Your firm decides what happens to client data; we do what you instruct. We keep it confidential, secure and available, we tell you if something goes wrong, we help you answer requests from clients, and we hand everything back when you leave. We do not use it for our own purposes, and we do not train anyone’s models on it.
1 · Parties and roles
This agreement applies where the firm uses OpenLPM to process personal data and we act as a processor. The firm is the controller — it decides why and how client and staff personal data is processed. OpenLPM is the processor, acting only on the firm’s documented instructions.
Where the firm operates a self-hosted deployment and we provide no operational service, we process no personal data at all, and this agreement is limited to §5 (security measures guidance) and §11 (information). Where the firm uses a managed deployment, all sections apply.
Both parties will comply with the data protection law applicable to them. Where the firm is established in a jurisdiction with additional requirements, those are recorded in the order form as an addendum.
2 · Scope of processing
| Item | Detail |
|---|---|
| Subject matter | The operation of the firm’s practice management system: matters, documents, time, billing, client money records, messages and related administrative data. |
| Duration | The term of the firm’s subscription, plus any agreed retention or handover period after termination. |
| Nature and purpose | Hosting, storing, backing up, securing, updating and supporting the system; providing functionality the firm enables; assisting with the firm’s own compliance obligations. |
| Categories of data subjects | The firm’s clients and their representatives; counterparties and other parties to matters; the firm’s staff, contractors and applicants; individuals who contact the firm through its website or intake forms. |
| Categories of personal data | Identification and contact details; matter and case information, which may include special-category data where the firm’s work requires it; financial data including client money records and invoices; communications; system activity data (logins, changes, audit entries). |
| Special categories | Where the firm’s matters involve special-category data, the firm is responsible for having a lawful basis and for deciding what is recorded. We apply the same security measures to all client data without inspecting it. |
3 · Our obligations as processor
- Instructions only. We process personal data only on the firm’s documented instructions, including as set out in this agreement and the service terms; if we believe an instruction is unlawful, we will tell the firm and may suspend that processing.
- Confidentiality. Personnel with access are bound by confidentiality obligations that survive their engagement, and access is limited to those who need it to operate or support the service.
- Security. We implement the measures in §5 and the Annex, and we do not materially reduce them during the term.
- Assistance. We assist the firm with its obligations under data protection law, including security, breach notification, impact assessments and consultation with supervisory authorities, taking account of the nature of processing and the information available to us.
- No own purposes. We do not process firm data for our own purposes, sell it, share it for advertising, or use it to train models.
- Deletion and return. On termination we return and then delete data as set out in §10.
4 · Your obligations as controller
- Lawful basis and notices. Ensuring there is a lawful basis for the personal data the firm records, and that clients and staff have been given appropriate information.
- Instructions. Giving documented instructions for processing, and ensuring they are lawful — including where the firm asks us to enable a connection to a third-party service.
- Early consultation. Consulting us before enabling a feature that materially changes the nature of processing, so that the effect on this agreement can be assessed.
- User management. Maintaining its own user list, roles and permissions, and telling us promptly about joiners, leavers and suspected compromise.
- Retention choices. Configuring retention periods appropriate to the firm’s regulatory obligations rather than keeping everything indefinitely.
5 · Security measures
We implement and maintain the technical and organisational measures summarised below and set out in the Annex. They are designed to ensure a level of security appropriate to the risk, taking into account the state of the art and the costs of implementation.
- Separation of each firm’s data, with the client-facing system kept separate from the staff system and holding only what the firm has deliberately shared.
- Access control: role-based permissions, multi-factor authentication support, forced password change on first sign-in, lockout after repeated failures, and session invalidation on password change.
- Encryption in transit; encryption of sensitive identifiers at rest with per-instance keys.
- Audit logging of logins, changes and money movements with before and after values.
- Parameterized data access throughout, with no string-built queries on the supported path.
- Upload controls and attachment-only delivery of documents.
- Scheduled exports, rehearsed restores and documented restore objectives.
- Change management with verification before release and per-firm rollback.
A summary written for technical evaluation is on the security page, including the limits we state ourselves.
6 · Sub-processors
The firm gives general authorisation for the categories of sub-processor listed on the sub-processors page. We impose data protection obligations on each sub-processor no less protective than those in this agreement, and we remain liable for their performance.
We give at least 30 days’ notice before engaging a new sub-processor that processes client personal data, so the firm can object. If the firm objects on reasonable data protection grounds and no alternative is available, the firm may terminate the affected service without penalty.
7 · International transfers
Managed deployments store data in the region selected at deployment. Where processing involves a transfer outside that region — for example through a support or messaging provider — the transfer relies on an appropriate safeguard under applicable law, and the firm is told which one in the order form or in a sub-processor notice.
Where a firm’s own regulatory position requires data to stay in a specific location it controls, self-hosting or a bring-your-own-account deployment is the appropriate answer, and we will say so rather than argue around it.
8 · Personal data breaches
- We notify the firm without undue delay after becoming aware of a personal data breach affecting firm data.
- The notification describes what happened, the categories and approximate volume of data concerned, the likely consequences, and the measures taken or proposed.
- We assist with the firm’s own notification obligations, and we do not notify a supervisory authority or data subject on the firm’s behalf unless the firm instructs us to.
- We provide a written summary after containment, and we record the incident and its remediation.
9 · Data subject requests
If an individual contacts us about data held in a firm’s system, we do not decide the matter: we refer the request to the firm and assist with it. Where the firm asks us to carry out a search or an export to answer a request, we do so within the support terms, and we keep a record of what was provided and when.
10 · Return and deletion
- On request, and in any event within 30 days of termination, we provide a complete export of the firm’s data in open formats, together with the keys needed to operate the deployment.
- The deployment is retained during a handover window — 30 days by default — so the firm can verify what it received before anything is deleted.
- After the handover window, data is deleted from live systems and from backups on the backup rotation cycle, and deletion is confirmed in writing on request.
- Where the firm must retain data to meet a statutory obligation, we may keep it for that period only, and only for that purpose.
11 · Audit and information
We provide the information necessary to demonstrate compliance with this agreement, and we allow for audits — including inspections — by the firm or an auditor the firm appoints, subject to reasonable notice, confidentiality, and avoiding interference with other firms’ data or our security measures.
In practice, most of what a firm’s auditor wants is available without an audit: the control summary, the restore drill record, the sub-processor list, and the export of the firm’s own data. We will provide those as a matter of routine.
12 · Term, liability and governing terms
This agreement takes effect when the firm begins using the service and continues until processing ends. Liability under this agreement is subject to the limitations in the Terms of Service. Where this agreement conflicts with the Terms of Service on a data protection matter, this agreement prevails.
Annex · Technical and organisational measures
- Confidentiality and integrity. Role-based access control; least-privilege administration; multi-factor authentication; forced first-sign-in password change; account lockout; session invalidation on credential change; audit logging of access to sensitive functions.
- Availability and resilience. Redundant managed infrastructure; monitoring and alerting; scheduled exports with defined recovery point and recovery time objectives; rehearsed restores with a drill record available on request.
- Data minimisation and separation. Separate systems for staff and client-facing data; only deliberately shared items present in the client-facing system; client identifiers encrypted with per-instance keys.
- Change management. Verification before release; staged delivery per firm; rollback capability; documented change record.
- Physical and environmental. Provided by the managed infrastructure provider under its own certifications; we do not operate physical servers.
- Personnel. Confidentiality obligations; access granted only where needed; access revoked promptly on change of role or departure.
- Testing. Routine checks of authentication, authorisation, money handling and restore paths; vulnerability reports triaged through security@openlpm.com.