Legal framework // Governance

Privacy Policy

At firmä ("we", "us", or "our"), we respect your privacy and are committed to protecting the proprietary assets you entrust to our platform. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service, specifically tailored for Strategic Advisors and Consultants.

01Information we collect

Our platform is designed to be Non-Custodial regarding your intellectual property. We minimize data collection to the absolute essentials required for service delivery.

Account identity

Basic profile information (Name, Email, Organization).

Google Drive metadata

We request access to file names, folder structures, and permission settings to organize your client portal. We do not store the actual content of your files.

Usage telemetry

Anonymized data on how you interact with the platform to improve performance.

02How we use your information

We use your data solely to facilitate the secure delivery of your professional services:

Automating the creation and management of Client Portals.

Enforcing access control and revocation policies ("Zombie Link" prevention).

Sending critical security alerts regarding your shared assets.

Generating audit logs for your engagements.

03Data sovereignty & sharing

Your client data remains in your Google Drive. We do not sell your data. We do not share your data with third parties, except:

Service providers

AWS/Vercel (Hosting), Supabase (Database), Stripe (Payments) – strictly for infrastructure.

Legal compliance

If compelled by law enforcement (highly specific and rare).

04Security & retention

Encryption protocols and data lifecycle management policies.

Encryption

We employ enterprise-grade encryption (TLS 1.2+) for all data in transit. Since we do not store your files, the security of your documents rests primarily on Google's world-class infrastructure, layered with our access governance.

Purge protocol

When you delete your firmä account, all metadata stored on our servers is permanently erased within 30 days. Your actual files in Google Drive remain untouched.

05Cookie policy

We use cookies to improve your experience, analyze site traffic, and deliver personalized content. You can adjust your preferences at any time via the "Cookie Settings" link in the footer.

Strictly necessary

Required

These cookies are essential for the operation of our secure portal. They handle user authentication, session security, and fraud prevention.

Analytics & performance

Optional

We use these to understand how you interact with firmä (e.g., page visit counts, load times, errors). Data is aggregated and anonymized.

06Contact us

For any privacy concerns or data requests, please contact our Data Protection Officer at

info@firmaone.com