Privacy Policy
Last updated: 2 October 2026 · Effective date: 2 October 2026
Please read this Privacy Policy in full.
It forms part of, and must be read together with, our Terms of Service, Cookie Policy, AI Policy and Sub-Processor List. By creating an account or using the Service you confirm that you have read and understood it. If you do not agree, please do not use the Service.
1. About this notice
This Privacy Policy explains how Big Berri Limited (trading as "Writford", "we", "us", "our") collects, uses, stores, shares and protects personal data when you use the Writford platform, including writford.co.uk, any associated sub-domains, the web application, the API, and any other service we provide (collectively the "Service"). It also explains your rights under the United Kingdom General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018").
2. Who we are
| Controller | Big Berri Limited |
| Trading as | Writford |
| Company number | 16562429 |
| Registered in | England and Wales |
| ICO registration number | ZC119995 |
| General contact | info@writford.co.uk |
| Data protection | info@writford.co.uk |
We are the "controller" of your personal data for the purposes of the UK GDPR when you create or administer an account, browse our website, correspond with us, or make a payment for the Service.
When our customers (typically solicitors, law firms and legal professionals) use the Service to process personal data relating to their own clients, matters, counterparties or other third parties, we act as a "processor" on their behalf. See Section 14 (Controller / Processor Relationship).
We have not appointed a statutory Data Protection Officer because we are not legally required to do so under Article 37 UK GDPR. Privacy queries are handled directly by the management of Big Berri Limited at the email address above.
3. Scope of this policy
This Privacy Policy applies to:
- information you give us directly when signing up, subscribing, contacting support, or interacting with our website;
- information generated automatically when you use the Service, such as usage counters and technical logs;
- information received from the limited third-party providers listed in Section 9.
This Privacy Policy does NOT apply to:
- The content of third-party websites linked from the Service (for example, legislation.gov.uk, The National Archives, or search results).
- Your own professional handling of client data as a solicitor. You remain the controller of your own client files and bear full professional responsibility for any personal data you choose to input into the Service.
4. Personal data we collect
We deliberately keep the personal data we hold about you to the minimum needed to run a secure, paid, professional service.
4.1 Account data
Provided by you at signup and in your account settings:
- Full name
- Work email address
- Name of law firm or organisation
- Solicitors Regulation Authority ("SRA") number (optional)
- Password, stored only as a one-way hash produced by an industry-standard slow hashing algorithm. We never see, store, or can recover your plain-text password.
- User preferences (onboarding status, notification toggles, UI options).
4.2 Subscription and billing data
We do not store full payment card details. Stripe (our PCI DSS Level 1 certified payment processor) holds this information directly and provides us only with:
- Stripe customer identifier
- Subscription identifier, status, plan key, billing interval, current period start/end
- Price snapshot (in pence)
- Invoice and payment events (paid, failed, refunded, cancelled, past due).
4.3 Security and anti-fraud data
To prevent account abuse (for example, the same person creating many free-trial accounts, or automated sign-ups by bots), we collect the following at signup and login:
- Signup IP address, taken from standard HTTP headers;
- A device fingerprint (a non-reversible hash derived from browser and hardware characteristics);
- Dates and timestamps of signup, email verification, login, password changes, and account deletion.
These values are written to a short-lived abuse-tracking database that automatically deletes entries ninety (90) days after creation using a database time-to-live index.
4.4 Service usage data
- Conversation history: the messages you send to the AI and the AI's responses, stored against your account in our database until you delete the individual conversation or delete your account.
- Mode of use: whether each query was standard chat, research, extended thinking, drafting, document analysis or image analysis.
- Token usage counters: input and output tokens per day and per billing period, used for rate limiting and billing.
- Audit-log entries recording that an event happened (for example "signup", "login", "chat", "account-delete") together with minimal metadata such as mode and token count. Audit logs do not contain the content of your messages.
- Product usage events: while you use the app we record which features are used, for example that a page was opened, a matter was created or a chat message was sent. Each event holds the time, the page address with any record numbers removed, a random number that groups the events from one open page, held only while that page is open and never saved in your browser, and a few fixed details such as your plan or whether a chat used web search. It is recorded against your account and your firm. It never holds client or matter names or numbers, documents, or anything you type. We use it, on the basis of our legitimate interest, to see how the product is used and to improve it. It stays in our own database, is shared with no one, and is deleted automatically after 180 days, or with your account.
- Desktop app diagnostics: if you use the Writford desktop app, it sends us its own technical log so we can see when something on your computer has gone wrong and put it right: the app version and operating system, what the app was doing (for example that a document was opened, saved back or could not be uploaded, with the file name), warnings and errors, and the times these happened. The log never contains your password, sign-in tokens, the contents of your documents or your messages. It is sent automatically while you are signed in. We keep each day's log for seven (7) days, filed under your account, and then delete it.
4.5 Communication data
If you email us or contact support, we keep a record of the correspondence, including your email address, your name, the date and the contents of the message.
4.6 Website and cookie data
The Service keeps a small amount of information in your browser: the cookies that keep you signed in, short-lived cookies that protect a sign-in or connection while it happens, the live timer's device number, messages you have typed but not sent, and your display choices. Our Cookie Policy lists every item, what it holds, how long it lasts and whether it is sent to us. We do not use advertising cookies, marketing cookies, profiling cookies, or third-party tracking cookies. We use Google Analytics 4 and Ahrefs Analytics in cookieless mode (no cookies set on your device) to collect anonymous, aggregate website statistics (page views, traffic sources). See our Cookie Policy for detail.
4.7 Matter management data
If you use our matter management features, we collect and store the following data server-side in our database on your behalf:
- Matter metadata: matter names, matter references, descriptions, notes, areas of law, matter status and any free-text fields you complete.
- Client and party information: names of clients, counterparties and other entities you enter into matters and conflict-check records, together with entity types and roles (for example, "Individual", "Client").
- Time-tracking data: descriptions of work performed, activity types, durations and dates recorded against a matter. When you use the live timer across our web app and desktop app, we additionally record, for the timer that is currently running, details of the device it started on: a device identifier, the device name (hostname) and operating system, and the IP address. We use these to attribute the timer to the correct device, keep it in sync across your devices, and pause or stop it automatically when that device sleeps or closes. This device information is held only for the active running timer and is discarded when the timer is stopped; it is notretained on the saved time entry.
- Key dates and deadlines: date labels and dates you associate with a matter (for example, "Filing deadline, 15 May 2026").
- Collaboration data: the email addresses of other registered users with whom you share access to a matter.
Lawful basis: We process matter management data under Article 6(1)(b) UK GDPR (performance of the contract to provide the Service to you) and Article 6(1)(f) (our legitimate interest in operating and improving the Service). Where the matter data you enter relates to identifiable third parties (for example, client names or counterparty details), you are the controller of that personal data and we act as your processor (see Section 14).
Retention: Matter management data is retained for as long as your account is active. You may view, export or delete individual matters at any time from within the Service. When you delete your account, all associated matter data stays exactly as it was for ninety (90) days so the deletion can be cancelled, and is then removed from our primary database, subject to backup rotation as described in Section 11.
Security: Matter data is encrypted at rest and in transit using industry-standard ciphers (TLS 1.2 or higher in transit). It is stored in a managed database service operated in the United Kingdom. Access is restricted to the members of your firm, according to the role your firm gives each of them, and to anyone you expressly share a matter with.
AI processing: Matter data is sent to an AI model only when you use a feature that needs it: when you ask the assistant about a matter (it then receives that matter's details and the relevant passages of its documents), when you run a conflict check (it receives the party names being compared), or when you use an AI action inside the document editor (it receives the text you selected). Matter data is never used to train any AI model (see Section 8).
What we do NOT collect
- Location data, GPS coordinates or geolocation
- Biometric data
- Contact lists, microphone, camera or photo-library data (calendar, mail and task data are collected only if you connect Microsoft 365; see Section 6B)
- Social-media profiles or friend graphs
- Advertising identifiers
- Special-category personal data (Article 9 UK GDPR), unless you yourself choose to include such data in a chat message, in which case the controller/processor terms in Section 14 apply.
5. Lawful bases for processing
We process personal data under the following lawful bases (Article 6 UK GDPR):
| Basis | Where it applies |
|---|---|
| Contract, Art. 6(1)(b) | To create and operate your account, deliver the Service you subscribed to (including matter management features), handle payments and invoices, and provide customer support. |
| Legitimate interests, Art. 6(1)(f) | Account security, rate limiting, fraud prevention, abuse prevention, audit logging, business administration, and communicating with you about the Service. We have weighed these interests against your data-protection rights and consider them proportionate: the processing is necessary to prevent abuse of a paid professional service and to maintain the security and stability of the platform, and the impact on individuals is low because only minimal metadata is processed for these purposes. You may object at any time by emailing info@writford.co.uk. |
| Legal obligation, Art. 6(1)(c) | To retain and disclose information where required by law, court order, HMRC, the ICO or another regulator. |
| Consent, Art. 6(1)(a) | Only where expressly asked for (for example, marketing emails, which we do not currently send). You can withdraw consent at any time. |
Where the personal data you input relates to a living person other than yourself, you are the controller of that data and we act as your processor. See Section 14.
6. Files and documents: what we store, where, and for how long
Writford keeps the files you put into it, so your matter file is complete and always there when you need it.
Every stored file is held in encrypted storage in the AWS London region. Only people in your firm who can reach the matter can open it, and your AI conversations are private to you. We never use your files to train any AI model.
6.1 What is stored for each way a file arrives
| How the file arrives | What we keep | How long |
|---|---|---|
| Uploaded to a matter | The original file. For PDFs and images, the text read from it, so the file can be searched and used by the assistant. | Until you delete it (see 6.4). |
| Imported from OneDrive or Google Drive | A copy of the original file, stored as a matter file exactly like an upload. The original stays in your drive. | Until you delete it. |
| An email filed to a matter | Always: the link details listed in Section 6A. Where full email filing is switched on: the complete message, a safe copy of its body for display, and each attachment as a matter file. | Until you remove it from the matter or delete the matter. |
| An email you are writing in Writford and have not sent | The draft: who it is to, the subject, the message and which attachments it names. Only the person writing it can see it. | Until it is sent or discarded, or 30 days after it was last changed. |
| Created in Writford (letters, template documents, bills, court bundles, documents the assistant drafts) | The finished document, in the matter or, for a document the assistant drafts, with the conversation it came from. | Until you delete it or the conversation. |
| Attached to an AI chat message | A working copy of the file and of the text read from it, used to answer you. The text also becomes part of the conversation. | Working copy of the file: deleted automatically after 1 day. Working copy of the text: 7 days. In the conversation: until you delete the conversation. |
| Firm document AI (every plan and the free trial, when your firm switches it on) | The text of your matter documents, divided into short passages, each with a numeric fingerprint that lets the assistant find the relevant passage. Held in our database in London. | Until the document is permanently deleted. |
6.2 Reading the text of PDFs and images
To read the text of a PDF, a scanned page or a photo of a document, the file is passed to Amazon Textract, an AWS text-recognition service, in the London region. AWS reads it on our instruction and does not use it to improve its own services. Word and plain-text files are read in your browser or by our own servers. Court bundles are text-searched on our own servers too, without any AWS AI service.
6.3 Who can open a stored file
- Your firm: the people who can reach the matter, according to the role your firm gave them (a Fee-earner sees their own and shared matters; Supervisors, Cashiers and Administrators see the whole firm's work).
- Your AI conversations: private to the person who wrote them, including from the firm owner.
- Our staff: we do not open customer files in the ordinary course of running the Service. A small number of our engineers have technical access to the storage in order to operate, back up and repair it, and use it only for that purpose or when you ask us to help with a specific problem.
6.4 Deleting a file
- Recycle bin: a deleted file waits in the matter's recycle bin for 30 days, so a mistake can be undone, and is then deleted automatically.
- Deleted for good: the file is removed from live storage straight away. Our storage keeps a recovery copy for up to 90 days to protect against accidental or malicious loss, and then deletes it permanently. Database records follow the 35-day backup cycle in Section 11.
- Account deletion: everything waits unchanged for 90 days so the deletion can be cancelled, and is then erased, followed by the same recovery-copy and backup periods.
Deleting a file in Writford never deletes the original in OneDrive, Google Drive or your mailbox. If a client asks for their data to be erased, those originals must also be deleted there, in the service that holds them.
You should not input data that would breach solicitor–client privilege or your SRA obligations without careful consideration, and you should apply the data-minimisation principle in UK GDPR Article 5(1)(c) when composing messages.
6A. Writford for Outlook add-in
Writford for Outlook is an optional Microsoft Office add-in distributed via the Microsoft Marketplace (formerly AppSource). It runs inside Outlook on the web, Outlook for Windows and Outlook for Mac, and is available only to customers on a paid Writford plan. The add-in extends the Service into your inbox and is governed by this Privacy Policy in addition to all other sections.
When you click an AI action in the add-in's task pane (for example Rewrite, Draft Reply orSummarise), the subject, sender, and body of the email currently open in Outlook are transmitted over HTTPS to Writford's backend, which forwards the request to an AWS AI service for processing. AI requests are processed by Amazon Web Services and may be processed outside the UK under the UK's approved data transfer safeguards (Section 10). The model response is returned to your task pane. Neither the prompt nor the response is stored by Writford.
When you choose to attach an email to a matterfrom the add-in, Writford always stores a link record for that email, consisting of:
- the email subject (truncated to 200 characters);
- the sender display name (truncated to 100 characters) and email address (truncated to 200 characters);
- the send date as reported by Outlook;
- the email's internet message identifier (a value already present in the email's technical headers, used so the add-in can show you which matter an email is attached to when you re-open it);
- the first 300 characters of the email body as a search-preview snippet; and
- the matter identifier the email was attached to.
If your firm has full email filing enabled and has connected its Microsoft mailbox, Writford also stores the complete message as an.eml file and stores its non-inline file attachments in the selected matter. This gives the firm its own matter copy if the mailbox copy is later moved or deleted. If full filing is unavailable, the add-in files only the link details above and tells you that it did so. The original message remains in Microsoft 365 in either case.
You can remove a filed email from the matter through Writford. This removes the link and any stored matter copy, but does not delete or change the original email in Outlook and does not alter the audit trail entry described under Section 4.7.
The add-in first tries Microsoft's nested app authentication to reuse the work account already signed in to Outlook. For that flow, a short-lived Microsoft Graph User.Read access token is sent to Writford's backend only to verify the Microsoft account and match it to a linked Writford account; Writford does not store that Microsoft token. If silent sign-in is unavailable, one Writford sign-in window opens instead. After either route succeeds, Writford issues a 12-hour add-in token, stored in local storage scoped toapp.writford.co.uk. We do not receive your Microsoft account password.
Sub-processors used by the add-in are the same set listed in Section 9 (AWS for the AI call, our managed database for the link record, and AWS for transactional email). International transfers and retention periods are unchanged from Sections 10 and 11; the link record is deleted when the matter is deleted, when you unlink it, or when your account is closed, subject to the same backup-rotation window described in Section 11.
6B. Connected Microsoft and Google services
Every connection below is optional and switched on by you. Each one asks Microsoft or Google for a stated set of permissions, and the consent screen shows them before you agree. Where a connection keeps working after you close your browser, Writford holds a long-lived access key (a "refresh token") for it, encrypted with AES-256.
| Connection | What Writford can reach | What Writford keeps |
|---|---|---|
| Sign in with Microsoft | Your name and email address, and read access to the files in your OneDrive, kept available so an import you start can carry on after you close your browser. | The encrypted refresh token. |
| OneDrive file browser (matter files and chat) | Lets you browse and search your OneDrive to choose files or folders. | A copy of each file you choose (Section 6.1). |
| OneDrive folder import | Every file inside the folders you select, up to six folder levels deep. | A copy of each file, filed into the matter it creates. |
| Microsoft 365 email | Read, file and send email from your own address. Writford is told when a new message arrives and reads its sender, subject and date to recognise replies in conversations you follow and to suggest the matter an email belongs to. It lists the details of your most recent messages when you sort your inbox. | The encrypted refresh token; a link record for each email you file or follow; the full email and its attachments where full email filing is switched on. |
| Microsoft 365 calendar | Read and write your default Outlook calendar. Writford adds your matter dates to it, and appointments you create there appear in your Writford diary, private to you unless you attach one to a matter. | The encrypted refresh token; the title, time, place and notes of each appointment. |
| Microsoft To Do | Only the "Writford" task list, kept in step both ways. | The encrypted refresh token; the tasks in that list. |
| Writford for Outlook add-in | Confirms who you are (Section 6A). | Nothing from Microsoft's sign-in. |
| Sign up with Google | Your name and email address, and access to the Google Drive files you choose through Writford (and no others). | The encrypted refresh token. |
| Google Drive file picker | Only the files you pick. | A copy of each file you choose (Section 6.1). |
| Sign in with Apple | Your name and email address. | The encrypted refresh token, withdrawn at Apple when you delete your account. |
How connected data is used: only to provide the feature you switched on. It is not used for advertising, profiling or AI model training.
Google Limited Use: Writford's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not transferred to, or used by, any third party other than as necessary to provide the features described above.
Disconnecting: disconnecting a service in Writford deletes the access key we hold and stops all background syncing. Writford then stays listed as an app you once approved in your Microsoft or Google account until you remove it there, at Microsoft account permissions or Google account permissions. Copies already filed in Writford stay in the matter until you delete them. Your originals in Microsoft and Google are always safe: Writford never deletes an email, appointment, task or file there.
7. How we use personal data
We use the personal data described in Section 4 for these purposes only:
- to create, authenticate and administer your account, including automated abuse-prevention checks against IP, device and email signals to prevent bulk sign-ups;
- to deliver the AI features you subscribed to (chat, research, extended thinking, drafting, document analysis, image analysis);
- to provide the matter management features, including storing matter metadata, time entries, key dates, conflict records and collaboration data on your behalf;
- to enforce rate limits and the monthly token budget associated with your subscription;
- to detect and prevent fraud, credential-stuffing, abuse of free trials, brute-force login attempts and prompt-injection attacks;
- to issue invoices and process payments via Stripe;
- to send transactional emails (verification, welcome, password reset, billing and security alerts) via an AWS transactional email service in the UK region;
- to maintain an audit trail of security-relevant events;
- to respond to support requests and handle complaints;
- to comply with law and respond to lawful requests;
- to establish, exercise or defend legal claims.
We do NOT:
- use your personal data, queries, documents or conversation history to train, fine-tune or develop any AI model;
- sell, rent, barter or licence your personal data to any third party;
- use your personal data for advertising, retargeting or profiling;
- engage in solely-automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 UK GDPR (see Section 16).
8. AI processing and no model training
The AI features of the Service are powered by large language models accessed through AWS inference services. AI requests are processed by Amazon Web Services and may be processed outside the UK under the UK's approved data transfer safeguards (Section 10). The companies that build the models never receive your queries, your documents or the responses: AWS runs the models in its own accounts.
AWS is contractually prohibited from using any data submitted through its inference services (including your queries, uploaded document text and conversation history) to train, retrain or improve any foundation model. AWS does not keep your prompt or the response after the request completes, with one exception: for some models, which may include the one behind the main chat assistant, AWS's automated abuse checks can keep a request they flag for up to 30 days, inside AWS and without sharing it with the company that built the model. The AWS text-recognition service that reads PDFs and images (Section 6.2) works on the same terms: it does not keep your documents or use them to improve its own services.
Every AI response is clearly labelled as AI-generated and carries a mandatory disclaimer that it must be reviewed by a qualified solicitor before being relied upon. Every exported document is watermarked "DRAFT - FOR SOLICITOR REVIEW ONLY". See our AI Policy for more detail.
9. Sub-processors
We use a small, fixed set of third-party service providers ("sub-processors") to operate the Service. All are contractually bound not to use customer data for their own purposes and not to train AI models on that data. A summary is published at writford.co.uk/sub-processors, and the up-to-date list is available on request via info@writford.co.uk.
As of the date of this policy, our sub-processors are:
- Amazon Web Services EMEA SARL: cloud hosting, the database (Amazon DocumentDB), encrypted file storage (Amazon S3), text recognition for PDFs and images (Amazon Textract) and transactional email, all in the UK region; and AI inference, which may be processed outside the UK under the UK's approved data transfer safeguards (Section 10).
- Stripe Payments Europe, Limited: subscription billing and payment processing. Stripe does not receive your chat messages, uploaded documents, AI responses or audit-log data.
- An independent web-search API: used to surface UK legal sources for your question. It receives the search query the assistant writes and returns links. The assistant searches a fixed list of UK legal and government sources first and ranks those above everything else; a small number of ordinary web results may also be returned, ranked below them. The assistant is instructed to put only the legal question and public facts (a court, a company, a statute, a case) in that query, and to leave out your client's identity and the private details of the matter. It does not receive your documents, files or conversation history.
- The National Archives (caselaw.nationalarchives.gov.uk): UK case-law search.
- legislation.gov.uk: UK legislation search.
- Google LLC: Sign in with Google and the Google Drive file picker (Section 6B). Google does not receive your chat messages or matter data. Our use is governed by the Google API Services User Data Policy.
- Microsoft Corporation: Sign in with Microsoft, OneDrive, Microsoft 365 email, calendar and To Do (Section 6B), and the Microsoft Office Add-in Marketplace, which distributes the Writford for Outlook add-in (Section 6A). Microsoft receives what you ask Writford to put into your own Microsoft account: the emails you send, the matter dates added to your calendar and the tasks in your Writford task list. It does not receive your chat messages or AI responses.
- Apple Inc.: Sign in with Apple. Apple receives nothing beyond the sign-in itself.
We will notify account administrators by email at least thirty (30) days before adding a new sub-processor. You may object during that notice period; if your objection cannot be resolved, you may terminate your subscription without penalty.
We use Google Analytics 4 (cookieless, client_storage: 'none', anonymised IP) and Ahrefs Analytics (cookieless) for aggregate website statistics. Neither service sets cookies on your device. We do NOT use Meta Pixel, LinkedIn Insight Tag, Segment, Mixpanel, Hotjar, Clarity, PostHog, Cloudflare Analytics, or any comparable advertising, profiling, or behavioural tracking service.
10. International data transfers
Your personal data is stored in the United Kingdom, in the AWS London region. AI requests are processed by Amazon Web Services and may be processed outside the UK under the UK's approved data transfer safeguards: AWS may answer them in any of its regions worldwide. Search queries the assistant sends to our web-search provider, and anything you exchange with Microsoft, Google or Apple when you connect them, may be processed in the United States.
Where a sub-processor (for example, AWS for AI requests, our payment processor or a search-API provider) has global operations and personal data may be transferred to a country outside the UK or EEA in connection with AI, billing, search or support, the transfer is protected by one of the transfer tools recognised by the UK GDPR:
- a UK adequacy decision;
- the International Data Transfer Agreement ("IDTA"); or
- the UK Addendum to the EU Standard Contractual Clauses.
We do not transfer personal data to any jurisdiction for the purpose of AI model training. For AI requests processed outside the UK we rely on AWS's data processing terms, which include the EU Standard Contractual Clauses with the UK Addendum. You can ask us for a copy at info@writford.co.uk.
11. Data retention
| Data | Retention |
|---|---|
| Account record | Until you delete your account. On deletion, kept unchanged for 90 days so you can cancel, then removed from our primary database; encrypted backups rotated thereafter. |
| Individual conversations | For as long as your account exists, unless you delete the conversation yourself. |
| Stored files, filed emails and documents created in Writford | Until you delete them. Deleted files wait 30 days in the recycle bin, then are removed. A recovery copy is kept in storage for up to 90 days after removal, then permanently deleted (Section 6.4). |
| Working copies of chat attachments | File: 1 day. Text read from it: 7 days. Both deleted automatically. |
| Firm document AI passages | Until the document they came from is permanently deleted. |
| Connected-service access keys (refresh tokens) | Until you disconnect that service or delete your account. |
| Matter management data (matter metadata, client/party information, time entries, key dates, conflict records, collaboration data) | For as long as your account exists, unless you delete the individual matter yourself. On account deletion, kept unchanged for 90 days so you can cancel, then erased. |
| Audit logs (activity history) | While your account exists, 6 years from the date each entry is written, then automatically deleted. When you delete your account, the activity history is erased with everything else once the 90-day cancellation period ends; export it first if you need to keep it. Entries relating to a matter under legal hold are kept until the hold is lifted. |
| Product usage events | 180 days, then deleted automatically; erased sooner if you delete your account. |
| Security / abuse tracker (signup IP, device fingerprint) | 90 days, then automatically deleted by database TTL index. |
| Rate-limit counters | Up to 90 days, then automatically deleted by database TTL index. |
| Your firm's accounts and registers (ledger, client and office balances, reconciliations, complaints, breaches and similar registers) | For as long as your account exists. On account deletion, kept unchanged for 90 days so you can cancel, then erased with everything else. We keep no copy, so download everything first (Settings, Security) if the rules require you to keep them. |
| Our own bills to you (your Writford subscription) | 6 years (HMRC tax and VAT record-keeping requirement; this also satisfies the accounting-records duty under the Companies Act 2006). |
| Support correspondence | Up to 2 years from date of last contact. |
| Our record of a data protection request you make to us (what you asked, the checks we made and our answer) | 6 years after we answer, then deleted automatically. It is kept even if you delete your account, because it is how we show the request was handled. |
| Our record of the emails we send you about changes to our sub-processors, and any objection you make | 6 years after the change takes effect or is withdrawn, then deleted automatically. |
| Database backups | 35 days, rolling. Data deleted from the live database leaves the backups within 35 days. |
If a legal obligation requires us to retain personal data for longer (for example, a litigation hold), we will retain the relevant data only for as long as that obligation applies.
12. Your rights under UK GDPR
You have the following rights in relation to your personal data:
- Right to be informed: this Privacy Policy is how we inform you.
- Right of access: ask for a copy of the personal data we hold about you.
- Right to rectification: ask us to correct inaccurate or incomplete data.
- Right to erasure: ask us to delete your account and associated data. You can do this yourself from account settings, or by emailing us.
- Right to restrict processing: ask us to stop actively using your data in certain situations.
- Right to data portability: ask for your account data in a structured, machine-readable format.
- Right to object: object to processing carried out on the basis of legitimate interests.
- Rights in relation to automated decision-making: we do not carry out such decision-making (see Section 16).
- Right to withdraw consent: where we rely on consent.
- Right to complain: to the Information Commissioner's Office at ico.org.uk or 0303 123 1113.
To exercise any right, email info@writford.co.uk, write to us, or tell anyone at Writford, including our support team. You do not need to use any particular words or form. We record every request on the day it reaches us and answer within one month. If we cannot be reasonably sure who you are, we will ask for proof, and the month starts when it arrives. If you ask for a copy of a large amount of information, we may ask what exactly you want, and the month pauses until you tell us. If a request is complex, or you have made several, we may take up to two further months; if so, we will tell you why within the first month. There is no charge for most requests; we reserve the right to charge a reasonable fee or refuse if a request is manifestly unfounded or excessive, and if we refuse we will tell you why and that you can complain to the ICO.
13. How we protect your data
Our technical and organisational measures include:
- All production hosting and data storage in the UK on reputable cloud providers (AWS in the UK region for compute, storage and transactional email; a managed database service in the UK region). AI inference also runs on AWS, which may process requests outside the UK under the UK's approved data transfer safeguards (Section 10).
- TLS 1.2 or higher for all connections.
- Stored files and the database encrypted at rest with AES-256, managed by AWS; access keys for connected services additionally encrypted by us with AES-256.
- Passwords stored only as one-way hashes produced by an industry-standard slow hashing algorithm. We can never see or recover your plain-text password.
- Short-lived signed session tokens delivered in secure, HTTP-only cookies, with token-versioning that lets us invalidate all sessions instantly.
- Server-side rate limiting (per minute and per day) against brute-force and abuse.
- Input validation and a prompt-injection filter on all AI inputs.
- Mandatory email verification (6-digit code) plus automated trial-abuse signalling on IP, device fingerprint and normalised email before a new account receives a trial.
- Separation of sub-processors (Stripe for payments, AWS for hosting, storage and AI) so payment card details never reach the provider that holds your documents.
- Audit logging of security-relevant events.
- A documented incident-response procedure, including our obligation under Article 33 UK GDPR to notify the ICO within 72 hours of becoming aware of a personal data breach likely to result in a risk to individuals.
No system is perfectly secure. You also play an important role: use a strong, unique password, do not share your login, log out of shared devices, and keep your device and browser up to date.
14. Controller / processor relationship
Where your use of the Service involves processing personal data relating to your own clients, counterparties, witnesses or other third parties (for example, when you ask the AI to analyse a contract that names identifiable individuals, or when you enter client names, party details or case information into the matter management features), you are the controller of that personal data and we are your processor.
In that role:
- We process that personal data only on your documented instructions (your chat messages).
- We apply the measures in Section 13.
- We do not use that data for any purpose other than providing the Service to you.
- We delete that data on your instruction or when your account is deleted, subject to backup rotation in Section 11.
- We do not engage any sub-processor beyond Section 9 without following the notice process there.
- We will assist you, to the extent reasonably required, in responding to data-subject requests and DPIAs, on payment of our reasonable costs where the assistance is not trivial.
If you are a law firm that requires a separate written Data Processing Addendum signed on its own letterhead, please email info@writford.co.uk.
15. Children
The Service is a business-to-business product aimed at qualified legal professionals. It is not directed at children, and we do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact info@writford.co.uk and we will delete it.
16. Automated decision-making and profiling
The Service uses AI language models accessed through AWS to generate responses. We do not consider this "automated decision-making which produces legal or similarly significant effects" within the meaning of Article 22 UK GDPR, because:
- every response is clearly labelled as AI-generated;
- every response carries a mandatory disclaimer that it must be reviewed by a qualified solicitor before being relied upon;
- every exported document is watermarked "DRAFT - FOR SOLICITOR REVIEW ONLY";
- no decision about you, your clients or any third party is taken by the AI. All decisions remain with the human solicitor, who retains full professional responsibility.
We do not carry out profiling of users for marketing, pricing, credit-scoring or any other purpose.
17. Law enforcement and lawful requests
We will only disclose personal data to law enforcement, regulators or government authorities where we are compelled to do so by a lawful order (for example, a court order, a production order, or a valid statutory notice) addressed to Big Berri Limited in the United Kingdom, or where we reasonably believe in good faith that disclosure is necessary to prevent an imminent risk of death or serious physical harm. We review every request individually and challenge overbroad, improperly served or invalid requests.
18. Limitation of liability for data-related claims
Important: please read carefully.
This Section must be read together with the limitation-of-liability provisions in our Terms of Service. It applies to you as a business user purchasing the Service for use in your trade or profession.
The Service is provided to you as a business user at a low subscription price. That pricing model is only possible because our aggregate financial exposure is capped at a commercially realistic level. Accordingly:
(a) Subject to paragraph (c) below, to the maximum extent permitted by law our total aggregate liability to you for any and all claims of any kind whatsoever arising out of or relating to the processing of personal data (including, without limitation, any claim under or in connection with the UK GDPR, the Data Protection Act 2018, the common law of confidence, negligence, breach of contract, breach of statutory duty, misrepresentation, or any other legal theory) is limited to the greater of: (i) fifty pounds sterling (£50.00); or (ii) the fees you have paid to Big Berri Limited for the twelve (12) months immediately preceding the event giving rise to the claim, counting the part of any longer up-front term payment that covers those twelve months, shared out evenly over the term.
(b) The cap in paragraph (a) applies per account and across the entire lifetime of your relationship with us. It is a single aggregate cap, not a per-incident cap. It uses the same formula as the overall liability cap in our Terms of Service.
(c) Nothing in this Privacy Policy or in our Terms of Service limits or excludes any liability that cannot be limited or excluded as a matter of the law of England and Wales, including liability for:
- death or personal injury caused by negligence;
- fraud or fraudulent misrepresentation;
- any statutory right of a data subject under the UK GDPR that cannot lawfully be limited by contract (in particular, any right to compensation under Article 82 UK GDPR, to the extent that such right cannot lawfully be capped);
- any other liability that cannot be limited or excluded as a matter of law.
(d) We will not be liable for any indirect, consequential, special, incidental, punitive or exemplary loss or damage, loss of profits, loss of goodwill, loss of reputation, loss of opportunity, loss of business, loss of revenue, or loss of anticipated savings, howsoever arising, in each case to the maximum extent permitted by law.
(e) We will not be liable for any loss, damage, fine, regulatory action or disciplinary finding (including any finding by the Solicitors Regulation Authority, the Legal Ombudsman or any professional body) that results wholly or partly from:
- your decision to input personal data, privileged information, or confidential client data into the Service;
- your reliance on an AI-generated response without the independent review of a qualified solicitor;
- your failure to follow the security best-practices described in Section 13 (such as sharing your password or logging in on a compromised device); or
- any third-party service, network, platform or device outside our reasonable control.
(f) You acknowledge that: (i) the fees for the Service are low precisely because this cap is in place; (ii) you are a business user purchasing the Service for use in your trade, business or profession; (iii) the cap was agreed between business parties and has been expressly drawn to your attention in this Privacy Policy and in our Terms of Service; and (iv) you have had the opportunity to obtain independent legal advice before agreeing to the cap. You further agree that, having regard to these matters, the cap is reasonable for the purposes of section 3 of the Unfair Contract Terms Act 1977.
This Section does not affect the statutory rights of data subjects to bring claims directly under Article 82 UK GDPR to the extent those rights cannot lawfully be limited by contract, and it does not replace the statutory breach- notification obligations we owe under Articles 33 and 34 UK GDPR.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our practices, our sub-processors or our product. When we make a material change, we will:
- update the "Last updated" date at the top of this page;
- post a notice on the website; and
- where we have your email address, email you at least fourteen (14) days before the change takes effect.
The current version is always available at writford.co.uk/privacy. By continuing to use the Service after a change takes effect, you confirm that you accept the revised Privacy Policy.
20. How to contact us
If you have any questions about this Privacy Policy, wish to exercise any of your rights, or want to raise a concern about how we handle your personal data, please contact:
Big Berri Limited
(trading as "Writford")
Company number: 16562429
(England and Wales)
ICO registration number: ZC119995
Email: info@writford.co.uk
Website: https://writford.co.uk
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Telephone: 0303 123 1113