BriefLink Privacy Notice
Version: 2026-06-07
Last updated: 7 June 2026
Contact: info.brieflink@gmail.com
Draft for counsel review. Do not treat this document as final legal advice.
1. Who we are
BriefLink (brieflink.co.za) provides legal practice management software to law firms and advocates in South Africa. For the purposes of the Protection of Personal Information Act, 2013 (POPIA):
- BriefLink acts as an operator when processing personal information on behalf of subscribing firms.
- Your firm (the subscriber) is the responsible party for personal information relating to your clients, matters, and counterparties that you enter into BriefLink or cause to be processed through connected integrations.
2. What we process
2.1 Firm user account data
We process information about attorneys, advocates, secretaries, and administrators who use BriefLink, including name, email address, role, firm membership, authentication credentials (hashed), and usage audit metadata.
Purpose: Provide and secure the BriefLink service, authenticate users, and maintain an audit trail.
2.2 Client and matter data (on firm instruction)
When your firm uses BriefLink, we process client and matter information that your firm enters, including encrypted client contact details, matter records, billing data, documents metadata, tasks, appointments, and correspondence log entries.
Purpose: Legal practice management on your firm's instruction.
2.3 Correspondence capture (optional, firm opt-in)
If your firm enables communications capture and a user connects a mailbox or messaging account, BriefLink processes:
- Message metadata (date, direction, counterparty label, match signals)
- A short snippet (up to 500 characters), not the full message body
- A deep link to open the original message in Gmail, Outlook, or WhatsApp
Full message bodies remain in the third-party mailbox or messaging platform. BriefLink does not store full email or WhatsApp message bodies by default.
Purpose: Matter correspondence logging and allocation on your firm's instruction.
2.4 Google Drive document storage
When your firm connects Google Workspace, documents uploaded through BriefLink are stored in your firm's Google Drive (Shared Drive or firm-controlled folder). BriefLink accesses files only via the limited `drive.file` scope and does not broaden sharing permissions.
Purpose: Document management on your firm's instruction. Your firm remains the responsible party for documents stored in your Drive.
2.5 Google Calendar sync (optional)
When a user connects a personal Google account, BriefLink may sync appointments between BriefLink and the user's Google Calendar (two-way). BriefLink processes calendar event metadata (title, time, location, attendees) to display and reconcile appointments. Calendar data is not used for advertising or unrelated purposes.
Purpose: Scheduling and calendar integration on your firm's instruction.
3. Lawful basis
BriefLink processes firm user account data to perform our contract with your firm (Terms of Service) and, where applicable, with your consent at registration.
Your firm determines the lawful basis for processing client and matter data, including correspondence capture. BriefLink processes that data strictly as operator on your firm's documented instructions. See our Data Processing Agreement.
4. Sub-processors
BriefLink uses the following sub-processors to deliver the service. A current register is published at /sub-processors.
| Sub-processor | Services used | Data processed |
|---|---|---|
| Microsoft Corporation | Microsoft Graph (Outlook/M365) | Email metadata and snippets when a user connects Outlook and capture is enabled |
| WhatsApp BSP *(if enabled)* | WhatsApp Business API | Message metadata and snippets for firm's registered business number only, when C3 feature is enabled |
We will update the sub-processor register before enabling new integrations.
5. Data minimisation and retention
- Client contact details are encrypted at rest (AES-256-GCM).
- Correspondence capture stores metadata, snippets, and deep links only — not full message bodies.
- Firms may configure snippet retention (purge snippet text after N months while keeping metadata and links).
- Audit logs record actions (not message content) and are retained for accountability purposes.
6. Security
We apply tenant isolation, role-based access controls, encrypted storage for sensitive client fields, rate limiting on sensitive endpoints, and structured logging that avoids PII in log payloads. See our Data Processing Agreement for further security commitments.
7. Your rights and your firm's obligations
7.1 Firm users
You may request access to or correction of your account information by contacting info.brieflink@gmail.com.
7.2 Client data subjects
Your firm's clients and counterparties should direct data-subject requests (access, correction, deletion) to your firm as responsible party. BriefLink supports your firm with:
- Correspondence erasure: In-app tool to delete captured correspondence entries for a client from BriefLink (does not delete originals in Gmail, Outlook, or WhatsApp).
- Per-client exclusion: `Exclude from capture` setting to stop future ingestion for a client.
- Client and matter deletion: Deleting matters and clients removes associated records per our data lifecycle; audit entries of deletions are retained.
8. International transfers
Google and Microsoft may process data in facilities outside South Africa. We rely on their standard contractual safeguards and your firm's acceptance of connected integrations.
9. Changes
We may update this notice. Material changes will be reflected in the version date above and, where required, communicated to firm administrators.
10. Contact
BriefLink
Email: info.brieflink@gmail.com
Website: https://brieflink.co.za
For complaints under POPIA, you may also contact the Information Regulator (South Africa).