Data Protection
How your data is stored, secured and handled across our systems, described concretely rather than reassuringly.
Last updated
The privacy policy explains what data we collect and why; this page explains how it is protected in practice, covering the systems, the safeguards and the habits. We describe our measures concretely, because “bank-level security” is a phrase, not a practice, and you deserve better than phrases.
Where your data lives
Personal data is stored with reputable hosting providers under data processing agreements. Transaction documents are kept separate from marketing tools, so a newsletter list can never quietly accumulate passport copies.
Backups exist so data survives failure, and they are stored separately from the live systems.
Technical safeguards
Connections to the site are encrypted, and access to personal data follows roles, so colleagues see only what their work needs. Software is kept up to date, and security fixes are applied by severity, not by convenience.
Forms are protected with rate limits and spam controls, sensitive actions require authentication, and account passwords are stored only as one way hashes.
- Encrypted connections to the website
- Role based access to personal data
- Passwords stored as one way hashes
- Rate limits and spam controls on forms
- Security updates applied promptly
Human safeguards
Most data incidents anywhere are human, not technical, so our habits are practical: recognising phishing, verifying payment detail changes by phone on a known number, and never moving client documents through private channels. Colleagues who handle client data are bound by confidentiality obligations.
A standing rule protects the riskiest moment in property: bank details are only ever confirmed through a second channel. If you receive an email changing where to send money, apparently from us, your lawyer or anyone else, call the known number before acting. We repeat this to every client, in writing, early.
We never change bank details by email alone. If any message asks you to redirect a payment, telephone us on the number you know before doing anything.
Retention and deletion
We keep data only as long as its purpose or a legal obligation requires: enquiry data lapses after twenty four months without contact, transaction records are held for their statutory period of typically seven years, and newsletter data for the life of the subscription. When the referral programme launches, its records will follow the same principle.
Deletion means deletion: removal from live systems promptly, and from backup rotations as those cycles expire. On request, we will tell you exactly which of your records fall due for deletion and when.
If something goes wrong, and where to ask
If a breach ever posed a risk to your rights, we would notify the supervisory authority within seventy two hours and you without undue delay, telling you plainly what happened, what it means for you, and what we are doing.
Questions about anything on this page go to hello@ordently.com. Security researchers who find a vulnerability on our site are asked to use the same address; we respond quickly and we do not shoot messengers.
Frequently asked
Are my passport and identity documents stored on the website?
What should I do if I receive a suspicious email that appears to be from you?
Questions about this policy?
A person, not a form letter, reads and answers every message. We are happy to explain any part of this page in plain language.