Privacy Policy
Last updated: August 21, 2026
Carrizo Global Law PLLC ("Carrizo Global Law," "CGL," "we," "us," or "our") respects privacy and recognizes that legal inquiries may involve sensitive information. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit carrizogloballaw.com, communicate with us through connected digital channels, request a consultation, or otherwise interact with our online services (collectively, the "Services").
This Privacy Policy is intended to provide transparency under applicable U.S. privacy laws and, where applicable to a particular interaction, the EU General Data Protection Regulation ("EU GDPR"), the UK GDPR and Data Protection Act 2018 as amended, and other privacy laws that may apply.
1. Who We Are and Scope
Carrizo Global Law PLLC is a District of Columbia law firm. The firm provides legal services in areas that may include U.S. immigration law, business and corporate law, federal tax and IRS matters, District of Columbia trusts and estates, and cross-border legal planning, subject in each case to applicable jurisdictional and professional-practice requirements.
This Policy applies to information collected through the Site and connected tools used for contact, intake, conflict screening, scheduling, communications, client service, case management, electronic signatures, billing and payments, analytics, security, automation, and related operations.
Third-party websites and services linked from our Site may have their own privacy practices. This Policy does not govern a third party acting independently as its own controller or business.
2. Professional Confidentiality and Prospective Clients
This Privacy Policy governs personal-information practices, but it does not limit or replace duties imposed by applicable rules of professional conduct, attorney-client privilege, work-product protections, court rules, or other law.
Depending on the circumstances, professional confidentiality duties may apply to information received from a prospective client even if no attorney-client relationship is ultimately formed. At the same time, merely sending an unsolicited message, submitting a general contact form, or using an automated tool does not by itself create an attorney-client relationship.
To protect both you and the firm, our initial consultation and contact forms ask for limited information. Please do not send confidential documents or highly sensitive personal information through general web forms unless we specifically request it and provide an appropriate method for transmission.
3. Categories of Information We Collect
A. Information You Provide
· Identity and contact information, such as name, email address, phone number, address, country of residence, and preferred language.
· Inquiry and intake information, such as practice area, a limited description of the matter, names of other people or organizations involved for preliminary conflict screening, and reported hearings, interviews, filing dates, response dates, or other deadlines.
· Communications, including emails, text messages, WhatsApp or social-media messages, telephone communications, and correspondence with our team.
· Scheduling information relating to consultations, meetings, hearings, or appointments.
· Matter information and documents provided after we authorize or request secure submission, which may include immigration, tax, corporate, financial, estate-planning, identity, government, court, or other legal records.
· Billing and payment information. Full payment-card credentials are generally processed by payment providers rather than stored directly by CGL.
· Marketing preferences, including consent or opt-out choices for email or text communications.
B. Information Collected Automatically
· Internet Protocol (IP) address, browser and device information, operating system, language, and approximate location derived from IP address.
· Pages viewed, links clicked, referring page, session information, timestamps, and similar website-usage information.
· Cookie, pixel, local-storage, or similar identifiers where used and permitted by your preferences and applicable law.
· Security, anti-abuse, and diagnostic information generated when you use the Services.
C. Information From Other Sources
Depending on how you interact with us, we may receive information from website hosting and analytics providers, CRM and intake platforms, case-management and client-portal systems, scheduling services, email and cloud providers, messaging and telephone providers, electronic-signature services, payment processors, social-media platforms, referral sources, public records, government agencies, courts, professional databases, or other sources relevant to providing or evaluating legal services.
4. Sensitive and Special-Category Information
Legal matters may involve information that is considered sensitive under U.S. state law or special-category data under EU or UK law. Depending on the matter, this can include government identifiers, account or tax information, immigration-related facts, health information, biometric information, racial or ethnic origin, religious or political information, sexual orientation, criminal-history information, or the contents of private communications.
We seek to collect sensitive information only when reasonably necessary for a legitimate legal, operational, security, or compliance purpose. We do not use sensitive legal-matter information for targeted advertising.
Where the EU GDPR or UK GDPR applies, we identify an applicable Article 6 lawful basis and, when required, an applicable condition for processing special-category data under Article 9. Depending on the circumstances, such a condition may include processing necessary for the establishment, exercise, or defense of legal claims, explicit consent, or another condition permitted by applicable law. Criminal-offence data is processed only when permitted by applicable law and subject to appropriate safeguards.
5. How and Why We Use Personal Information
· Respond to general inquiries and communications.
· Conduct preliminary intake, identity, conflict, jurisdiction, scope, and matter-fit review.
· Determine whether a consultation may be appropriate and communicate about scheduling, fees, or next steps.
· Provide legal services and administer client relationships after representation is undertaken.
· Prepare, review, organize, translate, analyze, transmit, or file documents when authorized and appropriate.
· Manage case records, deadlines, communications, billing, payments, and firm administration.
· Comply with legal, regulatory, tax, accounting, court, and professional-responsibility obligations.
· Protect the security, integrity, and availability of our systems; prevent abuse, fraud, or unauthorized access; and troubleshoot technical issues.
· Improve the Site, client experience, internal processes, and service quality.
· Send firm news, legal insights, or marketing communications when you have opted in or when another lawful basis permits such communication, and honor opt-out requests.
· Measure website and campaign performance using analytics or advertising technologies where permitted by applicable law and your cookie choices.
6. Artificial Intelligence and Automated Tools
Carrizo Global Law may use artificial intelligence ("AI"), machine-learning, and automated workflow technologies to support administrative, operational, research, and legal-service functions. Depending on the circumstances, these tools may assist with intake routing, information extraction, document organization, translation, summarization, transcription, legal research, drafting assistance, knowledge management, scheduling, quality control, security, or workflow administration.
When personal information is processed through AI-enabled or automated systems, we seek to use it only for legitimate business or legal-service purposes and to apply safeguards appropriate to the sensitivity of the information. AI and automation vendors may process information on our behalf as service providers or processors, subject to applicable contractual, confidentiality, security, and data-protection requirements.
We seek to minimize the personal and confidential information provided to AI-enabled systems. Where reasonably available and appropriate for legal services, we use enterprise, API, or comparable configurations with contractual or technical controls designed to limit provider use of submitted information, including use for general model training.
Human Review and Professional Judgment
Carrizo Global Law does not rely on AI to independently establish an attorney-client relationship, make final conflict-of-interest determinations, accept or decline legal representation, determine controlling legal deadlines, provide final legal advice, authorize filings, or make other binding legal decisions concerning a client or prospective client. Substantive legal decisions remain subject to attorney review and professional judgment.AI-generated or AI-assisted material may contain errors or incomplete information and is subject to appropriate human review before substantive reliance. If we offer an AI-enabled assistant directly to Site visitors or users, we will identify the interaction as automated or AI-assisted where required and provide a means to seek human assistance.
We do not currently use AI or automated processing to make decisions about individuals solely by automated means that produce legal or similarly significant effects. If this practice materially changes, we will update this Policy and provide any additional notices, safeguards, or rights required by applicable law.
7. Legal Bases for EEA and UK Processing
Where the EU GDPR or UK GDPR applies, our lawful basis depends on the purpose and context of the processing and may include:
· Consent - for example, certain marketing communications and non-essential cookies where consent is required. Consent may be withdrawn at any time without affecting prior lawful processing.
· Steps at your request before entering a contract, or performance of a contract - for example, evaluating a requested consultation, administering an engagement, or providing agreed legal services.
· Legitimate interests - for example, conflict screening, client and matter administration, service improvement, system security, fraud prevention, business continuity, and certain communications where those interests are not overridden by your rights and interests.
· Compliance with legal obligations - where processing is necessary to comply with applicable laws, court requirements, tax or accounting obligations, or other legally binding requirements.
· Establishment, exercise, or defense of legal claims and other applicable legal bases or special-category conditions, where relevant to legal services.
When we rely on legitimate interests, those interests may include operating and protecting a law practice, evaluating and managing legal matters, maintaining records necessary for conflict checking and risk management, improving services, and protecting the rights and security of CGL, our clients, prospective clients, personnel, and others.
8. Cookies and Similar Technologies
We and our service providers may use cookies, pixels, software development kits, local storage, and similar technologies. The specific technologies in use may change over time. Categories may include:
· Strictly necessary technologies used for security, authentication, fraud prevention, load balancing, session management, form functionality, and core Site operations.
· Functional technologies used to remember preferences or enhance Site features.
· Analytics technologies used to understand Site performance and visitor interactions.
· Advertising or measurement technologies, if enabled, used to measure campaigns or support relevant advertising.
Where applicable law requires consent for non-essential cookies, we seek consent before activating those technologies. You can use the Site cookie-preference controls, when available, to change non-essential cookie choices. Browser settings may also allow you to reject or delete cookies, although some Site functionality may be affected.
We do not intentionally place sensitive legal-matter facts in advertising cookies or pixels.
9. Marketing, Text Messages, and Communication Preferences
Transactional and inquiry-related communications may be necessary to respond to a message, administer an intake request, schedule a consultation, or provide legal services. Marketing communications are treated separately where required by law.
If you opt in to email marketing, you may unsubscribe using the link included in the message or by contacting us. If you opt in to text messages, message and data rates may apply and you may reply STOP to opt out, subject to the instructions provided with the communication.
Direct Marketing Objection Right
If EU or UK data-protection law applies to you, you have the right to object at any time to processing of your personal data for direct marketing, including related profiling.10. Disclosure and Sharing of Information
We may disclose personal information when reasonably necessary to the following categories of recipients:
· Service providers and processors supporting website hosting, cloud infrastructure, email, CRM, intake, case management, client portals, scheduling, electronic signatures, communications, payment processing, analytics, cybersecurity, IT support, automation, and AI-enabled functions.
· Attorneys, co-counsel, local counsel, experts, translators, interpreters, accountants, consultants, vendors, or other professional service providers when authorized, appropriate, or reasonably necessary for a matter.
· Courts, tribunals, government agencies, tax authorities, immigration authorities, law-enforcement bodies, or other recipients when authorized by the client, required by law, necessary for representation, or otherwise permitted by applicable professional obligations.
· Professional advisors, insurers, auditors, and compliance or security professionals when reasonably necessary.
· Parties involved in a lawful business transition, reorganization, or similar transaction, subject to applicable professional and confidentiality obligations.
We do not sell client files or confidential legal-matter information. We do not disclose client or prospective-client information publicly except with authorization or another lawful and professionally permissible basis.
11. U.S. State Privacy Rights and Targeted Advertising
Certain U.S. state privacy laws may apply only when statutory thresholds or other conditions are met. If and to the extent an applicable U.S. state privacy law grants you rights regarding personal information we control, those rights may include access or confirmation, correction, deletion, data portability, opt-out rights relating to targeted advertising or certain sales or sharing, appeal rights, and protection from unlawful discrimination for exercising privacy rights.
As of the effective date of this Policy, Carrizo Global Law does not sell personal information for monetary consideration. We do not use sensitive legal-matter information for targeted advertising. If we deploy advertising or measurement technologies that constitute a "sale," "sharing," or "targeted advertising" under an applicable state law, we will provide the notices and opt-out mechanisms required by that law.
Where applicable law requires recognition of qualifying opt-out preference signals, such as Global Privacy Control, we will process qualifying signals as required for the covered activity.
To submit a privacy request, email info@carrizogloballaw.com with the subject line "Privacy Request" and describe the right you wish to exercise. We may need to verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law. Some information may be exempt from a request, including information that must be retained for legal, professional-responsibility, conflict-checking, security, claims, or other permitted purposes.
12. Notice at Collection for California and Similar State Laws
Where a notice-at-collection requirement applies, the categories of personal information we may collect include identifiers and contact information; internet or device activity; approximate geolocation; professional or business information; communications; commercial or transaction information; legal inquiry and matter information; and sensitive personal information when reasonably necessary for legal services or another disclosed purpose.
We use these categories for the purposes described in this Policy, including intake and conflict screening, responding to inquiries, providing legal services, communications, billing, security, compliance, service improvement, analytics, and marketing where permitted. We retain each category only for as long as reasonably necessary for the disclosed purpose, taking into account legal and ethical obligations, conflict-screening and risk-management needs, contractual requirements, security requirements, dispute or claims considerations, and our records-management practices.
We may disclose these categories to the recipient categories described in Section 10. We do not use or disclose sensitive personal information for the purpose of inferring characteristics about an individual for targeted advertising.
13. EEA and UK Privacy Rights
If the EU GDPR or UK GDPR applies to our processing of your personal data, you may have rights including access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent, subject to the conditions and exceptions established by applicable law. You may also have the right to lodge a complaint with the data-protection supervisory authority in your country or, in the United Kingdom, with the Information Commissioner's Office.
Rights may differ depending on the lawful basis for processing. For example, erasure rights may be limited where information must be retained to comply with legal or professional obligations, protect legal rights, establish or defend claims, maintain conflict records, or for other permitted reasons.
Where solely automated decision-making with legal or similarly significant effects is used in the future and applicable law grants corresponding rights, we will provide the required information and safeguards, including human intervention or review where required.
14. International Data Transfers
Carrizo Global Law is based in the United States, and information may be processed in the United States and other countries where our service providers operate. Those countries may have privacy laws that differ from the laws of your home jurisdiction.
Where EU or UK data-protection law applies to a restricted international transfer, we use an applicable transfer mechanism or safeguard where required, which may include an adequacy decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, or another mechanism permitted by applicable law. You may contact us for information about applicable safeguards.
15. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected or another compatible and lawful purpose. Retention decisions may take into account:
· the nature, sensitivity, and volume of the information;
· the purpose for which the information was collected;
· whether a prospective-client or client relationship existed;
· conflict-checking, risk-management, insurance, accounting, tax, and professional-responsibility requirements;
· applicable statutes of limitation, litigation holds, investigations, or dispute-resolution needs;
· security and fraud-prevention requirements; and
· contractual or legal obligations imposed on CGL or our service providers.
We may retain limited prospective-client identity and conflict information even when representation does not occur if reasonably necessary for future conflict checking, professional obligations, or risk management. Marketing preference records may be retained as necessary to honor opt-outs and demonstrate consent history.
16. Data Security
We use administrative, technical, and physical safeguards that we consider appropriate to the nature of the information and the risks involved. Safeguards may include access controls, authentication, vendor review, secure communications or storage tools, backup and continuity measures, personnel procedures, and other security controls.
No system or method of transmission is completely secure. We therefore cannot guarantee absolute security. If you believe information provided to CGL has been compromised, please contact us promptly.
17. Children's Privacy
The Site is not directed to children under 16 and is not designed to solicit personal information from children for marketing purposes. Legal matters may, however, involve minors, in which case information may be processed as necessary for representation, intake, family authorization, or another lawful purpose. If you believe a child has submitted information through the Site inappropriately, please contact us.
18. Other International Privacy Rights
Residents of jurisdictions outside the United States, EEA, or United Kingdom may have additional privacy rights under local law, including in countries such as Brazil. Where such law applies to CGL's processing, we will respond to valid requests and provide required protections consistent with applicable law.
19. Changes to This Policy
We may revise this Privacy Policy from time to time to reflect changes in law, technology, our services, vendors, AI or automation practices, advertising and analytics practices, or other operational changes. The "Last updated" date identifies the most recent revision. Where required, we will provide additional notice of material changes.
20. Contact Us
Carrizo Global Law PLLC
1701 Pennsylvania Ave NW, Suite 200, Washington, DC 20006 - By appointment only
Email: info@carrizogloballaw.com
Phone: +1 202-888-5228
Privacy requests: use the subject line "Privacy Request."

