Back to Home
ChiefofStaff security shield

Security & Data Handling

ChiefofStaff is built for legal professionals with the highest expectations around privacy, control, and auditability. Every layer of our architecture reflects that commitment.

Encrypted in Transit

All data is encrypted using TLS during transmission between your device and our servers.

No Data Selling

We never sell personal data, use email content for advertising, or build marketing profiles.

Secure Hosting

Hosted on secure, access-controlled cloud infrastructure.

Data Storage & Isolation

Tasks, metadata, voice transcriptions, and account settings are stored securely with strict account isolation. Each user's data is logically separated to prevent cross-account access.

  • Voice recordings are immediately deleted after transcription
  • Transcriptions retained up to 30 days or until account termination
  • The Service does not access or import device phone contacts
  • Integration data (Google/Microsoft) used exclusively for core functionality

Data Retention

Data TypeRetention PeriodDeletion Trigger
Voice recordingsImmediately deleted after transcriptionAutomatic
TranscriptionsUp to 30 daysAutomatic or account termination
Account dataDuration of subscriptionAccount deletion
Task & productivity dataDuration of subscriptionAccount deletion
Integration dataWhile integration is activeDisconnection or account deletion
Security logsUp to 12 monthsSystem rotation

Upon account termination, personal data is deleted or anonymized within a commercially reasonable timeframe unless retention is legally required.

Verifiable Decision Records

ChiefofStaff is built on DONNA, our open-source decision-notarisation engine. Delegated decisions are recorded as Intent Decision Records (IDRs) — each signed and hash-chained to the one before it, so the decision trail is tamper-evident and can be verified independently, without having to rely on us.

DONNA is open source (AGPL-3.0), so the audit mechanism can be inspected or self-hosted. Task activity is also logged for an operational audit trail, and security event logs are retained for up to 12 months.

Security Measures

  • Encryption in transit (TLS)
  • Role-based access control
  • Limited internal access to production data
  • Secure U.S.-based infrastructure
  • Contractual subprocessor safeguards
  • OAuth 2.0 for Google and Microsoft integrations (we never see your passwords)

Access Control

You are responsible for maintaining the confidentiality of your account credentials and all activity under your account. We recommend:

  • Using strong, unique passwords
  • Notifying us immediately of any unauthorized access
  • Revoking third-party integration access if no longer needed

International Data Transfers

All data is hosted in the United States. For EU/EEA/UK users, transfers are safeguarded by:

  • Standard Contractual Clauses (EU 2021/914)
  • UK International Data Transfer Addendum (where applicable)
  • Technical and organizational security measures
  • Contractual safeguards with subprocessors

AI & Automated Processing

The Service uses AI to process voice commands and summarize information. Important safeguards include:

  • No decisions producing legal or similarly significant effects without human involvement
  • Users retain full control over actions taken based on AI-generated outputs
  • During early access, selected tasks may be reviewed internally to improve accuracy -- no data is shared externally

Subprocessors

We may use third-party service providers to host or support the Service. All subprocessors are contractually required to provide appropriate data protection safeguards.

A current list of subprocessors is available upon request at privacy@chiefofstaff.pro

Questions about security or data handling?

Contact us