Skip to content
£50 off with code HARBOUR50. See your price

Legal

Privacy Policy

LegalLast updated

01 Introduction

This policy explains what happens to the personal data you give through this website (safeharbour.legal): what is collected, where it goes, how long it is kept, and the rights you have over it. It is written to match what the website actually does.

Safe Harbour Legal is a trading name of Legal Studio Solicitors, itself a trading name of MDLS Solicitors Limited, which is authorised and regulated by the Solicitors Regulation Authority (SRA ID 598793). Aaron Johnson practises through it as a consultant solicitor. Check the register: SRA ID 598793. MDLS Solicitors Limited is registered in England and Wales (Company No. 08599445). In this policy "the firm" means MDLS Solicitors Limited.

This policy is issued under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

02 Data controller

For personal data collected through this website, the data controller is:

MDLS Solicitors Limited

Trading as
Legal Studio Solicitors / Safe Harbour Legal
Registered office of MDLS Solicitors Limited
The Tannery, 91 Kirkstall Road, Leeds, LS3 1HS, United Kingdom
ICO
Registration ZA057790

Aaron Johnson handles the data this website collects day to day. For any question about it, contact him:

Aaron Johnson, Safe Harbour Legal

Subject
Please put "Data Protection" in the subject line.

For client data processed in a legal matter, contact the firm's Data Protection Officer:

Matthew Dowell, Data Protection Officer

Phone
0113 247 3800

03 How your data is collected

Personal data reaches Aaron in the following ways:

  • Forms and questionnaires: the contact and call request forms, the guide request form, and the online questionnaires (wills, Lasting Powers of Attorney, probate, trusts and general enquiry). Your answers, and any documents or ID scans you upload, are sent as an email, with the files attached, through Resend to the firm's Microsoft 365 mailboxes. They are not stored on the website itself.
  • Call bookings: when you book a call at /book, your name, email address, phone number, any notes, the plan you chose, the wording of the consent you gave and a hashed (one-way scrambled) version of your IP address are stored in Netlify Blobs so the booking can be confirmed and managed. The record is deleted automatically 90 days after the date of the call.
  • A questionnaire you start but do not finish: only if you tick the box allowing it, the site sends Aaron one message with your name, email address, phone number and the step you reached, so he can offer to help. If you do not tick the box, nothing is sent.
  • The Plan Finder: records anonymous counts only. No personal data and no cookies. See Section 12.
  • WhatsApp: the WhatsApp link opens WhatsApp on your own device. Anything you send there is handled by WhatsApp under Meta's terms and privacy policy, not by this website.
  • Lead recovery store: if the email carrying an enquiry fails to deliver, a copy of the enquiry is kept for 90 days so it is not lost, then deleted.
  • Phone and email: when you call or email Aaron
  • The client portal (LawConnect): when you share documents with Aaron during a matter
  • Home visits and calls: when you meet or speak with Aaron about your matter
  • Public sources: where needed for your matter (for example the Land Registry, the probate registry or Companies House)

04 The information collected

The categories of personal information are:

  • Contact information: name, email address, phone number, postal address
  • Legal matter information: details of your enquiry, family circumstances, beneficiaries, executors, attorneys and related people
  • Identity verification documents: passport, driving licence, utility bills and bank statements, collected for anti-money laundering compliance by electronic verification (eCos), by certified copies, or as scans uploaded to a questionnaire
  • Financial information: asset values, property details and estate information where relevant to your matter
  • Booking data: the time you booked, any notes, the plan you chose, the consent wording and a hashed IP address
  • Technical data: Netlify's function logs record each request, including the IP address it came from, for up to 7 days. The site writes no personal data to those logs.
  • Marketing preferences: your consent status for the newsletter
  • Consent records: the text you consented to, the date and time, and how it was collected, kept for audit

06 How your information is used

Aaron uses your personal information to:

  • Answer your enquiry and provide legal services
  • Confirm, manage and remind you of a call you have booked
  • Offer help with a questionnaire you started, where you asked for that
  • Carry out conflict of interest checks
  • Verify your identity under anti-money laundering legislation
  • Comply with legal, regulatory and professional obligations, including the SRA's
  • Share documents with you through the client portal
  • Send invoices and process payments
  • Send you legal updates and information about the services, with your consent
  • Understand how the website is used, from anonymous counts only

07 Newsletter and mailing list

If you subscribe to the newsletter through this website, your email address is collected and your explicit consent is recorded (the consent text and a timestamp) for audit.

Subscriber data is managed through MailerLite (UAB MailerLite, registered in Lithuania, EU). MailerLite stores data on servers within the European Union and operates under GDPR. A Data Processing Agreement is in place with MailerLite.

  • Only people who sign up through this website are added to the mailing list.
  • No client data from the firm's case management systems is added to MailerLite.
  • Newsletter data is kept entirely separate from the legal case management systems.
  • Every email carries an unsubscribe link. You can also unsubscribe by contacting Aaron directly.
  • When you unsubscribe, your data is removed from the active mailing list within 30 days.

Marketing emails go only to people who have given explicit opt-in consent, as the Privacy and Electronic Communications Regulations 2003 (PECR) require.

08 Data processors and third-party sharing

Your personal data is shared only where necessary to provide the services or to comply with the law. The following processors handle data on the firm's behalf:

ProcessorPurposeWhere the data is heldSafeguard
Microsoft 365The firm's mailboxes, where every form, questionnaire and booking email arrives, with any documents and ID scans attached.United Kingdom and European Union (Microsoft regional data centres)Microsoft's data protection terms
ResendSends the emails this website generates: form and questionnaire submissions, with their attachments, booking confirmations and reminders. A copy of each sent email is held in the Resend dashboard for up to 30 days.United StatesStandard Contractual Clauses and the UK Addendum in Resend's data processing agreement
NetlifyHosts the website and runs its functions. Holds call bookings (name, email, phone, notes, the plan, the consent wording and a hashed IP address) and the lead recovery store in Netlify Blobs. Function logs are kept for up to 7 days; the site writes no personal data to them.United StatesStandard Contractual Clauses in Netlify's data processing agreement
MailerLiteEmail marketing for newsletter subscribers only, with an unsubscribe link in every email. See Section 7.European Union (Lithuania)Data Processing Agreement; the UK treats the EU as adequate
LEAP Legal SoftwareCase management, client records and matter files once you become a client.United KingdomData Processing Agreement
LawConnect (LEAP)The client portal used to share documents with you during a matter.United KingdomData Processing Agreement

Sanity holds the website's content and processes no personal data. Google Fonts are self-hosted through the website framework (Next.js): no request goes to Google and no personal data is transferred to Google.

Your information may also be disclosed to regulatory bodies (including the SRA, HMRC and the courts) where the law requires it or your matter needs it (for example HM Courts and Tribunals Service, the Office of the Public Guardian, or the Land Registry).

Your personal information is never sold, rented or traded.

09 International data transfers

Two processors hold data in the United States: Resend, which sends the emails this website generates and keeps a copy of each for up to 30 days, and Netlify, which hosts the website and holds call bookings, the lead recovery store and the function logs. Both transfers are covered by Standard Contractual Clauses, with the UK Addendum where it applies, in each processor's data processing agreement.

MailerLite holds newsletter data in the European Union, which the United Kingdom treats as providing adequate protection. LEAP, LawConnect and the firm's Microsoft 365 mailboxes hold data in the United Kingdom and the European Union. Google Fonts are self-hosted, so nothing goes to Google.

10 Data retention

Personal information is kept only as long as needed for the purpose it was collected for, or as the law requires. The retention periods are:

Data typeRetention period
General enquiries by form, phone or email (no engagement)12 months, then securely deleted
Call bookings made through this website90 days after the date of the call, then deleted automatically
Copy of an enquiry kept when email delivery fails (lead recovery store)90 days, then deleted
Copy of a sent form email in the Resend dashboardup to 30 days
Netlify function logsUp to 7 days
Newsletter subscribersUntil unsubscribe, plus 30 days for removal
Client matter files: wills and trusts15 years from completion of the matter
Client matter files: probate12 years from completion of the matter
Client matter files: Lasting Powers of Attorney6 years from completion of the matter
AML / identity verification records5 years from end of relationship (MLR 2017)
Financial records and invoices7 years (HMRC requirement)
Complaints records6 years from resolution
Consent recordsDuration of processing, plus 6 years

After the retention period, data is securely destroyed. Original documents (such as a signed will) are returned to you or stored as separately agreed.

11 Data security

Appropriate technical and organisational measures protect your personal information against unauthorised access, alteration, disclosure or destruction. They include:

  • Encrypted transmission (HTTPS/TLS) across the website and every email it sends
  • The client portal (LawConnect), an encrypted route for sensitive documents during a matter, which Aaron recommends over email attachments once your matter is open
  • Access limited to Aaron and to the people at the firm who need it for your matter or for its regulatory duties
  • Password protection and multi-factor authentication on every system holding personal data
  • Automatic deletion of call bookings and lead recovery copies at the end of their retention periods
  • Regular review of the security measures, and Aaron keeps his own data protection training current
  • Secure destruction of paper records when no longer required
  • Compliance with the SRA's requirements for information security

12 Cookies and browser storage

This website sets no cookies. There are no marketing, advertising or analytics cookies, no third-party tracking pixels (no Meta Pixel, no Google Analytics, nothing similar), and no cookie-consent banner, because there is nothing to consent to.

12.1 What the browser stores instead

A few small settings are kept in your own browser's storage, on your device. They are never sent to the website or to anyone else, and none of them identifies you:

  • Local storage: your text-size and contrast preference, and a promotion code you have applied or dismissed
  • Session storage: the unsent draft of a questionnaire you are part-way through, so a page refresh does not lose it; a one-off flag so the questionnaire follow-up in Section 3 is sent at most once; and a mark that a Plan Finder view has already been counted. All of it is cleared when you close the tab.

You can clear either at any time from your browser settings. Doing so does not stop you using the website; it only resets those preferences.

12.2 The SRA badge

The regulator's "Check this firm" badge at the foot of every page is delivered in an iframe from yoshki.com on behalf of the Solicitors Regulation Authority. It is there so you can check the firm's regulation. This website reads nothing from it and sets nothing through it.

12.3 Consent tick boxes

The tick boxes on the forms and questionnaires are not cookies. They record your permission for Aaron to handle your enquiry, to follow up a questionnaire you did not finish, or to send you the newsletter, and are covered elsewhere in this policy.

12.4 Counting how the Plan Finder is used

When the Plan Finder shows you a plan, the site records that a plan was shown and which kind (for example a standard will, powers of attorney or probate), with its fee band and any promotion code applied. This uses no cookie and no personal data: no name, no email address, no IP address and no browser fingerprint, and nothing that could link one visit to another. The counts show how the Plan Finder is used so it can be improved. If your browser sends a Do Not Track signal, nothing is recorded at all.

13 Your rights under UK GDPR

Under the UK GDPR and the Data Protection Act 2018 you have the following rights:

  • Right of access (subject access request): you can ask for a copy of the personal data held about you.
  • Right to rectification: you can ask for inaccurate or incomplete data to be corrected.
  • Right to erasure ("right to be forgotten"): you can ask for your data to be deleted, subject to the legal obligations to keep certain records (see Section 10).
  • Right to restrict processing: you can ask for the use of your data to be limited in certain circumstances.
  • Right to data portability: you can ask for your data in a structured, commonly used, machine-readable format.
  • Right to object: you can object to processing based on legitimate interests, or to direct marketing, at any time.
  • Right to withdraw consent: where processing is based on consent (the newsletter, or the questionnaire follow-up), you can withdraw it at any time. Withdrawal does not affect processing carried out before it. For the newsletter, use the unsubscribe link in any email or contact Aaron.
  • Rights related to automated decision-making: see Section 14.
  • Right to complain: from 19 June 2026 you have a statutory right to complain to the firm directly about how your personal data is handled, as well as to the Information Commissioner's Office (see Section 17).

To exercise any of these rights, email Aaron at aaron@safeharbour.legal or write to the firm at the registered office in Section 2. You receive a response within one month of the request. In most cases there is no fee. If a request is manifestly unfounded or excessive, a reasonable fee may be charged or the request refused, with the reason explained.

14 Automated decision-making

No automated decision-making or profiling, as defined in Article 22 of the UK GDPR, is used. The Plan Finder on this website suggests a plan from the answers you give, but it decides nothing about you: every decision affecting your legal matter is made by Aaron, a solicitor.

15 Children's data

The services are not directed at people under 18, and personal data is not knowingly collected from children. Where information about a child is processed in a client's matter (for example naming guardians in a will), that is done on the instructing client's consent and in the child's best interests.

If you believe personal data has been collected from a child without appropriate consent, contact Aaron straight away.

16 Electronic communications (PECR)

Electronic marketing complies with the Privacy and Electronic Communications Regulations 2003 (PECR):

  • Marketing emails go only to people who have given explicit opt-in consent
  • Every marketing email includes a working unsubscribe link
  • No unsolicited marketing calls
  • No unsolicited marketing text or WhatsApp messages
  • Every unsubscribe request is honoured promptly

17 Complaints about data handling

If you are unhappy with how your personal data has been handled, you can complain to the firm directly. From 19 June 2026 you have a statutory right to do so. Email aaron@safeharbour.legal (marking it "Data Protection Complaint"), or write to the data controller at the registered office in Section 2. Your complaint is acknowledged within 30 days and answered without undue delay.

This is in addition to, and does not affect, your right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Phone
0303 123 1113
Address
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

18 Contact

For questions about this policy, or to exercise your data protection rights, contact Aaron:

19 Changes to this policy

This policy is updated when the website or the law changes. Material changes are posted on this page with a new "Last updated" date, and where a change materially affects people whose data is held, they are told directly.

20 Governing legislation

This policy is governed by the laws of England and Wales. The main legislation governing the processing is:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations 2003 (PECR)
  • Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
  • Solicitors Regulation Authority Standards and Regulations

Ends