/ Privacy Notice

Your data, handled with care.

What is this notice?

We take your privacy very seriously. Please read this Privacy Notice carefully as it contains important information on who we are and how and why we collect, store, use and share your personal data. It also explains your rights in relation to your personal data and how to contact us or supervisory authorities in the event you have a complaint.

This Privacy Notice applies to you if you provide your personal data to us, even if you decide not to go ahead with any product or service that we offer, and does not apply to any third-party websites that may have links to our own website.

When you use our services or contact us, you trust us with your personal data. We collect, store and process this data about you to help us deliver the best possible legal service. When we do so we are subject to the UK General Data Protection Regulation (UK GDPR).

It is important that you read this Privacy Notice together with any other detailed privacy notices we may provide when we are collecting or processing personal data about you, so that you understand our privacy practices in relation to your data.

Who are we?

Data is collected, processed and stored by Justizia Ltd, trading as "Justizia Law". Justizia Ltd is a limited company, incorporated in England and Wales, authorised and regulated by the Solicitors Regulation Authority under number 656089. Unless we notify you otherwise, we are the controller for your personal data.

We are what is known as the "Data Controller" of the personal information you provide to us. A controller is a person or organisation who alone or jointly determines the purposes for which, and the manner in which, any personal data is, or is likely to be, processed. We handle and store your personal information in accordance with the law, including the UK GDPR and the Data Protection Act 2018.

Justizia Ltd is registered with the UK Information Commissioner's Office (ICO) under registration number ZA527169.

The Data (Use and Access) Act 2025 will, in due course, transfer the ICO's functions to a new body, the Information Commission; until that transition is complete, the ICO remains our supervisory authority under its current name.

Key terms

  • We, us, our — Justizia Ltd, Justizia Law, Justizia and our group companies and trading styles.
  • Personal data — any information relating to an identified or identifiable individual.
  • Special category personal data — personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; genetic data; biometric data (where used for identification purposes); and data concerning health, sex life or sexual orientation.
  • Data subject — the individual who the personal data relates to.

What personal data do we collect from you?

We will only collect information from you that is relevant to the matter we are dealing with, which shall depend on what you have asked us to do or what we are contracted to do for you. There are two types of personal data that you may provide to us: general personal data (such as your name, address, gender, date of birth, contact details and financial information) and sensitive (special category) personal data, to which additional protections apply.

  • Aggregated Data such as statistical or demographic data. This is not personal data at law unless combined with your personal data so that it can identify you.
  • Background Verification Data including your passport number, driver licence number, photographic identification or other details requested as part of our onboarding process to comply with due diligence obligations, anti-money laundering laws and ongoing monitoring commitments.
  • Contact Data including billing address, delivery address, email address and telephone numbers.
  • Financial Data including bank account and payment card details.
  • Identity Data including first name, middle name, maiden name, last name, title, date of birth, gender, job title and photographic identification.
  • Marketing and Communications Data including your preferences in receiving marketing from us, our third parties and partners.
  • Professional Information including, where you work with us or apply for a role, your professional history and experience.
  • Profile Data including your username and password for our portal, legal services you have requested, information shared with our social media platforms, your interests, preferences, feedback and survey responses.
  • Special Categories of Personal Data which we may collect or come across during background verification, when reviewing a CV, or when providing legal services to you.
  • Transaction Data including details about payments to and from us and other details of products and services purchased.
  • Technical and Usage Data including IP address, portal login data, browser session and geo-location data, device and network information, page views and sessions, acquisition sources, search queries, browsing behaviour and cookie data.

How we collect personal data

  • Directly — when you fill in forms on our website, sign up to our services, request legal services, subscribe to our marketing publications, or request assistance by email, online chat or telephone.
  • Indirectly — while interacting with us, such as when you use our website or portal, in emails, over the telephone and in your online enquiries.
  • From third parties — such as background check providers engaged for anti-money laundering and due diligence purposes, recruitment businesses, and our analytics, cookie and marketing providers.
  • From publicly available sources — such as Companies House and social and professional networking sites.

Our lawful bases for using your data

Under data protection law, we can only use your personal data if we have a proper reason, e.g.:

  • Where you have given consent;
  • To comply with our legal and regulatory obligations;
  • For the performance of a contract with you, or to take steps at your request before entering into a contract; or
  • For our legitimate interests or those of a third party.

Legitimate interests

A legitimate interest is when we have a business or commercial reason to use your personal data, so long as this is not overridden by your own rights and interests. We carry out an assessment when relying on legitimate interests, to balance our interests against your own. You have the right to object to processing based on legitimate interests. We must then stop the processing unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is required to establish, exercise or defend legal claims.

The Data (Use and Access) Act 2025 has also introduced a small number of "recognised legitimate interests" — including crime prevention and safeguarding — for which this balancing exercise is not required by law. Where we rely on a recognised legitimate interest, we will identify this specifically; otherwise, we continue to carry out a full legitimate interests assessment as described above.

The primary reason for asking you or others to provide us with your personal information is to provide legal services to you so we may perform our contract. Other examples of what we may use your information for include: verifying your identity and source of funds; liaising with you; obtaining insurance policies on your behalf, including After the Event Legal Expenses Insurance; progressing your file; seeking advice from legal and non-legal experts; responding to a complaint or allegation of negligence; retaining financial records; and where it is necessary for reasons of substantial public interest.

Collection and use of personal data

We may collect, hold, use and transfer personal data for purposes including:

  • To contact and communicate with you, and to provide legal services including onboarding, advising and acting on behalf of clients;
  • To run conflict checks for actual and potential clients and counterparties;
  • Statistical analysis to help us manage our business, direct marketing, and measuring the effectiveness of promotional campaigns;
  • Ensuring the confidentiality of commercially sensitive information and network and information systems security;
  • Administering accounts, processing payments, internal record keeping and administration;
  • Prevention and detection of fraud, credit reference checks (where appropriate) and identity checks;
  • Enforcing legal rights, defending or taking legal proceedings, and responding to audits, enquiries or investigations by governmental or regulatory bodies;
  • Operational reasons such as improving efficiency, training and quality control, and provision of education and training;
  • Enabling you to access and use our website, portal and associated platforms, and managing your participation in our events;
  • Considering your application to work with us and conducting pre-employment reference checks;
  • Sharing data with members of our group, partner companies and third parties in connection with a significant corporate transaction or restructuring, including a merger, acquisition, asset sale or insolvency. In such cases information will be anonymised where possible and only shared where necessary.

Use of Artificial Intelligence (AI) and automated tools

At Justizia Law, we use artificial intelligence ("AI") technologies to enhance our efficiency, client communication and case management. These systems are designed to assist our staff, not to replace qualified human judgment, and operate strictly under legal and regulatory supervision.

1. Purpose of AI use

We use a number of AI tools as part of our operations, including Pente.AI ("Pente Talk"), ChatGPT, Claude and Lovable. Depending on the tool, this may include using AI to:

  • Facilitate initial client enquiries and intake;
  • Manage communication, reminders and updates;
  • Support internal document automation and workflow efficiency; and
  • Analyse anonymised or aggregated data to improve our services.

2. Human oversight

AI tools do not provide legal advice or make independent decisions about cases. All legal matters and outputs are reviewed, approved and controlled by qualified members of our legal team.

3. Data handling and safeguards

Information processed by AI systems is treated with the same level of confidentiality as all other client data and is subject to:

  • Secure hosting and encryption standards;
  • Access controls and audit logs;
  • Strict contractual obligations with technology partners;
  • Anonymisation where data is used for service improvement.

4. Your rights and options

  • Request to interact solely with a human representative;
  • Object to the use of AI in your case;
  • Request details of any automated processing relating to your data; and
  • Withdraw consent for AI-based communications at any time.

5. Oversight

Our Compliance team regularly audit AI use to ensure fairness, transparency and compliance with the UK GDPR and SRA standards.

Our disclosures of personal data to third parties

Usually, we will only use your information within Justizia Law. However, there may be circumstances, in carrying out your legal work, where we need to disclose some information to third parties, for example:

  • Companies within the Justizia Ltd group, our employees, contractors and partner companies connected with the work we do for you;
  • Anyone to whom our business or assets (or any part of them) are, or may in good faith be, transferred;
  • Solicitors acting on the other side, barristers or Counsel, and non-legal experts;
  • Providers of identity verification, translation agencies, contracted suppliers and outsourcing companies;
  • External auditors and our regulators, i.e. the Solicitors Regulation Authority and the Information Commissioner's Office;
  • Payment service companies, banks, building societies and other financial institutions;
  • The Financial Ombudsman Service, Financial Services Compensation Scheme, Pension Ombudsman Service or any other Ombudsman;
  • Communication providers (e.g. text and live chat services) and third-party funders;
  • Insurance companies, e.g. for the purposes of acquiring After the Event Insurance;
  • Client feedback review platforms, including Trustpilot;
  • Marketing and advertising providers and partner companies such as Google, Facebook and LinkedIn, and PR and marketing agencies;
  • IT service providers, data storage, web hosting, CRM software and server providers such as HubSpot or Amazon Web Services;
  • Any third parties who may have introduced you to our services and require updates as to the progression of your matter;
  • Other third parties where we have your consent, or where required under a legal or regulatory obligation such as the prevention of financial crime or terrorism; and the emergency services if we think you or others are at risk.

We only allow those organisations to handle your personal data if we are satisfied they take appropriate measures to protect it. We ensure all outsourcing providers operate under service agreements consistent with our legal and professional obligations, including in relation to confidentiality.

Overseas transfers

Where we disclose personal data to our partner companies and third parties, these companies may store, transfer or access personal data outside of the United Kingdom, where the level of data protection may be less comprehensive than in the UK. Where we transfer your personal data outside of the UK, we will perform those transfers using appropriate safeguards in accordance with applicable data protection laws — on the basis of a UK adequacy regulation under Article 45 of the UK GDPR, standard data protection clauses recognised or issued under Article 46(2), or where a specific exception applies.

How long will we keep your information for?

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation. Following the end of the relevant retention period, we will delete or anonymise your personal data.

How we will keep your personal data secure

We have appropriate security measures to prevent personal data from being accidentally lost or used or accessed unlawfully. We limit access to your personal data to those who have a genuine business need to access it, and those processing your data do so only in an authorised manner and are subject to a duty of confidentiality. We also have procedures to deal with any suspected data security breach, and will notify you and any applicable regulator where legally required to do so.

For detailed information on protecting yourself online, visit getsafeonline.org, supported by HM Government and leading businesses.

Your rights and controlling your personal data

Access, correction, processing and portability

You may request details of the personal data that we hold about you and how we process it (commonly known as a "data subject request"). We will respond based on what is a reasonable and proportionate search in the circumstances, and the time we have to respond may be paused while we wait for you to verify your identity or clarify your request. You may also have the right to have your personal data rectified or deleted, to restrict our processing, to stop unauthorised transfers to a third party and, in some circumstances, to have data transferred to you or another organisation. Where a significant decision about you is based solely on automated processing of special category data, you have the right to be given information about that decision, to make representations, to obtain human intervention and to contest the decision; other significant automated decisions are subject to similar safeguards under the Data (Use and Access) Act 2025.

Information from third parties

In some situations we may receive personal data about an individual from a third party. If you are a third party providing personal data about somebody else, you represent and warrant that you have that person's consent, or are otherwise permitted by applicable data protection laws to share it with us.

Unsubscribe

To unsubscribe from our email database or opt out of communications (including marketing), please contact us or use the opt-out facilities provided in the communication. If you unsubscribe, please note that we retain your data for a period of six years unless we receive a specific request to erase it.

Withdraw consent

Where we are relying on consent, you have the right to withdraw it at any time. This will not affect the lawfulness of processing carried out before withdrawal. If you withdraw your consent, we may not be able to provide certain products or services to you, and we will advise you if this is the case.

Updating your details

If any of the information you have provided to us changes — for example your name or email address — please let us know.

Marketing

We will use your personal data to send you updates (by email, text message, telephone or post) about our services, including exclusive offers, promotions or new services. We may collect personal data when you sign up to a newsletter, submit an online enquiry, follow or subscribe to our social media channels, complete a questionnaire on our website, contact us with a query, post to our channels, or leave a review on Trustpilot.

Prospects

Consent will need to be recorded before being added to marketing campaigns.

Retainer clients

We have a legitimate interest in using your personal data for marketing purposes, so we do not usually need your consent to send you marketing information. You will be given the opportunity to opt in, and you can exclude yourself at any time by clicking the unsubscribe link on any marketing email, telling an adviser on the telephone, or contacting us. We have a legal obligation under the Data Protection Act 2018 and the UK GDPR to stop sending marketing communications if you object.

Fixed fee clients

Legitimate interest will be the legal basis for using your personal data for marketing purposes, as described in the "Retainer clients" section above.

Social media and other advertising

We use publicly available social media platforms to promote our services and share news and updates, and we may collect personal information from these platforms — for example if you post a message on our page. Those pages are publicly available, so please do not post personal or sensitive information there. Each platform processes information in accordance with its own privacy notice.

Google may show our advertisements on other third-party websites you visit for remarketing purposes, including cross-device remarketing, using cookies to tailor advertisements based on your previous visit to our website. We do not control the advertisements you see on third-party websites, but you can opt out or customise these using the Google Ads Preference Manager.

Recording calls

We may from time to time record calls that you make to us, or we make to you or any third party, for training, monitoring and quality purposes. Some calls may be observed by staff for training and development purposes.

Storage and security

We are committed to ensuring that the personal data we collect is secure. To prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures, including encryption, to safeguard personal data and protect it from misuse, interference, loss and unauthorised access, modification and disclosure.

Cookies

We may use cookies on our website and portal from time to time. Cookies are text files placed in your browser to store your preferences. You can find out more about the types of cookies we use in our Cookie Policy.

Our partners and links to other websites

Our website may contain links to our partner websites and to other websites. These have their own privacy notices and we do not accept responsibility or liability for them, nor for the protection and privacy of any personal data you provide while visiting them. Please check those policies before submitting any personal data.

Who can you complain to?

If you are unhappy about how we are using your information or how we have responded to your request, please contact us in the first instance. You also have the right to make a formal data protection complaint directly to us, and details of how to do this are set out in our Complaints Procedure.

You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk/make-a-complaint or by telephone on 0303 123 1113.

Amendments

We may change this Privacy Notice from time to time and without further notice to you, to reflect changes in our information practices or relevant laws. We will post a notice on our website to notify you of any significant changes, and will indicate at the bottom of the Privacy Notice when it was last updated.

How to contact us

If you have any queries about this policy, please contact us using our contact form or the details available on this website.

Last update · 22 July 2026