Privacy Policy
This Privacy Notice explains how and for what purposes we collect personal data about individuals, how we use, store, and share it, and the rights individuals have under data protection law. It applies to personal data we process in connection with our website, enquiries, legal services, recruitment, complaints, and other business operations.
This notice should be read alongside any additional privacy information we may provide to you, as well as our Cookies Policy and our website Terms and Conditions.
1. Who we are
Hodge Jones & Allen LLP is a law firm authorised and regulated by the Solicitors Regulation Authority. We are registered with the Information Commissioner’s Office as a data controller under registration number Z4785246.
For the purposes of data protection law, we are the controller of personal data we process in connection with our legal services and generally in connection with our business operations.
2. How to contact us about data protection
If you have any questions about this Privacy Notice, how we use your personal data, or if you wish to exercise your data protection rights, you can contact our Data Protection Officer by emailing dataprotection@hja.net or writing to our Data Protection Officer at:
Data Protection Officer
Hodge Jones & Allen LLP
180 North Gower Street
London
NW1 2NB
3. Applicable law
We process personal data in accordance with applicable data protection legislation, including the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and, where relevant, amendments made by the Data (Use and Access) Act 2025.
4. How we collect personal data
We may collect personal data directly from you, for example when you:
- make an enquiry with us or instruct us to provide legal services
- provide feedback or reviews, or make a complaint
- apply for a job or for work experience
- send us documents in hard copy or electronically
- use our website, write to us, meet with us in person, or communicate by telephone or video call
We may also receive personal data about you from other sources, for example from:
- clients, former clients, prospective clients, litigation friends, and referral organisations in connection with the legal services we provide
- other parties to legal proceedings and their representatives
- courts, barristers, experts, witnesses, and other third parties involved in the legal process
- other organisations or individuals who hold information about you that is relevant to a legal matter we are conducting, such as healthcare professionals and medical agencies
- interpreters, translators and transcription providers
- regulators and other organisations such as the Solicitors Regulation Authority, the Legal Ombudsman, and the Legal Aid Agency
5. What personal data we collect
The personal data we collect about you will depend on your relationship with us and, where applicable, the nature of your case. It may include for example:
- names, addresses, email addresses, telephone numbers, and other contact details
- dates of birth and identification information
- file reference numbers and matter details
- information about legal issues, enquiries, or instructions
- correspondence, attendance notes, advice, evidence, and documents relating to cases
- financial information, billing information, bank details, and payment information
- information required for identity, anti-money laundering, sanctions, conflict, and risk checks
- information about family members, household members, opponents, witnesses, or other people connected with cases
• information about complaints, concerns, or feedback
• website usage data, device information, cookie identifiers, and analytics information
• recruitment information
Because of the nature of our legal work, in certain circumstances we may process special category data, such as information about your health, disability, vulnerability, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life, sexual orientation, genetic data, or biometric data. We may also process criminal offence data, including information about criminal allegations, offences, convictions, cautions, investigations, or related proceedings, where this is relevant to a case.
6. Why we use personal data and our ‘lawful bases’ for processing
We use personal data for the purposes set out below, dependent on context. We only handle personal information where we have a valid lawful basis for doing so, and the lawful basis we rely on will similarly depend on the circumstances.
Where we process special category data, we will identify an Article 9 UK GDPR condition. Where we process criminal offence data, we will identify a condition under Article 10 UK GDPR and the Data Protection Act 2018 where required. In both cases, this will normally be because processing is necessary in connection with legal claims.
We rely on consent only where consent is the appropriate lawful basis or condition for the particular processing, and where the processing is genuinely optional. This may include certain non-essential cookies, some forms of electronic marketing, or optional feedback. Where we rely on consent, we will explain this when we ask for it and you may withdraw consent at any time.
Where we rely on legitimate interests, those interests may include operating and managing our legal practice, assessing whether we can act, communicating with clients and others involved in legal matters, protecting our clients’ and our own legal rights, maintaining professional standards, managing risk, preventing fraud, ensuring IT and information security, responding to complaints, and improving our services. We balance these interests against the rights and freedoms of the individuals affected.
6.1 Enquiries and prospective clients
In relation to enquiries and prospective clients, we use personal data in order to acknowledge and respond to the enquiry, assess whether we can assist, carry out initial conflict and risk checks, decide whether we can accept instructions, and communicate about possible legal services.
If you contact us about a potential matter, please provide only the information reasonably necessary for us to understand the general nature of your enquiry and to carry out conflict and suitability checks. Please do not provide detailed confidential documents or sensitive information at the initial enquiry stage unless we specifically ask you to do so.
If you provide information to us before we have confirmed that we can act for you, we will handle it in accordance with our legal, regulatory, confidentiality, and data protection obligations. However, we will only become your solicitors if and when we confirm that we are able to accept instructions. Submitting an enquiry to us does not mean that we have agreed to act for you or that a solicitor-client relationship has been created. We may already act for another person with an interest in the same matter, or there may be another reason why we cannot act for you. Providing information to us does not automatically prevent us from continuing to act for an existing client or from acting for another person, subject always to our professional obligations concerning conflicts, confidentiality, and legal professional privilege.
For the purposes of this section, where you are the prospective client, we rely primarily on the lawful basis that it is necessary in order to take steps at your request prior to entering into a contract; where someone else is the client, we rely primarily on the lawful basis that it is necessary for the purposes of pursuing our legitimate business interests.
6.2 Legal, regulatory, and professional obligations
We use personal data to comply with legal and regulatory obligations, including obligations relating to anti-money laundering, sanctions, conflict checks, confidentiality, legal professional privilege, court and tribunal rules, legal aid, complaints, professional indemnity insurance, audits, and regulatory reporting.
For these purposes, we rely on the lawful basis that it is necessary for compliance with a legal obligation where a specific legal/regulatory obligation applies; otherwise, we rely on the lawful basis that it is necessary for the purposes of pursuing our legitimate business interests.
6.3 Providing legal services
We use personal data to provide legal advice, assistance, and representation, open and administer client matters, communicate with you and others, prepare documents, gather evidence, instruct barristers or experts, deal with courts or tribunals, negotiate, settle or litigate claims, administer legal aid or insurance funding where applicable, bill for our work, and take steps reasonably connected with the conduct and administration of your matter.
For these purposes, where you are our client, we rely primarily on the lawful basis that it is necessary for the performance of our contract with you; where someone else is the client, we rely primarily on the lawful basis that it is necessary for the purposes of pursuing our legitimate business interests. Where court rules or legal duties require specific processing, we rely on the lawful basis that it is necessary for compliance with a legal obligation.
6.4 Complaints, risk management, and insurance
We use personal data to investigate and respond to complaints, manage claims or potential claims, obtain advice, deal with insurers, maintain professional standards and improve our services.
For these purposes, we rely on the lawful basis that it is necessary for compliance with a legal obligation where a specific legal/regulatory obligation applies; otherwise, we rely on the lawful basis that it is necessary for the purposes of pursuing our legitimate business interests.
6.5 Business administration and service improvement
We use personal data to administer our business, manage files, maintain records, train staff, supervise work, monitor service quality, obtain feedback, maintain accreditations, operate IT systems, ensure network and information security, and improve our services.
For these purposes, where relevant and where you are the client, we rely primarily on the lawful basis that it is necessary for the performance of our contract with you; otherwise, we rely on the lawful basis that it is necessary for the purposes of pursuing our legitimate business interests.
6.6 Website, email, analytics, and marketing
Our website may use cookies and similar technologies, such as tracking pixels, tags, scripts, web storage, or analytics tools. These technologies may collect information about your device, browser, IP address, pages visited, referral source, and how you interact with our website. Some cookies or similar technologies are necessary for the website to work. Others may be used for analytics, functionality, performance, advertising, measuring campaigns, or improving our services. Where required by law, we will ask for your consent before setting non-essential cookies or similar technologies.
We may therefore use personal data to operate our website, understand how it is used, manage enquiries, improve online services, measure marketing effectiveness, and comply with cookie and electronic communications rules.
To the extent permitted by law, we may process limited technical information about electronic communications, such as sender, recipient, date, time, routing information and security logs, where necessary for information security, system administration, compliance, audit, misuse investigation, client relationship management, or the protection of legal rights. Any monitoring will be proportionate and carried out in accordance with applicable law and our internal policies.
For essential website operation and security, we generally rely on legitimate interests. For non-essential cookies or similar technologies, and for electronic marketing where consent is required, we rely on consent. Where we carry out marketing or service improvement activities that do not require consent, we rely on legitimate interests, subject to your rights and any applicable opt-out.
For further information, see our Cookies Policy and our website Terms and Conditions.
6.7 Recruitment, work experience, and applications
We use personal data to deal with applications for employment, work experience, internships, training contracts, consultancy arrangements, or other roles with us. This may include assessing applications, communicating with applicants, arranging interviews or assessments, taking up references where appropriate, carrying out right to work, qualification, regulatory, DBS or other pre-engagement checks where required or appropriate, making recruitment decisions, keeping recruitment records, and dealing with any queries, complaints or disputes.
For these purposes, we rely primarily on the lawful bases of taking steps at your request before entering into a contract. Where applicable, we rely on the lawful basis of compliance with legal obligations instead. Where neither of the above applies, we rely on the lawful basis of legitimate interests in managing recruitment, assessing suitability, keeping appropriate records, and protecting our legal position.
7. Sharing personal data
We will only share personal data in accordance with the purposes and lawful bases set out above. Depending on the nature of your relationship with us, we may share personal data with recipients including for example:
- clients, former clients, prospective clients, litigation friends, and referral organisations in connection with the legal services we provide
- other parties to legal proceedings and their representatives
- courts, barristers, experts, witnesses, and other third parties involved in the legal process
- other organisations or individuals who hold information about you that is relevant to a legal matter we are conducting, such as healthcare professionals and medical agencies
- interpreters, translators and transcription providers
- IT hosting, case management, document management, email, archive, cybersecurity, and other IT support providers
- banks, payment processors and client account providers
- marketing, website, analytics, enquiry management, and feedback providers
- external storage, file destruction, or archive providers
- insurers, regulators, auditors, external regulatory advisers, and other organisations including the Solicitors Regulation Authority, the Legal Ombudsman, and the Legal Aid Agency
- identity, anti-money laundering, fraud prevention, and sanctions checking providers
- law enforcement agencies, regulators, or public authorities
8. Use of AI tools
Subject to strict safeguards, we may use approved technology tools, including AI-assisted tools, to support our work. This may include tasks such as document organisation, searching, summarising, transcription, drafting assistance, or internal administrative support. AI-assisted outputs are subject to human review where they are used or relied on in connection with legal work.
We only use such tools which have been carefully audited for their security and compliance with our policies and professional obligations, ensuring in particular no model training on personal data, appropriate access controls, and strong encryption for data in transit.
Further information about our use of AI tools is available in our AI notice.
9. International transfers
Some of our service providers may process personal data outside the United Kingdom.
Where this happens, we will take steps to ensure that appropriate safeguards are in place in accordance with data protection law.
These safeguards may include adequacy regulations, standard contractual clauses, the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, or other lawful transfer mechanisms.
10. How long we keep personal data
We keep personal data for as long as reasonably necessary for the purposes for which we hold it. Retention periods vary depending on the type of information and the context in which it is processed. For example:
- enquiry information may be kept for as long as reasonably necessary to respond to follow-up questions, manage conflicts, monitor enquiries, maintain business records, and deal with any complaint or issue arising from the enquiry, in accordance with our internal retention policy
- client matter files are normally retained for the minimum periods set out in the relevant client care letter and file closing letter (for most files, this minimum retention period is usually seven years)
- some original documents, such as wills or documents held for safekeeping, may be retained indefinitely or until returned
- complaints, claims, regulatory, and insurance records may be retained for as long as needed for legal, regulatory, audit, or risk management reasons
- anti-money laundering, identity and sanctions records will be retained in accordance with applicable legal and regulatory requirements
- website analytics, cookies and marketing data will be retained in accordance with the relevant cookie notice, consent settings, and platform retention periods
- we may retain recruitment information for a period after the recruitment process has ended in accordance with our internal retention policy
11. Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse, or unauthorised access, disclosure, or alteration. These measures include access controls, secure systems, staff confidentiality obligations, information security procedures, and secure communication options where appropriate.
We cannot guarantee the security of email during transmission. If you have concerns about the sensitivity of information you need to send to us, please contact us so that we can discuss appropriate arrangements. We may use secure email, password protection, secure file transfer or other protective measures where appropriate, particularly for sensitive information.
12. Your data protection rights
Depending on the circumstances, you may have the following rights under data protection law:
- the right to be informed about how we use your personal data
- the right of access to your personal data
- the right to rectification of inaccurate personal data
- the right to erasure of personal data in certain circumstances
- the right to restrict processing in certain circumstances
- the right to data portability in certain circumstances
- the right to object to processing in certain circumstances
- rights relating to automated decision-making and profiling
- the right to withdraw consent where we rely on consent
- the right to complain to us and to the Information Commissioner’s Office
These rights are not absolute. They may be subject to exemptions or restrictions, including where information is protected by legal professional privilege, confidentiality, legal claims, regulatory obligations, crime prevention, or the rights and freedoms of others.
13. Subject access requests and file requests
You have the right to request access to personal data we hold about you. This is commonly known as a subject access request (SAR).
A subject access request gives you a right of access to your personal data which we hold, but not necessarily to copies of the documents containing that personal data or (if you are a client) to our entire file relating to you. Additionally, some personal data may be withheld or redacted where an exemption applies, including legal professional privilege, confidentiality, information about other people, regulatory obligations, or other statutory restrictions.
We will usually respond to a subject access request free of charge. We may charge a reasonable fee or refuse to comply with a request where the law allows us to do so, for example where a request is manifestly unfounded or excessive.
We will respond without undue delay and within the applicable statutory period (normally one calendar month), after carrying out reasonable and proportionate searches for personal data falling within the scope of the request. Where we reasonably require information to confirm your identity or authority, the period for responding will not begin until we have received that information. Where clarification is reasonably required, the response period may be paused while we wait for your clarification.
Clients and former clients may also have separate rights to request documents that we hold legally belonging to them. Those rights are separate from subject access rights and may be subject to different legal and professional restrictions, including any lien we are entitled to exercise.
You can make a subject access request or file/documents request by emailing dataprotection@hja.net or writing to our Data Protection Officer at our office address. You can also make a request by other means, including verbally, but using these contact details will help us deal with your request promptly. We may ask you to specify whether you are seeking personal data under data protection law or documents belonging to you as a client or former client.
Please include enough information to help us identify you, understand whether you are making a subject access request or file/documents request, and locate the personal data or documents you are asking for, such as your name, contact details, any relevant file or matter reference, what specifically you are seeking, and any relevant dates or time periods.
14. Requests for rectification, erasure, restriction, or objection
You may ask us to rectify or erase personal data, restrict how we use it, or object to particular processing. We will consider any such request in accordance with data protection law.
However, we may need to continue to retain or process some personal data where we have a lawful reason to do so. For example, we may need to keep information to comply with legal, regulatory, professional indemnity, audit, complaints-handling, anti-money laundering, legal aid, limitation or file retention requirements, or to establish, exercise or defend legal claims. This means that we may not always be able to erase or stop processing personal data when asked.
Where you ask us to correct information, we may need to distinguish between information that is factually inaccurate and information that forms part of a contemporaneous record, opinion, allegation, legal analysis, or evidence on a file. In some cases, we may add a note recording your disagreement rather than altering the original record.
15. Rights relating to automated decision-making and profiling
We do not make decisions about you that have legal or similarly significant effects based solely on automated processing, unless we tell you otherwise.
16. Data protection complaints
If you are unhappy about how we have used your personal data, please contact us first so that we can investigate and respond to your concerns.
You can make a data protection complaint by contacting our Data Protection Officer or emailing dataprotection@hja.net. We will acknowledge data protection complaints within the statutory 30-day timeframe and respond without undue delay.
You also have the right to complain to the Information Commissioner’s Office. The ICO’s website is Information Commissioner’s Office.
17. Links to other websites
Our website may contain links to other websites. This Privacy Notice does not apply to other websites. If you follow a link to another website, you should read that website’s own privacy notice.
18. Changes to this Privacy Notice
We may update this Privacy Notice from time to time. The latest version will be published on our website.
Where we make significant changes to how we use personal data, we will take appropriate steps to bring those changes to the attention of affected individuals where required.