Privacy Policy

Last updated: 2 July 2026

1. Data controller

The controller of your personal data is Semper Paratus Legal House LLP, registered in England and Wales (Companies House no. OC417715), 42-44 Bishopsgate, London EC2N 4AH, United Kingdom (“we”, “us”). Data protection contact: info@semperparatus.law, phone +44 74 5638 6117. We have not appointed a Data Protection Officer — please contact us directly with any privacy matter.

We process personal data in accordance with the UK GDPR and the Data Protection Act 2018, and — where applicable to our clients in the European Union — Regulation (EU) 2016/679 (EU GDPR).

2. What data we process and why

  • Contact (e-mail, phone) — name, e-mail address, phone number and the content of your message, to answer your enquiry (Art. 6(1)(b) or (f) GDPR).
  • Consultation bookings — name, e-mail, chosen time slot and any details you provide in the booking form, to arrange and hold the consultation (Art. 6(1)(b) GDPR). Bookings run on our own self-hosted calendar system (a Cal.com instance on our infrastructure) — booking data is not passed to an external calendar operator.
  • Shop orders — name, company details, address, e-mail, phone and information necessary to deliver the service (e.g. company-formation details), to conclude and perform the contract and meet tax/accounting obligations (Art. 6(1)(b) and (c) GDPR).
  • Payments — handled by an external payment processor (Stripe). We never store full card details; we only receive a payment confirmation and its identifier.
  • Customer account — login details and order history, to maintain your account (Art. 6(1)(b) GDPR).
  • Blog comments — display name, e-mail, IP address and the comment itself; comments are moderated before publication (Art. 6(1)(f) GDPR — our legitimate interest in running the blog and preventing spam).
  • Server logs and security — IP address, browser data and requested URLs, to keep the site secure and stable (Art. 6(1)(f) GDPR).
  • Marketing and statistics — usage data collected by the tools described under “Cookies” (Art. 6(1)(a) or (f) GDPR).

Providing your data is voluntary but necessary to use our services (e.g. to place an order or book a consultation).

3. Recipients of data

We share data only with providers that support the operation of this website and our services:

  • Stripe (Stripe Payments Europe Ltd / Stripe Payments UK Ltd) — online payment processing.
  • Cloudflare, Inc. — CDN, security filtering and the anti-bot mechanism (Cloudflare Turnstile) on our forms.
  • Google (Google Ireland Ltd / Google LLC) — presenting our services in Google services (Google Merchant Center / Google Ads) and the YouTube player for videos embedded on this site.
  • Meta Platforms Ireland Ltd — presenting our services in Meta services (Facebook/Instagram product catalogue).
  • Server infrastructure provider — hosting of the website, e-mail and our booking system.
  • Where justified: legal and accounting advisers, public authorities (HMRC, Companies House) — only to the extent necessary to deliver the service or comply with a legal obligation.

4. International transfers

Transfers between the United Kingdom and the European Economic Area take place on the basis of adequacy decisions. Where any of our providers (e.g. Cloudflare, Google, Meta, Stripe) processes data in third countries (including the USA), this is based on approved safeguards such as Standard Contractual Clauses (SCCs) or the EU–US / UK–US Data Privacy Framework.

5. How long we keep data

  • order and billing records — for the period required by tax and accounting law (as a rule up to 6 years);
  • correspondence and booking data — up to 3 years after the matter is closed, unless a longer period is required by law or for legal claims;
  • customer accounts — until deleted;
  • comments — until removed at your request;
  • server logs — up to 12 months.

6. Your rights

You have the right to: access your data and obtain a copy, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and to withdraw consent at any time (without affecting the lawfulness of processing before withdrawal). Requests are handled free of charge, as a rule within 30 days — write to info@semperparatus.law.

You may also lodge a complaint with a supervisory authority: in the UK — the Information Commissioner’s Office (ico.org.uk); in Poland — the President of the Personal Data Protection Office (UODO) (uodo.gov.pl); or the authority in your country of residence.

7. Cookies

This site uses cookies and similar technologies:

  • Essential — session, shopping cart and checkout (WooCommerce), language preference (pll_language), login security and anti-bot protection (Cloudflare). The site cannot work properly without them.
  • Functional — remembering your details in the comment form (optional, at your request).
  • Marketing/statistics — may be set by the Google and Meta tools described in section 3 — including the _fbp cookie (Meta) and doubleclick.net cookies (Google Ads advertising infrastructure, e.g. the IDE cookie, used for conversion measurement and remarketing), if active during your visit.

You can manage cookies in your browser settings, including blocking or deleting them. Blocking essential cookies may prevent you from placing orders.

8. Embedded content

We embed external content: YouTube videos (Google) and a map based on OpenStreetMap tiles. When such content is displayed, the external provider may receive your IP address and set its own cookies — as if you had visited that provider’s website directly.

9. Security

Data transmission is encrypted (TLS/HTTPS). We use firewalling and traffic filtering (Cloudflare), access restrictions, regular software updates and backups. Only authorised persons have access to personal data, strictly to the extent needed for their duties.

10. Changes to this policy

This policy may be updated, for example when the law or the tools we use change. The current version, with the date of the last update, is always available at this address.