§ Privacy notice

How we handle your personal data

Last updated:

Lietuvių

This notice explains what personal data we hold, why we hold it, who we share it with, how long we keep it and what you can do about it. It is written for clients, for people we approach about our services, for people who contact us because we act as their organisation's data protection officer, and for visitors to this website.

Two points are worth knowing before the detail. First, information you share with us for legal advice is protected by professional secrecy, which is a stronger protection than data protection law alone provides. Second, we do not sell your data, and we do not make decisions about you by automated means without a person involved.

Who we are

MB HEXLaw ("HEXLaw", "we") is a company registered in Lithuania, with its registered office in Vilnius. We are the data controller for this website, for our data protection and compliance services, for our business contacts and for our marketing.

Where we provide legal services, those are provided by Migle Dewsbury, an assistant to an attorney-at-law (advokato padėjėja). Information you share in order to obtain legal advice is held under professional secrecy, which is explained below and which is a separate and stronger protection than this notice alone.

We have appointed a data protection officer. Their contact details are in the last section of this notice, and you can contact them directly about anything in it.

What data do we collect?

How much we hold depends entirely on how you deal with us. Someone who reads this website leaves us almost nothing. A client in an ongoing matter necessarily gives us a great deal.

Data you give us
  • Who you are: name, position, employer, email address, telephone number, and a postal address where one is needed.
  • Matter information: what you tell us about your legal or compliance question, the documents you send, and our correspondence with you.
  • Identity and anti-money-laundering information: copies of identity documents, beneficial ownership information and source of funds declarations, where the law requires us to carry out customer due diligence.
  • Billing information: invoicing details, VAT number and payment history.
Data we collect automatically

When you visit this website we collect technical data: IP address, browser and device, and the pages you looked at. Our cookie policy explains what is set and what you can refuse.

Data we collect from other sources

We research organisations we think may need our services, and in doing so we collect information about the people who work for them, usually a name, a role and a business email address. This is the one category of data we hold about people who have never contacted us, so it is worth being plain about where it comes from.

Our sources are publicly accessible: company and beneficial ownership registers, the organisation's own website and public filings, professional networking profiles, published decisions and enforcement notices of data protection authorities, and public news reporting.

We do this on the basis of our legitimate interest in identifying organisations that may need legal and data protection services, and we consider a business contact's professional details a proportionate thing to hold for that purpose. You can object at any time and we will stop, using the contact details at the end of this notice.

What do we use your data for?

Each purpose below names the lawful basis we rely on for it. Where that basis is our legitimate interest, we say what the interest is, and you have the right to object.

To act for you

Taking instructions, advising, drafting, corresponding on your behalf, producing deliverables, and invoicing for the work. Without this data we cannot act.

Legal basis · Performance of a contract, Art. 6(1)(b)

To check who you are, and to meet our anti-money-laundering duties

Customer due diligence, beneficial ownership checks, sanctions and politically exposed person screening, and record keeping, as required by Lithuanian anti-money-laundering and counter-terrorist-financing law. Where the law requires us to report, we must do so and we may be prohibited from telling you.

Legal basis · Legal obligation, Art. 6(1)(c)

To check for conflicts of interest

Before taking on work we check whether acting would conflict with our duties to an existing or former client. This requires us to hold a record of who we have acted for and against, including after a matter closes.

Legal basis · Legal obligation, Art. 6(1)(c), and our legitimate interest in complying with professional rules

To run and secure our systems

Access control, logging, backups, fault diagnosis and defending against attack. Our interest is in keeping client information safe, which is also your interest.

Legal basis · Legitimate interest, Art. 6(1)(f)

To tell you about our services

Contacting organisations we think we can help, and keeping existing clients informed about related services and about legal developments that affect them. We rely on legitimate interest for business contacts and on consent where the law requires it. You can object or withdraw consent at any time, and every message we send says how.

Legal basis · Legitimate interest, Art. 6(1)(f), or your consent, Art. 6(1)(a)

To comply with the law and to defend ourselves

Tax and accounting records, professional obligations, responding to lawful requests from authorities, and establishing or defending legal claims, including complaints about our own work.

Legal basis · Legal obligation, Art. 6(1)(c), and legitimate interest, Art. 6(1)(f)

Do you have to give us your data?

In some cases yes, and it is fairer to say so than to leave it implied.

  • Identity and anti-money-laundering information is a statutory requirement. If you do not provide it we are not permitted to act for you, and if we have already started we must stop.
  • Matter information is a contractual necessity. You decide what to tell us, but we can only advise on what we know, and gaps may mean we cannot give the advice you asked for.
  • Billing information is needed to perform the contract and to meet our accounting obligations.
  • Everything else is optional. Declining to receive marketing, or refusing non-essential cookies, has no effect on the service you receive.

Professional secrecy

Information entrusted to us in the course of legal work is covered by professional secrecy under the Lithuanian Law on the Bar. Article 39(3) obliges the lawyer to safeguard that information and not disclose it, and Article 46(1) provides that a lawyer cannot be called as a witness or required to give explanations about circumstances learned in performing professional duties.

This matters because it is wider than the protection data protection law gives you. It covers the fact that you approached us at all, the terms on which we were engaged, what you told us, and the advice we gave. It survives the end of the engagement.

It is not unlimited. Narrow exceptions exist where the law requires disclosure, most obviously under anti-money-laundering reporting duties. Where we rely on professional secrecy to decline a request, including a request from you to exercise a right under this notice, we will say so.

How do we use AI, and do we make automated decisions?

We use AI tools to help with research, review and drafting. A person reviews every output before it reaches you or is acted on, and the responsibility for the work is ours, not the tool's.

We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, by automated means alone. Where a tool ranks, scores or summarises, its output is an input to a human decision and never the decision itself.

AI services that process your data do so as our processors, under terms that prohibit using your data to train their models. Where you have told us you do not want AI assistance used on your matter, we record that and honour it.

Who do we share your data with?

We do not sell personal data and we do not share it for anyone else's marketing. We share it with the following kinds of recipient, and only as far as the purpose requires.

Service providers who help us run the firm

Cloud hosting and infrastructure, document storage and collaboration, email delivery, electronic signature, payment processing, accounting, marketing and website agencies, and AI services. They act on our instructions and may not use your data for their own purposes.

We keep a register of these providers and of the data protection terms agreed with each. Where terms are still being negotiated with a provider, that provider is recorded as such and is not given data beyond what the service requires. You can ask us which categories of provider hold your data.

Counterparties, courts, authorities and other professionals

Where acting for you requires it, and with your knowledge. This includes opposing parties and their lawyers, courts and tribunals, registries, notaries, and other advisers working alongside us.

Authorities, where the law requires it

Tax authorities, the financial crime investigation service, supervisory authorities and courts, where a legal obligation or a lawful order requires disclosure. Professional secrecy limits what can be required of us, and we apply it.

Our own advisers and insurers

Accountants, auditors, our professional indemnity insurer and our own lawyers, under confidentiality, and only where needed.

Does your data leave the European Economic Area?

Our infrastructure is hosted in the European Union. Some of the service providers we use are established outside the EEA, or are EEA entities that may route support or processing through group companies outside it, so some transfers do happen.

Where they do, we rely on the safeguards permitted by Chapter V of the GDPR: an adequacy decision of the European Commission where one covers the country in question, and otherwise the European Commission's standard contractual clauses, with additional technical and organisational measures where our assessment shows they are needed.

You are entitled to see the safeguards we rely on. Write to us using the contact details at the end of this notice and we will provide a copy of the relevant clauses, or tell you where they are published, redacted only so far as commercial confidentiality or another client's confidentiality requires.

If we act as your organisation's data protection officer

We provide an outsourced data protection officer service. If your employer or another organisation has appointed us as its DPO, you may contact us in that capacity under Article 38(4) of the GDPR about anything to do with your personal data or your rights.

It is worth being clear about who is responsible for what. Your organisation remains the controller of its own processing, and questions about what it does with your data are answered by it and by its own privacy notice. We are a controller in our own right only for what we hold in performing the DPO role: our advice and working papers, our record of the people who contact us, and our correspondence with the supervisory authority.

A data protection officer must act independently and cannot be instructed by the organisation on how to carry out the role. We are also bound to secrecy about the performance of those tasks under Article 38(5). In practice that means that if you raise something with us as DPO, we decide how to handle it, and we will tell you if we cannot keep it confidential from your organisation.

How long do we keep your data?

As a general rule we keep your data for as long as we are acting for you, and then for ten years after the matter closes. That period comes from our professional file-keeping obligations and from the limitation periods within which a claim about our work could still be brought.

Exceptions to the general rule

  • Anti-money-laundering records: eight years from the end of the business relationship, as required by law.
  • Accounting and tax records: ten years from creation, as required by law.
  • Conflict-checking records: kept indefinitely, but reduced to the minimum needed to run a conflict check, being the names of the parties and the nature of the matter. We cannot safely act for anyone if we cannot tell who we have acted against.
  • Business contacts and prospect research: three years from our last meaningful contact, or immediately on your objection.
  • Marketing consent: until you withdraw it, and we keep a record of the withdrawal itself so that we can honour it.
  • Website and technical data: as set out in our cookie policy.
  • Data held in our data protection officer role: for as long as we hold the appointment, and then for three years.

When a period ends we delete the data or anonymise it so that it can no longer be connected to you.

We keep backup copies of documents for up to 180 days. When we delete or erase your data, it is removed from our systems straight away and from our backups within 180 days, and it is not restored in the meantime.

How do we look after your data?

Technical measures

Encrypted connections, encryption of stored documents, access control so that people see only what their role requires, logging of access to client material, an append-only audit record for decisions of legal significance, and regular backups.

Organisational measures

A data protection officer overseeing how we handle your data, written internal policies, confidentiality obligations binding on everyone who works with us, contractual data protection terms with our service providers, and professional indemnity insurance.

Your part in it

Most incidents begin outside the systems that hold the data. Send us sensitive material through the channels we agree with you rather than whatever is convenient, keep your own access credentials to yourself, and tell us immediately if you think something has gone wrong. We would much rather hear about a false alarm.

Your choices

Separately from your legal rights, there are things you can simply decide.

  • What you tell us. Beyond what the law and the engagement require, what you share is up to you.
  • Whether we contact you about our services. You can say no at the outset or at any time afterwards.
  • Non-essential cookies. You can refuse them and the site will work.
  • Whether AI assistance is used on your matter. Tell us and we will record it.

Your rights

Data protection law gives you the following rights. Some are qualified, and professional secrecy and our retention obligations can limit what we are able to do. Where we cannot do what you ask, we will explain why.

  • Access: to be told whether we hold data about you and to receive a copy (Art. 15).
  • Rectification: to have inaccurate data corrected and incomplete data completed (Art. 16).
  • Erasure: to have data deleted where we no longer have grounds to keep it (Art. 17). Our legal retention duties often mean we cannot.
  • Restriction: to have processing paused while a dispute about it is resolved (Art. 18).
  • Portability: to receive data you gave us in a machine-readable form, or have it sent to someone else, where it is processed by automated means on consent or contract (Art. 20).
  • Objection: to object to processing based on legitimate interest, including prospect research and marketing (Art. 21). If you object to marketing we will stop, without exception.
  • Withdrawal of consent: at any time, without affecting what was lawful before you withdrew it.
  • Rights concerning automated decisions (Art. 22). As set out above, we do not take such decisions by automated means alone.
  • Complaint: to the supervisory authority.

To ask for a copy of what we hold about you, use our subject access request form. We will email you a link to confirm your email address, and we may ask for further proof of identity, for example an electronic signature. The month we have to answer runs from the day you send the form, not from the day you confirm.

To exercise any of the other rights, or if you would rather not use the form, write to us using the details below. We will answer within one month. If your request is complex we may extend that by a further two months, and we will tell you within the first month if we do. We may need to confirm your identity first, which is a protection for you rather than an obstacle.

Contact us

For anything in this notice, including exercising a right, write to privacy@hexlaw.ai.

Our data protection officer

We have appointed a data protection officer, who oversees how we handle personal data and who you can contact directly. Use the same address and mark your message for the data protection officer, or write to us at our registered office in Vilnius marking the envelope for their attention.

The supervisory authority

If you are not satisfied with how we have handled something, you can complain to the State Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija), the Lithuanian supervisory authority, at vdai.lrv.lt. We would rather you came to us first, but it is your right either way.

Changes to this notice

We review this notice when anything changes that affects it, including when we take on a new service provider. The date at the top is the last revision.

If we make a change that materially affects you, we will tell clients by email rather than relying on you noticing. For other changes, the updated page is the notice.