Skip to main content

Privacy Policy

Your privacy and personal data protection are our top priorities.

Last updated: 24 July 2026

Version: 1.6

1. Introduction

Keystone Estate Planning (“we”, “us”, “our”) is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our online legal document assembly service.

Who We Are

  • Company: Keystone Estate Planning
  • Service: Online legal document assembly platform for Wills and Lasting Powers of Attorney
  • Jurisdiction: England and Wales
  • Data Controller: Keystone Estate Planning
  • Contact Email: privacy@keystoneestateplanning.co.uk
  • Data Protection Officer: dpo@keystoneestateplanning.co.uk

We are a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy complies with all UK data protection laws and regulations.

2. What Data We Collect

We collect various types of personal data to provide our services effectively and securely:

Personal Identification Data

  • Full name (including previous names if applicable)
  • Date of birth
  • Current and previous addresses
  • Email address
  • Telephone number
  • National Insurance number (for LPA identity verification)

Financial Information

  • Payment card details (processed securely by Stripe - we never store full card numbers)
  • Billing address
  • Transaction history
  • Asset information (for estate planning purposes)

Legal Document Information

  • Will provisions (beneficiaries, executors, guardians, bequests)
  • LPA preferences (attorneys, replacement attorneys, instructions, preferences)
  • Beneficiary and attorney details (names, addresses, relationships)
  • Witness information (when documents are executed)

Special Category Data

We process special category data only where it is necessary for a Health & Welfare LPA:

  • Health information:Only for Health & Welfare LPAs, where you may provide preferences regarding medical treatment, life-sustaining treatment decisions, and care preferences.
  • This data is used solely to create your Health & Welfare LPA and the related guidance and registration pack.

Health Data Processing for Health & Welfare LPAs

If you create a Health & Welfare LPA, we will process your health information for the purpose of preparing that document, as described in this Privacy Policy. We treat this as special category data under GDPR Article 9.

We may process information about your life-sustaining treatment preferences, health care instructions, attorneys' authority over health decisions, and the contact and identity details needed to prepare the official forms and guidance.

You can ask to withdraw consent to this processing at any time before your document is completed. If you do, we may be unable to continue preparing your Health & Welfare LPA.

We do not share your health information with any artificial intelligence system as part of our automated document checks. The only exception is our assisted rewording service, which we use only if you ask for it and give your explicit consent, as explained in section 6.

Technical Data

  • IP address
  • Browser type and version
  • Device information
  • Operating system
  • Cookies and similar tracking technologies
  • Usage data (pages visited, time spent, features used)
  • Access logs and security audit trails

Communications

  • Contact form submissions
  • Support ticket correspondence
  • Email communications with our team
  • Survey responses and feedback

3. How We Collect Data

Directly From You

  • Account Registration: When you create an account on our platform
  • Document Questionnaires: When you complete our guided questionnaires for Wills or LPAs
  • Contact Forms: When you submit enquiries or support requests
  • Payment Process: When you purchase our services
  • Direct Communications: When you email or call us

Automatically

  • Cookies: Essential cookies for security and functionality
  • Analytics: Usage statistics and behaviour insights to improve our service, where you have consented to optional analytics cookies
  • Security Logs: Automated logging of access and security events
  • Error Tracking: Technical diagnostics for service reliability

From Third Parties

  • Stripe: Payment confirmation and transaction status
  • Email Delivery Services: Email delivery status and engagement metrics
  • We do not purchase or receive data from data brokers

4. Lawful Basis for Processing

Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following legal bases:

Contract Performance

Processing is necessary to fulfill our contract with you to provide legal document assembly services. This includes:

  • Creating and delivering your Will or LPA documents
  • Processing payments
  • Providing customer support
  • Managing your account

Consent

Where we require your explicit consent, including:

  • Marketing communications (you can opt-out at any time)
  • Non-essential cookies and analytics

Legal Obligation

Processing required by law, including:

  • Maintaining tax records (7 years)
  • Audit trails and compliance records
  • Anti-money laundering checks
  • Responding to lawful requests from authorities

Legitimate Interests

Processing necessary for our legitimate business interests, provided your rights are protected:

  • Fraud prevention and security monitoring
  • Service improvement and analytics
  • Network and information security
  • Account access monitoring, including login counts, failed-login counters, lockout events, and passwordless sign-in link use
  • Business continuity and disaster recovery
  • Follow-up contact (by telephone, SMS, or email) if you start a Will or Lasting Power of Attorney but do not complete it, so we can help you finish. See section 5 for details and how to opt out.

5. How We Use Your Data

We use your personal data for the following purposes:

Service Delivery

  • Generate legally valid Will and LPA documents based on your instructions
  • Pre-fill official Office of the Public Guardian (OPG) forms for LPAs
  • Store your documents securely for future access
  • Process and fulfill your orders
  • Provide document delivery services (digital download or postal)

Communication

  • Send order confirmations and status updates
  • Provide customer support and respond to enquiries
  • Send important service notifications (e.g., changes to terms, security alerts)
  • Request feedback to improve our services
  • Send marketing communications (only with your consent, opt-out available)

Email Delivery Tracking and Suppression

Certain emails we send are legally significant to your order, for example, the email inviting you to review and confirm your document details. To make sure these messages reach you, we record the delivery status of each such send and maintain a suppression register of email addresses that have previously rejected our messages, based on bounce and complaint feedback from our email provider.

  • Pseudonymised identifiers only: these records store a one-way cryptographic hash and a masked version of your email address. Your full email address is not stored in either record.
  • Purpose: to alert our staff to delivery problems so that we can verify your contact details rather than let an important message fail silently. A suppression entry never prevents us from contacting you; it prompts a member of staff to check the address with you first.
  • Legal basis: performance of contract (UK GDPR Article 6(1)(b)) and legitimate interests (Article 6(1)(f)) in reliable delivery of service messages.
  • Your rights: these records are included in subject access requests and are deleted when you exercise your right to erasure.

Trust Suitability Calls and File Notes

If you ask us about a trust, we arrange a suitability call with one of our specialists. That call may be recorded, and a written file note may be prepared from it, so that we have an accurate record of the advice given and the reasons for our recommendation.

  • How the note is prepared: we may use automated tools to produce a first draft of the file note from the call. That draft is always reviewed, corrected where necessary, and approved by the specialist before it becomes the record. No decision about your trust is made by automated means.
  • Special category data: a suitability call may touch on matters such as your health or family circumstances. Where the note contains this information, our lawful basis is the establishment, exercise or defence of legal claims (UK GDPR Article 9(2)(f)), alongside performance of contract and our legitimate interests in advising you responsibly (Article 6(1)(b) and Article 6(1)(f)). A note may also refer to other people, such as intended beneficiaries or attorneys.
  • How long we keep it: the original recording and the call transcript are deleted within 30 days of the file note being signed. The signed file note itself is retained for up to 7 years, in line with the record we keep of the documents we prepare for you.
  • Your rights: these records are included in subject access requests and are deleted when you exercise your right to erasure, unless we are required to keep them because of a legal hold.

Drop-off Follow-up Contact

If you start a Will or Lasting Power of Attorney with us but do not finish it, we may contact you to see if we can help you complete it. This contact is led by email, with limited text message reminders and, in some cases, a telephone call placed personally by a member of our team. We previously operated an automated AI telephone follow-up system; that system was withdrawn in July 2026 and automated follow-up calls are no longer made.

  • Legal basis: Legitimate interests (UK GDPR Article 6(1)(f)), to help you complete a product you have already started. We have carried out a Legitimate Interests Assessment balancing this against your rights and freedoms.
  • How often: We use an email-led follow-up sequence. Early-stage drop-offs may receive emails at about 1 hour, 24 hours, and 14 days. Later-stage drop-offs or unfinished checkouts may receive emails at about 1 hour, 24 hours, and 7 days. We stop the sequence as soon as you complete your form, pay for an order, or turn off follow-up reminders.
  • SMS reminders: Later-stage drop-offs and unfinished checkouts may receive reminder texts at about 24 hours and 7 days, only if your follow-up reminder preferences allow text messages. Each reminder text includes an opt-out link, and we may send one further fallback text late in the sequence.
  • Telephone calls: Where a telephone follow-up is made, the call is placed personally by a member of our team, in response to the enquiry or unfinished application that you started with us. As you contacted us first and have an existing relationship with us, these calls are made on that basis and not as unsolicited marketing. We call at reasonable times of day. Calls may be recorded for training and quality assurance.
  • How to opt out: Ask the caller not to contact you again and you will be removed immediately, turn off follow-up reminders on your account preferences page, or email privacy@keystoneestateplanning.co.uk. If you ask us to come back later, we pause follow-ups for 30 days. The opt-out setting applies across these reminder calls and text messages, and stays in place unless you later change your preferences.
  • Transcription and analysis: Calls we record, including calls with our team as well as calls with Amy, may be transcribed to text and analysed to help us with quality assurance, training, and compliance. Transcription is carried out by our own systems. Before any transcript is analysed, we apply automated redaction to remove personal details such as contact numbers, postcodes, and account identifiers. Analysis is carried out by our AI provider under a data-processing agreement that prohibits using the content to train its models.
  • Retention: Call audio recordings are retained under our call-recording retention policy and deleted once they are no longer needed for the purposes described above. Call transcripts and their analysis are kept for up to 6 years for training, quality assurance, and compliance, and are protected with encryption and access controls. TPS-screening audit records are also kept for 6 years to meet ICO evidence requirements. You can ask for a copy of, or the deletion of, the transcripts we hold about you.

Legal Compliance

  • Maintain audit trails as required by financial regulations
  • Retain records per UK tax and accounting requirements
  • Comply with court orders and lawful requests
  • Meet anti-money laundering obligations

Security and Fraud Prevention

  • Monitor for fraudulent activity and security threats
  • Issue and verify passwordless sign-in links, including reusable 72-hour links for customers who need extra time to complete sign-in
  • Record security telemetry such as last login, successful login counts, failed login counts, lockouts, blocked login attempts, and magic-link request/use/failure counts
  • Store sign-in link tokens as one-way hashes and store IP address or browser identifiers only as redacted or hashed security metadata where needed
  • Enforce our Terms of Service
  • Maintain access controls and audit logs
  • Investigate suspected violations

Service Improvement

  • Analyze usage patterns to improve user experience
  • Test new features and services
  • Conduct research and analytics using aggregated, pseudonymized, or anonymized data where appropriate
  • Optimize performance and reliability

6. Data Sharing and Third-Party Processors

We never sell, rent, or trade your personal data to third parties for their marketing purposes.

We share your data only with trusted third-party service providers who help us deliver our services. All processors are carefully vetted and bound by data processing agreements:

Stripe (Payment Processing)

  • Purpose: Secure payment processing
  • Data Shared: Name, email, billing address, payment card details
  • Certification: PCI DSS Level 1 compliant
  • Privacy Policy: stripe.com/gb/privacy

Amazon Web Services (AWS) - Hosting & Storage

  • Purpose: Cloud hosting, data storage, and infrastructure
  • Data Shared: All platform data (encrypted)
  • Location: UK and EU regions only
  • Certification: ISO 27001, SOC 2, UK GDPR compliant
  • Privacy Policy: aws.amazon.com/privacy

AWS Simple Email Service (SES)

  • Purpose: Transactional emails (order confirmations, notifications)
  • Data Shared: Name, email address, order details
  • Certification: UK GDPR compliant

Artificial Intelligence Document Checking (Google and Anthropic)

  • Purpose: We use secure artificial intelligence services provided by Google and Anthropic to help check the documents we prepare for you. This checking works in two ways. First, we send the text of your questionnaire and documents, with direct identifying details, such as names, dates of birth, addresses, telephone numbers and email addresses, replaced by placeholders before the text is sent. Second, for some checks we send images of the finished forms so that the service can read them back and confirm they have been completed correctly.
  • Health information: Our automated document checks are designed so that your health information is not sent to the artificial intelligence service. Where a document contains special category information, such as your health and welfare preferences or your life-sustaining treatment choices, the pages that hold that information are removed before any image is sent, and that information is removed from the text before it is sent.
  • Assisted rewording (the one exception): If you ask us to improve the wording of your preferences or instructions, and you give your explicit consent, our team may send that specific passage of text to the artificial intelligence service to suggest clearer wording. Your name and other direct identifying details are removed from the passage first. For a health and welfare document, that passage may itself describe your health wishes. We only do this with your explicit consent, and you can decline without affecting your order.
  • Human review: A person always reviews the results, and no decision about your documents is made by the artificial intelligence service alone.
  • Where it is processed:The Google element of this checking takes place on Google Cloud within the European Union. Your prompts are not used to train Google's or Anthropic's models. Where any information is transferred outside the UK, we rely on the standard contractual clauses within the provider's data processing agreement.
  • Retention: Records created for this artificial intelligence review are deleted on a scheduled basis after the review is complete.
  • Privacy Policies: policies.google.com/privacy and anthropic.com/legal/privacy

Anthropic (Artificial Intelligence Provider)

  • Purpose: Anthropic provides artificial intelligence services that we use for the automated document readiness checks described above and for internal analysis of recorded calls for quality assurance, training and compliance.
  • Data Shared: Text of documents and questionnaires with direct identifying details replaced by placeholders, images of finished forms for read-back checks, and redacted call transcripts. Direct identifying details are removed or replaced before this information is sent.
  • Safeguards: Anthropic processes this information under a data processing agreement that prohibits using the content to train its models. A person always reviews the results, and no decision about your documents or your order is made by the artificial intelligence service alone. Where any information is transferred outside the UK, we rely on the standard contractual clauses within that agreement.
  • Privacy Policy: anthropic.com/legal/privacy

Telnyx (Telephone Calls and Call Recording)

  • Purpose: Telnyx provides the telephone infrastructure we use to place and receive calls, including the follow-up calls described in section 5, and to record calls for training, quality assurance and compliance.
  • Data Shared: Your name and telephone number, the call audio, and related call metadata.
  • Where it is processed:Where any information is transferred outside the UK, we rely on the standard contractual clauses within the provider's data processing agreement.
  • Privacy Policy: telnyx.com/privacy-policy

Google Address Validation (Address Verification)

  • Purpose: We check the postal addresses on your documents to confirm they are complete and deliverable before dispatch
  • Data Shared: The postal address being checked
  • Where it is processed:Google Cloud. Where any information is transferred outside the UK, we rely on the standard contractual clauses within the provider's data processing agreement
  • Retention: The corrected address is held only for a short period, is protected by encryption while it is held, and is deleted on request.
  • Privacy Policy: policies.google.com/privacy

Legal Disclosures

We may disclose your personal data if required by law or in response to:

  • Valid court orders or legal processes
  • Requests from law enforcement or regulatory authorities
  • Protection of our legal rights or prevention of fraud
  • Emergency situations involving danger to persons or property

Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you of any such change and your rights regarding your data.

7. Data Security

We implement comprehensive technical and organizational security measures to protect your personal data:

Encryption

  • In Transit: TLS 1.3 encryption for all data transmitted over the internet
  • At Rest: AES-256 encryption for all stored data
  • Field-Level: Additional encryption for personally identifiable information (PII)
  • Database: Encrypted database storage with encrypted backups

Access Controls

  • Role-Based Access: Staff access limited to what is necessary for their role
  • Multi-Factor Authentication: Required for all administrative access
  • Audit Logging: All data access is logged and monitored
  • Regular Reviews: Access permissions reviewed quarterly

Infrastructure Security

  • Enterprise-grade firewalls and intrusion detection systems
  • Regular security patches and updates
  • Vulnerability scanning and penetration testing
  • DDoS protection and rate limiting
  • Secure development practices and code reviews

Organizational Security

  • Staff security training and awareness programs
  • Confidentiality agreements for all personnel
  • Background checks for staff with data access
  • Incident response and breach notification procedures
  • Regular security audits and compliance reviews

Your Role in Security

Please help us protect your data by:

  • Using a strong, unique password for your account
  • Enabling two-factor authentication if available
  • Not sharing your login credentials with others
  • Logging out after using shared or public computers
  • Reporting any suspicious activity immediately

Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office (ICO) within 72 hours as required by UK GDPR.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy and to comply with legal obligations:

Draft Documents

Retention Period: 90 days from last activity

Incomplete documents and questionnaires are automatically deleted after 90 days of inactivity to minimize data storage.

Completed Documents

Retention Period: 7 years from order completion

Finalized Wills and LPAs are retained to allow you to access copies if needed and to comply with professional indemnity requirements.

Payment Records

Retention Period: 7 years from transaction date

Required by HMRC for tax and accounting purposes under UK law.

Audit Logs

Retention Period: 7 years minimum

Security and access logs retained for compliance, dispute resolution, and forensic purposes.

Authentication and Sign-in Link Records

Retention Period: Sign-in link records up to 90 days after expiry or revocation; account security counters while the account is active

We keep passwordless sign-in token records briefly for security investigation and troubleshooting. Token values are stored as one-way hashes, not as reusable plaintext links. Account security counters are deleted or anonymized when your account is erased, except where information must remain in legal audit records.

Account Data

Retention Period: Until deletion request or 7 years of inactivity

Account information retained while account is active. Dormant accounts (7+ years inactive) are automatically deleted.

Marketing Data

Retention Period: Until consent is withdrawn

Marketing preferences and communication history retained only while consent is active.

Early Deletion

You may request deletion of your data at any time (see “Your Rights” below). However, we may be required to retain certain data for legal compliance (e.g., tax records) even after a deletion request.

Secure Disposal

When data reaches the end of its retention period, it is securely deleted using industry-standard methods that prevent recovery.

9. Your Rights Under UK GDPR

Under UK data protection law, you have the following rights regarding your personal data:

1.Right of Access (Subject Access Request)

You have the right to request a copy of the personal data we hold about you.

  • We will provide this free of charge within one month
  • You can request this via email to privacy@keystoneestateplanning.co.uk
  • We may require ID verification to protect your data

2.Right to Rectification

You have the right to correct inaccurate or incomplete personal data.

  • You can update most information directly in your account settings
  • Contact support for assistance with corrections
  • We will respond within one month

3.Right to Erasure (“Right to be Forgotten”)

You have the right to request deletion of your personal data in certain circumstances.

  • You can delete your account at any time via account settings
  • Some data may need to be retained for legal compliance (e.g., tax records)
  • We will inform you if we cannot delete certain data and explain why

4.Right to Restrict Processing

You have the right to request that we limit how we use your data in certain circumstances.

  • Useful if you contest the accuracy of data or object to processing
  • We may still store the data but will not use it further
  • Contact privacy@keystoneestateplanning.co.uk to request restriction

5.Right to Data Portability

You have the right to receive your personal data in a machine-readable format.

  • Applies to data you provided based on consent or contract
  • We will provide data in JSON or CSV format
  • You can transfer this data to another service provider

6.Right to Object

You have the right to object to processing based on legitimate interests or for marketing purposes.

  • Absolute right to object to direct marketing (opt-out anytime)
  • Right to object to processing for legitimate interests (we will cease unless we have compelling grounds)
  • Unsubscribe links provided in all marketing emails

7.Right to Withdraw Consent

Where processing is based on consent, you can withdraw consent at any time.

  • Withdrawal does not affect the lawfulness of prior processing
  • Manage consent preferences in your account settings
  • Some services may not function without certain consents or permissions (for example, we may be unable to continue preparing a Health & Welfare LPA if you withdraw permission for us to process the health information it requires)

8.Right to Lodge a Complaint

You have the right to complain to the UK supervisory authority if you believe we have not handled your data properly.

Information Commissioner's Office (ICO)

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We encourage you to contact us first so we can address your concerns directly.

How to Exercise Your Rights

To exercise any of these rights, please:

  1. Email us at privacy@keystoneestateplanning.co.uk
  2. Clearly state which right you wish to exercise
  3. Provide sufficient information to identify your account
  4. Include proof of identity (to protect your data from unauthorized access)

We will respond to all requests within one month (may be extended by two months for complex requests).

10. Cookies

We use cookies and similar tracking technologies to enhance your experience and improve our service. For detailed information, please see our Cookie Policy.

Types of Cookies We Use

Essential Cookies (Cannot be Disabled)

These cookies are necessary for the website to function:

  • Session Cookie: Keeps you logged in and maintains your session
  • CSRF Token: Protects against cross-site request forgery attacks
  • Cookie Consent: Remembers your cookie preferences

Analytics Cookies (Opt-Out Available)

These cookies help us understand how visitors use our website:

  • Usage statistics such as page views and navigation patterns
  • Performance monitoring
  • Sensitive form, checkout, account, admin, and document content is suppressed
  • You can opt out in your cookie settings

Third-Party Cookies

  • Stripe: Payment processing (essential for checkout)
  • CookieScript and Google Tag Manager: Manage cookie consent and optional analytics tags
  • Optional analytics and marketing cookies are used only where disclosed in our Cookie Policy and controlled through cookie preferences

Managing Cookies

You can control cookies through:

  • Our Cookie Settings: Manage preferences in your account or via the cookie banner
  • Browser Settings: Most browsers allow you to block or delete cookies
  • Note: Disabling essential cookies will prevent the website from functioning properly

11. International Transfers

We take the security of international data transfers seriously and ensure appropriate safeguards are in place.

Primary Data Storage

All data is primarily stored in:

  • AWS UK and EU regions
  • No routine transfers outside the UK/EU
  • Backups remain within UK/EU jurisdictions

Exceptional Transfers Outside UK/EU

In limited circumstances, data may be transferred outside the UK/EU (e.g., some third-party processors have operations in other countries). When this occurs, we ensure:

  • Standard Contractual Clauses (SCCs): We use EU Commission-approved SCCs for data transfers
  • Adequacy Decisions: We transfer to countries recognized by the UK government as providing adequate protection
  • Additional Safeguards: Encryption in transit and at rest, access controls, and audit rights
  • Data Processing Agreements: Contractual obligations requiring processors to protect your data

Your Rights

You have the right to request information about international transfers of your data and to obtain copies of the safeguards in place. Contact privacy@keystoneestateplanning.co.uk for details.

12. Children's Privacy

Age Requirement

Our service is not intended for individuals under the age of 18. You must be at least 18 years old to:

  • Create an account
  • Use our services
  • Make a legally valid Will (minimum age requirement in England and Wales)
  • Create a Lasting Power of Attorney

Guardian Appointments

While you may name guardians for your minor children in your Will, and may include information about minors as beneficiaries:

  • We do not directly collect personal data from children
  • Information about minors is provided by adults (parents/testators)
  • Such information is limited to what is necessary for the legal document
  • Parents/guardians are responsible for the accuracy of information about minors

Inadvertent Collection

We do not knowingly collect personal data from children under 18 directly. If we discover that we have inadvertently collected such data, we will delete it promptly. If you believe we have collected data from a child, please contact us immediately at privacy@keystoneestateplanning.co.uk.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You

  • Material Changes: We will notify you by email and/or prominent notice on our website at least 30 days before changes take effect
  • Minor Changes:We will update the “Last Updated” date at the top of this policy
  • Version History: We maintain a version history for transparency

Your Acceptance

By continuing to use our services after changes take effect, you accept the updated Privacy Policy. If you do not agree with the changes:

  • You may delete your account before the changes take effect
  • You may download your data using the data portability right
  • Contact us if you have concerns about the changes

Reviewing This Policy

We recommend reviewing this Privacy Policy periodically to stay informed about how we protect your data. The current version is always available at keystoneestateplanning.co.uk/privacy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

General Privacy Enquiries

Email: privacy@keystoneestateplanning.co.uk

Response Time: Within 3 business days

Data Protection Officer

Email: dpo@keystoneestateplanning.co.uk

For: GDPR rights requests, data concerns

Customer Support

Email: support@keystoneestateplanning.co.uk

For: Account issues, general help

Postal Address

Suite RA01, 195-197 Wood Street

London, E17 3NU

United Kingdom

Complaints

If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve your concerns.

If you remain dissatisfied, you have the right to lodge a complaint with:

Information Commissioner's Office (ICO)

Website: ico.org.uk/make-a-complaint

Helpline: 0303 123 1113

Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Privacy Policy Summary

We Collect:

  • Personal identification data
  • Legal document information
  • Payment information (via Stripe)
  • Health data (LPA-H only, with consent)

We Use It For:

  • Creating your legal documents
  • Processing orders and payments
  • Providing customer support
  • Legal compliance and security

Your Data is Protected By:

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Role-based access controls
  • Regular security audits

Your Rights:

  • Access your data
  • Correct inaccuracies
  • Request deletion
  • Data portability

This summary is for convenience only. Please read the full Privacy Policy above for complete details.