Privacy Policy

Effective date: 14 August 2026

Esas is a software service for lawyers and law firms, covering case, client, hearing, document and billing management. This policy applies to the getesas.com web application and the Esas mobile application (com.getesas.app).

In short: we do not sell your data, we do not use it for advertising, and we run no third-party tracking or analytics SDKs. All data is hosted on servers located in the European Union.

1. Controller and processor

Esas holds two distinct sets of data, and responsibility differs for each:

  • For your account data (name, email, role, firm membership, session and security records), Esas is the data controller.
  • For the content your firm enters (client details, case files, documents, hearings, invoices), the subscribing law firm is the data controller; Esas acts solely as a data processor, hosting and processing that content on the firm’s instructions.

If you are a client of a law firm and have a request about the data held in your file, please contact that firm directly. Esas does not act on such data without the firm’s instruction.

2. Personal data we process

2.1. Account and identity data

Full name, email address, your role (administrator · lawyer · staff), the firm you belong to, and invitation and membership records. Your password is stored by Firebase Authentication as a one-way hash; Esas cannot see or recover your password.

If you use Sign in with Google or Apple on the web application, the provider passes us only the identity details needed to create your account (your email address and, where available, your name). We access no other data from your social account and send no data back to the provider. These options are not offered in the mobile app.

2.2. Content entered by the firm

Client and contact records, case and matter details, hearing and deadline calendars, tasks, uploaded documents, invoices and payment records, time entries and notes. Given the nature of legal practice, this content may include special categories of personal data (e.g. health data or criminal-offence data). The purpose and legal basis for collecting it are determined by your firm.

2.3. Technical and security data

  • Session cookie and session expiry information.
  • Server logs containing IP address, browser or app version, and request time.
  • App integrity verification: Firebase App Check confirms that requests originate from the genuine app, via Google Play Integrity on Android and Apple App Attest on iOS.
  • In-app activity records (who changed what and when) and platform administration audit logs.
  • Push notification token (Firebase Cloud Messaging): when you allow notifications in the mobile app, the token generated for your device is stored against your account and used solely to deliver notifications to you. It identifies the device, not you personally, and is deleted when you sign out. Firebase also assigns each installation a technical identifier (installation ID); this is required for notification delivery and crash reporting to work and is not used for advertising.
  • Mobile app crash reports(Firebase Crashlytics): when the app closes unexpectedly or an operation fails, we record the technical error trace, device model, operating system and app version, the name of the action performed beforehand (e.g. “add deadline”), your user identifier and your firm and role. Your name, email address and client or case content are never included. Crash reports are collected only from release builds on real devices and are deleted by Firebase after 90 days.

2.4. Data we do not collect

We do not collect advertising identifiers, location data, device contacts, camera or photo library data. The mobile app requests none of these permissions. We use no third-party advertising, product analytics or tracking SDKs — the only diagnostic tool in the mobile app is the crash reporting described above, which does not track your usage behaviour. We never sell your data or share it for advertising purposes.

3. Purposes and legal bases

  • Providing the service — account creation, authorisation, case, client and document management: performance of a contract.
  • Transactional communication — invitations, password resets, hearing and task reminders: performance of a contract.
  • Security and abuse prevention — integrity checks, audit logs, detection of unauthorised access: legitimate interests.
  • Backups and business continuity — protection against data loss: legitimate interests.
  • Legal obligations — responding to lawful requests from competent authorities, statutory retention: legal obligation.

These bases are assessed under GDPR Art. 6 and, where applicable, Turkish Law No. 6698 (KVKK) Art. 5. We do not process personal data for marketing purposes.

4. The mobile application

The mobile app is a companion to the web application. Accordingly:

  • No accounts are created in the mobile app; you sign in with an existing account created on the web.
  • The app contains no purchases, no subscription sales and no advertising.
  • Sign-in uses email and password only; no social sign-in provider is used.
  • Session credentials are kept in the operating system’s secure storage on your device and are erased when you sign out.
  • When you open a document, the file is downloaded to the app’s temporary folder and opened with the system viewer; these temporary copies are cleared by the operating system.
  • The app requests no location, contacts, camera, microphone or calendar permissions.

5. Who we share data with

To deliver the service we rely on the following service providers (sub-processors):

  • Google Cloud / Firebase — authentication, database, file storage, application hosting, notifications, app integrity and mobile crash reporting. Data is stored in the europe-west1 (Belgium) and europe-west4 (Netherlands) regions.
  • Resend — transactional email only (invitations, notifications). The recipient address and message content are transmitted.
  • Google Play and Apple — distribution of the mobile app and verification of device/app integrity.

Beyond these, personal data is disclosed only in response to a lawful, properly formed request from a competent authority. We do not share data with advertising networks and we do not sell data.

6. Where your data is held

The database, uploaded documents and application servers run in data centres inside the European Union (Belgium and the Netherlands). Where a provider — such as our transactional email provider — may process data outside the EU, transfers rely on appropriate safeguards such as Standard Contractual Clauses.

7. Retention periods

  • Session cookie: 5 days, after which it expires.
  • Records moved to the trash: permanently deleted after 30 days, together with their associated files.
  • Point-in-time recovery: the last 7 days.
  • Daily backups: automatically deleted after 90 days.
  • Activity and audit logs: for as long as the account is active.
  • Active content data: until deleted by your firm or until the account is closed (see section 10).

8. Security

  • All traffic is encrypted with TLS; data is encrypted at rest.
  • Strict firm isolation: each firm’s data is held in its own scope, and every read and write passes a server-side identity, firm and role check. Database rules block direct writes from clients entirely.
  • Firebase App Check ensures only requests from a verified app instance are accepted.
  • The session cookie is HttpOnly and Secure, and cannot be read by JavaScript.
  • Whenever a platform administrator needs to access a firm’s data, that access is written to an audit log.
  • Passwords are stored as one-way hashes and are not visible to our staff.

9. Your rights

Under GDPR Art. 15–22 (and KVKK Art. 11 where applicable) you have the right to know whether your personal data is processed, to access it, to request its rectification or erasure, to request restriction of processing, to receive your data in a portable format, and to object to processing.

Send requests from the email address registered on your account to privacy@getesas.com. We respond within 30 days. If a request concerns case data held by a law firm, we will refer it to that firm.

10. Account and data deletion

You may request deletion of your account and data at any time.

  • Removing a user: a firm administrator can remove a user from the firm under Settings → Team.
  • Deleting your account entirely: email privacy@getesas.com from the address registered on your account with the subject "Account deletion request". We begin the process once your identity is verified.
  • What is deleted: your identity record, profile details, sessions and notification records. When an entire firm account is deleted, all of that firm’s client, case, document, invoice and time-entry data is deleted as well.
  • How long it takes: within 30 days from production systems, and within 90 days from backups, in line with our backup retention period.
  • Exception: records we are legally required to keep (e.g. invoices and accounting documents) are retained for the statutory period and used for no other purpose.

11. Children's data

Esas is a professional tool and is not directed at anyone under 18. We do not knowingly create accounts for users under 18.

12. Changes to this policy

When this policy is updated, the effective date on this page changes. We announce material changes separately, in the app or by email.

13. Contact

For any privacy question, request or complaint: privacy@getesas.com