Introduction
This website is owned and operated by Ringrose Law, an SRA-licensed Alternative Business Structure (ABS) with its head office at Endeavour House, 3 Gilbert Drive, Boston, Lincolnshire PE21 7TR. Ringrose Law is registered in England and Wales and is authorised and regulated by the Solicitors Regulation Authority under registration number 58125. As the data controller, Ringrose Law is committed to safeguarding the privacy of our website visitors and service users.
This Privacy Notice applies to website users, potential clients, and third parties whose data we process to provide legal services. We maintain separate privacy notices for clients, staff, and potential employees.
Ringrose Law processes your data in accordance with the requirements of the Data Protection Act 2018, the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019, and the UK General Data Protection Regulation (UK GDPR).
This Privacy Notice explains the types of personal data we may collect, how we use it, and the steps we take to protect it. We want you to be fully informed about your rights and our data practices.
Conditions for Processing data
We process your data when legally permitted, as outlined under Article 6 of UK GDPR:
- Contractual obligations: We process your data to fulfil our contract, including providing legal services and meeting Legal Aid Agency requirements, if applicable.
- Legitimate interests: We may process data to pursue legitimate business interests reasonably expected when running a law firm, such as quality audits.
- Legal compliance: Where required by law, such as reporting fraud or criminal activity, or compliance with court or regulatory requirements.
- Vital interests: We may process personal data if necessary to protect someone’s life, known as "vital interests," such as in urgent safeguarding situations.
- Legal claims, insurance, and risk management: We may process personal data as necessary for the establishment, exercise, or defence of legal claims, in connection with court proceedings or out-of-court processes, and for purposes related to obtaining or maintaining insurance coverage, managing risks, or obtaining professional advice. The legal basis for this processing is our legitimate interests in protecting our business against risks.
- Consent: With your consent, we process data for specific purposes, like sending newsletters.
When do we collect your data?
We collect your data when you provide it (e.g., via email, web form, phone, SignVideo BSL, in person, or by post) or from others involved in your case. We also automatically collect technical data when you visit our website. Please do not supply any other person’s personal data to us, unless we ask you to do so.
Correspondence Data
We may process information related to any communication you send to us, including the content and metadata associated with it. Metadata generated through website contact forms helps us with record-keeping and communication management. Our legal basis for processing correspondence data is our legitimate interests, specifically the proper administration of our website and effective communication with users.
Enquiry and Notification Data
We may process information contained in any enquiry you submit regarding our services ("enquiry data"). This data may be retained and used to provide relevant services and meet legal and regulatory obligations, based on our legitimate interests. For any marketing activities, the legal basis is consent, which you may withdraw at any time.
We may also process information you provide for subscribing to our email notifications ("notification data"), used solely for updates. Processing notification data is based on your consent, which you may withdraw at any time.
What sort of data do we collect?
- Information you provide: When contacting us, signing up for newsletters, leaving reviews, or using our services.
- Client services: Names, contact details, proof of ID, date of birth, address verification, financial data, legal matter information, sensitive data (e.g., health or criminal data), and demographic details as relevant.
- Website data: Technical data, such as IP address, location, and clickstream, which helps us improve site functionality and user experience. We may use cookies or pixels for analytics.
How do we use your data?
Provision of services: For legal advice, assistance, and representation, and for related purposes such as reporting to auditors and the Legal Aid Agency, managing our relationship, and resolving complaints.
Regulatory compliance: To meet legal obligations, including identity verification, fraud, credit, and anti-money laundering checks.
Consent-based use: With your consent, we may inform you of other services, enhance our website, conduct surveys, and gather feedback. You may adjust your direct marketing preferences at any time by contacting us directly / updating your preferences through your account settings, if applicable. Consent withdrawal does not affect the lawfulness of processing done prior to the withdrawal.
Cookies
A cookie is a small file placed on your device with your permission, helping us analyse web traffic and enhance your site experience. Cookies typically don’t identify you personally, but personal data we store may be linked to information obtained through cookies.
You can choose to accept or decline cookies. Most browsers automatically accept cookies, but you can modify your settings to decline them. However, this may limit certain website features.
We use several types of cookies:
- Necessary cookies – essential for website functionality.
- Preferences – to remember settings and preferences.
- Statistics – to analyse site usage.
- Marketing – to deliver targeted advertising.
- Unclassified – cookies yet to be categorized.
We also use third-party cookies, such as those from Google Analytics, to help monitor website use and improve services. For more details on cookies used and how to manage them, see our Cookie Policy.
By law, non-essential cookies require your consent. We use both session cookies (which expire when you close your browser) and persistent cookies (which remain until manually deleted or they reach their expiration date). The types of cookies we use:
- Authentication – to identify you when you visit and navigate our website.
- Status – to help us determine if you are logged into our website.
- Personalisation – to store your preferences and personalise the website experience.
- Security – as part of security measures used to protect user accounts and the website.
- Advertising – to display relevant advertisements.
- Analysis – to help us analyse site use and performance.
- Cookie consent – to remember your cookie preferences.
We also use third-party cookies such as Google Analytics, to help monitor website use and improve services. Google Analytics collects site usage data via cookies, including IP addresses. For more information, see Google’s Privacy Policy.
Our website may use cookies from third parties like analytics providers or social media platforms. We recommend reviewing their privacy policies for details on data management.
Managing Cookies
Most browsers allow you to refuse cookies or delete them. Instructions for managing cookies on popular browsers, such as Chrome, Firefox, Safari, and Edge, are available on each browser's official website. Simply visit the support or help section of your browser’s website for detailed guidance on managing cookies.
You can also manage or withdraw your cookie consent at any time through our Cookie Declaration tool, available on our website. Please note that blocking all cookies may affect your browsing experience and could limit the use of certain features of our website. For any questions about the cookies we use, please contact us.
How do we protect your data?
We recognise that much of the data you provide may be sensitive, confidential, or subject to Legal Professional Privilege. We have robust policies and security measures in place to protect it, including password-protected access, dual-factor authentication, and encryption for secure emails. Our systems are regularly monitored and tested for vulnerabilities.
How long will we keep your data?
We retain your data only as long as necessary for its purpose and review our retention periods regularly to ensure compliance:
- Enquiry data: Retained for up to six years to meet SRA conflict-checking requirements.
- Legal matters, complaints, and financial data: Retained for at least six years after matter completion to meet SRA, insurance, and other legal requirements. Cardholder data is destroyed immediately after processing; other financial data is retained for seven years per HMRC requirements. Data records are reviewed periodically to justify continued retention in line with data minimisation principles. Extended retention is subject to annual review and approval by our Data Privacy Manager.
International transfers of your personal data
We may transfer your personal data overseas (e.g. software services) or when sharing information with trusted professionals outside the UK as part of a client matter.
Our website hosting is UK-based; however, personal data you submit for online publication may be accessible worldwide.
To ensure your data receives an adequate level of protection wherever it is processed, we follow strict safeguards, including:
- Only transferring data to countries with UK adequacy decisions or similar measures, ensuring they provide sufficient data protection standards.
- Implementing contractual provisions with service providers that guarantee your data receives equivalent protections as required within the UK.
- Requiring third-party recipients overseas to use data only for specified purposes, secure it through appropriate technical and organisational measures, delete it when no longer needed, and treat it per this Data Privacy Notice and applicable data protection laws.
Links to other websites
Our website may contain links to external sites. We do not control these sites, so please review their privacy policies.
Your rights under UK GDPR
Under UK GDPR, you have the following rights regarding your personal data. Please note that these rights may be subject to limitations where legal or regulatory obligations require us to retain or process data.
- Right to be informed: About how we use your data, as outlined here in this Data Privacy Notice and any subsequent notices.
- Right of access: To request a copy of your personal data (via a "data subject access request"). If we cannot fulfil your request, we will explain why.
- Right to rectification: To correct inaccurate or incomplete data.
- Right to erasure: To request deletion in specific circumstances.
- Right to restrict processing: To temporary limit data processing for limited ICO-approved reasons.
- Right to data portability: To receive your data in a machine-readable format.
- Right to object: To request we stop processing your data in specific circumstances, either entirely or for certain purposes.
- Rights related to automated decision making: To limit decisions made by automated means – typically, we do not use automated decision-making.
- Withdrawing consent for marketing: You may also withdraw consent at any time for marketing communications by contacting us directly.
To support your rights under UK GDPR, you can contact us directly through our website Your Data page.
For more information, visit the ICO’s website or, if you believe your data has been mishandled, contact the ICO at 0303 123 1113 or via www.ico.org.uk/concerns.
Contact details
For questions or data requests, contact our Data Privacy Manager:
Name: David Heath
Website: Your Data page
Email: sar@ringroselaw.co.uk
Phone: 01636 594460
Post: Ringrose Law, PO Box 10997, Sleaford, NG34 4FG
Changes to this notice
We may update this notice to reflect changes in our data practices or to meet new standards. Continued use of our services implies acceptance of any changes. We encourage users to review this notice periodically to stay informed of any updates.