Privacy & data protectionEffective September 8, 2026Version 3.1
Law Enforcement and Government Requests
This policy explains how Digital Socket LLC responds when a law-enforcement agency, a regulator, a court or another government authority asks us for data, and what we commit to doing for the customers whose data is asked for.
Our Data Processing Addendum incorporates the commitments below, so they are contractual obligations to our customers rather than statements of intention.
Nothing here is a promise to obstruct a lawful order. It is a description of what we require, what we challenge, and what we tell you.
Go to the customer, not to us
Almost all the data an authority might want from us belongs to a customer. We hold it as a processor on that customer's behalf: the employer decides what is collected, why, and how long it is kept.
So our default answer to an authority is to direct it to the customer, which is the party that controls the data, can identify what is relevant, and can assert its own rights and privileges. We will do that unless the law forbids us from doing so.
We will not volunteer customer data to any authority. We disclose only what we are legally compelled to disclose, or what is needed to address an emergency involving a risk of death or serious physical injury.
What we require before we disclose anything
We require valid legal process, properly served, and we assess each request on its own terms.
- The request must come from an authority with jurisdiction over us, and must be served through a route the law recognizes. A request from a foreign authority that has not used a mutual legal assistance treaty or another lawful channel is not valid process, and we will say so.
- The request must be in writing, signed, and issued under a specific legal authority that it names.
- It must identify the account or data sought with particularity. We reject requests that ask for "all data" about an organization, that seek data about unnamed individuals, or that are so broad that complying would mean handing over data unrelated to the investigation.
- Content — screenshots, activity records, the substance of what is held — requires a warrant issued on probable cause by a court of competent jurisdiction, or its equivalent outside the United States. A subpoena is not sufficient for content.
- Basic subscriber information may be disclosed on valid process of a lower standard, where the law requires it.
- Where a request is defective, overbroad, or issued without jurisdiction, we push back and require it to be narrowed or reissued. We have no obligation to interpret a defective order generously and we do not.
We challenge what should be challenged
We will challenge a request that is unlawful, that is overbroad, that conflicts with the law of another jurisdiction — including a request whose compliance would breach the EU GDPR or the UK GDPR — or that is accompanied by a gag order we believe to be unjustified.
Where a request conflicts with our obligations under the Standard Contractual Clauses, we will do what those clauses require: assess it, challenge it where there are grounds, pursue appeals, and disclose only the minimum permissible under a reasonable interpretation of the order.
We will seek to have a non-disclosure obligation lifted or time-limited so that we can tell the affected customer.
We tell you
We will notify the affected customer of a request for its data before we disclose anything, and give it a reasonable opportunity to seek protective relief, unless we are legally prohibited from doing so or there is an emergency involving a risk of death or serious physical injury.
Where we are prohibited from notifying you, we will ask for permission to notify, will challenge the prohibition where there are grounds, and will notify you as soon as the prohibition lapses or is lifted — including after the fact.
Notice goes to the account administrators on file, so keep those current.
We disclose the minimum
Where we must comply, we disclose only the specific data the order compels, for the specific accounts and time period it names. We do not provide bulk access, direct access, or a standing feed to any authority.
We have not built, and will not build, a mechanism giving any government direct or unmediated access to customer data. Every disclosure passes through a person who reviews the order against this policy.
Each request and its outcome is recorded, so that a customer, an auditor or a regulator can be told what happened.
National-security orders and our current position
As at the effective date of this policy, Digital Socket LLC has never received a national-security order, a foreign-intelligence surveillance demand, or a national-security letter, and has never been subject to a gag order preventing it from saying so.
We have never disclosed customer content to any government authority.
We are a private company established in the United States and are not, to the best of our knowledge, an "electronic communication service provider" of the kind subject to section 702 of the US Foreign Intelligence Surveillance Act in the manner most often raised in transfer impact assessments. We nonetheless assess and disclose the risk rather than assert it away, and our transfer impact assessment is available to a customer's privacy team on request.
We will update the statements above if they cease to be true and we are permitted to say so. Where we are prohibited from saying so, the removal of these statements from a future version of this policy should be read for what it is.
Emergency requests
Where an authority certifies that there is an emergency involving an imminent risk of death or serious physical injury to a person, we may disclose the limited information needed to address that emergency without waiting for legal process.
We evaluate each such request on its own facts, disclose the minimum, record what we did, and notify the affected customer as soon as we lawfully can.
Preservation
We will honour a valid preservation request by preserving a snapshot of the specified data for the period the law requires, typically 90 days, renewable once.
Preservation is not disclosure. Preserved data is not handed to anyone without valid legal process, and the customer is notified on the same basis as for any other request.
Civil litigation and third-party subpoenas
A party in a civil dispute should seek data from the customer that controls it, not from us. We will object to a civil subpoena served on us for a customer's data and direct the requesting party to the customer.
Where we are nonetheless compelled to produce, we notify the customer and give it the opportunity to intervene, subject to the same exceptions as above.
We may seek reimbursement of our reasonable costs of responding to a third-party request, where the law allows it.
Transparency reporting
We will publish an annual transparency report giving the number of requests received, by type and jurisdiction, the number we challenged, and the number that resulted in disclosure.
No report is published yet: the company has received no requests to report, and we would rather say that plainly than publish a page of zeroes styled as a report. The first report will be published for the first calendar year in which a request is received, and its absence before then means what it says.