This Privacy Notice applies to all individuals who have dealings with us, whether as a client, a current or prospective employee or a third party from whom we are seeking to recover a debt on behalf of a client. Please read it accordingly. It explains why we may be processing your personal data, how long we will keep it for and who we may share it with. It also tells you the security mechanisms we have put in place to protect your data and how to contact us if you have a complaint.
Please Note: This Privacy Notice and the rights set out in it only apply to ‘personal data’, which broadly means private data that relates to an identified or identifiable natural person (that is, a human being) and do not apply to the data of corporate/legal entities, such as Limited Companies and Limited Liability Partnerships.
Who are we?
Kalstone Legal Limited (referred to in this document as ‘KLL’, ‘we’ or ‘us’) is a company registered in England under Company Number 16962534 that undertakes debt collection activities on behalf of our clients. We may use and be responsible for personal information about you. When we do this, we are the ‘controller’ of this information for the purposes of the UK General Data Protection Regulation (‘UK GDPR’) and other applicable data protection laws.
Our contact details:
Name: Kalstone Legal Limited
Address: Unit 2A, Link 606 Business Park, Staithgate Lane, Bradford BD6 1YA
Phone Number: 01274 066330
E-mail: help@kalstonelegal.com
What personal data do we use or collect?
In order to carry out our instructions or operate as a law firm, we may hold the following types of information about you:
- Your name
- Your contact information such as your address, phone number or email address
- Your date of birth, National Insurance number or tax reference
- Your bank or other financial details
- Your personal circumstances
- Employment or educational history
- Recordings of telephone calls with us
Special Category (‘Sensitive’) personal information, such as health or financial information:
You may voluntarily give us sensitive personal information by, for example, telephone calls, letters or emails. We will hold or use sensitive personal information for either employment matters or in relation to debt collection purposes, when we may share it with our client for the purposes of obtaining further instructions in relation to your account.
How do we obtain your personal data?
We collect information in the following types of ways:
- Information provided by our client
- Information provided by you, for example when you call, write or email us or in a job application or whilst working for us
(Please note: we record all calls, for compliance, quality and training purposes.)
- Information provided during the debt collection or litigation process
- Information from tracing agents or credit reference agencies
- Public sources, such as on the internet, social media, at Companies House or the Land Registry
How we use your personal information:
We use the personal data that we hold for the following types of purposes:
- To comply with our contractual obligations to our clients or employees
- To undertake debt recovery activities on behalf of our clients
- To manage your account
- To communicate with you or, if the need arises, to serve proceedings or notices
- To locate you and/or confirm your identity
- To process any payments that you make
Legal reasons we collect and use your personal information:
We rely on the following provisions as the legal basis for processing your information:
- Legitimate interests, for the following reasons
- It is in the commercial interests of our clients for debts to be collected on their behalf
- It is generally in debtors’ best interests to be contacted and given an opportunity to repay debt
- It is in the best interests of the economy and society in general that those who incur debts are asked to pay them, rather than the burden of unpaid debt driving up prices/costs for all
- It is in our interests to assist us to deliver high quality legal services to our clients
- Comply with both our clients’ and our own legal and regulatory obligations
- Processing is necessary for the performance of a contract
- With consent
Who could we share your personal information with?
We sometimes need to share your information with others in order to further our client’s instructions or to follow legal processes. We may share your data with the following types of people or organisations:
- Our clients – all data, including call recordings, may be shared with our client
- Tracing agents, credit reference agencies, process servers or enforcement agencies
- Barristers, Court advocates or other experts
- Courts and other parties to legal proceedings or enforcement activities
- Any advisor or legal representative appointed or authorised by you
- Our trusted suppliers, such as printing services or IT support
- Our professional advisors, insurers or auditors, if necessary
- Regulators, governmental bodies or law enforcement agencies, if required
Where will we store your personal data?
Generally, the information is securely stored in servers and filing systems within the UK.
Transfer of your information outside the UK:
Our systems may occasionally be accessed and stored locally outside the UK, such as by a staff member who is temporarily abroad, but we will ensure that safeguards are in place to maintain the security of data.
It may be necessary to transfer your personal information to countries within European Economic Area (EEA). These countries are subject to the General Data Protection Regulation (GDPR) which provides effectively identical data protection as the UK GDPR.
How long will we store your personal data for?
We will usually keep data linked to our clients’ instructions for up to 7 years after those particular instructions have ended and the matter closed. We will then securely dispose of your information.
Your data protection rights:
Under the UK GDPR, you have a number of important rights that you can exercise free of charge. In summary, these rights are:
- Right of Access to your personal information and other supplementary information;
- Right of Rectification – require us to correct any mistakes or complete missing information we hold on you;
- Right of Erasure – you can ask us to erase your personal information in certain circumstances;
- Right to Restrict Processing – in certain situations, you can request that we restrict our processing of your personal information;
- Right to Data Portability – You can receive a copy of the personal information you have provided to us or have this information be sent to a third party in a structured, commonly used and machine-readable format;
- Right to Object to us processing of your personal information for direct marketing;
- Rights related to automated decision-making – Where we use automated decision-making and/or profiling that significantly affects you, you have the right to receive information about the decision, make representations about it, request that a person reviews it, and contest the outcome.
If you want more information about your rights under the UK GDPR, please see the Guidance from the Information Commissioners Office on Individual’s rights under the UK GDPR.
If you want to exercise any of these rights, please contact us using the details provided at the top of this Privacy Notice, above.
How to make a complaint:
If you have a concern about how we have handled your personal data, you can raise a complaint with us directly through any of the contact details set out on the first page of this Privacy Notice.
We will acknowledge your complaint within 30 days and respond without undue delay.
If you are not satisfied with our response, or if you would prefer to go directly to the regulator, you also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s data protection supervisory authority. You can make a complaint to the ICO by calling 0303 123 1113 or via the complaints tool on their website: https://ico.org.uk/make-a-complaint/
Our security:
We take appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, alteration or disclosure. These measures include secure IT systems, access controls, encryption where appropriate, staff training, confidentiality obligations and procedures for responding to security incidents. Access to personal data is restricted to those who require it for legitimate business purposes.
Future processing:
We do not intend to process your personal information for any reason other than stated within this Privacy Notice. If this changes, we will update the Privacy Notice on our website.
Changes to this privacy notice:
This Privacy Notice was published in August 2026 and may be updated from time to time to make sure it is up-to-date with legal and regulatory requirements and good practice. The latest version will be published on our website.

