Privacy
Privacy policy
We advise on data protection, so this policy had better be a good one. Tell us if any part of it is unclear.
Who is responsible for your data
Morgan Law is the controller of personal data collected through this website and in the course of providing legal services. You can reach us at contact@morganlawgroup.co or at the postal address in the footer.
TODO: name a data protection officer or contact, if one is required.
What we collect
When you use the contact form
- Your name, email address, and phone number if you give it.
- The category of matter, approximate timing, approximate value, and the description you write.
- Technical data collected as part of handling the request, including your IP address, which we use to limit automated abuse of the form.
When you become a client
- Identity and verification documents required by anti-money laundering and know-your-client rules.
- Case material you provide, which in these matters frequently includes financial records and communications, and may include special category data.
- Billing and payment records.
When you browse this site
TODO: state exactly what analytics or tracking you use, if any. If you use none beyond what is strictly necessary, say so β it is a genuine differentiator for this client base, and it means you may not need a cookie banner at all. If you add analytics later, this section and your consent mechanism have to change with it.
Why we process it, and on what basis
- To respond to your enquiry β because you asked us to, and because we have a legitimate interest in answering people who contact us.
- To provide legal services β to perform our contract with you, and, for special category data, because processing is necessary for the establishment, exercise, or defence of legal claims.
- To meet our legal and regulatory obligations β client due diligence, conflict checks, and record-keeping required by our regulator.
- To protect this website β preventing spam and abuse of the contact form.
Who we share it with
Only where necessary for your matter or our obligations: counsel and experts instructed on your case, courts and tribunals, regulators and law enforcement where we are required or permitted to disclose, our professional insurers and auditors, and the service providers who run our IT, email, and document systems under written terms.
We do not sell personal data, and we do not share it for third-party marketing.
AI-assisted processing
We use AI tooling to analyse case material β see our Technology & AI page for the detail. In summary: providers are engaged under terms that prevent client content being used to train their models; identifying detail is removed where it is not needed for the analysis; and no automated output is acted on without review by a qualified lawyer.
We do not make decisions about you by automated means alone that produce legal or similarly significant effects. You may ask us to handle your matter without AI-assisted processing.
International transfers
TODO: list the countries data may be transferred to and the safeguards relied on β adequacy decisions, standard contractual clauses, or equivalent. This section matters more than most firms treat it, particularly where AI providers are involved.
How long we keep it
- Enquiries that do not become matters: TODO β typically 12 months, then deleted.
- Client files: TODO β set by your regulator and your insurer, commonly 6β7 years after the matter closes.
- Anti-money laundering records: TODO β as required by the applicable regulations.
Your rights
Subject to the applicable regime, you may request access to your data, correction of it, erasure, restriction of processing, or portability, and you may object to processing based on legitimate interests. Some of these rights are limited where we are required to retain records or where legal professional privilege applies.
To exercise any of them, email contact@morganlawgroup.co. We will respond within the statutory period.
You also have the right to complain to a supervisory authority. TODO: name the relevant authority and link to it.
Security
We apply technical and organisational measures appropriate to material that is confidential and often privileged. Note that standard email and this websiteβs contact form are not secure channels β once you are a client we will give you a secure route for sending documents.
Changes
If we change this policy we will update the date below, and we will tell clients directly where a change is material.
Last updated: TODO β set a real date.