Legal

Subprocessor Disclosure

Last Updated: June 1, 2026

1. Overview

This document identifies the third-party subprocessors used by Counsltrac in the operation of the service. A "subprocessor" is any third party engaged by Counsltrac that may access, store, transmit, or process Customer Data in connection with the Counsltrac service.

Counsltrac is operated by Counsltrac LLC, a Wyoming limited liability company ("Operator"), and runs entirely as a Slack application — there is no separate web application or browser dashboard. Counsltrac itself does not hold any independent security or privacy certifications. It is a small, single-operator product built on top of established infrastructure providers that are independently audited. The certifications listed below are held by those providers, not by Counsltrac. Their value to customers is that the parties that actually store, host, and process the data maintain externally verified security programs.

2. What Data Counsltrac Handles

Before describing each subprocessor, it is important to distinguish two data paths, because they involve different content:

Subject data minimization (by design): Counsltrac's data model contains no field for the identity of the individual who is the subject of a matter — no subject name, email, or identifier is ever requested or stored. A matter is characterized only by attributes such as matter type, business unit/department, and jurisdiction. This is an intentional design choice: the identifying details of a matter's underlying situation already exist in Slack, under the customer's own security and access controls. By pointing back to the originating Slack thread instead of copying that content into a separate database, Counsltrac avoids creating a second store of personal data and privileged material, minimizing both data-privacy exposure and attorney-client privilege concerns.

In-product caution: the optional Opening/Closing Notes and the reopen-reason field are free-text. To reinforce this at the point of entry, the Open Matter, Close Matter, and Reopen Matter forms display the following caution directly beneath each free-text field:

"Do not enter names of individuals or other personal identifiers, or any privileged or confidential details. Keep this to brief, non-identifying context."

3. Subprocessors

3.1 Supabase, Inc. — Database, Authentication, and Storage

Certifications published by Supabase: SOC 2 Type II, ISO/IEC 27001, HIPAA (available under a Business Associate Agreement), GDPR (Data Processing Addendum available), and PCI DSS.

Data-handling notes:

  • Role: PostgreSQL database, authentication, and storage — the system of record for all matter data
  • Data processed: Structured matter metadata and the optional free-text Opening Notes / Closing Notes
  • Data location: Amazon Web Services (AWS), United States — us-east-1 (pinned)
  • Website: supabase.com
  • Security page: supabase.com/security
  • DPA: supabase.com/legal/dpa

3.2 Anthropic, PBC — AI Inference

Certifications published by Anthropic: ISO/IEC 27001, ISO/IEC 42001 (AI management systems), and SOC 2 Type II.

What is actually sent to Anthropic — stated plainly:

How the privileged-content risk is managed:

  • Role: AI inference (Claude API) — powers intake suggestions, close-out field suggestions, and natural-language Q&A in Slack
  • Data processed: includes Slack message and thread content, not only structured metadata
  • Data location: United States
  • Website: anthropic.com
  • Privacy center: privacy.claude.com
  • API data policy: API & data retention docs

3.3 Render Services, Inc. — Infrastructure Hosting (Operational Subprocessor)

The Counsltrac Slack bot runs as a single process hosted on Render. Render is a compute (platform-as-a-service) provider, not the system of record: it does not hold matter records at rest. Customer Data nonetheless passes through this process, so Render is disclosed here as an operational subprocessor.

Certifications published by Render: SOC 2 Type II and ISO/IEC 27001. The SOC 2 report and ISO 27001 certificate are available through Render's Document Center (under NDA for eligible plans).

Data-handling notes:

  • Entity: Render Services, Inc.
  • Role: Hosting for the Slack bot process (compute only; not the system of record)
  • Data processed: Customer Data in transit, transient in-memory state, and application logs
  • Data location: United States
  • Website: render.com
  • DPA: render.com/dpa
  • Trust / subprocessors: trust.render.com

3.4 Slack — the Customer's Own Platform (Not a Counsltrac Subprocessor)

Slack is the customer's own communication platform, governed by the customer's existing agreement with Slack and their own retention and access settings. Counsltrac operates inside the customer's Slack workspace rather than engaging Slack on the customer's behalf, so Slack is deliberately not listed above as a Counsltrac-engaged subprocessor — even though all matter conversations originate there and Slack message and thread content is transmitted to the AI provider as described in Section 3.2. Customers should apply their existing Slack data-governance and retention controls accordingly.

4. Changes to Subprocessors

The Operator will provide at least 30 days' advance written notice before adding or replacing any subprocessor. Customers may object to a new subprocessor within that period by contacting the Operator at privacy@counsltrac.com.

5. Contact

For questions regarding this Subprocessor Disclosure, contact:

Counsltrac LLCprivacy@counsltrac.com