Skip to main content

Our Data Principles

At BundleCreator, we are committed to protecting your data and maintaining the highest standards of data governance. These principles guide every decision we make about data handling.

Our Commitment

As a platform built for legal professionals, we understand the critical importance of data protection. These principles are not just guidelines—they are fundamental to how we operate.

1. Data Minimization

We only collect and retain data that is absolutely necessary for providing our legal bundle creation services. This approach reduces risk, storage costs, and compliance burden for everyone.

What this means for you:

  • We don't collect marketing data or track your browsing habits
  • We only store documents you explicitly upload for bundles
  • We don't require unnecessary personal information
  • Temporary files are automatically deleted after processing

2. Purpose Limitation

Your data is used exclusively for the specific purposes it was collected for—creating and managing legal bundles. We will never use your data for any other purpose without your explicit consent.

Our guarantee:

  • Documents are only used for bundle creation and management
  • Personal data is only used for account management and support
  • We never sell or share your data with third parties
  • No data mining or profiling of your legal documents

3. Data Quality and Accuracy

We ensure your data remains accurate, complete, and up-to-date through automated processes and user controls. You have full ability to correct errors and update information at any time.

How we maintain quality:

  • Real-time updates to bundle and document information
  • Version control for document changes
  • Easy editing tools for correcting any errors
  • Automated cleanup of orphaned or outdated data

4. Transparency

We believe in complete transparency about data handling. You always know what data we collect, how we use it, who has access to it, and how long we keep it.

Our transparency commitments:

  • Clear privacy policy written in plain English
  • Activity logs showing all access to your data
  • Immediate notification of any data-related incidents
  • Open communication about our data practices

5. Security by Design

Security isn't an afterthought — it's built into every aspect of our platform. We implement appropriate technical and organisational measures (per UK GDPR Art 32) to protect your data throughout its lifecycle.

Security measures include:

  • AES-256 encryption at rest for all documents
  • TLS 1.3 encryption in transit
  • Regular security audits and penetration testing
  • Strict access controls and authentication
  • CORS (Cross-Origin Resource Sharing) protection
  • Continuous monitoring for threats

CORS Implementation:

Cross-Origin Resource Sharing (CORS) is implemented to protect your data from unauthorised access by other websites:

  • Only approved origins can access our API endpoints
  • Strict header validation for all API requests
  • Credentials required for authenticated requests
  • Specific methods allowed (GET, POST, PUT, DELETE, etc.)
  • Enhanced headers for secure PDF document handling

6. Lawfulness and Consent

We only process data when we have a valid legal basis. This includes your consent, contractual necessity, or compliance with legal obligations.

Legal basis for processing:

  • Consent: For marketing communications and optional features
  • Contract: For providing our bundle creation services
  • Legal obligation: For compliance with court requirements
  • Legitimate interest: For security and fraud prevention

7. Data Subject Rights

We respect and facilitate all your data protection rights. You have full control over your personal data and can exercise your rights at any time.

Your rights include:

  • Access: Download all your data at any time
  • Rectification: Correct any inaccurate information
  • Erasure: Delete your account and all associated data
  • Portability: Export your data in standard formats
  • Objection: Opt-out of specific processing activities

8. Accountability

We maintain comprehensive documentation of our data protection practices and can demonstrate compliance at any time through policies, procedures, and regular audits.

How we ensure accountability:

  • Detailed data processing records
  • Regular compliance audits
  • Data Protection Impact Assessments (DPIAs)
  • Staff training on data protection
  • Incident response procedures

9. Storage Limitation

We don't keep data longer than necessary. Our retention schedules ensure data is automatically deleted when no longer needed, reducing risk and storage costs.

Retention periods:

  • Active bundles: Retained while account is active
  • Deleted bundles: Permanently removed after 30 days
  • Temporary files: Deleted immediately after processing
  • Account data: Deleted 90 days after account closure
  • Legal holds: Extended only when legally required

10. Privacy by Design

Privacy considerations are built into our systems and processes from the ground up. Every feature is designed with privacy as a core requirement, not an afterthought.

Privacy-first features:

  • AES-256 encryption at rest, TLS 1.3 in transit
  • Minimal data collection requirements
  • Privacy-preserving analytics
  • Secure sharing with granular permissions
  • Anonymous usage options where possible

Compliance & Certification

Our data principles align with international data protection standards including:

  • UK GDPR (General Data Protection Regulation)
  • Data Protection Act 2018
  • ISO 27001 Information Security Standards (in progress)
  • Legal sector specific requirements

Questions About Our Data Principles?

We're committed to transparency and are happy to discuss our data principles in detail.

Data Protection Officer: dpo@bundlecreator.co

General Inquiries: privacy@bundlecreator.co

Related Documents

Last Updated: December 2025

Next Review: May 2026

Version: 1.1