Privacy Policy

Arthurs Solicitors is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store and share personal data, and your rights in relation to that data.

We process personal data in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 and, where relevant, the Privacy and Electronic Communications Regulations 2003.

Who we are

Arthurs Solicitors is the data controller for the personal data described in this Privacy Policy.
Contact details
Arthurs Solicitors
Laburnum House
2 Station Road
Birchington-on-Sea
Kent
CT7 9DQ

Telephone: 01843 210377

Email: compliance@arthurs-solicitors.co.uk

 

For questions about this Privacy Policy or how we handle personal data, please contact our Data Protection Officer:


Jeff Boateng
Data Protection Officer
Email: compliance@arthurs-solicitors.co.uk
Telephone: 01843 210377

The personal data we collect

The personal data we collect depends on how you interact with us, but may include:
• your name, postal address, email address and telephone number;
• date of birth;
• identification documents and information used to verify identity and address;
• information you provide when making an enquiry online, by email, by telephone, by post or in person;
• information relating to your legal matter, dispute or instructions;
• payment, billing and financial information;
• records of correspondence and communications with you;
• website usage and technical information, including IP address, browser type and pages visited, where permitted;
• CCTV images captured at our premises; and
• telephone call recordings where call recording is in operation.
In some matters, particularly family law and legally aided matters, we may also process special category personal data or other sensitive personal information where this is necessary and lawful.

How we collect personal data

We collect personal data:
• directly from you;
• from website forms;
• from telephone calls, emails, letters and meetings;
• from your opponent’s solicitors or other parties involved in your matter;
• from barristers, experts, courts, mediators, the Legal Aid Agency or other relevant third parties;
• from publicly available sources;
• from identity verification, anti-money laundering and compliance checks; and
• automatically through our website where cookies or similar technologies are used in accordance with your preferences.

How we use personal data

We use personal data for the following purposes:
• to respond to enquiries and assess whether we may be able to assist you;
• to provide legal advice, assistance and representation;
• to communicate with you and manage our relationship with you;
• to verify identity and carry out anti-money laundering, fraud prevention and regulatory checks;
• to administer billing, payments and financial records;
• to maintain records and comply with legal, regulatory and professional obligations;
• to respond to complaints and manage service quality;
• to operate, secure and improve our website and systems;
• to carry out business administration, auditing and compliance activities; and
• to send marketing communications where you have given consent or where we are otherwise permitted by law.

Lawful bases for processing

We must have a lawful basis for processing personal data. Depending on the circumstances, we may rely on one or more of the following lawful bases.

Contract

We process personal data where it is necessary to take steps at your request before entering into a contract, or to perform our contract with you for legal services.

Legal obligation

We process personal data where this is necessary to comply with legal and regulatory obligations, including anti-money laundering requirements, court obligations, accounting rules, regulatory reporting and professional record-keeping duties.

Legitimate interests

We process personal data where this is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and interests. This may include responding to enquiries, operating our business, protecting our legal position, ensuring network and information security, reviewing call quality, operating CCTV for safety and security, and improving our services.

Consent

We rely on consent where you have freely given it for a specific purpose, for example to receive marketing emails or text messages, or to allow non-essential cookies or analytics technologies.

Special category data

Where we process special category personal data, we do so only where an appropriate lawful condition applies. This may include where processing is necessary for the establishment, exercise or defence of legal claims, or where another condition under data protection law applies.

Website enquiries and contact forms

When you submit a contact form on our website, we use the information you provide to respond to your enquiry, assess whether we can assist you and contact you about the legal services you have requested.

Submitting a contact form does not sign you up to marketing communications unless you actively opt in. Marketing consent is separate and optional.
Please do not send highly sensitive, confidential or urgent information through the website unless you are content for us to review it for the purpose of responding to your enquiry.

Marketing communications

We may send marketing communications about our legal services, updates, events or news where:
• you have given your consent; or
• we are otherwise permitted by law.

Where we rely on consent for email or text marketing, you may withdraw that consent at any time. All marketing emails will include an unsubscribe mechanism, and you can also contact us directly to opt out.
We do not sell personal data or share your details with third parties for their own marketing purposes.

Website analytics and online technologies

We may use website analytics and similar technologies to understand how visitors use our site, improve performance and develop the site further.
Where these technologies are not strictly necessary, we will ask for your consent before using them.
Further information is set out in our Cookie Policy.

CCTV

We operate CCTV at our premises for safety, security, crime prevention, investigation and evidential purposes. Signs are displayed where CCTV is in operation.
We rely on our legitimate interests in maintaining a safe environment, protecting our premises and staff, and preventing and detecting crime. CCTV is not used for automated decision-making.

CCTV footage is usually retained for up to 90 days unless it is required for a longer period, for example in connection with an incident, complaint or investigation.

Telephone call recording

We record most incoming and outgoing telephone calls, except where payment card details are taken or other circumstances make recording inappropriate.
We use call recordings for service quality, training, complaint handling, regulatory compliance, evidential review and staff safety. We rely on our legitimate interests and, where relevant, legal obligations for this processing.

Call recordings are usually retained for six months unless there is a reason to retain them for longer, for example in connection with a complaint, claim, regulatory issue or investigation.

Artificial intelligence

In order to support the delivery of legal services and improve operational efficiency, we may use technology that includes artificial intelligence.

Where AI tools process personal data, we aim to ensure that their use is lawful, fair, secure and proportionate. We seek to maintain human oversight, assess risk, verify outputs where appropriate, and avoid unlawful solely automated decision-making that has legal or similarly significant effects.

Who we share personal data with

We may share personal data where necessary with:
• courts, tribunals and regulators;
• barristers, experts, mediators, translators, process servers and other professionals involved in your matter;
• the Legal Aid Agency and other public bodies where relevant;
• auditors, insurers, accountants and compliance advisers;
• identity verification, fraud prevention and anti-money laundering providers;
• IT service providers, cloud hosting providers and secure storage providers;
• payment processors and banking providers;
• website and communications service providers; and
• law enforcement agencies or other authorised bodies where required or permitted by law.
We only share personal data where we have a lawful basis for doing so, and we seek to ensure that third parties handle it securely and only for appropriate purposes.

International transfers

We generally store and process personal data within the United Kingdom. If we transfer personal data outside the UK, we will do so only where lawful safeguards are in place, such as an adequacy decision or appropriate contractual protections.

How long we keep personal data

We keep personal data only for as long as necessary for the purpose for which it was collected, including to meet legal, regulatory, insurance, limitation and operational requirements.

Our usual retention periods are:.

• matter files and related case data: usually 6 years after the matter ends, or longer where required by law, regulation, limitation periods or because the client was under 18;
• anti-money laundering and compliance records: usually 5 years from the end of the business relationship or matter, where applicable;
• unsuccessful enquiries / matters not taken on: usually 18 months;
• complaints files: usually 6 years after conclusion;
• financial and accounting records: usually 7 years;
• card payment data: not retained longer than necessary to process the transaction;
• call recordings: usually 6 months;
• CCTV footage: usually up to 90 days unless needed longer for an incident or investigation; and
• marketing suppression records: for as long as necessary to make sure we respect opt-out requests.

How we protect personal data

We take information security seriously. We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures may include encryption, password protection, access controls, monitoring, staff training, secure disposal and security testing.

Your rights

Depending on the circumstances, you may have the right to:
• be informed about how your personal data is used;
• request access to your personal data;
• request correction of inaccurate or incomplete personal data;
• request erasure of personal data;
• request restriction of processing;
• object to processing based on legitimate interests;
• object at any time to direct marketing;
• request portability of certain data; and
• withdraw consent where we rely on consent.
To exercise any of these rights, please contact our Data Protection Officer.

Complaints

If you are unhappy with how we use your personal data, please contact us first so that we can try to resolve the issue.

You also have the right to complain to the Information Commissioner’s Office.

Links to other websites

Our website may contain links to other websites. Once you leave our website, we are not responsible for the privacy practices of other sites. You should read the privacy notices applicable to those websites.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in law, regulation, guidance, technology or our processing activities. The latest version will always be published on our website.

Version: 2 – Date: 28.05.2026