Client Privacy Policy
Chandler Harris LLP
Introduction
Welcome to the Chandler Harris LLP Client Privacy Notice.
Chandler Harris LLP respects your privacy and is committed to protecting your personal data.
This Privacy Notice will give you information about the way, in which we look after your personal data when you enter into a contract with us for the provision of legal services and/or visit our website (regardless of the place, from which you visit it).
It will also tell you about your privacy rights and the way, in which the law protects you.
You can download a PDF version of this Privacy Notice (if you are viewing it on our website).
Please also use the Glossaries, contained in paragraphs 2.2 and 20 below, to help you to understand the meanings of some of the terms, used in this Privacy Notice.
-
IMPORTANT INFORMATION AND WHO WE ARE
-
PURPOSE OF THIS PRIVACY NOTICE
-
This Privacy Notice aims to give you information about the ways, in which Chandler Harris LLP collects and processes your personal data through our interactions with you, including:
- your use of our website; and
- any data, which you may provide when you contact us through our website.
-
It is important that you read this Privacy Notice (together with any other privacy notice or fair processing notice, which we may provide on specific occasions when we are collecting or processing personal data about you) so that you are fully aware of:
- the reasons why we use your personal data; and
- the ways, in which we use them.
-
This Privacy Notice:
- supplements any such other notices; and
- is not intended to override them.
-
This Privacy Notice aims to give you information about the ways, in which Chandler Harris LLP collects and processes your personal data through our interactions with you, including:
-
CONTROLLER
-
Chandler Harris LLP (also known as Chandler Harris, we, us or our in this Privacy Notice) is:
- the controller of; and
- responsible for;
- We have appointed a Data Protection Manager (DPM), who is responsible for overseeing questions in relation to this Privacy Notice.
- If you have any questions about this Privacy Notice (including any requests to exercise your legal rights), please contact the DPM, using the details, set out in paragraph 1.3 below.
-
Chandler Harris LLP (also known as Chandler Harris, we, us or our in this Privacy Notice) is:
-
CONTACT DETAILS
-
Our relevant contact details are as follows:-
- Full name of legal entity:
- Chandler Harris LLP
- Name or title of DPM:
- David Martin Harris
- E-mail address:
- david.harris@chandlerharris.com
- Postal address:
- 25 Byrom Street, Manchester M3 4PF, England
- Telephone number:
- (0044) (0)161 834 2200
- You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), which is the UK supervisory authority for data protection issues (www.ico.org.uk).
- However, we would appreciate the chance to deal with your concerns before you approach the ICO, so we would be very grateful if you could contact the DPM in the first instance.
-
Our relevant contact details are as follows:-
-
CHANGES TO THIS PRIVACY NOTICE AND YOUR DUTY TO INFORM US OF CHANGES
- This version of this Privacy Notice was last updated on 17 May 2018.
- Any historic versions of this Privacy Notice can be obtained by contacting us.
- It is important that the personal data, which we hold about you, be accurate and current.
- Therefore, please keep us informed if your personal data change during your relationship with us.
-
THIRD-PARTY LINKS
-
Our website may include links to:
- third-party websites;
- plug-ins; and
- applications.
-
Either:
- clicking on those links; or
- enabling those connections;
-
Please be aware that we:
- do not control those third-party websites; and
- are not responsible for their privacy statements.
- When you leave our website, we encourage you to read the privacy notice of every other website, which you visit.
-
Our website may include links to:
-
PURPOSE OF THIS PRIVACY NOTICE
-
THE DATA, WHICH WE COLLECT ABOUT YOU
-
PERSONAL DATA
The term personal data (otherwise known as personal information):
- means any information about an individual, from which that person can be identified; but
- does not include data, from which the identity has been removed (i.e. anonymous data).
-
GLOSSARY
We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:-
- Identity Data include first name, maiden name, last name, username or similar identifier, marital status, title, date of birth, gender, driving licence number and passport number.
- Contact Data include residential address, business address, billing address, e-mail address and telephone numbers.
- Financial Data include bank account and payment card details.
- Transaction Data include details about payments to and from you, together with other details of services (and any products), which we have supplied to you.
- Technical Data include internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices, which you use to access our website.
- Usage Data include information about the ways, in which you use our website and services.
- Marketing and Communications Data include your preferences in receiving marketing from us, together with your communication preferences.
-
AGGREGATED DATA
- We may collect, use and share Aggregated Data, such as statistical or demographic data, for any purpose.
-
Aggregated Data:
- may be derived from your personal data; but
- are not considered to be personal data in law, as such data do not directly or indirectly reveal your identity.
- For example, we may aggregate your Transaction Data for the purpose of making a proposal for professional indemnity insurance.
- However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data, which will be used in accordance with this Privacy Notice.
-
SPECIAL CATEGORY DATA
- Where necessary for the performance of the legal services, which you have requested, we may collect Special Category Data about you.
-
These may include:
-
details about your:
- race or ethnicity;
- religious or philosophical beliefs;
- sex life;
- sexual orientation;
- political opinions; &
- trade union membership;
-
information about your:
- health;
- biogenetic and
- biometric data.
- biometric data.
-
details about your:
-
We may also collect information about:
- criminal convictions;
- offences and alleged offences; and
- court proceedings, orders or judgments.
-
PERSONAL DATA
The term personal data (otherwise known as personal information):
-
IF YOU FAIL TO PROVIDE PERSONAL DATA
-
Where:
-
we need to collect personal data:
- by law; or
- under the terms of a contract, which we have with you; and
- you fail to provide those data when requested;
-
we need to collect personal data:
-
In this case:
- we may have to suspend or withdraw from performance of legal services for you; but
- we will notify you at the time before doing so.
-
Where:
-
HOW ARE YOUR PERSONAL DATA COLLECTED?
We use different methods to collect data from and about you, including the following:-
-
DIRECT INTERACTIONS
-
You may give us your Identity Data, Contact Data and Financial Data and any Special Category Data:
- in person; or
- by filling in forms; or
-
by corresponding with us:
- by post, telephone or e-mail; or
- otherwise.
-
Such data include personal data, which you provide when you:
- contact us with a request for performance of legal services;
- create an account on our website; or
- subscribe to a service or publication.
-
You may give us your Identity Data, Contact Data and Financial Data and any Special Category Data:
-
AUTOMATED TECHNOLOGIES OR INTERACTIONS
-
As you interact with our website, we may automatically collect Technical Data about your:
- equipment;
- browsing actions; and
- patterns.
-
We collect those personal data by using:
- cookies (for example, Google Analytics);
- server logs; and
- other similar technologies.
-
As you interact with our website, we may automatically collect Technical Data about your:
-
THIRD PARTIES OR PUBLICLY AVAILABLE SOURCES
We may receive personal data about you from various third parties and public sources, as set out below:-
- Technical Data from analytics providers, such as Google, which are based outside the EU.
- Contact Data, Financial Data and Transaction Data from providers of technical, payment and delivery services, based inside or outside the EU.
-
Identity Data and Contact Data from:
- data brokers;
- aggregators; or
- web-based search engines;
-
Identity Data and Contact Data from publicly availably sources, such as:
- the Land Registry;
- Companies House;
- credit reference agencies; and
- the Electoral Register;
- Identity Data, Contact Data, Financial Data, Transaction Data and Special Category Data from parties to any transaction, dispute or other matter, in respect of which we are engaged by you to provide legal services.
-
DIRECT INTERACTIONS
-
HOW WE USE YOUR PERSONAL DATA
- We will use your personal data only when the law allows us to do so.
-
Most commonly, we will use your personal data in the following circumstances:-
-
Where we need to perform a contract for the provision of legal services, into which we:
- are about to enter; or
- have entered;
-
Where:
-
it is necessary:
- for our legitimate interests; or
- for those of a third party; and
- your interests and fundamental rights do not override those interests.
-
it is necessary:
- Where we need to comply with a legal or regulatory obligation.
-
Where we need to perform a contract for the provision of legal services, into which we:
- Click here to find out more about the types of lawful basis, on which we will rely when processing your personal data (if you are viewing this Privacy Notice on our website).
-
Additionally, we rely on consent:
- as a legal basis for processing your personal data; and
-
in relation to sending you third party direct marketing communications via:
- e-mail; or
- text message.
-
You have the right to withdraw consent to processing and/or marketing at any time by contacting us either:
- using the contact details, which can be accessed by clicking on this link Contacting us, if you are viewing this Privacy Policy on our website; or
- using the contact details, set out in paragraph 1.3.1 above, if you are not viewing it on our website.
- However, in most cases, we will be unable to continue to provide legal services where consent to processing your personal data is withdrawn.
- We will not use your personal data for the purpose of automated decision making.
-
PURPOSES, FOR WHICH WE WILL USE YOUR PERSONAL DATA
-
We have set out below, in table format, descriptions of:
- all of the ways, in which we intend to use your personal data; and
- the legal bases, on which we intend to rely when doing so.
- We have also identified the nature of our legitimate interests, where appropriate.
- Please note that we may process your personal data for more than one lawful ground, depending on the specific purpose, for which we are using your data.
-
Please contact us either:
- using the contact details, which can be accessed by clicking on this link Contacting us, if you are viewing this Privacy Policy on our website; or
- using the contact details, set out in paragraph 1.3.1 above, if you are not viewing it on our website.
Purpose/Activity Type of data Lawful basis for processing, including basis of legitimate interest Registering you as a new client. - Identity Data
- Contact Data
- Special Category Data.
- Performance of a contract with you.
- Consent.
Opening a new matter file for you as an existing client. - Identity Data
- Contact Data
- Special Category Data.
- Performance of a contract with you.
- Consent.
Providing the legal services, requested by you, including: - managing payments, fees and charges; and
- collecting and recovering money, owed to us.
- Identity Data.
- Contact Data.
- Financial Data.
- Transaction Data.
- Special Category Data.
- Marketing and Communica-tions Data.
- Performance of a contract with you.
- Necessity for our legitimate interests (to enable us to recover, debts due to us).
- Consent.
Managing our relationship with you, which will include: - notifying you about changes to our terms or privacy policy; and
- notifying you about services, which we offer.
- Identity Data.
- Contact Data.
- Marketing and Communica-tions Data.
- Performance of a contract with you.
- Necessity to comply with a legal obligation.
- Necessity for our legitimate interests (to enable us to keep our records updated, to grow our business and to inform our marketing strategy).
- Consent.
Administering and protecting our business and our website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data). - Identity Data.
- Contact Data.
- Technical Data.
- Necessity for our legitimate interests (to enable us to run our business, to provide administration, IT services and network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise).
- Necessity to comply with a legal obligation.
- Consent.
Submitting proposals for professional indemnity insurance. - Identity Data.
- Contact Data.
- Financial Data.
- Transaction Data.
- Special Category Data.
- Necessity for our legitimate interests (in order to enable us to run our business and to comply with our professional obligation to maintain professional indemnity insurance).
- Necessity to comply with a legal obligation.
- Consent.
Using data analytics to improve our website, services, marketing and customer relationships and experiences. - Technical Data.
- Usage Data.
- Necessity for our legitimate interests (in order to define types of clients for our services (and any products), to keep our website updated and relevant, to develop our business and to inform our marketing strategy).
- Consent.
Making suggestions and recommendations to you about services, which may be of interest to you. - Identity Data.
- Contact Data.
- Technical Data.
- Usage Data.
- Necessity for our legitimate interests (in order to develop our services and any products, and to grow our business).
- Consent.
-
We have set out below, in table format, descriptions of:
- MARKETING FROM THIRD PARTIES We will obtain your express opt-in consent before we share your personal data with any company outside Chandler Harris LLP for marketing purposes.
-
MARKETING FROM US
-
We may use your Identity Data, Contact Data, Technical Data and Usage Data to form a view of the services, which we think:
- you may want or need; or
- may be of interest to you.
- This is how we decide which services (and any products) may be relevant for you.
- We call this marketing.
-
You may receive marketing communications from us if:
-
you have:
- requested information from us; or
- purchased services from us; and
- (in each case) you have not opted out of receiving such marketing communications.
-
you have:
-
We may use your Identity Data, Contact Data, Technical Data and Usage Data to form a view of the services, which we think:
-
OPTING OUT
-
You can ask us to stop sending you marketing messages at any time by contacting us either:
- using the contact details, which can be accessed by clicking on this link Contacting us, if you are viewing this Privacy Policy on our website; or
- using the contact details, set out in paragraph 1.3.1 above, if you are not viewing it on our website.
-
Where you opt out of receiving marketing messages, this will not affect the processing of personal data, provided to us as a result of:
- the provision of a service; or
- another transaction.
-
You can ask us to stop sending you marketing messages at any time by contacting us either:
-
COOKIES
-
You can set your browser:
- to refuse all or some browser cookies, or
- to alert you when websites set or access cookies.
-
If you disable or refuse cookies, please note that some parts of our website may:
- become inaccessible; or
- not function properly.
- For more information about the cookies, which we use, please see here (if you are viewing this Privacy Policy on our website).
-
You can set your browser:
-
CHANGE OF PURPOSE
-
We will use your personal data only for the purposes, for which we collected them, unless:
- we reasonably consider that we need to use them for another reason; and
- that reason is compatible with the original purpose.
-
If you wish to elicit an explanation of the respect, in which the processing for the new purpose is compatible with the original purpose, please contact us either:
- using the contact details, which can be accessed by clicking on this link Contacting us, if you are viewing this Privacy Policy on our website; or
- using the contact details, set out in paragraph 1.3.1 above, if you are not viewing it on our website.
-
If we need to use your personal data for an unrelated purpose, we will:
- notify you; and
- explain the legal basis, which allows us to do so.
-
Please note that we may process your personal data:
- without your knowledge or consent; and
- in compliance with the above rules;
-
We will use your personal data only for the purposes, for which we collected them, unless:
-
DISCLOSURES OF YOUR PERSONAL DATA
-
We may have to share your personal data with the parties, set out below, for the purposes, set out in the table in paragraph 6 above:-
- External Third Parties, as set out in the Glossary, contained in paragraph 20 below.
- Third parties, to whom we may choose to sell, transfer, or merge parts of our business or our assets.
-
Alternatively, we may:
- seek to acquire other businesses; or
- merge with them.
- If a change happens to our business, the new owners may use your personal data in the same ways as are set out in this Privacy Notice.
-
We require all third parties:
- to respect the security of your personal data; and
- to treat them in accordance with the law.
-
Please note:
- that we do not allow our third-party service providers to use your personal data for their own purposes; and
-
that we permit them to process your personal data only:
- for specified purposes; &
- in accordance with our instructions.
-
We may have to share your personal data with the parties, set out below, for the purposes, set out in the table in paragraph 6 above:-
-
INTERNATIONAL TRANSFERS
- Some of our service providers and consultants are based outside the European Economic Area (EEA), so their processing of your personal data will involve a transfer of data outside the EEA.
-
Whenever we transfer your personal data outside the EEA, we ensure that a similar degree of protection is afforded to them by ensuring that at least one of the following safeguards is implemented:-
- We will transfer your personal data only to countries, which have been deemed to provide an adequate level of protection for personal data by the European Commission (NB: for further details, please see European Commission: Adequacy of the protection of personal data in non-EU countries if you are viewing this Privacy Notice on our website).
- Where we use certain service providers, we may use specific contracts, approved by the European Commission, which give personal data the same protection as it enjoys in Europe (NB: for further details, please see European Commission: Model contracts for the transfer of personal data to third countries if you are viewing this Privacy Notice on our website).
- Where we use providers, based in the USA, we may transfer data to them if they are part of the Privacy Shield, which requires them to provide similar protection to personal data, shared between the Europe and the USA (NB: for further details, see European Commission: EU-US Privacy Shield if you are viewing this Privacy Notice on our website).
-
Please contact us either:
- using the contact details, which can be accessed by clicking on this link Contacting us, if you are viewing this Privacy Policy on our website; or
- using the contact details, set out in paragraph 1.3.1 above, if you are not viewing it on our website.
-
DATA SECURITY
-
We have put in place appropriate security measures to prevent your personal data from being accidentally:
- lost;
- used or accessed in an unauthorised way;
- altered; or
- disclosed.
- In addition, we limit access to your personal data to those employees, agents, contractors and other third parties, who have a business need to know.
-
Those persons:
- will process your personal data only on our instructions; and
- are subject to a duty of confidentiality.
-
Please note:
- that we have put in place procedures to deal with any suspected personal data breach; and
-
that we will notify:
- you; and
- any applicable regulator;
-
We have put in place appropriate security measures to prevent your personal data from being accidentally:
-
DATA RETENTION: FOR HOW LONG WILL WE USE OR RETAIN YOUR PERSONAL DATA?
-
Please note that:
- by law; and/or
- in accordance with the rules, governing our profession; and/or
-
in compliance with rules and recommendations, made from time to time:
- by the Law Society; &/or
- by the Solicitors Regulation Authority;
- In some cases, records (including the personal data, identified above) will be retained for a minimum of twelve years.
- In all cases, this Privacy Notice will continue to apply in respect of all retained personal data.
- In some circumstances, you can ask us to delete your data (NB: please see Request erasure below for further information if you are viewing this Privacy Notice on our website).
- In some circumstances, we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
-
Please note that:
-
YOUR LEGAL RIGHTS
- Under certain circumstances, you have rights under data protection laws in relation to your personal data.
- If you are viewing this Privacy Notice on our website, please click on the links below in order to find out more about these rights:-
-
If you wish to exercise any of the rights, set out above, please contact us either:
- using the contact details, which can be accessed by clicking on this link Contacting us, if you are viewing this Privacy Policy on our website; or
- using the contact details, set out in paragraph 1.3.1 above, if you are not viewing it on our website.
-
NO FEE USUALLY REQUIRED
-
You will not have to pay a fee:
- to access your personal data; or
- to exercise any of your other rights, listed above.
-
However, we may charge a reasonable fee if your request or requests is or are:
- clearly unfounded;
- repetitive; or
- excessive.
- Alternatively, we may refuse to comply with your request or requests in such circumstances.
-
You will not have to pay a fee:
-
WHAT WE MAY NEED FROM YOU
-
We may need to request specific information from you in order to help us:
- to confirm your identity; and
-
to ensure your right:
- to access your personal data; or
- to exercise any of your other rights, listed above.
- This is a security measure to ensure that personal data are not disclosed to any person, who has no right to receive them.
- We may also contact you to ask you for further information in relation to your request in order to speed up our response.
-
We may need to request specific information from you in order to help us:
-
TIME LIMIT TO RESPOND
- We try to respond to all legitimate requests within one month.
-
Occasionally, it may take us longer than a month:
- if your request is particularly complex; or
- if you have made a number of requests.
-
In such a case, we will:
- notify you; and
- keep you updated.
-
GLOSSARY
-
LAWFUL BASIS
-
Legitimate Interest
-
The term Legitimate Interest means the interest of our business in conducting and managing our business in order to enable us to give you:
- the best service; and
- the best and most secure experience.
-
We make sure that we consider and balance any potential impact:
- on you (both positive and negative); and
- on your rights;
-
We do not use your personal data for activities where our interests are overridden by the impact on you, unless we:
- have your consent; or
- are otherwise required or permitted to do so by law.
-
You can obtain further information about the way, in which we weigh our legitimate interests against any potential impact on you in respect of specific activities by contacting us, either:
- using the contact details, which can be accessed by clicking on this link Contacting us, if you are viewing this Privacy Policy on our website; or
- using the contact details, set out in paragraph 1.3.1 above, if you are not viewing it on our website.
-
The term Legitimate Interest means the interest of our business in conducting and managing our business in order to enable us to give you:
-
Performance of Contract
The term Performance of Contract means processing your data where it is necessary:
- for the performance of a contract, to which you are a party (such as a contract to provide legal services); or
- to take steps at your request before entering into such a contract.
- Comply with a legal or regulatory obligation The term Comply with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation, to which we are subject.
-
Legitimate Interest
-
EXTERNAL THIRD PARTIES
External Third Parties are:
-
service providers:
- acting as processors, controllers or joint controllers; &
- based inside or outside the EU;
-
professional advisers:
- acting as processors or joint controllers (including lawyers, bankers, auditors and insurers); &
- based inside or outside the EU;
- H M Revenue & Customs;
-
regulators and other authorities:
- acting as processors or joint controllers; &
- based in the United Kingdom;
-
insurers and brokers:
- acting as processors or joint controllers;
- providing professional indemnity insurance or legal risk insurance; &
- based inside or outside the EU.
-
service providers:
-
YOUR LEGAL RIGHTS
You have the following rights:-
-
Request access
- You have the right to request access to your personal data (commonly known as a ‘data subject access request’).
-
This enables you:
- to receive a copy of the personal data, which we hold about you; and
- to check that we are lawfully processing them.
-
Request correction
- You have the right to request correction of the personal data, which we hold about you.
- This enables you to have corrected any incomplete or inaccurate data, which we hold about you (although we may need to verify the accuracy of the new data, which you provide to us).
-
Request erasure
- You have the right to request erasure of your personal data.
- This enables you to ask us to delete or remove personal data where there is no good reason for our continuing to process it.
-
You also have the right to ask us to delete or remove your personal data:
- where you have successfully exercised your right to object to processing (NB: please see paragraph 20.3.4 below);
- where we may have processed your information unlawfully; or
- where we are required to erase your personal data in order to comply with local law.
- However, please note that we may not always be able to comply with your request of erasure for specific legal reasons, which will be notified to you (if applicable) at the time of your request.
-
Object to processing
-
You have the right to object to processing of your personal data (or those of a third party) where:
- we are relying on a legitimate interest; and
- there is something about your particular situation, which makes you want to object to processing on this ground, as you feel that it impacts on your fundamental rights and freedoms.
- You also have the right to object where we are processing your personal data for direct marketing purposes.
- In some cases, we may demonstrate that we have compelling legitimate grounds to process your information, which override your rights and freedoms.
-
You have the right to object to processing of your personal data (or those of a third party) where:
-
Request restriction of processing
- You have the right to request restriction of processing of your personal data.
-
This enables you to ask us to suspend the processing of your personal data in the following scenarios:-
- Where you want us to establish the data’s accuracy.
-
Where:
- our use of the data is unlawful; but
- you do not want us to erase them.
- Where you need us to hold the data, even if we no longer require them, as you need them to establish, exercise or defend legal claims.
-
Where:
- you have objected to our use of your data; but
- we need to verify whether we have overriding legitimate grounds to use them.
-
Request the transfer
-
You have the right to request the transfer of your personal data:
- to you; or
- to a third party.
-
We will provide:
- to you; or
- to the third party, whom you have nominated;
-
Please note that this right applies only to automated information:
- which you initially provided consent for us to use; or
- in circumstances, in which we used the information to perform a contract with you.
-
You have the right to request the transfer of your personal data:
-
Withdraw consent at any time
- You have the right to withdraw consent at any time where we are relying on consent to process your personal data.
- However, this will not affect the lawfulness of any processing, carried out before you withdraw your consent.
- If you withdraw your consent, we may not be able to provide certain products or services to you.
- We will advise you if this is the case at the time, at which you withdraw your consent.
-
Request access
-
LAWFUL BASIS