Privacy and Cookies Policy

Last updated: 24 August 2026

This policy explains how Do It Legally collects, uses, stores and protects personal information. It applies both to use of our website and to the legal advice, document preparation and related services that we provide.

Part A: Privacy Notice

1. Who we are

Do It Legally is an independent legal-services business based in Brighton & Hove.

Do It Legally is the trading name of the sole trader proprietor. The sole trader proprietor trading as Do It Legally is the data controller responsible for the personal information described in this policy.

Do It Legally is not an SRA-authorised firm.

Our contact details are:

Do It Legally
Citibase
95 Ditchling Road
Brighton
BN1 4ST
United Kingdom

Email: admin@doitlegally.co.uk
Telephone: 01273 011245

References in this policy to “Do It Legally”, “we”, “our” or “us” mean the data controller trading as Do It Legally.

2. Who this policy applies to

This policy applies to:

  • visitors to our website;
  • people who contact us about our services;
  • prospective, current and former clients;
  • individuals whose information is provided to us in connection with a client’s matter;
  • family members, beneficiaries, executors, attorneys, witnesses, representatives and other relevant parties;
  • suppliers, professional contacts and people with whom we conduct business; and
  • people who make a complaint or enquiry about our work.

3. Information we may collect

The information we collect depends on the nature of the enquiry or service. It may include:

  • names, postal addresses, email addresses and telephone numbers;
  • dates of birth and other identity information;
  • copies of passports, driving licences and other identification documents;
  • signatures and signed authorities;
  • family, relationship and household information;
  • information about children and dependants;
  • employment and business information;
  • property, asset, liability, tax, financial, banking and payment information;
  • nationality, residence, immigration or right-to-work information;
  • information about Wills, estates, beneficiaries, executors, attorneys and proposed gifts;
  • correspondence, documents, photographs and other evidence;
  • information about legal proceedings, disputes, complaints, penalties or regulatory matters;
  • records of advice, instructions, meetings and communications;
  • invoice and payment records; and
  • information submitted through our website, by email, telephone, messaging service, post or during a consultation.

Some matters may involve special-category information. This can include information about:

  • physical or mental health;
  • disability;
  • racial or ethnic origin;
  • religious or philosophical beliefs;
  • sexual orientation; or
  • trade-union membership.

We may also receive information concerning criminal allegations, convictions, offences, investigations, civil penalties or related proceedings where this is relevant to the work we are asked to undertake.

Please do not send highly sensitive documents through the website enquiry form unless we have asked you to do so. An initial enquiry should normally contain only enough information for us to understand the general nature of the matter and contact you.

4. Where information comes from

We usually receive personal information directly from the person concerned.

We may also receive information from:

  • a client or someone acting with the client’s authority;
  • family members, executors, attorneys, beneficiaries or representatives;
  • employers, employees or business representatives;
  • courts, tribunals, government departments, councils and public authorities;
  • medical, educational or other professional organisations;
  • landlords, managing agents, creditors or service providers;
  • another adviser, representative or party to a matter;
  • identity-verification or fraud-prevention services;
  • publicly available records and sources; or
  • another lawful source relevant to the work requested.

Where appropriate, clients should inform other people whose information they provide that it may be supplied to and used by Do It Legally.

5. How we use personal information

We may use personal information to:

  • respond to enquiries;
  • consider whether we can provide assistance;
  • carry out conflict and availability checks;
  • provide quotations and information about our services;
  • take steps requested before entering into an agreement;
  • verify identity, instructions and authority where appropriate;
  • prevent fraud or misuse of our services;
  • accept, manage and carry out client instructions;
  • provide legal information and advice;
  • prepare Wills, powers of attorney, agreements, applications and other documents;
  • communicate with clients and relevant third parties;
  • make enquiries, applications, requests, complaints or representations;
  • refer or introduce clients to appropriate third-party specialists where agreed;
  • administer document-storage arrangements;
  • maintain client, financial and business records;
  • issue invoices and record payments;
  • comply with legal, tax, insurance and other applicable requirements;
  • establish, exercise or defend legal rights and claims;
  • investigate and respond to complaints;
  • protect the security of our systems and communications; and
  • administer, maintain and improve our business and website.

We do not sell or rent personal information.

We will not use information supplied in an enquiry for unrelated electronic marketing unless the person has asked to receive it or the law otherwise permits us to do so. Marketing communications can be stopped at any time.

6. Our lawful bases

The lawful basis depends on the purpose for which the information is used.

We may process ordinary personal information because:

  • it is necessary to take steps at your request before entering into an agreement;
  • it is necessary to perform our agreement with you;
  • it is necessary to comply with a legal obligation;
  • it is necessary for our legitimate interests, or the legitimate interests of another person, provided those interests are not overridden by your rights; or
  • you have given consent where consent is the appropriate lawful basis.

Our legitimate interests may include:

  • responding to enquiries;
  • providing and administering our services;
  • maintaining proper client and business records;
  • protecting clients and our business against fraud or misuse;
  • securing our website, systems and communications;
  • obtaining professional advice or insurance cover; and
  • establishing, exercising or defending legal rights.

Where special-category information is necessary, we will also rely on an appropriate condition under Article 9 of the UK GDPR. Depending on the circumstances, this may include:

  • the establishment, exercise or defence of legal claims;
  • substantial public interest;
  • the protection of vital interests;
  • explicit consent; or
  • another condition permitted by law.

Criminal-offence information will be processed only where permitted by Article 10 of the UK GDPR and an applicable condition under the Data Protection Act 2018, including where it is necessary in connection with legal claims.

7. If information is not provided

You are not generally required to make an enquiry or provide information to us.

However, we may be unable to advise, prepare documents or carry out instructions if we do not receive information reasonably required to provide the service, verify instructions or comply with our legal obligations.

8. Sharing personal information

Where necessary and lawful, we may share information with:

  • website, email, cloud-storage, security, IT and communications providers;
  • payment, banking and accounting providers;
  • insurers and professional advisers;
  • barristers, solicitors, experts, consultants and other specialists involved in a matter;
  • identity-verification and fraud-prevention providers;
  • Will, deed or document-storage providers;
  • courts, tribunals, government departments, councils, regulators and public authorities;
  • dispute-resolution or complaints-handling bodies;
  • another party to a matter or that party’s representative;
  • a person authorised by the client; or
  • law-enforcement and other authorities where disclosure is required or permitted by law.

Where we introduce or refer a client to another professional, that professional will normally be responsible for explaining how they use personal information in connection with their own services.

We share only the information reasonably necessary for the relevant purpose. Providers acting on our behalf are expected to protect personal information and use it only for authorised purposes.

9. Technology and digital tools

We may use secure digital tools to assist with:

  • administration;
  • legal and factual research;
  • document preparation;
  • transcription;
  • organisation and review; and
  • management of client files and communications.

Where an external technology provider is used, we take reasonable steps to minimise the information disclosed, use appropriate security settings and avoid unnecessary disclosure of identifying or sensitive information.

Technology assists our work but does not replace professional judgement. We do not use solely automated decision-making to make decisions that have legal or similarly significant effects on individuals.

10. International transfers

Some technology, communications or cloud-service providers may process personal information outside the United Kingdom.

Where information is transferred internationally, we take reasonable steps to ensure that an appropriate legal safeguard applies. This may include:

  • a UK adequacy regulation;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved contractual clauses; or
  • another safeguard permitted by data-protection law.

11. Security

We use reasonable technical and organisational measures to protect personal information against loss, misuse, unauthorised access, alteration and disclosure.

No method of communication or electronic storage is completely secure. Clients should use an appropriately secure method when sending particularly sensitive or confidential information and contact us if they are unsure how it should be supplied.

12. How long we retain information

We keep personal information only for as long as reasonably necessary for the purpose for which it was obtained and to meet legal, insurance, tax and business requirements.

Our usual approach is:

  • enquiries that do not become client matters may normally be retained for up to 24 months;
  • ordinary client files may normally be retained for at least six years after the work is completed or the file is closed;
  • financial and invoice records are retained for the applicable statutory accounting and tax period;
  • complaint, dispute or claim records may be retained until the matter and relevant limitation periods have ended; and
  • Wills, deeds, Lasting Powers of Attorney and other documents intended to have a long-term effect may be retained for longer where this is necessary, agreed with the client or forms part of a document-storage service.

Information may be deleted earlier where there is no continuing reason to retain it. It may be retained longer where there is a lawful and proportionate reason, including an ongoing dispute, insurance requirement, legal claim or safeguarding concern.

13. Your rights

Depending on the circumstances and the lawful basis being used, you may have the right to:

  • ask for access to your personal information;
  • ask for inaccurate or incomplete information to be corrected;
  • ask for information to be erased;
  • ask for processing to be restricted;
  • object to particular processing;
  • receive certain information in a portable format;
  • withdraw consent where processing is based on consent; and
  • raise a concern or complaint.

These rights are not absolute. An exemption may apply, including where information must be retained to comply with the law, protect another person’s rights or establish, exercise or defend legal claims.

To exercise a right, please contact admin@doitlegally.co.uk.

We may ask for information reasonably necessary to confirm your identity and locate the relevant records. We will respond within the period required by law.

14. Complaints about personal information

Please contact us first if you are concerned about how your personal information has been handled. We will investigate the concern and try to resolve it promptly.

You also have the right to complain to the Information Commissioner’s Office, which is the UK data-protection regulator.

Website: www.ico.org.uk
Telephone: 0303 123 1113

15. Changes to this privacy notice

We may update this policy to reflect changes to our services, website, systems or legal obligations.

The latest version and its review date will be published on this page.

Part B: Cookies and Website Technology

16. Cookies and technical information

We do not currently intend to use advertising, personalisation or behavioural-tracking cookies on the public pages of this website.

The website is built using WordPress and Cornerstone and uses hosting and technical services supplied by GoDaddy and other providers. These services may process limited technical information, including:

  • internet protocol addresses;
  • browser and device information;
  • dates and times of access;
  • security events;
  • server logs; and
  • website-performance information.

This information may be processed where necessary to deliver, secure, maintain and troubleshoot the website.

Hosting, security and performance services may use strictly necessary technology even where an ordinary visit does not create a browser-accessible cookie.

If we introduce non-essential cookies, analytics services, advertising pixels or similar tracking technology, we will update this policy and request consent where required by law.

You can control or delete cookies through your browser settings. Blocking strictly necessary technology may affect the operation of some website functions.

17. Website enquiry form

Information entered into the website enquiry form is transmitted to us so that we can consider and respond to the enquiry.

Submitting an enquiry:

  • does not create a client relationship;
  • does not mean that we have accepted instructions;
  • does not reserve our availability; and
  • does not make us responsible for a deadline.

Please do not assume that urgent instructions or responsibility for a deadline have been accepted unless we expressly confirm this in writing.

Do It Legally
Citibase
95 Ditchling Road
Brighton
BN1 4ST

Email: admin@doitlegally.co.uk
Telephone: 01273 011245