Privacy Policy

Gretchen respects your privacy. This Privacy Policy covers Gretchen’s practices for the websites or mobile applications (“Sites”) that link to this Policy as well as to the products, services and web-based applications provided by Gretchen (our “Products”). This Policy describes our privacy practices.

What is Personal Data?

Personal Data is information relating to identified or identifiable individuals (including individual representatives of companies, such as employees or administrators). Gretchen collects Personal Data to market, sell, provision, manage and support our Products and to run our business. Gretchen is the controller of such Personal Data, and unless otherwise noted, the remainder of this Privacy Policy applies to Gretchen’s collection and use of Personal Data for which we are a controller. Gretchen also processes Personal Data we receive in our role as a service provider for our customers who use our Products.

Information that does not and cannot be used to directly or indirectly identify an individual is not Personal Data. This can be aggregated information about a group or category of data or data that has been de-identified so that it cannot be attributed to any individual. We may use and share such information to improve our Sites and our Products, develop new products, understand and/or analyze usage, demand, and general industry trends, develop and publish reports, and generally for any purpose related to our business. Our practices described in this Privacy Policy do not apply to nor restrict our collection and use of such data.

When and for what purposes do we collect Personal Data?

Gretchen collects Personal Data when someone visits our Sites, fills out a form or provides information on our Sites or on websites hosted on our behalf, submits an email or other inquiry to us, communicates with us in person, by phone or by email, enters a contest, provides feedback, purchases or uses a Product, or requests support for a Product.

We use Personal Data to fulfill the purpose for which the data is collected, such as to provide a requested product demonstration, to manage event or product registrations, or to process billing for our Products. We also use Personal Data we collect to maintain the security of Sites and Products and to run and manage our business.

How does Gretchen Collect Personal Data?

We collect Personal Data from several categories of sources. We collect Personal Data that you give us directly such as when you fill out a form, purchase a Product, or otherwise communicate with us. We also use information-gathering tools such as cookies and similar technologies that automatically collect information that may contain Personal Data from your computer or mobile device when you use our Products, visit our Sites or interact with emails from us.

How we may share Personal Data?

Gretchen may share Personal Data in the following circumstances:

  • to vendors, consultants or other service provider companies that provide services that help us with our business activities such as processing Customer payments, customer relationship management services, marketing, data analytics, security and enterprise resource planning. These companies are authorized to use Personal Data only as necessary to provide these services to us;
  • with other companies whose products or services we think may be of interest to you in joint marketing and support efforts. We will obtain your consent where required for such joint marketing efforts.

Gretchen may also disclose such Personal Data to a third party in the following limited circumstances:

  • as needed to enforce Gretchen’s Terms of Use, policies and any other contractual relationships with our customers;
  • when we have a good faith belief that the disclosure is necessary to prevent or respond to fraud, defend our Sites or Products against possible attacks, or protect the property and safety of Gretchen, our Customers or the public;
  • as required by law, such as to comply with an Order, subpoena, warrant, regulatory oversight or similar legal process.

International Transfers of Personal Information

We may transfer Personal Data to countries other than the country in which the information was originally collected. Those countries may not have the same data protection laws as the country in which the information was initially provided. When we transfer Personal Data to other countries, we will protect that Personal Data as described in this Privacy Policy.

Gretchen’s Commitment to Securing Personal Data

Gretchen is committed to protecting all Personal Data we collect and use. However, no system of electronic data collection, storage and retrieval can be made entirely impenetrable and by continuing to use our Sites and Products you acknowledge and accept that despite the security measures we employ, we do not guarantee that our Sites, Products and procedures are invulnerable to all security breaches or immune from viruses, security threats or other risks.

External Links/Third Party Websites

Gretchen’s Sites may provide links to and be accessed via links from third-party websites, including social media websites, whose privacy policies differ from those of Gretchen. Even if the third-party is affiliated with Gretchen through a business partnership or otherwise, Gretchen is not responsible for the content, privacy policies, or practices of such third parties. We encourage you to review carefully the privacy policy of any website you visit.


Integration with Third-Party Services

Gretchen integrates with third-party email services, specifically Gmail and Outlook, as well as the legal practice management software, Clio. This integration is designed to enhance your experience by enabling seamless access to your email communications and client documents within these services through Gretchen.

a. Acknowledgement of Third-Party Terms: By using Gretchen in conjunction with Gmail, Outlook, and Clio, you acknowledge that you are also subject to the terms and conditions of these respective third-party services. Your use of Gretchen does not alter your rights or obligations under the terms of service of Gmail, Outlook, or Clio. We encourage you to review the terms and privacy policies of these services, as Gretchen’s functionality is closely tied to their respective platforms, including the Google API Services User Data Policy and the Limited Use requirements.

b. Nature of Integration: When using Gretchen, you may access and interact with your email accounts on Gmail or Outlook and retrieve client documents from Clio. This integration is provided to facilitate ease of access to these services through a unified interface provided by Gretchen. However, Gretchen does not store your emails or documents from these services on our servers.

c. Data Sharing with Third-Party AI Platforms: Our application integrates with OpenAI's API to enhance your email communication experience. When you use our feature to generate a draft email, the application reads the body text of the email currently displayed in your interface. This text, and only this text, is then shared with OpenAI's AI platform to assist in generating a draft response. Additionally, for contextual understanding, the application may load a relevant document from Clio. We assure you that only the necessary content from these sources is used, and no other personal or sensitive data from your Google or Clio accounts is accessed or shared with the AI platform. This process is guided by strict adherence to data privacy and security protocols to ensure the confidentiality and integrity of your data.

d. Scope of Data Shared: When you use Gretchen to generate a draft email response, the text of the email currently open in your inbox is processed through a Large Language Model (LLM). This includes the body of the email and any included text that is visible in your email interface at the time of using the feature. The purpose of sharing this text is to allow the LLM to generate contextually relevant and accurate draft responses based on the content of your email. Only the text from the email you are actively viewing or selecting within Gretchen is shared with the LLM. No other data from your inbox, including other emails, attachments, or personal information, is transmitted to or accessed by the LLM.

e. Limitations and Restrictions: While Gretchen strives to provide a seamless integration experience, the functionality is dependent on the availability and functionality of Gmail, Outlook, and Clio’s APIs. Gretchen is not responsible for any changes or discontinuity in these services that may affect Gretchen’s integration with them. Furthermore, Gretchen does not claim any ownership or control over your data within Gmail, Outlook, or Clio, and our use of such data is strictly for the purpose of providing the services described herein.

f. User Responsibility: It is your responsibility to ensure that your use of Gretchen in conjunction with Gmail, Outlook, and Clio complies with the terms and policies of these services. You should also ensure that your use of Gretchen adheres to legal and ethical standards, particularly when handling sensitive client information.

Children

Our Sites and Products are not for minors and we do not knowingly attempt to solicit or receive any information from children. However, if a child under 18 provides Gretchen with Personal Data, the parent or guardian should contact Gretchen immediately by emailing us at privacy@gretchenapp.com so we can delete such information.

GDPR / European Privacy

This European Privacy Notice supplements the information contained in the Gretchen Privacy Policy, including its Privacy Notices, and applies to all visitors, users, and others from Europe. Specifically, if you are in the European Economic Area, Switzerland or the United Kingdom, you have the right to obtain information concerning your Personal Data. This includes the right to know whether or not we process personal data concerning you and, if this is the case, to access your personal data. In certain cases, you may request rectification, erasure or restriction of the processing of your personal data. Further, in certain cases you also have a right to object to the processing of personal data and the right to data portability.

Legal Basis for processing your information

We collect and use the personal data described above in order to provide you with the Sites and Products in a reliable and secure manner. We also collect and use personal data for our legitimate business needs. To the extent we process your personal data for other purposes, we ask for your consent in advance or require that others acting on our behalf obtain such consent.

If the processing of your personal data is based on legitimate interests, you have the right to object to the processing on grounds relating to your particular situation or to the fact that the data are processed for direct marketing purposes. In the latter case, you have a general right to object.

If the processing of your personal data is based on your consent, you are entitled to withdraw your consent at any time. Please bear in mind that such withdrawal of consent only has future effect. It does not render invalid nor illegal the processing based on consent before it is withdrawal.

Profiling and Automated Decision-making

Gretchen combines Personal Data we collect to help us determine what products and services might be of interest to an individual and when that individual might be ready to make a purchase based on repeated interaction with Gretchen or its Sites. Gretchen personnel are involved in this process and no automated decisions are made that would result in legal effects or significantly affect an individual. If you would like to make a request with respect to your rights please contact us.

You also have the right to lodge a complaint with the competent supervisory authority. A list of the competent supervisory authority can be accessed at Data Protection Authorities - European Commission.

If you would like to inquire about or exercise any rights you may have with respect to your Personal Data for which we are a processor that has been submitted to us through a Gretchen customer, you should reach out to that customer directly.

Privacy Notice for California Residents

This Privacy Notice for California Residents supplements the information contained in the Gretchen Privacy Policy, including its Privacy Notices, and applies solely to all visitors, users, and others who are California consumers. We adopt this notice to comply with the California Consumer Privacy Act of 2018 (CCPA) and any terms defined in the CCPA have the same meaning when used in this Notice.

The categories of Personal Information we collect, the categories of sources from which we collect it, the business or commercial purpose for collecting it and the categories of third parties with whom we may share it are the same for all individuals and are described above in our Privacy Policy and in our individual Privacy Notices.

Gretchen does not sell your Personal Information. Although we do not sell personal information in exchange for any monetary consideration, we do share personal information for other benefits that could be deemed a “sale,” as defined by the CCPA. This may include sharing identifiers and traffic information with advertising networks or website analytics companies. You have the right to customize your cookie preference settings at any time.

CCPA Rights

The CCPA provides California consumers with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.

You have the right to request that Gretchen disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable consumer request we will disclose to you, as applicable:

  • The categories of personal information we collected about you.
  • The categories of sources for the personal information we collected about you.
  • Our business or commercial purpose for collecting that personal information.
  • The categories of third parties with whom we share that personal information.
  • The specific pieces of personal information we collected about you (data portability)
  • If we disclosed your personal information for a business purpose: the personal information categories that each category of recipient obtained.
  • You have the right to request that Gretchen delete your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request we will delete (and direct our service providers to delete) your personal information from our records, unless an exception in the CCPA applies.

Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information.

You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:

  • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
  • We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us.

We will only use personal information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.

We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time, we will inform you of the reason and extension period in writing.

Any disclosures we provide will cover the 12-month period preceding the verifiable consumer request's receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily usable.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

If you would like to inquire about or exercise any rights you may have with respect to your personal information for which we are a service provider that has been submitted to us through a Gretchen customer, you should reach out to that customer directly.

Gretchen reserves the right to amend this Privacy Notice for California Residents at our discretion and at any time. When we make changes to this privacy notice, we will post the updated notice and update the notice's effective date.

Updates to our Privacy Policy

We may update this Privacy Policy from time to time. Please consult the “Effective Date” below to see when the Policy has been most recently updated. We encourage you to check this Policy frequently to see updates that may affect how your information may be used.

Effective Date: November 23, 2023

© Middle Layer Labs Ltd. All rights reserved.