dailybuilt
  • Platform
  • Pricing
  • Writing
  • Get early access
Get early access
Legal

Legal Process & Government Requests

Almost all of the data on our systems belongs to a customer and is held on that customer's instructions. A requester who wants a customer's records should ask that customer. This page states what we require when the request comes to us.

Effective July 28, 2026

DailyBuilt, Inc. ("DailyBuilt") provides business software to companies ("Customers"). Almost all of the data on our systems belongs to a Customer and is held by us on that Customer's instructions. A requester who wants a Customer's records should ask that Customer. DailyBuilt will produce Customer data to a government or civil requester only where valid legal process compels it, or where the Customer instructs us to.

This policy explains what we require, what we tell our Customers, and how we handle protected health information. It is a statement of our practices, not a contract; it creates no rights in any third party, does not waive any right or objection available to DailyBuilt or its Customers, and may change. Prior versions of this document are archived by date and are available on request to hello@dailybuilt.co.


1. Service of process

1.1 Where to serve. Legal process directed to DailyBuilt must be served on our registered agent:

DailyBuilt, Inc. c/o Corporation Service Company 251 Little Falls Drive Wilmington, DE 19808

1.2 Courtesy copy. Please email a copy to hello@dailybuilt.co with the case caption in the subject line. This speeds our review and helps us meet a return date. A courtesy copy is not service. We do not accept service by email, fax, voicemail, in-product message, or social media, and sending a courtesy copy does not waive any objection to service, sufficiency of process, personal jurisdiction, or venue.

1.3 Name the right entity. Process must name DailyBuilt, Inc., a Delaware corporation. Process naming only a Customer's business name, a booking or invoice page hosted for a Customer, or a trading style is not process on DailyBuilt, and we will treat it as misdirected.

1.4 What every request must contain. The issuing authority and case or matter number; the requester's name, agency or firm, badge or bar number, and official email and phone; the statutory or procedural authority relied on; a specific account identifier (account email address, workspace name or subdomain slug, or the URL of the hosted page); the specific records sought; and a date range. We reject requests that identify no account, seek "all records," or seek records of unidentified persons, and we may move to quash or seek to narrow process we believe is overbroad, unduly burdensome, or unlawful.

1.5 Response time. We do not guarantee production by a return date that is unreasonably short. Contact us before serving if timing is tight. We do not operate a law-enforcement portal and do not take requests by phone.

2. What legal process is required, by data category

DailyBuilt provides an electronic communication service and a remote computing service within the meaning of 18 U.S.C. §§ 2510(15) and 2711(2) with respect to the messages and stored content processed through the Service. We apply the Stored Communications Act, 18 U.S.C. § 2701 et seq. ("SCA"), to every request we receive, including civil subpoenas, and we apply the standards below to all requests for stored data.

2.1 Basic subscriber and account records — subpoena or higher. Account holder name; account email address; workspace name, subdomain slug, and business address as entered by the Customer; account and workspace creation dates; plan tier and subscription status; last-seen timestamps; and the IP address and user-agent string recorded in our audit log for a logged in-product action, where we have one for the identified account and period.

We do not hold some things requesters commonly ask for. We do not store account passwords or authentication credentials — sign-in is operated by our identity provider. We do not store payment card numbers or bank account numbers — payments run through our payment processor, and we retain only processor identifiers, amounts, status, and receipt links. Requests for those must go to the relevant provider, which we will identify.

2.2 Non-content transactional records — court order or higher. Records beyond §2.1 that are not content — message routing and delivery logs (sender, destination, channel, timestamps, delivery status, carrier error codes), booking and appointment event timestamps, document and signature event logs including a signer's IP address and user agent, and connection or integration event records — require a court order under 18 U.S.C. § 2703(d) or a warrant.

2.3 Content — warrant. Content requires a search warrant issued on probable cause under Federal Rule of Criminal Procedure 41 or an equivalent state warrant, or another mechanism the SCA expressly authorizes. Content includes: documents, contracts, templates, and their versions; clinical and contact notes; uploaded files and attachments; the body and subject of email and SMS messages sent or received through the Service; intake form and questionnaire answers; and anything else a Customer, its staff, or an End User authored and stored in the Service. A subpoena is not sufficient for content, and we will not produce content in response to one.

2.4 Customer consent. With the documented instruction of the Customer that controls the data, we may disclose that Customer's records, including content, without compelled process. 18 U.S.C. § 2702(b)(3). This is usually the fastest path and we will point requesters to it.

2.5 Civil subpoenas. We do not produce content in response to a civil subpoena. 18 U.S.C. § 2702(a). Direct the request to the Customer that controls the data, or obtain that Customer's documented consent under 18 U.S.C. § 2702(b)(3).

3. Protected health information

3.1 Our role. Where a Customer operates in Healthcare Edition, that Customer is a Covered Entity and DailyBuilt is its Business Associate under a Platform Business Associate Agreement ("BAA"). We disclose protected health information ("PHI") in response to legal process only as HIPAA permits and the BAA allows, and only the minimum necessary. 45 C.F.R. §§ 164.502(b), 164.504(e). Our default is to redirect the requester to the Covered Entity, which holds the record and the primary obligation.

3.2 Judicial and administrative proceedings — 45 C.F.R. § 164.512(e). We may disclose PHI in a judicial or administrative proceeding in response to (a) an order of a court or administrative tribunal, limited to the PHI expressly authorized by the order; or (b) a subpoena, discovery request, or other lawful process not accompanied by a court order, only where the requester documents either (i) satisfactory assurances that reasonable efforts were made to give the individual written notice with sufficient information to raise an objection, and the time to object has elapsed with no objection filed or all objections resolved by the tribunal, or (ii) reasonable efforts to secure a qualified protective order that prohibits use or disclosure of the PHI outside the proceeding and requires its return or destruction at the end. We require the written documentation described in § 164.512(e)(1)(iv). A requester's bare assertion that notice was given is not satisfactory assurance.

3.3 Law-enforcement purposes — 45 C.F.R. § 164.512(f). We may disclose PHI for a law-enforcement purpose only as § 164.512(f) permits, including in response to a court order, court-ordered warrant, subpoena or summons issued by a judicial officer, or grand jury subpoena; in response to an administrative request that meets each condition of § 164.512(f)(1)(ii)(C); for the limited identification and location purposes of § 164.512(f)(2) and only the data elements that paragraph lists; and in the victim, decedent, and crime-on-premises situations of § 164.512(f)(3)–(5). We do not treat § 164.512(f) as a general-purpose channel for content.

3.4 Notice to the healthcare Customer. We notify the affected Covered Entity of legal process seeking its PHI consistent with the BAA and §4 below, and we provide the information that Customer needs for its accounting of disclosures under 45 C.F.R. § 164.528.

4. Notice to the affected Customer

4.1 We tell the business first. Before disclosing data in response to legal process, DailyBuilt notifies the affected Customer at the account email address on file, provides a copy of the process, and allows a reasonable opportunity to seek protective relief. Where the process can lawfully be directed to the Customer instead, we say so to the requester.

4.2 Exceptions. We withhold notice where we are legally prohibited from giving it — including under a nondisclosure order issued under 18 U.S.C. § 2705(b) or a comparable sealing order — or where the request is an emergency under §5, or where we have a good-faith belief that notice would result in danger to an identifiable person, destruction of evidence, or obstruction of an investigation.

4.3 Notice after a prohibition lapses. When a nondisclosure order expires, is lifted, or is narrowed, we notify the affected Customer then, unless a separate prohibition still applies. We do not agree to indefinite nondisclosure and will ask that any gag be limited to a defined term.

5. Emergency requests

5.1 Standard. DailyBuilt may voluntarily disclose information to a governmental entity where we determine in good faith that an emergency involving danger of death or serious physical injury to any person requires disclosure without delay. 18 U.S.C. § 2702(b)(8), (c)(4). This is a permission, not an obligation, and the determination is ours.

5.2 How to submit. Email hello@dailybuilt.co with "EMERGENCY DISCLOSURE REQUEST" in the subject line, on agency letterhead, stating: the nature of the emergency; the specific danger of death or serious physical injury; the identity of the person at risk, if known; the account identifier and the exact information needed; and why that information is needed without delay. A follow-up phone number for verification is required.

5.3 Scope and follow-up. We disclose only the information we believe in good faith relates to the emergency. We document each emergency request and each disclosure under §9, and we may notify the affected Customer after the emergency has passed. We may decline a request that does not describe a qualifying emergency, and we may ask for compulsory process instead.

6. Preservation requests

6.1 What we do. On a written request from a governmental entity under 18 U.S.C. § 2703(f), DailyBuilt takes reasonable steps to preserve the records and other evidence in its possession that are described in the request, for 90 days, and for one additional 90-day period on a timely renewal request. We do not extend beyond one renewal absent legal process or a court order.

6.2 Requirements and limits. A preservation request must identify the account and a date range, and must be signed by the requesting official. Preservation is not disclosure: we hold a snapshot and produce nothing until valid process under §2 arrives. Preservation is limited to data that exists when the request is received; we do not begin collecting new data because of a preservation request, and it does not stop a Customer from deleting records in its own account. We do not accept § 2703(f) requests from private parties; civil litigation holds are handled separately through the Customer.

7. Cost reimbursement

Where the law permits, DailyBuilt seeks reimbursement for the costs of searching for, assembling, reproducing, and producing records, including reasonable attorney time spent responding. 18 U.S.C. § 2706; Fed. R. Civ. P. 45(d)(2)(B)(ii) for non-party civil subpoenas, and state analogues. We provide a written estimate before performing costly work. We do not seek reimbursement for emergency requests under §5, for preservation under §6, or where reimbursement is prohibited by law. A business-records certification under Fed. R. Evid. 902(11) is available with a production on request; DailyBuilt does not provide expert or opinion testimony.

8. What we will not do

We do not provide informal access, "courtesy lookups," bulk or standing access, real-time interception or wiretap capability, or continuous monitoring of any account. We do not build or maintain a government access channel into the Service. We do not disclose in response to process we believe is invalid, unlawful, or served on the wrong entity, and we will move to quash where appropriate.

9. Recordkeeping

DailyBuilt maintains a record of every legal or governmental request received and every disclosure made: the date received, the requesting authority and contact, the instrument relied on, the accounts and data categories implicated, whether Customer notice was given or withheld and the legal basis for withholding it, and exactly what was produced and when. Records relating to PHI are retained for at least six years, consistent with 45 C.F.R. § 164.530(j)(2), and support a Covered Entity's accounting of disclosures under 45 C.F.R. § 164.528.

10. International requests

DailyBuilt is a United States corporation and stores Customer data in the United States. A law-enforcement authority outside the United States must proceed through a mutual legal assistance treaty, letters rogatory, or another mechanism recognized under United States law — including an executive agreement under 18 U.S.C. § 2523 where one applies to the requesting government — and must produce valid United States legal process. We do not respond directly to legal process issued by a foreign court or agency, and responding to a request routed through U.S. process does not submit DailyBuilt to the jurisdiction of any foreign forum.


Questions about this policy (not service of process): hello@dailybuilt.co.

Related documents: Terms of Service · Privacy Policy · Data Processing Addendum · Security · Consumer Privacy Notice.

dailybuilt

The thinking layer for your whole business. Customers, bookings, payments, messaging, and your website in one login, one bill. In early access from Miami.

Platform
FeaturesHow it worksPricing
Company
Why we’re building itWritingFAQ
Contact
Get early accesshello@dailybuilt.coLinkedIn
Legal
TermsPrivacyEnd-User TermsConsumer Privacy NoticeDPAAcceptable UseSMS TermsBilling & RefundsCopyright & DMCASecurityAccessibilityCookiesLegal ProcessMeta Data DeletionSubprocessors
Consumer Health Data Privacy
dailybuilt
© 2026 DailyBuilt, Inc. All rights reserved.