Your data, your control
Your firm handles other people's most sensitive information for a living, so how a supplier treats yours matters. Here is the short version — the full detail is in the Security overview and the Data Processing Agreement.
You own it
Your client, matter and business data is yours and stays yours. Kefilex processes it on your behalf as your processor under a UK GDPR Data Processing Agreement — it does not become ours by passing through the platform.
You can take it with you
You can export your data in a complete, machine-readable form on request — including during a dispute. We waive any lien over it: there is no scenario where an unpaid invoice holds your data hostage. If you leave, there is a window to export before anything is removed.
You can have it deleted
Ask, and we delete your data from the live platform, keeping only what the law requires us to retain. You are never locked in by inertia.
What we never do
- We never sell your data, and we never share it with third parties for their own purposes.
- We never use it to train generalised AI models.
- We never publish it, even in aggregate.
Kept separate, kept protected
Every firm's data lives in its own isolated space — one firm can never see another's. It is encrypted in transit and at rest, and access by our team is limited to support and incident response, and logged. The full technical picture — hosting, encryption, tenant isolation and the sub-processors involved — is on the Security overview.