Privacy Notice

Winton & Winton Ltd

Privacy Notice

Version 1.2

This privacy notice explains how Winton & Winton Ltd (“Winton & Winton”, “the firm”, “we”, “us” or “our”) collects, uses, shares and protects personal information, and the rights you have in relation to that information. It applies to our clients and prospective clients, individuals connected with the matters on which we are instructed, visitors to our premises and website, suppliers and contacts, and applicants for employment.

We are a specialist private law firm advising on artificial intelligence, intellectual property, data protection and privacy, cybersecurity, payments, and commercial and corporate law. We are the controller of the personal information described in this notice. Because we are a law firm, the personal information we hold is also protected by our professional duty of confidentiality and, where it applies, by legal professional privilege — see section 4.

1. Who we are and how to contact us

Winton & Winton Ltd is a limited company and an authorised legal practice. Our details are:

Controller Winton & Winton Ltd (company number 05741756)
Registered / postal address Oxford House, 12–20 Oxford Street, Newbury, Berkshire RG14 1JB
Telephone 01635 595000
Email charlotte@winton.biz
Data protection contact ashley@winton.biz
SRA authorisation Authorised and regulated by the Solicitors Regulation Authority, SRA number 441262
ICO registration Registered with the Information Commissioner’s Office, registration number Z1546921

2. The personal information we collect, and why

The information we collect depends on our relationship with you and the matter on which we are instructed. We collect only what we need. The main categories are set out below.

2.1 Clients and prospective clients

  • Identity and contact details — name, postal and email address, telephone number, date of birth, job title and employer.
  • Client due diligence and anti-money-laundering (AML) information — identification documents (e.g. passport, photo ID), proof of address, information on source of funds and source of wealth, beneficial ownership, and the results of identity, sanctions, politically-exposed-person (PEP) and conflict-of-interest checks.
  • Matter information — your instructions, descriptions of the matter, documents, correspondence and records of advice, including information about third parties who are involved in or referred to by your instructions and correspondence.
  • Financial and billing information — payment and bank details, billing records, and account history.
  • Relationship and operational information — account and contact-management records, marketing preferences, records of meetings and decisions, and records of any compliments or complaints.
  • Communications — emails, letters, attendance and meeting notes, and (where we tell you in advance) call recordings.

2.2 Special category and criminal offence information

Because of the nature of legal work, the matters on which we are instructed may contain special category data (information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, or data concerning sex life or sexual orientation) and criminal offence data (including information about allegations, proceedings, convictions, and the results of DBS or sanctions checks). We do not seek this information unless it is relevant to the matter or required by law.

We process special category data only where we also have a condition under Article 9 of the UK GDPR, and we process criminal offence data only where we have a condition under Article 10 and Schedule 1 to the Data Protection Act 2018. The conditions we rely on are set out in section 3. Where Schedule 1 requires it, we maintain an Appropriate Policy Document describing how we comply and our retention and erasure policies; this is available on request.

2.3 Job applicants

If you apply to work with us, we collect your contact details, date of birth, the information in your application and CV (employment and education history, qualifications), right-to-work information, references, and — where lawful and relevant to the role — results of criminal records (DBS) and other vetting checks.

3. Our lawful bases

Under UK data protection law we must have a lawful basis for collecting and using personal information. The bases we rely on, and the purposes for which we rely on them, are set out in the table below.

Lawful basis (Art. 6 UK GDPR) How and why we rely on it
Contract To take steps at your request before entering into a retainer and to perform our engagement — providing legal advice and services, and managing billing and payment.
Legal obligation

To comply with obligations that apply to us as a regulated law firm, including:

  • anti-money-laundering and counter-terrorist-financing duties under the Money Laundering Regulations 2017 and the Proceeds of Crime Act 2002 (including client due diligence and, where required, suspicious activity reports to the National Crime Agency);
  • SRA regulatory requirements, court orders and disclosure obligations, and tax and accounting law.
Legitimate interests Where it is necessary for our or a third party’s legitimate interests and not overridden by your rights. Our legitimate interests are: running and administering our business and client relationships; carrying out conflict checks; securing our systems and information; pursuing payment; obtaining insurance and professional advice; establishing, exercising or defending legal rights; communicating with clients and contacts about our services and events; and using carefully selected technology, including artificial intelligence tools, to support the delivery and quality of our services. We carry out a legitimate interests assessment for these uses and only proceed where our interests are not outweighed by your interests, rights and freedoms.
Consent Where we ask for it — for example, certain direct marketing by electronic means, or specific optional processing. You can withdraw consent at any time without affecting processing already carried out.
Recognised legitimate interests In limited cases we may rely on a “recognised legitimate interest” under Article 6(1)(ea) and Annex 1 to the UK GDPR (introduced by the Data (Use and Access) Act 2025) — for example, disclosing information to a public authority that needs it for its functions, or for the detection or prevention of crime. We do not rely on this basis for our routine client work.
Vital interests Rarely, to protect someone’s life or physical safety in an emergency.

3.1 Conditions for special category and criminal offence data

Where we process special category or criminal offence data, in addition to a lawful basis above we rely on one or more of the following conditions:

  • Legal claims or judicial acts — the processing is necessary for the establishment, exercise or defence of legal claims or whenever a court is acting in its judicial capacity (Article 9(2)(f); and, for criminal offence data, the corresponding Schedule 1 condition).
  • Substantial public interest — including the conditions in Schedule 1 to the Data Protection Act 2018 for the prevention and detection of unlawful acts, regulatory compliance, and preventing fraud (relevant to our AML, sanctions and conflict checks).
  • Explicit consent — where we have asked for and you have given it.
  • Employment, social security and social protection — for recruitment and any subsequent employment relationship.

4. Confidentiality and legal professional privilege

As a law firm, we owe our clients a professional duty of confidentiality under the SRA’s rules, and much of the information we hold about a matter is protected by legal professional privilege. These protections operate alongside data protection law and are not displaced by it.

This means that when we respond to requests under data protection law (see section 9), we will not disclose information that is privileged, that is subject to a duty of confidence owed to another client or third party, or where an exemption in the Data Protection Act 2018 applies. We handle every matter on the basis that what you tell us stays confidential, save where you authorise disclosure or we are required or permitted by law to disclose it.

5. Where we obtain personal information

We collect personal information:

  • directly from you, in correspondence, meetings, calls and the documents you provide;
  • from people acting for you or connected with your matter, such as other professional advisers, agents and intermediaries;
  • from other parties to a matter, courts and tribunals, and from documents disclosed during a matter;
  • from identity-verification, sanctions, PEP, credit and conflict-checking providers we use for client due diligence;
  • from publicly available sources and registers (for example Companies House, court records, professional and trade sources, and public online sources); and
  • from referees and, where relevant and lawful, vetting providers (for job applicants).

6. How long we keep personal information

We keep personal information only for as long as we need it for the purposes described in this notice, and to meet our legal, regulatory and professional obligations.

Record Typical retention period
Client matter files (general) Usually 7 years from the end of the matter (subject to limitation periods).
Matters where longer periods apply (e.g. property, wills, trusts, certain corporate/IP records) Longer fixed periods or indefinitely, as the matter type requires.
Client due diligence / AML records 5 years from the end of the business relationship or completion of the transaction (Money Laundering Regulations 2017).
Accounting and tax records At least 6 years.
Unsuccessful job applicants Usually 6–12 months after the recruitment decision.
Marketing contacts Until you opt out or the contact is no longer current.

When we no longer need personal information, we securely delete or anonymise it. For more information about our retention periods or the criteria we use, please contact us using the details in section 1.

7. Who we share personal information with

We share personal information only where necessary and with appropriate safeguards. Depending on the matter, recipients may include:

  • barristers, experts, agents, foreign lawyers and other professionals we instruct to act on your matter (with your authority);
  • courts, tribunals, other parties and their advisers, and registries, where required to progress or conclude a matter;
  • our IT, cloud, document-management and other service providers who process information on our behalf as our processors;
  • identity-verification, sanctions, PEP and conflict-checking providers used for client due diligence;
  • our auditors, insurers, brokers and professional advisers;
  • regulators and authorities where we are required or permitted to share, including the SRA, the ICO, the National Crime Agency and HMRC; and
  • a successor practice or purchaser if the firm is reorganised, merged or transferred (in which case confidentiality and data protection obligations continue to apply).

Processors and AI tools. Where a third party processes personal information on our behalf, we put a written contract in place requiring it to keep the information confidential and secure and to act only on our instructions. Given the nature of our practice, we require providers of cloud and AI-enabled services not to use client or matter information to train their models or for their own purposes, and to maintain confidentiality consistent with our professional duties.

8. Transferring personal information outside the UK

We store and process personal information in the UK and the European Economic Area (EEA) where possible. Where personal information is transferred outside the UK, we ensure an appropriate safeguard recognised by UK data protection law is in place, namely one of:

  • UK adequacy regulations — where the country, territory or sector has been assessed by the UK as providing adequate protection (this covers the EEA);
  • the UK–US “Data Bridge” (the UK Extension to the EU–US Data Privacy Framework) — where the US recipient is certified under that framework; or
  • the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment, where no adequacy route applies.

Our principal overseas-capable provider is set out below:

Recipient Role Location & safeguard
Microsoft Corporation and group companies (incl. Microsoft Ireland Operations Ltd) Cloud storage, productivity and office services (including any AI-enabled features) Primarily UK/EEA data centres. EEA transfers are covered by UK adequacy regulations; any transfer to the US relies on the UK–US Data Bridge and/or the IDTA.

9. Your data protection rights

Subject to the exemptions in data protection law (including those protecting privilege, confidentiality owed to others, and legal proceedings), you have the following rights:

  • Access — to ask for a copy of your personal information and related information.
  • Rectification — to ask us to correct inaccurate or incomplete information.
  • Erasure — to ask us to delete your information in certain circumstances.
  • Restriction — to ask us to limit how we use your information.
  • Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
  • Portability — to receive certain information you provided to us in a portable format.
  • Withdraw consent — where we rely on consent, to withdraw it at any time.

Which rights apply depends on the lawful basis we rely on. We will respond to a request without undue delay and within one month. We may extend this by up to two further months for complex or numerous requests, and we will tell you if we do. Where we reasonably need to confirm your identity or clarify the scope of your request, the time limit pauses until you provide what we have asked for (“stop the clock”). We are required to carry out reasonable and proportionate searches, not exhaustive ones. To make a request, contact us using the details in section 1. There is more about these rights and the applicable exemptions on the ICO’s website at ico.org.uk.

10. Use of artificial intelligence

We may use artificial intelligence tools to help us deliver and improve our services — for example, to organise documents, assist with research and drafting, and improve efficiency — always under the supervision of our lawyers. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without a lawful basis and appropriate safeguards, including the ability to obtain human review. AI tools we use are subject to the confidentiality and “no training on your data” requirements described in section 7.

11. Changes to this notice

We keep this notice under review and will update it when our practices or the law change. The version number and effective date appear at the top. Where changes are significant, we will take reasonable steps to bring them to your attention.

12. How to complain

If you have any concerns about how we have used your personal information, please contact us first using the details in section 1. You have a right to complain to us, and we will acknowledge your complaint within 30 days and respond as soon as we can. (This reflects the new statutory complaint-handling duties on controllers under the Data (Use and Access) Act 2025, in force from 19 June 2026.)

If you remain dissatisfied after raising your concern with us, you can complain to the Information Commissioner’s Office (ICO):

Post Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113
Website ico.org.uk/make-a-complaint