Two kinds of information
This policy explains what Xaqdoon does with personal data. It covers two kinds of information, and the difference between them decides who you should ask about what.
The first is data about the practice itself and the people who sign in to it: the name and telephone number of the practice, the name and email address of each user, and the record of what they do in the system. We decide why that data is held, and we answer for it.
The second is what a practice records about its own clients and their matters. There, the practice decides what is collected and why; we hold it and process it on the practice's instruction. A client, a witness or an opposing party who wants to see or correct what is held about them should ask the practice, not us - it is the practice's file.
What we collect
Only what the service needs in order to work.
- Account details: the name of the practice, its telephone number, its city and contact details, and the name and email address of everyone who signs in.
- What you enter: clients, matters, hearings, documents, invoices, payments and the notes attached to them.
- A record of use: the audit trail of who did what and when, sign-in times, and the network address a request came from.
- Technical data: browser type, language preference, and the diagnostic logs a server keeps in order to stay healthy.
- Messages you send us: enquiries from the contact form, and consultation requests sent to a firm through the public directory - including where you are, when you type it or tick the box to share it.
Why we hold it
To run the service: to sign you in, show your records, send the notifications your practice has asked for, and produce its documents.
To keep it secure: to notice an unauthorised sign-in, to investigate a fault, and to be able to say afterwards who did what.
To support you: to answer a question your practice has put to us about its own workspace.
To meet our legal obligations, and to bill a practice that is on a paid plan.
We do not use your data for advertising, do not profile individuals, and do not sell anything about you to anyone.
One practice cannot see another
Every record carries the practice it belongs to, and the separation is enforced by the database itself rather than by the application alone: a query that arrives without a practice attached is refused, not quietly widened to everybody.
Each practice has its own address and its own sign-in, and a user of one practice holds no account in another. The public directory shows only what a firm has chosen to publish about itself.
How it is protected
Security is a set of habits rather than a single feature. These are the ones the service is built on.
- Everything travels encrypted: the service is served over HTTPS and nothing else.
- Passwords are stored hashed. Nobody at Xaqdoon can read yours, and we will never ask you for it.
- Access inside a practice is decided by role, by the practice's own administrator - a clerk does not reach what a partner reaches.
- Every action of consequence is written to an audit trail, with who did it and when.
- Backups run on a schedule, and a practice can take its own at any time and set how long they are kept.
- No system is perfectly secure. If a breach affects your data we will tell the practices concerned without undue delay, and say plainly what we know and what we are doing about it.
Who else is involved
A small number of providers make the service run: a hosting provider for the servers, a network provider in front of them, and a provider that delivers email. Each is given only what it needs for its part, and none may use it for its own purposes.
Beyond those, we share a practice's data only on the practice's instruction or where a lawful order requires it - and we tell the practice first wherever the law allows.
If the business is ever sold or merged, data may pass with it. The practices affected are told before that happens.
Where it is held
Xaqdoon runs on rented servers in a commercial data centre, and pages are delivered through a network with points of presence in several countries. That means your data is stored and served outside Somalia.
Wherever it is held, it stays under this policy and under our contracts with those providers. If your practice needs to know the current location in writing, ask us and we will tell you.
How long we keep it
While an account is open, records are kept until the practice deletes them. Deleting a record in the system removes it from the practice's workspace.
After an account is closed, the workspace is kept for thirty days so that a closure made in error can be undone, and then deleted.
A deleted record can survive for a while in a backup, until that backup ages out of the retention period the practice has set. Audit records and billing documents are kept for longer where the law requires it.
Your rights
For the data we answer for - your practice and the people who sign in to it - you may ask us to do any of the following, and we will answer within thirty days.
- Tell you what we hold about you, and why.
- Correct anything that is wrong. Most of it a practice can correct itself, from its own settings.
- Export your data in a form you can take elsewhere.
- Delete an account, and the data belonging to it.
- Object to something we are doing with it, or complain about how we have handled it.
- For anything a practice recorded about its clients, that request goes to the practice. We will act on the practice's instruction, and will point a request our way to the right practice where we can.
Children
Xaqdoon is a tool for legal practices and is not directed at children. We do not knowingly open an account for anyone under eighteen.
A practice may of course hold records about a child as part of a matter. Those are the practice's records, and they are handled under this policy like any other.
Changes to this policy
This policy will change as the service does. The date at the head of the page always says when the current version was published.
A material change is announced by email to each practice's administrator at least thirty days before it takes effect, so that a practice that does not accept it has time to export its records and close its account.