Privacy Policy
RSLO — R. Sese & Associates Law Office
1. Data We Collect
We collect account details (name, email, contact number and address), appointment and case information, files you upload and their filenames, types and sizes, and AI chat messages you submit. Documents and concerns may contain sensitive information about you or other people. Submit only information relevant to your request that you are authorized to provide.
2. How We Use Your Data
We use this information to manage accounts, verify email addresses, process password resets, schedule appointments, review documents, maintain case records and provide preliminary consultation guidance. The application also processes technical request information needed to operate and protect the service.
3. Confidentiality
Within the application, access to appointment and case records is restricted to the relevant customer and authorized Attorney and Legal Secretary accounts. Uploaded files are stored in a private storage bucket. Downloads require an access check and use a temporary link; anyone who obtains that link may use it while it remains valid. Do not share download links or account credentials. Hosting and storage providers process data as described below.
4. Data Retention
Records are retained for as long as necessary to provide legal services and comply with legal obligations, consistent with the Data Privacy Act of 2012 (RA 10173).
5. Your Rights
You may request access to, correction of, or deletion of your personal data by contacting the office at romeosese9@gmail.com.
6. Hosting and Storage Providers
The deployed service uses Netlify to host the website, Render to run the backend, MongoDB Atlas to store application records, and Supabase to store uploaded files. These providers process information needed to deliver their respective services, including technical request information. Data may be processed outside the Philippines depending on the configured service locations. Private storage does not mean that files are end-to-end encrypted or inaccessible to administrators of the service.
7. Google Gmail Access and Email Delivery
The office authorizes its own sending mailbox through Google OAuth using the gmail.send permission. RSLO uses this access to send email-verification and password-reset codes. Customers do not authorize access to their Google accounts, and the integration does not read inbox messages or contacts. Google processes recipient email addresses and message contents to deliver these emails. Uploaded documents and case details are not included in these automated code emails.
8. Google Credentials and Sent Messages
The office mailbox OAuth refresh token and client secret are stored in backend environment settings, not in the public website. The backend exchanges the refresh token for short-lived access tokens to send messages. Sent emails may remain in the office mailbox and recipient mailboxes under their respective settings. The office mailbox owner can revoke the application's access through Google Account permissions; this stops automated Gmail delivery until access is authorized again. Customer requests concerning stored records can be directed to romeosese9@gmail.com. Google mailbox access and email contents are not used by this integration for advertising or AI model training.
9. AI-Assisted Guidance
The assistant can use built-in classification rules. If the office enables an external AI provider, concern text submitted for classification is sent to that configured provider (OpenAI, Anthropic or Google, depending on the configuration). The current classification integration does not send uploaded file contents. Avoid including unnecessary identifiers or confidential details in chat. Contact the office to confirm the active provider before submitting sensitive information.