Privacy Notice

Zeidler Group Privacy Notice

This privacy notice explains how Zeidler Group collects and uses personal data when you:

  • visit our public website or any of its sub-domains (the “Website”);
  • access or use any Zeidler platform, portal or software product made available to you through login credentials (the “Platform”); and/or
  • interact or contract with any Zeidler entity in connection with our services, including as a client, prospective client, supplier, service provider or business contact.

It also explains your privacy rights and how the law protects you

About Zeidler – data controller

Zeidler Group (“Zeidler”) comprises the following entities: Zeidler Legal Services Rechtsanwaltsgesellschaft mbH, Zeidler Legal Services (UK) Limited, Zeidler Legal Process Outsourcing Limited, Zeidler Consultancy Services India Private Limited, Zeidler Legal Services (Luxembourg) S.A., Zeidler Legal Services LLP (i.e. Irish Partnership Dr. Arne Zeidler and Mr. Robert Boyle), Zeidler Regulatory Services (Switzerland) AG and Zeidler Legal and Regulatory Technologies LLC.

  • The relevant Zeidler entity will be the controller of your personal data depending on the context in which your personal data is processed. For example, the Zeidler entity that contracts with you or your organisation, provides the relevant services, manages your Platform access, or otherwise determines the purposes and means of processing your personal data will be the controller for that processing. In some cases, Zeidler entities may process personal data jointly for group administration, compliance, reporting, IT, security or operational management purposes.
  • In order to make it easy for you to communicate with Zeidler with regards to your data privacy rights, we provide a single contact point. In case of any communication related to this privacy notice with Zeidler, please contact: [email protected].
  • You can find the address of each Zeidler entity in the Annex 1 to this privacy notice.

We have appointed a data privacy manager who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the data privacy manager at: [email protected].

Important information

This privacy notice aims to give you information on how we collect and process your personal data through your use of the Website and/or the Platform, and in connection with our business relationship with you or the organisation you work for, including where you provide personal data to us directly, where we collect it through your use of our Website or Platform, or where we receive it from other sources.

This Website is not intended for children and we do not knowingly collect data relating to children.

This privacy notice is the main privacy notice for the Website, the Platform and our related business relationships. We may provide additional privacy information on specific occasions where this is relevant to a particular interaction or processing activity.

You have the right to make a complaint at any time to the competent supervisory, regulatory or enforcement authority, including the Information Commissioner’s Office (ICO) in the UK, the relevant data protection authority in the EEA, the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, and, in the United States where applicable, the relevant federal or state regulator or attorney general. We would, however, appreciate the opportunity to address your concerns first, so please contact us in the first instance.

Changes to the privacy notice

This version was last updated on 06 March 2026. It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

Personal Data we collect about you

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

  • Contact Data: includes records of business communications (for example, e-mails and/or notes of discussions concerning business matters), work email address and work phone number and work address.
  • Financial Data: includes bank account details, payment card details (where processed by or through us), billing address and other payment-related information.
  • Identity Data: includes first name, last name, username or similar identifier, title, job title, employer or company name and, where relevant, business address.
  • Marketing and Communications Data: includes your preferences in receiving marketing from us and your communication preferences.
  • Profile Data: includes your interests, preferences, account settings and service preferences in relation to our Website, Platform and services.
  • Technical Data: includes internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and other technology on the devices you use to access the Website, the Platform or our services.
  • Transaction Data: includes details about payments to and from you and other details of products and services you have purchased from us or accessed through us, including invoices, payment status, payment method, time, place and price.
  • Usage Data: includes information about how you use the Website, the Platform and our services.
  • Aggregated Data such as statistical data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific Website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.

As a general rule, we do not seek to collect special category personal data or information about criminal convictions and offences through the Website or the Platform. If, in exceptional circumstances, such data is provided to us or needs to be processed in connection with our services, we will only process it where permitted or required by applicable law.

We deal with clients who are professional organisations such as law firms, asset managers or financial institutions. There may be limited occasions where, as part of our services, we collect and process Identity and Contact Data relating to individuals (employees, service providers, consultants, etc) where it is necessary and relevant to our services.

How we collect personal data

Most of the data we collect is via direct interactions, although sometimes we obtain personal data via our own initiatives, such as from websites, LinkedIn or other sources. Please see the table below to learn more about how we collect your personal data.

Direct interactions You may give us your Identity, Contact, Financial and Transaction Data by submitting information to us through the Website, through the Platform, by filling in forms, during onboarding, when using our services, or by corresponding with us by post, phone, email or otherwise:enquire about our products or services;create a user account for a Zeidler website, platform or portal;onboard to, access or use our services;subscribe to our publications or alerts;request marketing to be sent to you;give us feedback, contact support or make a complaint; orprovide information to us in connection with a client, supplier or other business relationship.
Third parties or publicly available sources We may obtain information about you from other sources. For example, we may collect information from publicly available sources,when our clients request our services;when you interact with us on social media;social media profile or other publicly-available information; anddemographic information.
Technical and Contact Data We may receive your Technical Data from the following sources:directly from you;from the Third Party providers in respect of the particular services which we provide; andsearch information providers; andfrom Zeidler entities or affiliated companies.
Financial Data We may receive your Financial Data from the following sources:directly from you;from providers of technical, payment and delivery services;from the Third Party services providers, such as payment processing services providers, in respect of the particular services which we provide; andfrom Zeidler entities or affiliated companies.
Transaction Data directly from you;from providers of technical, payment and delivery services;from the Third Party providers in respect of the particular services provided to you; andfrom Zeidler entities or affiliated companies.

Automated technologies or interactions.

As you interact with our Website or the Platform, we may automatically collect Technical Data about your equipment, browsing actions and usage patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see the Cookie Notice available on our Website for further details.

How we use personal data

We constantly review the nature of our lawful bases for processing to ensure that each processing activity is on the basis of a specific, lawful and most appropriate basis for processing.

Type of data and Description Processing Purposes Lawful bases for processing
Identity Data to create your user profile;to register your user profile;to enable your access to the Website and/or the Platform;to establish and manage your Zeidler account and profile;to identify and authenticate you so you may access and use the Website and/or the Platform;to maintain the safety and security of personal data submitted through the Website, the Platform or in connection with our services;to prevent misuse;to check your identity;to administer and protect our business, including troubleshooting, data analysis and system testing;to provide our services;to establish and manage your Zeidler account and profile;to process and fulfil requests in connection with our services;to identify and authenticate you so you may access certain content, features or services via the Website and/or the Platform;to protect against theft and prevent fraud and other criminal activity, claims and other liabilities;to comply with and enforce applicable legal requirements, relevant industry standards and policies; andto recommend services which may interest you. necessary to perform a contract that we have entered into, or we will be entering into, in connection with our servicesnecessary for legitimate interests (please see the definition of the legitimate interests in the glossary below)necessary to comply with our legal obligation
Contact Data to contact you in respect of our products and services that you are interested in;to respond to your queries;to bill you for the services;to send you any information and updates relevant to the services which you have purchased or otherwise interested in;when you share comments and opinions with us, ask us questions or make a complaint we keep a record of this;we may monitor and record our phone calls with you, in line with the legislation, to make sure we are living up to the standards we set; andwe may process your Contact and Identity Data if you contact us through our “Contact Us” feature or client support tools available on our Website;to communicate with you (including providing you with offers and other communications about our products and services) and provide client support; andto comply with and enforce applicable legal requirements, relevant industry standards and policies. necessary to perform a contract that we have entered into, or we will be entering into, in connection with our servicesnecessary to comply with a legal obligationnecessary for legitimate interests (please see the definition of the legitimate interests in the glossary below)
Financial Data to collect payment for our services;to allow you to interact with certain third-party products or services;to perform analytics of anonymised personal data (including market and consumer research and trend analysis);for the purpose of billing reconciliation, collection, auditing, accounting;to protect against, identify theft and prevent fraud and other criminal activity, claims and other liabilities; andto comply with and enforce applicable legal requirements, relevant industry standards and policies. necessary to perform a contract that we have entered into, or we will be entering into, in connection with our servicesnecessary for legitimate interests
Transaction Data We may process your Transaction Data to record, administer and reconcile purchases, subscriptions, invoices, payments, account activity and service usage, and to comply with accounting, tax, audit and other legal or regulatory requirements. necessary to perform a contract that we have entered into, or will be entering into, in connection with our services;necessary for our legitimate interests; andnecessary to comply with a legal obligation.
Technical Data We may process Technical Data to administer, maintain, secure and improve our business, the Website, the Platform and related systems, including for troubleshooting, data analysis, testing, system maintenance, support, reporting, security monitoring and hosting.We may receive Technical Data from search information providers. As you interact with the Website or the Platform, we may automatically collect Technical Data about your equipment, browsing actions and usage patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see the Cookie Notice available on our Website for further details. necessary to perform a contract that we have entered into, or we will be entering into, in connection with our servicesnecessary for legitimate interests
Profile Data to ensure security of your accountto contact you in respect of our services that you are interested in; andto respond to your queries. necessary to perform a contract that we have entered into, or we will be entering into, in connection with our servicesnecessary for legitimate interests
Usage Data to understand how the Website and the Platform are used, so that we can improve the Website, the Platform and our services; and to tailor and improve user experience, functionality and support; andto provide personalised services to our users and clients. necessary to perform a contract that we have entered into, or we will be entering into, in connection with our servicesnecessary for legitimate interests
Marketing and Communications Data to send you updates, insights and marketing communications about Zeidler services where permitted by law;to manage your communication preferences and opt-outs;to understand engagement with our communications and improve future communicationsIn accordance with your marketing preferences, including any preferences you set when creating an account with us or otherwise providing your details to us, we may contact you by email, post or phone to keep you updated on our services where permitted by applicable law. necessary for our legitimate interests, namely to promote and develop our services and manage our business relationships; and, where required by applicable law, your consent
Aggregated Non-Personal Data We may process your Aggregated Data to operate, evaluate, develop, manage and improve our business (including operating, administering, analysing and improving our services and developing new services. necessary for legitimate interests

We sometimes use External Third Party service providers to deliver certain IT, technology and similar services to us (for example, the hosting of this Website or related services). Where this happens, they do so in the capacity of data processors on behalf of the relevant Zeidler company, on terms which are compliant with the applicable law, and which restrict their use of your personal data to that which is solely necessary in order for them to deliver services to us.

Generally, we do not rely on consent as a legal basis for processing your personal data except where consent is required by applicable law, including in certain cases for direct marketing communications. Where we rely on consent, you have the right to withdraw it at any time by contacting us or using the unsubscribe option in the relevant communication.

Sharing personal data with others

We share your personal details:

  • with people within our group who are involved in carrying out the processing described above;
  • with third party service providers who process your information on our behalf for the purposes above – such as IT hosting providers, payment service providers, data analytics specialists and other professionals retained by us; and
  • there may be rare occasions where the nature of a client instruction or supplier relationship mean that we have to share personal data with limited External Third Parties.

We will also share your personal information:

  • if we think this is necessary to in order to protect the rights, property, or safety of our business, our employees, our partners, or our clients. This includes sharing information for the purposes of fraud protection and credit risk reduction;
  • any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006;
  • third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal information in the same way as set out in this policy; and/or
  • with government authorities and/or law enforcement officials if required by law.

Storing your personal information and transfers outside the UK and EU

We may use our secure servers to store your personal data. We take appropriate physical, electronic and procedural measures to ensure that we keep your information secure, accurate and up to date in accordance with this policy. We use the following third parties to store electronic copies of your personal data: AWS cloud, Microsoft cloud, Hubspot, Salesforce Cloud, Google Cloud, Jira Cloud, Xero Cloud, Chaser Cloud, Exavault Cloud, Mailchimp, Pandadocs, Sendgrid, Testrail. We may, from time to time, store physical copies of your personal data in our offices. At all times we remain responsible for security of all your personal data.

Your personal information may be stored and processed outside of the country where it is collected, including outside of the UK (under the UK GDPR), outside the European Economic Area (EEA) (under the EU GDPR) or outside of Switzerland (under the Swiss Federal Act on Data Protection). When we transfer personal data internationally, we put in place appropriate safeguards in accordance with applicable data protection law, including adequacy regulations or decisions, standard contractual clauses, or other lawful transfer mechanisms. Where possible, we will transfer personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. Where it is necessary to transfer personal data to other countries, in the absence of an adequacy decision we make use of standard contractual clauses approved by the European Commission from time to time, or we implement other similar measures required by laws around the world. Please contact us at [email protected] for further information.

Personal data relating to someone else

Prior to providing to Zeidler any personal information concerning another individual, you must (unless we agree otherwise) ensure that you are authorised to disclose that personal data to us and, where required by applicable law, that the individual has been provided with the relevant privacy information.;

Data security

We have put in place appropriate security measures to prevent personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide services, manage our relationship with you or your organisation, comply with legal, regulatory, tax, accounting and reporting obligations, resolve disputes, and establish, exercise or defend legal claims. Retention periods vary depending on the nature of the data and the purpose of processing. In determining the appropriate retention period, we take into account the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, whether those purposes can be achieved by other means, and applicable legal requirements. We may retain anonymised or aggregated information, which is not personal data, for longer.

Your legal rights

Under certain circumstances, you have rights under the relevant data protection laws in relation to your personal data. Please see below the summary of your rights:

  • right to rectification:

If your personal information is incorrect or incomplete any way, you may notify a person dealing with your matter and where inaccurate or incomplete, we will correct it without delay.

  • right of access:
    • you may request a confirmation from us that we are processing your personal data;
    • access your personal data held by us and request a copy (unless providing a copy adversely affects the rights and freedoms of others);
    • obtain certain information about how we process your personal data, categories of personal data processed, recipients or categories of recipients who receive personal data from us; and
    • how long we store your personal data for and the criteria we use to determine retention periods.
    • right to be informed:
      • how your personal data is being processed;
      • how long it will be stored for;
      • the legal basis for processing,
      • recipients (or categories of recipients) of your personal data; and
      • whether personal data must be provided under statute or for another reason and the consequences of not providing the personal data to ensure the fair and transparent processing of your personal data.
    • right to restrict processing under certain circumstances:
      • if you contest the accuracy of your personal data, we may restrict its processing, until we can verify its accuracy;
      • if the processing is unlawful;
      • if we no longer need to process your personal data, unless we still need your personal data for the establishment, exercise, or defence of legal claims; and
      • if you object to processing that relies on public interest or our (or third party’s) legitimate interest as the lawful processing ground.
    • right to data portability:
      • right to receive from us a copy of your personal data in commonly used and machine-readable format and store it for further use on a private device; and
      • right to transmit personal data to another third party; or have your personal data transmitted directly from one third party to another where technically possible.
    • right not to be subject of automated processing:

Right not to be subject to automated decision-making, including profiling, which has legal or other significant effects on you.

  • right to object to processing:

you may object to processing of your personal data. We will stop processing your personal data once notified by you, except if we can demonstrate a compelling legitimate ground for processing the personal data that overrides your request; or processing is necessary to exercise or defend legal claims.

If you wish to exercise any of the rights set out above, please contact us at [email protected].

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or if you have made a number of requests. In this case, we will notify you and keep you updated.

Glossary

Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to.

External Third Parties

  • Service providers acting as processors who provide IT, system administration services and services.
  • Professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance, accounting services, third parties involved in legal proceedings.
  • HM Revenue & Customs, regulators and other authorities acting as processors or joint controllers based in the United Kingdom who require reporting of processing activities in certain circumstances.

Internal Third Parties means Zeidler companies and other entities which Zeidler is affiliated with.

Legitimate Interest means the interest of our business, our partners or third parties in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data on the basis of legitimate interests. We do not use your personal data for activities where such legitimate interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).

Where we rely on our legitimate interests or the legitimate interests of a third party (such as a Third Party Provider or Zeidler Company) to justify the processing of your personal information, our legitimate interests are:

  • improvement and development of our business operations and service offering;
  • pursuit of our commercial activities and objectives, or those of a third party (for example, by carrying out marketing);
  • provision of products and services which are tailored to your interests and to improve your experience;
  • protection of our business, shareholders, employees and clients, or those of a third party (for example, ensuring IT network and information security, prevention of fraud, enforcing claims, including debt collection); 
  • seeking investment for, or in the context of, an actual or proposed reorganisation, merger, sale, joint venture, assignment, divestiture, dissolution, liquidation, transfer or other transaction relating to all or any portion of our businesses, assets, companies or stock; and
  • analysing competition in the market for our services and to define types of clients for our products and services (for example, by carrying out research, including market research).

ANNEX 1
ZEIDLER ENTITIES´ OFFICE ADDRESSES

Entity Name Address
Zeidler Consultancy Services India Private Limited Wework WeWork Raheja Platinum, Sag Baug Road, Off Andheri-Kurla Rd, Marol, Andheri East, Mumbai 4000056, India
Zeidler Legal and Regulatory Technologies LLC 55 Washington Street, Suite 653, Brooklyn, New York 11201, United States of America
Zeidler Legal Process Outsourcing Limited 19-22 Lower Baggot Street, Dublin 2, Ireland
Zeidler Legal Services LLP 19-22 Lower Baggot Street, Dublin 2, Ireland
Zeidler Legal Services (Luxembourg) S.A. 21 rue du puits Romain, L-8070 Bertrange, Luxembourg
Zeidler Legal Services Rechtsanwaltsgesellschaft mbH Bettinastrasse 48, 60325, Frankfurt am Main, Germany
Zeidler Legal Services (UK) Limited 154-160 Fleet Street, London, EC4A 2DQ, United Kingdom
Zeidler Regulatory Services (Switzerland) AG Stadthausstrasse 14, CH-8400 Winterthur, Switzerland