Information Security Addendum

This Information Security Addendum forms part of the Agreement between OrdoLux and the Customer and supplements the Data Protection Addendum. It describes the technical and organisational measures referenced at paragraphs 2.5 and 4.1 of the Data Protection Addendum.

Contents

  1. Scope and purpose
  2. Infrastructure overview
  3. Technical security measures
  4. Organisational security measures
  5. Personnel security
  6. Physical and environmental security
  7. Vulnerability and penetration testing
  8. Incident management and breach response
  9. Data retention and deletion
  10. Independent certifications and assurance
  11. Sub-processors
  12. Data residency and international transfers
  13. Backups and disaster recovery
  14. Review and updates

1. Scope and purpose

This Addendum describes the technical and organisational measures implemented by OrdoLux (the Supplier) to safeguard Protected Data processed in the provision of the Services, as referenced at paragraphs 2.5 and 4.1 of the Data Protection Addendum.

OrdoLux is built and hosted on the Base44 platform (a Wix-owned company). The security measures described in this Addendum are implemented through a combination of OrdoLux's own application-level controls and the platform-level security infrastructure provided by Base44. Where measures are provided by Base44, this is stated explicitly.

2. Infrastructure overview

OrdoLux is a cloud-based legal practice management platform built on the Base44 platform (a Wix-owned company). Application data is hosted on Google Cloud infrastructure provided by Base44. Customer documents (PDFs, Word files, Excel files, and other matter documents) are stored within the Customer's own Microsoft 365 / SharePoint tenancy and are not hosted on OrdoLux infrastructure. OrdoLux accesses these documents via the Microsoft Graph API using scoped OAuth permissions limited to designated SharePoint sites.

OrdoLux application data (matter records, time entries, billing data, tasks, client and contact information, audit logs) is stored on Base44 infrastructure. Data residency and international transfer safeguards are addressed in paragraph 7 of the Data Protection Addendum and in section 12 of this Addendum.

3. Technical security measures

3.1 Encryption

3.2 Authentication and access control

3.3 Application security

4. Organisational security measures

4.1 Security management system

Base44 maintains an ISO 27001 certified Information Security Management System (ISMS) that governs security practices across people, processes, and technology. The ISMS is subject to regular internal audits and independent external assessment as part of the SOC 2 Type II audit cycle. OrdoLux benefits from this ISMS as a hosted application on the Base44 platform.

4.2 Security monitoring

5. Personnel security

Access to OrdoLux infrastructure and Base44 backend systems is restricted to authorised personnel with a legitimate business need. The following personnel security measures are implemented as part of Base44's ISO 27001 certified ISMS:

6. Physical and environmental security

OrdoLux application data is hosted on Google Cloud infrastructure provided by Base44. Physical and environmental security controls for the underlying data centres are managed by the cloud infrastructure provider and include:

Customer documents stored in the Customer's own Microsoft 365 / SharePoint tenancy benefit from Microsoft's own physical and environmental security controls, which are independently certified under ISO 27001, SOC 2, and other frameworks.

7. Vulnerability and penetration testing

8. Incident management and breach response

8.1 Incident response plan

Base44 maintains an incident response plan as part of its SOC 2 Type II and ISO 27001 certified controls. The plan covers detection, containment, eradication, recovery, and post-incident review. OrdoLux relies on Base44's incident response capabilities for infrastructure-level incidents and maintains its own application-level monitoring for OrdoLux-specific issues.

8.2 Breach notification

9. Data retention and deletion

10. Independent certifications and assurance

The Base44 platform (on which OrdoLux is built and hosted) holds the following independent security certifications. OrdoLux benefits from these certifications as a hosted application on the Base44 platform. The certifications cover the infrastructure, platform, and organisational controls that protect OrdoLux application data.

SOC 2 Type II An independent audit assessing Base44's controls against the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). The audit covers access controls, encryption, monitoring, incident management, and change management. The full report is available under NDA on request through the Base44 Security Trust Center.
ISO 27001 International standard for information security management. Confirms that Base44 operates a certified Information Security Management System (ISMS) covering people, processes, and technology. The certificate is publicly available.
PCI DSS Base44 holds PCI DSS certification for payment processing. This applies to payment functionality within OrdoLux that uses Base44's payment infrastructure.
GDPR compliance Base44 is GDPR compliant and maintains a Data Processing Agreement available on request.

OrdoLux can facilitate a request to Base44 for a copy of the SOC 2 Type II report under NDA if the Customer requires it for due diligence purposes. The ISO 27001 certificate is publicly available and can be provided on request.

11. Sub-processors

OrdoLux engages the following sub-processors in the provision of the Services. This list is maintained and updated in accordance with the Data Protection Addendum. The current list is also available at www.ordolux.co.uk/subprocessors/.

Sub-processor Role Location Transfer safeguard
Base44 (Wix.com) Application hosting, backend infrastructure, data storage, managed authentication United States UK International Data Transfer Agreement / UK Addendum to the EU SCCs
Google Cloud (via Base44) Underlying cloud infrastructure for OrdoLux application data United States UK International Data Transfer Agreement / UK Addendum to the EU SCCs
Microsoft (Microsoft 365 / Azure) Customer document storage (SharePoint), email integration, calendar integration, single sign-on United Kingdom (Customer's own tenancy) No international transfer (data remains in Customer's UK tenancy)
Stripe Payments UK Card payment processing for client invoices generated through OrdoLux United Kingdom / Ireland No international transfer required for UK/Ireland processing
Checkboard Know Your Customer (KYC) and Anti-Money Laundering (AML) identity verification for matter onboarding United Kingdom No international transfer required
TM Group Property search ordering and results delivery for conveyancing matters United Kingdom No international transfer required
OpenAI AI assistant (OrdoLux "Cas") processing of matter text for drafting assistance and analysis. Each Customer may use its own OpenAI API key, under which the Customer contracts directly with OpenAI. OrdoLux facilitates the data transfer. United States UK International Data Transfer Agreement / UK Addendum to the EU SCCs

Base44 maintains data processing agreements with its vendors, including approved transfer mechanisms for any international data transfers as required under Data Protection Laws. OrdoLux ensures that all sub-processors are engaged under written contracts containing materially the same data protection obligations as those set out in the Data Protection Addendum.

OrdoLux will provide the Customer with at least 30 days' notice of any addition or replacement of a sub-processor, in accordance with paragraph 5 of the Data Protection Addendum, and the Customer may exercise its rights under that paragraph.

12. Data residency and international transfers

OrdoLux application data is stored on Base44 infrastructure located in the United States. International transfers of Protected Data are governed by paragraph 7 of the Data Protection Addendum and effected using the Lawful Safeguards described therein, including the UK International Data Transfer Agreement and/or the UK Addendum to the EU Standard Contractual Clauses.

Customer documents stored in the Customer's own Microsoft 365 / SharePoint tenancy are not subject to any international transfer initiated by OrdoLux, as they remain within the Customer's own Microsoft environment.

Where sub-processors process Protected Data outside the United Kingdom, the applicable transfer safeguard is identified in the sub-processor table in section 11.

13. Backups and disaster recovery

14. Review and updates

OrdoLux may update this Information Security Addendum from time to time to reflect changes in infrastructure, certifications, sub-processors, or security practices. Material changes will be communicated to the Customer in accordance with the Agreement.