Privacy Policy OMB Legal

PRIVACY POLICY

OMB LEGAL
PRIVACY POLICY AND PRIVACY NOTICE

1. Introduction
OMB Legal respects your privacy and is committed to protecting your personal information.
This Privacy Policy and Privacy Notice (“Privacy Notice”) explains how we collect, use, store, disclose and protect personal information when you:
visit or use our website;
contact us through the website, email, telephone, social media or another communication channel;
make an enquiry about our services;
ask us to provide legal, consultancy, advisory or other professional services;
become or are considered as a prospective client;
deal with us on behalf of a client, business or other organisation;
subscribe to communications, newsletters or marketing;
attend an event, webinar or meeting organised by us;
apply for a role or otherwise communicate with us in a professional capacity; or
otherwise interact with OMB Legal.
This Privacy Notice should be read together with our Website Terms and Conditions, Cookie Notice and, where applicable, our Terms of Business, Engagement Letter, Client Care Letter or other client documentation.
We process personal information in accordance with applicable data protection and privacy legislation, including where applicable:
the UK General Data Protection Regulation (“UK GDPR”);
the Data Protection Act 2018;
the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”);
the Data (Use and Access) Act 2025 and amendments made by it; and
other applicable privacy, electronic communications and data protection legislation.
Where the laws of another jurisdiction apply to our processing, we will also comply with the mandatory requirements of those laws to the extent applicable.

2. Who We Are
OMB Legal is a trading name of FLRR Limited, a private limited company incorporated in England and Wales.
For the purposes of applicable data protection legislation, FLRR Limited will ordinarily be the data controller responsible for determining how and why your personal information is processed.
Legal entity: FLRR Limited trading as OMB Legal
Company number: [INSERT COMPANY NUMBER]
Registered office: [INSERT REGISTERED OFFICE]
Principal business address: [INSERT IF DIFFERENT]
Privacy email: [INSERT PRIVACY/DATA PROTECTION EMAIL]
Telephone: [INSERT TELEPHONE NUMBER]
ICO registration number: [INSERT IF APPLICABLE]
Where regulated or reserved legal services are provided through another authorised legal practice or professional, that organisation may act as a separate data controller, joint controller or processor in relation to information connected with those services. Where applicable, you will be informed of the identity of the relevant provider and any material additional privacy information.
In certain circumstances we may process information on behalf of another organisation as a data processor. Where we do so, the relevant controller’s privacy notice will normally explain how your information is used.

3. Scope of This Privacy Notice
This Privacy Notice applies to personal information concerning identifiable living individuals.
It applies to information relating to:
website visitors;
prospective clients;
clients;
former clients;
individuals connected with clients;
directors, shareholders, partners, employees and representatives of corporate clients;
beneficiaries, trustees, executors and personal representatives;
counterparties and persons connected with transactions;
witnesses and other individuals connected with legal matters;
professional advisers;
suppliers and contractors;
business contacts;
job applicants;
event attendees;
newsletter and marketing subscribers; and
other persons whose information we lawfully receive in connection with our business or professional services.

4. Personal Information We May Collect
Depending on the nature of our relationship with you, we may collect and process the following categories of personal information.
4.1 Identity information
This may include:
name;
title;
date of birth;
age;
gender where relevant;
photograph;
signature;
nationality;
citizenship;
passport information;
driving licence details;
national insurance or other identification numbers; and
identity verification information.
4.2 Contact information
This may include:
residential or business address;
email address;
telephone and mobile numbers;
correspondence address; and
social media or online contact details.
4.3 Client and matter information
This may include:
details of your enquiry or legal matter;
documents and correspondence;
instructions provided to us;
contracts and agreements;
transaction information;
property information;
business and corporate information;
litigation or dispute information;
family and personal circumstances;
estate-planning information;
information concerning wills, trusts or probate;
information relating to directors, shareholders, trustees, beneficiaries or other interested parties; and
any other information relevant to the services requested.
4.4 Financial information
This may include:
bank account information;
payment details;
billing information;
invoices;
financial circumstances;
assets and liabilities;
tax-related information;
investment or ownership information;
source-of-funds information; and
source-of-wealth information.
We will not ordinarily retain complete payment-card details where payment processing is carried out by a specialist payment provider.
4.5 Compliance and verification information
Where required or appropriate, we may process information for:
identity verification;
client due diligence;
anti-money laundering checks;
sanctions screening;
politically exposed person screening;
fraud prevention;
source-of-funds checks;
source-of-wealth checks;
conflict-of-interest checks;
regulatory checks; and
risk management.
4.6 Business and professional information
This may include:
employer;
job title;
professional qualifications;
directorships;
shareholdings;
business interests;
company information;
professional relationships; and
information contained within publicly available professional profiles.
4.7 Technical and website information
When you use our website, we or our authorised service providers may collect information including:
IP address;
browser type and version;
device information;
operating system;
approximate geographic location derived from technical information;
pages viewed;
links followed;
referral source;
dates and times of visits;
website interaction information;
security logs;
cookie identifiers;
consent preferences; and
other technical diagnostic information.
Further information about cookies and similar technologies is provided below and in our Cookie Notice.
4.8 Communications information
We may retain:
emails;
enquiry forms;
correspondence;
attendance notes;
records of telephone calls where appropriate;
video-conference information;
complaints;
feedback; and
other communications with you.
Where a telephone or video call is recorded, we will provide appropriate information where required by law.
4.9 Marketing information
This may include:
communication preferences;
marketing consent;
newsletter subscriptions;
event registrations;
areas of professional interest;
previous interactions with our communications; and
records of marketing objections or unsubscribes.
4.10 Recruitment information
Where you apply to work with us, information may include:
CV or résumé;
employment history;
education;
qualifications;
references;
remuneration information;
right-to-work information; and
information generated during recruitment.
Additional privacy information may be supplied during a recruitment process where appropriate.

5. Special Category and Criminal-Offence Information
Because of the nature of legal and professional services, we may occasionally need to process information receiving additional protection under data protection law.
Special category information may include information concerning:
racial or ethnic origin;
political opinions;
religious or philosophical beliefs;
trade union membership;
genetic information;
biometric information used for identification;
physical or mental health;
sex life; or
sexual orientation.
We may also process information relating to criminal convictions, alleged offences, investigations, proceedings, victims, witnesses or related security measures where this is lawfully necessary.
We will only process such information where both:
an appropriate lawful basis for ordinary personal information applies; and
an additional condition required by applicable data protection legislation is satisfied.
Depending on the circumstances, this may include processing:
with explicit consent;
for the establishment, exercise or defence of legal claims;
where necessary for substantial public-interest purposes;
for preventing or detecting unlawful acts, fraud, money laundering or terrorist financing;
for regulatory purposes;
to comply with legal obligations;
to protect vital interests; or
under another condition permitted by the Data Protection Act 2018 or UK GDPR.
Where legislation requires us to maintain an Appropriate Policy Document in connection with particular special-category or criminal-offence processing, we will do so.

6. How We Obtain Personal Information
We may obtain information directly from you when you:
use our website;
complete a form;
send us an email;
telephone us;
instruct us;
provide documents;
attend a meeting;
subscribe to communications;
interact through social media;
make a payment;
submit identification documents; or
otherwise communicate with us.
We may also obtain information from other sources where lawful and appropriate, including:
clients;
prospective clients;
family members;
directors, employees or representatives of organisations;
counterparties;
solicitors and other law firms;
barristers;
accountants;
tax advisers;
financial advisers;
surveyors and valuers;
lenders and financial institutions;
courts and tribunals;
HM Courts & Tribunals Service;
HM Revenue & Customs;
HM Land Registry;
Companies House;
the Office of the Public Guardian;
government bodies;
regulators;
law-enforcement bodies;
fraud-prevention and sanctions-screening services;
identity-verification providers;
credit-reference or due-diligence providers where lawful;
public registers;
publicly available websites;
professional databases;
social media;
insurers;
professional advisers; and
other persons involved in the relevant matter or transaction.
Where we receive your information from somebody else, we will provide privacy information where required by law, subject to any applicable exemption including duties of confidentiality, legal professional privilege or restrictions imposed by law.

7. Why We Use Personal Information and Our Lawful Bases
We must have a lawful basis before processing personal information.
The appropriate lawful basis depends upon the purpose and circumstances of the processing.
7.1 Enquiries and prospective clients
We may process information in order to:
respond to enquiries;
understand the services requested;
provide quotations;
determine whether we can act;
perform conflict checks;
complete preliminary due diligence; and
take steps requested before entering into a contract.
Our lawful bases may include taking steps at your request before entering into a contract, legitimate interests, recognised legitimate interests where applicable, compliance with legal obligations and consent where appropriate.
7.2 Providing our services
We may process information to:
open and administer matters;
provide agreed services;
communicate with clients;
prepare legal or commercial documents;
conduct research;
negotiate;
manage transactions;
coordinate professional advisers;
manage deadlines;
provide legal or strategic advice; and
perform our contractual responsibilities.
Lawful bases may include contractual necessity, steps taken before entering into a contract, legitimate interests and legal obligations.
7.3 Legal and regulatory compliance
We may process information to:
comply with anti-money laundering requirements;
verify identity;
undertake sanctions checks;
prevent fraud;
satisfy regulatory requirements;
comply with professional obligations;
respond to lawful demands;
make legally required reports;
maintain required records; and
establish, exercise or defend legal rights.
Our lawful bases may include legal obligation, recognised legitimate interests, legitimate interests and other bases authorised by law.
7.4 Conflict checking and professional-risk management
We may process information to:
identify conflicts;
protect clients;
assess whether we can accept instructions;
manage professional risk;
maintain insurance;
defend potential claims; and
maintain appropriate business records.
This will ordinarily be based on legitimate interests, legal obligations or recognised legitimate interests where applicable.
7.5 Billing and financial administration
We may process information to:
issue invoices;
receive payments;
manage accounts;
recover debts;
process refunds;
conduct financial administration; and
meet tax and accounting obligations.
Lawful bases may include contractual necessity, legal obligation and legitimate interests.
7.6 Website administration and security
We may process technical information to:
provide and operate the website;
maintain security;
prevent misuse;
diagnose technical problems;
maintain backups;
monitor website performance;
prevent fraud or cyber-attacks; and
improve our services.
Depending upon the particular technology and purpose, this may be based on legitimate interests, recognised legitimate interests, legal obligations or consent where required by PECR or other applicable legislation.
7.7 Business administration
We may process information for:
internal management;
training;
auditing;
quality assurance;
professional indemnity;
business continuity;
information security;
record keeping;
corporate transactions;
business planning; and
service improvement.
This will generally be based upon our legitimate interests, contractual responsibilities or legal obligations.
7.8 Legal claims
We may process and retain information where necessary to:
obtain legal advice;
establish legal rights;
exercise legal rights;
defend claims;
pursue claims; or
preserve relevant evidence.
7.9 Consent
Where we rely upon consent, you are entitled to withdraw that consent at any time.
Withdrawal will not affect the lawfulness of processing carried out before withdrawal.
Consent is not necessarily our lawful basis merely because you have voluntarily provided information to us.

8. Legitimate Interests
Where we rely on legitimate interests, those interests may include:
operating and developing our business;
responding to enquiries;
providing efficient professional services;
protecting our systems and information;
maintaining business and professional relationships;
preventing fraud and misuse;
managing professional and commercial risk;
improving our website and services;
pursuing or defending legal claims;
ensuring appropriate governance;
recovering sums owed;
maintaining network and information security; and
undertaking proportionate business-to-business marketing.
Where required, we assess whether our interests are overridden by your interests, fundamental rights or freedoms.
The fact that processing may benefit our business does not by itself mean that our interests automatically override your rights.

9. Marketing Communications
We may send information about OMB Legal, our services, legal developments, events, publications or other relevant professional content where permitted by law.
Where PECR requires consent for electronic marketing, we will obtain appropriate consent unless a statutory exception, such as an applicable existing-customer provision, permits the communication.
In other circumstances, including certain business-to-business communications, we may process information on the basis of legitimate interests where lawful.
You may object to direct marketing at any time.
You can unsubscribe by:
using the unsubscribe facility contained within the communication; or
contacting us using the details contained in this Privacy Notice.
We will maintain a limited suppression record where necessary to ensure that your marketing preference continues to be respected.
We will not sell your personal information to third parties for their independent marketing.

10. Cookies and Similar Technologies
Our website may use cookies and other storage and access technologies, including where applicable:
cookies;
local storage;
pixels;
tags;
scripts;
analytics technologies;
embedded content; and
comparable technologies.
Some technologies may be necessary for the website to operate, maintain security, remember choices or provide functionality requested by you.
Other technologies may require your consent before they are used.
Where consent is legally required, we will not activate the relevant technology before obtaining valid consent.
Certain uses may qualify for an exemption from consent under PECR where the statutory conditions are satisfied.
Where we use a consent-management tool, you can use that tool to accept, reject or change applicable preferences.
Detailed information concerning the technologies actually used on the website, their providers, purposes and durations should be contained within our separate Cookie Notice.

11. Analytics
Where enabled and lawfully configured, we may use analytics services to understand matters such as:
how visitors reach our website;
which pages are viewed;
general interaction patterns;
technical performance; and
how the website can be improved.
Where the use of an analytics technology requires consent, it will only be activated after the required consent has been obtained.
We will configure analytics and similar services to minimise unnecessary collection wherever reasonably practicable.

12. Artificial Intelligence, Automation and Technology-Assisted Services
OMB Legal may use appropriately selected technology to assist in delivering and administering its services, including:
artificial intelligence-assisted tools;
document automation;
legal research technology;
document review systems;
workflow-management systems;
transcription technologies;
secure client portals;
identity-verification systems;
cloud-based software; and
other professional technology.
Where personal information is processed using such systems, we will take appropriate steps having regard to the nature and risk of the processing. Those steps may include supplier due diligence, contractual protections, access controls, confidentiality measures and information-security safeguards.
Technology-assisted systems may support professional work, but their use does not remove the requirement for appropriate professional oversight where such oversight is necessary.
We do not intend to make decisions about individuals based solely on automated processing that produce legal effects or similarly significant effects unless the processing is lawful and appropriate safeguards required by applicable legislation are implemented.
If we introduce significant automated decision-making of this nature, we will provide any additional information and rights required by law.

13. Who We May Share Personal Information With
We do not disclose personal information indiscriminately.
Where necessary, proportionate and lawful, information may be shared with:
authorised solicitors and regulated law firms;
consultant solicitors;
barristers;
accountants;
tax advisers;
financial advisers;
surveyors;
valuers;
experts;
mediators;
notaries;
professional consultants;
courts and tribunals;
government departments;
regulators;
law-enforcement authorities;
HM Revenue & Customs;
HM Land Registry;
Companies House;
the Office of the Public Guardian;
Probate Registries;
lenders;
banks and payment providers;
counterparties and their professional advisers;
identity-verification providers;
anti-money laundering and sanctions-screening providers;
fraud-prevention providers;
insurers and insurance brokers;
auditors;
accountants;
IT support providers;
cloud-service providers;
email and communication providers;
website hosting providers;
cyber-security providers;
document-management providers;
electronic-signature providers;
marketing and communications providers where lawful;
analytics providers where applicable;
debt-recovery providers;
professional advisers to OMB Legal; and
prospective purchasers, investors or advisers in connection with a genuine business reorganisation, merger, acquisition or sale, subject to appropriate safeguards.
We require service providers handling personal information on our behalf to do so under appropriate contractual and confidentiality obligations.
Where another professional is independently responsible for determining how information is processed, that professional may be a separate data controller and their own privacy notice may apply.

14. Confidentiality and Legal Professional Privilege
Information provided to OMB Legal may be subject to professional duties of confidentiality and, depending upon the circumstances and provider involved, legal professional privilege.
Nothing in this Privacy Notice is intended to waive legal professional privilege or any other applicable right, duty or protection.
Certain rights or transparency obligations may be restricted where disclosure would conflict with legal professional privilege, duties of confidentiality, statutory restrictions, anti-money laundering legislation, rules preventing “tipping off”, court orders or other applicable law.

15. International Transfers
Some of our service providers, technology suppliers, professional advisers or recipients may process personal information outside the United Kingdom.
Where a transfer of personal information outside the UK constitutes a restricted international transfer, we will ensure that an appropriate transfer mechanism is available.
Depending upon the destination and circumstances, this may include:
UK adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to approved EU Standard Contractual Clauses;
another legally approved safeguard;
binding corporate rules where applicable; or
a statutory exception permitted by data protection legislation.
Where required, we will also undertake an appropriate transfer-risk assessment or data-protection test and consider whether supplementary safeguards are necessary.
You may contact us for further information regarding safeguards applicable to relevant international transfers.

16. Security
We take reasonable and appropriate technical and organisational measures designed to protect personal information against:
unauthorised access;
unlawful processing;
accidental loss;
alteration;
destruction;
damage; and
inappropriate disclosure.
Measures may include, as appropriate:
access controls;
authentication controls;
encryption;
secure systems;
data backups;
vulnerability management;
malware protection;
staff confidentiality obligations;
staff awareness and training;
supplier assessments;
security monitoring;
incident-response processes; and
business-continuity arrangements.
No electronic transmission or storage system can be guaranteed to be completely secure.
Where a personal-data breach occurs, we will investigate and take steps required by applicable law, including notification to the relevant supervisory authority and/or affected individuals where the statutory notification requirements are met.

17. How Long We Keep Personal Information
We do not intend to retain identifiable personal information for longer than is reasonably necessary for the purposes for which it was collected.
Retention periods are determined having regard to:
the nature of the information;
the nature and duration of our relationship with you;
the type of legal or professional matter;
applicable limitation periods;
regulatory obligations;
anti-money laundering requirements;
tax and accounting requirements;
professional indemnity requirements;
legal professional privilege;
the possibility of future legal proceedings;
contractual requirements;
security requirements; and
applicable legal or professional record-retention obligations.
Subject to those requirements:
Website enquiries that do not result in an engagement: normally retained for [INSERT PERIOD, e.g. 12–24 months] unless a longer period is reasonably necessary.
Client and matter files: retained in accordance with our matter-specific retention policy and applicable legal, regulatory and professional requirements. Different retention periods may apply to different categories of legal work.
Identity, anti-money laundering and compliance records: retained for the period required by applicable legislation and our regulatory obligations.
Financial and accounting records: retained for the period required by tax, accounting and other applicable legislation.
Marketing information: retained while you remain subscribed or while we have an appropriate lawful basis to contact you, together with limited suppression information where necessary to respect an opt-out.
Cookie and consent records: retained for an appropriate period having regard to the relevant technology, consent-management arrangements and legal requirements.
Complaints and claims information: retained for the period reasonably required to investigate and resolve the matter and protect legal rights.
Information may be retained for longer where necessary in connection with litigation, regulatory investigation, fraud prevention, legal obligations or the establishment, exercise or defence of legal claims.
At the end of the applicable retention period, information will be securely deleted, anonymised or otherwise disposed of in accordance with our procedures.

18. Your Data Protection Rights
Depending upon the circumstances and applicable law, you may have rights including the following.
18.1 Right of access
You may ask whether we process your personal information and request access to information we hold about you.
18.2 Right to rectification
You may ask us to correct personal information that is inaccurate and, where appropriate, complete information that is incomplete.
18.3 Right to erasure
In certain circumstances, you may request deletion of your personal information.
This right is not absolute and may not apply where information must be retained for legal, regulatory or legitimate purposes.
18.4 Right to restriction
In certain circumstances, you may request restriction of processing.
18.5 Right to data portability
Where the statutory conditions are satisfied, you may request certain information in a structured, commonly used and machine-readable format or ask that it be transferred to another controller where technically feasible.
18.6 Right to object
You may object to processing based upon legitimate interests in certain circumstances.
You have a particular right to object to processing for direct-marketing purposes.
18.7 Right to withdraw consent
Where processing is based upon consent, you may withdraw that consent at any time.
18.8 Rights relating to automated decision-making
Where applicable, you may have rights concerning decisions made solely through automated processing that have legal or similarly significant effects.
18.9 Right to complain
You have the right to raise a complaint concerning our processing of your personal information.
Not every right applies in every situation. Rights may be limited where an exemption or restriction applies, including in connection with legal professional privilege, legal proceedings, regulatory obligations or the rights of other persons.

19. How to Exercise Your Rights
To exercise a data protection right, please contact:
Privacy Contact
OMB Legal / FLRR Limited
[INSERT ADDRESS]
Email: [INSERT PRIVACY EMAIL]
Please provide enough information to enable us to understand and respond to your request.
We may need to verify your identity before disclosing information or acting upon a request.
We will respond within the timeframe required by applicable legislation.
Ordinarily, no fee is charged for exercising a data-protection right. However, the law permits a reasonable fee or other action in certain circumstances, including where a request is manifestly unfounded or excessive.

20. Data Protection Complaints
If you believe we have not handled your personal information correctly, you may make a data-protection complaint to us.
Complaints may be submitted electronically to:
[INSERT DATA PROTECTION COMPLAINTS EMAIL OR ONLINE FORM]
or in writing to:
OMB Legal / FLRR Limited
[INSERT POSTAL ADDRESS]
We will:
provide an accessible way for individuals to make data-protection complaints;
acknowledge a qualifying data-protection complaint within the period required by law;
take appropriate steps to investigate the complaint without undue delay;
keep you appropriately informed where required; and
communicate the outcome of our investigation.
Under current UK requirements, qualifying data-protection complaints should generally be acknowledged within 30 days.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent data-protection supervisory authority.
We would welcome the opportunity to address your concerns directly, but your right to approach the ICO is not dependent upon first obtaining a satisfactory response from us.

21. Information About Other People
If you provide personal information to us concerning another individual, you should ensure that you are entitled to provide that information.
Where appropriate, you should make that person aware that their information may be supplied to us and direct them to this Privacy Notice.
There may be circumstances in which this is inappropriate or legally restricted, including litigation, investigations, safeguarding concerns, confidential legal matters, fraud-prevention activity or anti-money laundering processes.

22. Children
Our general website is primarily intended for adults and businesses seeking professional services and is not designed specifically as an online service for children.
However, legal matters may involve information concerning children, beneficiaries, family members or other minors.
Where we process children’s personal information, we will take account of the nature of the information, the circumstances of the matter and any additional protections required by applicable law.
If any part of our online services becomes likely to be accessed directly by children, we will consider their particular rights and needs when determining how their personal information is used.

23. Third-Party Websites and Services
Our website may contain links to websites, applications, platforms or services operated by third parties.
Those third parties may process information independently from OMB Legal.
We do not control their privacy practices and this Privacy Notice does not govern their processing.
You should review the privacy information supplied by the relevant third party before providing personal information to them.

24. Social Media
If you interact with us through a social-media platform, both OMB Legal and the operator of that platform may process information concerning your interaction.
The platform operator’s privacy terms and settings will apply independently to its processing.
Information posted publicly on social-media platforms may be visible to other users. You should therefore avoid publishing confidential or sensitive information through public social-media channels.

25. International Visitors
OMB Legal is established in the United Kingdom and this Privacy Notice has been prepared principally to address UK data-protection requirements.
Depending upon the circumstances, individuals located outside the United Kingdom may also benefit from mandatory rights under the laws of their own jurisdiction.
Where the EU General Data Protection Regulation, another European privacy regime or another overseas privacy law applies to particular processing carried out by us, we will apply any additional mandatory requirements relevant to that processing.
This may include additional:
transparency information;
lawful-basis requirements;
consent requirements;
individual rights;
international-transfer safeguards;
local representative requirements; or
regulator contact information.
Nothing in this Privacy Notice is intended to restrict any mandatory privacy right that applies to an individual under applicable law.
Where necessary, a jurisdiction-specific supplemental privacy notice may be issued.

26. Sale of Personal Information
OMB Legal does not sell personal information in the ordinary meaning of that expression.
We do not intend to exchange personal information for monetary consideration with data brokers or third parties for their independent commercial exploitation.
Some overseas privacy laws use the expressions “sell”, “share” or similar terminology more broadly than their ordinary meaning. Where such legislation applies to OMB Legal, we will provide any additional disclosures or opt-out mechanisms required by that legislation.

27. Changes to This Privacy Notice
We may update this Privacy Notice periodically to reflect:
changes to our business;
changes to our services;
changes to technology;
changes to suppliers;
changes to our processing activities;
changes to regulatory guidance; or
changes to applicable law.
The current version will be made available through our website and the “Last updated” date will be amended when appropriate.
Where a change materially affects the way we process personal information, we will take reasonable steps to provide additional notice where required by law.

28. Contact Us
Questions about this Privacy Notice, our use of personal information or your data-protection rights should be directed to:
OMB Legal
A trading name of FLRR Limited
Registered office: [INSERT REGISTERED OFFICE]
Correspondence address: [INSERT IF DIFFERENT]
Email: [INSERT PRIVACY EMAIL]
Telephone: [INSERT TELEPHONE NUMBER]
For data-protection complaints:
[INSERT COMPLAINTS EMAIL / ELECTRONIC COMPLAINT FORM DETAILS]

29. Related Policies
This Privacy Notice should be read together with the following, where applicable:
Website Terms and Conditions;
Cookie Notice;
Terms of Business;
Client Care Letter or Engagement Letter;
Data Retention Policy;
Information Security Policy;
Data Breach and Incident Response Procedure;
Data Protection Complaints Procedure;
Appropriate Policy Document for special-category and criminal-offence data where required;
Data Processing Agreements with relevant processors; and
any service-specific or jurisdiction-specific privacy notice issued by OMB Legal.
End of Privacy Policy / Privacy Notice
 

Scroll to Top