AES Privacy policy
Purpose of this policy
Archer, Evrard & Sigurdsson LLP (“AES”, “we”, “us” or “our”) takes your privacy very seriously. We are committed to handling and protecting your personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This privacy policy explains how and why we collect, use, store and share your personal data in the course of providing legal services and operating our business.
This policy should be read together with any other privacy notice we may provide to you in specific circumstances. This policy supplements those notices and does not override them.
Data controller
AES is the data controller of your personal data when we act for you or otherwise process your information in the course of our business.
We are responsible for determining the purposes for which and the manner in which your personal data is processed.
Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this policy.
If you have any questions or wish to exercise your legal rights, please contact:
Archer, Evrard & Sigurdsson LLP
Adam House
10 Adam Street
London WC2N 6AA
Email: dpo@aeslawyers.com
You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO): www.ico.org.uk
What is personal data
Personal data means any information relating to an identified or identifiable individual.
This may include:
- identity information (such as name and date of birth)
- contact details
- financial information
- information relating to legal matters
We may also process special category data (for example, information relating to health or other sensitive matters) where this is necessary for the provision of legal services or the establishment, exercise or defence of legal claims.
What personal data we collect
In the course of providing legal services, we may collect and process the following categories of personal data:
- Identity data: name, date of birth and identification documents (passport, driving licence, etc.)
- Contact data: address, email address and telephone numbers
- Financial data: bank details, source of funds and transaction information
- Client and matter data: information relevant to the legal matter on which we are instructed
- Family or personal data: where relevant to a matter (for example, wills or disputes)
- Regulatory data: information required for anti-money laundering and compliance checks
- Technical data: IP address, browser type and usage data when accessing our website
- Marketing and communications data: preferences in receiving communications from us
We may also process any other personal data that you provide to us or which is necessary in connection with your matter.
How we collect your data
We collect personal data from a number of sources, including:
- directly from you (by email, telephone, meetings or correspondence)
- from publicly available sources (such as Companies House, HM Land Registry or court records)
- from third parties involved in your matter (such as other advisers, counterparties or experts)
- from compliance and due diligence providers (including AML and sanctions screening providers)
- through our IT systems and case management systems
- via our website and analytics providers
How we use your personal data
We will only use your personal data where permitted by law.
The principal lawful bases we rely on are:
- performance of a contract (providing legal services to you)
- compliance with legal obligations (including regulatory and anti-money laundering requirements)
- legitimate interests (for the operation and management of our business)
We may also process personal data where necessary for the establishment, exercise or defence of legal claims, including where special category data is involved.
Purposes of processing
We use your personal data for the following purposes:
- to provide legal advice and representation
- to take steps prior to entering into a client engagement
- to carry out client onboarding and compliance checks (including AML)
- to manage our relationship with you
- to administer and protect our business and systems
- to comply with legal, regulatory and professional obligations
- to communicate with you, including responding to enquiries
- to send you legal updates or marketing communications where permitted
Where we rely on legitimate interests, we ensure that your rights and interests are not overridden.
Sharing your personal data
We may share your personal data with:
- barristers, experts and other professional advisers instructed in your matter
- courts, tribunals, regulators and public authorities
- counterparties and their advisers where necessary
- banks and payment providers
- IT and case management providers (including Leap)
- auditors and professional advisers
- service providers supporting our business operations
We ensure that all third parties are subject to appropriate confidentiality and data protection obligations.
International transfers
Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including the use of UK-approved standard contractual clauses or transfers to jurisdictions recognised as providing adequate protection.
Data security
We have implemented appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or disclosure.
Access to personal data is limited to those who need it for legitimate business purposes and who are subject to confidentiality obligations.
We have procedures in place to deal with suspected data breaches and will notify you and any applicable regulator where required.
Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to comply with legal, regulatory and professional obligations.
As a general rule, we retain client file data for a minimum of six years following the end of a matter, although longer retention periods may apply depending on the nature of the work or where required for legal or regulatory reasons.
Your legal rights
You have rights under data protection law, including the right to:
- request access to your personal data
- request correction of inaccurate data
- request erasure of your data (in certain circumstances)
- object to processing
- request restriction of processing
- request transfer of your data
- withdraw consent where applicable
These rights may be subject to legal and professional obligations, including duties of confidentiality.
Exercising your rights
We may need to verify your identity before responding to any request.
We aim to respond to all requests within one month, although this may be extended where requests are complex.
Changes to this policy
We may update this policy from time to time. The latest version will always be available on our website.
Contact
If you have any questions about this policy or how we handle your personal data, please contact our Data Protection Officer at: dpo@aeslawyers.com
Archer, Evrard & Sigurdsson LLP
April 2026
