GDPR – CrimeLine Data Protection Policy and Privacy Notice

‘CrimeLine’ is CrimeLine Training Limited, a company registered in England and Wales.

CrimeLine holds a Cyber Essentials Plus accreditation that can be viewed here.

To view high-level data protection documentation, please contact us for a password, then access the documents via this page.

CrimeLine Training Limited

Privacy Notice

Registered office: 41 Bridgeman Terrace, Wigan WN1 1TT  ·  ICO registration Z2096592  ·  crimeline.co.uk

CrimeLine — Privacy Notice

CrimeLine Training Limited · Version 1.0 · 12 September 2026 · Owner: Data Protection Lead · Review: annually and on material change

This notice explains how CrimeLine collects and uses personal data, and the rights you have. It is written to be read by the people whose data we handle — our members and the individuals who use them, visitors to our website, and anyone who contacts us. It is deliberately plain and complete; a fuller technical account of our data flows and the suppliers we use is maintained separately in our DPIA Data Map, which we make available to customers carrying out due diligence.

1. Who we are

CrimeLine is the subscription legal reference service for criminal-law practitioners in England and Wales, operated by CrimeLine Training Limited (registered office: 41 Bridgeman Terrace, Wigan WN1 1TT; registered in England and Wales). We are registered with the Information Commissioner’s Office under registration number Z2096592. For anything in this notice, or to exercise any of your rights, contact our Data Protection Lead at [email protected]. We have assessed our activities under Article 37 UK GDPR and are not required to appoint a statutory Data Protection Officer; the Data Protection Lead named here is nonetheless our single point of accountability for data protection.

2. What this notice covers — and the important difference between your account data and the content you submit

For most of the personal data we handle — your account and membership details, how you use the service, security, support and marketing — CrimeLine is the controller, and this notice explains what we do and why. There is one important exception. When you use our AI tools (CrimeLine Ask and DocAssist) through a firm’s subscription, the documents and questions you submit to those tools (which we call “Submitted Content”) are handled on your firm’s behalf: your firm is the controller of that content and CrimeLine acts as its processor under a written contract. How that content is handled is summarised in section 5 below and governed by our subscriber terms and our standalone Data Processing Agreement, not primarily by this notice. This notice tells you how CrimeLine handles personal data for which CrimeLine itself is the controller.

3. The personal data we collect, why we use it, and our lawful basis

We collect only what we need to run the service. The table below sets out the personal data we hold as controller, why, and the lawful basis under Article 6 UK GDPR.

What we collect Why Lawful basis
Account and membership data — your name, work email, firm, role, membership status and preferences, and a securely hashed password To create and administer your account, give you access to the service, and provide the membership you have signed up for Performance of a contract (Art 6(1)(b))
Billing data — invoices and billing-contact details (payment card details are handled by our payment processor and are not stored by us) To take payment for the service and keep the accounting records the law requires Contract (Art 6(1)(b)) and legal obligation (Art 6(1)(c)) for statutory accounting retention
Login and security metadata — your login email, IP address, device/user-agent, login gateway, user ID and role at sign-in, and two-factor codes sent to your email To sign you in securely, enforce two-factor authentication, and protect accounts against unauthorised access and brute-force attempts Legitimate interests (Art 6(1)(f)) — securing the service and your account
Support correspondence — the content of support tickets you raise, and any attachments To answer your query and provide support Contract (Art 6(1)(b)) and legitimate interests (Art 6(1)(f)) in running an effective support service
Transcript access and usage data — when you view or download a court transcript through your membership, we record your member ID, the file, the date and time, and whether you viewed or downloaded it (we do not record your IP address), and we stamp your downloaded copy with your name and the time To make our licensed transcript collection available to members, and to protect it against bulk downloading and redistribution in line with your membership terms Legitimate interests (Art 6(1)(f)) — protecting our licensed materials — and contract (Art 6(1)(b))
Opt-in research features — where you choose to use them: a question you expressly share as feedback (question text only, no identity); “watched questions” you ask us to monitor (held against your account); and “amendment watch” (a public statutory reference held against your account) To improve the service, and to email you when new material or a legal change relevant to something you are following appears Consent (Art 6(1)(a)) — you can withdraw it at any time
Website and site-search data — pages you visit and searches you run; for searches that return nothing we may keep the query text (capped and with no identifying data) to improve results To operate and improve the website and its search Legitimate interests (Art 6(1)(f)) in operating and improving the site
Marketing data — your email address and how you engage with our newsletters and updates To send you the newsletters and service updates you have asked for Consent (Art 6(1)(a)), or our legitimate interests where we contact an existing customer about similar services (Art 6(1)(f)); you can opt out at any time

4. Where your data comes from

Almost all of the personal data we hold comes directly from you — when you register, use the service, contact support, or sign up for updates. Some technical data (such as IP address and device information) is generated automatically when you use the site, and some billing information comes from our payment processor. We do not buy personal data or build profiles of you from third-party sources.

5. Content you submit to our AI tools

When you use CrimeLine Ask or DocAssist, the documents and questions you submit are treated as highly sensitive and are handled under a strict rule: they are processed only for the moment needed to produce your answer and are not added to any search index, cache, log or training process. DocAssist content is never stored on our systems; documents attached to an Ask conversation are deleted automatically within a few hours; and question text is not retained after your answer is produced. The AI processing is carried out for us by Amazon Web Services using models hosted within the European Economic Area under a “zero data retention” configuration — the content is not kept by the provider once your answer is returned, is never used to train any model, and is not shared with the underlying model providers. Two narrow opt-in features (feedback and watched questions) are the only exceptions in which any element of what you type is retained, and only with your express consent, as described in section 3. Because this content belongs to your firm’s matters, your firm is its controller and we process it on your firm’s behalf; the full terms are in our subscriber agreement and Data Processing Agreement.

6. Special category and criminal-offence data

Given the nature of criminal-law practice, the content you submit to our AI tools or to support may include criminal-offence information and special-category data, and may be legally privileged. We handle it under the strict controls described above and in our Information Security Policy, and we never use it for any purpose other than providing the service you have asked for. The court transcripts in our library are public court documents; the personal data we create around your use of them is only the access record described in section 3.

7. Cookies

We use cookies and similar technologies that are strictly necessary to run the website and keep it secure — for example, to sign you in, keep you signed in, remember your session, and support two-factor authentication. These are always on because the service cannot work without them. Where we use any non-essential cookies (for example, to measure how the site is used), we set them only with your consent, which you can give or withdraw through our cookie controls. You can also manage cookies in your browser settings.

8. Who we share your data with

We do not sell your personal data and we do not share it for anyone else’s marketing. We use a small, carefully chosen set of service providers who process personal data on our behalf under written contracts (Article 28 UK GDPR), each permitted to use it only to provide their service to us:

  • WP Engine — our website and application hosting (United Kingdom), including the membership system, the transcript library and short-lived processing stores.

  • Amazon Web Services (AWS) — the AI processing behind CrimeLine Ask, DocAssist and our search (model inference, search embeddings and reranking), the secure relay that carries content to those models, and the stamping of transcript downloads — all within the European Economic Area (Ireland and Frankfurt). The AI model providers themselves (Anthropic and Cohere) run within AWS and receive no content from us.

  • Cloudflare — our global edge network and web application firewall (traffic protection and delivery); it carries traffic in transit and does not store your content.

  • Stripe — payment processing (your card details are provided directly to Stripe and are not stored by us).

  • Xero — our accounting system, for invoices and billing records.

  • Google Workspace — our email and business productivity systems.

  • Mailchimp (including Mailchimp Transactional) — our newsletters and service/notification emails.

  • Limit Login Attempts Reloaded (Atlantic Silicon Inc.) — our login-security layer, which processes authentication metadata only (never passwords and never site content).

We may also disclose personal data where we are required to by law, by a court order, or to establish, exercise or defend legal claims. A full, current list of these providers — with the data each receives, its location and the transfer safeguard — is maintained in our DPIA Data Map, available to customers on request.

9. Sending data outside the UK

The content you submit to our AI tools is processed exclusively within the European Economic Area, with no route to the United States. The UK has determined that the EEA offers an adequate level of protection, so this is not a “restricted transfer”. Some of our other providers (for example, for payments, email, business productivity and login security) are based in, or transfer data to, the United States or process it globally. Where personal data is transferred outside the UK to a country without UK “adequacy”, we rely on the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, as the appropriate safeguard. You can ask us for more detail about the safeguards that apply to a particular transfer.

10. How long we keep your data

  • Account and membership data — for the life of your membership and for about three months afterwards, then deleted.

  • Billing and accounting records — for the period required by law, then destroyed.

  • Login-security records — session data is deleted when your session ends; login-protection records are kept for about three months and successful-login records for about a year, as security logging.

  • Support tickets — deleted when the ticket is closed.

  • Content submitted to AI tools — not stored (DocAssist), or deleted within a few hours (documents attached to Ask); question text is not retained after your answer is produced.

  • Opt-in feature data — “watched questions” expire automatically after 90 days (and on your removal or account deletion); shared-feedback question text is kept only as a small rolling set with no identity; “amendment watch” references are kept until you remove them or close your account.

  • Transcript access log — kept only as a rolling record of the most recent entries and then overwritten; the associated usage counters reset each hour and day.

  • Marketing data — until you unsubscribe or ask us to stop.

11. How we protect your data

We operate a documented set of security controls — including encryption in transit and at rest, enforced two-factor authentication, least-privilege access, endpoint protection, independent penetration testing and a defined incident-response and breach-notification process. These are described in our Information Security Policy, which we make available to customers on request.

12. Your rights

Under UK data protection law you have the right, in the circumstances the law provides, to: access the personal data we hold about you; have inaccurate data corrected; have your data erased; restrict or object to our processing; obtain your data in a portable form (data portability); and, where we rely on your consent, withdraw that consent at any time (which does not affect processing already carried out). Where CrimeLine acts as processor for content submitted through your firm, a request about that content should usually be directed to your firm as controller, and we will support your firm in responding. To exercise any right, or if you have any question, contact [email protected]. We will respond within the statutory time limit (usually one month). We do not charge a fee for a valid request unless the law allows it.

13. Marketing choices

You can opt out of our marketing at any time — use the unsubscribe link in any marketing email, or email us. Opting out of marketing does not stop essential service messages (for example, about your account, security or a change to the service), which we need to send you to provide the service.

14. Automated decision-making

We do not make decisions about you by solely automated means that produce legal or similarly significant effects (Article 22 UK GDPR). Our AI tools produce research assistance for you to review and use in your own professional judgement; they do not make decisions about individuals.

15. Changes to this notice

We keep this notice under review and update it when our processing changes. Each version carries a version number and date at the top; this is version 1.0, dated 12 September 2026. Where a change is significant we will bring it to your attention.

16. How to complain

If you have a concern about how we handle your personal data, please contact us first at [email protected] so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; helpline 0303 123 1113; ico.org.uk.

CrimeLine Training Limited — Data Protection Lead ([email protected]).

Version 1.0 · 12 September 2026. This is the current version of our privacy notice; we update it from time to time.

Bookmark
Please login to bookmark Close