Privacy Notice
We take your privacy very seriously. Please read this privacy notice carefully as it contains important information about who we are and how and why we collect, store, use and share your personal data. It also explains your rights in relation to your personal data and how to contact us or the relevant supervisory authority if you have a complaint.
When we use your personal data, we are regulated by the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable data protection legislation. Nalders LLP is the controller of your personal data for the purposes of those laws.
Our use of your personal data is subject to your instructions, applicable data protection legislation, other relevant legal and regulatory obligations and our professional duty of confidentiality.
Key Terms
It may be helpful to explain some key terms used in this notice:
| We, us, our | Nalders LLP (trading as Nalders Solicitors) |
| Data Privacy Manager |
Gayle McDermott Farley House, Truro T: 01872 241414 “>gmd@nalders.co.uk |
| Personal data | Any information relating to an identified or identifiable individual. |
| Special category personal data |
Personal data revealing:
|
Personal data we collect about you
The table below sets out the personal data we will or may collect in the course of advising and/or acting for you.
| Personal data we will collect |
|---|
|
| Personal data we may collect depending on why you have instructed us |
|---|
|
This personal data is required to enable us to provide legal services to you. If you do not provide the information we request, this may delay or prevent us from providing services to you.
How your personal data is collected
- from publicly accessible sources, e.g. Companies House or HM Land Registry;
- directly from a third party, e.g.:
- sanctions screening providers;
- credit reference agencies;
- client due diligence providers;
- from a third party with your consent, e.g.:
- your bank or building society, another financial institution or advisor;
- consultants and other professionals we may engage in relation to your matter;
- your employer and/or trade union, professional body or pension administrators;
- your doctors, medical and occupational health professionals;
- via our website—we use cookies on our website (for more information on cookies, please see our cookies policy)
- via our information technology (IT) systems, e.g.:
- case management, document management and time recording systems;
- automated monitoring of our websites and other technical systems, such as our computer networks and connections, communications systems, email and instant messaging systems
How and why we use your personal data
Under data protection law, we can only use your personal data where we have a lawful basis for doing so. This will usually be because:
- we need to provide legal services to you;
- we are required to comply with legal or regulatory obligations;
- we have a legitimate business reason for using the information; or
- you have given your consent.
The table below summarises the main ways in which we use personal data and the legal basis for doing so.
| Purpose | Legal Basis |
|---|---|
| Providing legal services and managing your matter | Contract |
| Identity verification, anti-money laundering checks, sanctions screening and regulatory compliance | Legal obligation |
| Using approved technology systems, including approved artificial intelligence tools, to support the delivery, administration and quality assurance of legal services | Contract, legitimate interests and legal obligation |
| Responding to regulatory enquiries, audits, investigations and reporting requirements | Legal obligation |
| Business administration, staff training, quality assurance and service improvement | Legitimate interests |
| Protecting confidential information, systems and business assets | Legitimate interests and legal obligation |
| Maintaining and updating client records | Contract, legitimate interests and legal obligation |
| Statistical analysis and management information | Legitimate interests |
| Marketing our services | Legitimate interests |
| External audits, accreditations and quality assessments | Legitimate interests and legal obligation |
Where we process special category personal data, we will do so in accordance with applicable data protection legislation and any additional legal conditions that apply. In some cases this will be based on your consent, but it may also be necessary to establish, exercise or defend legal claims, comply with legal obligations or for other lawful reasons permitted by data protection legislation.
Promotional communications
We may send you information about:
- legal developments that may be relevant to you;
- our services;
- events and publications; and
- new service offerings.
We do this because we have a legitimate interest in keeping clients and contacts informed about matters that may be of interest to them. Where consent is required by law, we will ask for it separately.
We will never sell your personal data or allow other organisations to use it for their own marketing purposes.
You can opt out at any time by:
- emailing marketing@nalders.co.uk;
- using the unsubscribe link in a marketing email; or
- replying STOP to a marketing text message.
We may ask you to review your preferences if you instruct us again or if there are changes to our services or legal obligations.
Who we share your personal data with
We routinely share personal data with:
- professional advisers whom we instruct on your behalf or refer you to, such as barristers, medical professionals, accountants, tax advisers and other experts;
- other third parties where necessary to carry out your instructions, such as mortgage lenders, HM Land Registry, Companies House and other organisations involved in your matter;
- credit reference agencies;
- our insurers and insurance brokers;
- external auditors, for example in connection with Lexcel, ISO or other accreditations and financial audits;
- our bank;
- external service suppliers, representatives, agents, technology providers and software platforms that we use to support and improve the delivery of legal and administrative services, including case management systems, document management systems, client onboarding and identity verification platforms, appointment scheduling systems, document collation and analysis services, communication platforms and approved artificial intelligence tools and services operating within our technology environment.
We only allow our service providers to handle your personal data where we are satisfied that appropriate confidentiality, information security and data protection measures are in place. We also impose contractual obligations on service providers to ensure that they only use your personal data to provide services to us and, where applicable, to you.
Where we use external technology providers, including approved artificial intelligence providers, we only do so where we are satisfied that appropriate confidentiality, information security and data protection safeguards are in place.
We may disclose and exchange information with law enforcement agencies, courts, tribunals, regulators and other public authorities where required to comply with our legal and regulatory obligations.
We may also need to share personal data with other parties in connection with a sale, merger, acquisition, restructuring or other corporate transaction involving our business. We will seek to share the minimum information necessary and, where appropriate, information will be anonymised. Recipients of the information will be subject to confidentiality obligations.
Where your personal data is held
Information may be held at our offices and those of our third party agencies, service providers, representatives and agents as described above (see ‘Who we share your personal data with‘).
Personal data may also be processed within approved technology platforms used by the firm, including approved cloud-based services and approved artificial intelligence tools operating within our Microsoft 365 environment.
Some of these third parties may be based outside the European Economic Area. For more information, including how we safeguard your personal data when this occurs, please see below: ‘Transferring your personal data out of the EEA‘.
How long your personal data will be kept
We will retain your personal data after we have finished advising or acting for you where this is necessary:
- to respond to any questions, complaints or claims made by you or on your behalf;
- to demonstrate that we have treated you appropriately and in accordance with our professional obligations;
- to comply with legal, regulatory, accounting, insurance and record-keeping requirements; and
- to establish, exercise or defend legal claims.
We will not retain your personal data for longer than is necessary for the purposes set out in this notice. Different retention periods apply to different categories of personal data and different types of matter. Further details are available in our Records Retention Schedule, which is available on request.
This retention approach applies both to information provided to us and to information created during the course of providing legal services, including records, correspondence, notes, analyses and other work product generated by our staff or with the assistance of approved technology systems.
When it is no longer necessary to retain your personal data, we will securely delete, destroy or anonymise it.
Transferring your personal data out of the EEA
To deliver services to you, it is sometimes necessary for us to transfer your personal data outside the United Kingdom and/or the European Economic Area (EEA), for example:
- where our service providers, technology providers, approved artificial intelligence providers or software platforms process data outside the United Kingdom or the EEA;
- if you are located outside the United Kingdom or the EEA;
- where there is an international element to the matter on which we are advising you.
Whenever we transfer personal data outside the United Kingdom or the EEA, we ensure that appropriate safeguards are in place and that the transfer complies with applicable data protection laws.
Depending on the circumstances, these safeguards may include:
- transfers to countries that have been recognised as providing an adequate level of protection for personal data;
- the use of Standard Contractual Clauses and, where required, the UK International Data Transfer Addendum or other approved transfer mechanisms;
- contractual, technical and organisational measures designed to protect personal data.
Some of the technology platforms used by the firm, including approved cloud-based systems and approved artificial intelligence tools, may involve the processing of personal data outside the United Kingdom or the EEA. Where this occurs, we take steps to ensure that appropriate safeguards are in place and that your personal data remains protected.
If you would like further information about international transfers of your personal data, please contact us.
Your rights
You have the following rights, which you can exercise free of charge:
| Access | The right to be provided with a copy of your personal data. |
| Rectification | The right to require us to correct any mistakes in your personal data. |
| To be forgotten | The right to require us to delete your personal data in certain situations. |
| Restriction of processing | The right to require us to restrict processing of your personal data in certain circumstances, for example if you contest the accuracy of the data. |
| Data portability | The right to receive the personal data you provided to us in a structured, commonly used and machine-readable format and/or transmit that data to a third party in certain situations. |
| To object |
The right to object:
|
| Not to be subject to automated individual decision-making | The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. |
Nalders LLP does not make decisions affecting clients solely through automated processing or artificial intelligence systems without appropriate human involvement.
For further information on each of those rights, including the circumstances in which they apply, please contact us or see the https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/guidance published by the Information Commissioner’s Office (ICO) on individual rights under data protection legislation.
If you would like to exercise any of those rights, please:
- email, call or write to us – see below: How to contact us;
- provide enough information to identify you (for example your full name, address and client or matter reference number);
- provide proof of your identity and address (for example a copy of your driving licence or passport and a recent utility bill or bank statement); and
- let us know what right you wish to exercise and the information to which your request relates.
Keeping your personal data secure
We have appropriate technical and organisational security measures in place to protect personal data against accidental loss, unauthorised access, misuse, alteration or disclosure. Access to personal data is restricted to those who have a genuine business need to know it. Anyone processing personal data on our behalf does so only in an authorised manner and is subject to confidentiality obligations.
Some of the systems used by the firm include approved cloud-based technologies and artificial intelligence tools. Where such systems are used, we seek to ensure that appropriate technical and organisational measures are in place to protect personal data, maintain confidentiality and comply with applicable data protection requirements.
We also have procedures in place to identify, investigate and respond to suspected personal data breaches. Where we are legally required to do so, we will notify affected individuals and the appropriate regulator.
If you would like further information about protecting yourself against fraud, identity theft, cybercrime, viruses and other online risks, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
How to complain
We hope that we can resolve any query or concern you may raise about our use of your personal data.
You also have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK’s independent authority for data protection and privacy matters, if you believe that we have not complied with applicable data protection laws.
The ICO can be contacted via its website at httpsn 0303 123 1113.
We would, however, appreciate the opportunity to address your concerns before you contact the ICO and would encourage you to contact us first.
Changes to this privacy notice
This privacy notice was originally published on 23 May 2018 and was most recently updated on 14 July 2026.
The July 2026 update included changes relating to the firm’s use of approved technology systems and artificial intelligence tools, data processing activities, technology providers, international data transfers and data protection rights.
We may update this privacy notice from time to time to reflect changes in our business, technology, legal obligations or regulatory requirements. Any updated version will be published on our website.
How to contact us
Our contact details are shown below:
| Our contact details | Our Data Privacy Manager’s contact details |
| Nalders LLP
Farley House, Truro | T: 01872 241414 | contact@nalders.co.uk |
Gayle McDermott
Farley House, Truro | T: 01872 241414 | gmd@nalders.co.uk |
