Divvio Mediation Professional Data Protection and Confidentiality Terms
These are the controller and personal access obligations used for Divvio mediation practice workspaces. Applicants and invited team members can read them before creating or joining an account.
The independent controllers
- Practice controller
- The practice named in the application or invitation
- Its legal name, contact details and privacy notice are recorded when the practice applies or when a member joins its workspace.
Case information covered by these terms
Case information means any personal data made available through or received from the Divvio mediation service, including case membership and progress, declared financial figures, schedules and version history, supporting documents, consent and access records, and information about either party, children or other people. It may include health data or other special-category data where a person includes that information in a disclosure or document.
Independent controller relationship
Kintela Ltd, trading as Divvio (Divvio), and the named mediator or mediation practice (the Practice) each act as an independent controller for the personal data for which each determines its own purposes and means of processing. Nothing in these terms makes either party the processor, joint controller, agent or representative of the other unless the parties expressly agree otherwise in writing.
The Practice receives personal data as an independent controller when case information is first made accessible to it through the Divvio portal, whether or not anyone at the Practice has yet viewed, downloaded or exported it.
Each party is responsible for complying with the UK GDPR, the Data Protection Act 2018 and other data-protection law applicable to its own processing.
Permitted purpose and data minimisation
The Practice may access and use case information only to prepare for, conduct and administer the mediation to which the information relates, to meet applicable professional or legal obligations, and to establish, exercise or defend legal claims connected with that mediation.
The Practice must not use case information for advertising, unrelated client development, profiling, model training or any other incompatible purpose, and must access only the cases and information reasonably necessary for its work.
Lawful bases, special-category data and transparency
The Practice must identify, document and maintain its own lawful basis under Article 6 of the UK GDPR for each relevant purpose. Where information actually includes health data or another special category listed in Article 9, the Practice must also identify and document a valid Article 9 condition before processing it.
Financial information and ordinary personal information about children are not special-category data merely because they concern finances or children. The Practice must nevertheless treat all case information as highly confidential and give children’s personal data the particular protection required by data-protection law.
The Practice must provide the privacy information for which it is responsible, including its identity and contact details, purposes, lawful bases, recipients, retention periods and individual rights, at the time and in the manner required by law.
Mediation confidentiality and professional duties
The Practice must protect case information in accordance with its professional duty of confidentiality and, where applicable, the Family Mediation Council Standards Framework, Code of Practice and other binding professional rules.
These secure-handling obligations do not alter the evidential status of information under the applicable mediation rules. In particular, factual information material to financial issues is ordinarily open and may be referred to in later proceedings, while mediation discussions and proposals are ordinarily confidential or privileged subject to the applicable Code, safeguarding duties, law and court orders. The Practice must explain and apply that distinction accurately in the mediation.
The Practice may disclose case information only with appropriate authority from the relevant person, where required or permitted by law, a court, a regulator or an applicable safeguarding or professional duty, or to an authorised recipient who needs it for the permitted purpose and is bound by appropriate confidentiality and data-protection obligations.
Authorised people and onward sharing
The Practice must restrict access to personnel who need the information for the permitted purpose, have received appropriate data-protection and security training, and are bound by confidentiality obligations.
The Practice must not onward-share case information except as permitted by these terms and applicable law. Before using a processor, the Practice must carry out proportionate due diligence and put the written terms required by Article 28 of the UK GDPR in place.
Security, credentials and multi-factor authentication
The Practice must apply technical and organisational measures appropriate to the sensitivity and risk of the information, including least-privilege access, secure devices and networks, supported software, appropriate encryption, secure transfer and storage, and controls against accidental loss, alteration or unauthorised disclosure.
Every user must keep their Divvio credentials private, must not share an account, and must enable and maintain multi-factor authentication whenever Divvio makes it available. The Practice must also use multi-factor authentication on email, cloud-storage and other systems used to receive or hold downloaded case information wherever that capability is available.
The Practice must notify Divvio promptly if credentials may have been compromised and must immediately follow reasonable instructions to secure or suspend affected access.
Personal-data incidents
The Practice must notify Divvio without undue delay and, where practicable, within 24 hours after becoming aware of a personal-data breach or security incident affecting Divvio credentials or case information received through Divvio.
The notice must provide the information reasonably available about the incident, affected people and records, likely consequences, containment and remediation. The Practice must preserve relevant evidence, provide reasonable updates and cooperate with Divvio, while remaining responsible for its own notifications to the Information Commissioner, affected individuals or other authorities.
Individual rights and regulatory cooperation
The Practice is responsible for responding to requests and complaints concerning the copy of personal data it controls, including requests for access, rectification, erasure, restriction, objection and portability where applicable.
Each party must promptly route a request to the other where it concerns the other party’s processing and provide reasonable, timely assistance needed to identify relevant records, avoid disclosing another person’s information unlawfully, respond within statutory time limits, and deal with an enquiry from the Information Commissioner or another competent authority.
Retention, legal holds and secure deletion
The Practice must maintain and apply a documented retention schedule, keep case information no longer than necessary for the permitted purpose and applicable professional or legal obligations, and periodically review whether continued retention remains justified.
When retention is no longer justified, the Practice must securely delete or irreversibly anonymise portal exports, downloaded documents and other copies under its control, including copies held by its processors, subject to the normal expiry of protected backups. A lawful legal hold must be documented, limited in scope and reviewed regularly.
The Practice must promptly close or cancel the Divvio case when portal access is no longer required and must not keep a case open merely to postpone the start of Divvio’s retention period.
Client withdrawal and downloaded copies
A client’s withdrawal of sharing permission stops the Practice’s future access through Divvio in accordance with the service rules, but it cannot recall a PDF, spreadsheet, document or other copy already downloaded or otherwise received by the Practice.
After withdrawal, the Practice must reassess and document whether it has a lawful basis to retain or further use its copy, honour any applicable individual right, and stop processing that is no longer lawful or necessary. Withdrawal does not itself require erasure where the Practice has another valid basis and an applicable reason to retain the information.
Suspension, termination and continuing obligations
Divvio may suspend or terminate professional access where necessary to protect clients, comply with law, investigate misuse or address a breach of these terms. The Practice must stop using the portal immediately when access is suspended or terminated.
The independent-controller, confidentiality, security, incident, individual-rights, retention, deletion and cooperation obligations survive suspension or termination for as long as the Practice retains any case information.
The Practice must promptly tell Divvio if its controller identity, professional registration, privacy notice, authorised users or need for access changes, or if the person who accepted these terms lacked or ceased to have authority to bind it.
Effective date, changes and governing law
These terms take effect for the Practice when the authorised person records acceptance. Divvio may replace them for future access where reasonably necessary for legal, regulatory, security or service changes. A material new version does not bind the Practice merely because it is published: Divvio will require a fresh acceptance before further access to case information.
These terms and any non-contractual dispute arising from them are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, subject to any mandatory right or regulatory process that cannot lawfully be excluded.
Authority to accept
The person accepting these terms confirms that they are authorised to bind the named Practice or, where the mediator practises as a sole trader, to bind themselves in that professional capacity.
Member version 2026-07-31
Divvio Mediation Member Confidentiality and Secure-Access Acknowledgement
These personal duties apply to every person who receives access to a practice workspace. They sit alongside the controller terms above and cannot be satisfied through a shared practice login.
Private credentials
I will use my own Divvio credentials and will not share my account.
Assigned case access
I will access only cases assigned to me and use case information only for authorised mediation work.
Confidential handling
I will keep case information confidential and handle it using secure devices, networks, storage and transfer.
Incident reporting
I will report suspected credential compromise or a personal-data incident to my practice and Divvio without undue delay.
Continuing obligations
I understand that my access can be suspended or removed and that confidentiality, security, retention and deletion obligations continue for information already received.
Reading this page does not record acceptance
A founding Owner accepts for the named controller and personally during practice registration. An invited member accepts their personal commitments when joining the workspace. Divvio records the relevant version against that practice and account.