First Chair, Inc., doing business as inSession ("inSession," "we," "us," or "our"), provides an AI-powered trial simulation, litigation strategy, and legal training platform.
inSession may be marketed to and used by individuals and organizations located in the European Economic Area ("EEA"), United Kingdom ("UK"), and other jurisdictions outside the United States.
We recognize that international use of inSession may be subject to privacy and data-protection requirements, including the European Union General Data Protection Regulation ("GDPR") and applicable UK data-protection laws.
This page explains our current approach to GDPR and international privacy. It supplements our Privacy Policy, Terms of Use, Security, and Compliance & Trust information.
inSession does not currently represent that it has completed a comprehensive independent GDPR compliance certification or assessment.
Our role under data-protection law depends on the information involved and the circumstances in which it is processed.
Account and Business Information. For information collected to establish and administer accounts, manage subscriptions, communicate with users, operate our website, provide customer support, maintain security, and manage our business relationship, First Chair, Inc. generally acts as a data controller.
This means we determine the purposes and means of processing that information.
Case-Specific Data. When a law firm, organization, educational institution, or other customer submits Case-Specific Data to inSession and directs how that information is used through the platform, First Chair, Inc. generally acts as a data processor on behalf of that customer.
The customer may act as the data controller or may itself process the information on behalf of another party.
Our specific legal role may vary depending on the circumstances and applicable law.
Case-Specific Data may include information concerning actual or simulated legal matters, including:
Users retain ownership of their Case-Specific Data.
inSession does not sell Case-Specific Data.
inSession does not use Case-Specific Data to train artificial intelligence models.
Our service providers are not permitted to use Case-Specific Data processed on behalf of inSession to train their artificial intelligence models.
Case-Specific Data is processed as necessary to provide the services and functionality requested by the user.
Legal matters can contain highly sensitive information.
Depending on the matter, Case-Specific Data may contain information considered sensitive or subject to heightened protection under applicable law, including information concerning:
Some of this information may constitute special-category personal data under Article 9 of the GDPR or information subject to Article 10 of the GDPR concerning criminal convictions and offenses.
Users are responsible for determining whether they have an appropriate legal basis and authority to submit and process such information through inSession.
Organizations subject to GDPR or UK data-protection requirements should evaluate their obligations before submitting sensitive Case-Specific Data.
Where GDPR or UK data-protection law applies, our legal basis for processing personal data depends on the purpose and circumstances of the processing. Our legal bases may include:
Performance of a Contract. We may process information when necessary to provide inSession services requested by a user or organization or to take steps related to entering into a contractual relationship.
Legitimate Interests. We may process information where necessary for legitimate business interests, provided those interests are not overridden by applicable individual privacy rights. These interests may include:
Consent. We may rely on consent where required or appropriate, including for certain cookies, marketing technologies, communications, or other processing activities.
Where processing is based on consent, consent may be withdrawn at any time, subject to applicable law. Withdrawal does not affect the lawfulness of processing performed before consent was withdrawn.
Legal Obligations. We may process information when necessary to comply with applicable laws, regulations, court orders, or other legally binding obligations.
Other legal bases may apply depending on the circumstances and applicable law.
inSession uses artificial intelligence to provide simulations, analysis, scoring, feedback, transcription, reporting, and other platform functionality.
Case-Specific Data may be processed by vetted technology providers as necessary to provide functionality requested through inSession.
Case-Specific Data processed through inSession is not used to train artificial intelligence models.
Our service providers are not permitted to use Case-Specific Data processed on behalf of inSession to train their artificial intelligence models.
A current list of material service providers and subprocessors is available upon request by contacting [email protected].
inSession may generate automated scores, evaluations, simulations, assessments, recommendations, and other AI-generated outputs.
These tools are designed for litigation preparation, training, strategy, education, and professional development.
inSession's AI-generated scores, simulations, and assessments are not intended to make decisions producing legal effects or similarly significant effects concerning an individual without appropriate human involvement.
Organizations using inSession remain responsible for determining how platform outputs are used in employment, education, legal representation, professional evaluation, or other decision-making processes.
First Chair, Inc. is a United States company, and inSession's Case-Specific Data infrastructure is maintained in the United States.
Accordingly, use of inSession from the EEA, UK, or another jurisdiction outside the United States may involve transferring personal data to the United States.
Data-protection laws in the United States may differ from those in a user's home jurisdiction.
inSession does not currently represent that First Chair, Inc. is certified under the EU-U.S. Data Privacy Framework.
inSession has not currently implemented a generally available Data Processing Agreement incorporating European Commission Standard Contractual Clauses or a UK international data-transfer mechanism for all customers.
Organizations that require specific international data-transfer arrangements should contact [email protected] before submitting regulated personal data through the platform.
inSession does not currently offer a generally available Data Processing Agreement ("DPA") for all customers.
Organizations subject to GDPR, UK data-protection requirements, or other contractual privacy requirements should contact [email protected] before using inSession to process regulated personal data where a DPA or other contractual mechanism is required.
Our contractual and international data-protection capabilities may evolve as the platform grows.
Where GDPR, UK data-protection law, or another applicable law provides these rights, individuals may have the right to:
These rights are subject to applicable legal requirements, exceptions, and limitations.
To submit a privacy request, contact [email protected].
We may request information reasonably necessary to verify identity and determine the applicability of a request.
Where inSession acts as a processor of Case-Specific Data on behalf of a law firm, organization, school, or other customer, that organization may be responsible for responding to requests from individuals whose personal data appears within Case-Specific Data.
If we receive a request concerning personal data for which a customer is the controller, we may direct the requester to the applicable customer or assist the customer as appropriate and required by applicable law.
We retain personal information for as long as reasonably necessary to provide our services, maintain accounts, fulfill legitimate business purposes, maintain security, resolve disputes, comply with legal obligations, and enforce agreements.
Retention periods may vary depending on the information, account configuration, contractual requirements, operational requirements, and applicable law.
Users may have the ability to delete Case-Specific Data through platform controls and may also contact inSession regarding eligible deletion requests.
Deletion from active systems may not result in immediate deletion from encrypted backups, security logs, disaster-recovery systems, or other systems maintained for legitimate operational, security, or legal purposes.
inSession may use cookies and similar technologies on the public-facing portions of our website.
These technologies may include analytics and advertising technologies such as Google Analytics and the Meta Pixel.
These technologies are not used within authenticated member areas or case-related areas of inSession.
Case-Specific Data is not provided to these technologies for advertising or marketing purposes.
Where applicable law requires consent before non-essential cookies or similar technologies are activated, inSession seeks to obtain appropriate consent.
Users may withdraw applicable cookie consent through available privacy controls.
inSession uses vetted service providers for functions such as:
Providers processing Case-Specific Data on behalf of inSession are not permitted to sell that information or use it to train their artificial intelligence models.
A current list of material service providers and subprocessors is available upon request by contacting [email protected].
inSession uses technical and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
Current safeguards include measures such as:
Additional information is available on our Security page.
First Chair, Inc. has not currently appointed a representative in the European Union under Article 27 of the GDPR or a separate UK data-protection representative.
Whether such a representative is legally required depends on the nature and scope of First Chair, Inc.'s activities and applicable law.
As our international operations develop, we will evaluate these requirements and update our practices where necessary.
First Chair, Inc. has not currently appointed a formal Data Protection Officer ("DPO").
We will evaluate whether appointment of a DPO becomes required or appropriate as the nature and scale of our processing activities develop.
Privacy questions and requests may currently be directed to [email protected].
Individuals located in the EEA or UK may have the right to lodge a complaint with the data-protection supervisory authority responsible for their jurisdiction.
We encourage users to contact us at [email protected] with privacy concerns so that we have an opportunity to review and address them.
Nothing in this section limits a right to contact a supervisory authority where provided by applicable law.
Privacy and artificial intelligence regulation continues to evolve.
We may update our international privacy practices, contractual mechanisms, service-provider arrangements, and this page as inSession expands and applicable legal requirements change.
Material updates will be reflected on this page or in our Privacy Policy as appropriate.
For privacy inquiries, data-subject requests, or questions concerning personal information:
First Chair, Inc. dba inSession
Privacy: [email protected]
Website: inSession.law
For organizational GDPR, international data-transfer, contractual, or compliance inquiries:
Legal & Compliance: [email protected]