Privacy
Privacy Policy
This policy explains how Lawyal Group handles personal data submitted through our website, CRM intake forms, appointments, and official communication channels.
Last updated: 26 May 2026
Who is responsible for your data
Lawyal Group is responsible for the personal data collected through lawyalgroup.com and crm.lawyalgroup.com. You can contact us at gdpr@lawyalgroup.com for privacy questions, access requests, correction requests, or deletion requests.
Data we collect
We may collect contact details, appointment details, inquiry messages, preferred language, service interest, payment status references, and documents or information you choose to provide for legal service intake.
When you contact us through Instagram, Facebook, WhatsApp, YouTube, email, or web forms, we may store the inbound message, profile or channel identifier, message time, and case-linking notes in our CRM inbox.
Why we use personal data
We use personal data to respond to inquiries, schedule appointments, assess service requests, prepare engagement and payment steps, manage client matters, provide legal services, meet legal obligations, protect our systems, and maintain business records.
We do not use social channels as the place where legal procedures, document collection, or payment processing are completed. Those steps are handled through Lawyal CRM and approved service workflows.
Legal basis
Depending on the context, we process data based on your consent, pre-contractual or contractual necessity, legitimate interests in operating secure professional services, and legal obligations that apply to our work.
Service providers and transfers
We may use trusted providers such as Firebase/Google Cloud, Google reCAPTCHA Enterprise, Google Maps, Stripe, email providers, and Meta channel tools to operate our website, CRM, security controls, communication intake, and payment workflows.
Where providers process data outside the European Economic Area, we rely on appropriate transfer safeguards required by applicable data protection law.
Retention and security
We keep personal data only for as long as needed for the purpose collected, legal service administration, accounting, compliance, dispute management, and security logs.
Client files are stored in restricted CRM storage areas with role-based access controls. Sensitive documents are not stored in social channel metadata or payment metadata.
Security logging and IP addresses
When you attempt to sign in to the client portal, we collect and display your IP address and generate an incident identifier. This information is used to detect, prevent, and investigate unauthorized access attempts.
IP addresses associated with failed or suspicious sign-in attempts may be retained in security logs for up to 12 months. Successful sign-in IP data is retained only for session integrity purposes and removed after 30 days.
This processing is based on our legitimate interest in maintaining the security of our systems and protecting client data.
Your rights
You may request access, correction, deletion, restriction, portability, or objection where applicable. You may also withdraw consent where processing is based on consent.
To exercise your rights, email gdpr@lawyalgroup.com with enough information for us to identify the relevant request or communication channel.
Privacy, terms, and deletion requests can be sent to gdpr@lawyalgroup.com.