Privacy Policy

Introduction

1) This Privacy Policy explains how Charles Lyndon (“we”, “us”, “our”) collects, uses, discloses and protects personal data when you (a) visit our website, (b) engage our legal services, or (c) otherwise interact with us, including via a third party. It also sets out your rights under data protection law and how we protect those rights.

2) We are a law firm registered and practising in England & Wales, regulated by the Solicitors Regulation Authority (SRA) under number 622797. We are also registered with the UK Information Commissioner’s Office under Registration Number: ZA169163.

3) We are the data controller for the purposes of the UK GDPR and the Data Protection Act 2018 (together, “data protection legislation”). If you have any questions about this Privacy Policy or any requests about your data, please contact us at: info@charleslyndon.com or by telephone on 0207 058 0050.

The Personal Data We Collect

4) We may collect personal data in various contexts.

a. Website use and automated data, including but not limited to:

  • IP address, device identifiers, browser and technical data; and
  • Cookies analytics data (please refer to our Cookies Policy).

b. Client, prospective client or contact details, including but not limited to:

  • Name, contact details (email, telephone number, residential address); and
  • Identity verification information (e.g. photocopies of passports, proof of address).

c. Case and legal matter information, including but not limited to:

  • Financial information (e.g., credit data, bank account details, payment card details);
  • Health information relevant to legal advice (e.g. a respiratory condition affected by your housing conditions);
  • Criminal offence data (e.g., information relating to criminal allegations or convictions that we may become aware of when acting on a matter, including where reporting obligations apply); and
  • Other special category data that you provide to us, such as race, ethnicity, gender and sexual orientation.

d. Information we receive from third parties, including (where relevant) defendants or other parties to a dispute, courts or tribunals, counsel and experts, insurers, claims administrators, introducers/referrers, agents, public registers and screening providers (including for anti-money laundering, sanctions or fraud checks).

e. Where we need personal data to comply with legal obligations or to provide services to you, and you do not provide that personal data when requested, we may be unable to act for you or to continue to provide those services.

Lawful Basis for Processing Personal Data

5) Under the UK GDPR, all personal data processing must be based on a lawful basis under art. 6. The available bases include:

a. Contract – where processing is necessary to perform a contract with you;
b. Legal obligation – to comply with statutory duties, such as anti-money laundering checks or SRA regulatory requirements;
c. Legitimate interests – where our interests (or those of our clients) are balanced against your rights and freedoms; and
d. Consent – where you have explicitly agreed to specific uses of your information. For example: where you opt in to receive marketing communications or newsletters via email, or when you agree to participate in a survey.

6) In the context of providing legal services, we do not usually rely on consent as the primary lawful basis for processing client matter data; rather, we rely primarily on contract, legal obligation, and legitimate interests as the lawful bases for processing your data under art. 6. In instances where we do rely on consent (for example, mailing lists and certain marketing communications), you may withdraw consent at any time.

Special Category Data

7) Some information we handle, such as health, ethnic origin, or sensitive case details, is special category data under art. 9 and is given extra protection. Special category data cannot be processed unless:
a. A lawful basis under art. 6 applies; and
b. A specific condition under art. 9 is also met.

8) We may process special category data where necessary:
a. To provide legal advice and representation (art. 9(2)(f));
b. To comply with legal and regulatory obligations; and
c. Where you give explicit consent to do so.

9) Where we process special category data, we ensure additional safeguards are in place and document our justifications.

Purposes for which we will use your personal data

10) We have set out below, in a table format, a description of the most common ways that we plan to use your personal data, and which of the lawful bases we rely on to do so. We have also identified what our legitimate interests are, where appropriate.

Purpose/Use

Type of data

Lawful basis

To check whether we can act for you as a new or existing client or across from you as a counter party or other third party on a matter involving a new or existing client, and carry out all of our regulatory compliance requirements, including conflicts of interest, anti-money laundering, anti-terrorism, sanctions, fraud and background screening.

Identity;

Contact;

Financial;

Professional;

Transaction; and

Claim.

Performance of a contract with you;

Necessary to comply with a legal or regulatory obligation;

Public interest; and

Necessary for our legitimate interests (to detect and prevent the commission of fraud, money laundering and terrorism offences).

To deliver our services to you including engaging service providers, managing payments, fees and charges and collecting and recovering money owed to us.

Identity;

Contact;

Financial;

Transaction;

Marketing and Communications; and

Claim.

Performance of a contract with you; and

Necessary for our legitimate interests (to recover debts due to us).

To manage our relationship with you which will include notifying you about changes to our terms or privacy policy.

Identity;

Contact;

Marketing and Communications; and

Claim.

Performance of a contract with you;

Necessary to comply with a legal obligation; and

Necessary for our legitimate interests (to keep our records updated and to assess how customers and clients use our products and services).

To enable you to complete a survey.

Identity;

Contact;

Usage;

Marketing and Communications; and

Claim.

Performance of a contract with you; and

Necessary for our legitimate interests (to assess how customers and clients use our products and services).

To administer and protect our business and our website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data).

Identity;

Contact; and

Technical.

Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise); and

Necessary to comply with a legal obligation.

To deliver relevant website content to you and measure or understand the effectiveness of the marketing we provide to you.

Identity;

Contact;

Usage;

Marketing and Communications; and

Technical.

Necessary for our legitimate interests (to assess how customers use our products and services, to develop them).

To use data analytics to improve our website, products and services, marketing, customer relationships and experiences.

Technical; and

Usage.

Necessary for our legitimate interests (to define types of clients and customers for our products and services, and to keep our website updated).

To make suggestions and recommendations to you about services that may be of interest to you.

Identity;

Contact;

Technical;

Usage; and

Marketing and Communications.

Necessary for our legitimate interests (to develop our products and services).

Criminal Offence Data

11) Data about criminal offences and allegations are covered by separate rules (art. 10) and processed lawfully only when authorised by law and necessary for legal representation and compliance. We process such data in the context of legal matters where necessary under UK law.

Recipients and Data Sharing

12) We may share personal data with:
a. Courts, tribunals, government bodies and law enforcement, where required by law or where necessary for the establishment, exercise or defence of legal claims;
b. Professional advisors, experts and third-party service providers acting on our behalf (subject to confidentiality obligations);
c. Processors supporting our IT systems, analytics or marketing functions;
d. Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy.

13) We disclose your personal data only where there is a lawful basis under UK GDPR and appropriate safeguards are in place. We require all third parties, including for example cloud services providers, to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Recipients and Data Sharing: Artificial Intelligence

14) We may use enterprise-grade artificial intelligence and large language model tools as part of our internal business operations, including for document review, drafting assistance, summarisation and administrative support.

15) Where such tools are used, they are accessed through secure business accounts that provide enhanced data protection safeguards, and data inputted into these tools will not be used for model training.

Retention of Personal Data

16) We retain personal data only as long as necessary and proportionate to:

  • Fulfil the purposes for which it was collected, outlined above;
  • Meet regulatory, legal or contractual requirements; and
  • Establish, exercise or defend legal claims.

17) We will ordinarily retain your data for the duration of our instructions or engagement. Otherwise, we will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you. Once the retention period has expired, we will securely delete or anonymise your personal data unless continued retention is required by law.

18) To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. We periodically review our retention practices to ensure ongoing compliance with the UK GDPR.

Data Security

19) We implement appropriate technical, organisational, and administrative measures to safeguard personal data against unauthorised access, loss, destruction, or alteration. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a need to know this information. They will only process your personal data on our instructions, and they will be subject to a duty of confidentiality. We also maintain procedures to respond promptly to any suspected personal data breaches in accordance with our legal obligations under the UK GDPR.

International Transfers

20) If personal data is transferred outside the UK, we use appropriate safeguards such as UK Adequacy Decisions or the UK Addendum to the EU Standard Contractual Clauses (or the UK International Data Transfer Agreement) to ensure your data is protected in compliance with the UK GDPR.

Your Rights

21) Under the UK GDPR, you have rights including:

  • The right to access your personal data, known as a “data subject access request” (this right may be qualified, for example, where disclosure would adversely affect the rights and freedoms of others under art. 15(4)):
  • The right to correction of inaccurate data:
  • The right to erasure (where lawful), subject to art. 17(3);
  • The right to restrict processing, in accordance with art. 18;
  • The right to object to certain processing, in accordance with art. 21(1);
  • The right to object, at any time, to the processing of your personal data for direct marketing purposes;
  • The right to data portability, entitling you to receive your personal data in a structured, commonly used and machine‑readable format and to transmit that data to another controller where technically feasible, in line with art. 20; and
  • The right to withdraw consent (where consent is the lawful basis).

22) Some rights may be limited in the context of legal professional privilege or where retention is required by law.

23) Commonly exercised rights are the entitlement to ask for a copy of the personal data we have on record about you, the entitlement to correct or complete data that may be inaccurate or outdated, and the entitlement to request that we delete personal data where there is no good reason for continued processing. There are instances, however, where we may be obligated to refuse an erasure request.

24) You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time. If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for us to undertake the work that you have instructed us to undertake.

Data Deletion Requests

25) We assess data deletion requests on a case-by-case basis. Your right to request deletion of personal data we hold as a data controller under art. 17 is limited by the exceptions listed in art. 17(3).

26) We will respond to a request without undue delay and in any event within one month in accordance with art. 12(3) (this period may be extended by two months in certain cases as permitted by the UK GDPR).

27) You will not usually have to pay a fee to access your personal data (or to exercise any of the other rights). That being said, we may refuse to act on, or charge a reasonable fee for, requests that are manifestly unfounded or excessive, in line with art. 12(5).

28) Processing of personal data may remain necessary if the following conditions apply:
(a) for exercising the right of freedom of expression and information;
(b) for compliance with a legal obligation which requires processing [under domestic law] or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(c) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);
(d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
(e) for the establishment, exercise or defence of legal claims.

29) A common, but not the only, exception applicable to law firms such as Charles Lyndon is (b) ‘for compliance with a legal obligation’. Charles Lyndon’s Engagement Letter therefore notes that we retain files for a period of seven years after the conclusion of a matter after which time the files will usually be destroyed. By signing our engagement letter, you consent to this policy, which is intended to ensure that documents are retained for the duration of relevant statutory limitation periods and to protect the legal rights of both you and the firm.

30) Each request will be assessed on its individual facts to determine whether any part of the data can be erased, restricted or anonymised, even where full erasure is not appropriate. We will ensure, for example, that you are not included in future mailing lists.

Complaints

31) You have the right to lodge a complaint at any time with the Information Commissioner’s Office (“ICO”), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, welcome the opportunity to address any concerns you may have before you contact the ICO, and request that you contact us in the first instance.

Third-party links

32) This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

Changes to this Policy

33) We may update this policy from time to time to reflect changes in the law, technology, or our processing practices. The “Last updated” date will be amended accordingly.

Contact Information

34) For privacy queries, requests or to exercise your rights, please contact us at info@charleslyndon.com or by telephone on 0207 058 0050.

We’re here to provide the legal assistance you need when you need it most.

Contact Us

Have a Question?

If you have any questions about a specific case we are working on, would like to discuss us representing you or want to know more about who we are and what we do, then speak to our team. We will get back to you as soon as possible.

Contact Us