Occasionally a public authority asks a company to hand over user data. We would rather tell you how we handle that before it happens than after. Four commitments apply to every such request, whatever its source:
- We check that it is lawful. Every request is reviewed against the law of the jurisdiction it comes from before anything is disclosed. We require valid legal process — a warrant, court order, or an equivalent binding instrument. An informal request from an official, without legal process behind it, is refused.
- We push back on requests we believe are unlawful. If a request is overbroad, defective, or conflicts with the law we operate under, we challenge or reject it and take legal advice where the stakes warrant it.
- We disclose the minimum. Where disclosure is legally required, we produce only the specific records the instrument actually compels — never a whole account, and never a bulk export, because a request named one person.
- We write it down. Every request, our legal reasoning, who was involved, and exactly what was disclosed is recorded and retained.
Where we are legally permitted to do so, we will notify the affected customer before disclosing their data, so they have the opportunity to seek their own remedy.
To date we have never received a request of this kind. If that changes, this page changes with it.