Privacy Policy
CASE IT — Judicial Behaviour Insights Platform
Operated by CASE IT Legal
Fourteen sections. Open any one, or all of them.
1. IntroductionThis policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Using the Platform means you accept it.
CASE IT Legal (“we”, “us”, “our”) operates the CASE IT platform. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using the Platform, you consent to the practices described in this policy.
2. Information We CollectWe collect what you give us (name, email, password, optional firm name and practice profile, the notes, diary entries, watch lists and data-error reports you create, and support messages) and what the Platform records (usage, device, IP address, cookies, error data). Stripe handles card details. We do not collect government identifiers, health or biometric data, or information about children.
2.1 Information You Provide
| Data type | When collected | Purpose |
|---|---|---|
| Name and email address | Account registration | Account creation, communication |
| Password | Account registration | Authentication (stored as bcrypt hash — never stored in plaintext) |
| Payment information | Subscription purchase | Payment processing (handled entirely by Stripe — we do not store card numbers) |
| Organisation/firm name | Account registration (optional) | Account context, analytics |
| Practice profile (professional role, practice areas, primary jurisdiction, firm size) | Onboarding or your profile page (optional) | Showing the matter types and courts relevant to your practice first |
| Content you create (private notes on profiles, appearance diary entries including matter titles, watch lists, data-error reports) | When you use those features | Providing the feature to you. Notes and diary entries are visible only to you; data-error reports are read by us to correct the record and are never published |
| Support communications | When you contact us | Responding to enquiries |
2.2 Information Collected Automatically
| Data type | How collected | Purpose |
|---|---|---|
| Usage data | Platform activity | Search queries, page views, features used — to improve the Platform |
| Device and browser info | Web browser | Compatibility and debugging |
| IP address | Server logs | Security, rate limiting, fraud prevention |
| Error and performance data | Sentry integration | Debugging and service reliability |
2.3 Information We Do NOT Collect
- Credit card numbers or banking details (Stripe handles all payment processing)
- Government identifiers (Tax File Numbers, Social Security Numbers)
- Health information or biometric data
- Information about children under 18
3. How We Use Your InformationWe use it to run your account, talk to you about the service, improve the Platform and keep it secure. We do not sell it, use it for advertising profiles, or make automated decisions with legal effect.
- Providing the Service: Creating and managing your account, authenticating your identity, delivering Platform features, processing payments, and tracking usage quotas.
- Communicating With You: Responding to support requests, sending service-related notifications (billing, subscription changes, security alerts), and notifying you of material policy changes.
- Improving the Platform: Analysing aggregated and anonymised usage patterns, identifying errors, and understanding which features are most valuable.
- Security and Compliance: Detecting fraud and abuse, enforcing our Terms of Service, and complying with legal obligations.
We do not sell your personal information, use it for advertising profiling, or make automated decisions that produce legal effects.
4. How We Share Your InformationWe do not sell or rent personal information. We share it only with the service providers listed below, when the law requires, or in a business transfer, of which we would notify you.
We do not sell, rent, or trade your personal information. We share information only with the following service providers who process data on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | United States |
| Resend | Transactional email delivery | United States |
| Sentry | Error monitoring | European Union (Germany) |
| PostHog | Product analytics (only if you accept analytics cookies; your name and email are not sent) | United States |
| Fly.io | Infrastructure hosting | Sydney, Australia |
We may also disclose information if required by law, regulation, or legal process, or in connection with a merger, acquisition, or sale of assets (with prior notice to affected users).
5. Data About Judges, Legal Practitioners, and CourtsJudge, practitioner and firm information comes from public court records. We use public professional data only, and every insight traces to its source.
The Platform processes and displays information derived from publicly available court records and government databases (NSW Caselaw, the Open Australian Legal Corpus, CourtListener, the Federal Judicial Center, and the US Sentencing Commission). This includes judge names, court appointments, biographical information, legal practitioner names, professional admission details, and aggregated case metrics.
Our data principles: we use public data only, all insights are traceable to source records, we maintain a complete audit trail, and we analyse professional conduct only — never personal lives.
6. Data SecurityWe protect data with encryption in transit, hashed passwords, access controls and rate limiting. No system is completely secure.
- Encryption in transit: All data is encrypted using TLS/HTTPS
- Password security: Passwords are hashed with bcrypt and never stored in plaintext
- Authentication: JWT-based with secure token handling
- Access controls: Database access restricted to authorised services
- Rate limiting: API rate limiting to prevent abuse
No method of electronic transmission or storage is 100% secure. We use commercially reasonable measures to protect your information but cannot guarantee absolute security.
7. Cookies and TrackingEssential cookies keep you signed in. Analytics cookies are optional: none are set, and no analytics events are sent, unless you accept them in the cookie banner.
| Technology | Type | Purpose |
|---|---|---|
| Session cookie | Essential | Maintains your logged-in session |
| JWT token | Essential | Authentication |
| PostHog | Analytics (optional) | Usage analytics, set only if you accept analytics cookies. Persistent (up to 1 year) |
| Sentry | Functional | Error tracking and performance |
Essential cookies are required for the Platform to function. Analytics cookies (PostHog) are optional. They are not set, and no analytics events are sent, unless you accept them in the cookie banner. You can decline with no loss of functionality, and we respect your browser’s Do Not Track signal.
8. Data RetentionWe keep account data while your account is open plus 30 days, billing records for 7 years, usage logs for 12 months, error logs for 90 days and support messages for 3 years.
| Data type | Retention period |
|---|---|
| Account information | Duration of account + 30 days after deletion |
| Payment and billing records | 7 years (Australian tax law) |
| Usage logs | 12 months (then anonymised) |
| Error logs | 90 days |
| Support communications | 3 years after resolution |
9. Your RightsYou can ask to see or correct your information, and complain to privacy@caseit.legal. We respond within 30 days. EU, EEA and UK users have additional rights.
Under the Australian Privacy Principles, you have the right to:
- Access: Request access to the personal information we hold about you. We will respond within 30 days.
- Correction: Request correction of inaccurate or incomplete information. Most details can be updated directly in your account settings.
- Complaint: Lodge a complaint with us at privacy@caseit.legal. We will investigate and respond within 30 days.
- Opt Out: Unsubscribe from non-essential communications at any time via the unsubscribe link in any email.
Additional Rights for International Users
- EU/EEA (GDPR): You may also have the right to data portability, erasure, and to restrict or object to processing. Our lawful basis for processing is contract performance and legitimate interests. Contact us to exercise these rights.
- United Kingdom (UK GDPR): The same rights apply as for EU/EEA users above, including data portability, erasure, and the right to restrict or object to processing. Contact privacy@caseit.legal to exercise these rights.
10. Data Breach NotificationIf a breach is likely to cause serious harm, we assess it within 30 days, notify the regulator, and tell affected people what happened and what they can do.
10.1 Notifiable Data Breaches (Australia)
CASE IT Legal complies with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of a data breach likely to result in serious harm, we will:
- Contain the breach and assess whether it is an eligible data breach under the NDB scheme (within 30 days of becoming aware);
- If eligible, notify the relevant regulator as soon as practicable;
- Notify affected individuals directly, or through a public notice on our website where direct notification is not reasonably possible.
10.2 Reporting Security Incidents
To report a security incident, contact security@caseit.legal. We maintain an internal breach response procedure with designated personnel, assessment timelines, and escalation paths.
11. International Data TransfersOur main systems are in Sydney. Some providers are in the United States and the European Union, and we take reasonable steps to give transferred data comparable protection.
Our primary infrastructure is in Sydney, Australia. Some sub-processors are in the United States and European Union (see Section 4). When data is transferred outside Australia, we ensure it receives protection comparable to the Australian Privacy Principles through contractual obligations with sub-processors.
12. Children’s PrivacyThe Platform is not for anyone under 18, and we delete a child's information if we find it.
The Platform is not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will delete it promptly.
13. Changes to This PolicyWe notify you of material changes.
We may update this Privacy Policy from time to time. Material changes will be notified via email or Platform notification at least thirty (30) days in advance. We encourage you to review this policy periodically.
14. Contact Us
For questions or requests regarding this Privacy Policy:
CASE IT Legal
Email: privacy@caseit.legal
General: hello@caseit.legal