Policies

Privacy notice

How we collect, use and protect personal data under UK GDPR and the Data Protection Act 2018. Last updated 5 August 2026.

1. Controller and contact details

The data controller is NE26 Limited (company number 16030871), trading as LegalDirectory.org.uk, First Floor Office, 3 Hornton Place, London, W8 4LZ. We are registered with the Information Commissioner's Office under reference ZC054682.

For any privacy question, or to exercise your rights, email hello@legaldirectory.org.uk or write to the address above. We have not appointed a statutory Data Protection Officer as we are not required to do so.

2. Personal data we collect

Depending on how you use the Directory, we may collect:

  • Enquiry data - your name, work email address, telephone number, organisation, the Firm you contacted and the content of your message.
  • Account data - name, email address, hashed authentication credentials or Google sign-in identifier, and role.
  • Firm claim and verification data - claimant name, work email at the Firm's domain, position, SRA number and verification timestamps.
  • Billing data - subscription plan, billing contact, VAT details, invoices and payment status. Card details are collected and stored by Stripe, not by us.
  • Firm contact data - business contact details for regulated law firms, sourced from the SRA register and other public sources, used for directory listings and business-to-business outreach.
  • Usage and technical data - IP address, device and browser type, pages viewed, searches performed, filters used, referring URL, and consent choices.
  • Correspondence - emails, support tickets, corrections requests and complaints, including delivery, open and click events for messages we send.

3. Why we use it and our lawful bases

  • To transmit and manage enquiries to Firms - performance of a contract with you and our legitimate interest in operating the Directory.
  • To create, verify and maintain Firm listings and accounts - legitimate interests in a reliable, verified directory, and performance of a contract with subscribing Firms.
  • To take payment, manage subscriptions and meet accounting obligations - performance of a contract and legal obligation.
  • To publish regulatory information about law firms - legitimate interests in public-interest transparency, using data already published by the SRA.
  • To send business-to-business outreach to law firms about listing and subscribing - legitimate interests in marketing a relevant service to businesses, with an opt-out in every message.
  • To measure and improve the Directory using analytics and Google Tag Manager - consent, collected through our cookie banner.
  • To secure the service, prevent fraud and abuse, and enforce our terms - legitimate interests and legal obligation.
  • To handle corrections, complaints, regulatory requests and legal claims - legal obligation and legitimate interests.

4. Sharing your data

We do not sell personal data and we do not share it with third parties for their own marketing.

We share data with the Firm you choose to contact, which then acts as an independent controller of your enquiry, and with service providers acting as our processors under written terms.

  • Supabase - database, authentication and file storage hosting.
  • Cloudflare - application hosting, content delivery and security.
  • Mailgun (EU region) - transactional and outreach email delivery.
  • Stripe Payments Europe Limited - subscription payments and billing portal (an independent controller for payment processing).
  • Google (Tag Manager and analytics) - usage measurement, only where you have consented.
  • Professional advisers, insurers, auditors, regulators, law enforcement and courts where legally required or to establish or defend legal claims.
  • A buyer or successor if we sell or reorganise the business, subject to equivalent protections.

5. International transfers

We aim to keep data within the UK and European Economic Area. Where a provider processes data outside the UK, we rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses, together with appropriate technical and organisational safeguards. You may request a copy of the relevant safeguard.

6. How long we keep it

  • Enquiry data - 24 months from submission, then deleted or anonymised.
  • Account data - for the life of the account and 12 months after closure.
  • Firm claim and verification records - 6 years, to evidence who was authorised to control a listing.
  • Billing and tax records - 6 years after the end of the accounting period, as required by law.
  • Outreach and suppression records - suppression and unsubscribe entries are kept indefinitely so we do not contact you again.
  • Analytics and consent logs - up to 26 months.
  • Complaints and correction requests - 6 years from resolution.

7. Your rights

You have the right to be informed; to access a copy of your data; to rectification; to erasure; to restrict processing; to data portability; to object to processing based on legitimate interests; to object to direct marketing at any time; and not to be subject to solely automated decisions with legal or similarly significant effects. We do not carry out such automated decision-making.

Where we rely on consent, you may withdraw it at any time without affecting processing already carried out. Cookie consent can be changed at any time using the Cookie settings link in the footer.

To exercise a right, email hello@legaldirectory.org.uk. We will respond within one month and may ask for information to verify your identity. There is no fee unless a request is manifestly unfounded or excessive.

8. Law firm data and objections

Listings for regulated law firms are built from information the SRA publishes in the public interest, together with publicly available business contact details. Where that information identifies an individual, such as a sole practitioner, we rely on legitimate interests.

A Firm may request correction of its listing under our Corrections Policy, or object to inclusion by emailing hello@legaldirectory.org.uk. We will assess the objection and, where we cannot show overriding legitimate grounds, remove or restrict the listing.

9. Security

We use encryption in transit, access controls, row-level database security, least-privilege service credentials, secret management and audit logging. No system can be guaranteed completely secure. If a personal data breach is likely to result in a risk to your rights, we will notify the ICO within 72 hours and inform you where required.

10. Children

The Directory is a business service and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has provided data, contact us and we will delete it.

11. Changes and complaints

We may update this notice; the current version and its last-updated date are always published here, and we will notify account holders of material changes by email.

If you are unhappy with how we have handled your data, please contact us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, by calling 0303 123 1113, or by writing to Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.