INSTITUTIONAL PRIVACY & SECURITY

Privacy & Security Policy

First-principles data architecture, contractual zero-model training guarantees, ephemeral AI inference, and rigorous attorney work-product protection.

Contracting Entity: DepoGenius, Inc. d/b/a Koce
Effective Date: August 14, 2026
Version: 2.0 (Enterprise Privacy & Security)

Institutional Privacy Statement

This Privacy and Security Policy ("Policy") details the rigorous data governance, cryptographic isolation, and privacy safeguards enacted by DepoGenius, Inc., a Delaware corporation doing business as Koce and Koce Technologies ("Koce", "Company", "we", "us", or "our"), governing the collection, processing, and protection of confidential case data, deposition transcripts, video media, live audio feeds, and practitioner information across the Koce Litigation Suite (including Genius, Signal, Edits, Grow, and custom Enterprise Retainers).

INSTITUTIONAL GUARANTEE: KOCE IS ARCHITECTED EXCLUSIVELY FOR TRIAL LAWYERS, LITIGATION TEAMS, AND CORPORATE LEGAL DEPARTMENTS. WE OPERATE ON A FIRST-PRINCIPLES COMMITMENT TO COMPLETE CASE DATA ISOLATION. YOUR CONFIDENTIAL WORK-PRODUCT, CASE PLEADINGS, DEPOSITION TRANSCRIPTS, AND AUDIO-VIDEO FEEDS ARE NEVER USED TO TRAIN, FINE-TUNE, OR IMPROVE ANY FOUNDATION OR COMMERCIAL ARTIFICIAL INTELLIGENCE MODEL.

Article 01

Entity Identification, Structure & Institutional Scope

1.1 Contracting Entity. The Services are owned, operated, and provided exclusively by DepoGenius, Inc. d/b/a Koce. All data controller and data processor obligations described herein run to and from DepoGenius, Inc.

1.2 Professional Legal Context. The Services are engineered strictly for licensed attorneys, litigation support professionals, law firms, and corporate legal departments. Unlike generic consumer applications, Koce treats all customer-submitted records as confidential, proprietary, and potentially protected under the attorney-client privilege, the attorney work-product doctrine, or protective court orders.

1.3 Relationship to Master Terms. This Policy is incorporated into and subject to the Koce Master Terms of Service. In the event of any direct conflict regarding data handling between this Policy and an executed Enterprise Statement of Work (SOW), the more stringent confidentiality and data security provision shall control.

Article 02

Categories of Data Ingested and Processed

To provide high-throughput litigation analysis and live co-pilot capabilities, Koce ingests and processes the following distinct categories of data:

Article 03

Strict Purpose Limitation & Commercial Non-Sale Guarantee

3.1 Sole Permitted Purpose. Koce processes Customer Case Content and live deposition feeds solely and exclusively to deliver the requested litigation analysis, contradiction extraction, timeline generation, real-time live scoring, and video editing services requested by Customer.

3.2 Absolute Non-Sale Guarantee. Koce DOES NOT sell, rent, license, monetize, or commercialize Customer Case Content, personal data, or practitioner usage profiles to any data broker, third-party advertiser, behavioral ad network, or external vendor under any circumstances.

3.3 No Cross-Tenant Data Contamination. Data belonging to one law firm or litigation team is mathematically and cryptographically segregated from all other tenants. No insights, vector representations, or entities extracted from Customer's case records are ever surfaced to or shared with competing firms or adverse litigation parties.

Article 04

Contractual Zero-Model Training Guarantee & Ephemeral Inference

4.1 Absolute AI Training Prohibition. Koce covenants and contractually warrants that Customer Case Content, deposition transcripts, live audio transcriptions, and practitioner prompts are NEVER used to train, retrain, fine-tune, align, or evaluate any base, foundation, or public Large Language Model (LLM).

4.2 Ephemeral Enterprise Inference SLAs. All AI inference workflows (powered primarily via Google Cloud Vertex AI utilizing Gemini 2.0 Flash and Gemini Pro architectures) are executed under enterprise zero-data-retention service level agreements. Ingested text and tokens are processed transiently in volatile memory strictly to generate the requested analysis and are immediately discarded by the model provider upon completion of the inference call.

4.3 Deterministic Fallbacks & Hallucination Firewalls. Where factual citation verification is performed, Koce uses deterministic, rule-based algorithmic parsing and exact-match indexing rather than generative approximations, ensuring source fidelity and preventing hallucinated assertions.

Article 05

Attorney-Client Privilege & Work-Product Preservation

5.1 Non-Waiver Architecture. Transmission of confidential case documents and strategy outlines to Koce is conducted under strict confidentiality and does not constitute a waiver of the attorney-client privilege, work-product protection under Federal Rule of Civil Procedure 26(b)(3) (or state counterparts), or any applicable common-interest doctrine.

5.2 Confidential Commercial Service Provider. In executing automated analysis, Koce acts purely as an automated electronic service provider and litigation support instrumentality. Work-product generated within the platform—such as contradiction maps, cross-examination angles, admission scoring matrices, and trial demonstratives—remains the exclusive, proprietary work-product of Customer.

Article 06

Signal Live Deposition Audio, Zoom RTMS & Statutory Wiretap Protection

6.1 BYOK Zoom Architecture. Koce Signal integrates with Zoom via secure Server-to-Server OAuth and the Zoom Real-Time Media Stream (RTMS) API. Audio packets are routed over dedicated TLS encrypted WebSockets directly into the Signal evaluation engine.

6.2 Ephemeral In-Memory Audio Buffering. Raw PCM audio packets received by Signal are buffered in volatile memory solely for the duration required to generate immediate speech-to-text transcription and live evaluation scoring. Raw audio waveforms are NOT persistently archived to disk following session termination unless explicitly requested under a dedicated video recording retainer.

6.3 Statutory All-Party Consent Mandate. Pursuant to 18 U.S.C. § 2511, California Penal Code § 632, Florida Stat. § 934.03, and all state wiretapping and acoustic privacy statutes, Customer maintains the legal duty to provide an on-the-record admonition at the start of any deposition disclosing the presence of automated AI audio processing.

Article 07

Edits Video Deposition Studio & Media Retention Protocols

7.1 Video Storage & Codec Ingestion. Video deposition recordings uploaded to Koce Edits are stored in encrypted Google Cloud Storage multi-region buckets. Video files are accessible only to authenticated collaborators on the designated case.

7.2 Playout Clip Generation. Generated video clips, subtitle overlays, and contradiction reels are rendered via isolated cloud container workers and made available for direct download as standardized MPEG-4 / H.264 video bundles for trial presentation software.

7.3 Storage Lifecycles & Cold Archival. Unless Customer maintains an active high-capacity video storage subscription, raw video files are maintained in warm storage for the duration of the active case and transitioned to cold archival or purged pursuant to Customer's account retention rules.

Article 08

Grow Docket Intelligence & Public Court Data Ingestion

8.1 Public Records Boundaries. Koce Grow aggregates public court records, state docket filings, and attorney appearance notices from official government court portals. Grow indexes strictly public information.

8.2 Absolute Separation from Confidential Case Rooms. Public docket scraping daemons operate in completely isolated cloud compute environments (DG-scrappy01 and specialized fleet workers). Public docket intelligence feeds never intersect with, query, or expose confidential Customer Case Content stored inside Genius or Signal.

Article 09

Third-Party Subpoenas, Legal Compulsion & $350/hr Compliance Fees

9.1 Immediate Customer Notification. If Koce is served with a subpoena, court order, civil investigative demand, or search warrant seeking the disclosure of Customer Case Content or deposition insights, Koce shall (to the extent legally permissible) notify Customer within two (2) business days to afford Customer the opportunity to move to quash or seek an emergency protective order.

9.2 Subpoena Resistance & Non-Disclosure. Koce will not voluntarily produce Customer Case Content without a final, non-appealable judicial order or express written authorization from Customer's managing counsel.

9.3 Statutory & Technical Fee Reimbursement ($350/hr). In the event Koce is legally compelled to extract, redact, produce, or testify regarding Customer Case Content pursuant to third-party process in litigation where Koce is not a named defendant, Customer agrees to reimburse Koce for all internal engineering, technical data extraction, and forensic compliance hours at the institutional rate of $350.00 per hour, plus all reasonable outside legal fees incurred in responding to such process.

Article 10

Support Staff Access Controls & Role-Based Access (RBAC)

10.1 Access by Explicit Consent Only. Koce engineering and support personnel do not access Customer Case Content by default. Staff access is permitted only when Customer explicitly files a technical support inquiry or enables the "Support Access" toggle in Case Settings.

10.2 Immediate Revocation. Customer may revoke staff access at any time with immediate effect. Revocation instantly terminates active support tokens and isolates the case workspace.

10.3 Immutable Audit Logging. Every database read, file download, and administrative query executed by Koce personnel is logged immutably with timestamp, user ID, IP address, and cryptographic signature.

Article 11

Data Security, Cryptographic Architecture & Cloud Infrastructure

11.1 Encryption Standards. All data transmitted to or from the Services is encrypted in transit using Transport Layer Security (TLS 1.3). All data stored in Cloud Firestore, Cloud Storage buckets, and persistent volumes is encrypted at rest using industry-standard AES-256 encryption.

11.2 Google Cloud / Firebase Enterprise Infrastructure. Koce is hosted on Google Cloud Platform (GCP) and Firebase enterprise multi-zone infrastructure (us-central1 region), benefiting from physical datacenter security, redundant power systems, automated DDoS mitigation via Google Cloud Armor, and intrusion detection systems.

11.3 Vulnerability Management & Dependency Auditing. Our engineering pipeline enforces automated dependency auditing, container vulnerability scanning, and strict lint firewalls on every build to prevent supply-chain vulnerabilities.

Article 12

Data Retention, Self-Service Export & Permanent Deletion

12.1 Self-Service Data Portability. Customer maintains the right to export all deposition reports, contradiction summaries, demonstrative timelines, and synchronized video clips at any time in standard industry formats (PDF, DOCX, MP4, JSON, CSV).

12.2 Account Termination & Deletion Cycles. Upon account closure or explicit case deletion by Customer, case files are marked for soft-deletion and permanently purged from active production databases and cloud storage buckets within thirty (30) days, with residual disaster-recovery backup snapshots expiring according to standard cloud backup retention cycles.

Article 13

Multi-Jurisdictional Privacy Frameworks & Statutory Disclosures

13.1 European Union & UK GDPR Compliance. For legal practitioners and data subjects located in the EU and UK, Koce processes personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679). Koce acts as a Data Processor on behalf of Customer (the Data Controller). Standard Contractual Clauses (SCCs) apply to cross-border data transfers.

13.2 California Consumer Privacy Act (CCPA / CPRA). Under the CCPA/CPRA, Koce acts strictly as a Service Provider. Koce does not "sell" or "share" personal information as those terms are defined under California law.

13.3 Texas Data Privacy and Security Act (TDPSA). Koce complies with the TDPSA requirements, maintaining appropriate administrative, technical, and physical data security measures.

Article 14

Cookies, Telemetry & Transparent Web Tracking

14.1 Operational Cookies Only. The Services utilize only strictly necessary session and authentication cookies required to maintain authenticated user state and remember interface preferences.

14.2 Aggregated Analytics (GA4). We utilize Google Analytics 4 with IP anonymization enabled solely to understand aggregate landing page traffic, bounce rates, and navigation patterns. We do NOT deploy tracking pixels from third-party social media or advertising platforms.

Article 15

Amendments, Notifications & Data Protection Officer Contact

15.1 Policy Updates. We may update this Privacy and Security Policy periodically to reflect technological advancements, statutory revisions, or new product features. Material modifications will be announced via platform banners or direct email notification to account administrators.

15.2 Security & Privacy Officer Contact. For inquiries regarding data protection, security audits, sub-processor lists, or to exercise statutory privacy rights, please contact our Data Protection Officer: