Cygnet Law are ‘controllers’ of the information that we collect about you (‘personal data’). Being controllers of your personal data, we are responsible for how your data is processed. The word ‘process’ covers most things that can be done with personal data, including collecting, storing, using and destroying that data. As a data controller we are registered with the Information Commissioner’s Office with Registration Number ZA199533.
This notice explains why and how we process your data, and explains the rights you have around your data, including the right to access it and to object to the way it is processed. Please see the section on ‘Your rights as a data subject’ for more information.
Who we are
Cygnet Family Law Limited trading as ‘Cygnet Law’ is a Company registered in England & Wales under company number 07000449. Our registered office is Portland House, West Dyke Road, Redcar TS10 1DH. A list of Directors is available for inspection at the registered office. We are regulated and authorised by the Solicitors Regulation Authority (SRA) under number 544578. The SRA Code of Conduct sets out the regulatory framework imposed on service providers such as ours. The current edition of the Code is available on the SRA Website at www.sra.org.uk.
‘Personal data’ is any information that relates to a living, identifiable person. This data can include your name, contact details, and other information we gather as part of our relationship with you. It can also include ‘special categories’ of data, which is information about a person’s race or ethnic origin, religious, political or other beliefs, physical or mental health, trade union membership, genetic or biometric data, sex life or sexual orientation. The collection and use of these types of data is subject to strict controls. Similarly, information about criminal convictions and offences is also limited in the way it can be processed.
We are committed to protecting your personal data, whether it is ‘special categories’ or not, and we only process data if we need to for a specific purpose, as explained below. We collect your personal data mostly through our contact with you, and the data is usually provided by you, but in some instances, we may receive data about you from other people/organisations. We will explain when this might happen in this Notice.
Later sections of this Policy contain more information about:
Contacting you about events or areas of interest
As an individual, we will only send general invitations or updates to you if you have provided your consent for us to do so. If you represent an organisation, we may write to you from time to time unless you have told us that you do not wish to receive further mailings. Any marketing and briefing emails will provide you with the option to opt out of future mailings. You can also use this option to manage the type of mailings that you receive from us.
If you do not provide personal data
Where we need to collect personal data by law, or under the terms of a contract we have with you and you do not provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In this case, we may stop providing that service, but we will notify you if this is the case at the time.
Personal data received from third parties
Our clients, the courts and other legal professionals may include personal data about individuals that is relevant to a legal matter that we are working on. We are committed to protecting all personal data that we hold and will treat this data with the same care that we treat data held about our clients.
Processing your data to provide you with our services
In general terms, we process your data to fulfil our responsibilities in the relationship that we have with you. The table below lists more specific purposes for processing your data, and the legal basis for each type of processing.
Data we may process to provide our services to you
Legal basis for processing
There are three grounds under which we may process your data to provide you with legal services.
The nature of some of our work dictates that we will hold special category data that relates to you.
Additional grounds under which may process your data are:
For some processing purposes, we share your data with third parties. This is a list of the information we may share with external recipients, and for what purpose:
Who we share your data with
Our IT system providers have access to data so that we can ensure that our systems operate effectively and that we are running current versions of software. Financial and quality auditors view data to monitor that we are complying with statutory and regulatory requirements and to confirm that we are complying with the requirements of the Lexcel legal practice quality mark.
We will share your data with other legal professionals, costs drafting and other technical experts when that is appropriate to fulfil the requirements of the service we are providing for you. Specialist confidential waste disposal contractors manage our paper archive records and carry out controlled destruction of the records when they reach the end of their retention period.
Should you visit a website belonging to Cygnet Law, we may gather information about you. The information we collect may include your personal information, such as your name, contact information, IP addresses or other things that identify you individually.
Across our website you may come across a form which allows you to make enquiries about the firm. Should you use these forms a member our team will receive the enquiry. This information will then be sent to a lawyer in the department best placed to handle the enquiry.
By accessing a website belonging to Cygnet Law we may be able to get information about that usage. This allows us to:
How we store your data
Your personal data is held in both hard copy and electronic formats. Electronic data, including emails, is stored on our servers, which are located in the UK. Our cloud-based electronic systems store data in servers located within the European Economic Area (EEA).
We will not normally send such data outside the EEA. We may sometimes send such data to a recipient in a country outside the EEA which has been designated by the EU Commission as providing adequate data protection. If we need to send the data to a country outside the EEA that has not been so designated, we will have appropriate contract clauses agreed with the recipient place to protect the data.
How long we keep your data
If we are providing legal services to you, we will notify you about how long we will keep your data for when we close your matter with us. We maintain a schedule which dictates how long we keep documents for. Our document retention schedule applies dates that meet a statutory requirement, reflect limitation periods for action following completion of a legal transaction or reflect good business practice.
Once the applicable retention period expires, unless we are legally required to keep the data longer, or there are important and justifiable reasons why we should keep it, we will securely delete/destroy the data.
Your rights as a data subject
The General Data Protection Regulation provides you with a number of rights. These include:
Exercising your rights, queries and complaints
For more information on your rights, if you wish to exercise any right or for any queries you may have, or if you wish to make a complaint, please contact our Data Protection Manager, Mr Peter Medd email firstname.lastname@example.org.
Complaints to the Information Commissioner
You have a right to complain to the Information Commissioner’s Office (ICO) about the way in which we process your personal data. You can make a complaint on the ICO website https://ico.org.uk.
Changes to this Policy
We may change this privacy notice from time to time. If we make any significant changes in the way we treat your personal information we will take reasonable steps to draw your attention to this.