Kefilex.
Privacy

Privacy Policy.

How we handle personal data when you use Kefilex. Plain English first, the legally-required detail underneath. For the analytics-cookie specifics, see Cookies & analytics.

Version 1.1 · Effective 14 August 2026.

1. Who we are.

Kefilex is a product of Kefilab, based at 301 Bath Road, Hounslow, London TW3 3DB, United Kingdom, and registered with the Information Commissioner's Office — registration ZC207164. We are the independent data controller only for firm account and billing records, product-usage analytics, and the marketing-site and sales data described below. This policy applies to the marketing site at kefilex.com, the Kefilex web application at app.kefilex.com, and the platform-admin surface at admin.kefilex.com.

For the client, enquiry and matter data processed in a firm's tenant — including matter / contact / time-entry / bill records synchronised from a connected Clio account, and enquiries captured from the firm's website, phone systems and email — the firm is the data controller and we act as its data processor under the Data Processing Agreement incorporated into our Terms of Business.

2. Information we collect.

Account & authentication

Your email address, optional display name, and timestamps for sign-in events. We use a passwordless email-magic-link flow via our authentication sub-processor (Supabase) — we never see or store your password.

Firm & integration data

When a firm administrator connects a Clio account, we receive via OAuth: a Clio access token and refresh token (used only to fetch records on the firm's behalf), the firm's Clio account ID and region, and a copy of the firm's matters, contacts, time entries, bills, fee earners, practice areas, and per-matter trust and operating balances (refreshed in real time via webhooks plus a daily reconcile). We do not ingest Clio documents, calendar items or communications. Kefilex reads the firm's Clio account to keep this mirror current and to attribute outcomes, and writes back to Clio only when a user takes an action — opening a matter, booking a consultation, or taking a consultation payment. It never writes automatically, and never writes to the firm's billing. We read the firm's Clio calendar to show consultation availability, and write a calendar entry when a consultation is booked.

Subscription & billing

When a firm subscribes to a paid plan we receive a Stripe customer ID and subscription state from our billing sub-processor (Stripe). Card details are entered directly into Stripe's hosted page and never reach Kefilex servers.

Product analytics — consent-gated

Inside the app (app.kefilex.com), where analytics is enabled we use PostHog (EU region) to understand how the product is used and improve it. What we capture depends on the type of account, because paying firms run real client and matter data on screen:

Paying firms — content-blind. We collect product-usage events only: which pages are visited (path only, never the query string) and named actions such as starting a session or clicking a key button, plus anonymous performance timings. There is no session recording, no capture of on-screen text or the contents of any field, and no page addresses that could carry a client's name. We record how the product is used, never what is on the screen or who a matter concerns.

Trial and demo/sandbox accounts — full product analytics. These accounts contain seeded demonstration data, not real client information, so in addition to usage events we capture masked session recordings (mouse movement, scrolling and clicks) with all form-input contents masked at capture. This helps us see where evaluating firms get stuck. Users who do not consent load no analytics at all.

Marketing-site analytics — consent-gated

On kefilex.com we use PostHog (EU region) for product analytics. With your explicit consent (the "Allow analytics" banner) we capture pageviews, click events, scroll depth, web vitals, heatmaps, and session recordings of mouse movement, scrolling and clicks with form-input contents masked at capture. We never see what you type into a field; only submitted form values reach us, and only after you press the submit button. Decline the banner and zero events are sent. Full breakdown on the Cookies & analytics page. Analytics requests route through kefilex.com/ingest (a reverse proxy to PostHog EU) so that browser-level ad-blockers don't silently drop them — the data still flows to PostHog EU under the same consent gate.

Sign-up and trial pages — consent-gated

On our sign-up and trial pages at app.kefilex.com/signup and app.kefilex.com/trial we run the same PostHog (EU region) analytics as the marketing site, but only after you accept the cookie banner shown on those pages — it is opt-in, and nothing loads if you decline. We capture pageviews and clicks to understand the sign-up funnel, and, if you submit the form, associate that activity with your email address so we can follow up. There is no session recording on these pages.

Interactive product demo — consent-gated

On our interactive product demo at app.kefilex.com/demo/broker-portal we run the same PostHog (EU region) analytics, opt-in via the cookie banner shown on that page, remembered with a kfx_demo_consent cookie. Unlike our other public pages, this demo additionally records the session — pageviews, clicks, and a replay of mouse movement, scrolling and page transitions, with form-input contents masked at capture — so we can see how prospective partners explore it. We never see what you type. If you submit the demo portal's partner-enquiry form we associate that session with your email so we can follow up. Decline the banner and nothing is captured.

Sales enquiries and prospect research

When you contact us through a form on kefilex.com or by phone, we store your enquiry (name, firm, email, phone and your message) in our own sales records so we can respond and track the conversation. To prepare for that conversation we may enrich the record from public sources — the UK Companies House register — and, when a member of our team requests it, run an AI-assisted web-research summary about the firm and its key people, drawn from publicly available information, via our AI sub-processor Anthropic. The data we send is not used to train AI models. This is used solely for our own sales follow-up, is never sold or shared with advertisers, and you can object at any time by emailing privacy@kefilab.com.

Server logs and operational telemetry

We retain HTTP request metadata (timestamps, IP addresses, response codes, user-agent strings) for 14 days in our hosting provider's standard log retention, to diagnose service issues and detect abuse. Where we record an IP address as part of a contract record, that is described just below and kept on a different basis.

Contract records

When you accept our Terms of Business and Data Processing Agreement, we record the version you were shown, the date and time, your IP address and your browser's user-agent string. That is how we evidence what was agreed, and by whom.

We keep it for as long as the agreement is in force, and afterwards for as long as we may need to evidence its terms — for example while a claim relating to it could still be brought. Our basis is the performance of our contract with you, together with our legitimate interest in being able to prove what that contract said.

3. Lawful bases for processing.

  • ·Providing the service to a logged-in user — Contract (UK GDPR Article 6(1)(b)).
  • ·Marketing to prospective customers — Legitimate interest (Article 6(1)(f)); we honour every opt-out.
  • ·Sales enquiries and prospect research (including AI-assisted enrichment from public sources) — Legitimate interest (Article 6(1)(f)); we balance this against your rights and honour every objection.
  • ·Product analytics (usage only, all account types) — Consent (Article 6(1)(a)); withdrawable at any time.
  • ·Billing and fraud prevention — Legitimate interest and contract.
  • ·Compliance with UK / EU legal obligations — Legal obligation (Article 6(1)(c)).

4. Sub-processors.

Each processes personal data on our behalf under written terms that mirror or exceed UK GDPR Article 28. List current as of the effective date above. We give firms at least 30 days' notice before adding or replacing a sub-processor, with a right to object, as set out in our Data Processing Agreement.

Sub-processorPurposeRegion
SupabasePostgres database, authentication, file storageUK (eu-west-2)
NetlifyWeb hosting, edge + background functions (functions run in London; global CDN carries static assets only)UK (eu-west-2)
ResendTransactional email delivery (message content can include client names and enquiry / matter details)USA (EU–US DPF + UK Extension; SCCs + UK Addendum fallback)
StripePayment processing & subscription billingEU
PostHogConsent-gated analytics (marketing site, sign-up / trial pages, and usage-only in-app for all account types)EU (Frankfurt, eu.posthog.com)
AnthropicAI-assisted sales research / prospect enrichment (web search); data not used to train modelsUSA (SCCs / UK IDTA)
BetterStackExternal uptime monitoring & status pageEU / global edge
SentryApplication error & performance monitoring (diagnostics only; payload-scrubbed so client personal data is excluded from error reports)EU (Germany, ingest.de.sentry.io)
ClioPractice-management data source (per-tenant OAuth)Per Clio region
TwilioReception telephony for firms on the optional Switchboard add-on — inbound call routing, in-browser answer / transfer, and call metadata (caller number, call times, status); call audio relayed in transit, recording off by defaultEU data residency (Ireland, IE1); Twilio Inc. (US parent) under the UK Extension to the EU–US DPF, SCCs + UK Addendum fallback

When a sub-processor is located outside the UK we rely on a UK adequacy regulation (a "data bridge", such as the UK Extension to the EU–US Data Privacy Framework used for our US-established email provider Resend), the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, plus a transfer risk assessment where required.

5. How we share information.

We share personal data only with: (a) the sub-processors listed above, strictly to deliver the service; (b) law enforcement or regulators when required by a binding legal request; and (c) a successor in a sale of the business (with written notice to the firm). We do not sell personal data, ever, full stop.

6. Data residency.

Customer data is stored in the United Kingdom: database, authentication and file storage run on Supabase in AWS eu-west-2 (London), and our application functions run on Netlify in London. Netlify's global CDN carries static assets (pages, scripts, images) only — pages containing a firm's data are generated on demand in London and are not cached at the edge.

The one exception is transactional email. Email we send on a firm's behalf (notifications, invitations, alerts) is delivered by Resend, a US-established provider, which stores the email data — recipient address, subject and message content (which can include client names and enquiry or matter details) and delivery metadata — in the United States. That disclosure is a restricted transfer to the US, covered by Resend's certification under the UK Extension to the EU–US Data Privacy Framework, with the EU Standard Contractual Clauses and UK Addendum as a fallback safeguard and a completed transfer risk assessment on file. No other production personal data leaves the UK/EEA in normal operation.

7. Retention.

  • ·Account email + display name — while the account is active; 90 days after account deletion or subscription cancellation, then deleted from production, with backups expiring on rotation.
  • ·Firm tenant data, including Clio-sourced cached records (matters, contacts, time entries, bills) — while connected; after cancellation or disconnect the firm has a 90-day window in which, on request, we provide a full export of its data in machine-readable form, after which it is deleted from production, with backups expiring on rotation. The firm can request earlier deletion in writing at any time, and Clio-synchronised records can additionally be hard-deleted immediately from Admin → Clio settings.
  • ·Trial-tenant data — trials run in pooled demonstration environments seeded with fictional data; anything entered during a trial is deleted when the trial slot is recycled. Trials are free, take no payment card, and never convert automatically into a paid subscription.
  • ·Waitlist — your email address only, kept until we invite you or you ask to be removed.
  • ·Billing and subscription records — 7 years (UK tax / HMRC requirement).
  • ·Server logs and operational telemetry — 14 days.
  • ·Audit log entries (platform admin actions) — retained indefinitely as a tamper-evident operational record.

8. Your rights.

As a UK or EU resident you have the right to:

  • ·Access the personal data we hold about you
  • ·Rectify inaccurate personal data
  • ·Erase your personal data (subject to legal-retention overrides like the billing-records rule above)
  • ·Restrict or object to processing
  • ·Port your data to another provider
  • ·Withdraw consent for any processing based on consent (including product analytics) at any time
  • ·Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority

To exercise any of these rights, email privacy@kefilab.com. We respond within 30 days, or sooner where the request is straightforward.

9. Cookies and similar technologies.

We use only the strictly-necessary cookies required for sign-in and session management. We do not use advertising cookies. If you are a trial-tenant user who consented to product analytics, the PostHog SDK sets a first-party cookie scoped to your tenant; withdraw consent in Settings → Privacy to clear it. Full details on the Cookies & analytics page.

10. Children.

Kefilex is a business product intended for legal-practice professionals. It is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided data to us, contact privacy@kefilab.com and we will erase it.

11. Security.

For a full description of our security posture see the Security Policy. In summary: HTTPS everywhere, AES-256 encryption at rest across the database and backups, application-layer AES-256-GCM encryption of phone-system integration credentials (with Clio and other OAuth tokens stored encrypted in Postgres via pgcrypto), dependency vulnerability scanning, written incident-response playbook, and breach notification without undue delay, targeting 72 hours.

12. Breach notification.

If we become aware of a personal-data breach we will notify the UK Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware, as required by UK GDPR Article 33. We will notify affected firms without undue delay, targeting 72 hours, by email to their registered administrator address with the information required by Article 33(3).

13. Changes to this policy.

We may update this policy from time to time. Material changes will be announced by email to active customers at least 30 days before they take effect, and the "Effective" date at the top of this page will be updated. Continued use of the service after the effective date constitutes acceptance.

14. Contact us.

Last updated 14 August 2026. The contact above is the named point of contact for all data-protection matters.

← Back to home