Privacy Policy

How Chronicle Law collects, uses and protects personal information

Effective date: 5 August 2026

1. About this policy

This Privacy Policy explains how Chronicle Law collects, uses, shares and protects personal information.

It applies to:

  • Visitors to our website
  • Newsletter subscribers
  • Webinar and event registrants
  • Customers and prospective customers
  • Contributors, speakers and partners
  • People who contact or communicate with us
  • Professional contacts
  • Individuals whose business contact information we obtain from public or third-party sources
  • Individuals included in research, marketing, telephony and business-development campaigns

We process personal information in accordance with applicable UK data-protection and electronic-marketing law, including the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.

2. Who we are

Chronicle Law is a trading name of B Shaw Ltd, a company registered in England and Wales under company number 12912346.

B Shaw Ltd is the controller responsible for the personal information described in this policy.

Our contact details are:

B Shaw Ltd, trading as Chronicle Law
Company number: 12912346
Address: 2 Merchant Corner, Markeaton Street, Derby, DE22 3AP
Email: brett@chroniclelaw.co.uk
Telephone: 07480 990 290
Contact: Brett Shaw, Director

Our data-protection role may depend on the service being provided.

We normally act as an independent controller when we decide why and how professional contact information is researched, collected, maintained, used, supplied or licensed to business clients.

A client receiving professional contact information from us will normally act as an independent controller of that information and will be responsible for its subsequent use.

Where we process personal information solely on a client’s documented instructions, without determining the purposes for which it is used, we may act as that client’s processor. Our contract with the client will identify the parties’ respective roles and responsibilities.

3. Personal information we collect

Depending on how you interact with us, we may collect and use the following categories of personal information.

Identity and professional information

This may include:

  • Your name
  • Job title and seniority
  • Professional role
  • Employer or organisation
  • Department or practice area
  • Professional qualifications
  • Regulatory or professional identifiers
  • Publicly available professional biography
  • Publicly available professional profile URL

Business contact information

This may include:

  • Work email address
  • Business telephone or mobile number
  • Office address
  • Organisation website
  • Publicly displayed professional contact details

Customer and transaction information

This may include:

  • Services, products, subscriptions or event access purchased
  • Contracts and order information
  • Invoices and payment status
  • Customer-support information
  • Communications concerning an order, contract or service

Payment-card information may be processed directly by our payment provider rather than stored by Chronicle Law.

Enquiry and correspondence information

This may include:

  • Enquiries and requests
  • Email correspondence
  • Telephone call details and appropriate call notes
  • Feedback, complaints and responses
  • Records of professional communications

Publishing and contribution information

This may include:

  • Articles and other submitted content
  • Author and speaker biographies
  • Photographs and profile images
  • Professional credentials
  • Webinar recordings and presentation materials
  • Authorship and publication details

Marketing and preference information

This may include:

  • Newsletter and webinar subscriptions
  • Areas of professional interest
  • Campaign and content interactions
  • Webinar registrations and attendance
  • Email opens and link interactions, where enabled
  • Marketing permissions
  • Opt-outs and objections
  • Suppression records
  • Previous campaign responses

Website and technical information

This may include:

  • IP address
  • Browser and device information
  • Pages visited
  • Referring website or page
  • Approximate location derived from an IP address
  • Cookie identifiers
  • Website-security information
  • Analytics and interaction data

Special-category and criminal-offence information

We do not intentionally collect special-category personal information or criminal-offence information for our professional-contact databases or ordinary marketing activities.

If you provide such information in an enquiry, article, complaint or other communication, we will process it only where necessary and where an appropriate lawful basis and additional legal condition apply.

4. Where personal information comes from

We may obtain personal information:

  • Directly from you through our website, forms, emails, telephone calls, contracts, purchases, event registrations, webinar bookings and newsletter sign-ups
  • From your employer, organisation, colleague, representative or a Chronicle Law client
  • From public regulatory and professional sources, including information published by the Solicitors Regulation Authority, Companies House and other relevant public registers
  • From law firms’ and other organisations’ websites
  • From barristers’ chambers websites
  • From publicly available professional directories and profiles
  • From professional networking sources used in a business context
  • From business clients and suppliers where information is provided lawfully for a particular service or campaign
  • From service providers supporting our website, analytics, email delivery, telephony, payments, customer management and administration
  • From publicly available sources used to check, update or verify professional information

Where appropriate, we record or can identify the source from which professional contact information was obtained.

The fact that information is publicly available does not remove our obligations under data-protection law. We consider whether an individual is likely reasonably to expect their professional information to be used for the relevant purpose and whether its use is fair, necessary and proportionate.

Where we obtain personal information from someone other than the individual, we provide or make this privacy information available within the period required by law. This will normally be no later than one month after obtaining the information, at the time of our first communication with the individual, or before the information is first disclosed to another recipient, whichever applies first.

There may be limited circumstances in which the law provides an exemption from this requirement. Where we rely on an exemption, we will record our reason for doing so.

5. How and why we use personal information

We use personal information for the following purposes.

Enquiries and professional relationships

We use personal information to:

  • Respond to enquiries
  • Provide requested information
  • Manage professional contacts
  • Communicate with customers, contributors, speakers, partners and prospective clients
  • Maintain records of our professional relationships

Our lawful basis will normally be our legitimate interests in managing professional relationships and responding to enquiries, taking steps at an individual’s request before entering into a contract, or performing a contract.

Products and services

We use personal information to:

  • Supply services, subscriptions, publications, events and training
  • Deliver professional-data, research, marketing and business-development services
  • Administer contracts and orders
  • Provide customer support
  • Process invoices and payments
  • Produce service and campaign reports

Our lawful basis will normally be performing a contract, taking steps before entering into a contract, complying with a legal obligation, or our legitimate interests in administering and developing our services.

Publishing and contributions

We use personal information to:

  • Review and edit submitted material
  • Publish legal news, articles and professional commentary
  • Create contributor and speaker profiles
  • Deliver and promote webinars, events and training
  • Publish webinar recordings and supporting materials where agreed
  • Promote relevant Chronicle Law content

Our lawful basis will normally be performing a contract, consent where specifically requested or appropriate, or our legitimate interests in publishing and promoting relevant legal-sector information.

Professional-data services

We research, verify, organise, maintain, supply and license professional business information.

This may include supplying professional contact information to business clients for lawful:

  • Business-to-business marketing
  • Market research
  • Recruitment
  • Business development
  • Professional communications
  • Event and webinar promotion

Our lawful basis is normally our legitimate interests, or those of our clients, in maintaining accurate professional information and undertaking relevant business-to-business activity.

Before relying on legitimate interests, we consider whether the processing is necessary and proportionate and whether the individual’s interests, rights or freedoms override those interests.

Where a client receives professional information from us and determines how and why it will be used, that client will normally become an independent controller responsible for its subsequent processing.

Chronicle Law marketing

We use personal information to send relevant information about:

  • Chronicle Law publications and articles
  • Webinars and training
  • Events
  • Services and products
  • Partnership and contribution opportunities
  • Other relevant legal-sector developments

For newsletter subscribers and communications for which consent is required, we rely on consent.

Where consent is not required under the Privacy and Electronic Communications Regulations, we may rely on our legitimate interests in communicating relevant professional and business information, provided the processing is necessary, proportionate and unlikely to cause unwarranted harm or surprise.

Marketing campaigns for clients

We may use professional contact information to deliver campaigns for clients, including:

  • Educational campaigns
  • Email communications
  • Webinar and event promotion
  • Telephone outreach
  • Market research
  • Lead qualification
  • Business-development campaigns
  • Meeting generation

Depending on the campaign, Chronicle Law and the client may each act as independent controllers, or Chronicle Law may act as the client’s processor.

Our contract with the client will identify the parties’ roles and responsibilities.

Where Chronicle Law sends or instigates electronic marketing, we assess the applicable UK GDPR and PECR requirements. Where PECR requires consent, we will not rely on legitimate interests as a substitute for that consent.

Telephone outreach and market research

We may use business telephone numbers to contact organisations and professionals about:

  • Relevant professional services
  • Educational opportunities
  • Webinars and events
  • Market research
  • Client campaigns
  • Potential business relationships

Before making live direct-marketing calls, we take proportionate steps to screen relevant telephone numbers against the Telephone Preference Service, Corporate Telephone Preference Service and our own suppression records where required.

We may retain appropriate records of calls, including:

  • The date of the call
  • The recipient or organisation contacted
  • The general subject discussed
  • Relevant professional information provided
  • The outcome of the call
  • Any follow-up requested
  • Any request not to be contacted again

We do not use call notes to record unnecessary personal or sensitive information.

Website operation and analytics

We use technical information to:

  • Operate and maintain our website
  • Protect the website and our systems
  • Prevent fraud and misuse
  • Provide essential website functionality
  • Understand website performance
  • Improve navigation, content and user experience

We rely on our legitimate interests for essential website operation and security. We use consent where required for non-essential cookies, analytics and marketing technologies.

Legal, financial and governance requirements

We may use personal information for:

  • Accounting and taxation
  • Record-keeping
  • Information security
  • Fraud prevention
  • Insurance
  • Complaints
  • Regulatory matters
  • Enforcing agreements
  • Establishing, exercising or defending legal claims

Our lawful basis will normally be compliance with a legal obligation or our legitimate interests in protecting our organisation, enforcing agreements and managing legal or regulatory matters.

6. Legitimate interests

Where we rely on legitimate interests, we consider:

  • The purpose we are seeking to achieve
  • Whether using the information is necessary for that purpose
  • The nature and source of the information
  • The individual’s reasonable expectations
  • The likely effect on the individual
  • Whether less intrusive means are available
  • The safeguards, opt-outs and other controls available

Our legitimate interests may include:

  • Operating and developing Chronicle Law
  • Managing professional and commercial relationships
  • Publishing relevant legal-sector information
  • Maintaining accurate professional information
  • Supplying business-information services
  • Undertaking proportionate B2B marketing and market research
  • Promoting relevant webinars, events and training
  • Protecting our systems and services
  • Preventing fraud
  • Establishing or defending legal rights

7. Business marketing and professional data

We collect and maintain professional business information obtained from public regulatory, professional and business sources.

This information may be used to:

  • Maintain Chronicle Law’s legal-sector professional database
  • Publish and promote relevant legal-sector content, webinars and training
  • Undertake B2B marketing and professional communications
  • Conduct telephone research and outreach
  • Identify relevant law firms and professional decision-makers
  • Promote client webinars, events, services and educational campaigns
  • Qualify interest and arrange professional meetings
  • Produce aggregated market intelligence and campaign reports
  • Supply or license professional business information to business clients

Our professional data generally consists of information made available in a business or professional context, including names, job titles, professional roles, organisations, office addresses, work email addresses, business telephone numbers, regulatory information and professional profile URLs.

We do not intentionally collect contact details that are clearly published solely for personal or domestic use.

Electronic marketing

When sending or arranging electronic marketing, we consider both UK data-protection law and PECR.

The applicable rules depend on the recipient and communication channel. Limited companies, LLPs and other corporate subscribers are treated differently from sole traders and certain partnerships.

We do not assume that every publicly available business email address can automatically be used for marketing.

Where PECR requires consent, including for certain communications to individual subscribers, sole traders and some partnerships, we will send the communication only where we have valid consent or another applicable PECR permission, such as the soft opt-in.

Where PECR does not require consent, we may rely on legitimate interests under the UK GDPR, provided the use of the information is necessary, proportionate and fair.

Live telephone marketing

Where we undertake live telephone marketing, we apply the rules relevant to the recipient and screen telephone numbers against the Telephone Preference Service, Corporate Telephone Preference Service and our own suppression records where required.

We will not make further marketing calls to a person or organisation that has told us it does not wish to receive them.

Marketing safeguards

Where we send or arrange business marketing, we take proportionate steps to:

  • Identify the organisation responsible for the communication
  • Provide valid contact details
  • Assess the intended audience and relevance of the communication
  • Identify and document the applicable lawful basis
  • Apply the PECR rules relevant to the recipient and communication channel
  • Provide a clear and simple way to opt out or object
  • Record and respect objections, withdrawals and suppression preferences
  • Provide or link to relevant privacy information within the period required by law
  • Avoid using unnecessary or sensitive personal information

Campaigns undertaken for clients

Where Chronicle Law delivers a campaign for a client, our contract identifies the parties’ data-protection roles and responsibilities.

Depending on the campaign, Chronicle Law and the client may each act as independent controllers, or Chronicle Law may act as a processor where it uses information solely on the client’s documented instructions.

Where Chronicle Law and a client jointly determine the purpose and essential means of a campaign, we will consider whether the parties are joint controllers and put an appropriate arrangement in place where required.

Information supplied or licensed to clients

We may supply or license professional business contact information to clients for agreed lawful business purposes.

Clients receiving professional information are required to:

  • Use it only for agreed and lawful purposes
  • Identify and document their own lawful basis
  • Comply with UK GDPR, PECR and other applicable law
  • Provide their own privacy information where required
  • Respect objections, opt-outs and suppression preferences
  • Keep the information appropriately secure
  • Avoid disclosing or reselling the information unless expressly authorised and lawful
  • Delete or return the information where required by the applicable agreement

A client that determines why and how it uses supplied information will normally act as an independent controller and will be responsible for its own processing.

8. Segmentation, profiling and automated decisions

We may segment professional information using factors such as:

  • Organisation
  • Job title and seniority
  • Professional role
  • Department or practice area
  • Location
  • Firm size
  • Areas of professional interest
  • Previous content or campaign interactions

This helps us select relevant audiences, avoid irrelevant communications, understand campaign performance and provide more appropriate content and services.

We do not use personal information to make solely automated decisions that produce legal effects or similarly significant effects on individuals.

9. Who we share personal information with

We may disclose personal information, where necessary, proportionate and lawful, to:

  • Customers and clients receiving our publishing, professional-data, research, marketing, telephony or business-development services
  • Clients to whom we supply or license professional business information
  • Clients for whom we promote webinars, events, educational content, products or services
  • Website-hosting, security, email-delivery, webinar, analytics, customer-management, telephony, payment, accounting and administrative service providers
  • Professional advisers, including lawyers, accountants, insurers and auditors
  • Regulators, courts, law-enforcement bodies, tax authorities and other public bodies where disclosure is required or permitted by law
  • Prospective buyers, sellers, funders and professional advisers involved in a genuine business sale, investment, restructuring or transfer, subject to appropriate confidentiality safeguards
  • Other recipients where you ask us to make the disclosure or provide valid consent

Where a supplier acts as our processor, we require it to use personal information only in accordance with our instructions, apply appropriate security measures and meet applicable data-protection requirements.

Where we supply professional information to a business client that determines its own purposes and means of processing, that client will normally act as an independent controller. It will be responsible for providing its own privacy information and complying with data-protection and electronic-marketing law.

You may contact us to ask for more information about the types of recipient to whom your personal information has been disclosed. Where your rights entitle you to information about specific recipients, we will provide that information subject to any applicable exemptions.

10. International transfers

We primarily operate in the United Kingdom. However, some service providers we use may process, store or access personal information outside the United Kingdom.

Where personal information is transferred internationally, we take steps to ensure that the transfer complies with applicable data-protection law.

Depending on the destination and circumstances, safeguards may include:

  • UK adequacy regulations
  • The UK International Data Transfer Agreement
  • The UK Addendum to the EU Standard Contractual Clauses
  • Another lawful transfer mechanism

We may also transfer personal information outside the United Kingdom where this is necessary to provide a service requested by a customer, comply with a legal obligation, or establish, exercise or defend legal claims.

You may contact us for further information about the safeguards applicable to your personal information.

11. How long we keep personal information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including applicable legal, regulatory, taxation, accounting, security and dispute-resolution requirements.

When determining a retention period, we consider:

  • The purpose for which the information is used
  • The amount, nature and sensitivity of the information
  • The source and age of the information
  • The potential risk of harm from continued retention or unauthorised use
  • Whether the information remains accurate and relevant
  • Whether the purpose can be achieved in another way
  • Applicable legal, regulatory and contractual requirements

Customer, contractual, invoicing and accounting records are normally retained for six years after the end of the relevant customer relationship or transaction. They may be retained for longer where necessary to comply with a legal obligation or establish, exercise or defend legal claims.

Historical copies of professional information supplied or used in connection with a client service may be retained for audit, contractual, compliance and dispute-resolution purposes. Such information is not treated as current professional information or reused for new marketing activity.

Historical client-service records are normally deleted or anonymised six years after completion of the relevant service unless a longer period is required for legal, regulatory or contractual reasons.

Professional business information used for current services is reviewed and updated periodically using appropriate public and professional sources. We aim to review active professional records at least every 24 months and may review them more frequently where practical.

Information found to be inaccurate, obsolete or no longer relevant will be corrected, removed from active use, deleted or anonymised unless it must be retained for legal, compliance or suppression purposes.

Information identifying the source of a professional record may be retained for as long as that record remains in active use or forms part of a historical client-delivery record.

General enquiries and related correspondence are normally retained for up to two years after the last meaningful contact unless a longer period is required in connection with a contract, complaint or legal claim.

Telephone outreach records and ordinary campaign notes are normally retained for up to two years after the relevant campaign or last meaningful contact unless they form part of a customer contract, complaint, legal matter or suppression record.

Newsletter subscription information is retained for as long as the individual remains subscribed.

Website logs, cookie information and analytics data are retained for the periods described in our cookie information or configured within the relevant website, security and analytics services.

Where someone objects to direct marketing or opts out, we may retain the minimum information needed on a suppression record for as long as necessary to continue respecting that preference. Suppression information is not used to send marketing.

12. Security

We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure, access or destruction.

These measures may include:

  • Access controls
  • Secure accounts and systems
  • Staff and supplier confidentiality requirements
  • Security monitoring
  • Backups
  • Data-minimisation procedures
  • Supplier due diligence
  • Incident-response procedures
  • Restricting access to people with a legitimate business need

No method of transmitting or storing information is completely secure. However, we review our safeguards and take proportionate steps to manage the risks associated with the information we process.

13. Cookies, tracking technologies and website analytics

Our website uses cookies and similar technologies.

Some cookies are essential for the website to operate, remain secure, remember necessary settings and provide services requested by visitors. These cookies do not require consent where they are strictly necessary.

We may also use non-essential cookies or similar technologies for purposes such as:

  • Measuring website traffic and performance
  • Understanding how visitors use the website
  • Remembering preferences
  • Supporting embedded content and videos
  • Measuring engagement with content and campaigns
  • Supporting marketing and advertising

Where consent is required, non-essential cookies and tracking technologies will not be activated unless and until the visitor has provided that consent.

Visitors can accept, reject or manage non-essential cookies through the website’s cookie controls. Consent can be withdrawn or preferences changed through those controls. Cookies can also be managed through browser settings, although blocking essential cookies may affect website functionality.

Details of the cookies and technologies currently used, their providers, purposes and retention periods are available in our cookie information:

14. Your data-protection rights

Depending on the circumstances, you may have the right to:

  • Ask for access to your personal information and information about how it is used
  • Ask us to correct inaccurate or incomplete information
  • Ask us to erase personal information in certain circumstances
  • Ask us to restrict processing in certain circumstances
  • Object to processing based on legitimate interests
  • Object at any time to the use of your personal information for direct marketing
  • Receive certain information in a structured, commonly used and machine-readable format, or ask us to transfer it, where the right to data portability applies
  • Withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal
  • Complain to the Information Commissioner’s Office

These rights are not all absolute and may not apply in every circumstance.

We may need to verify your identity and may request information reasonably required to locate the relevant records.

We normally respond to a valid request within one month. The law allows this period to be extended in certain circumstances. We will explain if an exemption applies or if we require additional time.

15. Marketing preferences and objections

You have an absolute right to object to the use of your personal information for direct marketing.

You can:

  • Use the unsubscribe link in a marketing email
  • Tell our caller that you do not wish to receive further calls
  • Contact us at brett@chroniclelaw.co.uk
  • Telephone us on 07480 990 290

Once we receive an objection to direct marketing, we will stop using your personal information for that purpose.

We may retain the minimum information required on a suppression record to ensure that your preference continues to be respected. A suppression record is not used to send marketing.

Withdrawing from marketing does not necessarily require us to delete information that we must retain for another lawful purpose, such as accounting, contractual records, legal claims or suppression.

16. Complaints

Please contact us first if you have a concern about how we have used your personal information so that we can try to resolve it.

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113

The Information Commissioner’s Office may update its contact details. You may wish to check its website before submitting a complaint.

17. Contact us

For questions about this policy, to exercise a data-protection right or to object to direct marketing, please contact:

B Shaw Ltd, trading as Chronicle Law
2 Merchant Corner
Markeaton Street
Derby
DE22 3AP

Email: brett@chroniclelaw.co.uk
Telephone: 07480 990 290
Contact: Brett Shaw, Director

18. Changes to this policy

We may update this policy from time to time to reflect changes in our services, processing activities, suppliers or the law.

The latest version will be published on our website and will display its effective date.

Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected individuals.