LEGAL

Processors and third parties

Last updated 15 September 2026

Lawyerly Ltd is the controller of the personal data it handles for clients, prospective clients and the people connected with their matters. This page lists the organisations that process that data on our instructions and, where stated, those that act as controllers in their own right, with what each does, where data is held and the safeguard that applies when data leaves the United Kingdom.

Material changes are notified as described in our Privacy Notice.

Lawyerly Group and its technology partners

  1. Lawyerly GroupTechnology provider

    The South African parent of Lawyerly Ltd and our technology provider. Hosts and operates our case management platform, the Client Hub and our Microsoft 365 environment on our instructions as our processor, under a data processing agreement and an International Data Transfer Agreement. Provides no legal services and has no independent access to the content of client matters.

    South AfricaUK IDTA, supported by a Transfer Risk Assessment

  2. ShftPlatform engineering, hosting operations and IT security

    Engaged by Lawyerly Group to build and maintain the platform, operate the production infrastructure and administer our IT and security. Hosting runs on Microsoft Azure in the Netherlands, with SendGrid for transactional email and Elastic for system logs. Access to client data is limited to what technical operations require, granted on a least-privilege basis, time-bound and logged.

    South AfricaUK IDTA with Lawyerly Ltd, supported by a Transfer Risk Assessment

  3. Seek the JustMarketing operations

    Supports our marketing operations, processing the contact data of prospective clients and people who engage with our marketing channels, on our documented instructions and for our marketing only.

    South AfricaUK IDTA, supported by a Transfer Risk Assessment

Service providers

  1. MicrosoftEmail, documents and productivity (Microsoft 365)

    Provides our Microsoft 365 environment for email, documents and collaboration. The tenant is provisioned in the United Kingdom. Microsoft Corporation is US-incorporated, so the UK Extension to the EU-US Data Privacy Framework covers any access from the United States.

    United Kingdom (tenant hosting); United States (parent company)UK Extension to the EU-US Data Privacy Framework

  2. StripePayment processing (independent controller)

    Processes subscription and invoice payments. Stripe decides how it handles payment data and is a controller of that data in its own right, so its own privacy notice applies. Full card details are handled by Stripe under PCI DSS and are not stored by Lawyerly.

    United States and Republic of IrelandUK Extension to the EU-US Data Privacy Framework

  3. HubSpotCRM, website and marketing

    Hosts our website and holds contact records, enquiry forms and marketing engagement data. Our account is hosted in HubSpot's EU data region.

    European Union (hosting); United States (parent company)UK Extension to the EU-US Data Privacy Framework

  4. Auth0Identity and access management for the Client Hub

    Provides sign-in, multi-factor authentication and user account management for the Client Hub. Our tenant is hosted in the European Union. Auth0 is part of Okta, Inc., a US company.

    European Union (hosting); United States (parent company)UK Extension to the EU-US Data Privacy Framework

  5. SendbirdIn-app messaging in the Client Hub

    Powers messaging between clients and their solicitor inside the Client Hub. Our workspace is hosted in Frankfurt.

    Germany (Frankfurt hosting); United States (parent company)Standard Contractual Clauses with UK Addendum

  6. ComplyCubeIdentity verification and AML screening (independent controller)

    Performs the identity verification and anti-money laundering checks we must carry out on clients and the people who own or represent them. ComplyCube is a controller in its own right of certain verification records, and its own privacy notice applies to them. Registered with the Information Commissioner's Office and certified under the UK digital identity and attributes trust framework.

    United KingdomIntra-UK; no transfer mechanism required

  7. AnthropicAI tools supporting legal work

    Provides the Claude models our team uses for research, drafting, summarising and document review under our supervision, through Anthropic's commercial services and under written terms that prohibit use of our data for model training. Our solicitors remain responsible for all advice and work product.

    United StatesStandard Contractual Clauses with the UK Addendum, supported by a Transfer Risk Assessment

  8. FirefliesMeeting transcription (with consent)

    Records and transcribes meetings where participants have been told and have consented. Transcripts are moved to our case management platform and deleted from Fireflies shortly afterwards.

    United StatesStandard Contractual Clauses with UK Addendum, supported by a Transfer Risk Assessment

  9. monday.comInternal registers and operations

    Used for our internal compliance and operational registers. Personal data appears only where matter or supplier records refer to identifiable individuals.

    Germany (EU data centre)UK adequacy regulations