Skip to main content

Partner CRM Data-Sharing Agreement

Version 2026-09-28. Last updated: 28 September 2026

About this document: This agreement applies when a legal professional who offers our service under its own brand (the "Partner") connects its own customer relationship management system (the "CRM") so that Orchard72 ("we", "us") can send it limited details about people who come to us through the Partner's page. The Partner accepts it in its white-label settings before any CRM can be connected. It supplements, and does not replace, our Terms of Service and Privacy Policy.

1. Roles of the parties

This is a sharing arrangement between two independent controllers, made with regard to the Information Commissioner's data sharing code of practice. We are the controller of the personal data we hold about our users. Once the shared fields reach the Partner's CRM, the Partner is an independent controller of that copy and is responsible for its own compliance with UK GDPR and the Data Protection Act 2018. The Partner is not our processor and we are not the Partner's processor. The Partner's CRM provider is engaged by the Partner, not by us.

2. What is shared

We send only these three fields, and nothing else:

  • the person's name;
  • the person's email address; and
  • the status of that person's journey with the Partner (for example, whether a referral is open or complete).

Wills, estate and asset details, documents, health information and any other content a person records with us are never shared under this agreement. The Partner must not ask us to extend the fields, and we will not do so without a new version of this agreement and fresh consent from each person.

4. The Partner's obligations as controller

For the data it receives, the Partner will:

  • use it only to follow up with that person about the services the Partner offers through its page, and not sell, rent or disclose it to anyone else for their own purposes;
  • give the person the information required by Article 13 and 14 of UK GDPR in its own privacy notice, naming itself as controller of the CRM copy;
  • not send marketing to the person unless it has its own lawful basis and, where required, the person's consent under the Privacy and Electronic Communications Regulations;
  • keep the data secure with appropriate technical and organisational measures, and keep it no longer than it needs for that purpose;
  • handle requests to access, correct, erase or restrict its copy itself, and tell us without undue delay if a request concerns data we also hold;
  • be responsible for any transfer of the data outside the United Kingdom that its own CRM provider makes, and for the safeguards that transfer needs; and
  • tell us without undue delay of any personal data breach affecting the shared data that may also affect people who use our service.

5. Our obligations

We will send only the fields in section 2, only for people with active consent, and only while this agreement is accepted and the CRM is connected. We keep the CRM connection credentials encrypted. We keep a record of which version of this agreement the Partner accepted and when, and we disclose the sharing to our users in section 4.3C of our Privacy Policy.

6. Changes and ending the arrangement

If we change this agreement we publish a new version here. Sharing stops until the Partner accepts the new version. The Partner can end the arrangement at any time by disconnecting its CRM in its white-label settings; we then send nothing further. Data already in the Partner's CRM stays under the Partner's control and its obligations in section 4 continue for as long as it holds that data.

We use cookies to improve your experience. See our Cookie Policy (opens in a new tab) for details.