Privacy Notice – Endeavour Law
This privacy notice should be given to all clients. It could be attached to your terms of business and/or on your website (signposted in your client care letter).
Endeavour Law is committed to protecting and respecting your privacy.
This notice sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand how we will treat it, protect it and to understand more about your rights. By providing your personal information to us you are agreeing to us using your information as described in this policy.
|We or Us:||Endeavour Law, 21 Old Filed Road, Pencoed, Bridgend, CF35 5LJ.|
|Personal data:||Any data or information, in electronic or organised hard copy, that identifies you personally or which relates to you when you are identifiable.|
|Special categories of personal data:||Sensitive information relating to you, namely: health records; information regarding your sex life, sexual orientation, political opinions, religious or philosophical beliefs, racial or ethnic origin, trade union membership; and genetic and biometric data|
Personal data we process
- Your name and contact details
- ID and other information we require to conduct due diligence on you
- Personal and financial information relating to your legal matter
- Special categories of personal data, where relevant to your legal matter
Our lawful basis for processing your personal data and special categories of personal data (sensitive information)
You have instructed us to give you legal advice and/or representation. The solicitor-client relationship is a contractual one, and it is a requirement that you agree to our terms of business. To perform this contract, it is unavoidable that this requires us to collect, process and store personal information about you.
We have legal and regulatory duties to process certain personal data, including ID and other information we require to conduct due diligence on you.
The information requested when you instruct us is required in order to identify you and perform our service for you. If you do not provide the requested information we will not be able to provide our service to you.
We have a legitimate interest in contacting you to market our services to you.
For special categories of personal data, we are permitted to process your data (e.g. health records) for the purposes of giving legal advice.
In summary, we do not anticipate requiring your explicit consent to process your personal data. If that changes we will let you know.
How will we use your personal data
We use information you provide to us in the following ways:
- to identify you and provide you with the legal services you have requested;
- to provide you with information you have requested about services we offer;
- to carry out our obligations arising from any contracts entered into between you and us and to provide you with the information and services that you request from us;
- to notify you about changes to our service;
- to deal with your feedback, query or complaint;
- we also use your information to administer, support, improve and develop our business generally and to enforce our legal rights.
Where we get your personal data from
- You or your representatives
- Public records
- Other parties you instruct us to contact (e.g. doctors, employers, estate agents, accountants, banks, surveyors, medical professionals, courts, regulatory bodies and other advisors and specialists related to your matter)
- Our clients and matter contacts may also provide us information about you if you are involved in a transaction or dispute with one of our clients or have a connection with them such as being a tenant or employee of a client.
Your data rights
You have the right, free of charge, to:
- Access your personal data (known as a subject access request)
- Have mistakes rectified
- Have your personal data erased by us or restrict the way we process your personal data (subject to certain conditions)
- ‘Port’ your personal data to another provider
- Object to us using your personal data for direct marketing – simply
- Not be subject to ‘automated processing’ (often referred to as ‘profiling’).
You simply need to contact us to exercise any of your rights. In the case of marketing, there is always an ‘unsubscribe’ button in our marketing emails [insert methods for unsubscribing from other marketing methods e.g. SMS].
For more information on your legal rights see the Information Commissioner’s website (www.ico.org.uk).
Retention of personal data
We are required by our insurers and regulators to keep your file and personal data for minimum periods. We are not however permitted to keep your personal data indefinitely or for longer than is necessary.
Our retention policy is that the minimum period we will keep files and other personal data relating to a legal matter is [six] years. We may keep your file for significantly longer than that if it is necessary and in our legitimate interests to do so (for example files relating to wills, property or children, or where you request this).
We operate a rolling annual programme of file destruction. All our files and other documents containing personal data are destroyed securely.
Sharing your personal data
We may need to share your personal data with other professionals who we instruct on your behalf (e.g. barristers and doctors), third parties who are vital to a transaction (e.g. mortgage provider, the courts), providers of services that are necessary to progress a legal matter (e.g. to perform our client due diligence checks on you), and people who you ask us to share your personal data with (such as estate agents, family members or other representatives).
We may also need to share your personal data with our regulators, insurers, and law enforcement agencies.
We use external auditors to review our files for training, compliance and quality.
Where we share your personal data with third parties, we will ensure that they have appropriate data protection arrangements in place.
Where we hold your personal data
Your data will be stored at our offices and on our IT equipment, or where your information is shared with a third party, at their premises or on their IT equipment.
We archive our old files to a secure facility prior to destruction. Details are available on request.
Transferring your personal data outside of the EEA
Since we do not have offices outside England & Wales, we have no reason to transfer your personal data outside the European Economic Area unless you or a third party with whom we must share your personal data are based outside the EEA.
Where we use third party IT services (e.g. ‘cloud’ based software) we shall ensure that their data centres are either within the EEA or that there are lawful safeguards in place to protect your personal data to the same standard as if it were held within the EEA.
Data Protection Officer
We do not have a Data Protection Officer (DPO) but have appointed a Data Protection Manager to implement our data protection policies and procedures. Our Data Protection Manager’s details are:
Robert Smith, 21 Old Field Road, Pencoed, Bridgend, CF35 5LJ. Email: firstname.lastname@example.org, Telephone number: 01656 673 448
For the purpose of Data Protection legislation, the data controller is Endeavour Law
Complaints and questions
If you have a complaint or question about our use of your personal data, please contact in the first instance our Privacy Manager.
You may also make complaints direct to the Information Commissioner’s Office (web: www.ico.org.uk/concerns tel: 0303 123 1113).