Privacy and Cookie Notice
-
Leeds Day is a trading name of Leeds Day LLP, a limited liability partnership registered in England & Wales with Company number OC424623, whose registered office is at Godwin House, George Street, Huntingdon PE29 3BD - authorised and regulated by the Solicitors Regulation Authority 655766. Reference to “Partner” is reference to a Member of the LLP. A full list of Members is available for inspection on our website and at our registered office. Where we use the title “Salaried Partner” this does not relate to a Member of the LLP. Salaried Partners are employees only of the LLP.
We are regulated by the Solicitors Regulation Authority (SRA Regn. number 655766) and subject to rules and principles of professional conduct. To see the codes go to: SRA Code of Conduct page
Leeds Day does not accept Service by email.
-
Last updated: 7 October 2026
1. About this notice
Leeds Day LLP is committed to protecting the privacy and security of personal information.
This notice explains how Leeds Day LLP collects, uses, shares and protects personal information relating to:
clients and prospective clients;
visitors to its website;
subscribers to newsletters and other marketing communications;
individuals connected with client matters, including counterparties, witnesses, beneficiaries, employees, tenants and professional advisers;
suppliers and other business contacts; and
applicants for employment or work experience.
This notice applies to information relating to an identified or identifiable living individual, referred to as personal data.
References in this notice to “Leeds Day”, “the firm”, “we”, “us” or “our” mean Leeds Day LLP.
For the purposes of applicable data protection law, Leeds Day LLP is normally the controller of the personal data described in this notice. This means that the firm decides why and how that personal data is processed.
2. Data protection law
The firm processes personal data in accordance with applicable UK data protection and privacy legislation, including:
the UK General Data Protection Regulation (UK GDPR);
the Data Protection Act 2018;
the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), as amended; and
the Data (Use and Access) Act 2025, to the extent applicable.
3. Contact details
Questions about this notice or the firm’s use of personal data should be directed to:
Christopher Dodd – Partner and Data Protection Officer
Leeds Day LLP
Godwin House
George Street
Huntingdon
Cambridgeshire PE29 3BD
United KingdomEmail: christopher.dodd@leedsday.co.uk
Telephone: 0333 577 22504. Personal data collected by the firm
The personal data collected will depend on the nature of the firm’s relationship with the relevant individual and the legal services being provided. It may include:
name, title, date of birth and contact details;
home, business and correspondence addresses;
telephone numbers and email addresses;
identification documents and information used to verify identity;
financial information, including bank details, source of funds, source of wealth and transaction information;
information about personal, family, employment or business circumstances;
information concerning a legal matter, transaction, claim, dispute or enquiry;
communications with the firm;
billing and payment information;
records of attendance at the firm’s offices or events;
website usage, cookie, device, browser and IP address information;
marketing preferences;
recruitment information, including employment history, qualifications, references and right-to-work information; and
any other information provided to the firm or required for the provision of legal services.
The firm may also collect information about individuals who are not its clients where that information is relevant to a client matter. This may include information about counterparties, witnesses, beneficiaries, family members, employees, tenants, directors, shareholders and other persons connected with the matter.
5. Special category and criminal offence data
In appropriate cases, the firm may process special category data. This is personal data revealing or concerning:
racial or ethnic origin;
political opinions;
religious or philosophical beliefs;
trade union membership;
genetic data;
biometric data used to identify an individual;
physical or mental health;
sex life; or
sexual orientation.
The firm may also process information about criminal allegations, proceedings, convictions or offences where this is relevant to a legal matter or is required for regulatory, fraud prevention or anti-money laundering purposes.
This information will be processed only where the law permits, including where processing is necessary:
for the establishment, exercise or defence of legal claims;
for the provision of legal advice;
for reasons of substantial public interest;
to comply with employment, social security or social protection law;
to protect an individual’s vital interests;
where the individual has manifestly made the information public; or
with the individual’s explicit consent, where consent is the appropriate legal basis.
Additional safeguards will be applied where required by law.
6. How personal data is collected
6.1 Information provided directly
Personal data may be collected when an individual:
contacts the firm;
requests information, an estimate of costs or initial advice;
instructs the firm;
completes a form or questionnaire;
subscribes to a newsletter or other communication;
attends an event;
applies for employment or work experience;
uses the firm’s website or online services; or
otherwise communicates with the firm.
6.2 Information received from third parties
The firm may receive personal data from third parties, including:
clients and persons connected with clients;
counterparties and their advisers;
estate agents, accountants, banks, lenders, insurers and surveyors;
barristers, expert witnesses and other professional advisers;
medical and healthcare professionals;
courts, tribunals, regulators, law enforcement bodies and public authorities;
identity verification, fraud prevention, sanctions screening and credit reference providers;
Companies House, HM Land Registry and other public registers;
recruitment agencies, referees and former employers; and
publicly available sources.
6.3 Information collected through the website
When the website is used, the firm may collect:
IP address;
browser and device information;
operating system;
pages viewed and links selected;
the date, time and duration of visits;
referring website information; and
cookie identifiers and preferences.
Further information is provided in the cookie section below.
7. How personal data is used
The firm may use personal data to:
respond to enquiries and assess whether the firm can provide legal services;
provide legal advice and services;
open, administer and close client matters;
carry out conflict checks;
verify identity and undertake anti-money laundering, sanctions and fraud prevention checks;
communicate with clients, prospective clients and others involved in legal matters;
instruct and work with barristers, experts, foreign lawyers and other professional advisers;
manage billing, payments and client accounts;
comply with legal, professional, regulatory and insurance obligations;
establish, exercise or defend legal rights and claims;
maintain records and manage files;
manage complaints and respond to feedback;
improve the firm’s services, systems, website and business operations;
protect the security and integrity of the firm’s systems, premises and information;
manage supplier and professional relationships;
organise seminars, events and other business development activities;
send legal updates and marketing communications where permitted;
recruit and assess applicants;
prevent and investigate fraud, misuse, security incidents or other unlawful activity; and
manage a merger, acquisition, restructuring, transfer or disposal involving all or part of the firm’s business.
The firm will not use personal data for a purpose that is incompatible with the purpose for which it was collected unless that further use is permitted or required by law.
8. Lawful bases for processing
The lawful basis relied on will depend on the particular processing activity. The firm may process personal data where:
8.1 Contract
Processing is necessary to:
take steps at an individual’s request before entering into a contract; or
perform a contract with the individual, including a contract for legal services.
8.2 Legal obligation
Processing is necessary to comply with a legal or regulatory obligation, including obligations relating to:
anti-money laundering;
sanctions screening;
fraud prevention;
taxation and accounting;
professional conduct;
court orders; and
regulatory reporting.
8.3 Legitimate interests
Processing is necessary for the firm’s legitimate interests, or those of a third party, except where those interests are overridden by the individual’s rights and interests.
Those legitimate interests may include:
providing, administering and improving legal services;
responding to enquiries;
managing the firm’s business and professional relationships;
protecting the firm’s legal rights;
maintaining the security of systems, premises and information;
preventing fraud and misuse;
recovering fees and managing financial affairs;
developing the firm’s business; and
sending relevant business-to-business or existing-client marketing where permitted by law.
8.4 Consent
The firm may rely on consent where this is required or appropriate, including for certain electronic marketing communications, non-essential cookies or particular uses of special category data.
Where processing is based on consent, that consent may be withdrawn at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.
8.5 Vital interests
Processing may be necessary to protect an individual’s life or physical safety, for example in a medical emergency.
8.6 Public task
In limited circumstances, processing may be necessary for a task carried out in the public interest or in the exercise of official authority.
9. Anti-money laundering and identity checks
The firm is required to comply with anti-money laundering, counter-terrorist financing and sanctions legislation.
Identity and verification checks may be undertaken using specialist third-party providers. These checks may involve comparing information supplied to the firm against information held by credit reference agencies, fraud prevention agencies, public registers and other databases.
Such checks do not ordinarily involve a credit application and should not affect an individual’s credit rating. Further information about a particular provider and its use of personal data will be supplied where appropriate.
The firm may be legally prohibited from informing an individual about certain disclosures or investigations.
10. Marketing communications
The firm may send information about legal developments, services, seminars and events where:
the recipient has consented;
the communication is permitted under PECR, including where the existing-client “soft opt-in” applies; or
the communication is otherwise permitted on the basis of the firm’s legitimate interests.
Every electronic marketing communication will provide a clear means of opting out.
Marketing preferences may be changed at any time by:
Email: marketing@leedsday.co.uk
Telephone: 0333 577 2250
Post: Leeds Day LLP, Godwin House, George Street, Huntingdon, Cambridgeshire PE29 3BDThe firm may retain limited details on a suppression list to ensure that an opt-out request is respected.
11. Sharing personal data
The firm may share personal data with:
clients and persons authorised by clients;
barristers, experts, mediators, foreign lawyers and other professional advisers;
counterparties and their legal representatives;
courts, tribunals and dispute resolution bodies;
regulators, ombudsmen, law enforcement bodies and public authorities;
banks, payment service providers, insurers and auditors;
identity verification, anti-money laundering, sanctions screening, fraud prevention and credit reference providers;
information technology, document storage, cloud hosting, communications and cybersecurity providers;
confidential waste disposal and records management providers;
marketing, event management and website analytics providers;
recruitment agencies and employment screening providers; and
potential purchasers, investors, merger partners or other parties involved in a restructuring or transfer of the firm’s business.
The firm may also disclose personal data where required by law, court order or professional obligation, or where disclosure is necessary to establish, exercise or defend legal rights.
Service providers acting on the firm’s behalf are required to process personal data only in accordance with the firm’s instructions and to apply appropriate security measures.
Personal data will not be sold.
12. Legal professional privilege and confidentiality
Information provided to the firm may be protected by legal professional privilege and duties of professional confidentiality.
In some circumstances, these obligations or applicable statutory exemptions may limit the information the firm can disclose in response to a data protection request, particularly where disclosure would reveal privileged or confidential information relating to another person.
13. International transfers
Some service providers, professional advisers or parties involved in a legal matter may be located outside the United Kingdom.
Where personal data is transferred outside the United Kingdom, the firm will ensure that the transfer is lawful. Safeguards may include:
transferring information to a country recognised by the UK Government as providing an adequate level of protection;
using the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses;
relying on another lawful transfer mechanism; or
relying on a permitted exception for a specific situation, including where a transfer is necessary for legal proceedings or the provision of legal advice.
Further information about safeguards applying to a particular transfer may be requested using the contact details above.
14. Data security
The firm maintains appropriate technical and organisational measures designed to protect personal data against:
accidental or unlawful destruction;
loss or alteration;
unauthorised disclosure or access; and
other unlawful processing.
Those measures include access controls, staff training, system security, supplier due diligence, incident management procedures and secure information disposal.
Access to personal data is restricted to individuals who require it for a legitimate business or professional purpose and who are subject to confidentiality obligations.
No internet transmission or information storage system can be guaranteed to be completely secure. Any suspected security concern should be reported promptly to the firm.
15. Data retention
Personal data will be retained only for as long as reasonably necessary for the purpose for which it was collected, including to satisfy legal, regulatory, professional, insurance, accounting and reporting requirements.
Retention periods will depend on factors including:
the nature and duration of the professional relationship;
the type of legal matter;
applicable limitation periods;
regulatory and anti-money laundering requirements;
the possibility of a complaint, dispute or legal claim;
the interests of clients and relevant third parties; and
the sensitivity and volume of the information.
Client files will normally be retained for the period stated in the applicable client care documentation or terms of business. Some documents may need to be retained for longer, including wills, deeds, trust documents, probate records or material relevant to continuing legal rights.
When personal data is no longer required, it will be securely deleted, destroyed or anonymised.
16. Individual rights
Subject to applicable conditions, restrictions and exemptions, an individual may have the right to:
be informed about how personal data is used;
request access to personal data held by the firm;
request correction of inaccurate or incomplete personal data;
request erasure of personal data;
request restriction of processing;
object to processing based on legitimate interests or the performance of a public task;
object to direct marketing at any time;
request data portability where processing is automated and based on consent or contract;
withdraw consent where processing relies on consent; and
request safeguards relating to automated decision-making, where applicable.
These rights do not apply in every circumstance. In particular, the firm may need to retain or continue processing information to comply with legal and professional obligations, protect another person’s rights, preserve legal professional privilege, or establish, exercise or defend legal claims.
Requests should be sent to the Data Protection Officer using the contact details in section 3.
The firm may ask for information reasonably required to verify identity and locate the relevant personal data. There is usually no fee, although a reasonable fee may be charged, or a request may be refused, where permitted by law.
The firm will respond within the period required by applicable law. That period may be extended where a request is complex or multiple requests have been made. The requester will be informed if an extension applies.
17. Complaints
Concerns about the firm’s use of personal data should initially be sent to the Data Protection Officer using the contact details in section 3. The firm will investigate and respond in accordance with applicable data protection law and its complaints procedure.
A complaint may also be made to the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United KingdomTelephone: 0303 123 1113
Website: https://ico.org.uk18. Automated decision-making
The firm does not generally make decisions producing legal or similarly significant effects solely by automated means.
If such processing is introduced, affected individuals will be given the information required by law, including information about the logic involved, the significance and likely consequences of the processing, and any applicable right to request human intervention.
19. Third-party websites
The firm’s website may contain links to websites operated by third parties. The firm is not responsible for the privacy practices, security or content of those websites. Individuals should review the privacy information provided by the relevant third party before submitting personal data.
20. Cookies and similar technologies
20.1 What are cookies?
Cookies are small text files placed on a device when a website is visited. Similar technologies may include pixels, tags, local storage and software development kits.
Cookies may be:
session cookies, which expire when the browser is closed; or
persistent cookies, which remain until they expire or are deleted.
They may also be:
first-party cookies, set by the firm’s website; or
third-party cookies, set by another organisation whose services are used on the website.
20.2 Categories of cookies
The website may use the following categories:
Strictly necessary cookies
These cookies are required for the website to operate, maintain security, remember privacy choices or provide a service specifically requested by the visitor. They cannot usually be disabled through the firm’s cookie management tool.
Consent is not required for cookies that are strictly necessary under PECR.
Analytics cookies
These cookies help the firm understand how visitors use the website, including which pages are visited and whether errors occur. The information is used to measure performance and improve the website.
Analytics cookies will not be placed unless the visitor has given consent through the cookie banner or preference centre.
Functionality cookies
These cookies allow the website to remember choices and provide enhanced functionality. They will be used only where the visitor has consented, unless they are strictly necessary to provide a requested service.
Advertising or targeting cookies
These cookies may be used to build a profile of interests, measure advertising or show relevant content on other websites. They will not be used unless the visitor has consented.
20.3 Google Analytics
Where enabled, the website may use Google Analytics to collect statistical information about website use.
Google Analytics cookies will be activated only after the visitor has given consent. Information collected may include device, browser, approximate location, pages visited and interactions with the website.
Further information about Google’s use of information is available through Google’s privacy documentation. Google Analytics may be disabled at any time through the website’s cookie preference centre.
20.4 Cookie preferences
When a visitor first accesses the website, a cookie banner will provide options to:
accept optional cookies;
reject optional cookies; or
select individual cookie categories.
Rejecting optional cookies must be as straightforward as accepting them.
Consent may be withdrawn or preferences changed at any time through the “Cookie Settings” link available on the website. Withdrawing consent will not affect the lawfulness of processing carried out before consent was withdrawn.
A strictly necessary cookie may be used to record the visitor’s cookie choices.
20.5 Browser controls
Most browsers allow cookies to be viewed, blocked or deleted. Blocking all cookies may affect the operation of the website, including password-protected or interactive services.
Browser settings are separate from the firm’s cookie preference centre. If cookies are deleted or a different browser or device is used, cookie preferences may need to be selected again.
20.6 Cookie list
Current details of individual cookies, including their provider, purpose and duration, should be displayed in the website’s cookie preference centre or cookie schedule.
The cookie schedule should be reviewed regularly and updated whenever cookies, analytics tools or embedded third-party services change.
21. Changes to this notice
This notice may be amended to reflect changes in the firm’s services, systems, working practices or legal obligations.
The current version will be published on the firm’s website. Where a change materially affects how personal data is used, appropriate additional notice will be provided where required.

