Last updated 18 September 2026
AskPanda holds the first thing a prospective client tells a law firm about their problem. We treat that information as confidential and potentially privileged from the moment it arrives. This page describes how we protect it. It expands on Annex 2 of our Data Processing Agreement and is written for the partners, compliance officers and IT staff who assess suppliers.
| Where your data is stored | United Kingdom. Database and backups in the AWS London region. |
|---|---|
| Encryption | TLS 1.2 or higher in transit. Encrypted at rest, including backups. |
| Sign-in | Unique credentials per user, multi-factor authentication available to every user, passwords stored as salted hashes. |
| AI and your data | Never used to train models. The provider holds API data for up to 30 days for abuse monitoring only, then deletes it. |
| Backups | Daily, encrypted, kept for 7 days in the UK. |
| Breach notification | Without undue delay and within 72 hours of becoming aware. |
| Regulator | Registered with the ICO, reference ZB193262. |
The AskPanda database and its backups are hosted by Amazon Web Services in its London region. Our own systems store client enquiry data only in the United Kingdom. A small number of sub-processors, such as our email delivery and AI providers, process data briefly in the EU or the United States under the safeguards described in our sub-processor list , and keep it only for as long as they need to perform their function.
All traffic between your browser, the AskPanda platform and our sub-processors is encrypted with TLS 1.2 or higher. Data at rest, including the database and every backup, is encrypted using the cloud provider's managed encryption. Production secrets and API keys are kept outside source code and rotated when personnel change or exposure is suspected.
AskPanda uses third-party large language models to process enquiry content. The provider is listed in our sub-processor list. Our arrangements with the provider:
We do not use your data, or any other customer's, to build our own models.
The database is backed up automatically every day. Backups are encrypted, kept for 7 days in the same UK region, and are not restored except to recover the service. Backup copies are overwritten in the ordinary backup cycle after data is deleted from the live system.
Application errors and security-relevant events, including failed sign-in attempts and account lockouts, are logged and monitored, and key actions on enquiry records are recorded in an audit trail. Logs are retained for up to 30 days and access to them is restricted to the engineering team.
You control how long enquiry data is kept. You can delete individual records at any time. When a subscription ends you have 30 days to export your data, after which we delete it within a further 60 days, including from backups, and confirm deletion in writing on request.
We maintain a documented incident response procedure covering detection, containment, investigation, customer notification and post-incident review. If a personal data breach affects your data we will notify your account contact without undue delay and in any event within 72 hours of becoming aware, with the information you need to meet your own obligations to the ICO and to the individuals concerned. We will not contact your clients or a regulator about your data without your agreement unless the law requires it. To report a security concern, email support@legalpandas.com.
All code is version-controlled and reviewed before release. Dependencies are updated to address known vulnerabilities. Staff and contractors are bound by written confidentiality obligations and receive data protection training.
We assess every sub-processor before engagement and periodically afterwards, bind each by a written data protection contract, and give customers at least 30 days' notice before adding or replacing one. The current list, with locations and a change log, is published in Annex 3 of our Data Processing Agreement .
We are registered with the Information Commissioner's Office under reference ZB193262. Customers may request a summary of our security measures once a year under clause 9 of the Data Processing Agreement, and may commission an independent audit on the terms set out there.
Security is shared. To keep your enquiries safe, your firm should keep login credentials confidential and never share accounts, remove users who leave the practice, tell prospective clients in your own privacy notice that enquiries are handled with software that uses AI, review AI output before relying on it, and tell us at once if you suspect unauthorised access.
If your firm has a security questionnaire or due diligence process, send it to support@legalpandas.com and we will complete it.
For questions about these documents or about how we handle data, email us or use the chat.