VBMS Reviewer Privacy Policy
Effective date: September 4, 2026
Last updated: September 4, 2026
Service provider: Dmytro Usenko
Trading name: VBMS Reviewer
This Privacy Policy explains how VBMS Reviewer collects, uses, discloses, and protects personal information in connection with vbmsreviewer.com, reports.vbmsreviewer.com, the VBMS Reviewer professional workspace, the C-File Review Pack, related applications, communications, and support services (collectively, the "Services").
This Policy applies to professional users, purchasers, website visitors, customer personnel, and individuals whose information is contained in records submitted by a customer.
1. Our Role and Customer Responsibilities
VBMS Reviewer provides document-review and workflow-support services to attorneys, accredited claims agents, law firms, and professional case teams.
When a professional customer submits a veteran's, survivor's, claimant's, or other person's records, that customer determines why the records are submitted and how the resulting reports will be used. In that context, the customer is generally the business, controller, or responsible organization for the submitted data, and VBMS Reviewer processes the data on the customer's behalf to provide the Services.
Customers are responsible for providing all notices and obtaining all rights, consents, and authorizations required to submit records and personal information to VBMS Reviewer. If a separate data-processing agreement, confidentiality agreement, or customer agreement applies, it also governs our processing according to its terms.
If your information appears in records submitted by a law firm or other professional customer, requests concerning those records should normally be directed first to that customer. We will assist the customer as required by applicable law and our agreement with the customer.
2. Information We Collect
A. Contact, account, and business information
We may collect:
- name;
- professional title;
- firm or organization;
- email address;
- telephone number;
- account identifiers and authentication information;
- internal matter references supplied by a customer; and
- communications, support requests, survey responses, and other information you provide to us.
B. Transaction and order information
For purchases, we may collect:
- product purchased;
- order number;
- amount, currency, tax, payment status, refund status, and transaction identifiers;
- purchaser name, email address, billing country, and limited billing details received from our payment processor;
- business location information and geographic-eligibility confirmations for products limited to U.S. professional customers;
- the version of terms accepted, acceptance time, and related transaction evidence; and
- fulfillment, submission, processing, delivery, and support history.
Payment-card information is processed by Stripe or another disclosed payment processor. VBMS Reviewer does not receive or store complete payment-card numbers or card security codes.
C. Customer Record Data
Customers may submit information needed for a professional case review, including:
- C-files, eFolders, PDFs, and other case documents;
- veteran, survivor, claimant, dependent, witness, provider, and other individual names;
- limited identifying information, such as the last four digits of a VA file number;
- age, work status, service information, claim and appeal history;
- medical records, diagnoses, symptoms, treatment history, examination records, disability information, and other health-related information;
- service treatment records, personnel records, rating decisions, correspondence, forms, statements, and procedural records; and
- any other personal or sensitive information included in submitted documents.
Customer Record Data may contain highly sensitive information. Customers should submit only information they are authorized to provide and that is reasonably necessary for the requested service.
D. Generated Service Data
We create information when providing the Services, which may include:
- extracted text and document metadata;
- structured timelines and evidence maps;
- citations and page references;
- Evidence Reviews, Attorney Briefs or Strategic Reviews, Signals, and Case Boards;
- processing status, validation results, and quality-control information; and
- access, delivery, and audit records.
E. Website, device, and usage information
We may automatically collect:
- IP address;
- browser type, device type, operating system, and language;
- pages viewed, referring page, timestamps, and interaction data;
- cookie and similar-technology identifiers;
- authentication, security, diagnostic, and error logs; and
- approximate location derived from IP address.
We do not intentionally place veteran names, medical information, or the contents of submitted records into advertising analytics.
3. How We Collect Information
We collect information:
- directly from professional users, purchasers, and website visitors;
- from law firms, accredited representatives, and other customers that submit records;
- automatically through the Services and related security technologies;
- from payment, hosting, communications, authentication, analytics, and support providers; and
- from integrations authorized by a customer.
4. How We Use Information
We use personal information to:
- provide, operate, and fulfill the Services;
- create accounts and authenticate professional users;
- process purchases and confirm payments;
- verify eligibility for products offered only to professional or business customers located and billed in the United States;
- receive, validate, store, and process submitted records;
- generate, review, deliver, and support reports;
- provide customer service and communicate about orders or accounts;
- maintain security, prevent fraud and misuse, and investigate incidents;
- troubleshoot, monitor reliability, and improve service performance;
- maintain transaction, consent, delivery, and audit records;
- comply with legal, tax, accounting, regulatory, and contractual obligations;
- enforce our terms and protect our rights and the rights of customers or others; and
- complete a corporate transaction, subject to appropriate safeguards.
We do not sell Customer Record Data. We do not use Customer Record Data for targeted advertising.
5. AI-Assisted Processing
VBMS Reviewer uses automated and AI-assisted technologies to process documents, extract and organize information, identify possible review signals, and generate structured reports.
These systems support professional review. They do not make government decisions, legal decisions, medical decisions, or final case decisions. Outputs may contain errors or omissions and require verification by the customer's qualified professional personnel against the source records.
Customer Record Data may be transmitted to carefully selected cloud, document-processing, and AI service providers solely as needed to provide the Services, subject to contractual, technical, and organizational safeguards appropriate to the service relationship.
6. Legal Bases for Processing
Where the laws of the European Economic Area, United Kingdom, Switzerland, or another jurisdiction require a legal basis, we process personal information as applicable:
- to perform a contract or take steps requested before entering a contract;
- for our legitimate interests in providing, securing, supporting, and improving the Services, where those interests are not overridden by applicable rights;
- to comply with legal obligations;
- with consent, where consent is required; and
- to establish, exercise, or defend legal claims.
For Customer Record Data processed on behalf of a professional customer, the customer is responsible for identifying its lawful basis and instructions for processing.
7. How We Disclose Information
We may disclose personal information to:
A. Service providers and subprocessors
These may include providers of:
- cloud hosting, storage, networking, backup, and content delivery;
- document conversion, text extraction, search, and AI/model processing;
- payment processing, fraud prevention, invoicing, and tax calculation;
- authentication, email, customer support, monitoring, logging, and security; and
- professional services such as legal, accounting, insurance, and compliance support.
Service providers may use information only to perform services for us or as otherwise permitted by contract and law.
B. Customer-authorized recipients
We disclose reports and order information to the delivery addresses, workspace users, integrations, and other recipients authorized by the customer.
C. Legal and safety disclosures
We may disclose information when we reasonably believe disclosure is required by law, legal process, court order, or government request, or is necessary to protect rights, safety, security, prevent fraud, or investigate misuse.
D. Corporate transactions
Information may be disclosed in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate confidentiality and legal safeguards.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws.
8. Payment Processing
Purchases are processed by Stripe or another disclosed payment provider. The payment provider independently processes payment credentials and related transaction information under its own privacy policy.
We provide the payment processor only the information reasonably needed to create and reconcile a transaction. Veteran names, VA file numbers, medical information, source documents, and report contents should not be sent to Stripe as checkout metadata or custom fields.
9. Cookies and Similar Technologies
We may use:
- strictly necessary cookies for authentication, security, checkout state, and service operation;
- preference cookies that remember user choices; and
- limited analytics technologies that help us understand website and service performance.
Where required, we request consent before using non-essential cookies. You can manage available choices through our consent tool and browser settings. Blocking necessary cookies may prevent parts of the Services from working.
We do not use the contents of Customer Record Data for interest-based advertising.
10. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, security, support, dispute resolution, tax, accounting, legal compliance, and enforcement.
For one-time C-File Review Pack orders:
- private report links expire 30 days after delivery;
- submitted source files and generated reports are retained only as long as reasonably necessary to provide the service, maintain security, resolve support or delivery issues, and meet legal obligations; and
- order, payment, consent, tax, delivery, and dispute records may be retained for the periods reasonably necessary to meet legal, accounting, tax, security, and dispute-resolution obligations.
Professional workspace data is retained according to the applicable customer agreement, account settings, and documented deletion process.
Backup copies may remain for a limited period until overwritten through normal backup cycles. We may retain information longer when required by law, needed to establish or defend legal claims, necessary to investigate misuse or security incidents, or requested by a customer under a valid preservation obligation.
11. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. Depending on the service and data involved, these safeguards may include:
- private AWS infrastructure;
- encryption in transit and at rest;
- access controls and least-privilege permissions;
- authentication and authorization controls;
- logging, monitoring, backup, and incident-response procedures; and
- contractual safeguards with service providers.
No storage or transmission system is completely secure. Customers are responsible for protecting their credentials, private report links, downloaded reports, and devices, and for notifying us promptly of suspected unauthorized access.
12. International Data Transfers
VBMS Reviewer and its service providers may process information in the United States and other countries where they operate. These countries may have data-protection laws different from those in your location.
Where required, we use appropriate transfer mechanisms and safeguards, which may include contractual protections, adequacy decisions, or other legally recognized methods.
13. Privacy Rights and Choices
Depending on where you live and the context in which we process your information, you may have rights to:
- request access to personal information;
- request correction of inaccurate information;
- request deletion;
- receive a portable copy of certain information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- opt out of certain sales, sharing, or targeted advertising; and
- appeal a decision concerning a privacy request where applicable.
To submit a request, contact contact@vbmsreviewer.com. We may need to verify your identity and authority before acting. Authorized agents may submit requests where permitted by law, subject to verification.
If your information is contained in records submitted by one of our professional customers, identify that customer in your request when possible. We may refer the request to the customer or act on its documented instructions.
We will not discriminate against you for exercising applicable privacy rights.
Residents of the EEA, United Kingdom, or Switzerland may also lodge a complaint with their local data-protection authority. We encourage you to contact us first so we can address your concern.
14. U.S. State Privacy Disclosures
Applicable U.S. state laws may require disclosure of categories of personal information collected, purposes of use, and categories of recipients. The categories described in Sections 2, 4, and 7 provide this information.
During the preceding 12 months, we may have collected the following categories, depending on use of the Services:
- identifiers and contact information;
- customer records and transaction information;
- commercial information;
- internet or other electronic network activity;
- professional or employment-related information;
- sensitive personal information contained in Customer Record Data; and
- inferences and generated service information created during document processing.
We collect and disclose these categories for the business purposes described in this Policy. We do not sell these categories for money and do not share them for cross-context behavioral advertising.
We use sensitive personal information only as reasonably necessary to provide, secure, and support the Services, comply with law, and protect against fraud or misuse. We do not use sensitive Customer Record Data to infer characteristics for advertising.
15. Children's Privacy
The Services are intended for professional business users and are not directed to children under 18. We do not knowingly collect information directly from children through account registration or purchasing flows.
Submitted case records may contain information about dependents or minors. Such information is processed only on behalf of the professional customer as part of the submitted record and subject to the customer's authority and instructions.
16. Third-Party Sites and Services
The Services may link to third-party websites, payment pages, integrations, or services. Their privacy practices are governed by their own policies. We are not responsible for third-party practices outside our control.
17. Changes to This Privacy Policy
We may update this Policy to reflect changes in the Services, technology, law, or our practices. We will post the updated version and revise the effective date. If a change is material, we will provide additional notice where required by law or contract.
18. Contact Us
For privacy questions or requests, contact:
Service provider: Dmytro Usenko
Trading name: VBMS Reviewer
contact@vbmsreviewer.com
https://vbmsreviewer.com/
For Customer Record Data submitted by a law firm or other professional customer, you may also contact that customer directly.