Data protection
What happens to medical and legal records when they enter Sortica — the roles, the lawful basis, where the data physically sits, who else touches it, and what we have not built yet.
Last updated 1 September 2026
This statement describes Sortica's practices at the date above. It is written to be relied on during procurement and to be checked against our contract — but it is not itself the contract, and it is not legal advice. The binding terms are in the data processing agreement we sign with your firm.
Roles and purpose
The firm is the controller
Your firm determines the purposes and means of processing. Sortica acts solely on your documented instructions and does not determine the purposes of processing. Ownership of the records, and of everything generated from them, remains with the firm.
Sortica is the processor
We process records for one defined purpose: organising, extracting, summarising and structuring medical and legal documents in support of the establishment, exercise or defence of legal claims. There is no use beyond that purpose.
Purpose-limited by design
Matter data is not used for product analytics, benchmarking, marketing, or any secondary purpose, and is not disclosed to any third party outside the sub-processors listed below.
Medical data and AI
Special category data
Medical records are special category data under Article 9 UK GDPR. The lawful basis we rely on is Article 9(2)(f) — processing necessary for the establishment, exercise or defence of legal claims — with the firm confirming that basis in the DPA.
AI is assistive, never decisive
Models extract, structure and summarise. They do not make legal or medical decisions, and there is no automated decision-making or profiling with legal effect within the meaning of Article 22.
No training on your data
Client records are never used to train or fine-tune models, ours or anyone else’s. Documents are sent to the model gateway for inference on the matter in hand and for nothing else.
Human review is required, not optional
Every generated entry carries a verify control, and bundles are watermarked “AI-Generated — Review Required” until a fee earner signs the entries off. The watermark is part of the output, not a setting.
Where data lives
Every party that processes matter data on our behalf, what they do, and the region they do it in. Each is bound by data-protection obligations equivalent to those we accept, and we confirm the position for your firm in the DPA.
Amazon Web Services (S3, Textract)
eu-west-2 (London)Document storage and OCR of scanned or handwritten pages
Objects are written with AES-256 server-side encryption. Documents are read back through short-lived pre-signed URLs, not public objects.
AWS Amplify Hosting
eu-west-2 (London)Hosting and server-side rendering of the application
Serves both the marketing site and the authenticated application.
MongoDB Atlas
European Economic Area — eu-west-1 (Ireland)Application database — matter metadata, chronology entries, extracted text and embeddings
A managed cluster hosted within the EEA, covered by UK adequacy. Encrypted in transit and at rest, reachable only by the application, with access restricted to the personnel who operate the service. We confirm the hosting region for your firm in the DPA.
Managed AI gateway
Confirmed per engagementModel inference for extraction, chronology, summarisation and matter chat
Sortica is model-agnostic: inference is reached through a managed gateway under contractual terms that prohibit training on client content and limit processing to providing the service. No single model vendor is embedded in the product, so a model can be changed without altering the application or your data flows. We confirm the gateway’s processing locations for your firm on request.
Resend
EU/USTransactional and outreach email
Carries account and notification email only. Matter documents and chronology content are never sent by email.
We will not add a sub-processor that touches matter data without telling controllers first. Each is bound by data-protection obligations equivalent to those we accept.
Confidentiality and lifecycle
Access on a need-to-know basis
Application access is role-based — fee earner, firm administrator and super administrator — and a user only sees matters belonging to their own firm. Sortica staff access to production data is restricted to the personnel who operate the service.
Retention is controller-directed
Matter data is retained for as long as the matter is active in your account. On instruction we will export or delete a matter, or the firm’s entire dataset, and confirm deletion in writing.
No lock-in
Chronologies and bundles export as documents you keep. Ending the relationship does not strand your work inside the platform.
Security
Encryption
Documents are encrypted at rest with AES-256 server-side encryption in S3, and all traffic to and from the application is over TLS.
Segregation by firm
Every matter, document and chronology entry is bound to a firm, and every query is scoped to the requesting user’s firm. Documents in object storage are addressed by unguessable keys and served only through short-lived signed URLs.
Audit log
Views, edits, downloads and administrative actions are written to a per-matter audit log with the acting user and timestamp, so a firm can evidence who did what to a matter and when.
Authentication
Accounts are password-based with hashed credentials and session-based access; new firm signups are approved before activation. Multi-factor authentication and SSO/SAML are available on Enterprise terms.
AI use and professional responsibility
- Output is traceable to source: every chronology entry carries its document, real page number and the verbatim line supporting it.
- Original documents are preserved unaltered — the extraction sits alongside the source, never in place of it.
- Where records disagree, the conflict is raised for a human to resolve rather than silently reconciled.
- The firm retains professional responsibility for every legal conclusion drawn from the output. Sortica provides no legal or medical advice and makes no warranty as to the accuracy or completeness of generated content.
Incident response
If personal data we process for you is subject to a breach, we notify your firm without undue delay and give you what you need to meet your own obligation to the ICO: what happened, which matters and categories of data are affected, what we have done, and what we recommend. As controller, the decision to report to the regulator and to data subjects is yours. Where legally permitted, we would also tell you before disclosing any of your data in response to a legal demand.
FAQs
Which AI models do you use, and does our data train them?
Sortica is model-agnostic. Inference runs through a managed gateway under terms that prohibit training on client content, and no single model vendor is embedded in the product — models can be changed, or moved to a different deployment, without altering the application or your data flows. We name the current provider under NDA on request.
Does any of our data leave the UK?
Documents, OCR and generated bundles are stored and processed in AWS eu-west-2 (London). The application database is hosted within the EEA, under UK adequacy. Processing locations for every sub-processor are set out in the table above and confirmed for your firm in the DPA.
Can we get our data deleted, with confirmation?
Yes. On instruction we delete a matter or your firm’s entire dataset from the application database and object storage, and confirm the deletion in writing.
Who would you notify if there were a breach?
The firm, as controller, without undue delay and with the detail you need to meet your own Article 33 obligation to the ICO. The reporting decision to the regulator is the controller’s to make.
Will you sign our DPA rather than yours?
Yes, subject to review. We offer an Article 9-aware DPA as standard and are willing to work from the firm’s own surface.
Ask us anything here
Security questionnaires, your own DPA, a call with whoever owns information governance at your firm — all welcome. Write to hello@sortica.co.uk.