Privacy Notice

This privacy notice explains how Zeidler Group collects and uses personal data when you:

It also explains your privacy rights and how the law protects you.

About Zeidler – data controller

Zeidler Group (“Zeidler”) comprises the following separate entities: Zeidler Legal Services Rechtsanwaltsgesellschaft mbH, Zeidler Legal Services (UK) Limited, Zeidler Legal Process Outsourcing Limited, Zeidler Consultancy Services India Private Limited, Zeidler Legal Services (Luxembourg) S.A., Zeidler Legal Services LLP, Zeidler Regulatory Services (Switzerland) AG and Zeidler Legal and Regulatory Technologies LLC.

We have appointed a data privacy manager who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the data privacy manager at: [email protected].

This Website is not intended for children and we do not knowingly collect data relating to children.

This privacy notice is the main privacy notice for the Website, the Platform and our related business relationships. We may provide additional privacy information on specific occasions where this is relevant to a particular interaction or processing activity.

You have the right to make a complaint at any time to the competent supervisory, regulatory or enforcement authority. This may include the Irish Data Protection Commission where ZLPO is the controller, the Information Commissioner’s Office in the United Kingdom, the competent data protection authority in another EEA country, the Federal Data Protection and Information Commissioner in Switzerland or, in the United States where applicable, the relevant federal or state regulator or attorney general. We would, however, appreciate the opportunity to address your concerns first, so please contact us in the first instance.

Changes to the privacy notice

This version was last updated on 21 September 2026.

Personal data we collect about you

Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

Contact Data: includes records of business communications (for example, e-mails and/or notes of discussions concerning business matters), work email address and work phone number and work address.

Financial Data: includes bank account details, payment card details (where processed by or through us), billing address and other payment-related information.

Identity Data: includes first name, last name, username or similar identifier, title, job title, employer or company name and, where relevant, business address.

Marketing and Communications Data: includes your preferences in receiving marketing from us and your communication preferences.

Profile Data: includes your interests, preferences, account settings and service preferences in relation to our Website, Platform and services.

Technical Data: includes internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and other technology on the devices you use to access the Website, the Platform or our services.

Transaction Data: includes details about payments to and from you and other details of products and services you have purchased from us or accessed through us, including invoices, payment status, payment method, time, place and price.

Usage Data: includes information about how you use the Website, the Platform and our services.

Platform and Service Data: includes personal data contained in documents, marketing materials, due diligence responses, questions, prompts, instructions, configurations, AI Outputs and other information submitted to, generated through or otherwise processed in connection with the Platform or our services.

Aggregated Data: includes statistical or analytical data derived from your personal data. Aggregated Data is not considered personal data in law as it does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific Website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.

We do not generally request special category personal data or information about criminal convictions and offences through the Website. However, information submitted through the Platform or processed in connection with our services may contain such data, for example in due diligence, know your customer or similar compliance materials. Where such data is received or required, we process it only to the extent necessary and where permitted or required by applicable law, subject to appropriate safeguards.

We deal with clients who are professional organisations such as law firms, asset managers or financial institutions. This notice mainly covers personal data relating to representatives and personnel of our clients, suppliers and other business contacts, which we process as part of our ordinary business relationships and service delivery.

How we collect personal data

We collect personal data from a range of sources, including directly from you, through your use of the Website, the Platform and our services, from publicly available sources, from third parties such as our clients and service providers, and from other Zeidler entities. Please see the table below to learn more about how we collect your personal data.

Automated technologies or interactions.

As you interact with the Website, the Platform or our services, we may automatically collect Technical Data about your equipment, browsing actions and usage patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see the Cookie Policy available at https://zeidler.group/cookies-policy/ for further details.

Use of artificial intelligence

The Platform may use artificial intelligence, machine learning, large language models and other automated processing technologies (“AI Systems”) in connection with current and future Platform functionality. Examples include Autofill within the Due Diligence Module, which assists with reviewing due diligence information and generating draft responses, and the Marketing Material Review Module, which assists with analysing marketing materials and generating findings, comments, classifications, summaries or other outputs.

Depending on the relevant functionality, AI Systems may process Platform and Service Data, including due diligence information, counterparty responses, marketing materials, documents, questions, instructions, configurations, prompts and personal data contained in them. We may use third-party providers of artificial intelligence, machine learning and large language model services (“External AI Providers”), as well as models hosted and operated within ZLPO’s AWS environment (“Hosted Models”). The provider or model used may vary depending on the relevant Platform functionality and may change from time to time. AWS provides the infrastructure for Hosted Models and acts as an infrastructure sub-processor; use of a Hosted Model does not involve sending the data to a separate External AI Provider.

External AI Providers are engaged on contractual terms that restrict their use of personal data to providing the agreed services, prohibit them from using personal data we share with them to train or improve their general-purpose models, and impose appropriate confidentiality and security obligations. Hosted Models operate within ZLPO’s AWS environment and may use submitted data only for the relevant Platform functionality and the purposes described in this privacy notice, unless a different use has been expressly agreed with the relevant client. International transfers are addressed below.

AI Outputs may contain errors, omissions or inappropriate conclusions and are intended to support, not replace, appropriate human review and professional judgement. Users are responsible for appropriate review before relying on an AI Output. Where a service agreement provides for review by a Zeidler service provider, that review is performed in accordance with that agreement. Zeidler does not use AI Systems made available through the Platform to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Further information is available in the Platform Terms of Use at https://zeidler.group/website-terms-of-use/.

How we use personal data

We constantly review the nature of our lawful bases for processing to ensure that each processing activity is on the basis of a specific, lawful and most appropriate basis for processing.

We use external service providers and other recipients to deliver IT, hosting, technology, document processing, process management, translation, communications, data, monitoring, software testing, payment, professional and similar services. Where they process personal data on behalf of the relevant Zeidler controller, they act as processors under contractual terms that restrict processing to the agreed purposes and impose appropriate data protection and security obligations. These providers may include External AI Providers. Models hosted within ZLPO’s AWS environment are operated as Hosted Models rather than through a separate external AI model service.

Generally, we do not rely on consent as a legal basis for processing your personal data except where consent is required by applicable law, including in certain cases for direct marketing communications. Where we rely on consent, you have the right to withdraw it at any time by contacting us or using the unsubscribe option in the relevant communication.

Sharing personal data with others

We share your personal data:

with individuals within our Zeidler entities who are involved in carrying out the processing described above;

with service providers and other recipients who process personal data for the purposes described above, including IT and cloud hosting providers, document processing and process management providers, communications providers, data and analytics providers, monitoring and software testing providers, translation providers, payment service providers, professional advisers and External AI Providers; and

there may be rare occasions where the nature of a client instruction or supplier relationship mean that we have to share personal data with limited External Third Parties.

We will also share your personal data:

if we think this is necessary in order to protect the rights, property, or safety of our business, our employees, our partners, or our clients. This includes sharing personal data for the purposes of fraud protection and credit risk reduction;

any other Zeidler entity listed in this notice;

third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this policy; and/or

with government authorities and/or law enforcement officials if required by law.

Storing your personal data and international transfers

Depending on the relevant service or functionality, we use secure systems and service providers to host, store or otherwise process electronic personal data. These may include providers of cloud infrastructure and hosting, productivity, collaboration and project management tools, document processing and translation services, client relationship and communications systems, financial data and analytics services, database and application infrastructure, monitoring and software testing services, messaging and email delivery services and External AI Providers. Hosted Models are operated within ZLPO’s AWS environment. We may also retain physical records in our offices where appropriate. The relevant Zeidler controller remains responsible for ensuring that personal data is protected in accordance with applicable law.

Personal data may be stored, accessed or otherwise processed outside the country in which it was collected, including outside the EEA, the United Kingdom or Switzerland. Where applicable law restricts an international transfer, we use an appropriate transfer mechanism. Depending on the transfer, this may include an adequacy decision or regulation, the European Commission’s standard contractual clauses, the United Kingdom International Data Transfer Agreement or Addendum, recognised Swiss transfer safeguards, or the EU-U.S. Data Privacy Framework and its United Kingdom Extension where the recipient is certified and the transfer is covered. We may also implement supplementary technical, contractual or organisational measures where appropriate. Please contact us at [email protected] for further information about the safeguards applicable to a particular transfer.

Personal data relating to someone else

Prior to providing to Zeidler any personal data concerning another individual, you must (unless we agree otherwise) ensure that you are authorised to disclose that personal data to us and, where required by applicable law, that the individual has been provided with the relevant privacy information.

Data security

We have put in place appropriate security measures to prevent personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide services, manage our relationship with you or your organisation, comply with legal, regulatory, tax, accounting and reporting obligations, resolve disputes, and establish, exercise or defend legal claims. Retention periods vary depending on the nature of the data and the purpose of processing. In determining the appropriate retention period, we take into account the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, whether those purposes can be achieved by other means, and applicable legal requirements. We may retain anonymised or aggregated information, which is not personal data, for longer.

Your legal rights

Under certain circumstances, you have rights under the relevant data protection laws in relation to your personal data. Please see below the summary of your rights:

Right to rectification:

Right to erasure:

Right of access:

Right to be informed:

Right to restrict processing:

Right to data portability:

Right not to be subject to automated decision-making, including profiling:

Right to object to processing:

If you wish to exercise any of the rights set out above, please contact us at [email protected].

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or if you have made a number of requests. In this case, we will notify you and keep you updated.

Glossary

Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to.

External Third Parties

Service providers acting as processors who provide IT, system administration and related services.

Professional advisers acting as processors or, where applicable, independent controllers, including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services, and third parties involved in legal proceedings.

HM Revenue & Customs, regulators and other authorities acting as independent controllers based in the United Kingdom or elsewhere who require reporting of processing activities in certain circumstances.

Internal Third Parties means other Zeidler entities processing personal data for internal administration, compliance, IT, security or operational purposes.

Legitimate Interest means the interest of our business, our partners or third parties in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data on the basis of legitimate interests. We do not use your personal data for activities where such legitimate interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).

Where we rely on our legitimate interests or the legitimate interests of a third party (such as an External Third Party or Zeidler entity) to justify the processing of your personal data, our legitimate interests are:

improvement and development of our business operations and service offering;

pursuit of our commercial activities and objectives, or those of a third party (for example, by carrying out marketing);

provision of products and services which are tailored to your interests and to improve your experience;

protection of our business, shareholders, employees and clients, or those of a third party (for example, ensuring IT network and information security, prevention of fraud, enforcing claims, including debt collection);

seeking investment for, or in the context of, an actual or proposed reorganisation, merger, sale, joint venture, assignment, divestiture, dissolution, liquidation, transfer or other transaction relating to all or any portion of our businesses, assets, companies or stock; and

analysing competition in the market for our services and to define types of clients for our products and services (for example, by carrying out research, including market research).

ANNEX 1ZEIDLER ENTITIES’ ADDRESSES