Privacy Policy

Covers: forsivo.com and the Forsivo platform Effective · Version 1

If you are a client of a law firm that uses Forsivo, this is probably not the document you want. Your relationship is with your firm, not with us. Your firm decides what it collects from you and publishes its own privacy notice inside the portal. Section 5 explains the division; the short version is that we hold your information on your firm's behalf and act on your firm's instructions.

1. Visiting this website

This site sets no cookies, runs no analytics, and loads nothing from another company's servers. The fonts, images, stylesheet and script all come from forsivo.com. Reading this page tells no third party that you read it.

Our web host keeps ordinary server logs — the requesting IP address, the page requested, the time, and the browser's user-agent string. That is how a web server works; it is used to keep the site running and to investigate abuse, and we do not use it to build a profile of you. The site is hosted by Hostinger.

There is no tracking pixel here, no advertising network, and nothing to consent to. That is why you were not shown a cookie banner: there was nothing to ask about.

2. Writing to us

There is no form on this site. If you want early access, or have any other question, you send an email to an @forsivo.com address and it arrives in our inbox. Beyond the server logs described in section 1, nothing is collected from you by this website — there is no submission to process, no form provider in the middle, and no record of you here unless you choose to write.

So what we hold is simply the email you sent: your address, whatever name your mail client puts on it, and what you wrote. We keep it, and our reply, so that we have a record of the conversation.

We use it to reply to you, and for nothing else. We do not sell it. We do not add you to a marketing list. We do not enrich it against third-party data. There is no automated sequence — a person reads it and a person answers.

Our email is hosted by Hostinger, which handles delivery and storage.

Ordinary email is not a secure channel. Please don't send confidential client information, Social Security numbers, or account details to us this way. If you are already working with a firm that uses Forsivo, the portal is where that belongs — not our inbox.

3. Firm staff using the platform

For people at a firm with a Forsivo account, we hold what an account requires: name, email address, role, firm, and sign-in records — when someone signed in, from what network address and browser. Staff authentication runs through an identity provider we operate at login.forsivo.com.

We use it to run the platform: signing people in, applying the permissions the firm configured, keeping the audit trail, and supporting the firm when it asks us to.

4. Client information in the platform

Most of the personal information inside Forsivo does not belong to us in any meaningful sense. It is a law firm's client file, and the firm decides what goes in it.

The firm is the one making the decisions; we host and process on the firm's instructions. That includes everything the platform collects through the client portal: messages, uploaded documents, questionnaire answers, contact details, electronic signature records, and payment records. It also includes the sensitive categories the platform is built to hold — Social Security numbers, tax identifiers, bank and account details, and a structured inventory of a client's assets.

It also includes information a client provides about other people: family members, beneficiaries, fiduciaries, and financial advisors, who never see the portal themselves. If one of those people asks us what we hold about them, we will forward the request to the firm, because the file is the firm's and answering for it is the firm's.

If you are a client and you want to know what is held about you, why, or for how long — ask your firm. The firm publishes its own privacy notice inside the portal, and it is that notice, not this one, that describes your file. We will not disclose the contents of a firm's file to anyone but the firm.

What you tell your attorney is protected by attorney-client privilege and by the firm's professional duty of confidentiality. Nothing in this policy narrows either, and we do not treat our access to a firm's data as a waiver of anything.

5. Who else sees any of it

We use service providers to run the platform. They see what they need to see to provide their service and are not permitted to use it for their own purposes.

WhatWhoSees
Website and email hostingHostingerServer logs for forsivo.com; email we send and receive
Platform hostingAmazon Web ServicesStores and serves platform data; encryption keys are managed in AWS KMS
Staff sign-inAuth0Staff authentication events
Outbound platform emailAmazon SESMessages the platform sends on a firm's behalf
Card paymentsLawPayPayment details entered by the payer at the point of payment. Card numbers never reach Forsivo systems — the payer enters them into fields hosted by LawPay and we receive only a token.

Otherwise: only with your instruction, or where the law requires it. Where we receive a legal demand for a firm's data, we will tell the firm unless we are prohibited from doing so, so that the firm can assert privilege on its client's behalf.

We do not sell personal information, and we do not use it for advertising or to train machine learning models.

6. How long we keep it

Early-access enquiries
Kept while we are in contact and for a reasonable period afterwards, then deleted. Ask us to delete yours sooner and we will.
Server and email logs
Kept for a short operational period, then rotated out.
A firm's data in the platform
Kept for as long as the firm's account is open, and for 90 days after it closes so the firm can export it — see the terms of service.
Audit records
Append-only and retained — see section 9.

7. Your choices

Ask us for a copy of what we hold about you, or to correct it, at any time. Write to privacy@forsivo.com.

State privacy rights

Depending on where you live, a state privacy law may give you rights over your personal data — typically to see it, to correct it, and in some cases to opt out of certain uses of it. Which law applies turns on where you are, not where we are.

Where the information sits in a law firm's client file, the firm decides what is collected and why, and we hold it on the firm's behalf: send those requests to your firm. If you send one to us, we will forward it and support the firm's response.

Where we hold information in our own right — an email you sent us, a firm staff account, this website's server logs — write to privacy@forsivo.com and we will deal with it ourselves.

On deletion, please read section 8 first: some records in the platform cannot be altered, by design.

Marketing email

Marketing email the platform sends on a firm's behalf carries a one-click unsubscribe link in its footer. Opting out stops solicitation; it does not stop the mail about your own matter — a booking confirmation or a fee agreement is not advertising, and treating an opt-out as a blanket block would cut you off from your own file. See email preferences.

8. What we will not promise

We cannot promise complete erasure, and we are not going to pretend otherwise.

The platform's audit log, its published legal documents, and its records of who accepted what are append-only at the database level: the system physically refuses to update or delete them. That is deliberate. An audit trail that can be edited is not an audit trail, and a record of acceptance that can be rewritten proves nothing about what someone was actually shown.

So we offer access and correction, and we can delete substantive content. We cannot make the audit trail forget that something happened. If a right of erasure applies to you and this is a problem, tell us — it is an architectural question, not a wording one, and we would rather discuss it than quietly write a clause we cannot honour.

9. Security

The controls the platform implements:

Forsivo holds no third-party security certification. The list above is a description of what is implemented. It is not SOC 2, HIPAA attestation, or ISO 27001, and you should not read it as any of those. We would rather name the controls than imply an audit we have not had.

If we become aware of unauthorised access to data we hold, we will notify the affected firm without undue delay and support its own notification obligations. Report a suspected vulnerability to security@forsivo.com.

10. Children

Forsivo is software for law firms. It is not directed at children, and we do not knowingly collect information from a child through this website. A firm's file may of course name a minor — a beneficiary, for instance — and that information is the firm's to hold under its own notice.

11. Changes

If we change this policy we will post the revised version here with the date it took effect, and we will tell firm administrators about anything material rather than relying on you to notice.

12. Contact

Privacy questions: privacy@forsivo.com
Security reports: security@forsivo.com
Anything else: hello@forsivo.com

Forsivo LLC, an Oregon limited liability company. We handle privacy correspondence by email; if you need a postal address for formal service, ask and we will provide it.


See also the terms of service, the portal platform terms, and about our emails.