Professional Privacy FAQ
Who controls which data on Orchard72, what stays privileged, how long records are kept, and where your duty of confidence sits.
Controller relationships
Are you a processor or a joint controller?
Joint controller under GDPR Art. 26 for the matters you bring onto the platform. We co-determine purposes for the platform-managed parts of the workflow: audit logging, retention floors and security controls. You remain the controller for client-instructed processing (advice, drafting decisions, what to tell the client).
The Data Processing Agreement spells out who is responsible for what, the data subject contact points, and the rights cascade. It is published on the site, so you can read it before you onboard.
Why joint controller and not processor?
The platform sets retention floors (audit logs you cannot delete before the statutory minimum), security controls, and audit-trail mechanics that you cannot instruct away. Those are decisions we co-determine with you. For everything client-instructed, you remain in charge. Joint-controller is the honest description of that split.
Can I get a DPA?
Yes. Our Data Processing Agreement covers UK GDPR Article 28 obligations, joint-controller terms (Art. 26), sub-processor flow-through, and Standard Contractual Clauses for any cross-border transfers. Read it at Data Processing Agreement.
Professional privilege and client confidentiality
Does the platform see legally privileged communications?
The platform stores and routes communications you create on it; the underlying files are encrypted at rest and in transit. Operationally, our staff cannot read client matters at will. Access is role-scoped and audited. Privileged material is treated under the same controls as all matter content; we do not separately analyse or scan privileged communications.
Can my clients see who at Orchard72 accessed their matter?
On request, we will provide an access record. Routine staff support access is logged with reason, role, and timestamp. We do not share staff identities by default, because individual support staff names are an operational-security risk, but we will identify the role and the action taken.
What about cross-matter visibility?
Every client matter is a separate scope. One client's files never appear in another's view. Conflicts checking is the one place we look across your own client base, and it runs as its own recorded check with its own consent record rather than opening up general access between matters.
Retention and exit
How long is matter data kept?
Legal documents (signed wills, executed engagement letters, advice notes attached to a matter) are retained for the period you declare under "How long do you retain client files?" on your profile (the same value your engagement letters merge in), and longer where you choose. That period is yours to set from your own regulator's minimum, which varies by body and by jurisdiction, so the platform does not assume a figure for you; the Data Processing Agreement sets out how the floor is applied. Audit records follow the same floor. You can extend retention; you cannot drop below the floor while a matter is active.
What happens if I leave the platform?
- You export client matter records, will drafts, audit trails in standard formats
- We retain audit logs and matter metadata for the regulatory minimum
- Personal data we no longer need a lawful basis to keep is deleted
- Client-facing access is preserved during the wind-down window agreed in the DPA
What happens to a declined enquiry?
Until you accept an approach, you see only a prospective client's first name, last initial, and high-level demographics, not their full identity or contact details. If you decline an approach, or the client withdraws it, before any engagement begins, that shared snapshot is hidden from your view immediately and permanently removed within 90 days. Only a minimal audit record (the fact that the enquiry was declined, and the reason) is kept. Accepted approaches form a matter and follow the regulatory retention floor above.
Can clients request their data?
Yes. Data subject access requests (DSARs) are routed via you as the controller for client-instructed processing, with our support for retrieving the platform-stored records. The DPA sets out the response-time commitments and the contact points.
Sub-processors and confidentiality
Who do you share matter data with?
A short, named list of sub-processors, published openly at Sub-processors. Each is bound by written confidentiality and data-protection contracts that flow through to your client under the DPA.
Do third-party AI providers see client documents?
By default, identity documents and financial statements never leave our infrastructure for any third-party AI provider. They are processed on our own servers first; an external provider is used only if you (or your client) are not satisfied with that result and give explicit, per-document consent to enhanced external processing. It never happens silently or without approval. AI-assisted drafting (will text, matter notes) may likewise use a third-party AI provider when you opt in; those inputs are subject to no-training contract terms, and the provider keeps them only for the abuse-monitoring period its own terms set. The choice is per-document.
Procurement-ready paperwork
Can’t find what you’re looking for?
Our support team is here to help. Contact us and we’ll get back to you as soon as possible.
Contact Support
