Privacy Policy

How we collect, use and protect your personal information.

Thomas Bradley Legal Ltd (company number SC595391) acts as data controller for the personal information you provide when you instruct us to act on your behalf, unless otherwise stated.

We are committed to handling your data lawfully, fairly and transparently, in line with the UK GDPR and the Data Protection Act 2018. All staff receive appropriate data protection training.

We only collect information that is relevant and needed to deliver our services. We may ask for more information where necessary to progress your matter.

The Personal Information We Collect

Depending on the service you use, we may collect:

  • Identity details: name, title, date of birth, marital status.
  • Contact details: address, email address, phone numbers.
  • Family and relationship details: information about your spouse or partner, children, beneficiaries, executors, trustees, guardians and attorneys.
  • Financial information: details of your property, savings, investments, pensions, life cover, business interests and income, where needed for estate or Inheritance Tax planning.
  • Verification documents: passport, driving licence, proof of address and the results of identity and anti-money laundering checks.
  • Health information: where relevant to a Power of Attorney, a trust or your wishes, or where it affects how we should communicate with you.
  • Communications: records of calls, emails, letters, messages and appointment notes.
  • Website and technical data: IP address, browser and device type, pages visited, and information collected through cookies and similar technologies. See our Cookie Policy for more detail.
  • Marketing preferences: how you prefer to hear from us and whether you have opted out.

Information about other people. When you tell us about family members, beneficiaries or appointees, we process their information too. Please let them know you have shared their details with us and point them to this policy.

Where we get your information. Mostly from you directly, through our website forms, calls, appointments and online tools. We may also receive it from a firm or organisation that has referred you to us, from identity verification providers, and from public sources such as the Registers of Scotland or HM Land Registry.

Why We Use Your Information and Our Lawful Basis

The law requires us to have a lawful basis for each use of your data. We rely on the following:

  • Responding to your enquiry and arranging an appointment: steps taken at your request before entering a contract, and our legitimate interests.
  • Providing our services, preparing documents and acting as your agent: performance of our contract with you.
  • Identity and anti-money laundering checks, tax and regulatory reporting: legal obligation.
  • Handling complaints and keeping records to defend legal claims: legal obligation and our legitimate interests.
  • Telling existing clients about related services, legal changes and company news: legitimate interests. You can opt out at any time.
  • Sending marketing emails or texts to people who are not yet clients: consent.
  • Non-essential cookies and advertising tracking on our website: consent.
  • Introducing you to a partner firm: consent, or legitimate interests where it relates to advice you have asked for (see Referrals and Partner Firms below).
  • Asking for feedback to improve our services: legitimate interests.

Health information is "special category" data and needs extra protection. We only process it with your explicit consent, or where it is needed to establish, exercise or defend legal claims.

If you do not provide information we reasonably need, we may not be able to act for you or give appropriate advice.

Where we rely on legitimate interests, we have balanced our interests against yours. You have the right to object. Where we rely on consent, you can withdraw it at any time without affecting processing already carried out.

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

Who We Share Your Information With

Statutory and regulatory bodies. We may have to share information to meet legal obligations or complete your matter. This may include organisations such as:

  • HMRC
  • Registers of Scotland
  • Revenue Scotland
  • National Crime Agency
  • Office of the Public Guardian

This may relate to tax matters, land registration, anti-money laundering and reporting obligations.

Service providers. We use trusted suppliers who process data on our behalf under written contracts. These include providers of identity verification, client relationship management and appointment booking, email and document management, secure physical file storage, and website analytics and advertising. They may only use your information to provide their services to us.

Professional advisers. With your permission, we may share information with other professionals where specialist input is needed.

Referrals and Partner Firms

We work with other firms so clients can get joined-up advice. This works in two directions.

When we refer you. If your matter would benefit from specialist advice, we may introduce you to a partner firm, such as a solicitor firm, a financial adviser or an accountancy firm.

  • Sterling Wealth (financial advice: mortgages, insurance, investments and pensions)
  • Insight Tax & Accountancy (tax and accountancy)
  • Thomas Bradley Residential (estate agency)

We will always discuss an introduction with you first. We only pass on your contact details and the information the other firm needs to contact you about what you discussed with us. We will not share your full file without your agreement.

Once the partner firm contacts you, it becomes a separate data controller and is responsible for how it uses your information under its own privacy policy. You are under no obligation to use its services.

When you are referred to us. If a solicitor, employer, credit union or other partner introduces you, it will share your contact details and relevant information with us so we can contact you. We use that information in line with this policy.

International Transfers

Some of our service providers, such as client relationship management, email, cloud storage and advertising platforms, may be based in or access data from outside the UK, most commonly the United States.

Where your information is transferred outside the UK, we make sure it is protected by one of the following:

  • the country has been recognised by the UK Government as providing adequate protection (this includes the European Economic Area);
  • the recipient is certified under the UK Extension to the EU-US Data Privacy Framework; or
  • we have put in place the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

You can contact us for more information about the safeguards we use.

How We Protect Your Information

Your information is held on secure electronic systems with access limited to authorised staff who need it for the purposes above. Physical files are kept in a secure, access-controlled storage facility.

How Long We Keep Your Information

We only keep your information for as long as we need it:

  • Enquiries that do not become instructions: 2 years from last contact.
  • Client files and correspondence: 6 years after your matter ends.
  • Original wills and related documents held in storage: until your death and the estate is administered, or until you ask us to return them.
  • Trust documents: for the life of the trust, plus 6 years.
  • Identity and anti-money laundering records: 5 years after our business relationship ends, as required by law.
  • Complaints records: 6 years after the complaint is closed.
  • Marketing records: until you opt out, after which we keep a suppression record so we do not contact you again.
  • Website and cookie data: see our Cookie Policy.

We may keep information longer where needed for a legal claim, regulatory requirement or investigation. When information is no longer needed, we securely delete or destroy it.

Your Rights

Under data protection law you have the right to:

  • Access the personal information we hold about you (a subject access request).
  • Correct information that is inaccurate or incomplete.
  • Erase your information where there is no good reason for us to keep it.
  • Restrict how we use your information in certain circumstances.
  • Object to processing based on legitimate interests.
  • Object to direct marketing at any time. We will stop straight away.
  • Data portability: receive information you gave us in a commonly used format, or have it sent to another organisation, where processing is based on consent or contract and carried out by automated means.
  • Withdraw consent at any time where we rely on it.
  • Not be subject to decisions made solely by automated means that have legal or similarly significant effects.

Some rights have limits. For example, we may need to keep certain records to meet legal obligations even if you ask us to delete them. We will explain if this applies.

There is normally no charge. We will respond within one month, which may be extended by up to two further months for complex requests. We may ask you to verify your identity first.

Complaints and the ICO

If you are unhappy with how we have handled your information, please contact us first and we will try to put things right.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK regulator for data protection:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint

Contact Us

To exercise your rights or ask about this policy, contact us at:

Thomas Bradley Legal Ltd
Unit 12-13 Jacobean House
1 Glebe Street
East Kilbride
G74 4LY

Email: info@thomasbradleylegal.co.uk
Phone: 0330 390 9200

Changes to This Policy

We may update this policy from time to time. The latest version will always be on this page.

Last updated: 24 September 2026