1. ABOUT USSteelRose is managed and operated by a sole practitioner. We are committed to safeguarding the privacy of the personal information that is provided to us or collected by us during the course of our business as well as the personal information we receive from visitors (if any) to our website (the “Website”). SteelRose is the data controller in relation to the activities described below in section 2. This means that we decide why and how your personal information is processed. Our registered address is 5.07 Chancery House, 53-64 Chancery Lane, London, WC2A 1 QS.
This Privacy notice explains when and why we collect and use personal information about you and your rights in relation to that information. It is based on European Union (EU) and UK data protection laws/principles that are set out in the General Data Protection Regulation.
We may provide you with additional, specific privacy notices where we believe that it is appropriate to do so. To the extent that any of that information differs from what we say below, those specific statements will apply in those circumstances.
This Privacy notice applies in the following circumstances:
- when we conduct open-source searches on you in connection with our business development or business acceptance processes;
- when we agree to provide legal services to you or the organisation you work for;
- when you or the organisation you work for are a counterparty of one or more of our clients;
- when you request information from us or provide information to us;
- when you apply for a role or work experience opportunity, open day or insight event with us;
- when you visit our website; or
- when you complete application forms on various sections of our Website (if any).
3. WHAT INFORMATION DO WE COLLECT ABOUT YOU AND HOW?3.1 Business development and business acceptance
We collect personal information about prospective clients and their beneficial owners, controllers and/or directors as part of business development initiatives and our business acceptance process. The type of personal information we may collect includes name, address, nationality, business interests and employment history. We may obtain this information from publicly available open sources either directly or through a third party.
3.2 Legal services and keeping you up to date with relevant marketing
The type of personal information that we may collect includes current and historical information including your name and contact details (such as your address, email address and telephone numbers) and identifiers such as your organisation, employment history and positions held. We will also collect personal information you choose to provide to us directly, or, for example, through your use of our Apps or other online services, and information about your other dealings with us and our clients, including contact we have with you in person, by telephone, letter, email or online. This information may include access or dietary requirements which may reveal information about your health or religious beliefs. We obtain personal information from your IP address and the operating system and web browser that you use to access our Website. It enables us to identify which organisations have visited our Website and we use this information to compile statistical data on the use of those sites to help us to improve the user experience.
We collect personal information directly from you, from our clients or other parties to a matter and their authorised representatives. We may also collect personal information from third parties such as your employer, other organisations that you have dealings with, regulators, government agencies, credit reporting agencies, publicly available records (including electronic data sources to carry out checks to enable us to comply with applicable law), information or service providers (some of whom may process your personal information on our behalf), recruitment agencies and other law firms or professional advisers. Your personal information may be collected in the firm’s contact database when you register to receive legal updates or we otherwise receive your contact details.
3.3 Recruitment
If you apply for a role or work experience opportunity, open day or insight event at the firm we will collect personal information directly from you, or from recruitment agencies, recruitment Website and apps or other third parties involved in our recruitment and screening process. These third parties include service providers that we use to store this information or help us to contextualise the information, where relevant, and also screening check providers, providers of occupational personality tests, health service providers, professional associations, government and law enforcement agencies, referees and your current and previous employers.
We will use this information to consider your application for a position with SteelRose (with the exception of the information provided in the Equal Opportunity and Diversity section which will be used for statistical purposes (internally and via external providers) to help us better support a diverse and inclusive workplace and meet our regulatory and legal requirements). We will also use the information to process additional information about you through carrying out checks to verify the information provided by you (including reference, background, identity, suitability and criminal record checks).
In order to use your personal information we need a lawful basis to do so. We rely on the fact that using your personal information in this way is necessary for our legitimate interest in hiring appropriately skilled employees and running an effective recruitment process. We may also rely on the condition that we need to perform our obligations in a contract with you, for example if you have signed a trainee contract with us but have yet to join the firm. In some circumstances, such as meeting visa requirements, we have a legal obligation to use your personal information. If we need to process special categories of personal data or use any criminal offence information about you to conduct criminal background checks as part of our pre-employment screening exercise, we and/or our third party provider will ask for your consent, if necessary.
4. HOW WE USE YOUR INFORMATIONWe will only use your personal information if and to the extent that applicable law allows. We will therefore only process your personal information if:
- it is necessary for the performance of a contract with you or the organisation you work for;
- it is necessary in connection with a legal obligation;
- you have given your consent (where necessary) to such use or the organisation you work for has obtained your consent (where necessary) to share your information with us; or
- if we (or a third party) have a legitimate interest which is not overridden by your interests or your rights and freedoms. Such legitimate interests include the provision of legal services, running the firm’s business and store relevant services directly to you.
We may use your personal information to:
- consider whether we can pursue certain business development initiatives;
- comply with our legal obligations to identify and verify the identity of our clients and their beneficial owners;
- deliver legal services to you and/or the organisation you work for, if you are a client;
- run the firm’s business (e.g. carry out administrative or operational processes, including recruitment);
- maintain and develop our business relationship with you;
- improve our services and products to you, if you or the organisation you work for are a client or prospective client;
- identify services you may be interested in;
- send you marketing and invite you to events;
- monitor and analyse our business; or
- process and respond to requests, enquiries or complaints received from you.
We will only retain your personal information for as long as is necessary for the purpose for which it was collected, including for the purposes of complying with any legal, regulatory, accounting or reporting requirements. Personal information processed in connection with our business acceptance processes and/or providing legal services will be retained in accordance with the firm’s Retention and destruction policy. If you wish to know more about the firm’s Retention and destruction policy or any of the firm’s different retention periods, please contact
info@steelrose.uk.
5. HOW AND WHY DO WE SHARE YOUR PERSONAL INFORMATION?We are an international business and any information that you provide to us may be shared with our associated firm SteelRose Compliance (India) Private Limited in Mumbai, India.
We may also share your personal information with certain trusted third parties in accordance with contractual arrangements in place with them, including:
- Our professional advisers and auditors
- Our insurers and insurance brokers
- Suppliers to whom we outsource certain support services such as word processing, translation, photocopying and document review
- IT and other service providers to SteeRose Third parties engaged in the course of the services we provide to clients and with their prior consent, such as notary, local counsel and technology service providers like data room and case management services
- Third parties involved in hosting or organising events or seminars
We may also have to share your personal information with regulators, government agencies, courts and other third parties. While it is unlikely, we may be required to disclose your information to comply with legal or regulatory requirements. We will use reasonable endeavours to notify you before we do this, unless we are legally restricted from doing so.
As set out above, some of your personal information may be stored in a cloud located within or outside of the European Economic Area (the EEA) and managed by a third party service provider. Where we transfer your personal information outside the EEA we will take reasonable steps to ensure that your information is treated securely and the means of transfer provide adequate safeguards.
We may share your personal information with third parties where:
- you have consented to us doing so (where necessary) or the organisation that you work for has obtained your consent for us to do so (where necessary);
- we are under a legal, regulatory or professional obligation to do so (for example, to comply with anti-money laundering or sanctions requirements);
- it is necessary for the purpose of, or in connection with, legal proceedings or in order to exercise or defend legal rights;
- it is in our or a third party’s legitimate interest to share the information, and that legitimate interest is not overridden by your rights or freedoms; or
- it is appropriate to disclose the information to parties with whom we have promotional arrangements (such as jointly hosted events).
6. SECURITYWe use up to date data storage and security to hold your personal information securely in electronic and physical form to protect your personal information from unauthorised access, improper use or disclosure, unauthorised modification or unlawful destruction or accidental loss. Our IT usage and security policy is supported by our security standards, processes and procedures. Our premises are access controlled and our electronic databases require logins and password authentication.
However, the transmission of information via the internet is not completely secure. Although we take appropriate and proportionate steps to manage the risks posed, we cannot guarantee the security of your information transmitted to our online services.
7. THIRD PARTY SITESOur Website contain links to other sites which are controlled by third parties. You should review these other sitesprivacy policies. We do not accept any responsibility for their use of your personal information.
8. YOUR RIGHTSYou have certain rights that you can exercise under certain circumstances in relation to the personal information that we hold. These rights are to:
- request access to your personal information (known as a subject access request) and request certain information in relation to its processing;
- request rectification and updating of your personal information;
- request the erasure of your personal information;
- request that we restrict the processing of your personal information; and
- object to the processing of your personal information.
In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Once the firm has received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law. If you withdraw your consent, our use of your personal information before you withdraw is still lawful.
If you have provided consent for your details to be shared with a third party, and wish to withdraw this consent, please also contact the relevant third party in order to amend your preferences.
If you would like to exercise any of these rights, please contact the info@steelrose.uk in writing by email us or by letter to our registered office address.
You will not, in general, have to pay a fee to exercise any of your individual rights set out in this Privacy notice. However, we may refuse to provide access and may charge a fee for access if the relevant data protection legislation allows us to do so, in which case we will provide reasons for our decision as required by the law.
9. FURTHER INFORMATIONQuestions, comments and requests regarding this privacy notice are welcome.
Please direct any queries about this policy or about the way we process your personal information to the SteelRose team using the post and email details below.
If you wish to write to us, please write to us at :-
info@steelrose.ukIf you feel we have not handled your query or concern to your satisfaction you can contact the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues at
ico.org.uk/concerns or telephone 0303 123 1113.