our service providers operate. Those countries may have privacy laws that differ from the laws in your jurisdiction.

Where required, we use appropriate safeguards for cross-border transfers, such as contractual protections with service providers.


11. Your privacy rights

Depending on where you live, you may have rights to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete information
  • Export a copy of information you provided
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
  • Opt out of marketing emails
  • Appeal a decision on a privacy request, where local law provides that right

If you are a California resident, you may also have rights under the CCPA/CPRA, including the right to know, delete, and correct personal information, and to opt out of “sale” or “sharing” of personal information as those terms are defined by California law. CaseHive does not sell your personal information and does not share it for cross-context behavioral advertising. We also do not use or disclose sensitive personal information collected via the Website for purposes that California law treats as requiring a separate limit-use right.

To make a request, use the Contact page. We may need to verify your identity before completing the request. If you are a Platform user, we may redirect you to your organization, which is typically the controller of workplace account and customer-content data.

You may also have the right to lodge a complaint with a data protection authority. We encourage you to contact us first so we can try to resolve your concern.


12. Children

The Website and Platform are intended for business use by adults in professional settings. They are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.


13. Third-party services

The Website may link to third-party sites or services (for example, Microsoft or professional networks). Their privacy practices are governed by their own policies, not this one.


14. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. For material changes, we may provide an additional notice on the Website. Continued use of the Website after an update means the revised policy applies to information collected thereafter, and to existing information to the extent permitted by law.


15. Contact us

Questions about this Privacy Policy or our privacy practices can be sent through the Contact page on this Website.

Controller for Website visitor information: CaseHive Inc.