Skip to main content

Your data, protected

This Privacy Policy describes how BusinessFirst LLC collects, uses, and safeguards your information when you use AccuMax and its connected services.

Effective Date: October 2, 2026

1. Introduction

This Privacy Policy describes how BusinessFirst LLC ("BusinessFirst," "we," "us," or "our") collects, uses, shares, and protects information about you when you use AccuMax practice management services (the "Services"), including through our websites at accumax.ai, bfirst.ai, and businessfirst.ai, and our web, browser, and desktop applications.

By accessing or using the Services, you agree to this Privacy Policy. If you do not agree, you must not use the Services.

If you are a client of a firm that uses AccuMax, that firm controls your information and is responsible for how it is used within the platform. We process it on the firm's behalf, and you should direct access and deletion requests to the firm in the first instance.

2. Connected Email (Gmail & Outlook)

AccuMax lets you connect a personal mailbox (Google Gmail or Microsoft Outlook) so you can read, organize, and reply to your work email inside the platform. This integration is optional and is only enabled when you explicitly connect an account and grant consent through the provider's secure OAuth flow.

What we access

  • Email addresses (sender, recipients, cc and bcc)
  • Message subjects, bodies, and attachments
  • Message dates, labels, folders, and read/flag status
  • Your basic mailbox profile (name and email address)

How we use email data

  • Display your messages in your AccuMax inbox
  • Synchronize new and changed messages periodically
  • Let you read, reply to, forward, and send messages
  • Let you search, filter, flag, and link messages to client accounts

How email data is protected

  • OAuth tokens are encrypted at rest using AES-256-GCM
  • All data is transmitted over HTTPS (encrypted in transit)
  • Your mailbox is private to you — other users and admins cannot read it
  • Email data is isolated per tenant and never shared across firms
  • We never sell your email data, and we never use it to train AI models (see section 6)

Limited Use disclosure

AccuMax's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Gmail data for advertising, and we only access the data needed to provide the features described above.

Revoking access

You can disconnect your mailbox at any time:

When you disconnect, synchronization stops immediately and we delete stored messages and tokens for that mailbox within 30 days.

3. Other Information We Collect

  • Account information — name, email, firm name, phone, role, and profile details
  • Client and task data — documents, messages, notes, and workflow information you create in the platform
  • Payment information — processed by third-party processors; we do not store full card details
  • Usage and device data — IP address, browser, device identifiers, and pages visited
  • Enquiries — the name, email, firm and message you submit when you request a demo or contact us

4. How We Use Information

  • To provide, operate, and support the Services
  • To authenticate users and secure accounts
  • To process payments and administer subscriptions
  • To respond to enquiries, provide support, and send service messages about your account
  • To understand how the Services are used so we can improve them, in aggregate and without profiling individuals
  • To comply with legal, tax, and regulatory obligations

We do not sell personal information, and we do not use client data for advertising.

5. Legal Bases for Processing

Where the EU or UK General Data Protection Regulation applies, we process personal data on the following bases: performance of a contract with you; our legitimate interests in operating and securing the Services; compliance with a legal obligation; and your consent, where consent is required — for example, to connect a mailbox or to set non-essential cookies.

6. AI and Your Data

AccuMax's Agents read your firm's client record in order to do their work. That is what makes an answer specific to your client rather than generic: your data is supplied as context at the moment a question is answered, and it stops being used once that answer is returned.

That is a different thing from training, and the distinction matters: your client and tenant data is never used to train AI models — not ours, and not a provider's. It does not become part of any model's weights, it is not pooled with other firms' data, and it is never used to improve a model that anyone outside your firm will use.

The models AccuMax uses are those offered within the Microsoft Azure AI platform, so your data is not handed to an outside model provider. Our Security page sets out the controls in full.

7. How We Share Information

We share information only in these circumstances:

  • Service providers — vendors who host, secure, or support the Services, including Microsoft Azure for hosting and AI processing, and payment processors for billing. They may use the data only to provide services to us.
  • Within your firm — according to the roles and permissions your firm's administrators configure.
  • Legal requirements — where we are required by law, regulation, or valid legal process, or to protect rights, safety, or property.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

We do not sell personal information, and we do not share it with advertisers.

8. Cookies and Analytics

We use cookies and similar technologies on our websites to keep the site working, to remember your preferences, and to understand how the site is used in aggregate. We use privacy-respecting website analytics to count visits and measure which pages and campaigns bring people here; we do not use advertising or cross-site tracking cookies.

Our Cookie Policy explains what is set, why, and how to control it.

9. Data Security

  • Encryption at rest (AES-256-GCM) and in transit (HTTPS)
  • Multi-factor authentication available on all accounts
  • Role-based access controls and audit logging
  • Account and tenant isolation, enforced by the platform
  • CSRF protection and account lockout against brute-force attacks
  • Passwords hashed using industry-standard algorithms

No system can be guaranteed completely secure, but these are the controls we operate and maintain.

10. Data Retention

We retain your data while your account is active. When you stop being a customer, we provide a 30-day window to export your data, after which it is deleted from the platform. Connected mailbox data is deleted within 30 days of disconnecting that mailbox. We may retain limited records for longer where law requires it, for example for tax or accounting purposes.

11. International Data Transfers

BusinessFirst LLC is based in the United States and the Services are operated from there. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data protection law may differ from that of your country. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

12. Your Rights and Choices

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Request a portable copy of data you provided to us
  • Object to, or request restriction of, certain processing
  • Withdraw consent where processing is based on consent
  • Disconnect a connected mailbox at any time
  • Opt out of non-essential communications

Residents of California and of other US states with comprehensive privacy laws have the right to know what personal information is collected, to request its deletion or correction, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising.

To exercise any of these rights, contact us using the details in section 15. If you are in the EU or UK, you also have the right to lodge a complaint with your local supervisory authority.

13. Children's Privacy

The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the Effective Date above, and if the changes are material we will give notice through the Services or by email before they take effect.

15. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

BusinessFirst LLC
AccuMax Legal Department
14846 NE 17th PL, Bellevue, WA 98007
Email: accumaxsupport@bfirst.ai

Effective Date: October 2, 2026