FirstPanel › Privacy Policy
Version 1.2 — in force from 20 August 2026.
Last updated 20 August 2026. Previous versions are kept; ask at privacy@firstpanel.app.
What changed in 1.2: § 14 says a change to this policy takes effect when we post it, with no 30-day waiting period. What protects you is not the delay — it is the acceptance gate in Terms of Service § 20, which asks every user to accept a new version before continuing and never treats continued use as acceptance.
What changed in 1.1: notice of a new sub-processor is given when the change happens rather than 30 days beforehand (§ 6.1, and Data Processing Addendum § 7.4); and our own billing is described as what it is — our vendor, not a sub-processor of your data.
ZAP POP MVP LLC ("Company", "we") provides FirstPanel, a service used by California workers' compensation law firms to prepare and submit QME panel requests to the Division of Workers' Compensation ("DWC").
This policy explains what personal information the Service handles, why, how long it is kept, who else sees it, and what rights are available.
FirstPanel holds confidential information about people who are not our customers.
Our customers are law firms. But to submit a panel request, the Service necessarily holds information about the injured worker whose claim is at issue — their name, home address, claim number, date of injury, employer, the medical dispute in their case, and the objection letter and panel documents themselves.
That information is stored on infrastructure we control. It is not merely passed through.
We are not the party that decides what happens to that information. The law firm decides, and we act on the firm's instructions. In the language of California law, the firm is the business and we are its service provider. What that means in practice is set out in section 7.
| Firm users — attorneys and staff at a customer firm | We handle their information as a business, for account and billing purposes. Sections 3–6 apply. |
| Injured workers and other case participants — including opposing parties, adjusters, defense attorneys and physicians named in a matter | We handle their information only as a service provider, on the firm's instructions. Section 7 applies. |
| Website visitors and prospects | Sections 3–6 apply to whatever they send us. |
| Category (Cal. Civ. Code § 1798.140(v)) | What that is here |
|---|---|
| Identifiers | Name, work email address, work phone number |
| Commercial information | Subscription, invoices, payment records |
| Internet or network activity | Sign-in times, IP address, pages accessed within the Service, actions taken |
| Professional or employment-related information | Firm name, role at the firm, whether the user is an administrator |
We do not collect government identifiers, financial account numbers, biometric data, or precise geolocation from firm users. Payment card details are handled by our payment processor and do not reach our systems.
Entered by the firm, or returned to us by DWC on the firm's behalf:
| Category | What that is here |
|---|---|
| Identifiers | Injured worker's name and home address; names, phone numbers and email addresses of claims adjusters, defense attorneys and treating physicians |
| Personal information under § 1798.80 | Employer, insurance/claim number, medical information about the injury |
| Protected classification characteristics | Medical condition, to the extent the dispute describes it |
| Sensitive personal information | Health information — the nature of the injury, the treating physician's findings, the specialty in dispute, and the contents of the objection letter and any panel documents |
| Professional or employment-related information | Employer name, date of injury, the fact of a workers' compensation claim |
We treat this whole category as sensitive, whether or not each individual field technically qualifies, because in combination it identifies a named person's medical claim.
We do not collect Social Security numbers, driver's license numbers, financial account numbers, or biometric information — because the DWC Form 106 does not require them and the Service does not ask for them. If a firm uploads a document containing such information, it reaches us inside that document; we do not extract or index it.
We do not buy personal information, and we do not obtain it from data brokers, social networks, or advertising networks.
For firm users: to create and secure accounts; to authenticate; to provide support; to invoice; to send service messages such as filing results and failure alerts; to detect and investigate misuse; and to comply with law.
Within customer matters: for one purpose only — to provide the Service to the firm. Specifically: to fill and submit the DWC form, to calculate and display candidate filing dates, to check an uploaded letter against the entered information, to store and return what DWC issues, and to support the firm when it asks.
Most objection letters are scans or faxes with no text layer, so checking one against what the firm typed means reading the image. We say how, because "we check your document" without saying how is the part a firm should want answered:
We do not use information in customer matters for our own purposes. In particular we do not use it for marketing, for analytics about anything other than the operation of the Service, or to train or improve any machine-learning or artificial-intelligence model. There is no artificial-intelligence feature in this product: no large language model, no generated text, no automated decision-making about a claim. The software fills a form, calculates dates from statute, and reads a document to check two fields.
One company processes customer matter data on our behalf. The whole list is here rather than on a separate page, because a one-item list does not need a page of its own.
Amazon Web Services, Inc., Seattle, Washington, USA.
| What it does | All computing, database, object storage, encryption key management, and outbound email for the Service |
| Where | United States only — AWS's us-west-1 region, Northern California |
| Specific services used | EC2, RDS for PostgreSQL, S3, KMS, Secrets Manager, Systems Manager, CloudTrail, CloudWatch, Simple Email Service |
| On what terms | Its standard customer agreement, its data processing addendum, and a business associate agreement with us |
| Since | Launch |
AWS does not use the data for its own purposes. Its third-party attestations (SOC 1/2/3, ISO 27001 and others) are published by AWS and are the right evidence for the infrastructure layer — they are AWS's, not ours, and we do not present them as ours.
One more company handles email addressed to us, and never matter data.
Cloudflare, Inc. operates the mail routing for the firstpanel.app domain, so a message
sent to support@, privacy@ or legal@firstpanel.app passes through Cloudflare on its way
to us. It receives whatever is in that message and nothing else: it has no access to the
Service, the database, or any document. Mail we send out does not go through it. It is named
here because a policy that tells you to write to privacy@ should tell you what handles the
message.
Our own billing is not on this list, and here is why.
We invoice subscriptions manually. There is no payment processing inside FirstPanel: no billing integration, no card details anywhere in the Service, and nothing about paying us touches your matters.
Where we use a payment processor to invoice and collect our own fees — Stripe, Inc., South San Francisco, California, USA is the one we would use — it receives the billing contact on your firm's account: name, email, telephone, billing address, and whatever payment details you give it directly. It receives no matter data of any kind: no case, no injured worker, no document, no claim number, and no access to the Service, the database or stored documents.
That makes it our vendor, not a sub-processor. A sub-processor is a company we bring in to handle your data on your behalf. Collecting our fees is our own business, on our own account — the same as our bank or our accountant, neither of which is on this list either.
Adding or replacing a sub-processor means telling firm administrators when it happens, and keeping this list complete. See Data Processing Addendum § 7.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in the CCPA. We have not done so in the preceding twelve months. We do not serve advertising and we do not permit third-party trackers in the Service.
For everything within a customer's matters, we act as a service provider to the customer firm, which is the business.
We are contractually bound — in the Data Processing Addendum, which forms part of every customer agreement — to:
If you are an injured worker and want to know what is held about you, or want it corrected or deleted, contact the law firm handling your claim. They are the party that decides. We will help them respond. If you contact us directly, we will tell you so and, where we can identify the firm, pass your request to them.
| What | How long |
|---|---|
| Matter data while a firm is a customer | For as long as the firm's subscription is active |
| Matter data after a subscription or trial ends | 30 days by default; the firm may set up to 365 days; never fewer than 14 days after we record the account as ended |
| Copies in backups and prior stored versions | A further 14 days after deletion |
| Account records and the audit log | Retained after matter data is deleted — this is the record of what was deleted and when, and of who accessed what. It does not contain the contents of matters |
| Firm user account and billing records | For as long as needed for the relationship, and afterwards as required by tax and limitation periods |
A firm can export everything it holds with us, at any time, free of charge, without asking us.
The measures are described in full in Annex A of the Data Processing Addendum. In summary:
Everything the Service stores and processes stays in the United States — AWS's
us-west-1 region, Northern California. That covers the database and its automated backups
and snapshots, every stored document, the encryption keys, the audit logs, and the servers
that do the work. None of it is replicated to another region or another country.
Email is the one exception, and we would rather say so than write "never". Mail to us
at support@, privacy@ or legal@firstpanel.app is routed by Cloudflare (section 6.1),
whose network is global, so a message you send us may be processed outside the United States
in transit. Mail from us is sent through AWS in Northern California, but it is then
delivered to your own mail provider, wherever that is — a matter for you rather than us. Our
notification emails identify a filing and its outcome; they are not a copy of the file.
Reading a stored document leaves a trail in both of the two ways it can be read:
Those CloudTrail records are delivered to storage held under S3 Object Lock in compliance mode for 365 days, which means no one can alter or delete them for that period: not an administrator, not the account root, not us. That is a property of AWS's storage, not a promise about our behavior, which is the point of saying it.
No agency certifies that phrase, so it is always a vendor's claim about itself. What is true and checkable is that the infrastructure is HIPAA-eligible AWS infrastructure operated under a business associate agreement between us and AWS.
We do not offer a business associate agreement to customer firms: an applicant's law firm is generally neither a covered entity nor a business associate under HIPAA, so there would be nothing for such an agreement to do.
No system is perfectly secure. This is what we commit to, so that a firm knows what to expect rather than having to ask during the worst week of its year.
What counts. Any breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal information we hold — matter data or firm user data. That includes access by someone who should not have had it, even if nothing was changed and nothing was taken. It does not include an unsuccessful attempt that reached nothing, or a fault that made data unavailable without exposing it, though we will tell a firm about a significant outage anyway.
Who we tell, and when. We notify each affected firm's administrators by email, and by notice inside the Service, without undue delay and in any event within 72 hours of confirming the breach. The 72 hours runs from confirmation, not from the moment the breach began — we may not know at once, and a clock we cannot honestly start is worse than a longer one we can. We will not wait for the investigation to finish before telling you.
What the notice contains, to the extent known at the time: what happened and when; which categories of information and roughly how many individuals and matters are affected; whether your firm's matters are among them and which ones; what we have done to stop it; what we recommend you do; and a named person to reply to. Where we do not yet know something, the notice says so rather than leaving the gap unmarked, and we send what we have and follow up as the picture fills in.
Who tells the injured workers. You do, if anyone does. You are the firm and they are your clients; the decision and the communication are yours, and we would be the wrong party to make either. We will give you what you need to make it — including the specific records affected — and we will support you in meeting your own obligations, including any duty you have under the Rules of Professional Conduct. Where the law requires us to notify individuals directly, we will, and we will tell you before we do.
What we will not do. We will not describe an incident as resolved before it is. We will not treat our notice as an admission of fault, and it is not one. And we will not stay silent because the legal position is unclear — if we are unsure whether something is reportable, we report it.
The same commitment appears in the Data Processing Addendum § 5 and Terms of Service § 17.3. If those and this section ever disagree, tell us at privacy@firstpanel.app and we will treat the interpretation most favorable to the firm as governing until we have fixed it.
If you are a California resident, the CCPA as amended by the CPRA gives you rights to:
How to exercise them.
We do not charge for these requests.
We currently serve California workers' compensation practice, so California law is what governs in practice. If you are a resident of another state with a comprehensive privacy law, contact privacy@firstpanel.app and we will honor the rights that law gives you to the extent it applies.
The Service is a professional tool and is not directed to children. We do not knowingly collect personal information from anyone under 16 through account registration. A matter may concern an injured worker who is a minor; that information reaches us only from the firm, in the course of the firm's representation, and we handle it as section 7 describes.
The Service uses only the cookies necessary to keep a user signed in and to protect against cross-site request forgery. We do not use advertising, analytics or tracking cookies, and we do not permit third parties to set cookies in the Service.
We post any change here and update the version date. A change takes effect when we post it. There is no waiting period.
For a change that materially affects how we handle customer matter data, we notify firm administrators by email at the time of the change, and the Service asks every user to accept the new version of the agreement set before they can continue to use it — see Terms of Service section 20. We never treat continued use as acceptance.
ZAP POP MVP LLC 2108 N St #17231 Sacramento, CA 95816
Privacy: privacy@firstpanel.app Support: support@firstpanel.app