Last updated: March 30, 2026
SRipLaw, P.A. (“SRipLaw”, “we”, “us”, or “our”) respects your privacy and is committed to protecting personal data that we process in connection with our legal services and business operations. This Policy explains how we collect, use, disclose, and protect personal data, including personal data transferred from the European Economic Area (EEA), the United Kingdom, and Switzerland to the United States.
This Policy applies to personal data we process about:
If you have any questions about this Policy, please contact us using the details below.
SRipLaw, P.A. is the controller of personal data described in this Policy.
SRipLaw, P.A.
21301 Powerline Road, Suite 212
Boca Raton, Florida 33433
United States
Email: info@sriplaw.com
For EU/EEA, UK, or Swiss individuals, you may also contact us at the same email address with “Data Privacy Framework Request” in the subject line.
The personal data we process depends on your relationship with us and the context in which we collect the data, and may include:
We may also process sensitive personal data where necessary and permitted by law, for example:
We process sensitive data only where required for our legal services or employment purposes, where permitted by law, and subject to additional safeguards.
We process personal data for the following purposes:
Where EU/EEA, UK, or Swiss data protection law applies, we rely on one or more of the following legal bases:
SRipLaw, P.A. complies with the EU‑US Data Privacy Framework (EU‑US DPF), the UK Extension to the EU‑US DPF, and the Swiss‑US Data Privacy Framework (Swiss‑US DPF), as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data transferred from the European Union, the European Economic Area, the United Kingdom (and Gibraltar), and Switzerland to the United States. [web:21]
SRipLaw, P.A. has certified to the U.S. Department of Commerce that it adheres to the EU‑US Data Privacy Framework Principles, the UK Extension to the EU‑US DPF Principles, and the Swiss‑US Data Privacy Framework Principles (together, the “DPF Principles”). If there is any conflict between the terms in this Policy and the DPF Principles, the DPF Principles will govern. [web:21]
To learn more about the Data Privacy Framework program, and to view our certification once it is approved, please visit the Data Privacy Framework website at:
https://www.dataprivacyframework.gov [web:21]
(Once available, we will also include a direct link to our organization’s listing on the Data Privacy Framework List.)
SRipLaw, P.A. is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC) in connection with our adherence to the DPF Principles. [web:21]
For personal data subject to the EU‑US DPF, the UK Extension to the EU‑US DPF, or the Swiss‑US DPF, we may process such data for the purposes described above, including:
We will not use EU/UK/Swiss personal data for purposes materially different from those described in this Policy unless we have a lawful basis to do so and, where required, we provide you with an opportunity to opt out (or opt in for certain sensitive data). [web:21]
If you are an individual whose personal data is subject to the EU‑US DPF, the UK Extension to the EU‑US DPF, or the Swiss‑US DPF, you have the right to:
You can exercise these choices by contacting us at info@sriplaw.com.
Please note that certain data may be required for us to provide legal services or comply with legal obligations; if you choose not to provide such data or to request its deletion, we may not be able to provide certain services.
We may share personal data, including personal data subject to the DPF Principles, with:
When we transfer personal data subject to the DPF Principles to third‑party agents or service providers, we do so in accordance with the DPF requirements: [web:21]
SRipLaw, P.A. remains responsible under the DPF Principles if an agent processes personal data in a manner inconsistent with those Principles, unless SRipLaw proves that it is not responsible for the event giving rise to the damage. [web:21]
We use reasonable and appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures take into account the nature of the personal data and the risks involved in processing it.
We limit the personal data we collect to what is relevant for the purposes described in this Policy and we process it only in ways compatible with those purposes or as later authorized by you. [web:21]
We take reasonable steps to ensure that personal data is accurate, complete, and current, as appropriate to the purposes for which it is used. We retain personal data only for as long as necessary to achieve the purposes of processing, to comply with legal and regulatory obligations, and to protect or establish legal claims, after which we will delete or anonymize the data. [web:21]
If you are located in the EU/EEA, UK, or Switzerland, or if your personal data is processed under the DPF Principles, you have the right to:
These rights may be subject to limitations, for example where honoring your request would conflict with our legal obligations, the rights of others, or our ability to maintain legal privilege.
To exercise your rights, please contact us at info@sriplaw.com. We will respond to your request within a reasonable timeframe and in accordance with applicable law and the DPF Principles. [web:21]
If you have a question or complaint regarding this Policy or our handling of your personal data, please contact us first at:
Email: info@sriplaw.com
Subject line: “Data Privacy Framework Complaint”
We will investigate and attempt to resolve complaints or disputes regarding the use or disclosure of your personal data in accordance with this Policy and the DPF Principles, and we will respond within 45 days. [web:21]
If your complaint involves personal data transferred from the EU/EEA, the UK (and Gibraltar), or Switzerland under the DPF, and we are unable to resolve it satisfactorily, you may submit your complaint free of charge to our designated independent recourse mechanism:
JAMS – Data Privacy Framework (DPF) Dispute Resolution
(Data Privacy Framework Independent Recourse Mechanism)
For information on how to submit a complaint to JAMS under the Data Privacy Framework, including how to open a DPF dispute‑resolution case, please visit:
https://www.jamsadr.com/DPF-Dispute-Resolution [page:1]
JAMS provides independent dispute resolution services to investigate and resolve complaints regarding our compliance with the DPF Principles at no cost to you with respect to consumer‑initiated DPF disputes. [page:1]
For human resources data about individuals in the EU/EEA in the context of an employment relationship (if covered by our DPF certification), we will cooperate with the competent EU data protection authorities (DPAs) and comply with their advice. [web:21]
Under certain conditions, more fully described on the Data Privacy Framework website, you may be entitled to invoke binding arbitration before the Data Privacy Framework Panel as a last resort if your complaint is not resolved by SRipLaw, JAMS, and through other available mechanisms. [web:21][page:1]
We may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. [web:21]
Our services are not directed to children, and we do not knowingly collect personal data from children except where necessary in connection with a legal matter and in accordance with applicable law and professional obligations. If we learn that we have collected personal data from a child contrary to applicable law, we will take appropriate steps to delete it.
We may update this Policy from time to time to reflect changes in our practices, legal requirements, or the DPF program. The “Last updated” date at the top of this Policy indicates when it was last revised. [web:21]
If we make material changes, we will take reasonable steps to inform you, such as posting a prominent notice on our website or contacting you directly, where appropriate.
From general questions to potential IP misuse, choose the option that best fits your case.
Our team will review your submission and get back to you as soon as possible.