Privacy
Data protection and confidentiality.
This notice covers information processed through this website and Alexander’s professional practice where he determines why and how it is used.
Controller
Alexander Heylin is the controller of personal information where he determines why and how it is processed in connection with his professional practice and this website. His Information Commissioner's Office registration number is ZA521247.
Data-protection enquiries and requests may be sent by post to Alexander Heylin, Enterprise Chambers, 9 Old Square, Lincoln's Inn, London WC2A 3SR, marked “Private—Data protection”. Initial electronic correspondence may be sent to london@enterprisechambers.com, clearly marked “Private—Data protection: for Alexander Heylin”. Initial instructions and case enquiries should use the appropriate contact route on this website.
Enterprise Chambers
Enterprise Chambers provides clerking and administrative services in connection with Alexander's practice. Where Chambers determines the purposes and manner of processing for its own clerking, administration, billing, regulatory, complaints, marketing or chambers-management functions, it acts as a separate controller and its own privacy notice applies.
Where information is processed on Alexander's documented instructions, the applicable data-protection arrangements govern that processing. A person may need to contact both Alexander and Enterprise Chambers where each controls different information relating to the same enquiry or instruction.
Information and purposes
Information may include identity and contact details; enquiries and conflict-check information; instructions, evidence and case documents; information concerning case participants; billing records; complaints; and limited website-security data. Casework may necessarily include special-category or criminal-offence information.
Lawful bases
Processing is undertaken where necessary for a contract or steps requested before a contract; compliance with legal obligations; legitimate interests including conflict checking, practice security, complaints and legal rights; or another applicable lawful basis. Consent is reserved for genuinely optional processing.
Special-category data may be processed where necessary for legal claims under Article 9(2)(f) UK GDPR or another applicable condition. Criminal-offence data is processed only with an Article 6 basis and an applicable DPA 2018 Schedule 1 condition.
Sharing and transfers
Where necessary and lawful, information may be shared with Chambers, legal professionals, clients, courts, tribunals, arbitrators, experts, witnesses, regulators, insurers, accountants and secure service providers. It is not sold. International transfers use adequacy regulations, approved safeguards or an applicable exception, including necessity for legal claims.
Service providers
Alexander may use appropriately selected providers for website hosting and security, professional email, secure document transfer, document storage, information technology, accounting and practice administration. A provider acting as a processor may use personal information only for the agreed services and subject to appropriate contractual, confidentiality and security requirements.
Some recipients—including courts, regulators, insurers and independently instructed professional advisers—may instead act as controllers for their own functions. The identity and role of relevant providers will be reviewed when services are selected or changed.
International transfers
Some service providers or professional participants may process information outside the United Kingdom. This may also be necessary in cross-border instructions. Where UK GDPR applies to a restricted transfer, Alexander will use an applicable adequacy regulation, approved contractual safeguards, another lawful transfer mechanism or, where appropriate, a limited exception such as a transfer necessary for the establishment, exercise or defence of legal claims. Further information about safeguards applicable to a particular transfer may be requested using the privacy contact details.
Retention periods
Personal information is retained only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, regulatory, professional and insurance requirements. The normal periods are:
- Enquiries that do not result in instructions: enquiry correspondence and documents will normally be deleted within 3 months after the enquiry is closed. A limited conflicts record—normally names of relevant parties and connected entities and a brief matter identifier—may be retained for longer where reasonably necessary to identify or manage future conflicts. It will not ordinarily include substantive evidence or unnecessary confidential material.
- Public Access files: the records specified by the BSB Public Access Rules will be retained for at least 7 years after the date of the last item of work, unless reasonable steps have been taken to ensure that the Public Access client will retain the required records. At the end of that period, the information will be reviewed and securely deleted or anonymised unless a documented reason requires longer retention.
- Licensed Access files: the records required by the BSB will be retained for 7 years after the date of the last item of work, unless the required records are retained by the Licensed Access client in accordance with the applicable rules.
- Other professional instructions: files arising from instructions through solicitors, overseas lawyers or other professional clients will normally be retained for 6 years after completion. A longer period may apply where justified by limitation periods, the nature of the matter, the interests of a child or person lacking capacity, continuing proceedings, professional-indemnity requirements, a complaint, a regulatory obligation or anticipated legal proceedings.
- Complaints: complaints records and associated correspondence will be retained for 6 years after resolution, consistently with the BSB complaints requirements.
- Anti-money-laundering records: where the Money Laundering Regulations apply, relevant identity, verification and transaction records will normally be retained for 5 years after the end of the relevant business relationship or completion of the occasional transaction, subject to any applicable lawful exception.
- Website security records: technical and security logs will normally be retained for no longer than 30 days. Relevant records may be preserved for longer where necessary to investigate a security incident, misuse or legal claim.
- Data-protection requests: records of requests concerning data-protection rights will normally be retained for up to 12 months after the request has been concluded. A limited record may be retained longer where necessary to demonstrate compliance or manage a dispute.
Review and secure deletion
Retention periods are reviewed periodically. Information may be retained for longer where necessary because of a legal or regulatory requirement, professional-indemnity obligation, complaint, continuing proceedings, litigation hold or another documented reason.
When information is no longer required, it will be securely deleted, destroyed or irreversibly anonymised. Different periods may apply to particular records within the same file.
Your rights
Depending on the circumstances, individuals may request access, correction, erasure, restriction or portability, or object to processing. Rights may be limited by law, another person’s rights, legal professional privilege or professional confidentiality. A complaint may be made to the Information Commissioner’s Office.
Cookies and security
The website uses no advertising cookies, behavioural tracking, session replay or third-party analytics. It records aggregate, first-party statistics about page use and selected journeys—such as referrals, publication downloads and clicks towards instruction routes—without setting or reading analytics cookies or creating analytics visitor identifiers. No IP address, full referring URL, enquiry content or document content is stored in the analytics data. The hosting and security layers may set operational cookies, including Cloudflare's __cf_bm (normally about 30 minutes) and cf_clearance, and the hosting platform's __Host-appgarden-visitor cookie (observed with a maximum age of 90 days). The website does not read or use those cookies for its first-party analytics, advertising or behavioural profiling. Their operation and duration are controlled by the relevant hosting or security provider. Appropriate access controls, encryption in transit and incident procedures are maintained.
To preserve referral attribution while a visitor moves between pages, the website may hold a short categorical source—for example, LinkedIn, Google or Enterprise Chambers—in temporary session storage. It is not a visitor identifier and is removed when the browser session ends.
The Public Access questionnaire uses temporary session storage so that answers are not lost while a visitor moves through the questions. Those answers stay on the visitor's device, are not submitted to the website and are removed when the page session ends or the questionnaire is reset. Analytics records only aggregate events such as starting, completing or reaching a routing outcome; it does not record questionnaire answers.