The Legal Design School 

PRIVACY POLICY

Welcome to the website of The Legal Design School (“Website”), an initiative by Dot., operated by Dottir Attorneys Ltd (Company ID: 2733840-7) (“we”).

 

This Privacy Policy is applicable to the users of the Website (“you” or “User”). This Privacy Policy describes how we process the personal data concerning the Users.

 

We may update this Privacy Policy if it is necessary in order to reflect the changes in data processing practices or otherwise. 

 

Please note that this Privacy Policy applies to processing of personal data carried out by us as data controller.

 

CONTROLLER’S CONTACT DETAILS

Name: Dottir Attorneys Ltd
Company ID: 2733840-7

Correspondence address: Pohjoisesplanadi 35 Aa, 00100 Helsinki, Finland
E-mail address: hello@dot.legal

www.dot.legal

 

Contact person: Antti Innanen, antti@dot.legal

PERSONAL DATA PROCESSED AND SOURCES OF DATA

The personal data collected and processed by us in accordance with this Privacy Policy can be divided into two general data categories: i) User Data and iii) Analytics Data.

 

User Data

 

We may process the following User Data relating to you:

 

  • name

  • email address

  • other contact details

  • correspondence with you

 

You can always refuse to supply User Data but doing so may prevent you from engaging in certain Website related activities. 

 

Typically we receive the User Data directly from you at the point of registration on the Website. Some of the User Data may also be generated by us, such as correspondence between you and our representatives.

 

Analytics Data

 

The logging systems on the Website automatically log certain Analytics Data when you visit the Website. Although we do not normally use Analytics Data to identify you as an individual, you can sometimes be recognized from it, either alone or when combined or linked with User Data. In such situations, Analytics Data can also be considered personal data under applicable laws and we will treat such data as personal data.

 

We may automatically collect the following Analytics Data when you visit or interact with the Website:

 

  • Device Information. We collect the following information relating to the technical device you use when using the Website:

  • IP address

  • browser type and version

  • operating system

  • name of your Internet service providers

 

  • Usage Information. We collect information on your use of the Website, such as:

  • time spent on the Website 

  • time and date of your visits to the Website

  • sections of the Website you visited         

 

Cookies

We use various technologies to collect and store Analytics Data and other information when Users visit the Website, including cookies.

Cookies are small text files sent and saved on your device that allows us to identify visitors of the Website and facilitate the use of the Website and to create aggregate information of the Users. This helps us to improve the Website and better serve the Users. The cookies will not harm your device or files. We use cookies to tailor the Website and the information we provide in accordance with the individual interests of our Users. 

Users may choose to set their web browser to refuse cookies, or to alert when cookies are being sent. For example, the following links provide information on how to adjust the cookie settings on some popular browsers: 

Safari

Google Chrome

Internet Explorer

Mozilla Firefox

Please note that some parts of the Website may not function properly if use of cookies is refused.

Web analytics services

Our Website use Google Analytics and other web analytics services to compile Analytics Data and reports on User usage and to help us improve the Website. For an overview of Google Analytics, please visit Google Analytics. It is possible to opt-out of Google Analytics with the following browser add-on tool: Google Analytics opt-out add-on

PURPOSES AND LEGITIMATE GROUNDS FOR PROCESSING OF PERSONAL DATA 

Purposes

 

Personal data is processed by us for the following purposes:

 

To provide and operate the Website


We process personal data in the first place to be able to offer the Website to the Users. We may use the data for example to create a user account for you.

We may process personal data for the purpose of contacting Users regarding our servcies and to inform Users of changes in our services as well as to market our services.

For claims handling and legal processes

We may process your personal data in relation to claims handling and legal processes. We may also process data for the misuse of the Website and for data, system and network security.

For quality improvement and trend analysis 

We may process information regarding the use of the Website to improve the quality of the Website e.g. by analysing any trends in the use of the Website. When possible, we will do this using only aggregated, non-personally identifiable data.

Legitimate grounds for processing

 

We process personal data to pursue our legitimate interest to run, maintain and develop our business and to create and maintain customer relationships. When choosing to use your data on the basis of our legitimate interests, we weigh our own interests against your right to privacy and e.g. provideyou with easy to use opt-out from our marketing communications and use pseudonymized or non-personally identifiable data when possible.

In some parts of the Website, Users may be requested to grant their consent for the processing of personal data. In this event, Users may withdraw their consent at any time.

TRANSFER TO COUNTRIES OUTSIDE EUROPE

We store your personal data primarily within the European Economic Area. However, we have service providers in several geographical locations. As such, we and our service providers may transfer personal data to, or access it in, jurisdictions outside the European Economic Area or your domicile. 

If we transfer your personal data outside the European Economic Area, we provide adequate protection for such transfers through a series of agreements with our service providers based on the Standard Contractual Clauses or through other appropriate safeguards, such as the Privacy Shield Framework

PERSONAL DATA RECIPIENTS

We do not share personal data with third parties outside of our organization unless one of the following circumstances applies:

 

For legal reasons

We may share personal data with third parties outside our organization if we have a good-faith belief that access to and use of the personal data is reasonably necessary to: (i) meet any applicable law, regulation, and/or court order; (ii) detect, prevent, or otherwise address fraud, security or technical issues; and/or (iii) protect the Users’, our or the public’s interests, properties or safety in accordance with the law. When possible, we will inform Users about such transfer and processing.

 

To authorized service providers 

We may share personal data to authorized service providers who perform services for us (including data storage services). Our agreements with our service providers include commitments that the service providers agree to limit their use of personal data and to comply with privacy and security standards at least as stringent as the terms of this Privacy Policy.

For other legitimate reasons

If we are involved in a merger, acquisition or asset sale, we may transfer personal data to the third party involved. However, we will continue to ensure the confidentiality of all personal data. We will give notice to all Users concerned when the personal data are transferred or become subject to a different privacy policy as soon as reasonably possible.

With explicit consent

We may share personal data with third parties outside our organization for other reasons than the ones mentioned before, when we have the User’s explicit consent to do so. The User has the right to withdraw this consent at all times.

STORAGE PERIOD

We do not store personal data longer than is legally permitted and necessary for the purposes of providing the Website, our services or the relevant parts thereof. The storage period depends on the nature of the information and the purposes of processing. The maximum period may therefore vary per use.

We will store your User Data for as long as the you are a registered user of the Website and, thereafter, for no longer than is required by law or reasonably necessary for our legitimate interests for example for claims handling, internal reporting, marketing and reconciliation purposes. 

We will store Analytics Data relating to the Website for a period of six (6) months. 

USERS’ RIGHTS

Right to access

You have the right to access your personal data processed by us. Users may contact us and we will inform what personal data we have collected and processed regarding the said User.

Right to withdraw consent

In case the processing is based on a consent granted by User, User may withdraw the consent at any time. Withdrawing a consent may lead to fewer possibilities to use the Website and our services. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Right to rectify

Users have the right to have incorrect or incomplete personal data we have stored about the User corrected or completed. You can correct or update some of your personal data through your user account on the Website. 

Right to erasure

Users may also ask us to erase the User’s personal data from our systems. We will comply with such request unless we have a legitimate ground to not delete the data. 

Right to object

Users may object to the processing of personal data if such data are processed for other purposes than purposes necessary for the performance of our servicse to the User or for compliance with a legal obligation. In case we do not have legitimate grounds to continue processing such personal data, we shall no longer process the personal data after your objection.

Right to restriction of processing

Users may request us to restrict processing of personal data for example when your data erasure, rectification or objection requests are pending and/or when we do not have legitimate grounds to process your data. This may however lead to fewer possibilities to use the Website and our services.

Right to data portability

Users have the right to receive their personal data from us in a structured and commonly used format and to independently transmit those data to a third party.

How to use the rights

The above mentioned rights may be used by sending a letter or an e-mail to us on the addresses set out above, including the following information: the full name, company name, address, e-mail address and a phone number. We may request the provision of additional information necessary to confirm the identity of the User. We may reject requests that are unreasonably repetitive, excessive or manifestly unfounded. 

DIRECT MARKETING

Notwithstanding any consent granted beforehand for the purposes of direct marketing, User has the right to prohibit us from using User’s personal data for direct marketing purposes, market research and profiling made for direct marketing purposes by contacting us on the addresses indicated above or by using the functionalities of the Website or the unsubscribe possibility offered in connection with any direct marketing messages.

LODGING A COMPLAINT

In case User considers our processing of personal data to be inconsistent with the applicable data protection laws, a complaint may be lodged with the local supervisory authority for data protection.

INFORMATION SECURITY

We use administrative, organizational, technical, and physical safeguards to protect the personal data we collect and process. Measures include for example, where appropriate, encryption, firewalls, secure facilities and access right systems. Our security controls are designed to maintain an appropriate level of data confidentiality, integrity, availability, resilience and ability restore the data.

Should despite of the security measures, a security breach occur that is likely to have negative effects to the privacy of Users, we will inform the relevant Users and other affected parties, as well as relevant authorities when required by applicable data protection laws, about the breach as soon as possible.

© 2019 by Dot.

AN INITIATIVE BY