This Privacy Policy describes how XTND Technologies, Inc. ("XTND," "we," "our," or "us") collects, uses, and discloses personal information through our website at https://xtnd.legal, our platform, APIs, and related services (collectively, the "Service"). The Service is a business-to-business legal billing automation platform offered to law firms and legal organizations located in the United States.
1. Who We Are
Operator: XTND Technologies, Inc., a North Carolina corporation
Mailing Address: 1608 Queen St, PMB 3, Wilmington, NC 28401
Privacy requests: privacy@xtnd.legal
Security: security@xtnd.legal
Support: support@xtnd.legal
2. Our Two Roles
We handle personal information in two distinct capacities:
As a business (controller). For information about website visitors, prospective customers, and our customers' account administrators and billing contacts, XTND determines how and why the information is used. This Privacy Policy governs that information.
As a service provider (processor). For personal information contained in the data our law firm customers submit to or generate through the platform (such as matter records, time entries, invoices, and trust transactions, "Customer Platform Data"), XTND acts as a service provider under the CCPA/CPRA and processes that data only on the customer's documented instructions. The operative terms of that processing are set out in a written Data Processing Agreement (DPA) with each customer, which governs our processor obligations. If you are a client or contact of a law firm that uses XTND, please direct privacy requests to that firm. We will assist the firm in responding as required by our DPA and applicable law.
3. Information We Collect
You provide:
- Account and contact information: name, firm name, work email, phone
- Integration authorization data: OAuth credentials and tokens for Clio and QuickBooks Online connections (we do not collect or store your user passwords; authentication is via single sign-on)
- Billing information (payment card data is handled by our third-party payment processor; XTND never sees, stores, or transmits full card numbers)
- Support requests and related correspondence
Collected automatically:
- Device and browser details, IP address, usage logs and event data
From integrations, on your instruction:
- Matter, invoice, ledger, and trust transaction data synchronized from Clio and QuickBooks Online (this is Customer Platform Data, see Section 2)
4. How We Use Information
We use personal information to: provide, secure, and support the Service; authenticate users via SSO; process subscription billing; operate the Clio and QuickBooks Online integrations; automate billing workflows on your instructions; send service notifications and system alerts; respond to support requests; comply with law; and, with your opt-in consent, send marketing communications.
5. What We Don't Do
- We do not sell or share personal information (as "sell" and "share" are defined under the CCPA/CPRA), and we do not use it for targeted advertising.
- We do not train or fine-tune any machine-learning or AI model using Customer Platform Data or customer personal information.
- We do not combine personal information received from one customer with information from other customers, except as permitted by law for security and service-integrity purposes.
- We do not use Customer Platform Data for cross-customer benchmarking or analytics without the customer's express opt-in.
6. Sharing and Disclosure
We share personal information only with:
- Sub-processors and service providers engaged to help us deliver the Service (such as our US cloud hosting provider and the third-party platforms you authorize us to integrate with), in each case under written agreements consistent with our DPA. Customers can obtain our current sub-processor list, and the details of our sub-processor change and objection process, under their agreement.
- Professional advisors (legal counsel, insurers) under confidentiality obligations.
- Law enforcement or regulators when legally required. For Customer Platform Data, we notify the customer of legal demands before disclosure where lawfully permitted, and disclose only the minimum required, as committed in our DPA.
- A successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy's commitments.
7. Cookies and Analytics
xtnd.legal uses cookies and analytics tools to operate the site, measure performance, and improve usability. You can control cookies through your browser settings. We retain website analytics data for up to 24 months.
8. Security
XTND maintains a documented information security program aligned to the NIST Cybersecurity Framework 2.0, including: encryption at rest (AWS KMS, customer-managed keys) and in transit (TLS 1.2+); multi-factor authentication and least-privilege access controls; continuous monitoring and audit logging; tenant isolation; vulnerability management; an incident response program; and immutable, geographically separated backups with documented disaster recovery procedures. Our Security Program description and a completed security questionnaire are confidential and available to customers on reasonable written request under their agreement.
9. Data Residency
All Service data is hosted and stored exclusively in Amazon Web Services data centers located in the United States, with backup and disaster-recovery infrastructure also in the United States, and we do not store Customer Platform Data outside the United States. A limited number of named, background-screened personnel of XTND and its approved sub-processors may access data remotely from outside the United States, solely to provide, support, secure, and onboard the Service, in each case under written confidentiality and data-protection obligations, without storing, exporting, or retaining data outside the United States, and subject to access controls and logging that restrict such access to named individuals in declared locations. XTND maintains a current list of the countries from which such access occurs and makes it available to customers on request under their agreement.
10. Your Privacy Rights
Depending on your state of residence, you may have the right to: know and access the personal information we hold about you; correct inaccurate information; delete your information; receive a portable copy; and not be discriminated against for exercising these rights. Because we do not sell or share personal information, no sale/share opt-out is needed.
Submit requests to privacy@xtnd.legal. We will verify your identity before responding and respond within the timeframe required by law (generally 30 to 45 days). You may use an authorized agent with proof of authorization. If we decline a request, you may appeal by replying to our decision; we will explain the outcome of your appeal in writing.
If your information is contained in Customer Platform Data, we will route your request to the responsible law firm, as required by our role as a service provider.
11. Retention
We retain personal information only as long as reasonably necessary for the purposes above and to meet legal obligations. As a general guide: customer transaction and financial records are retained for the active customer relationship plus up to 7 years (or as the customer's contract requires); authentication metadata for the active account plus 12 months; system and audit logs for 12 to 24 months; website analytics for 24 months; and prospect contact data for 36 months from last contact or until you opt out. Residual copies in backups are deleted on a fixed schedule as backup retention expires; backup copies within an active immutability window cannot be deleted early by design.
12. Breach Notification
If a security breach affects personal information we process, we will notify affected customers without undue delay (and, where reasonably feasible, within 72 hours of confirmed discovery), followed by a detailed incident report, consistent with our DPA and applicable state breach-notification laws, including the North Carolina Identity Theft Protection Act.
13. International Use
The Service is offered to and intended for businesses located and operating in the United States, and we comply with applicable US federal and state privacy laws, including the CCPA/CPRA and the North Carolina Identity Theft Protection Act. The Service is not designed for personal data of individuals located in the European Economic Area, United Kingdom, or Switzerland; processing such data requires XTND's prior written consent and a separately executed EU Data Processing Addendum.
14. Children's Privacy
The Service is a B2B product for use by adults 18 and over. We do not knowingly collect personal information from children under 13, and customers are prohibited from submitting it. Contact us immediately if you believe a child's data has been submitted.
15. Do Not Track and Global Privacy Control
Because we do not sell or share personal information or use it for targeted advertising, there is no sale or sharing to opt out of. Our website does not respond to browser "Do Not Track" signals; we honor opt-out preference signals such as Global Privacy Control where applicable law requires.
16. Health Information
The Service is not designed to process Protected Health Information (PHI) under HIPAA, XTND is not a HIPAA business associate, and customers may not use the Service as a system of record for PHI.
17. Changes to This Policy
We will notify users of material changes by email or dashboard message before they take effect. Continued use after the effective date constitutes acceptance.
18. Contact
Questions or requests: privacy@xtnd.legal • XTND Technologies, Inc., 1608 Queen St, PMB 3, Wilmington, NC 28401. You may also contact your state Attorney General's office regarding privacy concerns.