PRIVACY NOTICE
Last updated: 17 June, 2026

Executive Summary

MIT Lawyers respects your privacy. This Website Privacy Policy applies only to users of this website and explains how we collect, use and protect personal data when you use our website.

The majority of the personal information collected by us is provided by you voluntarily on the MIT Lawyers website, for example when you use our website contact form, and is therefore collected with your permission. The remaining personal information is collected for MIT lawyers’ legitimate business purposes, for example to monitor and improve the quality of our website and our services, and to protect and defend our rights, property or safety of users of our website.

We also use only strictly necessary cookies and limited technical measures required to operate and secure the website. We do not use analytics, advertising or social media cookies on this website.

We use your personal data to respond to your enquiry, consider whether we can assist you, protect the website and our systems, and comply with applicable legal, regulatory and professional obligations.

If you have any privacy questions, please contact us using the details in the Contact Us section below.

Who We Are

MIT Lawyers is the controller of personal data collected through this website.

Legal entity name: MIT LAWYERS LTD
Trading name: MIT Lawyers
Registered address: 4th Floor Office, 205 Regent Street, London, England, W1B 4HB
Data protection contact ceo@mit-lawyers.com

Scope of This Policy

This Website Privacy Policy applies only to personal data collected from users of this website, including information submitted through our website contact form and data generated by strictly necessary cookies and basic website security tools.

If you send us an enquiry through this website, that does not automatically create a solicitor-client relationship.

Personal Data We Collect

If you use our website contact form, we collect:
  • your full name;
  • your telephone number;
  • your email address;
And we may also collect the contents of your message.

We may also process limited technical data strictly necessary to operate and secure the website, such as IP address, browser metadata, device information and server logs, where generated by your browser or our hosting environment.

We do not intentionally ask you to provide unnecessary personal data through the website.

How We Use Personal Data. Our Purposes and Lawful Bases
Purpose
Personal data used
Lawful basis and why we do this
To communicate with you about your enquiry submitted through the website contact form
Name, email address, telephone number, message content
Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).
Legitimate interest(s): responding to enquiries and messages we receive and keeping records of correspondence.


To comply with legal or regulatory obligations
Any personal data reasonably required for that purpose
Legal basis for processing: processing is necessary for compliance with a legal obligation to which the controller is subject (Article 6(1)(c) of the General Data Protection Regulation).
We may do this to comply with applicable law, regulation, court orders or professional rules.
To operate and protect the security of our website
Technical information such as server logs and IT security records
Legal basis for processing: compliance with a legal obligation to which we are subject (Article 6(1)(c) of the General Data Protection Regulation).
Legal obligation: we have a legal obligation to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of our processing of information about individuals.
Legal basis for processing: our and a third party’s legitimate interest (Article 6(1)(f) of the General Data Protection Regulation).
Legitimate interests: we have a legitimate interest in using your information for the purposes of ensuring network and information security.



Website operation and improvement
We may collect and use only strictly necessary technical cookies and similar technologies that are required for the website to function properly, maintain security, remember essential settings, and support basic website operations.
Legal basis for processing: our and a third party’s legitimate interest (Article 6(1)(f) of the General Data Protection Regulation).
Legitimate interests: we have a legitimate interest in using your information for the purposes of ensuring network and information security.



Where we rely on legitimate interests, those interests are to respond to enquiries, manage and secure our website and communications, carry out basic conflict and suitability checks, prevent misuse or fraud, and maintain records necessary to run our practice responsibly.

You are not under a statutory obligation to provide personal data through our website contact form. However, if you do not provide the information marked as required, we may be unable to respond to your enquiry.

Special Category Data and Criminal Offence Data

Please do not send special category or criminal offence data through the initial contact form unless it is necessary. If you do, we will only process it where we can do so lawfully under Article 6 and, where applicable, Article 9 or Article 10 UK GDPR and relevant UK law.

Cookies and Similar Technologies

We use only strictly necessary cookies and similar technologies, required to operate and secure the website. These may include session cookies, security cookies, load-balancing cookies and cookies used to remember basic technical settings.

Because these cookies are strictly necessary, they do not require consent under PECR.

We do not use analytics, advertising or social media cookies on this website.

If you block strictly necessary cookies in your browser, some parts of the website may not function properly.

Who We Share Personal Data With

We may share personal data, where necessary, with service providers acting on our behalf, such as:
  • website hosting providers;
  • business email providers;
  • IT support and cyber security providers; and
  • website platform or contact form providers, where applicable.
We require processors to process personal data only on our instructions, keep it secure, and use authorised sub-processors only under written contractual controls.

We may also disclose personal data where required to comply with law, regulation, court order, professional obligations, or to establish, exercise or defend legal claims.

We do not sell personal data.

International Transfers

We assume that personal data collected through this website is processed in the United Kingdom only. We do not transfer personal data outside the UK.

Marketing

We do not use website enquiry data for marketing emails or text messages unless you separately opt in or another lawful PECR-compliant basis applies. If we introduce a newsletter later, we will seek separate opt-in where required.

Retention

We keep personal data only for as long as necessary for the purposes explained in this policy.

Our current retention periods for website-user data are as follows:

Data / record type

Retention period

General website enquiries

Up to 12 months after our last substantive contact with you

Basic conflict-check and prospective matter screening records

Up to 6 years where needed to protect the firm and its clients and to establish, exercise or defend legal claims

Website security logs

Typically up to 30 days, unless longer retention is needed for security investigations, incidents or legal claims

Strictly necessary cookies

Session-only or for the period stated by the relevant cookie, depending on technical function


If your enquiry becomes a client matter or formal prospective client file, a separate retention period may apply under our client-facing privacy information and professional obligations.

Security

We use appropriate technical and organizational measures designed to protect personal data, including secure website transmission, access controls, least-privilege permissions, backup and recovery measures, and contractual safeguards with service providers.

However, no method of transmission or storage is completely secure. If we become aware of a personal data breach, we will deal with it in accordance with applicable law and our internal incident procedures.

Your Rights

Under the UK GDPR, you have various rights in relation to your Personal Information, such as the rights of access, correction, rectification, restriction, objection, portability, and erasure. Please note that these rights are subject to certain limitations set forth in applicable law.

For further information about your rights in relation to your information, including any limitations which apply, please visit the following pages on the ICO’s website:

https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/; and https://ico.org.uk/your-data-matters/

You can also find out further information about your rights, as well as information on any limitations which apply to those rights, by reading the underlying legislation contained in Articles 12 to 22 and 34 of the General Data Protection Regulation, which is available here: http://ec.europa.eu/justice/data-protection/reform/files/regulation_oj_en.pdf

To exercise these rights, please contact our Data Protection contact. We will seek to deal with your request without undue delay, and in any event in accordance with the requirements of applicable laws. Please note that we may keep a record of your communications to help us resolve any issues you raise.

Automated Decision-Making and Profiling

We do not use your website enquiry data for solely automated decision-making that produces legal or similarly significant effects.

We do not use website enquiry data for profiling or targeted advertising.

Children

We are committed to complying with the Children's Online Privacy Protection Act (COPPA). Our website and services are not directed to children under the age of 16. We do not knowingly collect personal information from children under the age of 16. If we receive personal information that we discover was provided by a child under the age of 16, we will promptly destroy such information. Schools and parents should supervise their children's online activities and consider the use of other means to provide a child-friendly online environment. Additional information is available on the Direct Marketing Association's home page at https://dma.org.uk/. If you would like to learn more about COPPA, visit the Federal Trade Commission home page at http://www.ftc.gov

Complaints

If you are unhappy with how we use your personal data, we would appreciate the opportunity to address your concerns first.

You also have the right to complain to the UK Information Commissioner’s Office (ICO) through its online complaint service.

Changes to This Policy

We may update this Website Privacy Policy from time to time. We will post the current version on this page and update the “Last updated” date above.

Contact Us

If you have any questions about this Website Privacy Policy or wish to exercise your rights, please contact:

MIT Lawyers
Legal entity name: MIT LAWYERS LTD
Address: 4th Floor Office, 205 Regent Street, London, England, W1B 4HB
Data protection contact: ceo@mit-lawyers.com