This Privacy Policy explains how Thornton Jones Solicitors Limited collects, uses, stores and shares personal data provided through our website. It is intended mainly for visitors to our website and people who contact us through our online forms. If you become a client, we will process a wider range of personal data and will provide further information through our Client Care Letter, Terms of Business and Data Protection and Privacy Statement for Clients.
Thornton Jones Solicitors Limited is the controller of the personal data covered by this policy. We are registered with the Information Commissioner’s Office under registration number Z2151779. Our Data Protection Officer is Molly Thornton and her email is molly@thorntonjones.co.uk. If you have any questions about this policy, or wish to exercise your data protection rights, please contact us using the contact details on our website.
Thornton Jones Solicitors Limited is owned by Thornton Jones Holdings Limited. Thornton Jones Solicitors Limited is authorised and regulated by the Solicitors Regulation Authority under SRA number 815236. Thornton Jones Holdings Limited is also authorised and regulated by the Solicitors Regulation Authority under SRA number 8014945.
Personal Data We Collect Through This Website
When you use this website, we may collect personal data that you choose to provide to us, such as your name, email address, telephone number and any information included in your enquiry. If you complete a website form, we will use the information you provide to respond to your enquiry and, where appropriate, to take steps at your request before entering into a contract for legal services.
If a form asks whether you would like to join a mailing list, we will only use your details for that purpose if you have actively opted in. You can unsubscribe or opt out of marketing communications at any time.
We may also collect limited technical information about how visitors use our website, such as device, browser and usage information, where this is collected through analytics or similar website tools.
How We Use Your Personal Data
We use the data you provide via this website to:
- respond to enquiries and communicate with you, for example by using your email address or telephone number to respond to a website enquiry;
- monitor and improve our website, for example by using analytics information to understand how visitors use the website and identify where improvements can be made;
- operate our business and protect our interests, for example by keeping appropriate records, dealing with feedback, preventing misuse of our website and maintaining information security.
Our Lawful Bases for Processing Personal Data
We process personal data only where we have a lawful basis to do so under the UK GDPR and the Data Protection Act 2018. Depending on the circumstances, we may rely on one or more of the following lawful bases: your consent, where you have opted in to receive marketing; taking steps at your request before entering into a contract, where you contact us about potential legal services; compliance with a legal or regulatory obligation; and our legitimate interests, including responding to enquiries, operating and improving our website, maintaining appropriate business records and protecting the security of our systems. Where we rely on consent, you may withdraw that consent at any time.
How Long We Keep Personal Data
Website enquiry data may be retained for as long as reasonably necessary to respond to your enquiry, manage any follow-up, keep appropriate business records and comply with any legal or regulatory obligations. If your enquiry leads to a client matter, your personal data will be retained in accordance with our client file retention periods, Law Society guidance, regulatory requirements and relevant legislation. Some website technical data may be retained for shorter periods depending on the relevant website or analytics tool.
Sharing and Transfer of Personal Data
We may share personal data with trusted service providers who help us operate our website, manage enquiries, provide IT, hosting, analytics, marketing or professional services, or otherwise support the running of our business. We may also share personal data where required by law, by our regulators, by a court or tribunal, or where necessary to provide legal services if you become a client. Where we use third-party service providers, we require them to protect personal data and only process it for authorised purposes. If personal data is transferred outside the UK, we will ensure that an appropriate UK GDPR transfer mechanism is in place, such as UK adequacy regulations or appropriate safeguards.
Security
We have appropriate technical and organisational measures in place to protect personal data against accidental loss, unauthorised access, alteration or disclosure. Access to personal data is limited to those who need it for legitimate business purposes, and staff and relevant service providers are subject to confidentiality obligations. We have procedures in place to deal with suspected personal data breaches and will notify affected individuals and the ICO where we are legally required to do so.
Your Rights, Questions and Complaints
You have rights under data protection law, which may include the right to request access to your personal data, correction of inaccurate data, erasure, restriction of processing, objection to processing, data portability and withdrawal of consent where we rely on consent. These rights do not apply in every circumstance, particularly where personal data must be retained for legal, regulatory or professional reasons. If you have any questions, wish to exercise your rights, or have concerns about how we handle your personal data, please contact our Data Protection Officer in the first instance. If you wish to make a complaint about how we have handled your personal data, please see our Data Protection Complaints Policy, which explains how we will investigate and respond to data protection complaints. You also have the right to complain to the Information Commissioner’s Office: https://ico.org.uk/concerns/
Cybercrime and Email Security
Please be aware that email accounts can be targeted by criminals. We will never notify you of changes to our bank details by email or other electronic means. If you receive any communication suggesting our bank details have changed, or asking you to send money to a different account, please contact us immediately using a verified telephone number from our website. We will also take steps to verify bank details provided to us before making payments. Email is not always secure, so please tell us if you do not want us to communicate with you by email or if you require particular security arrangements.
Our Use of Google Analytics
We use Google Analytics to monitor how our website is being used so we can make improvements. Our use of Google Analytics requires us to pass to Google your IP address (We may use Google Analytics or similar website analytics tools to understand how visitors use our website and to help us improve it. These tools may collect information such as IP address, device, browser and website usage information. Where required, we will obtain consent for non-essential cookies or similar technologies. You can manage cookies through your browser settings and any cookie controls available on our website. Related information:
Mediation Privacy Statement
This section applies where we provide mediation services.
For the purpose of mediation, we will keep information you provide to us securely and will not share it without your permission unless we are required or permitted to do so by law, regulation, professional obligation, or in connection with a complaint. If a complaint is referred to a regulator or relevant complaints handling organisation, your agreement to mediate will include your agreement that we may release relevant information or your file to that body for the purpose of resolving the complaint.
Our quality assurance standards may require monitoring of mediation files. From time to time, our practice consultant, professional practice consultant or supervisor may review files on a strictly confidential basis. Access is controlled, and any review will be carried out subject to appropriate confidentiality obligations. Anonymised information about mediation cases may also be used for training, quality assurance, research or statistical purposes, provided individuals cannot be identified.
We will retain mediation information for as long as necessary in connection with the mediation, any agreement to mediate, any complaint or regulatory requirement, and our legal or professional obligations. Where information is retained for research or statistical purposes, it will be anonymised where appropriate so that individuals cannot be identified.






