1.3 Our website is not intended for children. We do not knowingly collect or maintain the personal information of children under the age of 18. If you are under the age of 18, please do not access our website at any time or in any manner. We will take appropriate steps to delete the personal information of persons under the age of 18.
2. About us
2.1 We are a limited liability partnership registered in England and Wales under number OC304954, with our registered address as set out below.
2.2 You can contact us as follows:
FAO: Chief Operating Officer
Address: Harbottle & Lewis LLP
14 Hanover Square
3.1 Please click on the relevant heading below for more information on each of these areas:
4.1 We will collect any information that you provide to us when you:
4.1.1 make an enquiry, provide feedback, or make a complaint over the phone, by email, or via our website;
4.1.2 submit correspondence to us by post, email, or via our website;
4.1.3 submit answers to surveys, questionnaires and feedback forms to us in person, by post, email or via our website;;
4.1.4 subscribe to our newsletters, articles, bulletins, and other mailing lists;
4.1.5 register to and/or attend our events;
4.1.6 network with us (e.g. at law fairs, client events and/or other meetings or events either hosted or attended by us);
4.1.7 submit a CV and/or an application to a job vacancy; and
4.1.8 attend an interview or assessment.
4.2 We also capture visual data through CCTV employed in our office.
4.3 In certain circumstances, we will receive information about you from third parties. For example:
4.3.1 Employers, recruitment agencies and referees: if you are a job applicant we will contact your recruiter, current and former employers and/or referees, who may be based inside or outside the EU, to provide information about you and your application;
4.3.2 Service providers: we may collect personal information from our third party service providers, such as our email cloud service provider, email verification service provider, as well as financial crime compliance and KYC solutions provider, who are based inside the EU;
4.3.3 Website security: we will collect information from our website security service partners who are based inside the EU, about any misuse to the website, for instance, the introduction of viruses, Trojans, worms, logic bombs, website attacks or any other material or action that is malicious or harmful; and
4.3.4 Publicly available sources: we use publicly available sources such as Companies House, for instance to carry out identity and compliance checks.
4.4 We also receive information about you from third parties if you have indicated to such third party that you would like to hear from us.
5.1 The information we collect and process about you will include (depending on the circumstances):
(a) Identity: title, names, the company you work for, your title or position and your relationship to a person;
(b) Contact data: addresses, email addresses, and phone numbers;
(c) Identification and background information: information provided by you as part of our business acceptance processes, including your passport details or other personal identification documents;
(d) Information contained in correspondence: information contained in any correspondence between us. For example, if you contact us using a query button on our website or by email or telephone, we will keep a record of that correspondence;
(e) Information contained in survey, questionnaire and feedback forms: for example, if you complete a feedback form after attending one of our events, send us an email, or complete a survey or questionnaire online or participate in a survey sent in an email by us, we will keep a record of the information provided by you;
(f) Employment and background data: if you are submitting a job application, you may also provide additional information about your academic and work history, qualifications, skills, projects and research that you are involved in, references, proof of your entitlement to work in the UK, your national security number, your passport or other identity document details, and any other such similar information that you may provide to us;
(g) Website usage and other technical data: information about your interactions with the website and the device that you use to access our website, including information such as IP addresses, geographical location, your device information (such as your hardware model, mobile network information, unique device identifiers). This information may be collected by a third-party website analytics service provider on our behalf and/or may be collected using cookies or similar technologies. For more information on cookies please read paragraph 8 below; and
(h) Sensitive information: if you are submitting a job application, you may provide information about your race or ethnicity, religious beliefs, sexual orientation, health and whether or not you have any disability.
5.2 Sensitive information or ”special categories” of particularly sensitive personal information require higher levels of protection. We need to have further justification for collecting, storing and using this type of personal information. We process special categories of personal information where it is needed in the public interest for equal opportunities monitoring.
6.1 We will use your information for the purposes listed below either on the basis of:
6.1.1 your consent (where we request it);
6.1.2 where we need to comply with a legal or regulatory obligation; or
6.1.3 our legitimate interests.
6.2 We use your information for the following purposes:
6.2.2 To respond to enquiries: to respond to any enquires you make over the phone, by email, or via our website, in particular when you make inquiries about the provision of our legal services to you (on the basis of your consent, on the basis of our legitimate interest to respond to inquiries from prospective clients and to operate a lawful business, or otherwise to comply with our legal obligations);
6.2.3 To provide access to our website: to provide you with access to our website in a manner convenient and optimal and with personalised content relevant to you including sharing your information with our website hosts and developers (on the basis of our legitimate interest to ensure our website is presented in an effective and optimal manner);
6.2.5 User and customer support: to provide customer service and support in relation to your use of our website (on the basis of our contract with you or on the basis of our legitimate interests to provide you with customer service), and to deal with enquiries or complaints about the website (on the basis of our legitimate interest in providing the correct services to our website users and to comply with our legal obligations);
6.2.6 Recruitment: to process any job applications you submit to us, whether directly or via an agent or recruiter (on the basis of our legitimate interest to recruit new employees or contractors);
6.2.7 Marketing: to keep in contact with you about our news, events, new website features, and services that we believe may interest you, provided that we have the requisite permission to do so (either on the basis of your consent where we have requested it, or our legitimate interests to provide you with marketing communications where we may lawfully do so);
6.2.8 Analytics: to use data analytics to optimising the use of our website, to improve our website, products/services, marketing, customer relationships and experiences (on the basis of our legitimate interests in personalising, enhancing, modifying or otherwise improving the services and/or communications that we provide to you, developing our business, and informing our marketing strategy);
6.2.9 Fraud and unlawful activity detection: to protect, investigate, and deter against fraudulent, unauthorised, or illegal activity, including identity fraud (on the basis of our legitimate interests to detect and prevent fraud and to operate a safe and lawful business or where we have a legal obligation to do so); and
6.2.10 Compliance with policies, procedures and laws: to enable us to comply with our policies and procedures and enforce our legal rights, or to protect the rights, property or safety of our employees and share your information with our technical and legal advisors (on the basis of our legitimate interests to operate a safe and lawful business or where we have a legal obligation to do so).
6.3 Where we use your information for our legitimate interests, we make sure that we take into account any potential impact that such use may have on you. Our legitimate interests don’t automatically override yours and we won’t use your information if we believe your interests should override ours unless we have other grounds to do so (such as your consent or a legal obligation). If you have any concerns about our processing please refer to details of “Your rights to the information we hold about you” in paragraph 11 below.
7.1 In connection with the purposes and on the lawful grounds described above and in addition to the recipients of your information as described above, we will share your personal information when relevant with third parties such as:
7.1.1 Our service providers: Service providers we work with to deliver our business, who are acting as processors and provide us with:
(a) website development and hosting services based in the EU;
(b) IT, system administration and security services based in the EU;
(c) identity verification, fraud prevention and detection services based in the UK; and
(d) recruitment service providers based in the United Kingdom.
7.1.2 Regulators and governmental bodies: HM Revenue & Customs, regulators (including our regulator, the Solicitors Regulation Authority), governmental bodies and other authorities acting as processors or joint controllers based in the United Kingdom, who require reporting of processing activities in certain circumstances;
7.1.3 Marketing parties: any selected third party that you consent to our sharing your information with for marketing purposes;
7.1.4 Prospective buyers of our business: any prospective buyer of our business or assets, only in the event that we decide to sell our business or assets; and
7.1.5 Other third parties (including professional advisers): any other third parties (including legal or other advisors, regulatory authorities, courts, law enforcement agencies and government agencies) where necessary to enable us to enforce our legal rights, or to protect the rights, property, or safety of our employees, or where such disclosure may be permitted or required by law.
7.2 We require third parties to maintain appropriate security to protect your information from unauthorised access or processing.
8.2 If you do not wish for cookies to be installed on your device, you can change the settings on your browser or device to reject cookies. For more information about how to reject cookies using your internet browser settings please consult the “Help” section of your internet browser (or alternatively visit http://www.aboutcookies.org). Please note that, if you do set your Internet browser to reject cookies, you may not be able to access all of the functions of the website.
8.3 The names of the cookies used on our website and the purposes for which these cookies are used are set out below:
Cookie name: _ga
Purpose: Used to distinguish users
Duration: 2 years
Cookie name: _gid
Purpose: Used to distinguish users
Duration: 24 hours
9.1 We follow strict security procedures as to how your personal information is stored and used, and who sees it, to help stop any unauthorised person getting hold of it. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. Unfortunately, the transmission of information via the internet is inherently insecure and although we do our best to protect your personal data, we cannot absolutely guarantee its security.
9.2 We operate a policy of “privacy by design” by looking for opportunities to minimise the amount of personal information we hold about you. We use appropriate technological and operational security measures to protect your information against any unauthorised access or unlawful use, such as:
9.2.1 ensuring the physical security of our offices, or other sites;
9.2.2 ensuring the physical and digital security of our equipment and devices by using appropriate password protection and encryption; and
9.2.3 maintaining a data protection policy for, and delivering data protection training to, our employees.
9.3 We will retain your information for as long as is necessary to provide you with the services that you have requested from us or for as long as we reasonably require to retain the information for our lawful business purposes, such as for the purposes of exercising our legal rights, or where we are required by law to retain such information.
10.1 Our company is located in the UK.
10.2 We do not transfer your personal data outside the European Economic Area (EEA) unless you instruct us to transfer your personal data to third parties located outside the EEA; such transfer is necessary to provide the services you have requested from us; or it is otherwise required or permitted by law.
10.3 Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following transfer solutions is implemented:
10.3.1 Your personal data is transferred to a country that has been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries;
10.3.2 Your personal data is transferred to recipients on the basis of specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, European Commission: Model contracts for the transfer of personal data to third countries; and
10.3.3 Your personal data is transferred to recipients based in the US that are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US. For further details, see European Commission: EU-US Privacy Shield.
11.1 You have certain rights in respect of the information that we hold about you, including:
11.1.2 the right to ask us not to process your personal data for marketing purposes;
11.1.3 the right to request access to the information that we hold about you;
11.1.4 the right to request that we correct or rectify any information that we hold about you which is out of date or incorrect;
11.1.6 the right to object to our using your information on the basis of our legitimate interests (refer to paragraph 6 above to see when we are relying on our legitimate interests) (or those of a third party)) and there is something about your particular situation which makes you want to object to processing on this ground;
11.1.7 the right to receive a copy of any information we hold about you (or request that we transfer this to another service provider) in a structured, commonly-used, machine readable format, in certain circumstances;
11.1.8 in certain circumstances, the right to ask us to limit or cease processing or erase information we hold about you; and
11.1.9 the right to lodge a complaint about us to the UK Information Commissioner’s Office (https://ico.org.uk/) as well as a right to lodge a complaint with the relevant authority in your country of work or residence.
11.2 Please note that we may need to retain certain information for our own record-keeping and research purposes. We may also need to send you service-related communications relating to your website user account even when you have requested not to receive marketing communications.
11.3 How to exercise your rights
11.3.2 In addition, you may exercise your right to request access to the information that we hold about you by sending an email to email@example.com.
11.3.3 Please note that your objection to processing (or withdrawal of any previously given consent) could mean that we are unable to provide you with our legal services or otherwise perform the actions necessary to achieve the purposes set out above (see ‘How we use you information about you’). Please note that even after you have chosen to withdraw your consent we may be able to continue to process your personal information to the extent required or otherwise permitted by law, in particular in connection with exercising and defending our legal rights, or meeting our legal and regulatory obligations.
11.3.4 You may request us to cease sending you any marketing information at any time by notifying us in writing using the contact information set out in paragraph 2 above. Each marketing email sent to you will contain an easy, automated way for you to cease receiving marketing emails from us. If you wish to do this, simply follow the instructions at the end of any email.
11.3.5 If you have received unwanted, unsolicited emails sent via this system or purporting to be sent via this system, please forward a copy of that email with your comments to firstname.lastname@example.org for review.
11.4 What we need from you to process your requests
11.4.1 We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
11.4.2 Please note: before 25 May 2018, we are entitled by law to charge a fee of £10 to meet our costs in providing you with details of the information we hold about you. From 25 May 2018, you will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances. We will try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.