How information is handled
Privacy Policy
Last updated: 2026-09-19
This is operational information about CaseLoad Select. It is not legal advice.
Who we are
CaseLoad Select is a case-acquisition and selection service operated by Adriano Domingues, a senior communications strategist based in Toronto, Ontario. The service powers the intake forms and lawyer-triage workflow for the law firms that engage us.
When you submit an intake form on a law firm’s website, CaseLoad Select acts as a service provider to that firm. The firm is the controller of your information for the purpose of evaluating your matter; we process the information on the firm’s behalf under a written agreement.
What we collect
- Contact details you provide: name, email address, phone number.
- The matter description you provide during the intake conversation, including answers to follow-up questions and any details you choose to share.
- Technical metadata generated when you use the form: timestamp, the firm whose form you submitted to, and a generated lead identifier.
- Information about how the firm’s lawyer or operator handled the lead inside the CaseLoad Select system: scoring, status changes, decision timing.
We do not collect bank-account numbers, credit-card details, government-issued identification numbers, or biometric data through the intake form. Do not enter that information into the form.
Channels we receive intake on
CaseLoad Select receives intake submissions across seven channels. All seven route through the same CaseLoad Screen engine; the channel affects only how the conversation is initiated, not how your data is stored or retained. The web-based screening conversation runs in the CaseLoad Screen SPA at caseload-screen-v2.vercel.app or in the widget embedded on the firm’s website.
| Channel | How intake is initiated | Data captured |
|---|---|---|
| Web widget | Form embedded on the firm’s website or at app.caseloadselect.ca/widget/[firmId] | Typed description, follow-up answers, name, email, phone |
| Text conversation via the firm’s WhatsApp Business Account on Meta’s Cloud API | Message text, sender phone number, WhatsApp profile name | |
| SMS | Text conversation via the firm’s GoHighLevel number | Message text, mobile phone number |
| Voice | Inbound phone call handled by GoHighLevel Voice AI; transcript processed server-side | Call transcript, caller phone number |
| Instagram DM | Direct message on the firm’s Instagram Business account; received via the Meta Instagram webhook | Message text, sender Instagram-Scoped ID |
| Facebook Messenger | Direct message on the firm’s Facebook Page; received via the Meta Messenger webhook | Message text, sender Page-Scoped ID |
| Google Business Profile chat | Message initiated from the firm’s Google Business listing, routed through GoHighLevel | Message text, Google account name |
For Instagram DM and Facebook Messenger, Meta Platforms, Inc. processes the conversation before we receive it. Meta’s data processing terms govern the conversation layer; our policy applies from the point of receipt into our systems.
For Google Business Profile chat, Google LLC processes the conversation before we receive it. Google’s privacy terms govern the conversation layer.
Firm Voice Builder
The public Firm Voice Builder is a separate, AI-assisted working-profile tool. Each answer you submit in the interview is sent to Google LLC through Gemini 2.5 Flash so the service can generate the next question and the final profile.
The CaseLoad Select app processes the interview transcript without persisting it in its database. The browser stores the working transcript in local storage to support resume, and any transcript download is created in the browser. Do not enter client names, matter facts, privileged material, personal identifiers or unpublished credentials.
Why we collect it
- To evaluate whether the matter falls within the firm’s scope of practice and to score it for priority.
- To present a structured brief to the firm’s lawyer so they can decide quickly whether to take on the matter.
- To send you an automated reply that confirms next steps or, if the matter is outside the firm’s scope, suggests an alternative direction.
- To maintain an internal audit trail of how leads were handled by the firm.
Who sees it
- The lawyer or staff at the firm whose form you submitted to.
- Adriano Domingues, in the role of CaseLoad Select operator, for system administration, support, and quality control.
- The firm’s CRM and communication service provider (GoHighLevel) and transactional email provider (Resend), which deliver the firm’s automated replies. GoHighLevel handles SMS, voice, and Google Business Profile chat channels on the firm’s behalf. WhatsApp, Facebook Messenger, and Instagram DM intakes are received directly by CaseLoad Select from Meta’s APIs; the platform does not route those channels through the firm’s GoHighLevel account.
- Supabase Inc. (database hosting, Toronto region) and Vercel Inc. (application hosting), under written service agreements limited to processing on our instructions.
- Google LLC (Gemini 2.5 Flash processing for Screen 2.0, the voice channel, and the Firm Voice Builder), under Google’s data processing terms.
- OpenAI, L.L.C. (intake screening assistance for legacy web widget sessions), under OpenAI’s data processing terms.
- Meta Platforms, Inc., for intake that arrives via Facebook Messenger, Instagram Direct, or WhatsApp Cloud API. Meta processes the conversation before it reaches our systems and stores its own copy under Meta’s own retention rules. Our policy applies from the point of receipt into the CaseLoad Select webhook. We use Meta’s Page Send API and Cloud API messages endpoint to reply within the standard 24-hour customer-service window only.
We do not sell or rent your information. We do not use your information for advertising.
How long we keep it
Identifying intake information follows the priority band assigned to the matter. At the end of the applicable period, or after a verified deletion request, CaseLoad Select irreversibly removes message content and direct identifiers from the operational copies it controls. Remaining rows are limited to redacted or non-content operational records. This process does not delete copies controlled by a law firm or communication platform.
| Band | Retention |
|---|---|
| A or B | 1095 days (3 years) |
| C | 365 days |
| D | 180 days |
| E | 30 days |
| Unrated | 90 days |
If you become a client of the firm, the firm’s own retention rules govern your file from that point on, separate from this policy.
A limited audit record may remain for system security, delivery-integrity checks, proof that deletion was completed, and aggregate reporting. It excludes names, contact details, message content, platform sender IDs, and platform message IDs. Retained channel audit events have a three-year retention period measured from the original event. Separate deletion-request and anti-recontact suppression records are retained for their deletion-proof and re-collection-prevention purposes only.
Where it lives
Your data is stored on Supabase infrastructure in Montreal, Canada (AWS ca-central-1), encrypted at rest. Access requires a service-role key held only by the application and by the operator. We use TLS for every connection. Application-level recovery controls keep encrypted deletion instructions outside the operational database and block normal use until those instructions are replayed and verified after a restore. We tested that control with fictional data in a transactional logical-restore simulation. This was not a managed Supabase backup or point-in-time recovery rehearsal. Provider-managed backup copies remain subject to the provider’s retention and expiry controls.
Your rights
Under the federal Personal Information Protection and Electronic Documents Act and applicable provincial law, you may:
- Ask what information we hold about you.
- Ask us to correct inaccurate information.
- Ask us to irreversibly remove message content and direct identifiers outside the regular retention schedule. A limited audit record without names, contact details, message content, or platform identifiers may remain. If the firm took on your matter, the firm’s own record is governed by its policy, not ours.
- Withdraw consent at any time, subject to legal or contractual restrictions.
Send written requests to privacy@caseloadselect.ca. We will respond within 30 days.
Follow-up communications
By submitting an intake form, you provide express consent under Canada’s Anti-Spam Legislation (CASL) for the firm and CaseLoad Select to send you electronic messages related to your inquiry. This includes automated replies, status updates, and follow-up messages about your matter.
If you receive marketing messages (such as review requests or re-engagement messages from the firm), each message will identify the firm as the sender and include a working unsubscribe mechanism. Unsubscribing from marketing messages does not affect transactional messages directly related to your open matter.
Cookies
The intake form does not use tracking cookies. The lawyer portal and operator console each use a functional cookie called portal_session for up to 30 days. Each cookie is limited to its own host, so a lawyer session on the app host and an operator session on the admin host do not overwrite one another. These cookies are HMAC-signed, HTTP-only, and not used for analytics or advertising.
Contact
If you cannot resolve a privacy concern with us directly, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.