Legal
Privacy Policy
Last updated: 29 August 2026
Important notice: This Privacy Policy explains how Lloyds PR Solicitors processes personal data submitted through this website. It does not cover personal data processed as part of a legal retainer or client engagement — that is governed by the client care letter and our professional obligations under the SRA Code of Conduct.
1. Who We Are
Lloyds PR Solicitors ("we", "us", "our") is the data controller for personal data collected through this website. We are regulated by the Solicitors Regulation Authority (SRA).
Data controller contact: Lloyds PR Solicitors Email: info@lloydspr.com
2. What Personal Data We Collect
2.1 Contact enquiries
When you submit a contact form on this website, we collect:
- Full name
- Email address
- Telephone number
- Your message and description of your legal matter
- Your preferred office location (if selected)
2.2 Website technical data
Our web server automatically records standard access logs (IP address, browser type, pages visited, time and date). These are used solely for security monitoring and are retained for 30 days. We do not currently use analytics cookies or tracking scripts.
2.3 Cookies
We use a small number of cookies to operate the site. See our Cookie Policy for full details. Non-essential cookies (such as those set by Google Maps on our Contact page) are only set after you give consent via our cookie banner.
3. How We Use Your Data
3.1 Responding to enquiries
We use the information you submit via the contact form to respond to your legal enquiry, assess whether we are able to assist you, and arrange a consultation where appropriate.
3.2 Legal and regulatory obligations
As a regulated law firm, we may be required to retain certain records to comply with our obligations under the Solicitors Regulation Authority (SRA) Standards and Regulations, anti-money laundering legislation, and other applicable law.
4. Legal Basis for Processing
Under UK GDPR Article 6, we rely on the following lawful bases:
- Legitimate interests (Article 6(1)(f)): Processing your contact enquiry to respond to your request. We have assessed that our legitimate interest in responding to potential clients does not override your privacy rights, as you are voluntarily contacting us and have a reasonable expectation that we will respond.
- Legal obligation (Article 6(1)(c)): Where we are required to retain or disclose data by law (e.g. anti-money laundering requirements, court orders).
- Consent (Article 6(1)(a)): For non-essential cookies (analytics, maps) — only where you have given explicit, informed consent via our cookie banner. You may withdraw this consent at any time using the link in the footer.
5. How Long We Keep Your Data
| Data type | Retention period | Reason |
|---|---|---|
| Contact form submissions (non-client) | 3 years from date of submission | Limitation period for potential claims |
| Server access logs | 30 days | Security monitoring only |
| Cookie consent record | 365 days (1 year) | Proof of consent (PECR requirement) |
After the retention period expires, data is securely deleted. We do not sell, rent, or otherwise transfer your personal data to third parties for marketing.
6. Who We Share Data With
We do not sell your personal data. We may share it with:
- Railway.app — our cloud hosting provider, which stores the website database (including contact form submissions) on servers within the EEA. A Data Processing Agreement (DPA) compliant with UK GDPR Article 28 is in place. See Railway's Privacy Policy and Data Processing Addendum.
- Google (Maps) — only when you have consented to the "Maps" cookie category. Google may set cookies and process your IP address when the interactive map loads. See Google's Privacy Policy.
- Legal and regulatory bodies — where we are required to disclose data by law, court order, or regulatory requirement.
7. International Transfers
Our hosting infrastructure (Railway.app) operates primarily within the EEA. Railway's Data Processing Addendum includes Standard Contractual Clauses (SCCs) approved by the European Commission and recognized by the ICO, ensuring adequate safeguards for any data transfers outside the UK or EEA in accordance with UK GDPR Chapter V.
For Google Maps (when you consent), data may be transferred to the United States. Google has implemented appropriate safeguards including SCCs and adherence to the EU-U.S. Data Privacy Framework. See Google's framework commitments.
8. Your Rights
Under UK GDPR, you have the following rights:
- Right of access — to obtain a copy of the personal data we hold about you.
- Right to rectification — to correct inaccurate data.
- Right to erasure — to request deletion of your data where there is no overriding legitimate reason to retain it.
- Right to restriction — to request that we limit processing in certain circumstances.
- Right to data portability — to receive your data in a structured, machine-readable format.
- Right to object — to object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, to withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@lloydspr.com. We will respond within one calendar month.
9. Right to Complain
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first at privacy@lloydspr.com.
10. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction. These include HTTPS encryption, restricted database access, and regular security reviews. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page indicates when the most recent changes were made. We will notify users of material changes by displaying a notice on the website.
12. Contact Us
For any questions about this Privacy Policy or how we handle your personal data:
Email: privacy@lloydspr.com Post: Lloyds PR Solicitors, Data Privacy, [Registered Address]