Harmonics24Privacy Policy

Privacy Policy

Effective Date: April 24, 2026

1. Introduction

This Privacy Policy (“Policy”) describes how Harmonics24 (“we,” “us,” or “our”) collects, uses, discloses, and safeguards information about individuals (“you” or “your”) in connection with our legal services, website, and related communications. We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant privacy regulations.

By accessing our website or using our services, you acknowledge that you have read and understood this Policy.

2. Scope

This Policy applies to:

  • Visitors of our website
  • Clients and prospective clients
  • Opposing parties and counsel (in the context of legal proceedings)
  • Job applicants and employees
  • Any other individuals whose personal data we process

3. Personal Data We Collect

3.1 Information You Provide Directly

We may collect the following categories of personal data you provide to us:

CategoryExamples
Identity DataName, title, date of birth, signature
Contact DataEmail address, postal address, phone number
Financial DataBilling information, payment card details, invoice history
Case-Related DataMatter description, legal documents, evidence, correspondence
Employment DataCV, employment history, professional licenses, bar admissions
Communication PreferencesOpt-in preferences, communication history

3.2 Information Collected Automatically

When you visit our website, we may automatically collect:

  • IP address and device identifiers
  • Browser type and version
  • Operating system
  • Pages visited and time spent
  • Referring website addresses
  • Cookies and tracking technologies (see Section 10)

3.3 Information from Third Parties

We may receive personal data from:

  • Referral sources and professional contacts
  • Publicly available sources (court records, bar directories, corporate registries)
  • Service providers and vendors
  • Business partners (with your consent where required)

4. Purposes and Legal Basis for Processing

4.1 We Process Personal Data For:

PurposeGDPR Legal BasisCCPA Basis
Providing legal servicesContract performance (Art. 6(1)(b))Service delivery
Client onboarding and identificationLegal obligation (Art. 6(1)(c))Transaction completion
Billing and payment processingContract performance (Art. 6(1)(b))Transaction completion
Communicating about mattersLegitimate interests (Art. 6(1)(f))Service provision
Marketing (where permitted)Consent (Art. 6(1)(a))Right to opt-out
Complying with legal obligationsLegal obligation (Art. 6(1)(c))Legal compliance
Fraud prevention and securityLegitimate interests (Art. 6(1)(f))Security

4.2 Legitimate Interests

Where we rely on legitimate interests, we balance our interests against your rights and freedoms. You may object to this processing at any time (see Section 8).

5. Sensitive Personal Data

We may process sensitive personal data (special categories under GDPR, “sensitive personal information” under CCPA) only when:

  • Necessary for the establishment, exercise, or defense of legal claims
  • You have explicitly consented
  • Required by applicable law
  • Necessary to protect your vital interests

Sensitive data may include: Social Security Numbers, financial account information, health information disclosed in legal matters, and other data explicitly protected by law.

6. Data Sharing and Disclosures

6.1 We Do Not Sell Your Personal Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

6.2 We May Disclose Data To:

RecipientPurpose
Courts and Opposing CounselLitigation and dispute resolution
Government AuthoritiesRegulatory compliance and legal obligations
Service ProvidersBilling, technology, and administrative support
Professional AdvisorsAccounting, auditing, and legal advice
Successor EntitiesMergers, acquisitions, or firm transitions

6.3 International Transfers

If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards through:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Binding Corporate Rules (where applicable)

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required by law.

Data TypeRetention Period
Client matter files7 years after matter conclusion
Billing records7 years
Marketing dataUntil consent withdrawn + 2 years
Job applications (unsuccessful)6 months
Website logs1 year

8. Your Rights

8.1 General Rights

You may have the following rights regarding your personal data:

  • Access — Request a copy of your personal data
  • Rectification — Request correction of inaccurate data
  • Erasure — Request deletion of your data (“right to be forgotten”)
  • Restriction — Request limited processing
  • Portability — Receive your data in a structured, machine-readable format
  • Objection — Object to processing based on legitimate interests
  • Withdraw Consent — Where processing is based on consent

8.2 Additional Rights Under CCPA

California residents have the right to:

  • Know what personal information is collected about them
  • Know whether their data is sold or disclosed (and to whom)
  • Say no to the sale of personal information
  • Not be discriminated against for exercising their privacy rights

8.3 Additional Rights Under GDPR

EEA/UK residents have the right to:

  • Lodge a complaint with a supervisory authority
  • Receive a copy of SCCs upon request
  • Request human review of automated decisions

How to Exercise Your Rights

Email: privacy@lawfirm.com

Mail: Privacy Officer, 123 Legal Street, Suite 500, New York, NY 10001

Phone: (212) 555-0100

We will respond within 30 days. For CCPA requests, we will verify your identity before processing.

9. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • AES-256 encryption for data at rest
  • TLS 1.3 for data in transit
  • Multi-factor authentication for system access
  • Regular security assessments and penetration testing
  • Access controls and least-privilege principles
  • Employee training on data protection

In the event of a data breach affecting your rights, we will notify you and relevant authorities within 72 hours as required by GDPR Article 33.

10. Cookies and Tracking

10.1 Types of Cookies We Use

TypePurposeDuration
EssentialCore functionality, securitySession
AnalyticsWebsite usage statistics2 years
MarketingAd targeting (with consent)90 days

10.2 Managing Cookies

You may manage your cookie preferences through our Cookie Consent Tool or your browser settings. Disabling non-essential cookies may affect website functionality.

11. Children's Privacy

Our services are not directed to individuals under 18 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe we have collected such data, contact us immediately.

12. Changes to This Policy

We may update this Policy periodically. The “Effective Date” at the top indicates the most recent revision. For material changes, we will:

  • Provide prominent notice on our website
  • Request renewed consent where required
  • Email registered users of changes

13. Contact Information

For privacy-related inquiries or to exercise your rights:

Privacy Officer

Email: privacy@lawfirm.com

Phone: (212) 555-0100

Address: 123 Legal Street, Suite 500
New York, NY 10001

For EU/UK supervisory authorities, contact details are available at:

14. Force Majeure

We shall not be liable for any failure to perform our obligations where such failure results from causes beyond our reasonable control, including but not limited to acts of God, natural disasters, war, terrorism, riots, embargoes, acts of civil or military authorities, fire, floods, accidents, pandemic, strikes, or shortages of transportation, facilities, fuel, energy, labor, or materials.

Disclaimer: This Privacy Policy is provided for informational purposes and does not constitute legal advice. Consult with qualified legal counsel regarding specific privacy compliance obligations.