When we say 'Brodies', 'we' or 'us' in this statement, it means Brodies LLP. Brodies LLP is the 'controller' of your personal information.

We collect, use and store different types of personal information about you, which we have grouped together as follows:

Types of personal information Description                                                             
Identity Data  ID information including your name, marital status, title, date of birth, gender and National Insurance Number 
Contact Data Where you live and how to contact
Financial Data Your financial position and history, including bank details and credit rating
Transactional Data Details about payments to and from and other details about services you purchase from us 
Communications Data What we learn about you from letters, emails, call recordings and conversations between us 
Publicly Available Data Details about you that are publicly available, such as on Companies House or elsewhere on the internet 
Consents Data Any permissions, consents or preferences that you give us 

How we use your information

The table below outlines how we use your personal information and our reasons. Where these reasons include legitimate interests, we explain what these legitimate interests are.

What we use your information for  Our reasons  Our legitimate interests 
  • To receive the products or services you provide to us 
  • Contractual performance 
  • Legal obligation
  • Legitimate interests
  • For firm management
  • To maintain access and control records
  • For incident/breach reporting, management and investigation 
  • To fulfil our contractual obligations
  • Contractual performance
  • Legitimate interests
  • To comply with our contractual obligations to you and your organisation
  • To properly manage the risks and liabilities associated with the contracts we are party to 
  • To comply with laws and regulations that apply to us 
  • To protect our reputation 
  • To enforce the terms of our contract with you 
  • Contractual performance
  • Legitimate interest
  • To ensure that we benefit from the terms of the contract we have entered into and properly manage the risks and liabilities associated with them 
  • For procurement purposes, including supplier due diligence, background checks and the assessing of tenders
  • To carry out credit checks 
  • Contractual performance
  • Legitimate interests
  • Our legal duties 
  • To meet our contractual obligations to you or your organisation
  • To ensure that we benefit from the terms of the contracts we have entered into and properly manage the risks and liabilities associated with them
  • To comply with laws and regulations that apply to us
  • To establish, enforce and defend legal claims 
  • Consent
  • Contractual performance
  • Legitimate interests
  • To manage our business efficiently and properly in accordance with normal business practices, legal requirements and to optimise its value for shareholders
  • To ensure that we run our business in accordance with good business principles and meet corporate governance, accounting and audit standards 
  • For prevention of crime and public safety, including through the use of CCTV
  • Legal obligation
  • Legitimate interests
  • To manage the risk of crime and safety for us, our employees and our clients
  • To develop and improve how we deal with crime
  • To report criminality or the suspicion of criminality for the wider benefit of society
  • To be efficient about how we fulfil our responsibilities generally 

Where we collect your personal information from

We may collect personal information about you from the following sources:

  • Directly from you or the organisation for whom you work
  • Companies or individual that tell you about us
  • Public registrars and public information repositories, such as Companies House and Registers of Scotland.
  • The internet and social networking sites such as LinkedIn
  • Third parties with whom we deal during the course of carrying on our business
  • Market researchers
  • Intermediaries such as other professional firms who know you

Who we share your information with:

We may share your personal information with the following third parties:

  • Agents and service providers that we use during the course of providing legal services, including Mimecast and Concep 
  • Our professional advisors
  • Other suppliers to the firm
  • The police and other law enforcement agencies
  • Relevant regulators, including the Information Commissioner's Office in the event of a persoanl data breach
  • (a) Subsidiaries or affiliates of Brodies LLP, and (b) Brodies & Co (Trustees) Limited and any of its subsidiaries or affiliates  
  • Potential or actual purchasers of any part of our business or assets, or other third parties in the context of a possible transfer or restructuring of our business

If you choose not to give your personal information

If you choose not to give us your personal information, it may delay or prevent us from being able to comply with our own legal obligations. It may also result in us being unable to, or refusing to, engage you or your organisation as a supplier.

Automated decisions

We do not envisage taking any decisions about you based solely on automated processing (i.e. without human involvement), which have a legal or similarly significant effect on you.

How long we keep your personal information

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.

In general terms, we will hold your personal information for so long as you or the organisation for whom you work continue to provide us with products and services and for an additional period of 10 years thereafter.

International transfers

Some of the IT systems or services that we use are hosted or provided from outside the United Kingdom or may be supported by teams located outside the United Kingdom.

Where this is the case, we will usually use IT systems or services where personal information is hosted in or accessed only from countries or territories that are recognised under data protection law as providing an adequate level of protection for personal information (an approved destination) but we may process personal information in other countries or territories as well. In all cases where we process personal information outside the United Kingdom or an approved destination then we will use appropriate safeguards in accordance with the requirements of data protection law, such as a contract with the recipient that requires them to protect that information to the same standards as if the information were being processed within the United Kingdom.

The safeguards we use will depend on the location of the recipient, the function they are performing and the personal information being transferred.

      Complaints

      We seek to resolve directly all complaints about how we handle personal information. If you have a complaint about how your personal information has been handled, please follow our complaints process outlined here.

      In your complaint, please include your name and contact details, whether you are a client or not, the nature of the complaint and any relevant documents and background information to help us make appropriate enquiries. Please also tell us the outcome you are seeking. Please note that in appropriate cases, we may need to ask you to verify your identity as part of this process, especially if you are not an existing client.

      If you submitted a complaint, we will acknowledge receipt of your complaint within 2 working days and provide you with a unique customer number to quote in future correspondence.

      We aim to provide you with a substantive response to your complaint within 28 days of receiving all of the information we need to understand and investigate with your complaint. If we are unable to respond within 28 days we will advise you of this as soon as possible and explain why it has not been possible to respond within that timescale.

      If you remain dissatisfied, you also have the right to lodge a complaint with the UK's Information Commissioner's Office: