Privacy Notice
/privacy·Effective from: [go-live date]·Version 0.1 (draft)
1.1 Who we are
This privacy notice explains how Acer Prime Law Limited handles personal data through the Premier Trust Corporation Ltd client relationship and case management system (the “PTC CRM”). We use the CRM to administer trusts, keep client due-diligence records, run the trust ledger and produce fee notes and statutory filings.
| Controller | Acer Prime Law Limited |
|---|---|
| Registered office | [Registered office address — TO CONFIRM] |
| Companies House number | 10558502 |
| SRA authorisation number | 637478 |
| ICO registration | Registration in progress — number pending |
| How to contact us about data | privacy@acerprimelaw.co.uk |
| Postal address for data queries | [Postal address — TO CONFIRM] |
Where we act as trustee (or where a Premier Trust Corporation Ltd trust holds data about beneficiaries and third parties), Premier Trust Corporation Ltd is a joint controller with us for that limited purpose. Acer Prime Law Limited provides the CRM as processor to the trust; the trustees remain accountable for trustee decisions.
1.2 Categories of personal data we hold
Depending on your relationship with us, we may hold:
- Identity and contact data (name, former names, date of birth, nationality, address, phone, email).
- Identity-verification data (passport or driving-licence images, NI number, tax-residence information, source-of-funds evidence).
- Anti-money-laundering and sanctions data (PEP status, sanctions-screening results, risk ratings and narrative, CDD approval status).
- Financial data (bank details, trust ledger transactions, fee-note history, valuations of trust assets).
- Instruction and matter data (attendance notes, correspondence, documents you upload, task history).
- Access data (log-in identifiers, session logs, IP addresses and browser information generated while you use the CRM).
We do not process special category data (health, biometric, religious belief, and so on) except where it appears incidentally in trust papers we already hold for legitimate legal reasons — for example, a settlor’s letter of wishes that mentions a beneficiary’s illness. We treat such data with the same care as other trust material.
1.3 Where the data comes from
- Directly from you when you instruct us, upload documents, or complete forms.
- From colleagues within Acer Prime Law and the trustee company acting on the same matter.
- From publicly available sources (Companies House, HM Land Registry, the FCA and SRA registers, court judgments).
- From regulated data providers used for sanctions and PEP screening.
- From your other professional advisers (accountant, IFA, previous solicitor) where you have asked us to correspond with them.
1.4 Why we use the data (purposes and lawful bases)
| Purpose | Categories used | Lawful basis (UK GDPR) | Notes |
|---|---|---|---|
| Providing legal and trustee services | Identity, matter, financial | Contract (Art. 6(1)(b)) | Cannot administer a trust or draft a will without these. |
| Meeting our anti-money-laundering, sanctions and tax obligations | Identity, AML, financial | Legal obligation (Art. 6(1)(c)); public interest (Art. 6(1)(e)) | Money Laundering Regulations 2017, Proceeds of Crime Act 2002, Sanctions and Anti-Money Laundering Act 2018. |
| Filing with HMRC (TRS) and other statutory bodies | Identity, AML, financial | Legal obligation (Art. 6(1)(c)) | Trust Registration Service submissions and annual updates. |
| Billing and accounting | Identity, financial, matter | Contract; legal obligation for VAT/records | — |
| Keeping the CRM secure and auditable | Access data, matter | Legitimate interests (Art. 6(1)(f)) | Security logging, audit trail, prevention of unauthorised access. |
| Responding to complaints, professional-conduct enquiries and litigation | All categories as necessary | Legal obligation; legitimate interests | — |
| Marketing our services to existing clients | Contact | Legitimate interests, with opt-out | We do not send marketing to new prospects without consent. |
For any special category data that appears incidentally, we rely on Article 9(2)(f) (legal claims), Article 9(2)(g) (substantial public interest — legal services), or your explicit consent where none of those applies.
1.5 Who we share the data with
- The trustees of the trust you are connected to (where relevant to the administration of that trust).
- HMRC, the Land Registry, Companies House and other government bodies where legally required.
- Our regulator, the Solicitors Regulation Authority, and its inspectors.
- Our professional indemnity insurers and their advisers, in the event of a claim or potential claim.
- Auditors, accountants and IT service providers under written contracts requiring confidentiality.
- The core processors listed in the Data Processing Summary — currently Supabase (database and authentication), Vercel (hosting), Resend (transactional email) and Deepgram (voice-note transcription, only when a fee earner initiates it).
- Sanctions and PEP screening providers.
- Third parties in the context of a corporate transaction (for example, if the firm is sold or merged) — in that case we require the buyer to honour this notice.
We do not sell personal data. We do not use it for automated decision-making that has a legal effect on you.
1.6 International transfers
Personal data is stored on servers within the United Kingdom or the European Economic Area wherever technically possible. Some processors (for example, cloud infrastructure and transcription providers) may be based in or route traffic through the United States. Where that happens we rely on the International Data Transfer Addendum to the EU Standard Contractual Clauses, or on an equivalent transfer mechanism recognised by the ICO. Details for each processor are set out in the Data Processing Summary.
1.7 How long we keep the data
We keep personal data for the periods required by:
- Solicitors Regulation Authority rules and our own file-retention policy — typically seven years after a matter closes, longer for trust files.
- The Money Laundering Regulations 2017 — five years from the end of the business relationship.
- HMRC record-keeping rules — typically six years from the end of the accounting period.
For trust matters, we keep records for the life of the trust plus at least twelve years, because trustee liability can extend that far. Where periods differ, the longest applicable period applies. After that period the data is either destroyed or securely archived offline.
1.8 Your rights
Under UK GDPR you have the right to:
- Ask for a copy of the personal data we hold about you (a “subject access request”).
- Ask us to correct data that is inaccurate.
- Ask us to delete data where we no longer have a lawful basis to hold it (this is limited by our regulatory retention duties).
- Ask us to restrict processing while an issue is investigated.
- Object to processing based on our legitimate interests.
- Data portability, where the processing is based on your consent or on a contract with you and is carried out automatically.
- Withdraw consent, where processing is based on consent.
To exercise any of these rights, please email privacy@acerprimelaw.co.uk. We will respond within one month; that can be extended by up to two further months for complex requests, and we will tell you if that happens.
If you are unhappy with how we have handled your data, please contact us first so we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office — ico.org.uk or 0303 123 1113.
1.9 Security and breach notification
The CRM is encrypted in transit and at rest. Access requires multi-factor authentication where the underlying identity provider supports it, and all activity on trust data is logged. We test our access controls at least once a year. If we experience a personal-data breach that is likely to result in a risk to you, we will notify you and the ICO in line with UK GDPR Articles 33 and 34.
1.10 Changes to this notice
We may update this notice from time to time. The “Effective from” date at the top will always show when the current version came into force. Material changes will be flagged inside the CRM at next log-in and, where appropriate, by email.
