Privacy Policy
Last updated 21 August 2026
1. Who We Are
Candid (“Candid”, “we”, “us”) provides software that assembles and checks Form E financial disclosure for family law firms in England & Wales. This policy explains how we handle personal data when a firm uses Candid, and how that data is protected.
2. Controller and Processor Roles
Your firm is the data controller for any client financial information uploaded to Candid — you decide what is collected and why, and you remain responsible for your clients under UK GDPR. Candid acts as a data processor, handling that data solely on your firm's instructions and under a Data Processing Agreement (DPA) agreed with your firm. We do not decide how client data is used beyond providing the assembly and checking service you've asked for.
3. What Data We Process
On your firm's instruction, Candid processes documents and figures relevant to Form E disclosure, including bank statements, payslips, P60s, pension statements, property valuations, and the figures extracted from them. We also process account information for the fee-earners and associates at your firm who use Candid (name, work email, role).
4. Where Data Is Hosted
All data is hosted in the UK and does not leave UK jurisdiction. Data is encrypted in transit (TLS) and at rest. We do not use overseas sub-processors for storage or processing of client documents.
5. AI Processing
Candid uses AI models to help assemble and cross-check figures from uploaded documents. Client documents and data are never used to train or fine-tune AI models — ours or any third party's — and are never retained by a model provider beyond the processing of a single request.
6. Retention
We retain case data for as long as your firm's account is active, plus a limited period afterwards to allow export or offboarding, unless your firm instructs us to delete it sooner. Retention periods are set out in your firm's DPA.
7. Your Rights
Because your firm is the data controller, individuals wishing to exercise a data subject right (access, rectification, erasure, portability, or objection) over their own data should contact your firm directly. Candid supports your firm in fulfilling these requests within the timeframes required by UK GDPR.
8. Security
We maintain a full audit trail of activity on each case, encrypt data in transit and at rest, and require explicit sign-off before any disclosure document is finalised or shared. See our Security page for more detail.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be notified to your firm's account holder in advance of taking effect.
10. Contact
Questions about this policy or a request relating to your firm's DPA can be sent to privacy@candid.legal.