Hepburn Delaney Ltd respects your privacy and is committed to protecting your personal data. This Privacy and Data Notice explains how we collect, use, and protect your information, and your rights under data protection law. It also includes the GDPR complaints procedure.
Hepburn Delaney Ltd is a firm of solicitors specialising in family law, wills and probate, estate planning, and mediation.
Email: dataprotection@hepburndelaney.co.uk | Phone: 01442 218090
- What Is Personal Data
Personal data means any information identifying you. Special category data includes sensitive data such as health information.
- Why We Collect Your Data
We collect data to provide legal services, comply with obligations, verify identity, and improve services.
- Types of Data We Collect
Identity, contact, financial, case data, technical data, and special category data where required.
- How We Collect Your Data
Directly from you, automatically via website, and from third parties such as regulators and service providers.
- How We Use Your Data
We use your data for legal services, communication, compliance, administration, and fraud prevention.
6A. Lawful Basis for Processing
- Providing legal services – Contract – Necessary to perform our agreement with you
- AML checks – Legal obligation – Required by regulation
- Client management – Legitimate interests – To operate effectively
- Enquiries – Legitimate interests – To respond to requests
- Legal compliance – Legal obligation – Required by law
- Marketing (existing clients) – Legitimate interests – Relevant communications with opt-out
- Marketing (new contacts) – Consent – Only with permission
- Recruitment – Legitimate interests / Contract – Hiring purposes
- Website analytics – Legitimate interests – Improve performance
Special Category Data:
- Legal claims – Article 9(2)(f) – Legal proceedings
- Family matters – Article 9(2)(f)/(g) – Legal necessity/public interest
- Health data – Consent or legal claims basis
- Marketing
You may opt out at any time. We do not sell your data.
- Data Retention
We retain data only as necessary, typically 7 years for client matters, longer where required. For example. data that related to people under 18 years old is kept until that person turns 25 as per legal requirements. Wills are kept for the lifetime of the person.
- Data Security
We use secure systems, encryption and access controls.
- International Transfers
We use appropriate safeguards including adequacy decisions and contractual protections.
- Sharing Your Data
We share data with courts, advisers, service providers, and regulators where necessary.
- Your Rights
Access, correction, erasure, restriction, objection, portability, and complaint to the ICO.
- Complaints
Contact us first. You may escalate to the ICO if dissatisfied. Helpline on 0303 123 1113 / Make a complaint | ICO
-
- This section governs the handling of data protection complaints in line with UK GDPR, EU GDPR, and Data Protection Act 2018.
- What Is a Data Protection Complaint?
A complaint relating to the processing of personal data, including access requests, breaches, accuracy, retention, or lawful processing.
- Submitting a Complaint
Complaints may be submitted via email, phone, post, in person, or other channels. Required details include name, contact details and description.
- Acknowledgement
Complaints will be acknowledged within 30 calendar days.
- Investigation & Communication
Complaints will be investigated promptly with updates provided where appropriate.
- Outcome
A final written response will outline findings, actions taken and next steps.
- Escalation Procedures & External Remedies
Internal Escalation:
– Stage 1: Review by Data Protection Officer
– Stage 2: Director review
– Acknowledged within 10 working days; response within 30 days
External Escalation:
– Complainants may contact the ICO or EU supervisory authority
Judicial Remedies:
– Individuals retain rights under GDPR Articles 78–79
Internal Reporting:
– Escalated complaints logged and reviewed for improvement.
-
- Record Keeping & Reporting
Records maintained for 3 years and breaches reported where required.
- Training & Review
Annual training and policy review.
- Contact
DPO: dataprotection@hepburndelaney.co.uk
14. Access Requests (SAR)
We respond within one month, subject to exemptions.
- A SAR gives access to personal data, not automatically the whole legal file.
- Legal files may include privileged, confidential, third-party or internal material.
- Information may be withheld or redacted where exemptions apply.
- Requests for the full legal file should be treated separately from SARs.
- We may ask the requester to clarify whether they want personal data, the legal file, or both.
15. Cookies
Cookies are used to improve website functionality. See our cookie policy.
- Updates
We may update this notice periodically.
June 2026