SLDocs Consumer Health Data Privacy Policy
Effective Date: July 1, 2026
1. Why This Policy Exists
Fiji Systems LLC, dba SLDocs ("SLDocs," "we") provides an encrypted vault for estate-planning and end-of-life documents. Some documents people store — most obviously a healthcare directive or a healthcare power of attorney — are or may contain "consumer health data" under state law, including the Washington My Health My Data Act ("MHMDA") and similar state laws. SLDocs does not scan, read, or classify the contents of your documents, so we treat your vault as possibly containing consumer health data and apply this Policy's protections to it. This Policy supplements our Privacy Policy and applies to all users; certain rights below are guaranteed by statute to residents of specific states.
2. Consumer Health Data We May Collect
- Health-related documents you choose to store, such as healthcare directives, healthcare powers of attorney, living wills, or other documents that may reference physical or mental health conditions, diagnoses, treatments, medications, or healthcare providers. These are encrypted per-document; SLDocs does not read or classify them.
- Document-type labels you assign (for example, selecting "Healthcare Directive" as a document type) and document filenames you choose.
- Secure vault entries (notes) you create, which may contain healthcare-provider names, the location of a healthcare directive, patient-portal logins, or free-text health notes. These are field-encrypted and covered by the same consumer-health consent.
- Medical break-glass configuration: your designation of a medical proxy and which documents you place in your Emergency Medical Set.
- Access events: audit-log records of when health-designated documents are accessed, including emergency access by your medical proxy.
- Email you send us: if you write to our support, legal, or security inboxes, your message may describe health or estate circumstances. Unlike the documents in your vault — which are encrypted — email you send us is handled by a third-party mailbox provider, is stored unencrypted, and may reside on servers outside the United States. This is the least-protected way to send us information, so please do not email health documents or sensitive health details; use the in-product flows, which keep your information encrypted and U.S.-key-controlled, instead.
We do not collect biometric data, precise geolocation, or health data from third-party sources, and we do not infer health information about you.
3. Sources
You (your uploads, labels, and configurations); your designated medical proxy (when they trigger emergency access); and, for firm-channel accounts, your law firm — but only with your separate recorded consent — for documents the firm places in your vault, whether the firm uploads an existing file or generates a document (for example, through a guided document-preparation flow) and saves it to your vault.
4. Why We Collect It (Purposes)
Solely to provide the services you request: encrypted storage; retrieval by you; the recipient, medical-proxy, and executor access flows you configure; security; fraud prevention; and legal compliance. No advertising. No marketing based on health data. No profiling.
5. Sharing of Consumer Health Data
We do not sell consumer health data and will not sell it without the separate, signed authorization state law requires (we have no plans to seek one). We do not share it for advertising. Consumer health data is disclosed only:
- To service providers/processors that operate our infrastructure, listed with what each can see at /subprocessors. Each is bound by a written data-processing agreement that restricts its use of your data to providing services to us and prohibits using it for its own purposes. Only three can ever encounter unencrypted document content, and only transiently: our hosting provider (in-memory during authorized decryption), our malware-scanning provider (during upload scanning), and our SMS/fax provider (when you order fax delivery). Our backup, object-storage, and key-management providers hold only encrypted data.
- To people you authorize: your designated recipients, your medical proxy (Emergency Medical Set only, 72-hour auto-expiring, dual-channel verified), and a verified executor under our published process.
- As required by law, with valid legal process.
We have no affiliates: Fiji Systems LLC has no affiliated entities, and we therefore share no consumer health data with any affiliate.
6. Your Consent
How we obtain your consent depends on how your vault was created:
- Direct (consumer) accounts: before your first document upload, we ask for your affirmative, opt-in consent to collect and process consumer health data, separate from your acceptance of the Terms of Service. The consent describes the categories collected, the purposes, and your right to withdraw; it is versioned and recorded.
- Firm-channel accounts: your law firm cannot place any document in your vault until you personally confirm a recorded authorization inside the product. That single authorization both permits the firm to upload and serves as your consumer-health-data consent. The exact authorization you confirm reads:
Authorizing [Firm Name] to manage documents in your vault
Your SLDocs vault is provided through [Firm Name]. With your permission, [Firm Name] will upload and manage documents in your vault as part of representing you — for example, your will, trust, powers of attorney, and healthcare directives.
Some of these documents may contain consumer health data — information about your physical or mental health, healthcare providers, or treatment (for example, a healthcare directive or healthcare power of attorney). By authorizing [Firm Name] below, you also consent to SLDocs collecting and storing that consumer health data for one purpose only: to provide the secure vault service — storing your documents encrypted and releasing them only to the people and under the conditions you or your authorized fiduciaries configure.
SLDocs does not sell your health data, does not use it for advertising or profiling, and does not read or analyze your documents' contents. SLDocs shares it only with the service providers that operate the vault (each under a contract restricting use to providing the service) and with the people you authorize.
You can withdraw this consent at any time from your account settings or by contacting [Firm Name]. Withdrawal stops further uploads going forward; it does not delete documents already stored. You can delete documents you uploaded yourself; documents [Firm Name] uploaded are removed by [Firm Name]. Withdrawing does not affect [Firm Name]'s separate professional obligations to you. Using the SLDocs vault is not a condition of [Firm Name]'s representation of you.
Checkbox: I authorize [Firm Name] to upload and manage documents in my SLDocs vault, and I consent to SLDocs collecting and storing the consumer health data those documents may contain, for the purpose of providing the vault service. I understand I can withdraw this consent at any time.
In both channels, we do not collect consumer health data beyond what is necessary to provide the services you request, and we will obtain new consent before any new category or purpose.
The consent covers both the documents you upload and the secure vault entries you create, including any consumer health data they may contain, for the purpose of providing the vault service. Consent is recorded with its version, timestamp, and the IP address from which it was given; if we materially change the consent language, your prior consent no longer satisfies the gate and we ask you to affirm the current version before further collection.
7. Your Rights
You may, at any time:
- Access your consumer health data, including a list of third parties and affiliates with whom it has been shared and how to contact them. A self-serve export from your account settings provides your profile, recipients, vault entries, document metadata, billing, and recent account-activity records; the encrypted document files themselves are downloaded individually or in bulk from your vault rather than included in that data export;
- Withdraw consent to collection and sharing;
- Delete your consumer health data, including data we have shared with our service providers (we will instruct them to delete it);
- Appeal a refusal.
Submit requests at /privacy/appeal or legal@sldocs.com. We honor requests within 45 days (extendable once by an additional 45 days for complex requests, with notice to you), verify you against your account, and will not discriminate against you for exercising rights. If we deny your appeal, you may file a complaint with your state Attorney General. Consumer-health-data complaints can be directed to: Washington (My Health My Data Act) — Washington State Attorney General; Nevada (SB 370) — Nevada Attorney General; Connecticut — Connecticut Attorney General. Residents of other states may file a complaint with their own state Attorney General; a national directory is available through the National Association of Attorneys General "Find My AG" directory. You may also report a concern to the Federal Trade Commission at reportfraud.ftc.gov.
How to withdraw: you can withdraw this consent at any time from your account settings — no email or support contact required. Withdrawal takes effect immediately and is forward-looking: it blocks all further uploads until you consent again, but does not delete documents already stored. If we update the consent language, your prior consent no longer satisfies the gate and we will ask you to re-affirm at the current version before your next upload.
If your vault is provided through a law firm: you can withdraw the firm's upload authorization at any time, yourself, from your account settings — you do not need to contact the firm. Withdrawal is immediate and forward-looking: the firm can no longer add documents to your vault, but documents already stored remain. While the firm manages your vault, you can delete documents you uploaded yourself; documents the firm uploaded are removed by the firm. If your relationship with the firm ends and your vault transitions to your sole control, those documents become yours and you can delete them. Withdrawing does not affect your law firm's separate professional obligations to you.
Effect of withdrawal and deletion: withdrawing consent stops further collection; to remove already-stored documents you may delete individual documents you uploaded, or delete your account. (If your vault is firm-managed, see the firm-channel note above: you can delete documents you uploaded yourself, while firm-uploaded documents are removed by the firm during the relationship and become deletable by you after offboarding.) Deleted data is removed from our live systems immediately. Because backups are encrypted point-in-time snapshots, deleted data also remains in older backups until those backups are revised. We purge deleted consumer health data from backups within the period the law allows for backup deletion (under the Washington My Health My Data Act, up to six months): we run a scheduled backup-deletion process at least every five months that clears all deletion requests received since the last revision, so no deletion request waits longer than the law's window. If we restore from a backup in the interim, we re-apply every deletion made after that backup was taken, so restored data does not resurrect a completed deletion.
What a deletion removes — please read this carefully. Because we do not review, open, or classify what you store (a family vault, for example, may hold arbitrary documents and notes), we cannot reliably separate "health data" from everything else inside your vault. So if you ask us to delete your consumer health data, we delete all of your documents and stored data — we do not attempt to surgically remove only health-related items, because doing so accurately is not possible without reading your content, which we will not do. After the deletion is complete, you are free to re-upload whatever documents or data you wish. Each full deletion is recorded in our audit log.
What we retain after deletion (and why). A small set of records is kept even after a deletion, because the law either requires their retention or recognizes a legitimate basis for it: (i) a record of the consents you gave and withdrew — retained in anonymized form within our audit log, so we can show we honored your choices, without keeping the deleted account's identifying details; (ii) financial and transaction records — billing and payment history, kept for tax, accounting, and audit obligations (this category is not consumer health data, though it remains subject to other deletion rights where they apply); (iii) the deletion audit record itself — proof that and when the deletion occurred; (iv) fraud-prevention and security records tied to account-recovery or executor-access adjudications, kept for the defense of legal claims; and (v) information we are required to retain by a legal hold, subpoena, or other legal obligation (handled case-by-case if and when such an obligation arises). These retained records do not include the contents of your deleted documents.
Deletion also disables features that depend on the deleted documents (for example, the Emergency Medical Set).
8. No Geofencing
SLDocs does not use geofencing of any kind, and will never use a geofence around any healthcare facility to identify, track, or message consumers or to serve advertising.
9. Firm-Channel Accounts
If a law firm sponsors your vault: the firm cannot upload documents (health-related or otherwise) to your vault without your separate recorded consent, which you may revoke at any time; firm-uploaded documents are labeled with their origin; and your rights under this Policy run against SLDocs directly regardless of firm branding. During the firm relationship you can delete documents you uploaded yourself, while documents the firm uploaded are removed by the firm; if the relationship ends and your vault transitions to your sole control, those documents become yours and you can delete them. Your law firm has independent confidentiality and consent obligations to you as your counsel.
10. Changes; Contact
We will notify you of material changes and obtain fresh consent where the law requires. Contact: legal@sldocs.com; Fiji Systems LLC dba SLDocs, 7160 Preston Road, Ste 100, Plano, TX 75024 (Collin County).
Please don't email sensitive personal or health information or documents — email isn't encrypted and may be stored outside the U.S. Use your in-product vault instead.