Privacy Notice
Version 1.0 · Effective from Monday 31 August 2026
Version. 1.0
Effective from. Monday 31 August 2026
Review. Annually.
Published at. bonsai.law/circle/privacy
1. Who this notice is for
This notice is for applicants to, and members of, the Bonsai Circle. If you visit bonsai.law without applying or joining, the Bonsai Law privacy notice at bonsai.law/privacy applies to you instead.
2. Who the data controller is
Data controller: Bonsai Law Ltd, a company registered in England and Wales, registered office The Business Terrace, Maidstone House, King Street, Maidstone, Kent ME15 6JQ, company number 13926937.
ICO registration number: ZB361139.
Data protection contact: bonsai.circle@bonsai.law (subject line "Data Protection").
You have the right to complain to the Information Commissioner's Office at ico.org.uk. We would rather you came to us first, but you do not have to.
3. What personal data we process
About applicants:
- Name, previous professional names, date of birth, contact details including mobile telephone number, home address.
- Occupation, employer, professional qualifications, regulator, regulatory record.
- Companies House directorships and disqualifications.
- Adverse-media search results returned in respect of your name.
- Basic disclosure certificate issued by the Disclosure and Barring Service and returned to us by our DBS Responsible Organisation on your behalf.
- Declared unspent convictions and cautions.
- Written references and referee contact details.
- Sponsor interview minutes.
- Payment information (processed by Stripe on our behalf, held by them not us).
- The report of your identity and address verification prepared by our identity verification provider on your behalf. We do not receive, store or handle the underlying identity and address documents; they remain within the provider's platform.
About members, additionally:
- Attendance, slot choices (referral / problem / observer), and meeting participation.
- Forum posts, edits, and reactions, together with a per-page identity watermark rendered against your session.
- Direct messages sent to and received from other members through the Circle direct-message function, together with the same per-page identity watermark, the time each message was sent, and whether the recipient has read it.
- Attendance records for meetings you RSVP to and meetings you attend, including whether you were present, late, absent or joined a walk-in slot, and (for online meetings on the Teams integration once live) the time you joined and left the meeting.
- Human moderation decisions on your posts and direct messages, including any redaction or removal decision by the founders and any appeal outcome.
- Complaints or concerns raised about you, and their outcome.
- Communications with us about your membership.
Special category data and criminal offence data:
The basic disclosure certificate, declared convictions, and adverse-media findings are criminal offence data within Article 10 UK GDPR and Schedule 1 DPA 2018. We process them under the substantial public interest condition (Schedule 1 Part 2 paragraph 10, "preventing or detecting unlawful acts", and paragraph 12, "regulatory requirements relating to unlawful acts and dishonesty"), and hold an Appropriate Policy Document as required by paragraph 5.
We do not routinely process health data, racial or ethnic origin, political opinion, religion, trade union membership, genetic or biometric data. If a safeguarding matter requires us to record such data we will do so under Schedule 1 Part 2 paragraph 18 (safeguarding of individuals at risk) where applicable, and tell you.
4. What we use it for, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Deciding your application | Contract (Art 6(1)(b)): steps at your request prior to entering a contract. Legitimate interests (Art 6(1)(f)) for vetting checks on third parties: ensuring the safety of our members. |
| Vetting checks (DBS, adverse media, Companies House, references) | Art 6(1)(f) legitimate interests. Art 10 processing under Sch 1 Pt 2 para 10 and 12. |
| Running your membership and meetings | Contract (Art 6(1)(b)). |
| Operating the forum, including automated moderation | Contract (Art 6(1)(b)). Legitimate interests (Art 6(1)(f)) to keep the forum lawful and safe. |
| Complaint and disciplinary handling | Art 6(1)(f) legitimate interests. Sch 1 Pt 2 para 10 for any criminal offence data. |
| Safeguarding of individuals in Circle activity | Art 6(1)(f) legitimate interests. Sch 1 Pt 2 para 18 where safeguarding data arises. |
| Payment processing | Contract (Art 6(1)(b)). |
| Legal, regulatory and accounting compliance | Legal obligation (Art 6(1)(c)). |
| Improvements to the Circle service based on aggregated, non-identifying data | Legitimate interests (Art 6(1)(f)). |
Where we rely on legitimate interests we have carried out a balancing test. You may ask for a copy.
As part of vetting we may make a discretionary decision to decline an application on the basis of adverse media findings we consider material to your suitability for the Circle, or where we form the view that your expressed values, positions or professional conduct are materially incompatible with the values on which the Circle is built. This is not a decision based on any protected characteristic under the Equality Act 2010; it is an assessment of expressed views and conduct. Our lawful basis for this processing is legitimate interests, namely the operation of a small private members' club whose viability depends on trust between members. You have the right to request the reason for a decline decision, which we may give in summary form to protect the confidentiality of any third-party information relied on, and to request internal review by the second founder within 14 days.
5. Where the data comes from
- From you, in your application and during your membership.
- From your named referees.
- From the Disclosure and Barring Service, via our DBS Responsible Organisation acting on our instruction and on your consent.
- From Companies House, via its public API.
- From adverse-media search providers who query public and licensed news sources against your name.
- From Thirdfort, our identity and address verification provider, which returns a completed verification report to us. The underlying identity and address documents remain within Thirdfort's platform.
- From other members or third parties who raise concerns about you.
- From your interactions with the forum and member area.
6. Who we share it with
- Our staff and the founders, on a need-to-know basis.
- Thirdfort Limited, our identity and address verification provider, acting as processor. Company number 09933583. Registered in England and Wales. Certified against the UK Digital Verification Services trust framework. Personal data supplied for the ID and address check: your name, date of birth, mobile number and email. The underlying document images and biometric data are handled within Thirdfort's platform under their own data processing terms and are not returned to us.
- Our DBS Responsible Organisation, acting as processor for the purpose of instructing and receiving your basic DBS certificate on our behalf. Registered on the gov.uk Responsible Organisations register.
- Our adverse-media provider, acting as processor. Your name and declared identifiers, for the search.
- Anthropic PBC, as the model provider for the forum classifier when it is deployed, reached exclusively via AWS Bedrock EU or Google Cloud Vertex AI Europe. Post content, DM content and prompt metadata are sent for classification. No training use. Full detail in section 10.
- AWS EMEA SARL and/or Google Cloud EMEA Ltd, as infrastructure providers for the Bedrock or Vertex classifier route and for cloud hosting.
- Stripe Payments Europe Ltd, as payment processor.
- Microsoft Ireland Operations Ltd, for the online meeting platform (Teams), the member area (Microsoft 365 tenant), and email.
- Our insurers and professional advisers, only where relevant.
- Regulators, law enforcement and courts, where we are legally required.
We do not sell your data. We do not use your data for advertising. We do not share your membership status with the public.
6A. Founder access to direct messages
Direct messages between members are stored on the platform. Founder access to direct messages is limited to two modes:
Report-driven access. Where a member flags a direct message using the flag button on the message, the founders may open and review the thread containing that message to reach a moderation decision under the Forum Rules and the Confidentiality Regime. This is the ordinary route.
Legal-hold access. Where the founders are required to disclose direct-message content in connection with a SRA request, a court order, a statutory disclosure obligation or the defence of the firm in a complaint, the founders may export direct messages for the named members whose messages are within the scope of that requirement, up to a maximum of ten members per export. Every legal-hold export is logged with the founder's identity, the reason and the named members. Every legal-hold export triggers an email to the other founder. The aggregate number of legal-hold exports and the reason categories are included in the annual transparency summary. No firm-wide export of member direct messages is available.
Outside these two modes, founders do not read direct messages. Direct messages are retained for 7 years from the date of the message.
7. International transfers
Our default is UK/EU data residency and we choose providers and product configurations to keep it that way.
Where a transfer of your data to a jurisdiction outside the UK/EEA is unavoidable, we rely on:
- (a) UK adequacy regulations where in force;
- (b) the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses;
- (c) supplementary technical measures where the transfer risk assessment identifies them as necessary.
8. How long we keep it
Full detail in the Data Retention Schedule. In summary:
- Application file including DBS certificate: duration of membership plus 7 years, or until any legal claim is resolved.
- Refused applications: 12 months from decision, then anonymised.
- Forum posts:
- Referrals board: archived at 30 days, destroyed at 90 days.
- Problems board: archived at 60 days, destroyed at 12 months.
- Recommendations board: evergreen, reviewed annually.
- Circle News: retained for the life of the Circle.
- Direct messages between members: seven years from the date of the last message in the thread. This retention window is set by our record-keeping obligations as a regulated law firm and aligns with the Limitation Act 1980 for potential claims arising from Circle-based interactions.
- Meeting attendance records: seven years from the meeting date, aligned with the direct-message retention window and the record-keeping obligations above.
- Moderation and classifier audit log: 3 years.
- Complaints, disciplinary and removal records: 7 years from closure.
- Accounting records: 7 years, to meet HMRC requirements.
- On leaving: your name on forum posts and in direct-message threads is updated to "Former member" (or "Removed" where the departure follows a founder decision), and the content itself is retained on the schedule above. The other party to a direct-message thread can continue to read the history but cannot send messages to your account. Complete erasure is available on request under section 9, subject to the carve-outs in that section.
9. Your rights
You have the right to:
- ask us for a copy of your data (right of access);
- ask us to correct data that is wrong (right to rectification);
- ask us to delete data (right to erasure). Where UK GDPR Article 17(3) permits us to retain data despite an erasure request, we do so - in particular under Article 17(3)(b) where retention is required for compliance with a legal obligation, and under Article 17(3)(e) where retention is necessary for the establishment, exercise or defence of legal claims. Direct-message content and meeting attendance records fall within these carve-outs and are retained for the full seven-year window even after your membership ends; we pseudonymise your identifying details in the directory in response to an erasure request, but the underlying records remain until they age out. Moderation audit log entries are retained for the same reasons for the duration of their own retention period, and we may retain a summary record of a removed member for as long as necessary to prevent re-admission;
- ask us to limit our processing while a question is resolved (right to restriction);
- object to processing based on legitimate interests (right to object);
- ask for your data in a machine-readable form (right to data portability), where applicable;
- withdraw consent, where consent was our lawful basis, without affecting past processing;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects - see section 10;
- complain to the Information Commissioner's Office.
To exercise a right, email bonsai.circle@bonsai.law with the subject line "Data Protection". We reply within 30 days, or explain why we need longer.
Consent record export
Every acknowledgement or consent you have given as part of your application or membership is stored as a discrete consent event, recording the policy or provision acknowledged, its version, a content hash of the exact text at the time you ticked, the timestamp, and the IP address and user-agent from which the tick was recorded. On request under Article 15 UK GDPR we produce a consent report for you showing exactly what you agreed to and when. Email bonsai.circle@bonsai.law with the subject line "Data Protection" to request one.
10. Automated decision-making on the forum
The Circle does not currently use automated decision-making on forum content or on direct messages. All moderation is carried out by the founders under the Moderation Standard Operating Procedure. Article 22 UK GDPR therefore has no current application to your use of the Circle forum.
Automated pre-publication screening is planned for a future release. Before we introduce it we will:
- (a) publish an Automated Decision-Making Disclosure at bonsai.law/circle/moderation describing the model, the routing, what the classifier sees, and your rights;
- (b) complete and publish (in redacted form) a Data Protection Impact Assessment;
- (c) update this notice;
- (d) notify members by email at least 30 days before the change takes effect.
11. Watermarking
Every page rendered to you in the member area, on the forum, and in the direct-message function carries a faint identity watermark tied to your session. This is a technical measure that deters and traces screenshot leaks. The watermark contains data derived from your account identifier and session token, is faintly visible on the page you are viewing but not stored or transmitted to other members' devices, and is only decoded if we are investigating a suspected leak. Watermark data forms part of the moderation audit log and is retained on the same schedule.
12. Cookies
The bonsai.law/circle pages use only strictly necessary cookies for session management and CSRF protection. We do not use analytics or advertising cookies on Circle pages. Full detail in the Cookie Notice.
13. Security
We host on Microsoft 365 (UK tenant) and, for the forum, on infrastructure under our direct control in the UK/EEA. Access to member data is restricted to the founders and named staff. All access is logged. We require MFA on all administrator accounts. We test backups and review access rights annually.
14. Changes to this notice
We may update this notice. Where changes materially affect you we tell you by email to the notification address you have given us, at least 30 days before the change takes effect.
15. Contact
Data protection queries: bonsai.circle@bonsai.law, subject "Data Protection"
Correspondence from us: clientcare@bonsai.law
ICO: ico.org.uk, telephone 0303 123 1113
