Skip to main content

Archive Digitisation Processor Terms

Last updated: 22 September 2026

About this document: These are the standard UK GDPR Article 28 processor terms that apply when a professional firm (the "Firm") instructs Orchard72 ("we", "us", the "Processor") to digitise and index its client files. The Firm remains the controller of the personal data in those files. We act only on the Firm's documented instructions. These terms supplement, and do not replace, our Terms of Service and Privacy Policy.

1. Parties, roles and scope

The Firm is the controller and we are the processor for every category of personal data contained in the files the Firm submits for digitisation. That includes data about people who have never been our users and who may never become our users: clients, former clients, deceased clients, executors, beneficiaries, attorneys, witnesses, opponents and third parties named in correspondence.

These terms cover the archive digitisation service only: ingest of the Firm's files, classification, indexing, review, sign-off and delivery back into the Firm's own space on our platform. Where the Firm also uses our platform to serve its own clients directly, the roles for that activity are set out in our Data Processing Agreement.

2. Subject matter, duration, nature and purpose

  • Subject matter: digitisation, classification, indexing and secure storage of the Firm's client files.
  • Duration: from the start of the engagement until the Firm's instruction to delete or return the records, subject to section 11.
  • Nature and purpose: converting paper and image files into searchable records held under the Firm's control, so that the Firm can retrieve, review and act on its own matter records.
  • Types of personal data: identity and contact details, family and relationship details, financial and asset details, health information where it appears in a matter file, and any special category data the Firm's files happen to contain.
  • Categories of data subject: the Firm's clients and former clients, deceased clients, and third parties named in their files.

3. The Firm's instructions and warranties

We process personal data only on the Firm's documented instructions, including on transfers, unless we are required to do otherwise by law. Where a legal requirement forces us to go beyond the Firm's instructions, we will tell the Firm before processing, unless the law prohibits that notice.

The Firm warrants that:

  • it has authority over the files it submits and is entitled to have them processed by a third party;
  • it has a lawful basis for the processing and, where the files contain special category data, an Article 9 condition;
  • its own privacy information covers the use of a digitisation processor, and it has considered whether Article 14 notice to data subjects is required or exempt;
  • it has satisfied its own professional conduct and confidentiality obligations, including any regulator requirements on outsourcing and file retention.

We will tell the Firm if, in our opinion, an instruction infringes data protection law. We are not the Firm's adviser on its retention obligations and we do not decide how long the Firm should keep a matter file.

4. What we do not do

Two limits matter enough to state in the contract rather than leave to the scoping conversation:

  • We never take custody of your original documents. Paper stays with the Firm or with the Firm's own storage provider. Where a scanning bureau is used, it is engaged under the Firm's own chain of custody arrangements and the originals are returned to the Firm.
  • We never attest that a scanned record is a true copy of an original. A scan we produce is an image of what was supplied to us. Certification of a true copy is an act of the Firm or another authorised person, not of a processor.

We also do not make retention, destruction or disclosure decisions about the Firm's records. We execute the Firm's instruction and record who gave it.

5. The sign-off model

Classification output is a proposal until a named person at the Firm signs it off. A batch moves through ingest, automated classification, the Firm's review queue and then sign-off by a person the Firm has authorised. We record who signed off, when and against which sample. Nothing is treated as the Firm's accepted record until that sign-off exists.

6. Confidentiality

Everyone we authorise to process the Firm's data is bound by a duty of confidentiality that survives the end of their engagement with us. Access is granted on a need-to-know basis and is scoped to the Firm's own space on the platform.

7. Security measures

We implement appropriate technical and organisational measures under Article 32. Those in place for archive digitisation include:

  • envelope encryption of stored documents: each document is sealed under its own data key, and those data keys are encrypted under a key held and managed separately from the encrypted content;
  • least-privilege role-based access control for our own staff, under which administrative views are masked by default, and reading an unmasked record requires a time-limited, reason-bound break-glass elevation recorded internally against the incident or request that authorised it;
  • encryption in transit for every ingest, review and retrieval path;
  • storage scoped to the Firm's own space, enforced in the data model so that a record cannot be read across firm boundaries;
  • access control, authentication and audit logging of document access and sign-off events;
  • restricted deletion, so that a space cannot be removed while records the Firm still relies on are attached to it;
  • backup and restoration testing, and regular review of these measures.

8. How content is processed by our models

Classification and extraction in this service run on local models on our own servers. Document content is not sent to an external AI provider in the archive digitisation lane. Your data never leaves our servers without your approval: there is no default, silent or fallback route to a third-party model, and if our local processing is unavailable we wait or fail the batch rather than send content elsewhere.

Model output is a suggestion for the Firm's review queue. It does not by itself produce a legal effect for any data subject, and a person at the Firm decides what the record is.

9. Sub-processors

The Firm gives general written authorisation for us to engage sub-processors. We impose data protection obligations on each sub-processor that are no less protective than these terms, and we remain fully liable to the Firm for their performance.

Our current sub-processors are listed on the sub-processors page. For archive digitisation specifically, a scanning bureau partner may be engaged as a sub-processor to convert paper to images where the Firm asks us to arrange that step. We name the relationship here before a partner is signed so that the Firm knows the category of sub-processor the service contemplates. We will give the Firm advance notice of any intended addition or replacement of a sub-processor in this lane, and the Firm may object on reasonable data protection grounds.

10. International transfers

Archive digitisation data is hosted in the United Kingdom and the European Economic Area. We do not transfer the Firm's data outside the UK or EEA for this service without the Firm's instruction. Where a transfer is instructed, it is made only under a transfer mechanism recognised by UK GDPR Article 46 (the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses), together with a transfer risk assessment.

11. Deletion and return on termination

On the Firm's instruction, and in any event at the end of the engagement, we return the digitised records to the Firm in a structured, machine-readable export, or delete them, at the Firm's choice. Deletion covers existing copies unless storage is required by law, in which case we tell the Firm what must be retained and for how long.

Retention of an archive record is anchored to the Firm's matter, not to any subscription of ours. A record does not become deletable because a subscription ends, and it is not retained beyond the Firm's instruction because a subscription continues. Backups roll off on their own cycle, which we describe in our Privacy Policy.

12. Assistance to the Firm

  • Data subject rights: we provide the search, export and deletion tooling the Firm needs to answer a request itself, and we assist with any request that reaches us. We pass a request that reaches us directly to the Firm and do not respond to it ourselves unless the Firm instructs us to.
  • Articles 32 to 36: we assist the Firm with security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us.

13. Personal data breaches

We notify the Firm without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting the Firm's data. The notification describes the nature of the breach, the categories and approximate number of records concerned, the likely consequences and the measures taken. The Firm decides whether to notify the regulator and the data subjects.

14. Information and audit rights

We make available to the Firm the information necessary to demonstrate compliance with Article 28, including our record of processing activities for this service, our security measures and our sub-processor list. We allow for and contribute to audits, including inspections, conducted by the Firm or an auditor it mandates.

Audits are on reasonable notice, during business hours, no more than once in any twelve-month period unless a breach or a regulator requires otherwise, and subject to confidentiality, because an auditor on our systems is also standing next to other firms' client data.

15. Records of processing

We maintain a record of the processing we carry out on the Firm's behalf under Article 30(2), covering the categories of processing, transfers and the security measures applied. It is available to the Firm and to the regulator on request.

We use cookies to improve your experience. See our Cookie Policy (opens in a new tab) for details.