Privacy Policy
Viberts respects your privacy and is committed to protecting your personal data. The purpose of this privacy notice is to let you know how we look after your personal data, and to inform you of your legal rights. There is a glossary below, describing some of the terms used in this notice.
1. Important Information on who we are
Purpose of this privacy notice
This privacy notice aims to give you information on how Viberts collects and processes your personal data, including any data you may provide through our websites or when you purchase a service.
It is important that you read this notice together with any other privacy or fair-processing notice we may provide when collecting or processing personal data about you. This privacy notice supplements other notices and is not intended to override them.
Data Controller
Viberts Jersey Lawyers is a partnership constituted under Jersey law, trading under the business name Viberts. Our registered office is PO Box 737, Viberts House, Don Street, St. Helier, Jersey JE4 8ZQ. Viberts provides legal services and advises on Jersey law.
Viberts is the controller of, and responsible for, your personal data (collectively referred to as we, us or our in this privacy notice).
If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact us using the details below.
Contact Details
Name & title of contact: Jonathan Reynolds, Head of Risk and Compliance
Email address: compliance@viberts.com
Emails to the Head of Risk and Compliance will be copied to colleagues supporting the Head of Risk & Compliance.
Postal address: Viberts House, PO Box 737, Don Street, St. Helier, Jersey JE4 8ZQ
You also have the right to make complaints to the Jersey supervisory authority for data protection:
Jersey Office of the Information Commissioner (JOIC)
Email address: enquiries@jerseyoic.org
Postal Address: 2nd Floor, 5 Castle Street, St. Helier, Jersey JE2 3BT
We would appreciate the chance to deal with your concerns before you approach the JOIC, so please contact the Head of Risk and Compliance using the email shown above in the first instance.
Changes to the privacy notice and your duty to inform us of changes
It is important that the data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
2. The data we collect about you
Personal data
Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymised data and general data which is not about a specified individual).
We may collect, use, store and transfer these different kinds of data about you:
- Identity data includes full name, maiden name, marital status, title, date of birth and gender.
- Contact data includes billing address, delivery address, email address and telephone numbers.
- Financial data includes bank account and payment card details.
- Transaction data includes details about products and services you have purchased from us.
- Technical data includes internet protocol (IP) addresses, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
- Profile data includes your username and password, purchases or orders made by you, your interests & preferences and feedback and survey responses.
- Client due diligence information relating to you (proof of identity, proof of address and other information including public records and record searches relevant to our client take-on procedures and compliance requirements).
- Usage data includes information about how you use our website and services.
- Marketing and communications data includes your preferences in receiving marketing information from us and third parties and your communication preferences.
If you fail to provide personal data
Where we need to collect personal data by law or under the terms of a contract and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with services). In this case, we may have to cancel a product or service you have with us; however, we will notify you before doing so.
3. How is your data collected
We use different methods to collect data from and about you, including:
- Direct interactions. You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email etc. This includes data you provide when you:
- apply for our services;
- subscribe to our services or publications;
- request marketing communication be sent to you; or
- enter a competition, promotion or survey.
- Automated technologies or interactions. When you interact with our website, we may automatically collect technical data about your equipment, browsing actions and patterns.
- Third parties or public sources. We may receive data about you from analytics or search providers (e.g. Google) or public sources (Companies House, Electoral register etc.).
4. How we use your personal data
We have set out below a description of the ways we use your personal data, and the lawful bases we rely upon to do so. We have also identified our legitimate interests, where appropriate.
Where more than one basis is listed in the table below, please contact us for further details regarding the specific legal ground upon which we are relying.
| Purpose/Activity | Type of Data | Lawful Basis / Legitimate Interest |
| Register you as a new customer. |
|
1. Performance of a contract with you. 2. Prevention of crime; prevention of unlawful acts. |
| Process your service including:
1. Managing payments & charges. 2. Recovering money owed to us. |
|
3. Performance of a contract with you. 4. To recover debts due to us. |
| Manage our relationship including:
1. Notifying changes to our terms. 2. Asking you for feedback. |
|
1. Performance of a contract with you. 2. Compliance with a legal obligation. 3. Contacting you (where consent given). 4. To maintain our records and study how customers use our services. |
| To enable us to invite you to client social functions and events, and to partake in a competition or survey. |
|
1. Performance of a contract with you. 2. Contacting you (where consent given). 3. To study how customers use our services, to develop those services and to grow our business. |
| To administer and protect our business (including troubleshooting, analysis, testing, system maintenance, support, reporting and hosting of data). |
|
1. Compliance with a legal obligation. a. For running our business, provision of administration and IT services, network security, preventing fraud and business reorganisation activities. |
| To deliver relevant website content to you. |
|
To study how customers use our services, to develop those services and to grow our business. |
| To use data analytics to improve our website, services, marketing, customer relationships and experiences. |
|
To define types of customers, to keep our website updated and relevant, to develop our business and to inform our marketing strategy. |
| To make suggestions & recommendations about services that may be of interest to you. |
|
To develop our services and to grow our business. |
Providing you with advice/legal services
We will use your information in order to provide you with advice and in order to manage your file, including in relation to managing financial matters associated with work for you. This may include disclosing your personal data (including special category data) in the course of adversarial proceedings, such as litigation, and otherwise if we are obliged to do so.
Client take-on (inc due diligence)
We obtain information from you, from publicly available information and sometimes from third party sources in order to complete our client take on procedures. These procedures ensure that we comply with applicable anti money laundering and related legislation, that we can properly act for you (given the work we do) and that you are a suitable client for us (given your personal circumstances and requirements).
Marketing
We strive to provide you with choices regarding certain personal data uses, particularly in terms of marketing and advertising. We have established the following personal data control mechanisms:
Promotional offers from us
We may use your Identity, Contact, Technical, Usage and Profile Data to inform what we think you may want or need, or what may be of interest to you. This is how we decide which services and offers may be relevant for you.
You will receive marketing communications from us if you have requested information from us or purchased services from us or if you have provided us with your details and, in each case, you have opted into receiving that marketing.
Third-party marketing
We will ask for your express consent before we share your personal data with any third party for marketing purposes.
Opting out
You can ask us to stop sending you marketing messages at any time, by following the opt-out links on any marketing message or by contacting us directly.
Using publicly available information
We will use publicly available information (e.g. business news information and case reports) for articles and news items, including in our work for clients, on our website, on social media and in presentations, advice and discussions. Case reports are an important source of Jersey law on which we advise our clients and about which we regularly publish articles and news items; other published information may also be referred to in articles, news items and work materials.
How we process information (including use of AI)
We use a range of information technology and digital services, including Microsoft Office products and other case management software.
We sometimes use AI to work on files, which may include appropriate use of AI when we carry out research, prepare court documents and otherwise work on your file. The extent to which we are able to use AI in a client matter takes into account factors including the limited available published Jersey case law and the differences between Jersey law and the law of other jurisdictions. If you have questions about this please speak to the Viberts’ partner responsible for your matter.
Change of purpose
We will only use your personal data for the purposes under which it was collected, unless we identify an alternative reason that is compatible with the original purpose.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent (in compliance with the above controls) where this is required or permitted by law.
5. Disclosure of your personal data
We may have to share your personal data with the parties set out below for the purposes set out in the table in '4. How we use your personal data':
External third parties as set out in the glossary.
Third parties to whom we may choose to sell, transfer or merge parts of our business or assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, the new owners may use your personal data in the same way as set out in this privacy notice.
6. International transfers
We will only transfer your personal data to providers and countries that have been deemed to provide an EU-equivalent level of protection for personal data.
7. Data security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, altered, disclosed or accessed in an unauthorised way. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need-to-know. Those parties will only process your data on our instructions, and they are subject to a duty of confidentiality.
We have also put in place procedures to deal with any suspected data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
8. Data retention
We will only retain your personal data for as long as necessary (including for the purposes of satisfying any legal, accounting or reporting requirements).
To determine the appropriate retention period for your personal data, we consider the nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for processing (and whether we can achieve those purposes through other means) and the applicable legal requirements.
Retention periods for different aspects of your personal data are set out here:
| Data | Retention Period |
| Marketing details | Normally reviewed every 3 years or more frequently |
| Website usage | 5 years |
| Financial data | 7 years (unless covered by the below) |
| Contract-related information | At least 11 years |
9. Your legal rights
Explanation
For research or statistical purposes, we may anonymise your personal data (so that it can no longer be associated with you). In such cases we may use the information indefinitely without further notice to you.
You have certain rights under data protection law. These include:
- Requesting access to your personal data (a “data subject access request”).
- Requesting correction of your personal data.
- Requesting erasure of your personal data.
- Objecting to processing of your personal data.
- Requesting restriction of processing your personal data.
- Requesting transfer of your personal data to you or a third party.
- The right to withdraw consent, where we are relying on consent to process your personal data.
If you wish to exercise any of these rights, please contact us using the details in Section 1 above.
Please note that your right is the right to make a request in relation to the matters set out above. We will respond to requests taking into account our respective rights and obligations.
No fee usually required
You will not usually have to pay a fee to access your personal data (or to exercise any of the other rights above). We may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. (In some circumstances we may refuse to comply with your request where there are lawful grounds for us to do this.)
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. To speed up our response, we may also contact you for further information in relation to your request.
Time limit to respond
We try to respond to all legitimate data subject access requests within one month. If your request is complex or you have made a number of requests it may take us longer than a month. In this case, we will notify you and keep you updated as to our progress.
Right to lodge a complaint
You also have the right to make complaints to the Jersey supervisory authority for data protection:
Jersey Office of the Information Commissioner (JOIC)
More information can be found in Section 1 above under the header ‘Contact Details’.
If you have questions or concerns about how work for you is being handled please provide us with details in the first instance, so that we can endeavour to resolve matters to your satisfaction.
10. Glossary
Lawful basis
Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best and most secure experience. We will consider and balance your rights with any potential impact on you (both positive and negative) before we process your personal data for our legitimate interest. We will not use your personal data for activities where the impact on you overrides our interests (unless we have your consent or are otherwise required or permitted by law).
Performance of Contract means the processing of your data where it is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into such a contract.
Comply with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation to which we are subject.
Third parties
External third parties include:
- Professional advisers (including lawyers, bankers, auditors and insurers) who provide consultancy, banking, legal, insurance and accounting services.
- Regulators and other authorities who require reporting of processing activities.
- Fraud prevention, anti-money-laundering agencies etc.
Get in touch with us
Get in touch with us
Please complete all fields marked *