Privacy & security

Sensitive work should require only the information it genuinely needs.

Our service is designed around data minimisation, clear authority and controlled actions.

No passwords

We do not ask for account passwords as part of the service.

Minimum necessary data

We ask for identifying information relevant to discovery and the evidence needed for authorised provider requests.

Action review

Consequential provider actions are reviewed before submission.

Living people’s data

Information about executors, relatives and other living people is handled as personal data where applicable.

Retention

Case information should not be kept indefinitely. Retention periods are defined by purpose and reviewed.

Provider boundaries

We use provider-authorised processes; we do not bypass account security.

This preview describes the intended operating controls. The production service will publish the final controller identity, retention schedule, processors and contact details before accepting live cases.