Privacy policy
This policy explains what personal data TECHLAWG collects, why, who we share it with, how long we keep it, and what rights you have. We draft these for a living, so we have tried to make ours actually readable.
1. Who is responsible for your data
TECHLAWG is the controller of personal data described in this policy. You can reach us at contact@techlawg.com. Where we act as a processor on behalf of a client, that client is the controller and their privacy notice governs; our processing in that role is set out in the applicable data processing agreement.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Enquiry data | Name, work email, company, website, description of your product, jurisdictions, deadline | You, via forms or email |
| Client data | Billing contact, entity details, engagement correspondence, intake responses, documents you send us | You |
| Transaction data | Invoice records, payment status, payment method reference | You and our payment processor |
| Technical data | IP address, device and browser type, referring URL, pages viewed, approximate location derived from IP | Automatically, via server logs and, with consent, analytics |
| Communications data | Emails, messages, call scheduling records | You |
| Marketing data | Subscription status, engagement with our emails, preferences | You and our email provider |
We do not seek special category data. Please do not send it to us unless we have specifically asked for it in the context of a matter that requires it.
Interactive tools on this site, including the EU AI Act applicability checker, run in your browser. Your answers are not transmitted to us unless you then choose to contact us and include them.
3. Why we use it, and on what basis
| Purpose | Lawful basis (GDPR / UK GDPR) |
|---|---|
| Responding to enquiries and preparing quotes | Steps at your request prior to entering a contract; legitimate interests in responding to business enquiries |
| Delivering our services | Performance of a contract |
| Invoicing, payment and accounting | Performance of a contract; legal obligation |
| Conflicts checking and client onboarding | Legal obligation; legitimate interests in professional compliance |
| Record keeping, tax and regulatory retention | Legal obligation |
| Site security, fraud prevention and abuse detection | Legitimate interests in protecting our systems |
| Analytics and service improvement | Consent |
| Marketing emails to business contacts | Consent, or legitimate interests where permitted for existing clients on similar services |
| Establishing, exercising or defending legal claims | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights. You can ask us for that assessment.
4. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by solely automated means. Our checker tools produce indicative output for your own use and are not used by us to make decisions about you.
5. Who we share it with
We share personal data only where necessary, with:
- hosting and infrastructure providers;
- email, calendaring and document storage providers;
- form handling and CRM providers;
- payment processors and our accountants;
- analytics providers, where you have consented;
- partner counsel, where an engagement requires locally qualified advice and you have been told;
- professional advisers, insurers and auditors;
- authorities, where required by law or to establish or defend legal claims.
We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy law.
A current list of our sub-processors is available on request to contact@techlawg.com.
6. International transfers
We operate internationally and our providers may process data outside your country, including outside the EEA and the UK. Where we transfer personal data from the EEA, UK or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses and, for UK transfers, the UK Addendum or the International Data Transfer Agreement, together with supplementary measures where our transfer assessment indicates they are needed. You can request details of the safeguards applied.
7. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become engagements | 12 months from last contact |
| Client matter files and deliverables | 7 years from conclusion of the matter, or longer where professional or limitation rules require |
| Financial and tax records | As required by applicable tax law, typically 6 to 7 years |
| Marketing contacts | Until you unsubscribe, plus a suppression record thereafter |
| Server logs | Up to 12 months |
| Analytics data | Up to 14 months |
8. Your rights
Depending on where you are, you may have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have data erased, where no overriding obligation requires us to keep it;
- restrict or object to processing, including objecting to processing based on legitimate interests;
- receive data in a portable format and have it transmitted to another controller;
- withdraw consent at any time, without affecting processing already carried out;
- opt out of the sale or sharing of personal data and of targeted advertising, where applicable (we do not do either);
- not be discriminated against for exercising your rights.
To exercise a right, email contact@techlawg.com. We will verify your identity proportionately to the sensitivity of the request and respond within the period required by applicable law, ordinarily one month under GDPR and 45 days under US state law, extendable where permitted.
You may use an authorised agent where the applicable law allows it, subject to us verifying their authority.
If you are in the EEA, UK or Switzerland, you can complain to your supervisory authority. We would ask you to raise it with us first so we have a chance to fix it.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access control on a need-to-know basis, multi-factor authentication on business systems, vendor due diligence, and confidentiality obligations on everyone who handles client material. No system is perfectly secure, and we cannot guarantee absolute security.
Please do not send confidential or privileged material through the website enquiry form. Ask us for a secure channel or an NDA first.
10. Children
Our services are directed at businesses. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
11. Cookies
We use a small number of cookies and similar technologies. Non-essential cookies load only after you consent. See our cookie policy for the detail and for how to change your choice.
12. Changes to this policy
We update this policy when our practices or the law change. The version and effective date are shown at the top. Where a change is material we will take reasonable steps to notify affected individuals.