Table of contents
- 1. Definitions and Interpretation
- 2. Scope of This Policy
- 3. Data Controller Information
- 4. Categories of Personal Data
- 5. How We Collect Personal Data
- 6. Purposes of Processing
- 7. Legal Bases for Processing
- 8. Website Usage Data; No Tracking by Default
- 9. Cookies and Similar Technologies
- 10. Recipients of Personal Data
- 11. International Data Transfers
- 12. Data Retention
- 13. Data Security
- 14. Your Rights
- 15. Automated Decision-Making
- 16. Children's Privacy
- 17. Complaints to a Supervisory Authority
- 18. Changes to This Policy
- 19. Contact Information
This Privacy Policy explains how salamandralab (the "Firm") processes personal data collected in connection with this website (the "Website"). It is written with reference to widely recognized data protection principles, including those reflected in the EU General Data Protection Regulation ("GDPR"), as a matter of good practice. This Policy describes the Firm's intended approach; it is not a representation or certification that the Firm's processing has been independently verified as compliant with the GDPR or any other specific law, and applicable obligations depend on the jurisdictions identified below.
1. Definitions and Interpretation
Capitalized terms used but not defined in this Policy have the meanings given in Section 1 of the Website Terms of Use. In addition, in this Policy:
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
- "Controller" means the entity that determines the purposes and means of Processing.
- "Supervisory Authority" means a public authority responsible for monitoring the application of data protection law.
2. Scope of This Policy
This Policy applies to Personal Data processed through the Website, including Personal Data submitted in an Inquiry. It does not apply to Personal Data the Firm processes in the course of providing Services to a Client under an Engagement Agreement, which is addressed separately in that Engagement Agreement and any related client-specific privacy notice.
3. Data Controller Information
The Controller for Personal Data processed through the Website is: [CONTROLLER LEGAL NAME — PLACEHOLDER], of [REGISTERED OFFICE ADDRESS — PLACEHOLDER], registered in [JURISDICTION OF REGISTRATION — PLACEHOLDER] under registration number [REGISTRATION NUMBER, IF APPLICABLE — PLACEHOLDER]. Where the Firm has appointed a data protection officer or equivalent privacy contact, their details are: [DATA PROTECTION CONTACT — PLACEHOLDER, IF APPLICABLE].
4. Categories of Personal Data
Depending on how you interact with the Website, the Firm may process the following categories of Personal Data:
| Category | Examples |
|---|---|
| Identity and contact data | Name, email address, and any other contact details you choose to include in an Inquiry. |
| Inquiry content | The substance of the message you send, and any details you choose to provide about a prospective matter. |
| Technical data | Limited server-level data generated by any web request, such as approximate access times and error logs, to the extent the hosting environment records them. |
| Special categories or sensitive data | Only if you choose to include such data in an Inquiry; you are asked not to do so before receiving instructions, per Section 10 of the Website Terms of Use. |
5. How We Collect Personal Data
The Firm collects Personal Data that you provide directly, principally through an Inquiry sent by email or through a contact link on the Website. The Website does not, by default, use analytics tools, tracking cookies, or third-party embeds that would collect Personal Data about your browsing behavior. Any technical data generated simply by the operation of standard web server software is described in Section 8.
6. Purposes of Processing
The Firm may process Personal Data collected through the Website for the following purposes: (a) responding to Inquiries and assessing whether the Firm can act on a prospective matter; (b) performing conflict-of-interest checks; (c) client identification and anti-money-laundering procedures where applicable; (d) maintaining records of correspondence; (e) protecting the security and integrity of the Website; and (f) complying with legal obligations, including those described in the Compliance and Law Enforcement Requests Policy.
7. Legal Bases for Processing
Where data protection law requiring a documented legal basis applies, the Firm's Processing of Personal Data collected through the Website may rely on one or more of the following bases, depending on the circumstances: (a) consent, where you have chosen to send an Inquiry; (b) legitimate interests, in responding to Inquiries, protecting the Website, and assessing prospective engagements, balanced against your rights and interests; (c) compliance with a legal obligation, such as client identification, sanctions screening, or responding to lawful requests as described in the Compliance and Law Enforcement Requests Policy; and (d) steps taken at your request prior to entering into an agreement, where an Inquiry is directed toward a possible Engagement Agreement. The specific basis applicable to a given instance of Processing depends on the facts and the governing law, identified at [GOVERNING DATA PROTECTION LAW / JURISDICTION — PLACEHOLDER].
8. Website Usage Data; No Tracking by Default
This Website is built and delivered without analytics services, advertising trackers, social media widgets, or other third-party embeds that would monitor your browsing activity, and no tracking cookies are set by default. Assets such as stylesheets and scripts are self-hosted rather than loaded from third-party content delivery networks, so routine page views do not, by design, share your browsing activity with third parties through this Website. If this approach changes in a future version of the Website — for example, by adding analytics — this Policy will be updated first, and any consent mechanism required by Applicable Law will be implemented before such tools are activated.
The environment hosting the Website may, independently of any code on the Website itself, generate ordinary server or infrastructure logs (such as IP address, request timestamp, and user agent) as a standard incident of operating a web server. The Firm has not catalogued the specific logging behavior of any particular hosting provider in this Policy; if you host this site, describe your hosting provider's logging practices at [HOSTING PROVIDER LOGGING PRACTICES — PLACEHOLDER].
9. Cookies and Similar Technologies
As delivered, this Website does not set analytics or advertising cookies. It may use, at most, a strictly necessary session mechanism if required for basic technical functionality; no such mechanism is active in the base version of this Website. If cookies requiring consent are introduced later, a cookie notice and consent mechanism appropriate to the applicable law will be added, and this section will be updated to describe the categories of cookies used, their purpose, and their duration.
10. Recipients of Personal Data
The Firm may share Personal Data collected through the Website with: personnel of the Firm who need it to respond to your Inquiry or assess a prospective engagement; professional advisers bound by confidentiality obligations, where necessary; service providers who support the Firm's operation of the Website or email systems, acting on the Firm's instructions; and authorities or other parties where required by Applicable Law, as described in the Compliance and Law Enforcement Requests Policy. The Firm has not identified specific third-party processors in this Policy; where a specific vendor (such as an email or hosting provider) is engaged, it should be listed at [LIST OF PROCESSORS / VENDORS — PLACEHOLDER] together with the safeguards applicable to that vendor.
11. International Data Transfers
Personal Data collected through the Website may be processed in a country other than the one from which it was sent, including where the Firm's personnel, email provider, or hosting infrastructure are located outside your country. Where such a transfer involves moving Personal Data out of a jurisdiction that restricts international transfers (such as the European Economic Area), the Firm intends to rely on an appropriate transfer mechanism recognized under the applicable law, such as an adequacy decision or standard contractual clauses. The specific countries involved and the transfer mechanism relied upon have not been finalized in this template and should be completed at [TRANSFER DESTINATIONS AND SAFEGUARDS — PLACEHOLDER].
12. Data Retention
The Firm retains Personal Data collected through the Website only for as long as reasonably necessary for the purposes described in Section 6, taking into account: the need to respond to and document an Inquiry; applicable limitation periods for potential legal claims; conflict-check record-keeping practices; and any specific retention period required by Applicable Law, including professional-conduct or anti-money-laundering rules. The Firm has not fixed specific retention periods in this Policy; they should be set out at [RETENTION PERIODS BY DATA CATEGORY — PLACEHOLDER], consistent with applicable professional and statutory record-keeping requirements.
13. Data Security
The Firm intends to apply technical and organizational measures appropriate to the nature of the Personal Data processed through the Website, such as restricting access to Inquiry correspondence to personnel who need it and using reputable email and hosting infrastructure. No method of transmission or storage is completely secure, and the Firm cannot guarantee absolute security, particularly for information sent by ordinary email before an Engagement Agreement is in place, which is why Section 10 of the Website Terms of Use asks you not to send sensitive information at that stage.
If the Firm becomes aware of a security incident affecting Personal Data collected through the Website that is likely to result in a risk to the individuals concerned, it intends to assess the incident, take reasonable steps to contain it, and provide notification to affected individuals and, where legally required, to a Supervisory Authority, within the timeframe required by Applicable Law. The specific incident-response procedure and notification timetable applicable to the Firm have not been finalized in this Policy and should be completed at [INCIDENT RESPONSE / BREACH NOTIFICATION PROCEDURE — PLACEHOLDER].
14. Your Rights
Subject to the conditions and exceptions under Applicable Law, you may have some or all of the following rights in relation to your Personal Data: to be informed about its Processing; to access a copy of it; to request correction of inaccurate data; to request erasure; to request restriction of Processing; to data portability; to object to Processing based on legitimate interests; and to withdraw consent at any time where Processing is based on consent, without affecting the lawfulness of Processing before withdrawal. To exercise a right, contact the Firm using the details in Section 19. The Firm may need to verify your identity and may decline a request to the extent an exception under Applicable Law applies, including exceptions that protect confidential or privileged information relating to other clients or matters.
15. Automated Decision-Making
The Firm does not use Personal Data collected through the Website to make decisions about you based solely on automated processing, including profiling, that would produce legal or similarly significant effects. Whether to respond to an Inquiry, pursue a conflict check, or accept an engagement is decided by Firm personnel.
16. Children's Privacy
The Website is directed at adults seeking legal services for themselves or an organization. It is not intended for use by children, and the Firm does not knowingly collect Personal Data from children through the Website. If you believe a child has provided Personal Data through the Website, please contact the Firm using the details in Section 19.
17. Complaints to a Supervisory Authority
If you believe the Firm's Processing of your Personal Data does not comply with Applicable Law, you may contact the Firm using the details in Section 19, and, where applicable, you may also have the right to lodge a complaint with a Supervisory Authority. The Supervisory Authority relevant to the Firm has not been finalized in this Policy and should be specified at [SUPERVISORY AUTHORITY NAME AND CONTACT DETAILS — PLACEHOLDER].
18. Changes to This Policy
The Firm may update this Policy from time to time to reflect changes in its practices or Applicable Law. The effective date at the top of this page reflects the date of the most recent update. Material changes affecting how Personal Data is processed will be reflected by updating that date, and, where required by Applicable Law, through additional notice.
19. Contact Information
Questions about this Policy, or requests to exercise a privacy right, may be sent to contact@salamandralab.example.