Privacy policy

This policy explains what we hold about you, why we hold it, and the controls that surround it.

Last updated 2026

Data we collect

Identity and verification records gathered at onboarding (name, address, date of birth, identity documents), contact details, account and settlement activity, correspondence with your advisory team, and technical data such as device and session information used to secure your account.

Why we hold it

To operate your account, execute and record settlements, meet anti-money-laundering and know-your-customer obligations, detect fraud, and communicate with you about your mandates. We do not sell client data and we do not use it for third-party advertising.

Storage and security

Records are held in encrypted managed infrastructure with encryption in transit and at rest. Access is limited to your assigned officer and compliance staff, every access event is logged, and sessions are bound to recognised devices with two-factor authentication.

Sharing

We share data only with regulators and law enforcement where legally required, with payment and banking partners strictly to execute your instructions, and with processors bound by confidentiality obligations. We do not transfer client records outside these purposes.

Retention

Account and settlement records are retained for the statutory period applicable to regulated financial records, generally a minimum of five years after the relationship ends. After that period records are securely destroyed.

Your rights

You may request access to your records, correction of inaccurate data, a copy of the data you supplied, and erasure where no statutory retention obligation applies. Requests are raised through secure messaging in your dashboard and answered within thirty days.