PRIVACY AND ELECTRONIC COMMUNICATION POLICY

Last updated: 9 April 2025

STATUS AND CONFIDENTIALITY OBLIGATIONS

ArsLegem is a law firm (Attorneys’ Association) established under Ukrainian law, operating in accordance with the Law of Ukraine “On the Bar and Advocacy” and the Rules of Advocate Ethics. Under Article 22 of that Law, any information learned by ArsLegem’s attorneys about a client – including information about a person who was denied a legal assistance contract – is subject to attorney-client confidentiality (professional secrecy). We strictly uphold this duty of confidentiality. The obligation of non-disclosure applies to all lawyers and staff of ArsLegem, and we provide conditions that prevent any unauthorized persons from accessing or divulging confidential information. No information obtained from a client or prospective client is disclosed without the individual’s consent or another lawful basis.

COMMUNICATION WITH US AND ATTORNEY-CLIENT RELATIONSHIP

Contacting ArsLegem (through our website, email, or other means) in itself does not establish an attorney-client relationship, nor does it constitute an automatic agreement for legal services. Our attorneys provide legal assistance only on the basis of a signed written agreement with the client. Until such an agreement (engagement letter) is executed, any communications or exchange of information are preliminary and do not obligate ArsLegem to represent you or provide advice. In particular, any opinions or information provided in correspondence are not to be considered official legal advice unless and until confirmed in writing under a formal engagement. Please note that only after we explicitly agree to take your case and a legal services contract is signed do we enter into an attorney-client relationship with you.

We assure you that even if you contact us for a consultation and no legal services agreement is ultimately concluded, any information you have provided will remain confidential in accordance with the law and this Policy.

ELECTRONIC MAIL POLICY AND SECURITY

No Special Encryption:

Our email communications generally use standard email transmission without additional end-to-end encryption (we do not use PGP or S/MIME by default). While our email servers employ TLS encryption in transit, emails are not fully encrypted from end to end. Email, by its nature, does not provide complete security for confidential data, meaning information sent via email could potentially be intercepted or read by unauthorized parties.

Cybersecurity Risks and Viruses:

We caution users about the risks associated with email. Both senders and recipients should be aware of the possibility of computer viruses or other threats during data transmission. We take reasonable precautions (including virus scanning of emails) to keep our communications secure, but we cannot guarantee absolute safety. The recipient is responsible for scanning attachments for viruses, and ArsLegem accepts no liability for any loss or damage caused by viruses or malware in email content or attachments. Likewise, we cannot guarantee the integrity of messages that may be altered or corrupted in transit over the Internet.

Third-Party Interference:

By sending email to us or receiving email from us, you acknowledge the risk that unauthorized third parties may intercept or tamper with electronic communications. ArsLegem is not liable for any consequences of unlawful interception, hacking, or other unauthorized access by third parties to electronic communications. Similarly, we do not accept responsibility for the proper and complete transmission of the information in an email, nor for any delays, errors, or omissions in its receipt.

If You Receive an Email in Error:

All email messages from ArsLegem are intended for the designated recipient and may contain confidential information protected by law. If you are not the intended recipient, any disclosure, copying, distribution or use of the contents is strictly prohibited and may be unlawful. If you have received an email from us in error, please notify the sender immediately by reply email and delete the message from your system.

Confidential Nature of Emails:

The content of ArsLegem’s official emails is confidential and intended solely for the person or entity to whom it is addressed. Our correspondence may contain information subject to attorney-client privilege or other protected information. Recipients should treat such communications as confidential and not forward or disclose them to others without our permission. The inclusion of a confidentiality notice in our emails does not itself create an attorney-client relationship if one does not already exist; it simply underscores the confidential nature of the communication.

USE OF CLOUD SERVICES

To enhance data security and efficiency, we utilize external cloud services, specifically Tresorit and Microsoft OneDrive, for data storage and collaboration. These services have been chosen for their high security standards: Tresorit provides end-to-end encryption of files, and OneDrive (a service provided by Microsoft) adheres to advanced security protocols and holds industry certifications demonstrating data protection.

Confidential documents and communications may be stored on secure servers operated by these providers. ArsLegem ensures that the use of cloud services is conducted in a manner consistent with our professional secrecy obligations and in compliance with data protection laws. We have taken steps to verify that our chosen providers implement appropriate technical and organizational measures to safeguard data.

Please be aware that information stored in cloud services may reside on servers outside ArsLegem’s physical offices, including servers located in other jurisdictions (for example, within the EU or the USA). We use only those cloud platforms that provide a level of data protection equivalent to the requirements of Ukrainian law and the GDPR, and where necessary, we have agreements in place with those providers to maintain confidentiality.

By engaging ArsLegem, you consent to our use of these cloud platforms to store or transmit information related to your matter as needed. We remain responsible for protecting your confidential information even when it is stored on third-party services. If you have objections to the use of a particular cloud service for your data, please let us know – we will consider alternative arrangements for storing or sharing information.

PUBLICATION OF CLIENT CASES

ArsLegem respects clients’ confidentiality and does not disclose information about client matters without the client’s consent. We may share general information about successful cases or projects for marketing or informational purposes (for example, on our website or in firm publications), but only with the prior explicit consent of the client involved.

Any information published with a client’s permission will be agreed upon with the client as to its scope and content. Under Ukrainian law, confidential information loses its status as attorney-client privileged only by a written statement of the client. Even with such consent, ArsLegem is careful not to disclose unnecessary personal data or details. If describing a case involves information about third parties, we will comply with personal data protection laws when disclosing such information (for example, by anonymizing third-party data or obtaining additional permissions as required).

Consenting to have one’s case published is entirely voluntary. A client’s refusal or withdrawal of consent for publicity will not affect the legal services provided to that client in any way.

DATA PROTECTION AND GDPR COMPLIANCE

ArsLegem processes personal data in accordance with the Law of Ukraine “On Protection of Personal Data” and, to the extent applicable, the EU’s General Data Protection Regulation (EU Regulation 2016/679, GDPR). As our clients and website users may include residents of the European Union, we have voluntarily implemented GDPR principles in our data processing practices.

When you visit our website, we may passively collect technical information such as your IP address, browser type, time of visit, and cookies. This information is collected solely for administering and ensuring the functionality of our website, as well as for analyzing its performance. We do not use such data to identify individual visitors and do not share it with third parties except as needed for website support (e.g., with a hosting provider), and always under duties of confidentiality.

If you contact us via a form on our website or by email, we will process the personal data you provide (e.g., your name, contact information, and the content of your inquiry) only for purposes of responding to you and providing any legal services you request. The legal basis for such processing may be your consent, the need to take steps at your request prior to entering into a contract, or our legitimate interest in effectively responding to inquiries.

Personal data of clients is used only for purposes of providing legal services and fulfilling legal obligations (such as accounting, conflict checks, anti-money laundering compliance, etc.). We do not disclose client personal data to third parties unless required by law or with the client’s consent. Exceptions may include situations mandated by law or necessary to protect our rights (for example, complying with a court order or law enforcement request), in which case we will act strictly in accordance with the law.

ArsLegem ensures the exercise of data subject rights. Every individual whose data we process has the right to know what personal data we hold about them, to access that data, and to request correction, cessation of processing, or deletion of their data as provided by law. For EU data subjects, we also take into account the rights guaranteed by the GDPR (such as the right to object to processing and the right to data portability). To exercise your rights, you may contact us using the information below. We will consider your request in accordance with applicable laws and respond within the legally required timeframe.

We retain personal data only for as long as necessary to achieve the purposes for which it was collected, unless a longer retention is required by law or professional obligations. Technical website logs (server logs) are generally automatically deleted after a short period, unless kept longer to investigate security incidents. Client matter data is retained for the duration of the legal services agreement and for a period thereafter as dictated by our retention policies (for archiving and legal compliance).

INTERNAL INFORMATION SECURITY STANDARDS

ArsLegem maintains rigorous internal policies and procedures to protect confidential and personal information. Our employees and partners are required to follow strict information security rules; upon hiring, they sign non-disclosure agreements (NDAs) or similar documents obligating them to preserve attorney-client confidentiality. Access to client files is restricted to a limited circle of personnel strictly on a need-to-know basis.

We utilize modern information security measures: data backup systems, encryption of devices and communication channels, access control systems, secure data storage platforms, and other safeguards. An internal access management policy is in place, defining access levels to information based on an employee’s role and necessity. Confidential documents are stored in encrypted form or on secure platforms (such as Tresorit). Physical media containing sensitive information are kept in safes or locked cabinets and are properly destroyed when no longer needed.

Our internal standards align with the best practices of law firms in Ukraine and the EU regarding cybersecurity and information protection. We conduct periodic security audits and staff training to maintain a high level of awareness and preparedness in data protection. Any suspected breach of confidentiality is investigated immediately by our management, and necessary measures are taken to remediate the issue and prevent recurrence. In this way, clients can be confident that their information is securely handled at all stages of their engagement with ArsLegem.

EFFECTIVE DATE AND EMAIL SIGNATURE NOTICE

This Privacy and Electronic Mail Policy is a unified document that serves as both our website privacy policy and our email disclaimer. A link to this Policy (labeled “Confidentiality E-mail Policy”) is included in the footer of each outgoing email from our firm.

By continuing to correspond with us via email or by using our website, you acknowledge that you have read and agree to the terms of this Policy. If you do not agree with any provision, please inform us and refrain from further electronic communication (we can arrange an alternative method of communication if necessary).

ArsLegem reserves the right to revise and update this Policy periodically to reflect changes in law or improvements in our practices. In the event of significant changes, we will post the updated Policy on our website. Please check this page to stay informed of any updates. The current version of this Policy is effective from the date indicated next to the title.

If you have any questions regarding this Policy or wish to exercise your rights regarding personal data, you may contact us at office@arslegem.com or using the contact information provided on our website. We are committed to promptly addressing any concerns and ensuring that your information is protected.