Privacy
Privacy Policy
Last updated 24 July 2026
This Privacy Policy explains how LegalPro Law Corporation (“LegalPro”, “we”, “us”) collects, uses, discloses and protects personal data in connection with our Singapore law practice and the website at legalpro.pro. We handle personal data in line with the Personal Data Protection Act 2012 of Singapore (PDPA) and professional confidentiality duties that apply to legal services. By using our website or contacting us, you acknowledge that you have read this policy. It should be read together with our Cookie Policy and Terms of Use.
A. Who we are and what this policy covers
LegalPro Law Corporation · UEN 202771259M · Registered address: 63 Market Street, #19-02, Bank of Singapore Centre, Singapore 048942 · Telephone: +65 6643 5192 · General email: [email protected] · Privacy email: [email protected].
We are a law corporation providing legal services in Singapore — business formation, commercial contracts, conveyancing, regulatory compliance, family and personal matters, and small-business retainer advisory — under letters of engagement after conflict checks. We are not a legal-tech subscription product, document-template marketplace, income scheme, claims-farming service or law course. Website content is general information, not legal advice; submitting an enquiry does not create a solicitor–client relationship.
This policy applies to personal data collected through legalpro.pro, email and telephone communications, in-person meetings at our Market Street office, and any other channels where we act as an organisation handling personal data. It does not apply to third-party websites linked from our site. Client files may also be subject to additional terms in engagement letters and professional obligations under the Legal Profession Act framework.
B. Personal data we may collect
Depending on your interaction with us, we may collect the following categories of personal data:
- Identity and contact data: name, email address, telephone number, postal address, company name, job title and organisation role.
- Enquiry data: information you provide in contact forms, emails or consultations about your legal matter — we ask you not to submit highly sensitive or privileged details via unsecured web forms before engagement.
- Client matter data: if you engage us, documents, correspondence, billing records, instructions and notes relating to your legal matter.
- Technical data: IP address, browser type, device information, referral URLs and cookie identifiers when you use our website (see Section G).
- Marketing preferences: whether you have opted in to receive updates about our services, where permitted by law — we do not add enquiry contacts to marketing lists without separate consent.
- Financial data: billing address, payment references and invoice history for client matters — we do not store full payment card numbers on our own servers where processing is handled by a payment provider.
You are responsible for the accuracy of information you provide. Inaccurate data may affect our ability to advise, quote fees or complete conflict checks. Where a matter involves minors — for example, estate planning — we collect children's data only as necessary for the legal purpose and with appropriate consent from parents or lawful guardians.
C. Purposes of collection, use and disclosure
We collect and use personal data for purposes including:
- Responding to enquiries and scheduling consultations at our Raffles Place desk;
- Conducting conflicts checks before accepting engagement;
- Preparing and performing letters of engagement and delivering legal services;
- Managing appointments, client care and matter communications;
- Issuing fee estimates, invoices and accounting records;
- Complying with Singapore law and professional regulation associated with the Law Society of Singapore;
- Operating, securing and improving this website;
- Managing cookie preferences and consent records;
- Establishing, exercising or defending legal claims.
We do not sell personal data. We do not use enquiry data for unrelated marketing without your consent. We do not purchase contact lists or harvest leads for claims-farming purposes. Analytics cookies, if enabled, help us understand aggregate traffic patterns — not to profile individuals for advertising.
D. Consent, legal bases and withdrawal
Under the PDPA, we rely on consent, contractual necessity, legal obligation and legitimate interests as appropriate. When you submit our contact form, you must tick the consent checkbox — it is not pre-selected. The checkbox confirms you understand we will use your enquiry data to respond and that submission does not engage the firm or create legal advice.
You may withdraw consent for optional processing — such as analytics cookies — without affecting strictly necessary processing required to respond to your enquiry or perform legal services under engagement. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. Where we must retain data for legal or professional reasons, we will inform you of the basis for continued retention.
Conflict checks may require limited processing of personal data about you and other parties before a full engagement letter is signed. We document the outcome internally and retain minimal records where we decline a matter for professional reasons.
E. Enquiry handling before engagement
Enquiry messages are treated as prospective-client communications. They are stored securely, accessed only by personnel who need them for conflict checks and scheduling, and not used for unrelated marketing lists. Submitting an enquiry does not mean we act for you. If we cannot take a matter, we may retain limited records of the conflict check outcome.
We instruct you not to send full confidential bundles via the website contact form. Secure exchange methods — encrypted email, client portal or physical delivery — are agreed upon engagement. Casual website messages are generally not protected by legal professional privilege.
F. Confidentiality and legal professional privilege
Professional confidentiality obligations apply to client matters under engagement. Legal professional privilege may apply to certain lawyer–client communications for the dominant purpose of legal advice or litigation, subject to exceptions under Singapore law. Privilege does not attach to information sent before engagement is confirmed or to general website browsing data. We explain privilege boundaries during onboarding so you know what may be disclosed to courts or regulators if required.
Staff with access to client matter data receive periodic training on PDPA obligations and professional confidentiality. Remote access to matter files uses authenticated connections; devices used for client work are password-protected.
G. Cookies and similar technologies
Our website uses cookies as described in our Cookie Policy. Strictly necessary cookies operate the site and record your cookie consent choice for six months. Analytics and preference cookies are placed only if you click “Accept all” or enable them in “Customise”. You may change preferences by clearing site data or contacting [email protected].
H. Disclosure to third parties
We may disclose personal data to:
- Service providers who assist with hosting, email delivery, document management or accounting — under contractual confidentiality and data protection terms;
- Courts, regulators or law enforcement when required by law or court order;
- Other professional advisers — counsel, notaries, foreign lawyers — with your consent or as necessary for your matter;
- Successors in the event of a merger or restructuring, subject to equivalent protection.
We assess vendor security practices before engaging sub-processors. Details of specific sub-processors are available on request to [email protected].
I. Cross-border transfers
Our primary systems are located in Singapore. If personal data is transferred overseas — for example, to a cloud provider with regional redundancy or foreign counsel on your matter — we ensure that the recipient provides a standard of protection comparable to that under the PDPA, typically through contractual clauses or verified certification mechanisms. We discuss foreign processing with you before sharing where required.
J. Retention
We retain personal data only as long as necessary for the purposes collected:
- Enquiries not converted to engagements: typically up to 24 months, unless a longer period is needed to manage complaints or legal claims.
- Client matter files: in accordance with Law Society guidance, limitation periods and your instructions — often six to seven years after matter closure, or longer where required.
- Cookie consent records: six months, aligned with our cookie banner.
- Financial records: as required by applicable tax and accounting laws.
When retention ends, we delete or anonymise data where feasible. Previous versions of this policy are archived internally; contact [email protected] if you require a copy of an earlier version.
K. Access, correction and portability
You may request access to or correction of your personal data by writing to [email protected] or by post to the registered address marked “Data Protection Officer”. We will respond within a reasonable period and in accordance with PDPA requirements. We may charge a reasonable fee for manifestly unfounded or excessive requests.
In some circumstances — for example, where disclosure would affect the rights of another person, reveal conflict-check outcomes about third parties or disclose privileged material — we may refuse access with reasons provided as required by law.
L. Data Protection Officer
Our Data Protection Officer can be reached at [email protected] or by post to LegalPro Law Corporation, 63 Market Street, #19-02, Bank of Singapore Centre, Singapore 048942, marked “Data Protection Officer”. Please include sufficient detail to identify your request and verify your identity where appropriate.
M. PDPC contact
If you have concerns about our handling of personal data that we cannot resolve, you may contact the Personal Data Protection Commission (PDPC) of Singapore via https://www.pdpc.gov.sg/ or the channels published by the PDPC. We encourage contacting us first so we can address the issue directly.
N. Security and breach notification
We implement administrative, technical and physical safeguards appropriate to the sensitivity of the data we hold — including access controls, encrypted transmission (HTTPS), staff training on confidentiality and vendor diligence. No method of transmission or storage is completely secure; we encourage clients to use agreed secure channels for sensitive documents.
In the event of a personal data breach likely to result in significant harm, we will assess notification obligations under the PDPA and notify affected individuals and the PDPC where required. We maintain an internal incident log for security events affecting personal data.
O. Children
Our services and website are directed at adults and business users. We do not knowingly collect personal data from children under 13 without parental or guardian involvement appropriate to the matter.
P. Changes to this policy
We may update this Privacy Policy to reflect legal, technical or business changes. The “Last updated” date at the top will be revised, and material changes may be highlighted on our website. Continued use after changes constitutes acknowledgement of the updated policy where permitted by law.
- 24 July 2026 — Initial publication.
Questions: [email protected]. Engagement letters for client matters may contain additional data-handling terms specific to your file.