Taskflow reads your Clio matters so it can create the tasks and deadlines you have configured. That is the whole job.
- We never sell or share your data, and we never use client matter data to train AI models.
- Your firm owns everything in Clio. We hold a working copy only for as long as your subscription is active.
- Cancel, and we delete your data immediately. No archive, no grace period.
- Ask us anything about your data at marwie@otomatesystems.com.
Who we are and what this covers
Taskflow is a task automation product for Clio, built and operated by otoMate Systems. This policy explains what personal information we handle, why we handle it, and the choices you have. It covers our marketing site, the Taskflow application, and the support we provide over email.
It does not cover Clio itself. When you connect Clio to Taskflow, Clio’s own privacy terms continue to govern the data held in your Clio account. It also does not cover your firm’s obligations to your own clients — those remain yours.
Two kinds of data, two different roles
The distinction below decides who is responsible for what, so it comes before everything else.
Matters, contacts, dates, custom fields and tasks that arrive from your Clio account. Your firm decides what exists and why. We process it on your instruction only — under California law we act as your service provider, not a business selling data.
Your name, work email, firm name, role, subscription record and support history. We decide how this is used, so for this narrow set we are the business.
What we collect
| Category | What it is, and why we have it |
|---|---|
| Clio matter data | Matter number, practice area, stage, responsible attorney, contact names, key dates and the custom fields your rules read. Retrieved through Clio’s API so a template can decide which tasks to create and when they are due. |
| Account details | Name, work email, firm name and the role assigned to you by your firm admin. Needed to sign you in and to decide what you are allowed to change. |
| Template configuration | Your templates, tasks, rules, assignee mappings, working week and blocked-out dates. This is the product; without it Taskflow has nothing to run. |
| Run logs and timeline | Which run touched which matter, what it created, what it skipped, and who triggered it. This is your audit trail and our only way to explain an unexpected due date. |
| Calendar events | Events Taskflow creates or reschedules in Clio, and the events it must read to avoid double-booking a deadline. |
| Support correspondence | Emails and tickets you send us, including anything you paste into them. Kept so we can answer you and recognise a repeat issue. |
| Product telemetry | Which screens are used, which actions fail, error traces and rough performance figures. Aggregated wherever it can be. We do not send matter content to any analytics tool. |
| Cookies | A session cookie that keeps you signed in, and a preference cookie or two. No advertising cookies, no cross-site trackers. |
We do not ask for and do not want payment card numbers, government identifiers, health records or biometric data. If any of that reaches us inside a matter field, it is client matter data and is treated as such.
How we use it
- To run the automations your firm has configured — matching rules, deciding due dates, creating tasks and events in Clio.
- To show you what happened, on the Runs screen and the matter timeline.
- To keep your account secure and enforce the roles your admin set.
- To answer support requests and diagnose faults, including a dry run against a test matter when you ask us to look at something.
- To send service email — run failures, expiring Clio credentials, billing receipts, material changes to this policy.
- To bill your subscription and meet our tax and accounting obligations.
- To improve the product using aggregated usage patterns and error rates.
What we never do
The Clio connection
You connect Clio by authorising Taskflow through Clio’s own consent screen. We receive an access token, never your Clio password. The token is encrypted at rest and can be revoked from inside Clio at any time, or by disconnecting in Taskflow — either action stops all reading and writing immediately.
We request the narrowest scopes the product needs: matters, contacts, custom fields, tasks and calendar entries. We do not request documents, billing records, trust accounting or communications.
Who else touches your data
A short list, and it stays short. Each vendor is contractually bound to use the data only to provide their service to us.
| Vendor | Purpose | Region |
|---|---|---|
| Clio | Source and destination of all matter data. Taskflow reads from and writes to your account. | United States |
| Vercel | Application hosting and content delivery. | United States |
| Convex | Application database — templates, run logs and the working copy of matter data. | United States |
| Resend | Transactional email — run alerts, receipts, password resets. Receives your name and email address only. | United States |
| Cal.com | Demo booking on this site. Receives only what you type into the booking form. | United States |
We also disclose information where the law requires it — a valid subpoena, court order or regulatory demand — and, if we are ever acquired or merged, to the acquiring party under the same commitments made here. We will tell you before your data moves, unless we are legally barred from doing so.
How long we keep it
While your subscription is active, we keep your configuration and run history so the audit trail stays intact.
Your data is deleted immediately. There is no archive, no grace period, and no recovery window — so export anything you need first.
Two narrow exceptions survive deletion: billing and tax records, which we must keep for the period the law requires, and encrypted infrastructure backups, which roll off on their own schedule within 30 days and are never restored selectively. Everything Taskflow already wrote into Clio stays in Clio — those tasks and events belong to your firm, and deleting your Taskflow account does not remove them.
Security
Data is encrypted in transit with TLS and at rest by our hosting providers. Clio tokens are encrypted with keys held separately from the database. Access to production is limited to the people who need it, requires multi-factor authentication, and is logged. Roles inside Taskflow are enforced server-side, not just hidden in the interface.
No system is perfect. If we discover a breach affecting your data we will notify you and, where required, the relevant authorities, without undue delay and with what we know at the time rather than after the investigation closes.
Your privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you the rights below. Residents of Colorado, Connecticut, Virginia, Utah, Texas and other states with comprehensive privacy laws have substantially similar rights, and we extend the same process to everyone regardless of where you live.
- Know and access. Ask what personal information we hold about you, where it came from, why we have it and who we disclosed it to.
- Delete. Ask us to delete it, subject to the legal-retention exceptions above.
- Correct. Have inaccurate information about you fixed.
- Portability. Receive a copy in a usable, machine-readable format.
- Opt out of sale or sharing. Already satisfied — we do neither, so there is nothing to opt out of.
- Limit use of sensitive information. We do not collect sensitive personal information for the purposes this right restricts.
- No retaliation. Exercising any of these rights will not get your account degraded, priced differently, or closed.
Email marwie@otomatesystems.com to exercise any of them. We will confirm receipt within 10 days and respond within 45 days, extending once by a further 45 if the request is complex — we will tell you if that happens. We may need to verify your identity against information already in your account. An authorised agent may act for you with written permission.
One important routing note: if your request concerns client matter data, your firm is the controller, not us. Send it to your firm, and we will support them in fulfilling it. Requests about your own account data come straight to us.
Cookies and tracking
Taskflow sets a first-party session cookie to keep you signed in, and stores a small number of interface preferences. That is the extent of it. There are no advertising cookies, no third-party trackers and no cross-site profiling, which is why you are not being asked to dismiss a consent banner. Because we do not track you across sites, Global Privacy Control and Do Not Track signals have nothing to switch off — we honour them by design.
Children
Taskflow is a professional tool sold to law firms. We do not knowingly collect information from anyone under 16 as a user of the product. If a minor appears as a client or contact inside a matter, that data is client matter data under your firm’s control and is handled under the same restrictions as everything else.
Changes to this policy
We update the effective date at the top whenever this policy changes. For any change that materially affects how we handle your information — a new category of data, a new subprocessor, a new purpose — we email account admins at least 30 days before it takes effect. Continued use after that date means you accept the updated policy.