Legal
Privacy Policy
LegalLast updated
01 Introduction
This policy explains what happens to the personal data you give through this website (safeharbour.legal): what is collected, where it goes, how long it is kept, and the rights you have over it. It is written to match what the website actually does.
Safe Harbour Legal is a trading name of Legal Studio Solicitors, itself a trading name of MDLS Solicitors Limited, which is authorised and regulated by the Solicitors Regulation Authority (SRA ID 598793). Aaron Johnson practises through it as a consultant solicitor. Check the register: SRA ID 598793. MDLS Solicitors Limited is registered in England and Wales (Company No. 08599445). In this policy "the firm" means MDLS Solicitors Limited.
This policy is issued under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
02 Data controller
For personal data collected through this website, the data controller is:
MDLS Solicitors Limited
- Trading as
- Legal Studio Solicitors / Safe Harbour Legal
- Registered office of MDLS Solicitors Limited
- The Tannery, 91 Kirkstall Road, Leeds, LS3 1HS, United Kingdom
- ICO
- Registration ZA057790
Aaron Johnson handles the data this website collects day to day. For any question about it, contact him:
Aaron Johnson, Safe Harbour Legal
- Phone
- 01262 310 850
- Subject
- Please put "Data Protection" in the subject line.
For client data processed in a legal matter, contact the firm's Data Protection Officer:
Matthew Dowell, Data Protection Officer
- md@legalstudio.co.uk
- Phone
- 0113 247 3800
03 How your data is collected
Personal data reaches Aaron in the following ways:
- Forms and questionnaires: the contact and call request forms, the guide request form, and the online questionnaires (wills, Lasting Powers of Attorney, probate, trusts and general enquiry). Your answers, and any documents or ID scans you upload, are sent as an email, with the files attached, through Resend to the firm's Microsoft 365 mailboxes. They are not stored on the website itself.
- Call bookings: when you book a call at /book, your name, email address, phone number, any notes, the plan you chose, the wording of the consent you gave and a hashed (one-way scrambled) version of your IP address are stored in Netlify Blobs so the booking can be confirmed and managed. The record is deleted automatically 90 days after the date of the call.
- A questionnaire you start but do not finish: only if you tick the box allowing it, the site sends Aaron one message with your name, email address, phone number and the step you reached, so he can offer to help. If you do not tick the box, nothing is sent.
- The Plan Finder: records anonymous counts only. No personal data and no cookies. See Section 12.
- WhatsApp: the WhatsApp link opens WhatsApp on your own device. Anything you send there is handled by WhatsApp under Meta's terms and privacy policy, not by this website.
- Lead recovery store: if the email carrying an enquiry fails to deliver, a copy of the enquiry is kept for 90 days so it is not lost, then deleted.
- Phone and email: when you call or email Aaron
- The client portal (LawConnect): when you share documents with Aaron during a matter
- Home visits and calls: when you meet or speak with Aaron about your matter
- Public sources: where needed for your matter (for example the Land Registry, the probate registry or Companies House)
04 The information collected
The categories of personal information are:
- Contact information: name, email address, phone number, postal address
- Legal matter information: details of your enquiry, family circumstances, beneficiaries, executors, attorneys and related people
- Identity verification documents: passport, driving licence, utility bills and bank statements, collected for anti-money laundering compliance by electronic verification (eCos), by certified copies, or as scans uploaded to a questionnaire
- Financial information: asset values, property details and estate information where relevant to your matter
- Booking data: the time you booked, any notes, the plan you chose, the consent wording and a hashed IP address
- Technical data: Netlify's function logs record each request, including the IP address it came from, for up to 7 days. The site writes no personal data to those logs.
- Marketing preferences: your consent status for the newsletter
- Consent records: the text you consented to, the date and time, and how it was collected, kept for audit
05 Legal basis for processing
Under UK GDPR Article 6 there must be a lawful basis for processing your personal data. The bases relied on are:
| Purpose | Legal basis | GDPR Article |
|---|---|---|
| Providing legal services | Performance of a contract | Art 6(1)(b) |
| Responding to enquiries and call bookings | Pre-contractual steps / legitimate interests | Art 6(1)(b) / (f) |
| Following up a questionnaire you started but did not finish | Consent (the tick box on the questionnaire) | Art 6(1)(a) |
| Anti-money laundering and identity checks | Legal obligation (Money Laundering Regulations 2017) | Art 6(1)(c) |
| SRA regulatory compliance | Legal obligation | Art 6(1)(c) |
| Sending newsletters and marketing emails | Consent (explicit opt-in) | Art 6(1)(a) |
| Hosting and function logs (Netlify) | Legitimate interests (security and performance) | Art 6(1)(f) |
| Invoicing and financial records | Legal obligation (HMRC requirements) | Art 6(1)(c) |
06 How your information is used
Aaron uses your personal information to:
- Answer your enquiry and provide legal services
- Confirm, manage and remind you of a call you have booked
- Offer help with a questionnaire you started, where you asked for that
- Carry out conflict of interest checks
- Verify your identity under anti-money laundering legislation
- Comply with legal, regulatory and professional obligations, including the SRA's
- Share documents with you through the client portal
- Send invoices and process payments
- Send you legal updates and information about the services, with your consent
- Understand how the website is used, from anonymous counts only
08 Data processors and third-party sharing
Your personal data is shared only where necessary to provide the services or to comply with the law. The following processors handle data on the firm's behalf:
| Processor | Purpose | Where the data is held | Safeguard |
|---|---|---|---|
| Microsoft 365 | The firm's mailboxes, where every form, questionnaire and booking email arrives, with any documents and ID scans attached. | United Kingdom and European Union (Microsoft regional data centres) | Microsoft's data protection terms |
| Resend | Sends the emails this website generates: form and questionnaire submissions, with their attachments, booking confirmations and reminders. A copy of each sent email is held in the Resend dashboard for up to 30 days. | United States | Standard Contractual Clauses and the UK Addendum in Resend's data processing agreement |
| Netlify | Hosts the website and runs its functions. Holds call bookings (name, email, phone, notes, the plan, the consent wording and a hashed IP address) and the lead recovery store in Netlify Blobs. Function logs are kept for up to 7 days; the site writes no personal data to them. | United States | Standard Contractual Clauses in Netlify's data processing agreement |
| MailerLite | Email marketing for newsletter subscribers only, with an unsubscribe link in every email. See Section 7. | European Union (Lithuania) | Data Processing Agreement; the UK treats the EU as adequate |
| LEAP Legal Software | Case management, client records and matter files once you become a client. | United Kingdom | Data Processing Agreement |
| LawConnect (LEAP) | The client portal used to share documents with you during a matter. | United Kingdom | Data Processing Agreement |
Sanity holds the website's content and processes no personal data. Google Fonts are self-hosted through the website framework (Next.js): no request goes to Google and no personal data is transferred to Google.
Your information may also be disclosed to regulatory bodies (including the SRA, HMRC and the courts) where the law requires it or your matter needs it (for example HM Courts and Tribunals Service, the Office of the Public Guardian, or the Land Registry).
Your personal information is never sold, rented or traded.
09 International data transfers
Two processors hold data in the United States: Resend, which sends the emails this website generates and keeps a copy of each for up to 30 days, and Netlify, which hosts the website and holds call bookings, the lead recovery store and the function logs. Both transfers are covered by Standard Contractual Clauses, with the UK Addendum where it applies, in each processor's data processing agreement.
MailerLite holds newsletter data in the European Union, which the United Kingdom treats as providing adequate protection. LEAP, LawConnect and the firm's Microsoft 365 mailboxes hold data in the United Kingdom and the European Union. Google Fonts are self-hosted, so nothing goes to Google.
10 Data retention
Personal information is kept only as long as needed for the purpose it was collected for, or as the law requires. The retention periods are:
| Data type | Retention period |
|---|---|
| General enquiries by form, phone or email (no engagement) | 12 months, then securely deleted |
| Call bookings made through this website | 90 days after the date of the call, then deleted automatically |
| Copy of an enquiry kept when email delivery fails (lead recovery store) | 90 days, then deleted |
| Copy of a sent form email in the Resend dashboard | up to 30 days |
| Netlify function logs | Up to 7 days |
| Newsletter subscribers | Until unsubscribe, plus 30 days for removal |
| Client matter files: wills and trusts | 15 years from completion of the matter |
| Client matter files: probate | 12 years from completion of the matter |
| Client matter files: Lasting Powers of Attorney | 6 years from completion of the matter |
| AML / identity verification records | 5 years from end of relationship (MLR 2017) |
| Financial records and invoices | 7 years (HMRC requirement) |
| Complaints records | 6 years from resolution |
| Consent records | Duration of processing, plus 6 years |
After the retention period, data is securely destroyed. Original documents (such as a signed will) are returned to you or stored as separately agreed.
11 Data security
Appropriate technical and organisational measures protect your personal information against unauthorised access, alteration, disclosure or destruction. They include:
- Encrypted transmission (HTTPS/TLS) across the website and every email it sends
- The client portal (LawConnect), an encrypted route for sensitive documents during a matter, which Aaron recommends over email attachments once your matter is open
- Access limited to Aaron and to the people at the firm who need it for your matter or for its regulatory duties
- Password protection and multi-factor authentication on every system holding personal data
- Automatic deletion of call bookings and lead recovery copies at the end of their retention periods
- Regular review of the security measures, and Aaron keeps his own data protection training current
- Secure destruction of paper records when no longer required
- Compliance with the SRA's requirements for information security
13 Your rights under UK GDPR
Under the UK GDPR and the Data Protection Act 2018 you have the following rights:
- Right of access (subject access request): you can ask for a copy of the personal data held about you.
- Right to rectification: you can ask for inaccurate or incomplete data to be corrected.
- Right to erasure ("right to be forgotten"): you can ask for your data to be deleted, subject to the legal obligations to keep certain records (see Section 10).
- Right to restrict processing: you can ask for the use of your data to be limited in certain circumstances.
- Right to data portability: you can ask for your data in a structured, commonly used, machine-readable format.
- Right to object: you can object to processing based on legitimate interests, or to direct marketing, at any time.
- Right to withdraw consent: where processing is based on consent (the newsletter, or the questionnaire follow-up), you can withdraw it at any time. Withdrawal does not affect processing carried out before it. For the newsletter, use the unsubscribe link in any email or contact Aaron.
- Rights related to automated decision-making: see Section 14.
- Right to complain: from 19 June 2026 you have a statutory right to complain to the firm directly about how your personal data is handled, as well as to the Information Commissioner's Office (see Section 17).
To exercise any of these rights, email Aaron at aaron@safeharbour.legal or write to the firm at the registered office in Section 2. You receive a response within one month of the request. In most cases there is no fee. If a request is manifestly unfounded or excessive, a reasonable fee may be charged or the request refused, with the reason explained.
14 Automated decision-making
No automated decision-making or profiling, as defined in Article 22 of the UK GDPR, is used. The Plan Finder on this website suggests a plan from the answers you give, but it decides nothing about you: every decision affecting your legal matter is made by Aaron, a solicitor.
15 Children's data
The services are not directed at people under 18, and personal data is not knowingly collected from children. Where information about a child is processed in a client's matter (for example naming guardians in a will), that is done on the instructing client's consent and in the child's best interests.
If you believe personal data has been collected from a child without appropriate consent, contact Aaron straight away.
16 Electronic communications (PECR)
Electronic marketing complies with the Privacy and Electronic Communications Regulations 2003 (PECR):
- Marketing emails go only to people who have given explicit opt-in consent
- Every marketing email includes a working unsubscribe link
- No unsolicited marketing calls
- No unsolicited marketing text or WhatsApp messages
- Every unsubscribe request is honoured promptly
17 Complaints about data handling
If you are unhappy with how your personal data has been handled, you can complain to the firm directly. From 19 June 2026 you have a statutory right to do so. Email aaron@safeharbour.legal (marking it "Data Protection Complaint"), or write to the data controller at the registered office in Section 2. Your complaint is acknowledged within 30 days and answered without undue delay.
This is in addition to, and does not affect, your right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
- Website
- ico.org.uk/make-a-complaint
- Phone
- 0303 123 1113
- Address
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
18 Contact
For questions about this policy, or to exercise your data protection rights, contact Aaron:
- Phone
- 01262 310 850
19 Changes to this policy
This policy is updated when the website or the law changes. Material changes are posted on this page with a new "Last updated" date, and where a change materially affects people whose data is held, they are told directly.
20 Governing legislation
This policy is governed by the laws of England and Wales. The main legislation governing the processing is:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations 2003 (PECR)
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
- Solicitors Regulation Authority Standards and Regulations
Ends