Skip to main content
Legal

Privacy Policy

What personal data the platform holds, why, how long, and what you can ask us to do.

Last updated 21 August 2026

What counts as evidenceThree rows. A control described in a document is unticked; a control enforced by code and one refused by the database are ticked. Only the second and third are evidence that something holds.Described in a documentEnforced by codeRefused by the database

Before you rely on this

This document is a drafting framework prepared for a platform that is not yet trading. It has not been reviewed by qualified counsel in any jurisdiction, and it must be before it is relied upon by anybody.

This policy covers personal data we process as a controller. Where we process personal data on behalf of a customer — an issuer’s investor records, for example — that customer is the controller and we are a processor acting on their instructions.

1. Who is responsible

LEGAL ENTITY NAME is the controller for the data described in this policy. Our data protection contact is DATA PROTECTION CONTACT. We are registered with SUPERVISORY AUTHORITY under REGISTRATION NUMBER.

2. What we hold, and why

Account dataName, work email, workspace and role. Needed to give you access and to attribute actions to a person. Lawful basis: contract.
Authentication dataA password hash — never the password — and multi-factor credentials. Lawful basis: legal obligation and legitimate interest in securing the service.
Audit recordsWho did what, when, and from what session. Retained for the full retention period and never editable. Lawful basis: legal obligation.
Investor recordsIdentity and verification data, where an issuer records it. We process this as a processor on that issuer’s instructions. Identifying fields are encrypted at rest with a key bound to the record.
Technical dataIP address, request metadata and error traces, kept for security and diagnosis. Lawful basis: legitimate interest.

We do not use personal data to train machine-learning models. Where the platform offers an assistant, the material sent to the model provider is checked for personal data first and the request is refused — not redacted — if any is found.

3. How long we keep it

  • Account data: for the life of the account, then ACCOUNT RETENTION PERIOD.
  • Audit and financial records: STATUTORY RETENTION PERIOD, which is set by the operator’s regulatory obligations rather than by preference.
  • Technical logs: LOG RETENTION PERIOD.
  • Backups: purged on the backup rotation, which may lag a deletion request by up to BACKUP ROTATION PERIOD.

4. Your rights

Depending on where you are, you may have the right to access your data, correct it, have it erased, restrict or object to processing, and receive it in a portable form. To exercise any of these, contact DATA PROTECTION CONTACT.

One limit, stated plainly

The audit trail cannot be edited or erased, by you or by us. It is hash-chained specifically so that it cannot be, because an alterable record of who authorised a financial action is not evidence of anything. Where erasure would otherwise apply, we rely on the legal-obligation and establishment-of-legal-claims grounds to retain it, and we will tell you that is what we are doing rather than quietly declining.

5. Who else sees it

We share personal data with the sub-processors listed on the Sub-processors page, and with nobody else except where compelled by law. We do not sell personal data and we do not share it for advertising.

6. International transfers

Data is held in DATA REGION. Where data is transferred outside that region, we rely on TRANSFER MECHANISM and can supply the relevant documentation on request.

7. Complaints

If you are dissatisfied with how we have handled your data, please tell us first — see the Complaints page. You also have the right to complain directly to SUPERVISORY AUTHORITY.

Before this page is published

The highlighted terms above are facts about a specific legal entity that this draft does not know. Each must be supplied, and the whole document reviewed by qualified counsel, before anybody relies on it.

  • LEGAL ENTITY NAME and COMPANY REGISTRATION NUMBER
  • DATA PROTECTION OFFICER name and contact, where one is required
  • SUPERVISORY AUTHORITY the operator is registered with, and the registration number
  • REPRESENTATIVE in the UK or EU, where the operator is established outside it
  • RETENTION PERIODS confirmed against the operator’s regulatory obligations