Privacy Policy

Contents

    1. Definitions.
    2. Name and Address of the controller.
    3. Name and Address of the Data Protection Contact
    4. Cookies.
    5. Collection of general data and information.
    6. Our Legal Bases.
    7. Sharing Your Information.
    8. Retention, Routine erasure and blocking of personal data.
    9. Your Rights.
    10. Exceptions.
    11. Payments and GDPR.
    12. International transfers of personal data.
    13. Changes to this Privacy Policy.

 

For the purpose of this policy, Kalen Legal means Kalen Legal, Shenick Drive, Skerries, Co Dublin, Ireland, a sole practitioner legal firm registered with the Law Society of Ireland.  Principal is Odhran Banim.

This policy applies to the legal services we provide you, your use of our website and apps, and where we pass your details on to insurance or finance providers or other third parties as part of the provision of our services, or your payment for our services. 

It also applies even if you’re not one of our clients, but you interact with us as part of us running our business, for example by:

  • Availing of our services via a third party
  • acting with authorisation on behalf of one of our clients
  • generally enquiring about our services

If you need to give us personal information about someone else in relation to our services, this privacy notice will also apply to their information. We may need the permission of the other person to use that information and will seek relevant consents where required.

Data protection is of a particularly high priority for the management of Kalen Legal.  The processing of personal data, such as the name, address, e-mail address, or telephone number of a data subject, shall always be in line with the General Data Protection Regulation (GDPR), the Data Protection Act 2018, and any other data protection legislation applicable to Kalen Legal.  By means of this data protection declaration, we wish to inform you of the nature, scope, and purpose of the personal data we collect, use, and process, as well as of your rights.

If the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain consent from the data subject.

Whilst Kalen Legal has implemented robust technical and organisational measures to ensure protection of personal data processed through the website or any apps, internet-based data transmissions may have security gaps outside our control and so absolute protection may not be guaranteed. For this reason, you may ask to transfer data to us via an alternative means (e.g. by telephone).

1. Definitions

The data protection declaration of Kalen Legal is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). The following terminology is used throughout:

Personal data:  Personal data means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Data subject: Data subject is any identified or identifiable natural person, whose personal data is processed by the controller responsible for the processing.

Processing: Processing is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Restriction of processing: Restriction of processing is the marking of stored personal data with the aim of limiting their processing in the future.

Profiling: Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

Pseudonymisation:  Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

Controller or controller responsible for the processing: Controller or controller responsible for the processing is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Processor: Processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Recipient: Recipient is a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.

Third party: Third party is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Consent: Consent of the data subject is any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.

2. Name and Address of the controller

Controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in member states of the European Union and other provisions related to data protection is:

Kalen Legal

29 Shenick Drive, Skerries, Co. Dublin, K34 ED95

+ 353 1 9692092

info@kalenlegal.com

3. Name and Address of the Data Protection Contact

The Data Protection Contact of Kalen Legal — who may be contacted in relation to any data protection matter, including any request to exercise your rights under the GDPR and the Data Protection Act 2018 — is:

Odhran Banim

Partner

obanim@kalenlegal.com

+ 353 83 194 4783

4. Cookies

The Internet pages of Kalen Legal use cookies. Cookies are text files that are stored in a computer system via an Internet browser. Kalen Legal generally only uses strictly necessary cookies, which are required for the website to function.  This does not require consent in line with the GDPR and the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011).  Where cookies are not strictly necessary for the operation of our website, we set them only with your prior consent, which we obtain by means of a cookie consent banner displayed when you first visit our website. You can withdraw or change your consent at any time using the cookie settings on our website.

Through the use of cookies, Kalen Legal can provide the users of this website with more user-friendly services that would not be possible without the cookie setting.  By means of a cookie, the information on our website can be optimised with the user in mind. Cookies allow us, as previously mentioned, to recognise our website users. The purpose of this recognition is to make it easier for users to utilise our website. The website user that uses cookies, e.g., does not have to enter access data each time the website is accessed, because this is taken over by the website, and the cookie is thus stored on the user’s computer system.

You may, at any time, prevent the setting of cookies through our website by means of a corresponding setting of the Internet browser used and may permanently deny the setting of cookies.  Furthermore, already set cookies may be deleted at any time via an Internet browser or other software programs.  If you deactivate the setting of cookies in the Internet browser used, not all functions of our website may be entirely usable.

5. Collection of general data and information

  1. For the purpose of providing our Services

Providing legal services: If you are our client, we will collect and use information relating to you relating to the type of legal services we provide to you and also as part of our administrative, financial and operational processes. This information may include your contact details, payment and financial information, marketing profiles (including information, newsletters and invites for events you may be interested in), and client relationship management and feedback information, in addition to the information you give us so we can provide legal services to you (which may include sensitive personal data). We will also collect and process AML information (described below). In carrying out this processing we rely on the following legal bases: contractual necessity, compliance with our legal obligations and legitimate interests (described below).

If you are not a client, we may also collect, use and otherwise process your information in the course of providing legal advice and assistance to our clients where your information is considered by us or our clients to be relevant to the legal advice and assistance we provide to our clients. The precise information will depend on what legal advice and assistance we are giving. For instance, if we are advising on a claim or dispute that involves you, the information will include any information about you that is relevant to that claim. In carrying out this processing we rely on the following legal bases: compliance with our legal obligations and legitimate interests (described below).

AML compliance: We may collect and use your information in the context of compliance with anti-money laundering (AML) laws and our regulatory obligations. This includes your ID and proof-of-address information as required by law and practice.  In carrying out this processing we rely on the following legal bases: compliance with our legal obligations.

Business contacts: If you are a current or former client or have agreed that we may stay in touch with you in relation to updates and events, we will include your information in our database. We do so to keep in touch with you such as to send you communications, surveys and marketing about our Services; to identify what other events or Services we think you might be interested in; and understand how you use our Services. We add business contact information to our databases to provide insights to understand who is requesting our Services. We also keep business contact information including information about meetings and communications between our staff and you in the past for business intelligence purposes. We may receive your business contact information directly from you, as a client or from business cards, or we may get your information from third party sources, such as your website or professional network profile. In carrying out this processing we rely on the following legal bases: legitimate interests.

Sensitive Information: In the course of providing legal Services, we may process certain information that attracts special protection under law. For example, in the context of litigation or disputes, we might process information relating to health (e.g. your medical condition), genetics, race, religious beliefs, sex life, sexual orientation, or trade union membership. This information could be in respect of a client, a claimant, witness or an individual otherwise connected with a case or other legal matter.  We rely on exceptions contained in Article 9 of the GDPR and in the Data Protection Act 2018 to process this information.

Information about third parties: If you provide information to us about any person other than yourself, you should ensure that you have a legal basis for doing so and that you have complied with your transparency obligations under data protection law.  The Data Protection Act 2018 provides that processing of special categories of personal data shall be lawful where necessary for the purposes of providing or obtaining legal advice or for the purposes of, or in connection with, legal claims, prospective legal claims, legal proceedings or prospective legal proceedings, or is otherwise necessary for the purposes of establishing, exercising or defending legal rights.  You should always try to limit the personal information you give us to what you think is necessary for us to provide you with legal advice and assistance.

  1. Via our Website, Social Media and Apps

The website of Kalen Legal collects a series of general data and information when a data subject or automated system calls up the website. This general data and information are stored in the server log files. Collected may be (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrers), (4) the sub-websites, (5) the date and time of access to the Internet site, (6) an Internet protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) any other similar data and information that may be used in the event of attacks on our information technology systems.

When using these general data and information, Kalen Legal does not draw any conclusions about the data subject. Rather, this information is needed to (1) deliver the content of our website correctly, (2) optimise the content of our website as well as its advertisement, (3) ensure the long-term viability of our information technology systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attack. Therefore, Kalen Legal analyses anonymously collected data and information statistically, with the aim of increasing the data protection and data security of our enterprise and to ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from all personal data provided by a data subject.

In carrying out this processing we rely on the following legal bases: our legitimate interest in ensuring the network and information security, integrity and proper functioning of our website and IT systems. These server log files are retained only for as long as is necessary for these purposes and are then erased.

The website of Kalen Legal contains information that enables quick electronic contact with our enterprise, as well as direct communication with us, which also includes a general address of the so-called electronic mail (e-mail address). If a data subject contacts the controller by e-mail or via a contact form via our website, or on our social media pages or apps. the personal data transmitted by the data subject are automatically stored. Such personal data transmitted on a voluntary basis by a data subject to the data controller are stored for the purpose of processing or contacting the data subject. There is no transfer of this personal data to third parties.

6. Our Legal Bases

In order to collect, use, share, and otherwise process your information for the purposes described in this Notice, we rely on a number of legal bases, some of which are mentioned above, including where:

  1. Contractual Necessity: necessary to perform a contract we have with you and to provide the Services;
  2. Consent: you have consented to the processing (in which case you may revoke your consent at any time);
  3. Compliance with Law: necessary for us to comply with a legal obligation, or to establish, exercise or defend legal claims;
  4. necessary to protect your vital interests or those of others;
  5. necessary in the public interest;
  6. Legitimate Interest: necessary for Kalen Legal or a third party’s legitimate interests, such as those of clients, partners, staff or others, provided that those interests are not overridden by your interests or fundamental rights and freedoms. Our Legitimate Interests include the following:
  • Provision of legal services: We use your information to pursue our clients and other impacted individuals’ legitimate interests in obtaining and/or benefitting from legal advice and assistance, as well as our interests in providing legal advice and assistance to our clients.
  • Keeping our Services Safe and Secure: We use your information in certain instances as necessary to pursue our and your legitimate interests of keeping some of our Services, such as our domains, websites, apps, offices and events, safe and secure.
  • Marketing our Services: We use your information as necessary to pursue our legitimate interests in marketing our Services, and tailoring and improving our Services. For example, where permitted by digital marketing law we may contact you by email to let you know of future events you might be interested in.
  • Business Intelligence: We use your information as necessary to pursue our legitimate interests in understanding who is requesting and using our Services.

Under the Data Protection Act 2018, the processing of special categories of personal data shall be lawful where the processing is necessary for the purposes of providing or obtaining legal advice or for the purposes of, or in connection with, legal claims, prospective legal claims, legal proceedings or prospective legal proceedings, or is otherwise necessary for the purposes of establishing, exercising or defending legal rights.

7. Sharing Your Information

In the course of providing the Services, we may share information with various third parties, including service providers, clients, mediators, arbitrators, translators, couriers, barristers, other solicitors and law firms, independent experts, witnesses, insurance companies, actuaries, summons servers, private investigators, government departments, regulators, and statutory and public bodies.

We do this based upon the legal bases and exceptions mentioned in section 6 of this policy.

Legal and safety reasons: We may retain, preserve, or share your information if we have a good-faith belief that it is reasonably necessary to (a) respond, based on applicable law, to a legal request (e.g., a subpoena, search warrant, court order, or other request from government or law enforcement); (b) detect, investigate, prevent, and address fraud and other illegal activity, security, or technical issues; (c) protect our rights, property, or safety; (d) enforce our Terms of Engagement or any other contracts we have with you; (e) prevent physical injury or other harm to any person or entity, including you and members of the public.

8. Retention, Routine erasure and blocking of personal data

We shall process and store your personal data only for the period necessary to achieve the purpose of storage, or as far as this is granted by the European legislator or other legislators in laws or regulations to which we are subject to.

We take account of guidance issued by the Law Society of Ireland in determining how long to store client files. We also have certain legal obligations to retain certain information for specific periods such as AML information.  In general, we will retain information and documents relating to a matter on which we has acted for between 6 and 15 years after the matter is completed.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. We also consider regulatory and Law Society guidance, as appropriate.

9. Your Rights

You have a number of rights in relation to your information that we process. To exercise these rights, please contact us at info@kalenlegal.com

a) Right of confirmation

You have the right to confirmation as to whether or not personal data concerning you is being processed by Kalen Legal.

b) Right of access

You have the right to obtain information about your personal data stored at any time and a copy of this information free of charge.  You can request your information verbally, in writing, or electronically.  If a request is made by a third party (e.g. a solicitor or union representative), proof of authority must be supplied. 

Requests must clearly identify the individual and, if possible, specify the data sought to help locate it efficiently.  We will respond to your request within one month of receipt, but reserve the right to extend the response period for up to two additional months if the request is complex or numerous.  We will inform you if an extension is required and the basis for same.

We will respond in electronic format unless we advise you otherwise.  Information is provided free of charge but a reasonable fee may be charged for further copies or if the request is manifestly unfounded or excessive

We may refuse a request for access of information if the data subject’s identity cannot be verified or if the request is clearly excessive. We will communicate any refusal to you with reasons and information on the right to complain to the DPC or seek judicial remedy.

c) Right to rectification

You have the right to request the rectification of inaccurate personal data concerning you, including the right to have incomplete personal data completed, including by means of providing a supplementary statement.

d) Right to erasure (Right to be forgotten)

You have the right to request the the erasure of personal data concerning you without undue delay, and Kalen Legal shall have the obligation to erase personal data without undue delay where one of the following grounds applies, as long as the processing is not necessary:

  • The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
  • The data subject withdraws consent to which the processing is based according to point (a) of Article 6(1) of the GDPR or point (a) of Article 9(2) of the GDPR, and where there is no other legal ground for the processing.
  • The data subject objects to the processing pursuant to Article 21(1) of the GDPR, and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) of the GDPR.
  • The personal data have been unlawfully processed.
  • The personal data must be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject.
  • The personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR.

Where Kalen Legal has made personal data public and is obliged pursuant to Article 17(1) to erase the personal data, Kalen Legal, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform other controllers processing the personal data that you have requested erasure by such controllers of any links to, or copy or replication of, those personal data, as far as processing is not required.

e) Right of restriction of processing

You have the right to restriction of processing where one of the following applies:

  • The accuracy of the personal data is contested by the data subject for a period enabling the controller to verify the accuracy of the personal data.
  • The processing is unlawful, and the data subject opposes the erasure of the personal data and requests instead the restriction of its use.
  • The controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims.
  • The data subject has objected to processing pursuant to Article 21(1) of the GDPR pending the verification of whether the legitimate grounds of the controller override those of the data subject.

f) Right to data portability

You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format, and to transmit that data to another controller without hindrance (or, where technically feasible to have the personal data transmitted directly to another processor), as long as the processing is based on consent or contract, and the processing is carried out by automated means and is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.  Where technically fe

g) Right to object

You have the right to object, on grounds relating to your particular situation, at any time, to processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to profiling based on these provisions.

Kalen Legal will no longer process the personal data in the event of the objection, unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.

If Kalen Legal processes personal data for direct marketing purposes, you have the right to object at any time to processing of personal data for such marketing. This applies to profiling to the extent that it is related to such direct marketing.

h) Automated individual decision-making, including profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you.  Kalen Legal does not use decision based automated processing or profiling.

i) Right to withdraw data protection consent

You have the right to withdraw consent to the processing of your personal data at any time.

j) Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement, if the data subject considers that the processing of personal data relating to them infringes the GDPR or the Data Protection Act 2018. In Ireland, the supervisory authority is the Data Protection Commission, which may be contacted at 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland, or through its website at www.dataprotection.ie. This right is without prejudice to any other administrative or judicial remedy.

10. Exceptions

These rights are subject to a number of exceptions under law. For instance, the Irish Data Protection Act 2018 provides that certain of your rights under the GDPR and Data Protection Act 2018 (such as the right of access and objection) may not apply:

  • to personal data processed for the purpose of seeking, receiving or giving legal advice,
  • to personal data in respect of which a claim of privilege could be made for the purpose of or in the course of legal proceedings, including personal data consisting of communications between a client and his or her legal advisers or between those advisers, or
  • where the exercise of such rights or performance of such obligations would constitute a contempt of court.

Kalen Legal will review each request received in accordance with the law and its legal requirements.

11. Payments and GDPR

We collect and store your transactional information in order to enable you to view certain details of all your transactions which have been made using our services, to provide you uninterrupted and satisfactory services, to administer our relationship with you, to comply with any statutory or regulatory requirement, and to ensure accurate billing for our services.

12. International transfers of personal data

Some of our third-party service providers (for example, providers of social media plug-ins and web analytics services) may be established outside the European Economic Area (EEA), including in the United States of America. Where we, or our processors, transfer personal data to a country outside the EEA, we ensure that the transfer is subject to appropriate safeguards as required by Chapter V of the GDPR. These safeguards include transfers to countries that the European Commission has decided ensure an adequate level of protection, transfers made under the European Commission’s Standard Contractual Clauses, and, where applicable, transfers to organisations certified under the EU–US Data Privacy Framework. You may request further information about these safeguards, and a copy of the relevant safeguards, by contacting us using the details set out in this Privacy Policy.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory or operational reasons. Any changes will be published on this page and, where appropriate, notified to you. This Privacy Policy was last updated on 15 June 2026.

We use cookies to enhance your experience and analyse website traffic. Learn more about our cookie policy.