Privacy Policy

Version dated 29 August 2026. This version replaces the policy dated 25 May 2018.

1. Who is responsible for your data?

Law Right SRL, a law firm registered with the Brussels Bar, Avenue Louise 231, 1050 Brussels, company number BE 0478.744.389, is the data controller.

Contact: cboeraeve@law-right.com, +32 (0)2 643 11 00. You may use these details for any question about this policy or the exercise of your rights.

Law Right has not appointed a data protection officer. Following an assessment, the firm considers that its current activities do not fall within the cases in which the GDPR requires such an appointment. The contact details above remain the single point of contact.

This policy covers www.law-right.com and processing relating to clients, prospective clients, professional contacts and newsletter recipients.

2. Legal professional privilege

The firm is bound by legal professional privilege. This is not merely an internal policy: it is protected by Article 458 of the Belgian Criminal Code and by the professional rules governing lawyers.

Information covered by legal professional privilege is not disclosed except where a legal rule requires or permits disclosure and only in accordance with the applicable procedure.

Where exercising a right would reveal privileged information concerning another client or a third party, the firm may restrict that right to the extent legally necessary and proportionate. Any refusal or restriction will be explained insofar as the law and legal professional privilege permit.

The firm processes only data that are necessary for the relevant purpose.

3. What data do we process, why, and on what legal basis?

Website visits. IP address, pages viewed and technical browser data. Purposes: website security, proper operation and audience measurement. Legal basis: the firm’s legitimate interest in operating a safe and functional website and, for trackers that require it, your consent.

Contact form. Name, first name, email address, telephone number and subject of the request. Purposes: responding to your request and checking for conflicts of interest before accepting any engagement. Legal basis: steps taken at your request before entering into a contract and, for the conflict check, the firm’s legal and professional obligations.

Client relationship. Identification and contact details, documents and information contained in the matter, and billing data. Purposes: carrying out the engagement, billing, and complying with the firm’s legal and professional obligations. Legal basis: performance of the contract, compliance with legal obligations and the legitimate interest in internal matter management.

Anti-money-laundering obligations. A copy of an identity document and information concerning the beneficial owner and source of funds, where the anti-money-laundering legislation applies. Legal basis: legal obligation. These data are not used for any other purpose.

Newsletter. Email address, first name and language. Legal basis: your consent or, for existing clients, the statutory exception where the address was obtained directly in connection with a service, the communication concerns similar services and, when the address was collected, you were clearly offered a free and easy means of objecting. Every message provides an easy and free way to unsubscribe.

The firm does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you, and it does not engage in profiling.

If the firm proposes processing that is not covered by this policy, it will provide the required information before that processing begins.

4. Cookies and other trackers

Cookies that are strictly necessary for the website to operate are placed without consent. Other cookies, including certain audience-measurement and social-media cookies, are placed only after your prior consent where required by law. Refusing must be as easy as accepting. You may change your choice at any time through the same consent tool.

5. Retention periods

At the end of the applicable period, data are deleted or irreversibly anonymised.

6. Who receives your data?

Your data are accessible only to the firm’s lawyers and staff to the extent required for their duties.

Technical service providers may also process data, including providers of email, hosting, back-up, accounting and newsletter delivery services. Where they act as processors, they process data only on the firm’s instructions and under an agreement that complies with the GDPR.

Some providers belong to groups established outside the European Economic Area or use technical resources located there. Where data are transferred outside the EEA, the transfer relies on a European Commission adequacy decision or appropriate safeguards, such as the Standard Contractual Clauses, supplemented by additional measures where necessary. You may request information about the applicable safeguards.

Your data are not sold or rented and are not disclosed to third parties for their own marketing purposes.

The firm discloses data to an authority only where required by law, a court order or a valid official request, while respecting legal professional privilege.

7. Your rights

Subject to the conditions laid down in the GDPR, you have rights of access and copy, rectification, erasure, restriction, portability and objection.

Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out beforehand.

You may object at any time, free of charge and without giving reasons, to the use of your data for direct marketing.

The firm generally responds within one month. That period may be extended by two months where the request is complex or numerous requests have been made; you will be informed within the first month. Where there are reasonable doubts, the firm may request additional information to confirm your identity.

These rights may be restricted by law, including because of legal professional privilege, statutory retention duties or the establishment, exercise or defence of legal claims. Any refusal will be explained to the extent legally possible.

8. Security and data breaches

The firm implements technical and organisational measures appropriate to the risk. Depending on the relevant system and processing, these include need-to-know access controls, enhanced authentication, secure communications and media, regular back-ups, system updates and awareness measures for people who process data.

Where a personal data breach is likely to result in a risk to your rights and freedoms, the firm reports it to the Belgian Data Protection Authority in accordance with Article 33 GDPR, where feasible within 72 hours after becoming aware of it. Where a high risk is likely, you will be informed without undue delay in accordance with Article 34 GDPR, unless a statutory exception applies.

9. Complaints and remedies

Please contact the firm first where possible; this is often the quickest way to investigate your request.

You may also lodge a complaint with the Belgian Data Protection Authority at www.dataprotectionauthority.be. If you reside in another Member State, the list of national supervisory authorities is available at www.edpb.europa.eu.

You retain the right to seek a remedy before the competent courts.

10. Lexi, OpenAI and WhatsApp

Lexi is Law Right’s AI-powered conversational assistant. From the first interaction, users are informed that they are communicating with an AI, not Christophe Boeraeve or another human. Lexi explains editorial content and its sources; it does not provide personalised legal advice and does not make decisions producing legal or similarly significant effects.

Depending on the channel used, Law Right may process conversation text, the selected language, technical session or channel identifiers, activation status, STOP or HUMAN requests, timestamps, and data strictly necessary for security, service continuity and transfer to a human. The purposes are to answer editorial questions, secure the service, respect the user’s choices and organise human assistance when requested. The legal bases are performance of the requested service, the legitimate interest in providing and securing that service, and consent where required to activate an optional channel.

Conversations may be processed by service providers acting for Law Right, including OpenAI for the AI service, Meta/WhatsApp for the WhatsApp channel, and hosting or infrastructure providers. Certain processing may involve transfers outside the European Economic Area. Law Right verifies the applicable safeguards, including adequacy decisions or Standard Contractual Clauses, and provides further information on request.

Users must not provide Lexi with information protected by legal professional privilege, sensitive data, case-file information or confidential information. Conversations are retained only for as long as necessary to provide and secure the service, handle a human-assistance request and comply with legal obligations; precise periods are documented in the internal record and reviewed periodically. Users may request erasure or object as explained under “Your rights”. They may write HUMAN to request a person; Lexi is then paused in accordance with the available process. STOP disables WhatsApp communications.

11. Changes and applicable law

The firm may update this policy. Each new version will be published on the website with its date. Material changes will be brought to your attention where appropriate and where the firm holds your contact details.

This policy is governed by Belgian law. Jurisdiction is determined in accordance with the applicable statutory rules.