Legal
Privacy Policy
This policy explains what information Frix collects, how we use it, and the choices you have when using Frix, Donna, and related services.
Last updated: 22 September 2026
Who we are
Frix provides software for law firms: call answering and intake, matter and document management, and Donna, an AI assistant that reads a firm's own files. This policy explains how we handle personal information across our websites, the Law Library, and the product.
When a law firm uses the product, that firm is the controller of the client data it puts into it and we are its processor, acting on its instructions under our agreement with it. For our own website visitors and account holders, we are the controller.
What we collect
Information you give us
- Account details: name, work email, phone number, firm name, and role.
- Billing details: plan, billing contact, and the last four digits and expiry of a card. Full card numbers are handled by our payment processor and never reach our servers.
- Firm content: matters, documents, notes, tasks, calendar entries, contacts, call recordings and transcripts, and anything else uploaded or created in the product.
- Messages you send to Donna, and the files attached to them.
- Support requests and anything you write to us.
Information we collect automatically
- Usage data: pages viewed, features used, and the time and duration of a session.
- Device and connection data: browser, operating system, approximate location from IP address, and IP address itself.
- Security logs: sign-in attempts, session tokens, and administrative actions within a firm's account.
Using the site without an account
The Law Library and a limited trial of Donna are open without signing in. In that case we store a small amount of information in your browser to keep the trial working, count how many pages you have browsed, and remember that you dismissed a prompt. We do not attach that to a named person, and it stays on your device until you clear it.
Please do not paste confidential client information into the signed-out trial. It is a demonstration, and it does not carry the protections that apply to a firm's own workspace.
How we use it
- To run the product: store your files, answer your calls, and let Donna read and cite your own documents.
- To keep accounts secure, detect abuse, and investigate incidents.
- To bill you, and to collect payment.
- To support you when you ask, which may mean looking at a record you point us to.
- To understand which features are used, in aggregate, so we can improve them.
- To send service messages about outages, changes, security, and billing. These are not marketing and you cannot opt out of them while you hold an account.
- To meet legal obligations and to enforce our terms.
Your content and AI
This is the part law firms ask about first, so it is stated plainly.
- Your firm's content is not used to train our models, or anyone else's.
- Your firm's content is isolated to your firm. Donna answers from the files in your workspace, not from another firm's files and not from the open internet.
- Where a third-party model provider is used to generate an answer, it is used under terms that forbid training on the content sent to it and require it to be deleted after the request is served.
- Donna's answers cite the document and page they came from, so every answer can be checked against the source.
Donna can be wrong. Her output is not legal advice and it is not a substitute for a lawyer's own judgement. Check every answer against the cited source before relying on it.
Confidentiality
We understand that a law firm's files are privileged and confidential. Our staff do not browse firm content. Access to production data is restricted to the small number of engineers who need it to operate the service, is logged, and is granted only for a specific purpose such as resolving a fault you have reported or responding to a security incident.
If we receive a legal demand for a firm's content, we will, unless we are legally forbidden from doing so, notify that firm before producing anything, so it can assert privilege on its own and its clients' behalf.
Where data lives, and how long
Firm content is stored on cloud infrastructure in the United States, encrypted in transit and at rest. Some service providers may process data elsewhere; where that happens across a border, it is covered by standard contractual clauses or an equivalent transfer mechanism.
- Firm content is kept for as long as the account is open.
- After an account closes, content is retained for 30 days so it can be recovered or exported, then deleted from live systems. Encrypted backups age out within a further 90 days.
- Billing and tax records are kept for as long as the law requires, usually seven years.
- Security logs are kept for up to 12 months.
- Signed-out trial conversations are held only for the length of the browser session.
Security
- Encryption in transit (TLS) and at rest.
- Every firm's data isolated from every other firm's.
- Role-based access inside a firm, set by that firm's administrators.
- Least-privilege, logged access for our own staff.
- Regular dependency and infrastructure patching.
No system is perfectly secure. If a breach affects your data we will tell you without undue delay, and in any event within the time the law requires.
Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, object to or restrict how we use it, receive a copy in a portable format, and withdraw consent you have given. You also have the right to complain to your data protection authority.
If you are a client of a firm that uses our product, ask that firm first: your information is theirs to control, and we will pass your request to them.
To exercise a right, write to privacy@callfrix.com. We will answer within 30 days, and we will not charge you or treat you differently for asking.
Children
The product is for legal professionals. It is not directed at anyone under 18, and we do not knowingly collect their information. If you believe a child has given us information, write to us and we will delete it.
Changes to this policy
If we change this policy in a way that matters, we will email account holders and show a notice in the product before the change takes effect. The date at the top always reflects the current version.
Contact
Questions about privacy go to privacy@callfrix.com. Anything else goes to support@frixlaw.com.
Written to be read. If a line here is unclear, or you need it in a form your own counsel can mark up, write to support@frixlaw.com and we will send it.