1. Who we are
This site is operated by LawFirmWebDesign.co ("we", "us", "our") — a web design and SEO agency that builds websites exclusively for law firms in the United States and United Kingdom. For data protection purposes we are the data controller. If you have any questions about this policy or your data, email us at hello@lawfirmwebdesign.co.
2. What data we collect
We only collect what we actually need to help you. That means:
- Information you give us — your name, email, phone number, firm name, and any details you share when you fill in our contact form, book a call, or email us.
- Information collected automatically — your IP address, browser type, device, pages viewed, time on site, and referring URL. We use this to understand how the site is performing.
- Cookies — small files stored on your device. See section 6 below.
We do not ask for or store sensitive personal data (like financial details, health, or anything similar) through this website.
3. Why we collect it
We use your data for these specific purposes:
- To respond to your enquiry and quote your project.
- To deliver the work you have hired us for.
- To send you proposals, invoices, and project updates.
- To improve the site and the way we serve law firms.
- To send occasional emails about our services, but only if you have opted in. You can unsubscribe at any time with one click.
4. Confidentiality of client materials
We recognise that our clients are law firms that handle legally privileged and confidential information. We do not access, review, or process any privileged client data held by your firm. The materials you share with us in connection with your website project — such as practice area descriptions, attorney biographies, and brand assets — are treated as strictly confidential and are used solely to deliver the agreed work. We will never disclose them to third parties except where necessary to operate the project (e.g. a hosting provider) and only under appropriate confidentiality obligations.
5. Lawful basis for processing
For UK clients, we process your data under UK GDPR on one of these grounds: contract (when you have hired us), legitimate interest (responding to enquiries, running the business, improving the site), consent (marketing emails, non-essential cookies), and legal obligation (HMRC, accounting records). For US clients, we comply with applicable US state privacy laws (including California CCPA where relevant) and handle your data with the same care and transparency described in this policy.
6. Who we share it with
We do not sell your data. Ever. We share it only with trusted suppliers who help us run the business:
- Email and CRM tools (e.g. Google Workspace, HubSpot)
- Hosting and analytics providers (e.g. Vercel, Google Analytics)
- Payment and accounting providers (e.g. Stripe, Xero)
- Government bodies in the UK or US if legally required
Where any provider is based outside the UK or EU, we ensure the transfer is covered by appropriate safeguards (e.g. Standard Contractual Clauses).
7. Cookies
We use a small number of cookies to keep the site working and to understand traffic.
- Essential cookies — required for the site to function. These cannot be turned off.
- Analytics cookies — used to count visits and see which pages perform. Anonymised. Set only if you accept.
- Marketing cookies — only used if you fill in a form or click through from a paid ad. You can decline these.
You can clear or block cookies any time from your browser settings. Doing so might break parts of the site.
8. How long we keep it
Enquiry data: up to 24 months from your last interaction. Client records: 7 years after the engagement ends (in line with UK tax law; comparable retention periods apply for US records). Analytics: rolled-up indefinitely, but never tied to identifying details.
9. Your rights
UK clients have rights under UK GDPR, including the right to:
- Ask for a copy of the data we hold on you
- Correct anything inaccurate
- Ask us to delete it (where we do not need it for legal reasons)
- Object to processing or ask us to restrict it
- Withdraw consent at any time
- Lodge a complaint with the ICO at ico.org.uk
US clients may have additional rights under applicable state law (e.g. the right to know, delete, or opt out of sale under CCPA). To exercise any of these rights, email hello@lawfirmwebdesign.co. We will respond within 30 days.
10. How we keep your data safe
Encrypted connections (HTTPS), strong passwords with two-factor auth, access on a need-to-know basis, and reputable suppliers. We cannot promise the internet is 100% safe — nobody can — but we treat your data the way we would want ours treated.
11. Changes to this policy
If we change this policy we will update the "Last updated" date at the top. For any material change we will email anyone we have an active relationship with.
12. Contact
Questions? Concerns? Email hello@lawfirmwebdesign.co.