Privacy policy
This policy explains what we hold about you, why we hold it, and the controls that surround it.
Last updated 2026
Data we collect
Identity and verification records gathered at onboarding (name, address, date of birth, identity documents), contact details, account and settlement activity, correspondence with your advisory team, and technical data such as device and session information used to secure your account.
Why we hold it
To operate your account, execute and record settlements, meet anti-money-laundering and know-your-customer obligations, detect fraud, and communicate with you about your mandates. We do not sell client data and we do not use it for third-party advertising.
Storage and security
Records are held in encrypted managed infrastructure with encryption in transit and at rest. Access is limited to your assigned officer and compliance staff, every access event is logged, and sessions are bound to recognised devices with two-factor authentication.
Sharing
We share data only with regulators and law enforcement where legally required, with payment and banking partners strictly to execute your instructions, and with processors bound by confidentiality obligations. We do not transfer client records outside these purposes.
Retention
Account and settlement records are retained for the statutory period applicable to regulated financial records, generally a minimum of five years after the relationship ends. After that period records are securely destroyed.
Your rights
You may request access to your records, correction of inaccurate data, a copy of the data you supplied, and erasure where no statutory retention obligation applies. Requests are raised through secure messaging in your dashboard and answered within thirty days.