Privacy Notice
Effective 10 August 2026 · Last updated 10 August 2026
Fenix.ai LLC (“Fenix”, “we”) provides practice-management software to patent law firms. This notice explains what personal information we handle, why, and what we do and do not do with it.
We serve law firms, not consumers. Most of the personal information that passes through Fenix belongs to our clients’ files — inventors, applicants and correspondents named in patent documents — and we handle it on our clients’ instructions, not our own. That distinction runs through everything below.
1. The short version
- We never sell, rent, or share personal information for marketing.
- We never use client data to train AI models, and neither do the AI providers we use.
- Client data is isolated per client— its own database and its own storage bucket, not a shared pool.
- Client data is stored and processed in the United States only.
- If you are named in a client’s patent file and want your information accessed, corrected, or deleted, the firm that engaged us controls that data — see section 6.
2. The information we handle, and our role in each case
Whether we are a controller (we decide why and how information is used) or a processor(we act on a client’s instructions) depends on the category:
| What | Examples | Our role |
|---|---|---|
| Personal information inside client files | Inventor and applicant names and addresses in patent applications, correspondence, disclosures, office actions | Processor— processed solely to deliver the contracted service to the owning firm |
| Client user accounts | Name, work email, and authentication identifiers of firm personnel who use Fenix | Controller |
| Fenix personnel records | Employment and contractor records | Controller |
| Operational metadata | Application and audit logs, usage and cost records | Controller |
We collect only what the service requires. A Fenix user account needs a name and a work email address— nothing more.
3. Why we process it
Client filesare processed for one purpose: to deliver the service the firm has contracted for — docketing, document handling, correspondence processing, drafting support, and USPTO/EPO data retrieval. We do not process client data for marketing, profiling, resale, or AI model training. This is a contractual and policy limit, not a preference.
Accounts and operational metadata are processed to authenticate users, secure the service, support clients, investigate incidents, meet legal obligations, and bill accurately.
4. How client data is separated
Each client firm gets its own database and its own storage bucket. Data is not pooled across firms, and the separation is architectural rather than a filter applied at query time. Personal information inside client files is classified as Restricted and handled accordingly.
5. Who else touches the data
We use a small number of service providers (“subprocessors”) that store or process client data on our behalf. All hold current third-party security certifications, which we verify at least annually:
| Provider | What it does |
|---|---|
| Amazon Web Services | Object storage, transactional email, queues, OCR, serverless functions |
| MongoDB Atlas | Managed database |
| Vercel | Application hosting |
| OpenAI (API platform) | Document understanding — extraction and classification |
We also use GitHub for source control and Upstash (via the Vercel Marketplace) for rate limiting; neither receives client document content.
We do not share personal information with anyone else. The current list, with each provider’s certifications and where to verify them, is available to clients on request. Adding or replacing a subprocessor requires a vendor review beforeany client data flows to them, and — where a client’s contract requires it — advance notice to that client.
Artificial intelligence
Fenix uses AI in one product pipeline: understanding documents (classifying correspondence, extracting dates, references and office-action content).
- No AI provider trains on client data.OpenAI’s API terms exclude API data from training. AWS Textract performs transient OCR, and we have set the account-level opt-out from AI service improvement.
- OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring, then deletes them. We operate under these standard terms.
- AI calls are made within a single client’s context. Results are written only to that client’s database; source documents remain only in that client’s bucket. Every AI call is logged in the client’s own audit record.
- Client-connected AI assistants are separate. A firm may connect its own Claude to Fenix. Where it does, data flows to Anthropic under the firm’s own agreement, at the firm’s initiative — not ours.
6. Your choices and requests
If you are named in a patent file we hold— as an inventor, applicant, or correspondent — the law firm that engaged us controls that information. Send your request to that firm. If you send it to us, we will route it to them and act on their instruction.
If you are a user of Fenix at a client firm, contact your firm’s administrator or write to us directly.
Our Privacy Officer acknowledges privacy requests within 5 business days and tracks them to completion.
Privacy Officer— Jeffrey Woodworthjeff@fenix.ai
Fenix.ai LLC, 7865 S Flat Rock Way, Aurora, CO 80016
7. How long we keep things
| What | How long |
|---|---|
| Client data | Duration of the contract, plus 30 daysafter it ends — unless the client asks for earlier deletion, or their contract says otherwise |
| Database backups | Deleted data ages out of all backups within at most 12 months |
| Application and audit logs | 12 months |
| Security records | 3 years minimum |
When a client leaves, we offer a data export first (the firm has 30 days from termination to request it), then delete their database and storage buckets and revoke their access. Because each client has their own database and bucket, deletion is complete and demonstrable — we can certify it in writing.
8. Security
We protect information with TLS 1.2 or higher in transit and AES-256 encryption at rest for both the database and object storage. Access to production systems is restricted by role, requires multi-factor authentication, and is reviewed quarterly. Endpoints are encrypted. We run a documented incident response process and maintain SOC 2-aligned policies covering access control, change management, vulnerability management, and vendor oversight.
If a security incident affects a client’s data, we notify that client with a preliminary notice within 48 hours of becoming aware (within 24 hours where their contract requires it), detailed findings within 72 hours, and a final report once the investigation closes.
No system is perfectly secure, and we do not claim otherwise.
9. Where data lives
Client data is stored and processed in the United States only— MongoDB Atlas in us-east-1, AWS in us-west-2, and Vercel in iad1 (US East).
Fenix personnel and contractors may access production systems remotely from outside the United States, under role restrictions and multi-factor authentication. This does not change where data is stored or processed.
10. Legal position
Fenix does not currently target establishment in the European Union. Where a client’s contract requires GDPR processor terms, our Privacy Officer reviews them before signature, and a standard data processing agreement is available on request.
Fenix.ai LLC is a Colorado limited liability company. Under US state privacy laws — including the Colorado Privacy Act — our processing is business-to-business: the individuals whose information we handle are acting in a commercial or professional capacity, not as consumers in an individual or household context. We do not sell personal information, and we do not share it for targeted or cross-context behavioural advertising, as those laws define those terms.
11. Children
Fenix is professional software for law firms. It is not directed to children and we do not knowingly collect information from them.
12. Changes to this notice
We will post any change here and update the “last updated” date. Where a change materially affects how we handle client data, clients are notified under their agreements rather than by a website update alone.
13. Contact
Privacy Officer— Jeffrey Woodworthjeff@fenix.ai
Fenix.ai LLC
7865 S Flat Rock Way
Aurora, CO 80016
United States