Partner CRM Data-Sharing Agreement
Version 2026-09-28. Last updated: 28 September 2026
About this document: This agreement applies when a legal professional who offers our service under its own brand (the "Partner") connects its own customer relationship management system (the "CRM") so that Orchard72 ("we", "us") can send it limited details about people who come to us through the Partner's page. The Partner accepts it in its white-label settings before any CRM can be connected. It supplements, and does not replace, our Terms of Service and Privacy Policy.
1. Roles of the parties
This is a sharing arrangement between two independent controllers, made with regard to the Information Commissioner's data sharing code of practice. We are the controller of the personal data we hold about our users. Once the shared fields reach the Partner's CRM, the Partner is an independent controller of that copy and is responsible for its own compliance with UK GDPR and the Data Protection Act 2018. The Partner is not our processor and we are not the Partner's processor. The Partner's CRM provider is engaged by the Partner, not by us.
3. Consent is the only basis for sharing
Sharing is off by default. We send a person's details to the Partner only after that person has given their own recorded consent to sharing with the Partner by name, on a screen that names the Partner and the fields shared. Consent given to another partner, or for any other purpose on our platform, never counts. A person can withdraw consent at any time; from then on we send nothing further about them.
4. The Partner's obligations as controller
For the data it receives, the Partner will:
- use it only to follow up with that person about the services the Partner offers through its page, and not sell, rent or disclose it to anyone else for their own purposes;
- give the person the information required by Article 13 and 14 of UK GDPR in its own privacy notice, naming itself as controller of the CRM copy;
- not send marketing to the person unless it has its own lawful basis and, where required, the person's consent under the Privacy and Electronic Communications Regulations;
- keep the data secure with appropriate technical and organisational measures, and keep it no longer than it needs for that purpose;
- handle requests to access, correct, erase or restrict its copy itself, and tell us without undue delay if a request concerns data we also hold;
- be responsible for any transfer of the data outside the United Kingdom that its own CRM provider makes, and for the safeguards that transfer needs; and
- tell us without undue delay of any personal data breach affecting the shared data that may also affect people who use our service.
5. Our obligations
We will send only the fields in section 2, only for people with active consent, and only while this agreement is accepted and the CRM is connected. We keep the CRM connection credentials encrypted. We keep a record of which version of this agreement the Partner accepted and when, and we disclose the sharing to our users in section 4.3C of our Privacy Policy.
6. Changes and ending the arrangement
If we change this agreement we publish a new version here. Sharing stops until the Partner accepts the new version. The Partner can end the arrangement at any time by disconnecting its CRM in its white-label settings; we then send nothing further. Data already in the Partner's CRM stays under the Partner's control and its obligations in section 4 continue for as long as it holds that data.

