Security & data handling
Built for confidential legal work.
What protects your documents, who can see them, and how we handle data. Written to be pasted into your vendor questionnaire.
What protects you
Your service agreement is with Icon.Partners (AndAnd Operations OÜ), established in the EU and bound by GDPR, by professional confidentiality obligations in the agreement, and by the personal undertakings every person on your matter has signed. Matter data is processed under a written DPA.
Where your documents live
Matter documents live in Icon.Partners’ company systems — Google Workspace and Slack — and are shared with you through a secure upload link and a private channel per client. Nothing is kept on personal accounts or devices. We do not accept contract documents by ordinary email attachment unless you choose to send them that way. Data is encrypted in transit (TLS 1.2+) and at rest by the platform provider. Access to each matter folder is limited to the people working on that matter.
Who can see them
The senior lawyer responsible for your matter and the named Icon.Partners lawyers and project staff assigned to it. Every person with access has signed a personal confidentiality undertaking and works under that lawyer’s supervision. No offshore subcontractors, no anonymous freelancers, no data brokers. A list of individuals with access to your matter is available to you on request.
Access controls
Multi-factor authentication on every account that touches matter data. Access is granted per matter and removed when the matter closes or the person leaves. Every team member works under a written contract and a signed confidentiality undertaking, and goes through regular internal training on confidentiality and data handling.
Software and AI tools
Client documents and anything identifying a client or counterparty do not go into AI tools as such. Where AI assists a first draft, it works on anonymised text with parties, names and amounts replaced by placeholders, through providers under a data-processing agreement that do not train on our data. Every draft is reviewed and approved by a lawyer before you see it.
GDPR and data-processing agreement
Icon.Partners is established in the European Union and processes personal data in your documents as your processor under a written data-processing agreement (GDPR Article 28). If your own customers require a DPA that covers your vendors, we sign one with you, with Icon.Partners as processor. Sub-processors at this date: Google Workspace, Slack, Cloudflare (website hosting), Resend (transactional email). We give 14 days’ notice before adding one.
The client portal runs on EU infrastructure. Documents are encrypted at rest, access is per user and per matter, every download is logged, and MFA is on for everyone — ours and yours.
Incidents
If we become aware of a security incident affecting your documents, we tell you within 48 hours with what we know, what we have done and what we need from you. There has been no such incident to date.
Retention and return
On request, and in any case within 30 days of a matter closing, Icon.Partners returns or securely deletes matter documents. Icon.Partners keeps the engagement record for the period required by Estonian accounting and anti-money-laundering law.
For your security questionnaire
We keep a maintained master answer set and can return most vendor questionnaires within a few business days. Ask at office@icon.partners with “security questionnaire” in the subject line.
16 September 2026. This page is a statement of practice, not a contractual commitment; the commitments are in your service agreement and data-processing agreement.