Privacy
Privacy notice
Last updated 12 June 2026
Scope
This notice describes how Aegis Legal Technology Advisory collects, uses and protects personal data through this website and in the course of client engagements. It applies to prospective clients, clients, candidates and website visitors.
Data we collect
Information you provide directly: name, work email, organisation, role, and the content of enquiries or consultation requests.
Information collected automatically: pages visited, referring source, approximate location derived from IP address, and device or browser type. We do not use advertising cookies or third-party tracking pixels.
Information received during engagements: contact details of client personnel and any material shared with us under the engagement letter.
How we use it
To respond to enquiries and arrange consultations; to deliver and administer engagements; to send requested reports or frameworks; to comply with legal, regulatory and professional obligations; and to improve the operation of this website.
We do not sell personal data, and we do not share it with vendors for marketing purposes.
Legal basis
Where the GDPR or equivalent legislation applies, we process personal data on the basis of legitimate interests (responding to business enquiries and operating the firm), performance of a contract (delivering engagements), consent (where you request materials), and legal obligation.
Confidentiality and privilege
Material received during engagements is treated as confidential and, where applicable, privileged. Access is restricted to engagement personnel, segregated by client, and governed by the security controls set out in the engagement letter.
Retention
Enquiry data is retained for 24 months from last contact. Engagement records are retained for seven years following completion, or longer where a legal hold or regulatory obligation applies. Candidate data is retained for 12 months unless you ask us to keep it longer.
International transfers
Aegis operates in the United States, the United Kingdom and Singapore. Where personal data is transferred between these locations we rely on standard contractual clauses or an equivalent recognised transfer mechanism.
Your rights
Subject to applicable law you may request access to, correction of, or deletion of your personal data; object to or restrict processing; and request portability. Requests should be sent to advisory@aegis-legal.com and are answered within 30 days.
Security
We maintain administrative, technical and physical safeguards aligned to ISO 27001 and SOC 2 control objectives, including encryption in transit and at rest, least-privilege access, logging, and annual third-party assessment. Our security documentation is available to clients under NDA.
Contact
Questions about this notice, or about how we handle personal data, should be directed to advisory@aegis-legal.com or to Aegis Legal Technology Advisory, One Bryant Park, 42nd Floor, New York, NY 10036.
Questions
Need something clarified?
Legal, procurement and security teams can reach us directly for documentation, DPAs or vendor assessment responses.