This Privacy Policy explains how AICSUITE, LLC, a Delaware limited liability company ("AICSUITE," "we," "our," or "us") collects, uses, discloses, retains, and protects personal information when you visit our website at aicsuite.com or use our software-as-a-service platform (collectively, the "Services").
1. Introduction and Scope
AICSUITE provides workforce, operations, and business-management software to service businesses, including court-reporting agencies. This Privacy Policy applies to personal information processed in connection with the Services. It does not apply to third-party websites or services that may be linked from the Services.
2. Our Role: Controller vs. Processor
Depending on the activity, AICSUITE acts either as a data controller or a data processor:
- Controller: For account holders (administrators) of our Services and visitors to our marketing website, we are the controller of personal information we collect directly from you, such as your name, email, and billing details.
- Processor: For personal information that our customers upload, import, or otherwise submit to the Services about their employees, contractors, clients, or other third parties ("Customer Data"), AICSUITE acts as a processor on behalf of the customer. Processing of Customer Data is governed by our Data Processing Agreement.
3. Information We Collect
3.1 Information You Provide
- Account information: name, email address, phone number, organization name, billing address, and password (stored as a salted one-way hash);
- Payment information: processed by our payment provider Stripe; we do not store full card numbers on our servers;
- Communications: support tickets, emails, and feedback you send us.
3.2 Customer Data Submitted to the Services
When you use the Services to manage your workforce, you may submit personal information about employees, contractors, and clients. Customer Data may include:
- Worker identifiers: name, address, phone, email, date of birth;
- Sensitive identifiers: Social Security Numbers (SSNs) and other government identifiers. SSNs are encrypted at rest using AES-256, decrypted only when strictly necessary, and access is restricted to authorized roles via database row-level security;
- Banking and payment details for payroll (account numbers, routing numbers); these are encrypted at rest;
- Worker classification (employee vs. independent contractor), pay rates, tax forms, and payroll history;
- Job, assignment, schedule, client, invoice, and payment records you enter into the platform.
3.3 Information Collected Automatically
- Device and log data: IP address, browser type, operating system, referring URLs, pages viewed, and timestamps;
- Usage data: features accessed, actions taken, and diagnostic information used for security, debugging, and product improvement;
- Cookies and similar technologies: see our Cookie Policy.
3.4 Information From Third Parties
We may receive limited information from third parties such as payment processors (e.g., transaction status from Stripe), authentication providers, and analytics providers.
4. How We Use Information
We use personal information to:
- provide, operate, maintain, and improve the Services;
- authenticate users, secure accounts, prevent fraud, and enforce our Terms of Service and Acceptable Use Policy;
- process subscription payments and send transactional communications;
- provide customer support and respond to your inquiries;
- generate aggregated, de-identified analytics to understand usage patterns;
- comply with applicable legal obligations, court orders, and lawful government requests;
- send service announcements, security notices, and (where lawful) marketing communications you may opt out of.
We do not sell personal information. We do not use Customer Data (including SSNs or other sensitive identifiers) to train third-party AI models. AI features that operate on Customer Data do so only within the scope of providing the Services to the customer who owns that data.
5. Legal Bases for Processing (GDPR / UK GDPR)
When subject to the EU or UK GDPR, we rely on the following legal bases:
- Performance of a contract — to deliver the Services you have requested;
- Legitimate interests — for security, fraud prevention, product improvement, and limited marketing to existing customers;
- Legal obligation — to comply with applicable laws;
- Consent — where required (e.g., certain cookies or marketing); consent may be withdrawn at any time.
6. Sharing and Disclosure
We share personal information only as described below:
6.1 Service Providers (Subprocessors)
We engage trusted third-party service providers to operate the Services. Each is bound by written confidentiality and data-protection obligations. See our full Subprocessors list. Current subprocessors include:
- Supabase — database, authentication, and storage (United States);
- Amazon Web Services (AWS) — application hosting and AI inference via AWS Bedrock (United States);
- Cloudflare — content delivery, DNS, and DDoS protection (United States);
- Stripe — subscription billing and payment processing (United States).
6.2 Legal Requirements
We may disclose information when we believe in good faith that disclosure is required to comply with a law, regulation, legal process, or lawful governmental request; to protect the safety of any person; to address fraud or security issues; or to enforce our agreements.
6.3 Business Transfers
If AICSUITE is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to the protections of this Privacy Policy.
6.4 With Your Consent
We may share information for other purposes with your consent or at your direction.
7. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, or as required by law (for example, payroll and tax records). Specifically:
- Customer Data: retained for the duration of the customer's subscription. Following termination, customers may export data for thirty (30) days, after which Customer Data is deleted or de-identified within sixty (60) days, unless longer retention is required by law.
- Account records: retained for the life of the account and for a reasonable period afterward to comply with legal and audit requirements.
- Log data: typically retained for up to twelve (12) months.
- Backups: encrypted backups may persist for up to thirty (30) days following deletion.
8. Security Measures
We implement administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption at rest — AES-256 for sensitive identifiers (SSNs), banking details, and similar fields;
- Encryption in transit — TLS 1.2 or higher for all connections;
- Row-Level Security (RLS) — enforced at the PostgreSQL database layer to provide tenant isolation;
- Role-Based Access Control — least-privilege access across our five-tier role hierarchy (Administrator, Manager, Staff, Contractor, User);
- Authentication — secure password hashing, JWT-based session tokens, and optional multi-factor authentication;
- Monitoring — application and infrastructure logging, anomaly detection, and security alerting;
- Vendor management — written agreements with all subprocessors handling personal information.
Despite our safeguards, no system is completely secure. See our Security Overview for additional detail.
9. Your Rights (General)
Subject to applicable law, you may have the right to access, correct, update, port, restrict, or delete personal information we hold about you; object to or restrict certain processing; or withdraw consent where processing is based on consent. To exercise these rights, email privacy@aicsuite.com.
If you are an employee, contractor, or client of an AICSUITE customer and wish to exercise rights regarding Customer Data, please contact that customer directly; we will assist them in responding to your request as required by law.
10. U.S. State Privacy Rights (CCPA/CPRA and Similar Laws)
Residents of California, Colorado, Connecticut, Virginia, Utah, and other U.S. states with comprehensive privacy laws have certain rights:
- Right to know what categories of personal information we have collected, the sources, the purposes, and the categories of third parties to which it was disclosed;
- Right to access a copy of personal information;
- Right to correct inaccurate personal information;
- Right to delete personal information (subject to exceptions);
- Right to opt out of "sales" or "sharing" of personal information for cross-context behavioral advertising. AICSUITE does not sell or share personal information for these purposes;
- Right to limit use and disclosure of sensitive personal information;
- Right to non-discrimination for exercising rights.
To submit a request, email privacy@aicsuite.com. We will verify your identity before responding. You may designate an authorized agent to submit a request on your behalf with appropriate proof of authorization.
11. GDPR / UK GDPR Rights
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following additional rights with respect to personal information of which AICSUITE is the controller: access, rectification, erasure, restriction, portability, and objection. You also have the right to lodge a complaint with your local supervisory authority.
12. Children's Privacy
The Services are not directed to children under the age of sixteen (16) and we do not knowingly collect personal information from children. If we learn that we have collected such information, we will delete it promptly. Contact us at privacy@aicsuite.com with any concerns.
13. International Data Transfers
AICSUITE is based in the United States and processes personal information in the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in countries with data protection laws that differ from those of your country. Where required for transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms with our subprocessors.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on this page and updating the "Last Updated" date above. Where required by law, we will provide additional notice (such as email).
15. Contact / Data Protection Officer
For privacy questions, requests, or complaints, contact us:
- Email: privacy@aicsuite.com
- General legal inquiries: legal@aicsuite.com
- Entity: AICSUITE, LLC, a Delaware limited liability company
Questions about this document?
Email us at legal@aicsuite.com
AICSUITE, LLC · A Delaware limited liability company