Privacy & Data Protection Policy
Introduction
This Privacy & Data Protection Policy outlines the commitment of Notta Taj Law (“we”, “us”, “our”) to protect the privacy of individuals (“you”, “your”) in accordance with the Data Protection Act 2018 and the General Data Protection Regulation (GDPR). This policy applies to all personal data that we collect, use, and are responsible for. We are the “controller” of this information for the purposes of these laws.
The Data We Collect
We may collect, use, store, and transfer different kinds of personal data about you, which may include:
On this website
- Usage Data: information about how you use our website, products, and services.
- Marketing and Communications Data: your preferences in receiving marketing from us and our third parties and your communication preferences.
- Technical Data: Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website.
- Enquiry Data: in the event you submit an enquiry via our contact form, information you share with us including your name, email address, telephone number and details surrounding your enquiry.
If you engage our services
Please refer to the letter of engagement which will be provided to you before commencement of your engagement of us.
- Identity Data: your marital status, title, date of birth, gender, job title, employer.
- Medical history: diagnoses, treatment, prognosis and other relevant medical data.
- Financial Data: your bank account and payment card details.
- Transaction Data: details about payments to and from you for our services.
- Call Data: call recordings may be used for training and quality control.
- Correspondence data: any written communication we may have with you.
- Any other information you may share with us as part of your instructions to us.
How We Use Your Personal Data
We use the information you provide primarily for the provision of legal services to you and for related purposes, including:-
- Updating and enhancing client records
- Analysis to help us manage our practice.
- Legal and regulatory compliance.
Our use of that information is subject to your instructions, the Data Protection Act 1988 and our duty of confidentiality.
Sharing Your Personal Data
We may have to share your personal data with the parties set out below for the purposes set out in the table above:
- Service providers who provide IT and system administration services.
- Professional advisers including lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services required to carry out your instructions.
- HM Revenue & Customs, regulators, and other authorities based in the United Kingdom who require reporting of processing activities in certain circumstances.
- Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets.
Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Your Legal Rights
In this section, we have summarised the rights that you have under data protection law, but this summary is not comprehensive. Therefore, please read the relevant laws and guidance from relevant regulatory authorities for a fuller explanation of these rights.
Your principal rights under data protection law are:
- the right to access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to object to processing;
- the right to data portability;
- the right to complain to a supervisory authority; and
- the right to withdraw consent.
The General Data Protection Regulation also gives you the right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where the alleged infringement of data protection laws occurred. The UK supervisory authority if the Information Commissioner’s Office who can be contacted at https://ico.org.uk/make-a-complaint/.
You may exercise any of your rights in relation to your personal data by written notice to us at info@nottatajlaw.com.
Changes to This Policy
We may update this Privacy & Data Protection Policy from time to time. Any updates will be reflected on this page.
Contact Us
If you have any questions about this Privacy & Data Protection Policy, please contact us at info@nottatajlaw.com.
Last updated 23 April 2024.