Zabulis Legal

Legal · Data protection

Privacy policy — how your information is handled

How Zabulis Legal collects, uses and stores personal information, how long it is kept, who it is shared with, and the rights you have over it.

Vincentas ZabulisSolicitor, England & Wales · Data Protection OfficerSRA No. 621485Reviewed 18 August 2026

Who this policy is from

Vincentas Zabulis, trading as Zabulis Legal, is a freelance solicitor authorised and regulated by the Solicitors Regulation Authority in England and Wales under practice SRA No. 666548, at 86B Lordship Park, Stoke Newington, London N16 5UA. The register entry can be checked on the SRA's register of solicitors.

ZABULIS LEGAL, APB is a law firm in Lithuania, company number 306641254, regulated by the Lithuanian Bar. Its head office in Lithuania is at Vokiečių str. 18A-7, 01130 Vilnius. The Lithuanian Bar's register is at advokatura.lt.

Data Protection Officer
Vincentas Zabulis. Any request about your personal information, including a request to see it or to have it deleted, should go to info@zabulislegal.com.

What is collected

Personal data means information from which an individual can be identified. It does not include data from which identity has been removed.

  • Contact details: name, title, address, telephone numbers and email addresses.
  • Date of birth.
  • Identity documents: passport, national identity card or driving licence.
  • Casework information, including the details of advice given to you.

Information is collected when you instruct the practice, either directly from you or from a third party who refers you. More is collected during the matter as the work proceeds.

Why it is used, and on what basis

Personal information is only used where the law permits it. In practice that means one of three grounds.

The usual grounds

  • Performing the contract we have entered into with you
  • Complying with a legal obligation, such as anti-money laundering checks
  • Legitimate interests of the practice or a third party, where those do not override your rights

Rare grounds

  • Protecting your vital interests or someone else's
  • Where processing is needed in the public interest or for official purposes
  • Consent, in the limited situations where it has been asked for and given

The specific situations in which your information is processed are: deciding whether the practice can act for you; determining the fees payable; providing advice and representation; administering the engagement; business management, accounting and auditing; preventing fraud; and maintaining the security of systems and communications. Several grounds frequently apply to the same processing.

Who it is shared with

Personal information is shared with third parties where the law requires it, where it is necessary to run the engagement, or where there is another legitimate interest in doing so. Those third parties include experts, accountants, IT providers, other lawyers, and regulators.

Third-party providers are required to take appropriate security measures, are permitted to process your data only for specified purposes and on instruction, and are not permitted to use it for their own purposes. Information may also be shared in the context of a merger or restructuring of the practice, or where a regulator requires it.

Your information may be transferred outside the EU. Where that happens, you can expect a similar degree of protection to apply.

How long it is kept

  1. During the matter

    Held and used for the engagement

    Kept securely, with access limited to those who need it, and processed only for the purposes described above.

  2. One year

    Original documents securely destroyed

    If you want originals held for longer or returned to you, ask in writing at the point you send them rather than afterwards.

  3. Six years, minimum

    Electronic file retained

    Emails and letters are scanned and stored electronically for at least six years, which reflects the periods for which legal, accounting and regulatory obligations require records to be available.

  4. Afterwards

    Securely destroyed, or anonymised

    Retention periods are set by reference to the volume and sensitivity of the data, the risk of harm, the purposes of processing and the applicable legal requirements.

Your rights

What you can ask for

  • Access. A copy of the personal information held about you, and confirmation that it is being processed lawfully.
  • Correction. Anything incomplete or inaccurate put right.
  • Erasure. Deletion where there is no good reason for continuing to hold it, or where you have objected to the processing.
  • Objection. To processing based on legitimate interests where your situation makes that inappropriate, and to direct marketing at any time.
  • Restriction. Suspension of processing, for example while accuracy is being established.
  • Portability. Transfer of your information to another party.

Requests go in writing to the Data Protection Officer at info@zabulislegal.com. There is normally no fee. A reasonable fee may be charged, or a request refused, where it is clearly unfounded or excessive. Confirmation of your identity may be requested first, which is itself a security measure to ensure information is not disclosed to someone with no right to it.

Where you have given consent for a specific purpose, you may withdraw it at any time by writing to the same address. Withdrawal stops that processing unless there is another lawful basis for it.

Security, and changes to this policy

Measures are in place to prevent personal information being lost, misused, accessed without authorisation, altered or disclosed. Access is limited to those with a business need, and everyone with access is under a duty of confidentiality. Procedures exist for handling a suspected breach, and you and any applicable regulator will be notified where the law requires it.

External firms may audit files as part of quality checking, and files may be reviewed in a due diligence exercise on a sale or transfer of the practice. Confidentiality is a specific requirement imposed on anyone carrying out such a review. If you would prefer your file not to be used this way, say so.

This policy may be updated at any time. Where an update is substantial, a new version will be provided.

Common questions

How do I ask for a copy of the information you hold about me?

Write to the Data Protection Officer, Vincentas Zabulis, at info@zabulislegal.com. This is commonly called a data subject access request. There is normally no fee, though confirmation of your identity may be requested before information is released.

How long do you keep my file?

Electronic records are kept for a minimum of six years, which reflects the legal, accounting and regulatory periods that apply. Original paper documents are securely destroyed after one year unless you have asked in writing for them to be returned or retained.

Can I ask you to delete my data?

You can ask, and it will be done where there is no good reason to continue holding it. Erasure is not absolute: where information must be retained to meet a legal or regulatory obligation, such as anti-money laundering record keeping, it cannot be deleted on request.

Do you send marketing emails?

Information that may be of interest is occasionally sent. You can object to direct marketing at any time, with no reason required and no effect on any matter being handled for you.

Is my information transferred outside the EU?

It may be. Where that happens you can expect a similar degree of protection to apply to it as it has within the EU.

Who can I complain to about how my data is handled?

Raise it first with the Data Protection Officer at info@zabulislegal.com. If you remain dissatisfied, the Information Commissioner's Office is the supervisory authority for the UK, and the State Data Protection Inspectorate is the equivalent in Lithuania.

This page states the law of England & Wales and Lithuania as at 18 August 2026. It is general information, not advice on your matter, and reading it does not create a solicitor-client relationship.