‘CrimeLine’ is CrimeLine Training Limited, a company registered in England and Wales.
CrimeLine holds a Cyber Essentials Plus accreditation that can be viewed here.
To receive a copy of our Information Security Policy, Data Map and DPIA assessment document, please contact us.
Specific Data Processing Clause:
X. Data processing — documents and questions submitted to the Service
X.1 Roles. Where a member submits documents or questions to DocAssist, CrimeLine Ask or the support ticket service (“Submitted Content“), the member — or, where the member uses the Service in the course of practice or employment, the member’s employer — is the controller of any personal data contained in the Submitted Content, and CrimeLine is a processor. CrimeLine remains controller of member account, billing and service-administration data, as described in the Privacy Notice.
X.2 Instructions. CrimeLine processes Submitted Content only to provide the analysis or support requested by the authorised user, and only on the controller’s documented instructions, which are given by the act of submission. CrimeLine will not process Submitted Content for any other purpose, and will inform the controller if it believes an instruction infringes data protection law, or if it is required by law to process otherwise (unless that law prohibits such notice).
X.3 Duration, retention and deletion. Submitted Content is processed transiently. DocAssist content is not stored on CrimeLine systems; documents attached in CrimeLine Ask are deleted automatically within 4 hours of upload; ticket attachments are deleted when the ticket is closed. Submitted Content is never added to any search index, cache, log or model-training process. Content transmitted to the AI inference provider is deleted by that provider within 30 days under its terms and is not used to train models. On termination of a membership, no Submitted Content remains to be returned or deleted, this being achieved by design rather than on request; any residual account data is handled as described in the Privacy Notice.
X.4 Confidentiality. Access to systems capable of holding Submitted Content is restricted to a single named individual bound by professional and contractual duties of confidentiality; no CrimeLine workflow involves reading Submitted Content.
X.5 Security. CrimeLine implements the technical and organisational measures described in its current DPIA documentation and Data Map (including TLS encryption in transit, encryption at rest, access restriction and multi-factor authentication) and keeps them under review.
X.6 Sub-processors. The controller gives general authorisation for the sub-processors listed in CrimeLine’s current Data Map (hosting, edge security, AI inference, email, and accounting services). CrimeLine will give reasonable prior notice of any intended change of sub-processor materially affecting Submitted Content, allowing the controller to object; each sub-processor is engaged on terms imposing data protection obligations materially equivalent to this clause.
X.7 International transfers. Where processing involves a transfer of personal data outside the United Kingdom, the transfer is made only under appropriate safeguards (standard contractual clauses and/or the UK Addendum or International Data Transfer Agreement, as applicable).
X.8 Assistance. Taking into account the nature of the processing, CrimeLine will assist the controller, insofar as possible, in responding to data subject rights requests and in meeting its obligations regarding security, breach notification and data protection impact assessments. CrimeLine will notify the controller without undue delay after becoming aware of a personal data breach affecting Submitted Content.
X.9 Demonstrating compliance. CrimeLine will, on request, make available the information reasonably necessary to demonstrate compliance with this clause, including its current Data Map and DPIA documentation. Given the transient nature of the processing, audit rights are exercised by review of that documentation and written responses to reasonable enquiries, no more than once in any 12-month period save following a personal data breach.
Last revision:
14 July 2026 Data processing clause added
28 April 2026 Reference to two-factor authorisation and data retained by third-party (IP address and browser details), necessary to ensure maximum data security. Please note that, at present, the third party, due to the software version we are using, is not retaining any data. If this changes, this notice will be updated.
10 December 2024 Reference to Cyber Essentials Plus Accreditation added
14 May 2024 Reference to two-factor authorisation added
2 February 2024 Explicit reference to the Open Justice Licence added.
24/01/2024 [added information in relation to CrimeLineAssist submissions].