Privacy Policy
Who We Are
Legal entity / data controller. Versa Group is operated as a sole proprietorship by Olena Olshevska. References to "Versa Group," "we," "our," and "us" in this Privacy Policy refer to Olena Olshevska doing business as Versa Group. Day-to-day operation of the service is led by founder Arsenii Olshevsky. For any privacy question or request, contact hello@versagroup.tech.
Versa Group ("Versa Group," "we," "our," "us") provides AI-powered lead intake automation software for personal injury law firms and other legal practices. Our website is versagroup.tech.
Versa Group is not a law firm and does not provide legal advice. We provide software services only.
Information We Collect
When you contact us through our website or use the Versa Group service, we may collect:
- Name, firm name, email address, and any message you submit through our contact or demo forms
- Business information you provide during onboarding (intake questions, case criteria, call routing rules, scripts)
- Lead data sent to our intake workflow on behalf of subscribing law firms — typically the inbound caller's or website visitor's name, phone number, email, and free-text description of their legal matter
- System logs of intake events (timestamps, message status, errors) used to monitor service health
We do not collect more information than is needed to operate the service for the subscribing firm.
How We Use Your Information
- To respond to your inquiries and configure your AI intake system
- To operate the lead-response workflow on behalf of the subscribing firm
- To send service-related communications and updates (billing, downtime, releases)
- To improve our service and technical infrastructure
- To comply with legal obligations and to investigate misuse, fraud, or security incidents
We do not sell, rent, or trade your personal information, and we do not use lead data to train third-party AI models.
SMS & Email Communications
The Versa Group system sends SMS and email messages on behalf of the subscribing law firm to leads who have reached out to that firm. By connecting your accounts and approving your scripts, the subscribing firm confirms that recipients have a reasonable expectation of receiving a reply (for example, because they called the firm or submitted a contact form).
Outbound messages are designed to comply with the Telephone Consumer Protection Act (TCPA), the CAN-SPAM Act, and related rules. SMS recipients can opt out at any time by replying STOP. Email recipients can opt out at any time by replying to the message or contacting the firm directly.
Each subscribing firm remains responsible for its own consent practices, advertising disclosures, and compliance with applicable state bar rules.
What We Do Not Store
- Passwords or login credentials for your firm's CRM or email — we use OAuth 2.0 token-based access only
- Payment card numbers — billing is processed by our payment processor; we never see full card data
- Government identification numbers, financial account numbers, or other highly sensitive identifiers, unless explicitly placed in the lead intake script by the subscribing firm
- Medical records, diagnoses from healthcare providers, or other health data beyond the injury and treatment details the subscribing firm expressly approves for intake
Third-Party Services
To operate the service we rely on third-party providers, including:
- Twilio for SMS delivery and missed-call routing
- OpenAI for natural-language processing of intake messages
- n8n for workflow automation and orchestration of intake processing
- Supabase (PostgreSQL) for secure storage of lead and conversation records
- Google Gmail for email delivery. Google Sheets is used only when a subscribing firm expressly requests a non-sensitive reporting export; it is not the production system of record for lead conversations
- Cal.com for optional consultation booking (Growth plan)
- Netlify and other standard cloud infrastructure providers
- Optional CRM delivery selected by the subscribing firm. Webhook or Zapier connections are scoped per firm; Clio is enabled only after mapping and testing. Other systems are not represented as native integrations unless separately confirmed in writing
Each provider operates under its own privacy and security policies. We disclose only the data necessary for them to perform their function. In relation to lead data, the subscribing law firm acts as the data controller, Versa Group acts as a processor / service provider, and the providers listed above act as subprocessors.
Security
Data in transit is encrypted using industry-standard TLS. Data at rest is stored in our providers' encrypted environments. Production conversations are stored with firm-level tenant identifiers and access policies; they are not served from a public Google Sheet. Access to production systems is limited to authorized personnel.
No system is perfectly secure. Subscribing firms are responsible for keeping their own credentials, devices, and connected accounts secure.
Injury Details, HIPAA, and Business Associate Agreements
Firm-approved intake may include sensitive descriptions of injuries and treatment. Whether that information is protected health information under HIPAA depends on its source and on whether the parties are acting as a covered entity or business associate. Starter and Growth are not sold as HIPAA / BAA plans.
If a proposed workflow requires a Business Associate Agreement, the firm should not activate that workflow on Starter or Growth. The data path, subprocessors, retention, and agreement must first be scoped separately with the firm's counsel. This page does not make a blanket claim that all personal-injury intake is or is not subject to HIPAA.
Data Retention & Deletion
Lead intake records are retained for as long as the subscribing firm maintains an active subscription, or as required by applicable law, whichever is longer. Retention periods are configurable per firm.
You can request deletion of your account data at any time by emailing hello@versagroup.tech. You can revoke our access to any connected account through that account's settings — connections terminate immediately upon revocation.
Children
Versa Group is a B2B service intended for law firms and their staff. We do not knowingly collect personal information directly from children under 13.
International Users
Our service is operated for clients in the United States. If you access the service from outside the U.S., you understand that your information may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated to active subscribers by email.
Not Legal Advice
Nothing on this page constitutes legal advice. Versa Group is not a law firm and does not represent any party. Each subscribing firm is solely responsible for its compliance with applicable advertising rules, consent rules, and unauthorized-practice-of-law statutes in every jurisdiction in which it operates.
Contact
Questions or requests about this policy? Email us at hello@versagroup.tech.