Hepburn Delaney Ltd respects your privacy and is committed to protecting your personal data. This Privacy and Data Notice explains how we collect, use, and protect your information, and your rights under data protection law.  It also includes the GDPR complaints procedure.
  1. Who We Are

Hepburn Delaney Ltd is a firm of solicitors specialising in family law, wills and probate, estate planning, and mediation.

Email: dataprotection@hepburndelaney.co.uk | Phone: 01442 218090

  1. What Is Personal Data

Personal data means any information identifying you. Special category data includes sensitive data such as health information.

  1. Why We Collect Your Data

We collect data to provide legal services, comply with obligations, verify identity, and improve services.

  1. Types of Data We Collect

Identity, contact, financial, case data, technical data, and special category data where required.

  1. How We Collect Your Data

Directly from you, automatically via website, and from third parties such as regulators and service providers.

  1. How We Use Your Data

We use your data for legal services, communication, compliance, administration, and fraud prevention.

6A. Lawful Basis for Processing

  • Providing legal services – Contract – Necessary to perform our agreement with you
  • AML checks – Legal obligation – Required by regulation
  • Client management – Legitimate interests – To operate effectively
  • Enquiries – Legitimate interests – To respond to requests
  • Legal compliance – Legal obligation – Required by law
  • Marketing (existing clients) – Legitimate interests – Relevant communications with opt-out
  • Marketing (new contacts) – Consent – Only with permission
  • Recruitment – Legitimate interests / Contract – Hiring purposes
  • Website analytics – Legitimate interests – Improve performance

Special Category Data:

  • Legal claims – Article 9(2)(f) – Legal proceedings
  • Family matters – Article 9(2)(f)/(g) – Legal necessity/public interest
  • Health data – Consent or legal claims basis
  1. Marketing

You may opt out at any time. We do not sell your data.

  1. Data Retention

We retain data only as necessary, typically 7 years for client matters, longer where required.  For example. data that related to people under 18 years old is kept until that person turns 25 as per legal requirements.  Wills are kept for the lifetime of the person.

  1. Data Security

We use secure systems, encryption and access controls.

  1. International Transfers

We use appropriate safeguards including adequacy decisions and contractual protections.

  1. Sharing Your Data

We share data with courts, advisers, service providers, and regulators where necessary.

  1. Your Rights

Access, correction, erasure, restriction, objection, portability, and complaint to the ICO.

  1. Complaints

Contact us first. You may escalate to the ICO if dissatisfied.  Helpline on 0303 123 1113 / Make a complaint | ICO

    1. This section governs the handling of data protection complaints in line with UK GDPR, EU GDPR, and Data Protection Act 2018.
    2. What Is a Data Protection Complaint?
      A complaint relating to the processing of personal data, including access requests, breaches, accuracy, retention, or lawful processing.
    3. Submitting a Complaint
      Complaints may be submitted via email, phone, post, in person, or other channels. Required details include name, contact details and description.
    4. Acknowledgement
      Complaints will be acknowledged within 30 calendar days.
    5. Investigation & Communication
      Complaints will be investigated promptly with updates provided where appropriate.
    6. Outcome
      A final written response will outline findings, actions taken and next steps.
    7. Escalation Procedures & External Remedies

Internal Escalation:
– Stage 1: Review by Data Protection Officer
– Stage 2: Director review
– Acknowledged within 10 working days; response within 30 days

External Escalation:
– Complainants may contact the ICO or EU supervisory authority

Judicial Remedies:
– Individuals retain rights under GDPR Articles 78–79

Internal Reporting:
– Escalated complaints logged and reviewed for improvement.

    • Record Keeping & Reporting
      Records maintained for 3 years and breaches reported where required.
    • Training & Review
      Annual training and policy review.
    • Contact
      DPO: dataprotection@hepburndelaney.co.uk

14. Access Requests (SAR)

We respond within one month, subject to exemptions.

  • A SAR gives access to personal data, not automatically the whole legal file.
  • Legal files may include privileged, confidential, third-party or internal material.
  • Information may be withheld or redacted where exemptions apply.
  • Requests for the full legal file should be treated separately from SARs.
  • We may ask the requester to clarify whether they want personal data, the legal file, or both.

15. Cookies

Cookies are used to improve website functionality. See our cookie policy.

  1. Updates

We may update this notice periodically.

June 2026