1. Who we are
Weston Legal Ltd (‘the Firm’, ‘we’, ‘us,’ ‘our’) is a limited liability company which provides legal services and is based in the UK.
Our registered office, where you can contact us is: Charles House, 4th floor, 108-110 Finchley Road, London NW3 5JJ or on data@westonlegal.ltd
We are bound by the Data Protection Act 2018 and the UK GDPR. We are registered at the Information Commissioner’s Office under registration number: ZB685256. Information is available at the Information Commissioner’s Office (ICO) here: https://ico.org.uk/
2. About this privacy notice
We value and respect your privacy. We take all reasonable steps to comply with our legal duties and ethical responsibilities to manage, protect and account for your personal information, and to inform and deliver upon your data protection rights.
This notice explains our routine activities where your personal information may be collected and used, why and for how long. Other infrequent activities may occur; when they do we aim to provide you with bespoke information that should be read in conjunction with this notice.
This notice complies with the transparency requirements of the UK legislation referenced above. Provisions within this notice do not grant additional rights when you are a citizen of an overseas territory not covered by these regulations.
3. Collection and use of your personal information
3.1 Types of personal information we may collect
During our routine operations we may collect and use different types of personal information. That is, anything that identifies you or relates to you, directly or indirectly, on its own or when combined with other available information. We define personal information within the categories below.
| Identity | Includes: first name, family name, last name, username or similar identifier, marital status, title, date of birth, gender, career. |
|---|---|
| Contact | Includes: home and email addresses and telephone numbers, billing address, delivery address. |
| Financial | Includes: salary, spending habits, claims and payments, credit history, scoring and rating, billing, bank account and payment card details. |
| Special category | Includes: details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your physical or mental health, medical history, genetic and biometric data. |
| Criminal convictions and offences | Includes: allegations, prosecutions and convictions of criminal nature. |
| Marketing and communications | Includes: your preferences in receiving marketing from us and your communication preferences. |
| Profile data | Includes: your username and password, purchases or orders made by you, your interests, preferences, feedback, and survey responses. |
| Transaction logs | Includes: details about payments to and from you and other details of products and services from us. |
| Usage | Includes: details relating to the use of our website, products, and services. |
| Technical | Includes: system usage logs, internet protocol (IP) address, CCTV, networks accessed, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website. |
3.2 When and how we collect and use your information
As a firm offering legal services, most of the personal information we collect, and use is required to fulfil legal or contractual obligations that arise during the delivery of a client matter and/or when we are instructed to provide a legal service.
Your personal information may be collected, exchanged and used with/by a client, from you, other third parties, or from publicly available sources.
We take care to only collect and use information required to fulfil our lawful purpose and retain for a proportionate period.
3.3 How long we may keep your information
Our retention policies reflect our statutory obligations and specific business requirements. The retention period will vary according to the category and nature of the information, and why we have it.
We have statutory obligations to retain some documents in their original format; for everything else, we routinely scan and destroy.
Please contact data@westonlegal.ltd for further details about retention schedules relating to your information.
3.4 Our most common activities involving the use of your personal information
See below for the most common activities involving the use of your personal information.
i. You are a client or in the process of instructing us
| Onboarding checks |
|
|---|---|
| Delivering your service |
|
| Administration of our relationship |
|
| Industry updates |
|
| Statutory obligations - other |
|
| Our business operations |
|
| Transparency | When we process your information we will be transparent with you, unless we have legal or professional obligation not to. |
| Retention | Generally, most of the information generated during the provision of our legal services is retained for a minimum of 6 years from the matter closure date. This is the primary limitation period under the Limitation Act 1980. However, depending on the nature of the information and the engaged services, some information may be subject to significantly different retention requirements. |
ii. Your information was provided during a matter, and you are not a client
We are not regulated by the Solicitors Regulation Authority but the solicitors who work for us are and regulations mandate them to maintain confidentiality of client affairs, unless permitted by law or the client consents.
This means, when we process your information to deliver a client service, we may do this without your knowledge or consent. Confidentiality rules may also exempt us from fulfilling some data protection rights requests, such as your right of access.
Activities that may take place involving your personal information:
| Delivering client services |
|
|---|---|
| Administrating client relationships |
|
| Statutory obligations |
|
| Our business operations |
|
iii. Communicating with us
| Phone |
|
|---|---|
| Microsoft email |
|
| Microsoft Teams |
|
| Post |
|
| Social media |
|
| Other tools or platforms |
|
| Other uses |
|
iv. Visiting an office
| Managing your visit |
|
|---|---|
| Guest wifi |
|
| Capture and use of CCTV |
|
v. You subscribe to receive marketing materials
| Your subscription | When you agree to receive promotional materials by subscribing via our website or sign up for an event. Subscription information is stored within our secure marketing database. We may use software to review and categorise your preferences and identify relevant materials to provide. |
|---|---|
| Your interactions | We may use our approved third-party tools to deliver materials to you. We use analytic tools to monitor delivery success, we use this information to improve email services. |
| Consent | Where you have not contacted us or engaged with our emails, we may contact you periodically to confirm your continued consent. |
| Suppression list | When you unsubscribe or ‘opt out’ we may add your name to our suppression list to ensure that you do not receive future materials. |
| Maintenance | Our trusted third parties may access our database to provide us with technical support during routine or operational performance and maintenance. You can change your preferences or unsubscribe ‘Opt-out’ at any time by following the embedded links within the footers of our direct marketing emails, or you can let us know by email to data@westonlegal.ltd. |
| Collection | From the subscriber. You can change your preferences or unsubscribe ‘Opt-out’ at any time by following the embedded links within the footers of our direct marketing emails, or you can let us know by email to data@westonlegal.ltd. |
| Categories | Identity, contact, preferences, and usage. You can change your preferences or unsubscribe ‘Opt-out’ at any time by following the embedded links within the footers of our direct marketing emails, or you can let us know by email to data@westonlegal.ltd. |
vi. You submit an information request or make a complaint
| Your contacts | A member of the team will review and triage your complaint or request made via data@westonlegal.ltd. |
|---|---|
| Identity | We may use your personal information to take reasonable measures to verify your identity and confirm your authority to make the complaint, enquiry, or request. |
| Investigations | We review information you provide and other relevant personal information that we hold, we may share this with relevant personnel, to the extent required to investigate and manage the query. |
| Third party sharing | We may share your personal information with relevant third-parties or agencies such as the regulator, clients, solicitors, or insurers). |
| Mitigations | We may make changes or update your information and implement appropriate actions to achieve the required outcome. |
| Collection | Direct, Indirect, Technical. |
| Categories | Identity, contact, technical and any information relevant to your contact. |
vii. You work with us or have made an application
| Applications | When applying for a position through any method, you will receive a notice and be provided with a link to this privacy notice. |
|---|---|
| Our systems | We will communicate with you by phone, Teams, Zoom and/or email. Information is collected usually by email which is used to store, send, and receive email communications with you and associated parties involved in the recruitment process, securely store your application, test results scores, online interview or video presentation. |
| Third parties | We may use contracted services of third-party providers to deliver elements of the recruitment process or conduct assessments on our behalf. When we do, we will inform you in advance and provide you with links to their privacy notice. Unless otherwise stated, relevant information obtained and processed will be shared with us to manage your application. |
| Unsuccessful applicants | We are required to retain information of unsuccessful applicants for a period six months. However, with your consent we may add your details to our ‘Talent pool’ and your information may be retained for this purpose for up to two years. |
| Pre-employment checks | Information of successful applicants is further processed and may be shared with relevant parties to obtain references, manage health questionnaires, conduct conflict of interest, PEP’s, DBS, and other background checks. |
| Equality and diversity | When you update voluntary sections of the application forms, such as equality, diversity and equal opportunities information, your responses are used and shared solely for the purposes and monitoring of equal opportunities statistics. These are not accessible to the hiring manager or recruitment panel. |
| Collection | From the candidate, recruitment panel and contracted third parties. |
| Categories | Identity, career, criminal, contact, preferences, technical, usage. Plus, any personal the information you provide. |
| Successful applicants | Our employee privacy notice is available for those who work with us. Available upon request to our compliance manager at data@westonlegal.ltd. |
viii. Our other business operations
| Host information | Deliver our IT services, apply security and monitoring practices, improvements and testing, maintenance. |
|---|---|
| System security | Your information may be processed when we apply security measures. We use physical, electronic, and administrative safeguards designed to protect your personal data from loss, misuse, and unauthorised access, use, alteration, or disclosure. We store all personal data you provide to us behind firewalls on servers employing security protections. We continually review and improve our technical systems and tools to maintain resilience, security, and adaptability of our IT Infrastructure. |
| Physical security | Your information may be processed when we apply physical security measures. We apply high standards of on-site physical security and have technical and organisational measures to protect our working space and physical information and data assets. |
| Risk assessments | Your information may be processed when we carry out risk assessments and reviews. Activities that require the use of personal information undergo risk assessments to ensure they are lawful and comply with our data protection polices; these are regularly reviewed to ensure ongoing suitability. |
| Our people | Our people may process, access and review your information for duties consistent with their position and responsibilities, such as delivering a client service and performance management. Bespoke training is a mandatory requirement for all of those who have access to personal information. We restrict access to personnel and service providers who have a legitimate ‘need to know’. There are contractual obligations of confidentiality and data protection. |
| Our third parties | When we use third parties to perform activities for us, we complete due diligence checks to ensure information remains secure, confidential, and used for the contracted purposes. |
| Automated decision making | We do not make use of automated decision-making tools that fall into a category requiring your notification. If our position changes, we will update this notice and inform you directly where required. |
| Management Information | Your information may be processed when we produce management information such as budgets, client satisfaction, performance reviews or resource management. |
| Sale or transfer of business assets | We may disclose your personal information to a prospective seller or buyer or successor in the event that we sell or buy any part of our business group, entity or assets or seek to acquire new businesses, merger, divestiture, restructuring, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, where one of the transferred assets is the personal data we hold. |
| Other obligations | Other relevant obligations to which we are legally bound such as to comply with court order, legal or regulated request. |
| Our legal rights | Your information may be lawfully processed when our obligations or legal rights outweigh your right to privacy. We take reasonable measures that protect and enforce our legal rights against breach of contract or agreement, detection or prevention of fraud or crime, and to protect people, property, or assets. |
| Non-personal information | We may process and share other, non-personal information without restriction of this notice. However, we will consider our other regulatory or contractual obligations prior to use. |
4. Data Protection and your rights
4.1 Your rights
The UK General Data Protection Regulation (known as the UK GDPR) and the UK Data Protection Act 2018 provide individuals within the UK and EEA with specific data protection rights, explained by the UK regulator here: https://ico.org.uk/for-the-public/
In more detail, your rights are:
These rights are not absolute and the ability to enforce your rights is dependent on the nature of the information and why we have it.
There are exemptions within data protection regulations and other legislation or Acts, to which we are bound. These may override your rights. You can find those exemptions here: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/exemptions/a-guide-to-the-data-protection-exemptions/
These rights may vary for those outside of the UK and EEA; please contact us for more information.
4.2 Making a request
There are no restrictions for who you can ask or how you make your request. However, we encourage you to contact data@westonlegal.ltd.
You may find the ICO guidance helpful: Getting copies of your information (SAR), here: https://ico.org.uk/for-the-public/getting-copies-of-your-information-subject-access-request/
When we receive your request, we will let you know we have received it and inform you if we need any additional information from you such as to verify your identity.
We usually provide an outcome within one month, however if we need any extra time we will let you know and provide you with an explanation.
4.3 Data protection complaints procedure
You have a statutory right to make a complaint to us if you believe that, in connection with your personal data, we have breached applicable data protection law.
How to make a complaint
You can raise a data protection complaint with us at any time and in any format, including by email, post, telephone, or as part of an ongoing interaction with us. You do not need to use legal terminology or refer to specific legislation.
We encourage you to contact us using the following details:
Data Protection Complaints
Weston Legal Ltd
Email: data@westonlegal.ltd
Address: Charles House, 4th Floor, 108-110 Finchley Road, London NW3 5JJ
What happens next
When we receive a data protection complaint:
- • we will acknowledge receipt within 30 days of receiving it;
- • we will take appropriate steps to investigate the complaint without undue delay, which may include reviewing relevant records, making internal enquiries, and seeking further information from you where necessary; and
- • we will inform you of the outcome of your complaint as soon as reasonably possible.
During our investigation, we may keep you informed of progress where appropriate. If we require additional information to progress the complaint, we will let you know.
Complaints may be handled by our compliance function or other appropriate senior personnel, depending on their nature.
4.4 Raise a concern to us
If you have a concern or complaint about how we process your personal information, please refer to Section 4.3 (Data protection complaints procedure) above, which explains how to raise a data protection complaint and how we will handle it.
4.5 Contact our compliance officer
Please contact our compliance officer here:
Data Compliance Officer
Weston Legal Ltd
Charles House
4th Floor
108-110 Finchley Road
London NW3 5JJ
For general enquiries, please allow up to seven working days for a response from receipt.
4.6 Raise a concern to the regulator
Data protection law requires that you raise data protection complaints with us first, so that we have the opportunity to investigate and resolve them. If you remain dissatisfied after receiving our final response, you may escalate your complaint to the Information Commissioner’s Office (ICO), the UK data protection regulator.
ICO contact details are available at https://ico.org.uk/make-a-complaint/data-protection-complaints/personal-information-complaint/
The ICO will normally expect evidence that you have raised your complaint with us before they consider the matter.
5. Changes to Our Privacy Notice
5.1 Content Change
Changes to this notice may occur periodically, either during our annual review or following interim changes to legislation or the way we work.
We will update section ‘Privacy notice history’ with details of amendments and version history.
Where there are significant changes that materially alter how we use or treat your personal data we will make best endeavours to notify you directly.
5.2 Privacy notice history
Date: 16/11/2023: Version: 1 issued.
Date: 10/12/2024: Version 2 issued (reg number added).
Data: 01/05/2026: Version 3 (contact details and URLs updated and complaints procedures updated)