TKJ Legal Vault
Privacy Policy
Last updated: 15 August 2026
This Privacy Policy explains how TKJ GLOBAL MEDIA LTD (Company No. 08272919, England and Wales — "Company", "we", "us") handles information in connection with the TKJ Legal Vault service, including the web application and, when released, our mobile and desktop apps. It should be read with our Terms of Use.
In plain language: this tells you exactly what we can and cannot see. The short version is unusual for a tech product — your documents, their names, and your filing structure are encrypted before they reach us. We hold ciphertext we cannot read.
1. The zero-knowledge design comes first
The Service is built so that documents, filenames, Vault Box names, and your folder structure are encrypted on your device with keys derived from your passphrase. We never receive your passphrase or your keys.
We cannot access, read, search, analyse, or disclose the plaintext of your documents — to you, to ourselves, or to anyone else. This policy is therefore mostly about the small amount of operational data we do process.
In plain language: We designed ourselves out of the ability to read your files. What's left to talk about is account details and activity records.
2. Our roles
For account, billing, and audit/operational data, the Company is the data controller. For the contents of documents your Firm stores, your Firm remains responsible as controller of its own client data. We act, at most, as a processor of ciphertext on the Firm's instructions — ciphertext we are technically incapable of reading.
In plain language: We're responsible for the data about your account and activity. What's inside your documents stays your Firm's responsibility — we couldn't look if we wanted to.
3. Information we collect
You provide directly: name, email address and role when you register; your Firm's name, chosen data-residency region and optional branding (logo and colour — deliberately public, shown to share recipients); encrypted key envelopes, key-derivation salts and version tags, and a hashed login verifier — none of which reveal your passphrase or keys; encrypted documents, metadata and Vault Box payloads (ciphertext only); API key names and scopes (tokens stored hashed); webhook endpoint URLs you register.
Collected automatically: audit events — event type, account and document/share identifiers, timestamp and IP address, linked in a tamper-evident hash chain (this includes the IP addresses of anonymous share-link recipients); ciphertext sizes and upload timestamps; a single session cookie (section 6); and transient, in-memory rate-limiting counters.
What we never collect: passphrases; plaintext documents, filenames or folder structures; browsing analytics; advertising identifiers; tracking pixels. The Service contains no analytics or marketing trackers.
In plain language: We know who you are, when you signed in, and that a given encrypted document was uploaded, shared, or downloaded and from which IP — but not what the document is, what it's called, or what's in it.
4. How we use information
Account details and key envelopes operate your vault (sign-in, on-device decryption, firm escrow recovery). Audit events, including IPs, form the chain-of-custody log your Firm relies on — security, integrity evidence, PDF certificates. Ciphertext and sizes let us store and serve your encrypted documents and enforce plan limits. The session cookie and rate-limit counters keep you signed in and keep attackers out. API keys and webhook configurations power the integrations your Firm sets up. Billing details (when subscriptions launch) are used to charge for the Service and keep tax records.
We do not use your information for advertising, profiling, or training any AI system, and we do not sell it.
In plain language: Everything we hold exists to run the vault, prove chain of custody, and keep attackers out. Nothing else.
5. How we share information
Object storage providers — encrypted blobs are stored with S3-compatible providers (Cloudflare R2 by default, or the provider matching your Firm's chosen data residency). They receive ciphertext only. Hosting — the application runs on infrastructure that processes the operational data described above (provider to be named at production deployment). Your Firm's administrators — by design, firm admins see the firm-wide audit log and can recover member vaults through escrow recovery; every recovery is itself audit-logged. Webhook endpoints you configure — event metadata only (never ciphertext, filenames, or keys), HMAC-signed. Payment processor — when paid subscriptions launch, payments will be processed by Stripe; we will not store full card numbers.
Legal requirements — if compelled by law, we can disclose only what we hold: account details, audit metadata, and ciphertext. We cannot produce plaintext documents in response to any demand, because we do not possess the keys. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
In plain language: Storage providers get scrambled bytes; your firm's partners see the activity log (that's the product working as intended); and if a court orders us to hand things over, the most anyone gets from us is ciphertext and metadata.
6. Cookies
The Service sets one cookie: lv_session, an essential, httpOnly session cookie that keeps you signed in. It is strictly necessary, so no consent banner is required under PECR. Your decryption keys live in your browser tab's session storage and are never transmitted to us. There are no analytics, advertising, or third-party cookies. If we ever add analytics, we commit to an opt-in banner first.
In plain language: One cookie, and it just keeps you logged in. No trackers.
7. Data retention
Account details and encrypted content: life of the account plus 30 days after closure (an export/grace window). Audit logs: per your Firm's plan — 30 days on Solo, up to 7 years on Practice and above. Revoked API keys and deleted webhooks: the record of their creation and revocation remains in the audit chain. Billing records (when live): 6 years after the relevant tax year, per UK requirements. Rate-limit counters: minutes, in memory only.
In plain language: Your data lives while your account does, plus 30 days' grace. Activity logs last as long as your plan promises. Tax records stick around because HMRC says so.
8. Your rights
You can ask us to access, correct, delete, or export the personal data we hold about you, or object to or restrict processing. Contact us via section 13; we respond within one month.
Two honest caveats unique to this design: (a) we cannot "hand over" or delete the contents of documents in any readable form — we can delete ciphertext, and export of readable documents happens on your device while you hold the keys; and (b) audit-chain entries are tamper-evident by design — where erasure of an event would break integrity guarantees your Firm relies on, we may instead anonymise the personal identifiers within it, where the law allows.
In plain language: Ask and we'll show you, fix, or delete what we hold. But we can't decrypt your documents for you, and the activity chain is deliberately hard to quietly edit — that's its job.
9. UK & EU (GDPR)
Where UK GDPR / EU GDPR applies, our legal bases are: contract (running the Service you signed up for), legitimate interests (security, audit integrity, abuse prevention), legal obligation (tax and company records), and consent where we ever ask for it separately. You have the rights in section 8 plus the right to complain to the Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.
International transfers: encrypted content is stored in the region your Firm selects. Where operational data leaves the UK/EEA, we rely on adequacy regulations or standard contractual clauses / the UK IDTA — noting that document content is end-to-end encrypted wherever it sits.
In plain language: EU/UK privacy law applies in full, you can complain to the regulator, and your firm literally chooses which country the encrypted files live in.
10. California (CCPA/CPRA)
We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. California residents may exercise rights to know, delete, and correct via the contact in section 13, without discrimination. Categories collected: identifiers (name, email, IP), professional information (firm, role), and internet activity limited to the audit events described in section 3.
In plain language: California's rights apply too, and the answer to "do you sell my data" is no.
11. Children
The Service is for professional business use by adults (18+). We do not knowingly collect information from children, and no part of the Service is directed at them.
In plain language: This is a tool for law firms, not children.
12. Security
Documents are encrypted client-side with AES-256-GCM (per-file keys, wrapped under your vault key); passphrases are stretched with memory-hard Argon2id; login verifiers, session tokens, and API keys are stored hashed; every sensitive action lands on a tamper-evident audit chain; and the service ships with rate limiting, account lockout, and strict security headers. Pilot honesty: the cryptography has not yet been independently audited. If a breach affects your personal data, we will notify you and the relevant regulator without undue delay and within the timeframes required by law (72 hours to the ICO where GDPR applies). A breach of our storage, it is worth saying plainly, exposes ciphertext.
In plain language: Strong, modern crypto with the keys in your hands — if someone ever steals our hard drives, they get gibberish. We'll still tell you if anything goes wrong.
13. Changes and contact
We will give reasonable notice of material changes to this policy (email or in-Service notice) and update the date above. TKJ GLOBAL MEDIA LTD (Company No. 08272919, England and Wales). Registered office and privacy contact email to be confirmed on publication.
In plain language: If this policy changes meaningfully, you'll hear about it before it applies.