Designed around privacy, security and respect.
Legacy Lock is being built with privacy and security as design principles, not afterthoughts. Below is how we think about protecting what you preserve.
Privacy First Design
Privacy is the starting point. You decide what to upload, share or omit. We collect only what is necessary to operate the service.
Security First Design
Security informs every architectural decision — from how data is stored and transmitted to who can request access, and under what conditions.
Data Protection
Legacy Lock is designed around UK GDPR and the Data Protection Act 2018. We document lawful bases, honour subject rights, and minimise the data we hold.
Encryption
Customer data is encrypted in transit, and encryption-at-rest is planned at launch. Encryption keys and key-handling procedures are designed around least-privilege access.
Access Controls
Access to systems is role-based and audit-logged. Legacy Lock staff do not browse customer vaults; administrative access is restricted to a small number of named individuals.
Future Two-Factor Authentication
Two-factor authentication is a planned launch feature, giving you an additional layer of protection on top of your password.
Data Minimisation
We collect only what is needed, for only as long as it's needed. You are not required to upload anything you don't want preserved.
Incident Response
If a personal data breach occurs that meets the threshold under UK GDPR, we will notify the ICO within 72 hours and affected individuals where required.
User Rights
You have the right to access, rectify, port, restrict, delete and object to processing of your personal data. Requests can be made via our contact channels.