This Privacy Policy explains how Rosen ADR Personal Corporation, doing business as ADRassistant (“ADRassistant,” “we,” “us,” or “our”), collects, uses, shares, and protects information in connection with the adrassistant.com website, our interactive demo, and the ADRassistant booking, billing, and case-workflow software (the “Service”).
Who this policy covers
This policy applies to visitors to adrassistant.com; to firms and neutrals who use the Service in their arbitration, mediation, or case-management practice; and to parties, counsel, and other participants whose information is handled through the Service.
Rosen ADR also provides its own arbitration and mediation services under a separate privacy policy available at rosenadr.com. That policy governs matters administered by Rosen ADR itself; this policy governs the ADRassistant software and website.
Information we collect
Information you provide to us
- Inquiries. When you use the contact form on adrassistant.com, we collect your name, email address, firm or organization, and the content of your message.
- Demo. Any information you type into the interactive demo (see “The interactive demo” below).
- Onboarding and account details. If your firm engages the Service, we collect the information needed to set it up — such as names, firm and contact details, sign-in identities, configuration choices, and billing information.
- Case information entered through the Service. Names and contact details of parties and counsel, scheduling details, documents and exhibits, and invoicing information — typically entered by the firm or neutral who is using the Service.
Information collected automatically
- Log and device data. When you visit the site, our servers and hosting providers record technical information such as your IP address, browser and device type, pages viewed, referring page, and timestamps.
- Security signals. To protect the contact form from automated abuse, our bot-protection provider (Cloudflare Turnstile) processes limited technical information, including your IP address, to tell human visitors from bots. We also keep short-lived rate-limiting records tied to IP address.
Information held within your Microsoft 365
When a firm uses the Service, the case documents, party and counsel contact details, calendar entries, secure folder links, and records that the Service creates are stored in that firm’s own Microsoft 365 (OneDrive and SharePoint) and Microsoft Azure environment — not on a separate ADRassistant platform. See “How the Service protects case information” below.
How we use information
We use the information we collect to:
- respond to your inquiries and demo requests, and follow up about the Service;
- provide, operate, maintain, secure, and improve the Service;
- schedule proceedings and create the case folders, secure links, meetings, calendar entries, and notices that the Service automates;
- prepare and process invoices and payments through our payment processor;
- verify the identity of authorized users, including sending one-time codes by text message before sensitive actions (two-factor authentication);
- keep activity logs, prevent abuse, and protect the security and integrity of our systems; and
- comply with legal, tax, and professional obligations.
The interactive demo
The demo on adrassistant.com runs in an isolated demonstration environment that is completely separate from any live practice. It uses fictional sample data, makes no real charges, creates no real meetings, and opens no real case files. Anything you type into the demo is used only to show you how the workflow behaves. Please do not enter real, confidential, or sensitive case information into the demo.
How the Service protects case information
The Service runs on Microsoft’s cloud — the same Microsoft 365 and Microsoft Azure platform relied on by law firms, courts, and government agencies — hosted in Microsoft’s data centers in the United States. Microsoft maintains these systems to recognized industry standards and undergoes independent security audits and certifications (for example, SOC 2 and ISO 27001). In everyday terms:
- Your data stays with you. Case files, folders, exhibits, calendars, and records remain in your own Microsoft 365 Business account. Nothing is copied to a separate third-party platform.
- Encrypted in transit and at rest. Information is encrypted both while it travels over the internet and while it is stored on Microsoft’s servers.
- Sign-in required. The booking and assistant tools sit behind your firm’s Microsoft 365 sign-in, so only people on your firm’s domain can open them.
- Protected credentials. The automated parts of the Service authenticate to Microsoft using a built-in, passwordless managed identity, and the few sensitive keys in use are held in a Microsoft Key Vault. Actions that move money require an approved user and a one-time passcode.
- Private, personalized folder links. Case folders are shared through secure links tied to a specific recipient’s email address, with one-time email verification — not open links anyone could forward. Each party sees only its own folder. When the case closes, access is turned off.
- No outside middlemen. The Service connects directly to Microsoft’s services through Microsoft’s official, permission-limited interface. Case data is not routed through third-party automation services.
- Backups and recovery. Microsoft keeps redundant copies and a full version history of documents, with a recycle bin, so files can be recovered if something is accidentally changed or deleted.
- Logging and tamper protection. System activity is logged for review, and automated entry points are guarded against forged or “spoofed” requests.
Where a firm uses the Service, the firm controls its own environment and the people it authorizes; ADRassistant processes the information to provide the Service on the firm’s behalf.
Service providers we use
We rely on a small number of trusted providers to run the website and the Service, including:
- Microsoft — Microsoft 365 and Microsoft Azure for website and application hosting, storage, email, and sign-in;
- Cloudflare — bot protection (Turnstile) on the contact form;
- Zoom — video meetings with per-party breakout rooms;
- a payment processor — for card and ACH invoice payments; and
- a text-message (SMS) provider — for one-time identity-verification codes.
These providers act under confidentiality and data-processing terms and are permitted to use the information only to provide their service to us. We do not sell personal information, and we do not use it for third-party advertising.
How we share information
We do not sell personal information. We share information only as needed to operate the Service — for example, with parties and counsel to a matter as appropriate to administer it, and with the service providers described above under confidentiality obligations. When your firm uses the Service, information is shared within your own Microsoft 365 environment and with the people your firm authorizes. We may also disclose information when required by law or legal process, to enforce our terms, to protect the rights, property, or safety of any person, or in connection with a merger, acquisition, or other business transfer — in which case this policy would continue to govern the information transferred.
Text messaging (SMS) and identity verification
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors that provide support services (for example, message delivery) is permitted solely to operate the Service. Text-messaging originator opt-in data and consent are never shared with any third parties for any other purpose.
ADRassistant uses SMS only to send one-time verification codes to authorized personnel to confirm identity before approving certain sensitive actions (two-factor authentication). Message frequency varies and is on demand. Message and data rates may apply. Reply STOP to opt out of these messages at any time, or HELP for help.
Cookies and similar technologies
The adrassistant.com website uses a small number of strictly necessary and functional cookies to make the site work and keep it secure. Cloudflare Turnstile may set a cookie to distinguish human visitors from automated abuse. We do not use advertising or cross-site tracking cookies. You can block or delete cookies through your browser settings, although some features of the site may not work as intended.
Data retention
We keep website inquiry information for as long as needed to respond to you and for our reasonable business records. Information within the Service is retained for as long as needed to provide the Service and to meet legal, tax, and professional obligations. When your firm uses the Service, retention of case materials in your Microsoft 365 account is controlled by your firm, and Microsoft’s standard backup and version-history retention applies.
Your privacy choices and rights
You may contact us to request access to, correction of, or deletion of information we hold about you, subject to legal and professional limits. You may opt out of verification text messages at any time by replying STOP.
Depending on where you live, you may have additional rights under state privacy laws — such as the right to access, correct, delete, or obtain a copy of your personal information, and the right not to be discriminated against for exercising those rights. To make a request, contact us using the details below, and we will respond as required by applicable law.
If you are a party, counsel, or other participant in a matter administered by a firm or neutral that uses ADRassistant, that firm or neutral controls your case information and it is stored in their Microsoft 365 account. Please direct requests about that information to them; we will assist them as their service provider.
Confidentiality of ADR proceedings
This policy is a general description of our data practices. It does not modify, waive, or override any confidentiality order, protective order, engagement agreement, arbitration or mediation confidentiality rule, or other agreement that governs a particular matter. Where those obligations are more protective than this policy, they control.
Children’s privacy
adrassistant.com and the Service are intended for professional and business use and are not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, please contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. The effective date at the top reflects the current version, and material changes will be posted on this page.
Contact us
Rosen ADR Personal Corporation, d/b/a ADRassistant
PO Box 15811, Seattle, WA 98115
Or reach us through the contact form on adrassistant.com.