Roles and scope
This addendum applies where ANT LLP operates an AntChambers private instance for a subscribing firm. It forms part of the signed order and master services agreement between us.
- The firm
- Data Fiduciary. It decides what personal data enters the instance, who may see it, and how long it stays.
- ANT LLP
- Data Processor. We handle that data only to operate the service, on the firm’s instructions.
The data covered is everything the firm places in its instance: clients and contacts, matters, opposing parties, timesheet entries, expenses, bills and receipts, documents, and the firm’s own user accounts and audit records.
Processing only on instruction
We process firm data only to:
- Run, maintain and support the instance.
- Apply tested releases and security updates.
- Take, verify and restore backups.
- Investigate a fault the firm has reported, or one our monitoring has raised.
- Perform a migration, export or restore the firm has asked for.
- Comply with a legal obligation binding on us.
And we commit that we will not:
- Use firm data to train machine-learning models, our own or anyone else’s.
- Aggregate it into benchmarks, market reports or product analytics, whether identified or de-identified.
- Pool it with another firm’s records. Each firm has a separate instance, database, document store and backup boundary.
- Sell, licence or share it with anyone outside the sub-processor list in clause 05.
- Access it for any purpose beyond the list above.
If we believe an instruction from the firm would breach applicable data protection law, we will say so and will not act on it until it is resolved.
Confidentiality and privilege
A law firm’s records carry obligations most customer data does not. Material in an instance may be subject to legal professional privilege and to the firm’s professional duty of confidence, and we treat it accordingly.
- Our personnel are bound by written confidentiality obligations that survive their engagement.
- Access is limited to named personnel who need it for a specific task, under written confidentiality obligations.
- Nothing we do is intended to waive privilege. If we receive a demand for firm data, we will not assert or waive privilege on the firm’s behalf.
Security measures
We maintain, at a minimum, the measures below. We may improve them; we will not weaken them during a subscription.
- One dedicated application stack, PostgreSQL database, document store and backup boundary per firm.
- Encryption of traffic in transit, with certificates managed as part of the service.
- Authentication by email and password with optional second factor; lockout on repeated failure; passwords stored irreversibly hashed.
- Per-module authorisation enforced server-side, not by hiding controls in the interface.
- An attributed audit trail of changes and sign-ins, attributed to a person and a time.
- The standard service scope includes daily encrypted off-server database and document backups retained for 30 days. These are scheduled backups, not point-in-time recovery; the service schedule records recovery arrangements.
- The standard service scope requires a restore test before launch and quarterly thereafter, using a separate recovery environment. Verification and responsibilities are recorded in the service schedule; failed verification is treated as an incident.
- Administrative access for our operations personnel is separate from firm user accounts and is not routed through them.
Sub-processors
The complete list. Each is bound by written terms no less protective than this addendum.
The current list is supplied with the order and on request before you buy, naming each sub-processor, what it does and where it is. We would rather give you a list that is accurate on the day you read it than one on a web page that has drifted. Every entry is bound by written terms no less protective than this addendum, and the notice and objection rights below apply to all of them.
Before we add or replace a sub-processor we give subscribing firms 30 days’ notice. A firm that reasonably objects on data protection grounds may raise it with us, and if we cannot resolve the objection the firm may terminate the affected service without penalty for the remainder of its term.
Requests from data principals
If someone contacts us directly asking to see, correct or erase data held in a firm’s instance, we do not act on it. We tell them to approach the firm and we tell the firm we heard from them.
That is not obstruction. The firm, not us, knows whether the person is who they claim to be, whether the material is privileged, and whether disclosing it would harm another client. We assist the firm in responding — locating records, producing exports — at no additional charge for a reasonable volume of requests.
Breach notification
If we become aware of a personal data breach affecting a firm’s instance, we notify that firm on this timetable, whether or not the cause reflects well on us:
- Within 48 hours of becoming aware
- Initial notice: what we know, which instance is affected, and what we are doing.
- Within 72 hours
- Fuller report: categories and approximate volume of data involved, likely consequences, and the measures taken or proposed.
- Continuing
- Updates as the investigation develops, and a written post-incident report on closure.
The firm, as Data Fiduciary, is responsible for notifying the Data Protection Board of India and affected data principals. We give the firm what it needs to do that, promptly and without charge.
We will not delay a notification because the cause is embarrassing, unresolved, or ours.
Audit and assurance
A firm may satisfy itself that we are doing what this addendum says. On reasonable notice and no more than once a year — or at any time following a breach affecting its instance — a firm may:
- Ask us in writing about our security measures and receive a substantive answer.
- Request the access log for its own instance.
- Audit us, or appoint an independent auditor bound by confidentiality, at the firm’s cost.
An audit must not compromise another firm’s confidentiality, and we may require an auditor who is not one of our competitors.
Location and transfers
Instances, databases, document stores and backups are hosted inIndia, on infrastructure named in the sub-processor list supplied with the order.
We do not transfer firm data outside India. Any change would require the firm’s written agreement, recorded on its order, before it took effect.
Return and deletion
Ending a subscription does not strand the firm’s records.
- Export
- The firm may request a complete export of its data at any time during the subscription and throughout the retention window. We produce it — as a database dump plus the document store — within ten working days, at no charge. Reports and the audit trail can additionally be exported from the application at any time.
- Read-only
- After expiry the instance enters a stated grace period and then becomes read-only. It does not vanish on the renewal date.
- Retention window
- The instance is kept after termination, for the period stated in the order, so the export can be completed.
- Destruction
- The instance, its database, its document store and its backups are then destroyed. We certify destruction in writing if the firm asks.
Where law requires us to retain something — a commercial or tax record — we keep only that, for only as long as required, and it stays subject to clause 03.
Precedence
Where this addendum conflicts with the master services agreement or the order, this addendum prevails on matters of data protection and the other documents prevail on everything else.
A firm that needs its own paper signed instead is welcome to send it. We would rather agree terms you have read than terms you have accepted.
Questions go to privacy@antchambers.com. How we handle personal data more generally is in the Privacy Policy.