Snapshot 77679
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy Policy
ClientLogic (Provided by Intakelogic Ltd)
Last updated June 2025
1. Introduction
Intakelogic Ltd ("we", "us", or "our") is the company behind ClientLogic, a client management platform designed for law firms. This Privacy Policy covers our handling of personal data across all three of our services:
Our marketing website at client-logic.com (the "Website")
The ClientLogic web application (the "Web App")
The ClientLogic mobile application for iOS and Android (the "Mobile App")
Together these are referred to as our "Services".
This policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights in relation to it.
Our registered address is available on request. You can contact us using the details in Section 14.
2. Our Role as Controller and Processor
Our relationship with personal data differs depending on which part of our Services is being used. This distinction matters because it determines who is responsible for your data and who you should contact to exercise your rights.
Context Our role
Marketing website (client-logic.com) Data controller — we determine why and how your data is used
Firm administrator and billing contacts Data controller — we hold your details to manage the commercial relationship
ClientLogic web app and mobile app (end users provisioned via firm SSO) Data processor — we process personal data on behalf of your firm, which is the data controller
End users of the Web App and Mobile App (i.e. individuals at law firms who access ClientLogic via their firm's single sign-on): Your firm has contracted with Intakelogic Ltd to provide the ClientLogic platform and has provisioned your access. Your firm is the data controller for the personal data you submit or generate within the platform. Intakelogic processes that data strictly as a data processor, acting on the firm's documented instructions under a Data Processing Agreement (DPA). If you wish to access, correct, or delete your data within the platform, please contact your firm's administrator in the first instance.
Website visitors and firm contacts: Intakelogic Ltd is the data controller for personal data collected through the Website and for data relating to firm administrators, billing contacts, and others involved in the commercial relationship. The remainder of this policy applies to data processed in this capacity.
3. Personal Data We Collect
We collect only data that is necessary for the relevant purpose.
3.1 Data You Provide Directly
Full name and job title
Work email address and telephone number
Company or firm name and address
Communication and notification preferences
Any other information you voluntarily submit through forms, enquiries, or support requests
3.2 Data Collected Automatically
When you visit our Website or use the Web App or Mobile App, we may automatically collect:
Device information (device type, operating system version, browser type and version)
Usage data (pages visited, features accessed, session duration, button interactions)
Crash logs and diagnostic information
IP address (used only for security, fraud prevention, and approximate geolocation for analytics)
Cookie and tracking data — see Section 8 for full details
We do not collect your precise location, contacts, photos, camera, or microphone data unless you have explicitly granted permission and a specific feature requires it.
3.3 Data Received from Firms (as Processor)
When law firms use the ClientLogic platform, they may upload or generate personal data relating to their clients and matters. This may include names, contact details, and case-related information. Intakelogic processes this data solely on the firm's instructions and does not use it for any other purpose.
4. How and Why We Use Your Data
We process personal data (in our capacity as controller) only where we have a valid legal basis under UK GDPR. The table below sets out our processing purposes and the corresponding legal basis.
Purpose Legal Basis (UK GDPR)
To operate and maintain the ClientLogic platform for contracted law firms Contract performance (Art. 6(1)(b))
To provision user access via the firm's SSO integration Contract performance (Art. 6(1)(b))
To send service notifications, technical updates, and security alerts Contract performance (Art. 6(1)(b))
To respond to support requests and provide customer assistance Contract performance / Legitimate interests (Art. 6(1)(f))
To detect, investigate, and prevent fraud, abuse, or security incidents Legitimate interests (Art. 6(1)(f))
To comply with legal and regulatory obligations Legal obligation (Art. 6(1)(c))
To send marketing communications about our products and services Consent (Art. 6(1)(a)) — you may withdraw at any time
To analyse website and platform usage to improve our services Legitimate interests (Art. 6(1)(f)) or Consent (where analytics cookies / SDKs are used)
To manage our commercial relationship with client firms Contract performance / Legitimate interests (Art. 6(1)(f))
5. How We Share Your Data
We do not sell, rent, or trade your personal data. We may share it only in the following limited circumstances:
Sub-processors and service providers: Trusted third-party providers that host our infrastructure, process payments, and deliver analytics. These parties are appointed under written data processing agreements and may only use your data to provide services on our behalf. A list of our current sub-processors is available on request.
Law firms (as controller): Where we are acting as a data processor, we share data back with the relevant firm in accordance with our DPA with that firm.
Legal and regulatory requirements: Where required by law, court order, or to protect the rights, property, or safety of Intakelogic Ltd, our users, or others.
Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
With your explicit consent: For any sharing not described above.
6. International Data Transfers
Intakelogic Ltd is based in the United Kingdom. Where we or our sub-processors transfer personal data to countries outside the UK or the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or UK-approved Standard Contractual Clauses (SCCs). Details of the safeguards in place for any specific transfer are available on request.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes in this policy, or as required or permitted by law.
Account and firm contact data: Retained for the duration of the contract plus up to 3 years after termination to satisfy legal and business obligations.
Platform data (processed as processor on behalf of firms): Retained in accordance with the applicable DPA. Firms may request deletion at any time; data is purged within 30 days of a verified deletion request or contract termination.
Website analytics data: Retained for a maximum of 12 months, then automatically deleted or anonymised.
Marketing consent records: Retained while you remain subscribed, plus 2 years after unsubscribing as evidence of consent.
Support and communications: Retained for up to 3 years from the date of last contact.
When data is no longer required, we securely delete or anonymise it.
8. Cookies and Tracking Technologies
8.1 Website
Our Website uses cookies and similar tracking technologies. We use three categories:
Essential cookies: Strictly necessary for the Website to function. No consent is required.
Analytics cookies: Help us understand how visitors use the Website (e.g. Google Analytics). Activated only with your consent.
Marketing cookies: Used to deliver relevant communications and measure campaign effectiveness. Activated only with your consent.
You can manage or withdraw your cookie consent at any time at Cookie Settings. Withdrawing consent does not affect any processing carried out before withdrawal.
8.2 Web App and Mobile App
The Web App and Mobile App do not use advertising cookies. They may use analytics SDKs (software development kits) to collect aggregated, anonymised usage data to help us improve the product. Where such SDKs are used, they are activated only with your consent or, where applicable, under a legitimate interests assessment. You can opt out of analytics data collection at any time in the app settings.
9. Children's Privacy
Our Services are business-to-business products intended solely for use by professionals at law firms. They are not directed at, or intended for use by, individuals under the age of 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us immediately and we will delete it promptly.
10. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, or disclosure. These include:
Encryption of data in transit using TLS (Transport Layer Security)
Encryption of data at rest
Role-based access controls and SSO-enforced authentication
Regular security assessments and penetration testing
Staff training on data protection and information security
Documented incident response and breach notification procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and will inform affected individuals without undue delay where required by law.
No method of transmission or storage is entirely secure. If you discover a security concern related to our Services, please contact us immediately at the address in Section 14.
11. Your Rights Under UK GDPR
Where Intakelogic Ltd is the data controller, you have the following rights. You can exercise them free of charge by contacting us (Section 14). We will respond within one calendar month; if your request is complex, we may extend this by up to a further two months and will notify you within the first 30 days.
Right of access: Request a copy of the personal data we hold about you.
Right to rectification: Ask us to correct inaccurate or incomplete data.
Right to erasure ('right to be forgotten'): Ask us to delete your data where there is no compelling reason for continued processing.
Right to restrict processing: Ask us to pause processing in certain circumstances.
Right to data portability: Receive your data in a structured, commonly used, machine-readable format.
Right to object: Object to processing based on legitimate interests or for direct marketing purposes (which we will always honour immediately).
Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
Rights related to automated decision-making: The right not to be subject to a solely automated decision that produces a legal or similarly significant effect. We do not currently carry out such processing.
If you are an end user of the Web App or Mobile App provisioned by your firm, your firm is the data controller for the data you submit within the platform. Please direct data rights requests to your firm's administrator in the first instance. We will cooperate with firms to assist in fulfilling such requests under the terms of our DPA.
You also have the right to lodge a complaint with the UK's supervisory authority: Information Commissioner's Office (ICO) · ico.org.uk/make-a-complaint · 0303 123 1113
12. Third-Party Links and Services
Our Services may contain links to third-party websites or integrations with third-party services (for example, your firm's identity provider for SSO). We are not responsible for the privacy practices of those third parties, and this Privacy Policy does not apply to them. We encourage you to review the privacy policies of any third-party services you use in connection with ClientLogic.
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will notify you via the Services or by email at least 14 days before the changes take effect. The "Last updated" date at the top of this document will always reflect the most recent revision. Continued use of our Services after any update constitutes acceptance of the revised policy.
14. Contact Us
For any questions about this Privacy Policy, to exercise your data rights, or to raise a concern, please contact us:
Intakelogic Ltd
Privacy and data protection enquiries: privacy@client-logic.com
General enquiries: info@client-logic.com
Website: www.client-logic.com
We aim to respond to all requests within 30 calendar days. Where a request is complex or you have submitted multiple requests, we may extend this by up to a further two months and will inform you within the first 30 days.
We value your privacy
We use cookies to enhance your browsing experience, analyze site traffic, and provide personalized content. Essential cookies are always enabled to ensure the site functions properly.