Security, privacy, and compliance for sensitive legal data
The short version
HarkIQ processes call transcripts that contain some of the most sensitive information a law firm holds: client health details, vulnerability indicators, legal proceedings, and financial circumstances. We built HarkIQ knowing that this data demands the highest level of care. Here is exactly how we handle it.
Looking for the full briefing for your DPO? Download the DPO Briefing Document or the DPIA Template.
Your firm decides what data to upload and how the analysis is used. HarkIQ processes transcripts solely on your instructions, to provide the analysis service. We never make independent decisions about your data.
HarkIQ is multi-tenant with strict data isolation. Every firm’s data is segregated at the database level using PostgreSQL row-level security. No firm can ever see, access, or be affected by another firm’s transcripts or analysis. This is enforced at the infrastructure level, not just the application level.
We do not sell your data. We do not licence it to third parties. We do not use it for marketing purposes. Your transcripts and analysis exist solely to provide you with the HarkIQ service.
Every analysis can be exported as a PDF report or CSV file directly from your dashboard. Data is kept for the retention period your firm configures (365 days by default), then deleted. Everything can be exported on request, including after you cancel.
When you upload a transcript, it is sent to the Anthropic Claude API for analysis. This is important to understand:
HarkIQ’s AI analyses each transcript against eight quality dimensions and returns a structured score, vulnerability flags, and recommendations. It does not:
HarkIQ automatically redacts personal identifiers and financial details from every transcript before it is sent to the AI for analysis. This is on by default for every firm. Names are the deliberate exception: they stay in so your firm can match repeat callers and handlers.
The conversation itself: what was said, how it was said, whether the caller was handled well, and the names used in it.
When redaction is on (the default), the original transcript is deleted immediately after analysis and only the redacted copy is stored. Only the redacted copy is available in your dashboard.
Call quality scoring is based on how a conversation was handled: the empathy, the listening, the information gathering, the compliance. None of that requires a caller’s phone number, address or bank details. By stripping those before they reach the AI, we reduce the sensitivity of the data being processed and simplify your firm’s data protection position.
HarkIQ’s security is designed for the sensitivity of legal sector data.
All stored data is encrypted using AES-256 via Supabase managed encryption.
All communications between your browser, our servers, and the AI API use TLS.
Database-level isolation ensures each firm’s data is completely separated. This is enforced by PostgreSQL, not application code.
Four permission levels (Admin, Manager, Analyst, Viewer) control who sees what within your firm. Handler performance data is restricted to management roles.
Email and password login with optional multi-factor authentication. Session tokens with configurable expiry.
Every data access event, analysis, and user action is logged with timestamp and user identity for compliance reporting.
On by default. Phone numbers, email addresses, postcodes, NHS and NI numbers, card numbers, bank details, IBANs, and dates of birth are automatically stripped from transcripts before AI analysis. Names are kept for repeat-caller matching.
All API endpoints are rate-limited and validated using structured schemas to prevent abuse.
All stored data (transcripts, analyses, and firm accounts) is held on EU servers. AI analysis stays in AWS’s London region (Claude accessed through Amazon Bedrock in AWS’s London region, account pinned to zero data retention: no request or response written to durable storage by AWS or shared with Anthropic; not used for training). One thing leaves the UK and EU: crisis alert emails sent through SendGrid (United States), which carry only a call reference number and a severity level.
Transparency about where data flows is important. A full list of services, their data processing locations, and transfer mechanisms is set out in the International data transfers section below.
HarkIQ is designed for UK GDPR compliance. We operate as a data processor under Article 28. A Data Processing Agreement is available for all customers and is provided during onboarding. Our DPA covers processing scope, security measures, breach notification, sub-processor management, and data deletion.
We recognise that call transcripts may contain special category data under UK GDPR, including health information and details of legal proceedings. Our security architecture, data isolation, closed AI model, and retention policies are specifically designed to handle this classification of data appropriately.
We provide a DPIA template to help your firm’s DPO assess the data protection implications of using HarkIQ. This covers the data processed, lawful basis guidance, risk assessment, and the technical mitigations HarkIQ provides. Download our pre-populated DPIA template to get started. It includes HarkIQ-specific information covering data flows, sub-processors, risk assessments, and recommended measures, with fillable fields for your firm’s DPO to complete.
In the event of a personal data breach, we will notify affected customers within 72 hours, in line with UK GDPR requirements. Notification includes the nature of the breach, data subjects affected, likely consequences, and measures taken.
HarkIQ has been designed in line with the SRA’s warning notice on the misuse of AI, published 17 August 2026, and its earlier compliance tips on the use of AI and technology. We recommend that every firm considering HarkIQ reads both before making a decision: SRA warning notice: misuse of AI (17 August 2026) and SRA compliance tips for solicitors on AI and technology.
The sections below set out how HarkIQ addresses each of the SRA’s requirements.
The SRA is explicit: the Compliance Officer for Legal Practice (COLP) should be responsible for regulatory compliance when new technology is introduced, with board-level oversight of both the purchasing decision and ongoing use.
Before going live with HarkIQ, we recommend your firm does the following:
HarkIQ analyses call transcripts that your firm has already created. We do not record calls. However, for HarkIQ to be lawfully used, your call recording consent notices and client-facing privacy notices must cover AI-powered analysis of transcripts as a processing purpose.
Your standard call recording announcement (the message callers hear at the start of a call) and your firm’s privacy notice should state that calls may be transcribed, and that transcripts may be analysed using AI tools for quality monitoring, vulnerability detection, and compliance purposes.
We provide template wording to help your firm update these notices. Contact us to request it.
This is your firm’s responsibility as data controller. We flag it here because it is the most commonly overlooked compliance step when firms implement call analysis tools.
UK GDPR Article 22 gives individuals the right not to be subject to decisions based solely on automated processing where those decisions produce significant legal or similarly significant effects.
HarkIQ does not constitute automated decision-making within the meaning of Article 22. HarkIQ produces scores, flags, and recommendations. It does not make decisions. Every output requires a human professional to review it and apply their own judgement before any action is taken. HarkIQ has no authority to take any action affecting a client or a member of staff.
Your internal policy should confirm that HarkIQ scores are not used as the sole basis for any consequential decision, including disciplinary action, performance management, or safeguarding referrals. The score informs. The professional decides.
AI analysis is not infallible. A transcript may be mis-scored because of transcript quality, unusual call content, or the inherent limitations of AI pattern recognition.
HarkIQ scores are management indicators, not verified assessments. If a score appears inconsistent with your professional experience of a call or handler, treat your professional judgement as the primary source. Do not act on a score that does not make sense to you without first reviewing the underlying transcript.
If you believe HarkIQ has produced a materially incorrect analysis, contact us. We will investigate, and where the issue is with the model or prompt we will correct it. We maintain version control of all AI prompts and can re-analyse transcripts if required.
Your firm retains full professional responsibility for any decision made using HarkIQ outputs. HarkIQ is a tool. The solicitor remains accountable.
HarkIQ’s database is hosted entirely within the European Union. All transcripts, analysis results, and firm account data are stored on EU servers and never leave the EU for storage purposes. AI analysis stays in AWS’s London region (Claude accessed through Amazon Bedrock in AWS’s London region, account pinned to zero data retention: no request or response written to durable storage by AWS or shared with Anthropic; not used for training). One thing leaves the UK and EU: crisis alert emails sent through SendGrid (United States), which carry only a call reference number and a severity level.
The sub-processor table below lists several US-based services. Seeing “United States” in that table does not mean your data is unprotected. UK GDPR does not prohibit international transfers; it requires appropriate safeguards. The position for each service that handles personal data:
| Service | What it does | Location | Receives transcript data? | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Database and authentication | European Union | Yes: stores all data on EU servers. AES-256 encryption at rest. | No international transfer. All data stored on EU servers. |
| Claude accessed through Amazon Bedrock in AWS’s London region | AI transcript analysis | United Kingdom (AWS London region) | Yes: PII-redacted transcripts. Zero data retention; nothing written to durable storage. Not used for training. | No international transfer for AI analysis: processing stays in AWS’s London region under the AWS Customer Agreement and its GDPR Data Processing Addendum. |
| SendGrid (Twilio) | Crisis alert and account emails | United States | No: a call reference number and severity level only | Twilio standard terms incorporating Standard Contractual Clauses with the UK Addendum; under review |
| Vercel | Web application hosting | US with global edge nodes | No | Not applicable |
| Stripe | Payment processing | United States | No: billing details only | Not applicable |
| HubSpot | Marketing emails | United States | No: email address and firm name only | Not applicable |
Anthropic’s full Data Processing Addendum, which includes the UK Addendum covering transfers from the UK to the US, is published at anthropic.com/legal/data-processing-addendum.
Our Data Processing Agreement sets out the transfer mechanism for each sub-processor in full. Enterprise customers can request copies of all sub-processor DPAs by contacting david@harkiq.com.
It provides AI-generated scores, vulnerability flags, and recommendations to help law firms understand call quality patterns, identify coaching opportunities, and evidence compliance improvement.
HarkIQ should not be used as:
Vulnerability detection is an assistive flag aligned with the FCA’s four-driver model. It highlights calls that may warrant further attention. Your professionals make the decisions.
Two documents written for Data Protection Officers and compliance leads at law firms considering HarkIQ.
DPO Briefing Document
Full briefing covering data flows, Law Society GDPR guidance mapping, sub-processors, international transfers, and security architecture. 18 sections.
DPIA Template
Fillable PDF form pre-populated with HarkIQ’s information. Your DPO completes the firm-specific sections, records the approval decision, and retains it as part of your data protection records. 10 sections, 41 interactive fields.
Our Terms of Service, Privacy Policy, and Data Processing Agreement are also available on request. Email david@harkiq.com.
If you have questions about how HarkIQ handles your data, or if your DPO needs additional information before approving HarkIQ for use, contact us at david@harkiq.com. We are happy to provide our Data Processing Agreement or discuss specific security requirements.
Download the DPO Briefing Document and DPIA Template above, or email david@harkiq.com for our Terms of Service, Privacy Policy, and Data Processing Agreement.