Last updated 16 September 2026
CasexAtlas is case management software for personal-injury law firms. It holds sensitive personal information, including injuries, medical treatment and case details. This policy sets out how that information is handled.
CasexAtlas is operated by XATLAS LLC. Anything in this policy that says "we" means that company. Questions about your data, and requests to exercise a right described below, should be sent to info@casexatlas.com.
Firm data is what your firm puts into CasexAtlas: cases, clients, contacts, documents, medical records, communications, financials. It belongs to your firm. We hold and process it on your firm's instructions in order to operate the product. We do not determine its contents, use it for our own purposes, or sell or share it with advertisers.
Account data is what we require to operate the service: user identities, records of user activity, billing details, support correspondence, and technical logs. We determine how that data is handled, within the limits of this policy.
From your firm's use of the product: case records and matter details; client and contact information including dates of birth; injury descriptions, diagnoses, treatment records and providers; documents you upload or generate; emails, calls and notes logged against a case; settlement, lien, expense and time-entry figures; and an audit log of who did what.
To operate accounts: names, work email addresses and roles, authentication records, and IP addresses used for rate limiting and abuse prevention.
When you accept these documents: the date and time, which version you accepted, your IP address and your browser's user agent string. That record is retained for as long as your firm holds an account, as evidence of acceptance.
Automatically: aggregate page performance and traffic analytics through Vercel Analytics and Speed Insights, and server logs that may include IP addresses and request metadata.
From the public site: anything you type into a contact or access-request form.
We use third-party infrastructure. These are the services that can hold or see firm data in the course of running CasexAtlas:
If your firm connects an optional integration, that provider also receives the relevant data: a phone system for call logging, or Microsoft or Google for calendar and email sync. Those connections are made by your firm and are disabled unless your firm enables them.
CasexAtlas includes an AI assistant that reads case facts to answer questions and draft documents. To do that, it sends those facts to Anthropic's API.
Case content is transmitted in readable form. Encryption at rest does not apply to this step. Depending on the matter, that content may include injuries, diagnoses, treatment history and communications.
Under Anthropic's commercial API terms, that data is not used to train their models. We send the minimum needed to answer the request.
We do not currently hold a HIPAA Business Associate Agreement with Anthropic. Where your matters involve protected health information and your obligations require a BAA covering every processor, that information must not be processed through the AI features. Contact us before doing so.
You can switch off the automatic part. In Settings, under AI reading of calls and email, one control governs everything that happens without anyone asking: call recordings sent to OpenAI to be transcribed, and transcripts and unrouted email sent to Anthropic to be summarised and filed. With it off, none of that leaves CasexAtlas. Calls are still logged with their recordings, and email a rule cannot place waits for someone at your firm to file by hand. Where you connect a phone system through Settings, that connection has its own finer controls as well.
The assistant is separate, because a person asks it a question and chooses what to send. Switching the control above off does not disable it.
Data is encrypted in transit. Each firm's data is isolated from every other firm's at the query level, and access within a firm is scoped by user role.
Certain sensitive fields are additionally encrypted at rest in the database: injury descriptions and injury details, diagnoses, body parts and treatment descriptions, dates of birth, and call and communication transcripts, summaries and recording links.
Other fields, including names, case numbers and financial figures, are stored unencrypted at the application layer and rely on the database's own protections. Uploaded document files are stored in private storage and are not encrypted by us beyond that.
We do not claim any security certification. Our current compliance position, including measures not yet in place, is set out on the security page.
Where there is a breach affecting your firm's data, we will notify your account administrators without undue delay, and within the period required by law. Our commitments, and the point at which your firm's own duties to its clients begin, are set out in the terms.
The database is backed up nightly. Backups are encrypted with AES-256 before they leave the machine that made them, and are held by a storage provider separate from the ones that run the application and the database, so that losing one provider does not lose the backups too. Files uploaded to the product are archived the same way. Both are kept for 90 days and then deleted automatically.
Restoration from these backups is tested. An archive cannot be read without the passphrase, including by the company that stores it.
We keep firm data for as long as your firm has an account, and afterwards only as needed to finish winding the account down or to meet a legal obligation.
A firm administrator can export your firm's records at any time, and you can ask us to delete the firm entirely. The export covers your records. Documents are included as their details rather than as the files themselves. Uploaded files are provided on request.
Deleting a case takes its history with it: its notes, calls, emails, appointments, tasks, treatment records and financial entries. Records that were never attached to a case, such as an unmatched incoming call or a firm-wide calendar entry, are not affected.
Deletion is subject to four limits:
Where the law gives you rights over personal data, including access, correction, deletion, portability, or objecting to certain processing, you can exercise them by writing to info@casexatlas.com.
For data belonging to a firm's clients, the firm is the first point of contact, as the firm determines what is collected and for what purpose. A client of a firm using CasexAtlas should contact that firm; we will assist the firm in responding.
The rights that apply depend on the individual's location rather than ours. Where a firm's clients are subject to privacy laws granting broader rights than those where we operate, we will assist the firm in meeting those requests.
If this policy changes in a way that materially affects how we handle your data, we will notify account administrators. Changes will not be made by revising the date alone.
Questions about this document? info@casexatlas.com