Effective Date: TO BE CONFIRMED Last Updated: 2026-08-07
This Privacy Policy describes how RNDBI LLC ("RNDBI," "we," "us," or "our") collects, uses, and protects information in connection with the RNDBI Work platform and related services (the "Service"). This Policy applies to our customers (law firms and legal professionals, "Customer" or "you") and to individuals whose information Customer submits to the Service in the course of its own business.
The Service is a business tool for law firms and legal professionals. It is not directed to consumers, and we do not knowingly market the Service to, or collect information directly from, individual consumers or children. Where Customer Data submitted to the Service includes personal information about Customer's own clients or contacts, RNDBI processes that information on Customer's behalf and instruction, as described below.
1.1 Account and Registration Information. Name, work email address, firm name, and role, provided when you or your firm sign up for the Service.
1.2 Customer Data. Information that Customer and its Authorized Users submit to, or generate within, the Service in the ordinary course of using it, which may include: matter and engagement details, party and contact records, time entries and narratives, task and project information, billing and invoicing records, trust accounting transactions, and documents or attachments Customer chooses to store in the Service. Customer controls what it submits and owns this data under our Terms of Service.
1.3 Usage and Technical Information. Log data generated by normal operation of the Service (for example, timestamps of sign-in, error logs, and system performance data) collected to operate, secure, and troubleshoot the Service.
1.4 Communications. Information you provide when you contact us for support, sales, or other communications.
We do not currently operate payment processing for the Service; if a paid tier is introduced, this Policy will be updated to describe any payment information handling before that feature launches.
We use the information described above to:
We do not sell Customer Data. We do not use Customer Data to train third-party AI/ML models outside of operating the Service, and we do not use Customer Data for advertising purposes.
We use a limited set of third-party service providers ("sub-processors") to operate the Service. As of the date of this Policy, the sub-processors we can confirm are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting, database, and application infrastructure for the Service | West US 2 (United States) |
We are compiling a complete, versioned sub-processor list as part of our launch preparation. This section will be kept current, and we will provide advance notice before adding a new sub-processor that will process Customer Data, consistent with our obligations to Customer.
4.1 Current State. RNDBI does not yet have a formal, published data-retention schedule. We are actively developing one. Our interim practice is: Customer Data is retained for as long as Customer maintains an active account, and (subject to Section 5 of our Terms of Service and Section 6 of this Policy) for a limited period following termination to allow Customer to retrieve its data before deletion.
4.2 No Automated Retention Enforcement Yet. As of this Policy's effective date, deletion of records within the Service (for example, "soft-deleted" items) does not trigger automatic permanent purging on a fixed schedule. We are working on formal retention and deletion tooling. Until it ships, deletion requests for specific records can be directed to legal@rndbi.com and will be handled manually on a best-efforts basis, subject to the technical and legal constraints described in Section 6.4.
4.3 Backups. We maintain routine automated backups of the Service's underlying database to support disaster recovery. Backup copies are retained on a rolling basis and are not immediately purged when a live record is deleted; this is standard practice for disaster-recovery backups and is not a substitute for the retention schedule described in Section 4.1.
5.1 Manual Process (Interim). The Service does not yet include a self-service data export or account-level data-access dashboard. Until that capability ships, you may request a copy of your data, or ask us to correct or delete specific records, by contacting legal@rndbi.com. We will respond and act on verified requests on a best-efforts basis within 15 business days, consistent with Section 8 of our Terms of Service.
5.2 Access Requests Are Not Yet Individually Logged. As of this Policy's effective date, the Service does not maintain a per-record log of who has viewed a given piece of Customer Data - only creation, modification, and deletion events are logged. We are treating read-access logging as a priority engineering item. This means that, today, we cannot produce a "who has viewed this record" report; we can produce records of who created, edited, or deleted a given record.
5.3 State Consumer Privacy Law Rights. If you are a resident of a US state with a consumer privacy law that grants rights such as the right to know, access, correct, or delete personal information (for example, California, Colorado, Connecticut, Virginia, or other states with comparable laws), and those rights apply to information we hold about you outside of the business-to-business Customer relationship described in Section 1.2, you may submit a request to legal@rndbi.com. RNDBI acts as a service provider / processor with respect to Customer Data submitted by Customer, and as a business / controller only with respect to the account and usage information described in Sections 1.1, 1.3 and 1.4. We do not sell personal information and do not use it for cross-context behavioral advertising.
6.1 Measures We Currently Have in Place.
6.2 What We Do Not Yet Have. In the interest of transparency during our beta stage, we are stating plainly what is not yet in place, rather than implying otherwise:
6.3 No Guarantee. No method of electronic storage or transmission is 100% secure. While we use commercially reasonable measures appropriate to our stage of operation, we cannot guarantee absolute security, and the Service should not be used as Customer's sole system of record for information it cannot afford to lose (see Section 10 of our Terms of Service).
If we become aware of a security incident that results in unauthorized access to, or acquisition of, Customer Data, we will notify affected Customers without undue delay, and in any event as required by applicable law, with information reasonably available to us about the nature of the incident, the data involved, and steps being taken in response. We will cooperate with Customer's own legal or regulatory notification obligations where an incident affecting Customer Data may trigger them.
Trust accounting records processed through the Service (including posted trust transactions) are subject to system-level controls that prevent editing or deletion of posted entries once recorded, supporting the integrity of that financial record. This is a recordkeeping-integrity control, not a privacy control, and is described further in our Terms of Service, Section 6. It also means that, as a matter of database design, a posted trust transaction's memo/description field generally cannot be edited or removed even in response to a data-correction request - see Section 5.1 for how we handle correction requests involving such records, and Section 6 of our Terms of Service for the underlying no-legal-advice disclaimer on trust-accounting features generally.
The Service is a business tool for law firms and legal professionals and is not directed to, marketed to, or intended for use by individuals under 18. We do not knowingly collect personal information directly from children. If we become aware that we have inadvertently collected such information, we will take steps to delete it.
The Service is operated from, and Customer Data is stored in, the United States. The Service is offered to US-based law firms. We do not currently offer data residency outside the United States. If Customer Data includes information about individuals located outside the United States, Customer is responsible for determining whether its own transfer obligations are met before submitting that information to the Service.
We may update this Privacy Policy as the Service evolves, particularly as retention tooling, export capability, and access logging described above are built. We will post the updated Policy with a new "Last Updated" date and, for material changes, provide advance notice (for example, by email or in-app notice) before the changes take effect.
Questions about this Privacy Policy, or requests described in Sections 4 and 5, may be directed to: legal@rndbi.com
RNDBI LLC TO BE CONFIRMED
This document was prepared as an interim, non-lawyer draft to support an early beta launch and is pending review by qualified counsel. It should not be relied upon as a final legal instrument until that review is complete and Darrington has approved publication.