We collect the minimum needed to answer you and run the service. We use no advertising trackers. Client data belongs to your firm, and we act only on your instructions.
1. Who is responsible for what
On this website and for our mailing list, we are the controller of the personal data described below.
In a managed deployment, your firm is the controller of everything in its instance and we are the processor, acting only on your instructions. Your firm decides what is collected from clients, how long it is kept and who can see it. Our role is to keep it secure and available.
2. What we collect
| Where | What | Why |
|---|---|---|
| This website | Aggregate, cookieless analytics: page views, referrer, country, device class | To understand which pages are useful. No cross-site tracking, no advertising identifiers |
| Demo request form | Name, work email, firm, practice size, your notes | To reply and to prepare a relevant demonstration |
| Newsletter | Email address, name (optional), firm (optional), subscription segment | To send what you asked for, and nothing else |
| Support | Contact details, the technical detail of your request | To resolve the issue and keep a record of it |
| Managed service | Firm and user records, activity logs, audit entries | To operate the service, keep it secure and meet our obligations to you |
3. Why we are allowed to do this
- Contract — to provide and support the service your firm has subscribed to.
- Legitimate interests — to answer enquiries, keep the service secure, prevent abuse, and improve the product; balanced against your rights, which you can exercise at any time.
- Consent — for the newsletter. You can withdraw it with one click in any email.
- Legal obligation — where we must keep records, for example for tax or to respond to lawful requests.
4. What we never do
- We do not sell personal data, and we do not share it for advertising.
- We do not use advertising or cross-site tracking cookies on this website.
- We do not read a firm’s client files as part of routine operations, and we do not use client data to train third-party models.
- We do not disclose a firm’s data to a third party except on the firm’s instruction, or where compelled by law — in which case we tell the firm unless prohibited.
- We do not make automated decisions about individuals that produce legal effects.
5. Cookies and analytics
This website uses strictly necessary cookies only, and cookieless aggregate analytics. There is no consent banner because there is nothing to consent to; if we ever add advertising or third-party tracking, we will ask first and this notice will change before it happens.
6. How long we keep things
- Website analytics — 12 months, in aggregate.
- Demo requests — 24 months, so we can remember the context of a conversation.
- Newsletter — until you unsubscribe, plus a suppression record so we do not re-add you.
- Support tickets — 24 months.
- Managed service data — per your firm’s retention policy, which the firm controls; on termination we follow the exit process in the managed service terms.
7. Your rights
You may ask for access to your personal data, correction of it, deletion, restriction of processing, portability, or object to processing based on legitimate interests. You may also withdraw consent for the newsletter at any time. Write to privacy@openlpm.com and we will respond within 30 days.
If your request concerns data inside a firm’s instance — a matter, a document, a message — the firm is the controller and we will forward your request to them, because we are not permitted to decide what happens to their file.
You also have the right to complain to your local data protection authority.
8. Where data is stored and transfers
Website and mailing data are stored with established providers in the regions they operate. Managed deployments store data in the region selected at deployment. Where data moves between regions, we rely on appropriate safeguards, and the sub-processor list is available with your order form.
9. How we protect it
Access is role-limited and recorded, credentials are hashed, multi-factor authentication is supported and encouraged, and firm data lives in the firm’s own instance rather than a shared pool. A summary of the controls is on the security page — written for the person who will test the claims.
10. Changes and contact
We will post any change here with a new version date, and notify mailing-list subscribers in the next email. Questions: privacy@openlpm.com.