Privacy Notice

How RM Clayton collects, uses and protects your personal information

Last updated: April 2026

Please read this notice carefully. It explains who we are, what personal information we collect, why we collect it, how we use it, how long we keep it, how we protect it, and your rights.

1.- Who We Are

RM Clayton Limited is a solicitors’ practice authorised and regulated by the Solicitors Regulation Authority.

Company number: 17051434
SRA number: 8015547
ICO registration number: ZC178203
Registered office: 1 Broad View, Great Orton, Carlisle, Cumbria, CA5 6LY
Website: 
rmclayton.co.uk

RM Clayton Limited is the data controller for the personal data we process.

We process personal data in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, and other applicable data protection and privacy laws.

2.- Data Protection Contact

For data protection enquiries, or to exercise any of your rights, please contact:

Christopher Clayton
Email: 
chris@rmclayton.co.uk

We are not required to appoint a Data Protection Officer. Data protection enquiries should be directed to the contact above.

3.- Personal Information We Collect

The personal information we collect depends on the nature of your enquiry, matter or relationship with us. It may include:

Information you provide directly

  • your name, address, email address and telephone number;

  • date of birth and identity information;

  • identity documents, such as a passport or driving licence;

  • proof of address;

  • financial information relevant to your matter, including source of funds information where required;

  • details of your dispute, transaction, claim, legal issue or matter;

  • correspondence, instructions, documents and evidence you provide to us;

  • billing and payment information;

  • information about your preferences and how you wish us to communicate with you; and

  • any other information you choose to provide.

Information we obtain from third parties

We may obtain personal information from third parties where relevant to your matter, our legal services, our regulatory obligations, or the operation of our business. This may include information from:

  • opposing parties and their legal representatives;

  • courts, tribunals and other dispute resolution bodies;

  • barristers, experts, witnesses and other professionals;

  • regulators, public authorities and law enforcement bodies;

  • public registers and public sources, including Companies House, HM Land Registry, the Individual Insolvency Register and similar sources;

  • financial institutions and payment providers where relevant;

  • identity verification and anti-money laundering providers, including InfoTrack;

  • insurers, accountants and other professional advisers;

  • your employer, business, agents, representatives or referrers, where relevant; and

  • online or professional platforms, including LinkedIn or similar platforms.

Website, communications and marketing information

We may collect information when you use our website, contact us by email, subscribe to our newsletter or engage with our content. This may include:

  • information submitted through website forms;

  • email and communication metadata;

  • newsletter subscription and marketing preference information;

  • website usage information;

  • device, browser and cookie information; and

  • professional or business contact details.

4.- Why We Use Your Personal Information and Our Lawful Bases

We only use personal information where we have a lawful basis to do so. The main lawful bases we rely on are:

  • contract: where processing is necessary to enter into or perform a contract with you;

  • legal obligation: where we need to comply with legal, regulatory or professional obligations;

  • legitimate interests: where processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms;

  • consent: where we ask for and rely on your consent; and

  • legal claims: where processing is necessary for the establishment, exercise or defence of legal claims.

We use personal information for the following purposes:

Purpose

Examples of data used

Lawful basis

Responding to enquiries

Contact details, enquiry details, communications

Legitimate interests; steps before entering into a contract

Opening and managing your matter

Contact details, identity details, matter information, instructions, correspondence

Contract; legitimate interests

Providing legal advice and representation

Matter information, evidence, legal documents, correspondence, financial information

Contract; legitimate interests; legal claims

Verifying identity and carrying out anti-money laundering, sanctions and conflict checks

Identity documents, proof of address, date of birth, financial and source of funds information

Legal obligation; legitimate interests

Communicating with you and others involved in your matter

Contact details, correspondence, matter information

Contract; legitimate interests; legal claims

Managing billing, payments and accounting

Billing details, payment information, matter details, accounting records

Contract; legal obligation; legitimate interests

Complying with SRA, court, tax, accounting, anti-money laundering and other legal or regulatory obligations

Identity, financial, matter, billing and compliance information

Legal obligation; legitimate interests

Managing complaints, disputes, claims or regulatory enquiries

Matter information, complaint correspondance, file records, communications

Legal obligation; legitimate interests; legal claims

Maintaining professional indemnity insurance and dealing with insurers

Matter information, claims or complaints information, file records

Legal obligation; legitimate interests; legal claims

Managing and improving our business, systems and services

Communications, usage information, business records

Legitimate interests

Website operation, security and analytics

Device information, cookie data, usage information

Legitimate interests; consent where required for non-essential cookies

Sending newsletters, legal updates and marketing communications

Contact details, marketing preferences, engagement information

Consent or legitimate interests, depending on the communication and applicable law

Where we rely on legitimate interests, our interests may include providing and managing legal services, running our business efficiently, protecting our legal rights, maintaining accurate records, securing our systems, improving our services, preventing fraud, complying with professional standards, and communicating with clients and professional contacts.

If you do not provide information that we reasonably require, we may be unable to act for you, continue acting for you, comply with our legal or regulatory obligations, verify your identity, carry out required checks, or provide the services you have requested.

5.- Special Category Data

Some matters may involve special category data. This is more sensitive personal information and may include information about:

  • health, medical conditions or disability;

  • racial or ethnic origin;

  • political opinions;

  • religious or philosophical beliefs;

  • trade union membership;

  • sex life or sexual orientation;

  • genetic data; or

  • biometric data used for identification purposes.

We will only process special category data where it is relevant and lawful to do so. This may include where processing is necessary for the establishment, exercise or defence of legal claims, where it is necessary for legal advice or legal proceedings, where we have your explicit consent, or where another condition under data protection law applies.

6.- Criminal Offence Data

Some matters may involve information about criminal allegations, offences, proceedings, convictions, cautions, penalties, sanctions, regulatory breaches or related security measures.

We will only process this type of information where it is relevant to your matter, our legal services, anti-money laundering or sanctions checks, regulatory obligations, risk management, or the establishment, exercise or defence of legal claims, and where permitted by data protection law.

7.- Who We Share Your Information With

We may share personal information where necessary for your matter, our legal services, our legal or regulatory obligations, or the operation of our business. This may include sharing information with:

  • barristers, experts, witnesses and other professionals;

  • courts, tribunals, mediators, arbitrators and other dispute resolution bodies;

  • opposing parties and their legal representatives;

  • regulators, public authorities, law enforcement bodies and tax authorities;

  • professional indemnity insurers, brokers, accountants and auditors;

  • identity verification, anti-money laundering and search providers, including InfoTrack;

  • IT, software, cloud and practice management providers, including Microsoft 365ClioXeroDropbox and OneDrive;

  • banks, payment providers and other financial institutions where relevant;

  • document production, storage, secure destruction and archiving providers, if used;

  • website, hosting, analytics and marketing providers; and

  • other third parties where you authorise us to share information, or where sharing is necessary or permitted by law.

We only share personal information where we have a proper reason to do so. We do not sell your personal information.

8.- International Transfers

We do not intentionally transfer client personal data outside the United Kingdom as part of our ordinary practice.

Some of our technology, cloud, software, communications, analytics or marketing providers may, however, process or access limited personal data outside the UK through their systems, support arrangements or sub-processors.

Where personal data is transferred outside the UK, we will take steps to ensure that appropriate safeguards are in place. These may include:

  • UK adequacy regulations;

  • the UK International Data Transfer Agreement;

  • the UK Addendum to the EU Standard Contractual Clauses;

  • contractual commitments with service providers; or

  • another lawful transfer mechanism under UK data protection law.

You may contact us if you would like further information about any relevant international transfer safeguards.

9.- How Long We Keep Your Personal Information

We keep personal information only for as long as necessary for the purposes for which it was collected, including to provide legal services, comply with legal and regulatory obligations, deal with complaints or claims, maintain records, and protect our legal rights.

We do not generally maintain paper files. Closed matter files are ordinarily archived electronically.

Our usual retention periods are:

Type of information

Usual retention period

Client matter files

Usually 6 years after the matter closes

Anti-money laundering, identity verification and source of funds records

Usually 5 years after the end of the business relationship or relevant transaction, unless a longer period is required or permitted

Financial, accounting, billing and tax records

Usually 6 years

Complaints, claims, regulatory or insurance records

Usually 6 years, or longer where needed for legal, regulatory, professional indemnity insurance or risk management reasons

Matters involving minors, capacity issues, long-tail risk or potential future claims

Longer where appropriate, depending on the circumstances

General enquiries where no matter is opened

Usually up to 2 years

Marketing records

Until you unsubscribe or object, with limited suppression records retained to ensure we respect your preferences

We may keep information for longer where required or appropriate because of limitation periods, legal proceedings, regulatory obligations, professional indemnity insurance, complaints, claims, fraud prevention, professional duties, or other legal reasons.

10.- Security

We take appropriate technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include:

  • secure cloud and practice management systems;

  • access controls and password protection;

  • multi-factor authentication where appropriate;

  • encryption and secure transmission where appropriate;

  • secure electronic storage and archiving;

  • staff confidentiality obligations;

  • procedures for handling data protection incidents; and

  • regular review of our systems and providers.

If a personal data breach occurs, we will assess it promptly. Where required, we will report a notifiable breach to the Information Commissioner’s Office within 72 hours of becoming aware of it and will notify affected individuals where required by law.

11.- Your Rights

Subject to certain conditions and exemptions, you have the following rights under UK data protection law:

  • right of access: to request a copy of the personal information we hold about you;

  • right to rectification: to ask us to correct inaccurate or incomplete information;

  • right to erasure: to ask us to delete personal information in certain circumstances;

  • right to restrict processing: to ask us to restrict how we use your information in certain circumstances;

  • right to data portability: to receive certain information in a structured, commonly used and machine-readable format, where applicable;

  • right to object: to object to processing based on legitimate interests in certain circumstances;

  • right to object to direct marketing: to object to direct marketing at any time;

  • right to withdraw consent: where we rely on consent, to withdraw that consent at any time; and

  • rights relating to automated decision-making: to rights in relation to solely automated decision-making, including profiling, where this has legal or similarly significant effects.

If you withdraw consent, this will not affect the lawfulness of processing carried out before consent was withdrawn.

Some rights may not apply in all circumstances. For example, we may need to retain certain information to comply with legal or regulatory obligations, maintain legal professional privilege, or establish, exercise or defend legal claims.

We will usually respond to rights requests within one month. If a request is complex or if you make multiple requests, we may extend the response period where permitted by law. We may ask you to verify your identity before responding.

12.- Automated Decision-Making

We do not use your personal information for solely automated decision-making, including profiling, that produces legal or similarly significant effects.

13.- Cookies and Similar Technologies

Our website may use cookies and similar technologies to operate the website, understand how it is used, improve performance, and support marketing or analytics.

Some cookies are necessary for the website to function. We may also use non-essential cookies, such as analytics or marketing cookies, but only where permitted by law and, where required, with your consent.

Non-essential cookies may include, for example:

  • analytics cookies;

  • performance cookies;

  • functionality cookies;

  • marketing or advertising cookies;

  • embedded content cookies; or

  • third-party cookies set by website tools or integrations.

You can manage cookies through your browser settings and, where available, through the cookie preference tools on our website.

Further cookie details, including the specific cookies used, their purposes and their duration, should be set out in our website cookie banner or cookie policy.

14.- Marketing and Newsletters

If you subscribe to our newsletter, request updates, engage with our content, or are an existing client or professional contact, we may send you legal updates, invitations, newsletters or information about our services.

We will only send marketing communications where we are permitted to do so under data protection and electronic marketing laws. Depending on the circumstances, we may rely on your consent or our legitimate interests.

You have an absolute right to object to direct marketing at any time. You can unsubscribe or change your marketing preferences by using the unsubscribe link in our communications, where available, or by contacting us at chris@rmclayton.co.uk.

We do not sell your personal information for marketing purposes.

Newsletter platform: [insert platform/provider, if applicable]

15.- Client Money

RM Clayton Limited does not operate a client account and does not hold client money.

16.- Complaints

If you have concerns about how we handle your personal information, please contact us first so that we can try to resolve the issue.

You also have the right to complain to the Information Commissioner’s Office at any time.

ICO contact details:

Website: www.ico.org.uk
Telephone: 0303 123 1113
Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

17.- Changes to This Notice

We may update this privacy notice from time to time. The latest version will be available on our website.

18.- Contact

RM Clayton Limited
1 Broad View
Great Orton
Carlisle
Cumbria
CA5 6LY

Email: chris@rmclayton.co.uk
Website: 
rmclayton.co.uk