Middleton Law Ltd Privacy Policy
- DATA CONTROLLER
This privacy notice provides you with details of how we collect and process your personal data. We are required to notify you of this information under data protection legislation, including the General Data Protection Regulation. Please ensure that you read this Notice carefully and any other similar notice we may provide to you from time to time when we collect or process personal information about you.
Middleton Law Ltd registered at 1 Stable Court Beechwood Estate, Elmete Lane, Leeds, West Yorkshire, England, LS8 2LQ is the Data Controller for the purpose of relevant data protection legislation, including the General Data Protection Regulation (“GDPR”) for the information which it collects for marketing, recruitment and employment purposes.
- LEGAL BASIS
Your data will be processed on the basis that Middleton Law Ltd has a legitimate interest in being able to achieve the aims of processing set out below. Where special category data is provided, the provider of the data warrants that they consent to Middleton Law Ltd processing that data or that they have obtained written consent from the data subject.
- WHAT INFORMATION DO WE COLLECT ABOUT YOU?
Personal data means any information capable of identifying an individual. It does not include anonymised data.
We will only use your personal data for a purpose it was collected for or a reasonably compatible purpose if necessary. For more information on this please email us at admin@middletonlawltd.co.uk.
We may process the following categories of personal data about you:
- Communication Data – any communication that you send to us (e.g. through email, text, social media messaging, social media posting or any other communication that you send us). We process this data for the purposes of communicating with you, for record keeping and for the establishment, pursuance or defence of legal claims.
• Customer Data – data relating to any charges for services/goods such as your name, title, billing address, delivery address email address, phone number, contact details, purchase details and your card details. We process this data to supply the services and to keep records of such transactions.
• User Data – information about how you use our website. We process this data to operate our website, ensure relevant content is provided to you, maintain the security of our website, maintain backups and administer our website. Further information about our use of cookies and similar technologies can be found in our Cookie Policy.
• Technical Data – data about your use of our website and online services such as your IP address, browser type and version, device information, page views, length of visits and other technical information. We may collect this information through analytics tools and cookies where appropriate consent has been provided. Further information can be found in our Cookie Policy.
• Marketing Data – contact details for you (e.g. name, address or location, email address and telephone number) data about your marketing and communication preferences, ‘CRM’ data relating to exchanges we have had with you over different mediums (e.g. email or telephone or in person).
3.1 SENSITIVE DATA – We do not routinely collect any Sensitive Data about you, although you may provide it in the course of providing instructions. Sensitive data refers to data that includes details about your race or ethnicity, religious or philosophical beliefs, sexuality, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data. We do not collect information about criminal convictions or offences.
3.2 FAILURE TO PROVIDE DATA – Where we are required to collect personal data by law, or under the terms of the contract between us, we may not be able to provide services to you if you do not provide us with that data when requested, but if that is the case we will notify you at the time.
- HOW WE USE COOKIES
Our website uses cookies and similar technologies to distinguish you from other users of our website, to provide website functionality, to analyse website traffic and usage, and to improve our services.
Full details of the cookies we use, the purposes for which they are used, the third parties who may place cookies on our website, and information on how to manage your cookie preferences can be found in our Cookie Policy.
When you first visit our website, you will be presented with a cookie consent banner which allows you to manage your cookie preferences. You may change your preferences at any time through the cookie settings available on our website.
Where required by law, non-essential cookies will only be placed on your device with your consent.
.
- MARKETING COMMUNICATIONS
Under the Privacy and Electronic Communications Regulations, we may send you marketing communications from us if (i) you made a purchase or asked for information from us about our goods or services or (ii) you agreed to receive marketing communications and in each case you have not opted out of receiving such communications since. Under these regulations, if you are a limited company, we may send you marketing emails without your consent. However, you can still opt out of receiving marketing emails from us at any time.
We do not share your personal data with any third parties for their own marketing purposes. You can update your marketing preferences or unsubscribe from communications from us at any time by emailing admin@middletonlawltd.co.uk. If you opt out of receiving marketing communications this opt-out does not apply to personal data provided as a result of other transactions/services.
- SHARING YOUR PERSONAL DATA
We may have to share your personal data with the parties set out below:
- Service providers who provide IT, marketing and system administration services.
• Professional advisers including other lawyers, bankers, auditors and insurers.
• Government bodies that require us to report processing activities.
• Partners who deliver our services on our behalf.
• Third parties to whom we may sell, transfer, or merge parts of our business or our assets. We require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.
- TRANSFER OF DATA OUTSIDE THE UNITED KINGDOM
Some of our service providers may process personal data outside the United Kingdom. Whenever we transfer personal data outside the UK, we ensure that an appropriate level of protection is afforded to it by ensuring that at least one of the following safeguards applies:
• The recipient is located in a country that has been deemed by the UK Government to provide an adequate level of protection for personal data;
• Appropriate safeguards are in place, including the use of the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or other approved transfer mechanisms;
• Another lawful transfer mechanism permitted under applicable data protection legislation applies.
Where required by law, we will obtain your consent before transferring your personal data outside the United Kingdom.
You will have the right to withdraw this consent at any time.
- DATA SECURITY
We have put in place security measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed without authorisation. We also allow access to your personal data only to those employees and partners who have a business need to know such data. They will only process your personal data on our instructions and they must keep it confidential.
We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach if we are legally required to.
- DATA RETENTION
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
When deciding how long to keep the data we look at its amount, nature and sensitivity, potential risk of harm from unauthorised use or disclosure, the processing purposes, if these can be achieved by other means and legal requirements. The law requires us to keep basic information about our customers (including Contact details, Identity, Financial and Transaction Data) for six years after they stop being customers.
- YOUR LEGAL RIGHTS
Under data protection laws you have rights in relation to your personal data that include the right to request access, correction, erasure, restriction, transfer, to complain, to object to processing, to portability of data and (where the lawful ground of processing is consent) to withdraw consent.
You can see more about these rights in our Data Breach Complaints Policy, and at: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individualrights/
If you wish to exercise any of the rights set out above, please email us at admin@middletonlawltd.co.uk.
If you are not happy with any aspect of how we collect and use your data, you have the right to complain to us and to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk).
Policy Updated 4th June 2026
