AES Privacy policy

Purpose of this policy

Archer, Evrard & Sigurdsson LLP (“AES”, “we”, “us” or “our”) takes your privacy very seriously. We are committed to handling and protecting your personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This privacy policy explains how and why we collect, use, store and share your personal data in the course of providing legal services and operating our business.

This policy should be read together with any other privacy notice we may provide to you in specific circumstances. This policy supplements those notices and does not override them.

Data controller

AES is the data controller of your personal data when we act for you or otherwise process your information in the course of our business.

We are responsible for determining the purposes for which and the manner in which your personal data is processed.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this policy.


If you have any questions or wish to exercise your legal rights, please contact:
Archer, Evrard & Sigurdsson LLP
Adam House
10 Adam Street
London WC2N 6AA
Email: dpo@aeslawyers.com

You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO): www.ico.org.uk


What is personal data

Personal data means any information relating to an identified or identifiable individual.

This may include:

We may also process special category data (for example, information relating to health or other sensitive matters) where this is necessary for the provision of legal services or the establishment, exercise or defence of legal claims.

What personal data we collect

In the course of providing legal services, we may collect and process the following categories of personal data:

We may also process any other personal data that you provide to us or which is necessary in connection with your matter.

How we collect your data

We collect personal data from a number of sources, including:

How we use your personal data

We will only use your personal data where permitted by law.

The principal lawful bases we rely on are:

We may also process personal data where necessary for the establishment, exercise or defence of legal claims, including where special category data is involved.

Purposes of processing

We use your personal data for the following purposes:

Where we rely on legitimate interests, we ensure that your rights and interests are not overridden.

Sharing your personal data

We may share your personal data with:

We ensure that all third parties are subject to appropriate confidentiality and data protection obligations.

International transfers

Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including the use of UK-approved standard contractual clauses or transfers to jurisdictions recognised as providing adequate protection.

Data security

We have implemented appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or disclosure.

Access to personal data is limited to those who need it for legitimate business purposes and who are subject to confidentiality obligations.

We have procedures in place to deal with suspected data breaches and will notify you and any applicable regulator where required.

Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to comply with legal, regulatory and professional obligations.

As a general rule, we retain client file data for a minimum of six years following the end of a matter, although longer retention periods may apply depending on the nature of the work or where required for legal or regulatory reasons.

Your legal rights

You have rights under data protection law, including the right to:

These rights may be subject to legal and professional obligations, including duties of confidentiality.

Exercising your rights

We may need to verify your identity before responding to any request.

We aim to respond to all requests within one month, although this may be extended where requests are complex.

Changes to this policy

We may update this policy from time to time. The latest version will always be available on our website.

Contact

If you have any questions about this policy or how we handle your personal data, please contact our Data Protection Officer at: dpo@aeslawyers.com

Archer, Evrard & Sigurdsson LLP
April 2026