Legal
Privacy policy
Numo Law is used by regulated legal practices to run family law matters. Most of the personal data in it belongs to a firm’s clients and to the other people in their case, and the firm, not Numo, decides what happens to it. This policy explains that split, what we process in each role, and what you can ask us for.
Last updated
01
Who we are, and which hat we are wearing
Numo Law is a trading name of DAPPER TRADING LTD, a company registered in England and Wales under company number 8800299, whose registered office is at Oak House, Reeds Crescent, Watford, WD24 4QP, United Kingdom. Our VAT registration number is 190396586. We are registered with the Information Commissioner’s Office under registration [ICO registration number]. In this policy, “we” and “Numo” mean that company, and “the firm” means the legal practice whose account holds the data.
We act in two different roles, and which one applies decides who you should speak to:
- We are a processor
- for everything a firm puts into its account: matters, the people in them, documents, files, chronologies, figures, notes, messages and the assistant’s answers about them. The firm is the controller. It decides why that data is there and what is done with it, and we act on its documented instructions under a written data processing agreement.
- We are a controller
- for the accounts of the professionals who sign in, for our own billing and support records, for security and abuse logs, and for the people who contact us through this website or ask for a demonstration or a trial.
If you are a client of a firm that uses Numo Law and you want to know what is held about you, ask the firm. They hold the file, they know why each item is there, and under data protection law the request is theirs to answer. We will help them answer it.
02
How to reach us
Email support@numolaw.com for anything in this policy, including a request about your own data, a question from a firm’s COLP or data protection lead, or a security report. Post reaches us at DAPPER TRADING LTD, Oak House, Reeds Crescent, Watford, WD24 4QP, United Kingdom.
Our data protection contact is [name and role of the data protection contact]. Please do not send client-identifying information in a first email; we will open a secure channel before anything confidential moves.
03
What is processed, area by area
The product has a small number of places where personal data actually lives. This is all of them.
- Professional accounts
- Name, work email address, the organisation, the role, the regulator and registration number where a firm records one, a profile photograph if uploaded, sign-in times and the device and network address used. Passwords are never stored in a readable form.
- Matters and people
- The matter reference, jurisdiction, parties, children and other connected people, relationships, key dates, issues and objectives, and whatever the firm chooses to record. In family law this routinely includes information about health, sexual life, religion, ethnicity and alleged or actual criminal offences.
- Files and documents
- Everything read onto a matter: statements, disclosure, correspondence, photographs, valuations, bank statements, pension statements and the text extracted from them, together with who uploaded each one and when.
- The vault
- Files a firm has sealed. We hold only ciphertext and the wrapped key material. Filenames are inside the encrypted payload, so we do not hold a readable list of what is in there. See section 7.
- Assistant conversations
- The questions asked, the answers given, and the record of which files, registers and web pages were read to produce each answer, held against the matter they concern.
- Connected accounts
- Where a professional connects their own Google, Dropbox or Calendly account, the access tokens for that connection, encrypted, and a record of every action taken in it and every permission allowed or declined.
- Signing
- For each signature: the document as signed, the drawn signature image, the signer’s name and email address, the account they signed in with, the date and time, the internet address and browser the signature came from, the declarations they confirmed in the exact words shown to them, and whether they signed personally or for a named company in a named position. The signer is told all of this on the screen before they sign, and can decline instead. The drawn signature is encrypted at rest under a key held only inside the function that verifies it, so a copy of the database or of the file store yields ciphertext.
- The client portal
- Where a firm gives a client an account: their name and email address, what the firm has asked them for, what they have sent back including any files or photographs, the messages exchanged with the firm, and when they last signed in. A client sees only their own matter. The firm can end a portal, which stops that person signing in and deletes nothing.
- Notifications and devices
- What each person has been told and whether they have read it, and, where somebody uses the desktop application and asks to be notified, an identifier for that installation. We do not hold the contents of a notification anywhere the person it is about could not already see.
- Audit and workflow records
- Every action on a matter, hash-chained to the one before it, with who did it and when, plus each workflow run and what each of its steps did.
- This website
- Enquiry, demonstration and trial requests you send us: your name, work email address, telephone number if you give one, your role, the practice and how it is constituted, its regulator and registration number, its size and jurisdiction, what you want to see, and which plan you were looking at when you asked. We keep these so that a request is answered once rather than lost between two inboxes. Also the minimum traffic information our host records to serve and protect the site. There is no advertising and no cross-site tracking on this site.
04
Why, and on what lawful basis
Where the firm is the controller
The firm chooses its own lawful basis for holding its case file, which for legal practice is usually the performance of its retainer, its legal obligations, or its legitimate interests in conducting the client’s matter. Because family law files routinely contain special category data and criminal offence data, firms generally rely on the legal claims condition in Article 9(2)(f) UK GDPR, with the corresponding condition in the Data Protection Act 2018 where one is required. We process that data only on the firm’s instructions and for no purpose of our own.
Where we are the controller
- Running the service
- Performance of our contract with the firm, and our legitimate interests in operating, supporting and improving a product firms rely on.
- Security, abuse and fraud prevention
- Our legitimate interests, and our legal obligations, in keeping the service and its contents safe.
- Billing and records
- Performance of the contract, and our legal obligations in company and tax law.
- Answering your enquiry
- Steps taken at your request before entering a contract, and our legitimate interests in responding to people who contact us.
- Product emails to professional users
- Our legitimate interests in telling account holders about changes that affect them. Marketing email is sent only where you have asked for it, and every one carries an unsubscribe link.
05
Artificial intelligence, and what it is allowed to do
Numo Bot is the assistant inside the product. When a question needs it, the relevant part of the matter is sent to a large language model provider over an encrypted connection, an answer comes back, and the request ends. We have chosen the provider’s commercial terms, under which content sent through the interface we use is not used to train their models. The provider is named on the sub-processors page.
What is sent
- Only what the question needs. Retrieval selects the relevant files, facts and provisions rather than sending an entire matter.
- Only what the person asking is entitled to see. Retrieval runs under the same database permissions as their own pages, so an assistant answer cannot contain a matter they cannot open.
- Never a vault object, unless the vault has been unlocked in that session and a consent to analyse that specific object has been recorded.
What it is not allowed to do
- It cannot serve, file, send or approve anything. Those require a named person’s decision, recorded against the exact version.
- It cannot act in a connected account without a separate permission, granted at the moment, showing exactly what would happen.
- It does not make decisions about people. There is no automated decision-making producing legal or similarly significant effects within the meaning of Article 22 UK GDPR, and no profiling of clients.
- It does not produce figures. Money is computed deterministically in integer pence with its workings shown.
Every question, the sources read and the answer are recorded against the matter with the name of whoever asked, so a firm can account for what was used and when.
06
Accounts a professional connects
Connecting Gmail does not connect Drive. Each service is a separate connection, granted by one person for their own account, and the product tells you what the connection will be able to do before you make it.
- Tokens are encrypted with a key held only by the server function that uses them. A copy of the database on its own opens nothing.
- Nothing is read in the background. A connection sits idle until an action is allowed.
- Every action in a connected account is asked for separately, and both allowing and declining are written into the firm’s audit trail.
- Disconnecting destroys the stored tokens. Any later action has to ask the service for consent again.
When you use the place finder, the address you type and the location you look at are sent to Google Maps Platform to return results and imagery. Those requests are subject to Google’s own terms as well as this policy.
07
The vault, and what we deliberately cannot do
A file sealed into the vault is encrypted before it leaves the firm’s session. Each object has its own content key, wrapped by a vault key derived from a passphrase using Argon2id. We hold the ciphertext and the wrapped keys. We do not hold the passphrase, and there is no administrative route to the contents.
- Filenames are stored inside the encrypted payload, not beside it, because a list of sealed filenames is itself disclosure.
- Our support staff cannot read a vault object, and neither can a background job, a workflow or the assistant.
- If the passphrase and the recovery key are both lost, the contents cannot be recovered by anybody, including us. That is the property that makes the rest of this section true.
09
Where it is stored, and transfers out of the UK
Matter data, files and the audit trail are held in the European Union, in Ireland. The product is served from a content network with locations in the UK and the EU.
Two things involve a transfer outside the UK and the EEA: the language model provider and, where a firm uses it, the transactional email provider. Those transfers are made under the International Data Transfer Addendum to the European Commission’s standard contractual clauses, or under the UK Addendum, together with our own assessment of the transfer. The detail for each is on the sub-processors page.
A firm that cannot accept a transfer outside the UK should speak to us before signing. Some features depend on providers who are not UK-only, and we would rather say so in advance than have a firm discover it later.
10
How long it is kept
Where the firm is the controller, the firm sets the retention period, because only the firm knows its regulatory and professional obligations. Numo holds the data for as long as the firm’s account holds it, and deletes or returns it on the firm’s instruction and at the end of the contract.
| What | Kept for | Then |
|---|---|---|
| A firm's matter data | As long as the firm keeps it | Deleted or exported on instruction, and within 30 days of the contract ending unless the firm asks for longer |
| Professional account records | For the life of the account | Deleted within 90 days of closure, except entries needed for the audit chain |
| Audit trail entries | As long as the matter they concern | Deleted with the matter. Entries cannot be edited while they exist, which is the point of them |
| Signing records | As long as the matter they concern | Deleted with the matter. The signed PDF is the firm's record |
| Client portal messages, requests and replies | As long as the matter they concern | Deleted with the matter. Ending a portal stops the person signing in and deletes nothing, so a client who later asks what they were sent can still be told |
| Notifications | 90 days | Deleted. A notification is a prompt, not a record; what it pointed at is the record |
| Desktop device identifiers | Until the device stops appearing, or 12 months | Deleted |
| Security and abuse logs | 12 months | Deleted |
| Enquiries through this site | 24 months from the last contact | Deleted. Where one became a trial or an account, the account record is kept under its own row above |
| Billing records | 7 years | Deleted. Kept this long because tax law requires it |
11
Your rights
Under UK data protection law you can ask for a copy of your data, ask for it to be corrected or erased, ask us to restrict or stop certain processing, object to processing based on legitimate interests, and ask for data you gave us to be handed over in a portable form. You can withdraw consent at any time where consent is what we relied on.
If the data is in a firm’s matter, make the request to that firm. They are the controller, they know why each item is there, and they can weigh the exemptions that apply to legal files, including legal professional privilege and the exemption for legal proceedings. We will support them in answering within the statutory period.
For your own professional account, or for an enquiry you sent us, email support@numolaw.com. We will answer within one month and will tell you if we need longer because the request is complex.
You can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right.
12
How it is kept safe
Security here is a property of the software, not a paragraph in a policy. The security page describes it in full. In summary:
- Access is decided in the database, not on the screen. A role that cannot open a matter cannot have it read to them by the assistant either.
- Every action is hash-chained to the one before it and verified when the trail is read, so an entry cannot be altered after the fact.
- No secret lives in the applications. Every key sits in a server function’s own secret store, and the apps hold two public values and nothing else.
- Text from a document is treated as evidence, never as instruction. A file that addresses an automated reader is quarantined before anything reads it.
- Data is encrypted in transit and at rest, and vault objects are encrypted again under a key we do not hold.
If you believe you have found a vulnerability, email support@numolaw.com. We will acknowledge within one working day and we will not pursue anyone who reports in good faith and does not access other people’s data.
13
Children
Family law files contain information about children, often a great deal of it. That data is put there by a regulated practice for the conduct of proceedings, and the firm is its controller.
Numo Law itself is not offered to children. Accounts are created by a firm’s administrator for professional users; there is no public sign-up, and nobody under 18 is given an account.
14
Changes to this policy
When this policy changes we update the date at the top. Where a change materially affects how a firm’s data is processed, we tell the firm’s administrators by email before it takes effect, and the data processing agreement sets out what a firm can do if it objects.
Previous versions are available on request from support@numolaw.com.