Privacy Policy

This Privacy Policy sets out how we, Christopher Burgon Limited, trading as Christopher Burgon Solicitors, registered in England and Wales under company number 07567899, registered office 60 Gray’s Inn Road, London, WC1X 8AQ (“we”, “us”, “our”), collect, store and use information about you when you use or interact with our website, www.christopherburgon.co.uk, and where we otherwise obtain or collect information about you. This version of the Privacy Policy is effective from 1 September 2026.

Contents

Summary

This section summarises how we obtain, store and use information about you. It is a general overview only and must be read alongside the full sections below.

● Data controller: Christopher Burgon Limited.

● How we collect information about you: when you provide it directly (for example, by contacting us, booking a meeting, or downloading a guide); from your use of our website, using cookies and similar technologies; and occasionally from third parties.

● Information we collect: your name, contact details, IP address, information from cookies, information about your device and browser, information about how you use our website, your company or business name (if applicable), and any further information you choose to include in a message, form or download request.

● How we use your information: to respond to enquiries and administer our relationship with you, to fulfil contractual obligations, to send marketing communications where you have consented, to analyse and improve our website, to show you relevant advertising where you have consented, and to comply with our legal and regulatory obligations.

● Disclosure to third parties: only to the extent necessary to run our business, to fulfil a contract, to provide services you have requested (such as sending you a guide or newsletter), or where required by law. We do not sell your information.

● Retention: for no longer than necessary, taking into account our legal and regulatory obligations as a firm of solicitors. See ‘How long we retain your information’ below for specific periods.

● Cookies: we use essential, functional, analytics and targeting/advertising cookies. Analytics and targeting cookies are only set with your consent, given through the cookie banner on our website. See our cookies policy for full details: christopherburgon.co.uk/cookie-policy/.

● Targeted advertising: where you consent, we use the LinkedIn Insight Tag and, where enabled, the Meta Pixel and Google Ads remarketing tag, to show you adverts about our services after you leave our website. You can withdraw this consent at any time.

● Transfers outside the UK: some of our service providers (including Google, LinkedIn, Meta and HubSpot) may store or process information outside the United Kingdom, including in the United States, under an appropriate safeguard. See ‘Transfers of your information outside the United Kingdom’ below.

● Your rights: to access, correct, delete, restrict or port your information; to object to its use, including for direct marketing and profiling; to withdraw consent; and to complain to the Information Commissioner’s Office. See ‘Your rights in relation to your information’ below for how to exercise these.

Our details

The data controller in respect of our website is Christopher Burgon Limited, trading as Christopher Burgon Solicitors, company registration number 07567899, of 60 Gray’s Inn Road, London, WC1X 8AQ. You can contact us by writing to that address or by emailing legal@christopherburgon.co.uk.

Christopher Burgon acts as the firm’s data protection contact. You can contact him at the address above or by emailing legal@christopherburgon.co.uk. If you have any questions about this Privacy Policy, please use these details.

Information we collect when you visit our website

Web server log information

We use a third-party hosting provider, WP Engine, whose privacy policy is available at https://wpengine.com/gb/legal/privacy/. Our website server automatically logs the IP address you use to access our website, the pages you access, the date and time of your request, the source of your visit (such as the site or search engine that referred you), and your browser and operating system.

Use of server log information for IT security

We and our hosting provider retain server logs to protect the security of our network and website, including detecting and preventing unauthorised access, malicious code and denial-of-service attacks.

Legal basis for processing: compliance with a legal obligation to implement appropriate security measures (Article 6(1)(c) UK GDPR), and our and our hosting provider’s legitimate interest in network and information security (Article 6(1)(f) UK GDPR).

Use of server log information to analyse and improve our website

We analyse server log data — such as visit numbers, timing, location and browser/operating system — to understand how our website is used and to improve its content and structure.

Legal basis for processing: our legitimate interest in improving our website for visitors (Article 6(1)(f) UK GDPR).

Cookies and similar technologies

Cookies are small data files sent from a website to your browser to record information for various purposes. We use essential, functional, analytics and targeting cookies, described below.

Essential and functional cookies

These are necessary for our website to function (for example, remembering your cookie preferences) or to provide features you have chosen to use. These do not require consent, though you can block them via your browser settings, which may affect how the site works.

Analytics and targeting/advertising cookies

Where you consent through our cookie banner, we use the following analytics and targeting cookies. Analytics cookies help us understand how our website is used. Targeting (or “retargeting”) cookies allow us, and the advertising platforms below, to show you adverts about our services after you leave our website. None of these tools identify you by name — they recognise your browser only, unless you separately give us your details, for example by booking a meeting or downloading a guide.

● Google Analytics 4 (analytics) — provided by Google Ireland Limited. We use this to understand visitor numbers, behaviour and the effectiveness of our content.

● LinkedIn Insight Tag (targeting/advertising) — provided by LinkedIn Ireland Unlimited Company. We use this to show relevant advertising to past visitors on LinkedIn, and to measure how effective that advertising is.

● Meta Pixel (targeting/advertising) — provided by Meta Platforms Ireland Limited, where enabled. We use this to show relevant advertising to past visitors on Facebook and Instagram.

● Google Ads remarketing tag (targeting/advertising) — provided by Google Ireland Limited, where enabled. We use this to show relevant advertising to past visitors as they continue to browse or search elsewhere.

Legal basis for processing: your consent, given through our cookie banner (Article 6(1)(a) UK GDPR and Regulation 6 of the Privacy and Electronic Communications Regulations (PECR)). For Google Analytics 4, we also rely on our legitimate interest in understanding website use (Article 6(1)(f) UK GDPR) for any processing that falls outside what consent covers.

You can withdraw your consent to analytics and targeting cookies at any time using the cookie settings tool available on every page of our website, or by changing your browser settings. Withdrawing consent will not affect the lawfulness of anything already done on the basis of your consent before you withdrew it. For more detail, including how to opt out directly with each provider, see our cookies policy at christopherburgon.co.uk/cookie-policy/ and allaboutcookies.org.

Information we collect when you contact us

Email

When you email us, we collect your email address and any other information you include, such as your name, phone number or a signature block.

Legal basis for processing: our legitimate interest in responding to enquiries and keeping records of correspondence (Article 6(1)(f) UK GDPR); and, where your message relates to us providing services to you, taking steps to enter into or perform a contract with you (Article 6(1)(b) UK GDPR).

Emails you send us are stored with our email provider, Microsoft, within the United Kingdom or European Economic Area. Microsoft’s privacy policy is available at privacy.microsoft.com/en-gb/privacystatement.

Contact form

When you use our contact form, we collect your name, email address, IP address, and any other information you choose to include, such as in the message field. If you do not provide the required fields, you will not be able to submit the form.

Legal basis for processing: our legitimate interest in responding to enquiries (Article 6(1)(f) UK GDPR); and, where relevant, taking steps to enter into or perform a contract with you (Article 6(1)(b) UK GDPR).

Messages sent via our contact form are stored on our hosting provider’s servers (Cloudways), within the United Kingdom or European Economic Area.

Downloading a guide or resource

When you download a guide or resource from our website — for example, a director’s or shareholder’s guide relating to a business dispute — we collect the email address, and any name, you provide in that form.

We use this information to: send you the guide or resource you requested; where you consent, send you a short related follow-up email sequence about the topic of the guide and our services; and understand, on an aggregate basis, which topics visitors are most interested in.

Legal basis for processing: our legitimate interest in responding to your request by sending the guide (Article 6(1)(f) UK GDPR); and, for the follow-up email sequence, your consent, given at the point you submit the form (Article 6(1)(a) UK GDPR and Regulation 22 of PECR).

You can unsubscribe from the follow-up sequence at any time using the link in any email we send you, or by emailing legal@christopherburgon.co.uk. We may record the general subject matter of your download (for example, the broad scale of company involved) so that any follow-up correspondence is relevant, but we do not use this to make any decision about you without human involvement.

Phone

When you call us, we collect your phone number and any information you give us during the call.

Legal basis for processing: our legitimate interest in responding to enquiries (Article 6(1)(f) UK GDPR); and, where relevant, taking steps to enter into or perform a contract with you (Article 6(1)(b) UK GDPR).

Information about your call is processed by our telephone service provider, AT Telecommunications, whose privacy policy is available on request.

Post

If you write to us, we will collect the information you include in your letter.

Legal basis for processing: our legitimate interest in responding to correspondence (Article 6(1)(f) UK GDPR); and, where relevant, taking steps to enter into or perform a contract with you (Article 6(1)(b) UK GDPR).

Information collected or obtained from third parties

We do not generally receive information about you from third parties. Where a third party does provide information about you — for example, a referrer introducing you to us, or a professional adviser acting on your behalf — this will usually be your name and contact details, plus any further information they choose to share.

Legal basis for processing: taking steps to enter into or perform a contract with you (Article 6(1)(b) UK GDPR), where the introduction relates to services we may provide to you; your consent (Article 6(1)(a) UK GDPR), where you have asked a third party to pass your details to us; and our legitimate interest (Article 6(1)(f) UK GDPR), for example where we need to perform obligations under a sub-contract, or to investigate a suspected infringement of our legal rights.

Where we receive information about you from a public source — such as Companies House, the electoral register, HM Land Registry, business directories or a party’s own website or social media — we do so to verify information we hold, or to obtain missing information needed to provide our services.

Legal basis for processing: taking steps to enter into or perform a contract with you (Article 6(1)(b) UK GDPR); or our legitimate interest in investigating a suspected infringement of our legal rights (Article 6(1)(f) UK GDPR).

If we receive information about you in error, or without a valid legal basis for processing it, we will delete it.

Disclosure and additional uses of your information

Service providers

We use the following third parties to help run our business. They process your information on our behalf, under contractual terms that protect your information.

● Telephone provider: AT Telecommunications.

● Email provider: Microsoft. Privacy policy: privacy.microsoft.com/en-gb/privacystatement.

● Hosting provider: WP Engine. Privacy policy: https://wpengine.com/gb/legal/privacy/.

● CRM and email marketing providers: HubSpot Ireland Limited and Sendinblue, a company incorporated in France trading as Brevo , used to record enquiries, meetings and instructions by source, and to send marketing and nurture emails to those who have consented. Privacy policy available on the HubSpot and Brevo websites.

● Analytics and advertising platforms: Google Ireland Limited (Google Analytics 4, Google Ads), LinkedIn Ireland Unlimited Company (LinkedIn Insight Tag) and, where enabled, Meta Platforms Ireland Limited (Meta Pixel) — see ‘Cookies and similar technologies’ above.

● IT support provider: IT4Business.

● Web developer: Webfx.

Apart from our email, CRM, analytics and advertising providers — which may store or process information in the United States — our service providers are located in the United Kingdom and Ghana. We do not publicly name every service provider for security and competitive reasons, but will provide further detail on request where you have a legitimate reason for asking, for example because we have shared your information with them.

Legal basis for processing: our legitimate interest in running and managing our business efficiently (Article 6(1)(f) UK GDPR); and, where relevant, taking steps to enter into or perform a contract with you (Article 6(1)(b) UK GDPR).

Other disclosures

We may also share your information with: our accountants, for tax and accounting purposes; other professional advisers (such as financial advisers, lawyers, management consultants or marketing/PR professionals), where necessary for them to advise us; business partners such as barristers or agent solicitors, where you have requested services they provide; independent contractors, such as IT or marketing support, where necessary for them to perform their role; our insurers, in connection with an actual or potential claim; and a prospective purchaser or seller, in the context of a sale, acquisition or merger of our business. These third parties are generally located in the UK.

Legal basis for processing: our legitimate interest in running and managing our business efficiently (Article 6(1)(f) UK GDPR).

Legal reasons

We may disclose or use your information: to report suspected criminal conduct to an appropriate authority, such as the police; to enforce our legal rights, including sharing information with debt collection agencies; in connection with an actual or potential legal dispute, including mediation, arbitration or court proceedings; and to comply with legal obligations, such as a court order, or a report to the National Crime Agency in connection with suspected money laundering.

Legal basis for processing: our legitimate interest in preventing crime and enforcing or defending our legal rights (Article 6(1)(f) UK GDPR); and compliance with a legal obligation (Article 6(1)(c) UK GDPR).

How long we retain your information

We retain your information for no longer than necessary, taking into account our legal and regulatory obligations as a firm of solicitors, and the criteria set out at the end of this section.

● Server log information: retained for 12 months, then deleted or anonymised.

● Correspondence and enquiries: retained for as long as it takes to resolve your enquiry, and for six further months afterwards, unless it becomes a client matter (see below).

● Client and matter records: retained for six years from the conclusion of the matter, in line with our professional indemnity and regulatory record-keeping obligations as solicitors, or longer where a specific matter requires it (for example, ongoing limitation risk).

● CRM records of enquiries, meetings and instructions: retained for as long as you remain a client or prospective client with an active or reasonably foreseeable matter, and for six years afterwards.

● Marketing/nurture email list: retained until you unsubscribe, or until 24 months have passed since you last opened or clicked one of our emails, whichever is sooner.

● Analytics and advertising cookie data: retained according to each provider’s own default period (typically 13–26 months), after which it is automatically deleted by that provider.

In any other circumstance, we determine the retention period by considering: the purpose and ongoing use of the information; any legal or regulatory obligation to keep it; any legal basis we have to continue processing it, such as your consent; how valuable the information is; relevant industry practice; the risk, cost and liability of continuing to hold it; how easily it can be kept accurate and up to date; and the nature of our relationship with you.

How we secure your information

We take appropriate technical and organisational measures to protect your information against unauthorised or unlawful use, and against accidental loss or destruction, including: limiting access to the minimum necessary, and on an anonymised basis wherever possible; using secure servers; encrypting data in transit using SSL/TLS technology; and verifying identity before granting access to personal information on request.

Transmission of information over the internet is not entirely secure. If you send us information by email, via our website, or by any other electronic means, you do so at your own risk. We cannot be responsible for loss or damage arising from your decision to transmit information to us in this way.

Transfers of your information outside the European Economic Area

Where possible, we store and process your information within the United Kingdom. However, some of the third parties we use — including Google, LinkedIn, Meta and HubSpot — may store or process your information outside the United Kingdom, including in the United States.

Where this happens, we ensure an appropriate safeguard is in place, such as the UK’s International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or reliance on the relevant UK adequacy regulations recognising that a particular country provides an adequate level of protection. You can ask us for more information about the safeguard used for a particular transfer by contacting us at legal@christopherburgon.co.uk.

Your rights in relation to your information

Subject to certain limitations, you have the following rights in relation to your information. You can exercise any of them by writing to Christopher Burgon Limited, 60 Gray’s Inn Road, London, WC1X 8AQ, or by emailing legal@christopherburgon.co.uk:

● to request access to your information and how we use it;

● to request correction or deletion of your information;

● to request that we restrict our use of your information;

● to receive information you have provided to us in a structured, commonly used, machine-readable format, and to have it transferred to another controller;

● to object to our use of your information for certain purposes (see below);

● to withdraw your consent at any time, where we rely on consent — this will not affect the lawfulness of processing carried out before you withdraw it; and

● not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you. We do not currently make any such decisions.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority: ico.org.uk/global/contact-us/.

Verifying your identity

Where you request access to your information, we are required to take reasonable steps to verify your identity first, to protect your information from unauthorised access. We will confirm what we need from you, if anything beyond information we already hold, at the time of your request.

Your right to object to the processing of your information for certain purposes

You have the right to object, by writing to us at the address above:

● to our use of your information where we rely on our legitimate interests or a public interest task, including any related profiling; and

● to our use of your information for direct marketing, including any related profiling.

You can exercise your right to object to direct marketing by clicking “unsubscribe” in any marketing email, or by emailing legal@christopherburgon.co.uk with the words “OPT OUT”.

You can withdraw your consent to targeting/advertising cookies — the LinkedIn Insight Tag, Meta Pixel and Google Ads remarketing tag — at any time using the cookie settings tool on our website, without affecting the rest of your browsing. For further detail, see our cookies policy at christopherburgon.co.uk/cookie-policy/.

Sensitive Personal Information

‘Sensitive personal information’ (known in UK GDPR as ‘special category data’) includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, or information about health, sex life or sexual orientation.

We do not knowingly or intentionally seek to collect sensitive personal information through our website, and ask that you do not submit it to us other than where it is necessary and relevant to instructing us on a legal matter, in which case we will discuss the appropriate basis for processing it with you directly.

If you inadvertently send us sensitive personal information other than in the context of instructing us, we will treat this as your explicit consent to our processing it for the purpose of assessing whether to retain it as part of a client matter, or otherwise deleting it.

Changes to our Privacy Policy

We review and update this Privacy Policy from time to time. Where we make minor changes, we will update the effective date at the top of this page. Where we make major changes, or intend to use your information for a materially different purpose, we will notify you by email where possible, or by posting a notice on our website, and will obtain your consent first where the law requires it.

Children’s Privacy

Our website and services are directed at businesses and individuals aged 18 or over, and we do not knowingly collect information from anyone under 18. If we become aware that we have inadvertently collected information from

someone under 18, we will delete it, save where we are required by law to retain it or to seek parental consent. If you believe we hold information about a person under 18, please contact us at legal@christopherburgon.co.uk.

Do Not Track Disclosures

“Do Not Track” is a browser setting that requests websites not to track a visitor’s activity. We do not currently respond to Do Not Track signals. You can control analytics and targeting cookies directly using the cookie settings tool on our website, regardless of your Do Not Track setting — see our cookies policy at christopherburgon.co.uk/cookie-policy/.