TierFive considers customer privacy and confidentiality a fundamental responsibility. We do not disclose customer information unless authorized by the customer, required by valid and enforceable legal process, or otherwise permitted by applicable law. Where legally allowed, TierFive may notify the affected customer, provide a reasonable opportunity to seek protective relief, challenge or narrow overbroad requests, limit disclosure to the minimum information legally required, require secure handling, recover reasonable response costs, and require foreign requests to proceed through a legally recognized U.S. process.
Legal Process, Government Requests, and Customer Information Policy
1. Purpose and Scope
2. General Principles
- Required by valid and enforceable legal process.
- Authorized by the affected customer or another person with sufficient legal authority.
- Permitted by applicable law and reasonably necessary to address a qualifying emergency.
- Reasonably necessary to protect TierFive, its customers, users, personnel, systems, or legal rights.
- Otherwise permitted or required under applicable law or a controlling written agreement.
3. Request Information Directly From the Customer
4. Categories of Information
4.1 Customer Content
4.2 Subscriber and Account Information
4.3 Technical and Transactional Information
4.4 TierFive Business Records
4.5 Physical Records and Media
5. Requirements for Legal Process
- The full name, title, agency, organization, firm, and contact information of the requester.
- The court, tribunal, agency, jurisdiction, case caption, case number, and issuing authority.
- A complete and legible copy of the subpoena, warrant, court order, administrative demand, or other legal authority.
- The specific customer, subscriber, user, account, project, file, location, or other identifier at issue.
- The exact categories of information sought and the relevant date range.
- A clear explanation of the relationship between the requested information and the matter under investigation or litigation.
- The response deadline, return instructions, requested format, and secure delivery method.
- Any applicable sealing, nondisclosure, delayed-notice, preservation, or confidentiality order.
- The name and direct contact information of a person authorized to discuss narrowing, scheduling, costs, security, or technical issues.
6. Service and Intake of Legal Process

7. Government and Law-Enforcement Requests
- Be issued by a court or authority with jurisdiction.
- Identify the account, person, service, information type, and time period with appropriate particularity.
- Establish legal authority sufficient for the requested content or records.
- Comply with the Stored Communications Act, the California Electronic Communications Privacy Act, and other applicable privacy laws.
- Include any notice, delayed-notice, nondisclosure, sealing, or minimization requirements.
- Provide a secure and authenticated method for delivery and verification.
8. Civil Subpoenas and Private-Party Requests
- Seeks information more appropriately obtained from the customer or another party.
- Seeks customer content or communications that applicable law does not permit TierFive to disclose through the process presented.
- Is vague, overbroad, disproportionate, duplicative, cumulative, or unduly burdensome.
- Seeks privileged, confidential, proprietary, personal, regulated, or security-sensitive information.
- Requires creation of records, forensic reconstruction, expert analysis, or testimony not otherwise required by law.
- Seeks information outside TierFive’s possession, custody, or control.
- Provides insufficient time for review, customer notice, legal consultation, retrieval, or secure production.
9. Customer Notice
10. Nondisclosure and Delayed Notice
11. Preservation Requests
- Identify the requesting governmental entity or other legally authorized requester.
- Identify the account, customer, project, records, or material with reasonable specificity.
- State the legal authority for the request.
- Identify the relevant time period and categories of information.
- Provide a direct contact for authentication and follow-up.
- Be timely renewed or followed by valid legal process where required.
12. Emergency Disclosure Requests
- The requesting agency, official’s full name, title, badge or identification number, and official contact information.
- The specific person, account, customer, project, or records involved.
- A detailed description of the emergency and the imminent danger of death or serious physical injury.
- An explanation of why disclosure is necessary without delay.
- The specific information requested and its relationship to the emergency.
- A certification that the requester is authorized to make the request and that the information provided is accurate.
- The legal authority supporting the requested disclosure.
13. Foreign Government and Cross-Border Requests
- A mutual legal assistance treaty or other government-to-government process.
- Letters rogatory or a request under 28 U.S.C. § 1782.
- Legal process domesticated or issued by a court with appropriate United States jurisdiction.
- An order issued under a qualifying executive agreement recognized by applicable federal law.
- Another legally authorized cross-border procedure.
14. Physical Records, Media, and Active Projects
- Coordination with and authorization from the affected customer.
- Specific identification of containers, projects, record series, or materials.
- A protocol protecting confidentiality, evidentiary integrity, and chain of custody.
- Secure on-site inspection rather than removal from TierFive’s facility.
- Use of approved personnel, equipment, couriers, forensic vendors, or secure transportation.
- Advance payment of reasonable retrieval, staging, supervision, duplication, transportation, and restoration costs.
- Scheduling that does not unreasonably disrupt active conversion, quality-control, delivery, retention, or destruction workflows.
15. Regulated, Confidential, Privileged, and Security-Sensitive Information
- Protected health information and medical records.
- Student, education, and academic records.
- Personnel, employment, background-screening, and payroll records.
- Financial, payment, tax, insurance, and account information.
- Attorney-client communications, attorney work product, and litigation materials.
- Government-restricted, law-enforcement, criminal-justice, defense, export-controlled, or security-sensitive information.
- Trade secrets, confidential business information, proprietary methods, and customer-confidential information.
- Sealed records, records subject to protective orders, and information restricted by contract or statute.
16. Search, Collection, Review, and Production
- Limit production to information responsive to valid and enforceable process.
- Use reasonable search criteria, account identifiers, project identifiers, custodians, systems, and date ranges.
- Redact unrelated, privileged, confidential, proprietary, personal, regulated, or security-sensitive information.
- Produce information in a reasonably usable format rather than the exact format requested.
- Use secure electronic delivery, encrypted media, controlled inspection, or another protective method.
- Mark information confidential or subject to a protective order.
- Require a production protocol, confidentiality agreement, protective order, or acknowledgment of handling restrictions.
- Provide a declaration, certification, or business-records affidavit where appropriate and reasonably available.
- Use outside counsel, forensic specialists, e-discovery vendors, restoration providers, or other qualified service providers.
17. Costs and Reimbursement
- Personnel and project-management time.
- Legal review and outside counsel.
- Forensic, e-discovery, restoration, vendor, and technical services.
- Media, copying, scanning, printing, storage, encryption, and secure delivery.
- Physical retrieval, staging, supervision, transportation, and chain-of-custody services.
- Business-records certifications, declarations, testimony, depositions, and witness expenses.
- Necessary disruption of normal operations.
18. Retention, Deletion, Availability, and Technical Limitations
- That a requested customer, account, project, record, file, communication, or identifier exists.
- That requested information remains available, recoverable, complete, accurate, authentic, or readable.
- That deleted, overwritten, expired, corrupted, encrypted, or inaccessible information can be restored.
- That backups exist, are searchable, or can be restored without disproportionate cost or disruption.
- That TierFive can decrypt information protected by customer-controlled encryption, passwords, keys, or third-party systems.
- That information can be produced in a requested proprietary, legacy, native, or forensic format.
- That information held by TierFive is the complete or authoritative version of a customer’s records.
19. Customer-Authorized and Voluntary Disclosures
20. Challenges, Objections, and Protective Relief
- Validity, jurisdiction, service, and legal authority.
- Relevance, proportionality, specificity, and burden.
- Availability of the information from the customer or another source.
- Privacy, confidentiality, privilege, security, and contractual obligations.
- The interests and instructions of the affected customer.
- Cross-border conflicts of law and comity.
- Operational, technical, financial, and evidentiary consequences.
- The urgency and nature of the underlying matter.
21. Security and Delivery
22. Requests Involving TierFive as a Party
23. Changes to This Policy
24. Contact
