Skip to content

Privacy policy

Last updated 2 September 2026

This text describes how Dangana works and is offered as a starting point. The firm operating this deployment should review it with counsel before publishing it as its own policy.

How Dangana handles personal data: what the firm's deployment holds, how it is protected, how long it is kept and what you can ask for.

Who is responsible for your data

Dangana runs as a single deployment operated by one law firm. That firm is the controller of every record held in its deployment: it decides what is entered, who may see it, and how long it is kept. The software vendor supplies and maintains the software; it does not hold a copy of the firm's data and cannot reach the deployment unless the firm opens a time-boxed support window.

What the system holds

The deployment stores what the firm enters and what the system records about its own use:

  • Staff accounts: name, work email, phone, job title and grade, practising details, and security settings such as multi-factor authentication.
  • Sign-in records: the time, outcome, network address and device description of every sign-in attempt, kept for twelve months.
  • Audit entries: who changed what and when, including the state before and after, so that access to confidential material can be investigated. The audit log cannot be edited or deleted.
  • Client and matter data entered by the firm: parties, identity details, addresses, matters, documents, diary entries, time, bills and accounting records.
  • In-app notifications and the emails or messages sent to deliver them.

How sensitive fields are protected

Identity numbers, passport numbers, bank account details and dates of birth are encrypted before they reach the database, so a copy of the database alone does not expose them. Documents are held in private storage and can only be opened through a short-lived link issued after the system has checked that the person asking may see them. Every such download is recorded.

Cookies

The application sets one session cookie that identifies your signed-in session and one small marker that tells the application a session may exist so it can send you to the right page. Neither is readable by scripts and neither is shared with anyone. No analytics or advertising cookies are set unless the firm configures an error-tracking service, in which case that service receives technical error reports without document contents.

How long records are kept

Retention follows the firm's professional and statutory obligations. Matter files and client account records are kept for at least seven years after closure, financial records for at least six years, identity verification records for five years after the relationship ends, and the audit log for at least seven years. Conflict-check history is kept permanently because future conflict checks depend on it. Nothing is destroyed automatically: records past their retention date are listed for review and destroyed only by a deliberate, recorded action.

Your rights

You may ask the firm what personal data it holds about you, ask for it to be corrected, ask for it to be erased, or ask for a copy in a portable form. The system records each request and its outcome. Erasure may be limited where the firm is required to keep a record by law or professional rules, or where a legal hold applies; in that case the firm will tell you what can and cannot be erased and why.

Vendor support access

Support access is off by default. A firm administrator may open a window of up to seventy-two hours during which a named support account with an explicit, limited set of permissions can act in the system. Every action taken by that account is tagged in the audit log, a banner is shown to all users while the window is open, and a summary of what the account did is sent to the administrator when it closes.

Contact

Questions about this policy go to the firm operating this deployment. Questions about the software itself go to contact@dangana.com.