← MatterLink

Privacy notice

How MatterLink handles personal data it holds in its own right. If you are a client of a solicitor who uses MatterLink, section 1 tells you where to look instead.

Version:
1.0
Effective:
3 August 2026
Last updated:
3 August 2026
Our role:
Controller

Contents

  1. Which personal data this notice covers
  2. Who we are
  3. What we collect, and where it comes from
  4. What we use it for, and our lawful basis
  5. Who we share it with
  6. Cookies and similar technologies
  7. Where your data is held
  8. How long we keep it
  9. Automated decision-making
  10. Your rights
  11. How to complain
  12. Changes to this notice

Which personal data this notice covers

MatterLink handles personal data in two quite different roles, and this notice covers only one of them. Getting this distinction right is the first thing a compliance reader will check, so it is the first thing on the page.

Personal dataOur roleWhere to look
People who visit our website, ask for a demo, or hold a MatterLink account at a solicitor firm — and our own business recordsControllerThis notice
Clients, sellers, purchasers and other parties whose details a firm enters into a transactionProcessor, acting on the firm’s instructionsData processing, and the firm’s own privacy notice

If you are a client of a solicitor who uses MatterLink

Your solicitor is in charge of your information, not us. We hold it only to provide their software, and we act only on their instructions. Ask your solicitor if you want to see, correct or delete anything, or if you want to know how long they keep it — they are the right person to answer, and they have to. If you want to understand our side of it, the data processing page sets out what we do and do not do with it.

Who we are

The controller for the personal data described in this notice is MatterLink Ltd, a company registered in Scotland (number [Company number]), whose registered office is at [Registered office address], Glasgow, [Postcode].

We are registered with the Information Commissioner’s Office under registration [ICO registration number].

We have not appointed a data protection officer. We are not required to under Article 37 of the UK GDPR: we are not a public authority, and our own controller activities do not involve large scale regular and systematic monitoring or large scale processing of special category data. Data protection questions come to a named person rather than a role inbox — privacy@matterlink.co.uk reaches us directly.

What we collect, and where it comes from

If you enquire or book a demo

Your name, your firm, your work email address and phone number, and whatever you choose to tell us in the message. It comes from you.

If you hold a MatterLink account

Your name, work email address, the firm you belong to, your role within it, your password in hashed form (we never see it), and any multi-factor authentication settings. It comes from you or from your firm’s administrator.

Whenever anyone uses the service

Records of significant actions — who did what, in which firm, and when — as an audit trail; sign-in events; and technical logs including IP address, browser type and the pages requested. These are generated automatically. The audit trail is a deliberate product feature, not incidental logging: it exists so a firm can answer questions about who changed what.

Our own business records

Correspondence with you, notes of calls, contract records and, on paid plans, billing details. Payment card details are handled by our payment provider and never reach our systems.

What we do not do

  • We do not buy personal data or scrape it from third-party sources.
  • We do not use tracking or advertising cookies (see section 6).
  • We do not send any personal data to any artificial intelligence model or model provider, for any purpose.

What we use it for, and our lawful basis

PurposeDataLawful basis
Responding to an enquiry or arranging a demoEnquiry detailsLegitimate interests — responding to someone who has asked us to get in touch. If it leads towards a contract, Article 6(1)(b).
Providing the service to your firm and administering accountsAccount detailsArticle 6(1)(b) where you contract with us personally; otherwise legitimate interests in performing our contract with your firm.
Keeping the service secure — sign-in monitoring, abuse prevention, auditAccount details, technical logs, audit recordsLegitimate interests in protecting the confidentiality of legal data, which is also a security obligation under Article 32.
Support, and fixing faultsAccount details, correspondence, logsLegitimate interests in making the product work.
Improving MatterLinkAggregate usage patterns, feedback you give usLegitimate interests in developing the product. We do not use the contents of your firm’s matters for this.
Telling firms about the productWork contact detailsLegitimate interests in marketing to businesses, or consent where required. Every message has an unsubscribe link and we honour it immediately.
Billing, accounts and tax (paid plans)Billing contact and transaction recordsLegal obligation, and legitimate interests in getting paid.
Complaints, disputes and legal claimsWhatever is relevantLegal obligation, and legitimate interests in establishing, exercising or defending claims.
Responding to a regulator, or reporting something we are required or entitled to reportWhatever is relevantLegal obligation, or the recognised legitimate interest in Article 6(1)(ea) of the UK GDPR where it applies.

Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them. We will explain that assessment if you ask.

Special category and criminal offence data

We do not ask for, and have no use for, special category data or criminal offence data about the people covered by this notice. A firm’s conveyancing matter may occasionally contain such data — a client’s health, for example, in the background to a sale. Where it does, we hold it only as that firm’s processor, on the firm’s lawful basis and its Schedule 1 condition, and we do not use it for any purpose of our own.

Who we share it with

We do not sell personal data, and we never will. We share it only in these situations:

  • Service providers who help us run MatterLink — hosting, database and email. They act on our instructions under written terms and cannot use the data for their own purposes. They are listed by name on the data processing page, which is kept current because firms’ procurement questionnaires ask for it.
  • Our professional advisers — accountants, lawyers, insurers — where they need it and are under a duty of confidence.
  • A regulator, court or law enforcement, where we are legally required to or where the law permits it. If a request concerns a firm’s data we will tell the firm before responding, unless the law prevents us from doing so.
  • A buyer, if the business is ever sold or transferred — under confidentiality obligations, and with notice to affected firms.

Within the product, information moves between the two firms in a transaction only where a firm chooses to share it. That disclosure is the sharing firm’s own, made on its own lawful basis; we transmit it and record it, and we are not a controller of it.

Cookies and similar technologies

We use as few as we can get away with, and no advertising or cross-site tracking technologies at all.

TODO before publishing. Open the live site in a private window and list what is actually set — the table below is a shape, not a statement of fact. Under the Privacy and Electronic Communications Regulations 2003 as amended by the Data (Use and Access) Act 2025, strictly necessary cookies need no consent, and a narrow exception now covers low-risk statistical cookies, but only where the results are aggregate, cannot reasonably identify anyone, are not combined with advertising data and involve no profiling — and you must still tell people and offer an opt-out. If your analytics does not clearly meet all of that, it needs a consent banner. Delete this note once the table is real.

CookiePurposeTypeExpires
Authentication and session cookiesKeeping you signed in, and protecting against cross-site request forgery. The service cannot work without them.Strictly necessary — no consent requiredOn sign-out or expiry of the session
[Name any analytics cookie here, or delete this row][Purpose][Consent basis][Duration]

You can block or delete cookies in your browser settings. Blocking the strictly necessary ones will stop you signing in.

Where your data is held

The database and all stored files are in the United Kingdom, in Amazon Web Services’ London region (eu-west-2). Everything in transit is protected with TLS; everything stored is encrypted at rest with AES-256.

We do not routinely transfer personal data outside the UK. If a supplier ever needed to process data elsewhere — for example, support staff in another country — we would only do it under a transfer mechanism recognised by the UK GDPR, such as the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, after a transfer risk assessment. Any such arrangement would be named on the data processing page before it started, with notice to affected firms.

How long we keep it

WhatHow longWhy
Enquiries that do not become a customer relationship12 months from the last contactLong enough to pick up a conversation, short enough not to hoard.
Account records for a userWhile the account is active, then 5 yearsThe short negative prescriptive period under the Prescription and Limitation (Scotland) Act 1973.
Audit trail for a transactionFor as long as the firm’s data is held, then deleted with it under section 18 of the termsAn audit trail that outlives its subject matter serves nobody.
Technical and security logs12 monthsLong enough to investigate an incident found late.
Accounting and tax records6 years from the end of the financial yearCompanies Act and HMRC requirements.
Correspondence about a complaint or claim5 years from resolutionPrescription, as above.

Content that belongs to a firm follows that firm’s instructions and the termination provisions in section 18 of the terms of service, not this table. Deletion from routine backups happens as those backups age out rather than instantly.

Automated decision-making

We do not make automated decisions that produce legal effects for you or similarly significantly affect you, and we do not profile you. MatterLink calculates progress from the statuses people have set — it does not decide anything about a person.

Your rights

In relation to personal data we hold as controller, you can ask us to:

  • give you a copy of it, and tell you what we do with it;
  • correct anything inaccurate or incomplete;
  • delete it, where we no longer need it and no legal obligation requires us to keep it;
  • restrict what we do with it while a question about it is resolved;
  • transfer it to you or someone else in a structured, machine-readable format, where we hold it on the basis of consent or a contract and process it automatically;
  • stop processing it where we rely on legitimate interests, and stop using it for direct marketing — for marketing, this one is absolute and we will act on it immediately.

Where we rely on your consent for anything, you can withdraw it at any time. That does not affect what we did before you withdrew it.

Write to privacy@matterlink.co.uk. We will respond within one month, and will tell you if we need to extend that by up to two further months because the request is complex. We may ask you to confirm your identity first, and we may ask you to narrow a very wide request so that we can search reasonably and proportionately for what you are actually looking for — if we do, the clock pauses until you come back to us. It is free unless a request is manifestly unfounded or excessive, in which case we will tell you why before doing anything.

If your request is about a conveyancing matter, we are the processor and not the controller. Send it to the solicitor firm instead — we will point you to them, and we will help them answer it.

How to complain

If you think we have handled your personal data badly, tell us first. We would rather fix it than have you find out from the regulator that we should have.

  • By electronic form: matterlink.co.uk/privacy/complaint
  • By email: privacy@matterlink.co.uk
  • By post: Data Protection, MatterLink Ltd, [Registered office address], Glasgow, [Postcode]

We will acknowledge your complaint within 30 days of receiving it, as section 164A of the Data Protection Act 2018 requires, and then take appropriate steps to respond to it — including investigating and telling you the outcome.

You can also complain to the Information Commissioner’s Office at any time, and you do not have to come to us first — though the ICO will normally expect you to have tried.

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113 · ico.org.uk

Changes to this notice

We will update this notice when what we do changes, and when the law does. The version number and date at the top of the page tell you which version you are reading. If a change materially affects how we use personal data about you, we will tell you directly rather than relying on you noticing — by email where we hold an address for you, and by a notice in the service for account holders.

Terms of servicePrivacy noticeData processing

MatterLink Ltd · Registered in Scotland no. [Company number]