FINREGE PRIVACY NOTICE (B2B)

1. INTRODUCTION 

1.1 Purpose. This Vendor Privacy Notice (‘Notice’) sets out how FinregE Limited (‘we’, ‘us’, ‘our’, or ‘FinregE’) collects, uses, stores, transfers, and protects personal data in accordance with applicable data protection and privacy laws. This Policy applies to all customers, subscribers, and platform users where personal data is processed. 

1.2 Regulatory Framework. This Notice is established in compliance with: (a) the Assimilated Regulation (EU) 2016/679, UK General Data Protection Regulation (‘UK GDPR’); (b) the Data Protection Act 2018; (c) the Data (Use and Access) Act 2025 insofar as it applies (‘DUAA’); (d) the Privacy and Electronic Communications Regulations 2003 (‘PECR’); and (e) other applicable international data protection and privacy laws, including any amendments introduced under the UK data protection and privacy framework. 

1.3 InfoSec Management Framework Integration. This Policy forms a component of FinregE’s Information Security Management System (“ISMS”) and operates in conjunction with our ISO/IEC 27001:2022-aligned controls, ensuring that the protection of personal data is embedded within our broader information security, risk management, and governance framework. 

2. DATA CONTROLLER AND PROCESSOR ROLES 

2.1 Controller Status. We operate as a controller for personal data collected directly through our services, websites, applications and business operations. We are an organisation established and incorporated in England.  

2.2 Company Information. FINREGE LIMITED (company registration no. 11139011), One Canada Square, Canary Wharf, London, E14 5AB, United Kingdom. Email: [email protected]  

2.3 Processor Obligations. When acting as a processor, we only process personal data on documented instructions from the data controller (our client). Our processor obligations and technical and organisational measures are aligned with our ISMS and ISO/IEC 27001:2022 Annex A controls. 

3. CATEGORIES OF PERSONAL DATA PROCESSED 

3.1 Overview of Data Categories. In the course of providing our services, we collect and process various categories of personal data. The specific categories processed depend on the nature of the services provided and the interactions between the data subject and our platforms. All personal data categories described below are mapped to our Information Assets Registers and data inventories and are classified in line with our Information Security Policy and InfoSec Management Framework. 

a. Identification Data. We process identification data including name, job title, contact details, and business correspondence information. This data is collected for the purpose of establishing and maintaining customer relationships, providing support services, and facilitating communication regarding our services. 

b. Account Data. We process account data including username, password, authentication logs, and access credentials. This data is necessary for the provision of secure access to our platforms and for maintaining the integrity of user accounts. 

c. Usage Data. We process usage data including IP address, browser type, time zone settings, pages visited, and interaction logs. This data is collected for the purposes of system security, service improvement, and understanding how customers interact with our platforms. 

d. Device Data. We process device data including device type, operating system, device settings, and endpoint configurations. This data supports technical compatibility, security monitoring, and troubleshooting activities. 

e. AI-Processed Data. We process AI-processed data including input data submitted by users for AI analysis and resulting outputs, which may include personal data. This processing is subject to additional safeguards as set out in Section 5 of this Policy. 

f. Client Data. We process client data including business contact details, service preferences, transaction history, and subscription information. This data is processed for contract administration, service delivery, and customer relationship management. 

g. Special Categories of Data. Special categories of personal data are only processed where necessary and with explicit consent. Examples may include biometric data used in some AI services. We do not knowingly collect data from children under the age of 16 without verified parental consent. 

4. LAWFUL BASIS FOR PROCESSING 

4.1 Processing Purposes and Legal Basis. FinregE processes personal data only where a lawful basis exists under Article 6 of the UK and EU GDPR. The table below sets out our processing purposes and the corresponding lawful basis for each: 

 

PURPOSE 

LAWFUL BASIS 

To provide and manage our software and AI services 

Contractual necessity 

To maintain and secure our systems 

Legitimate interests / obligations 

To respond to enquiries and support requests 

Contractual necessity / legal interests 

To personalise our experience through AI 

Legitimate interests / consent (where required) 

For research and product development 

Legitimate interests (with safeguards) 

To comply with legal and regulatory requirements 

Legal obligations 

For marketing and communications 

Consent or legitimate interests (soft opt-in) 

 

4.2 Data Minimisation Principle. Personal data is collected and processed only where strictly necessary for the specified purposes. AI models are trained on anonymised or pseudonymised datasets wherever feasible. Default configurations promote data protection by design and by default. 

4.3 Purpose Limitation. AI systems are periodically reviewed to ensure data usage remains aligned with original collection purposes. Where personal data is to be used for a new purpose, we will assess whether this is compatible with the original purpose and notify data subjects where required. 

5. AUTOMATED DECISION-MAKING AND AI PROCESSING 

5.1 Automated Decision Disclosure. Our AI systems may involve automated processing, including profiling, in the context of delivering insights, recommendations, or decisions such as risk assessments and predictions. Data subjects are entitled to know when automated decision-making is being applied to their personal data. 

5.2 Safeguards for Significant Effects. Where automated decision-making has legal or similarly significant effects on data subjects, we ensure the following safeguards are in place: a meaningful explanation of the logic involved is provided; human review is available upon request; and data subjects have the right to contest the decision. 

5.3 Data Protection Impact Assessments. We conduct Data Protection Impact Assessments (DPIAs) or Transfer Risk Assessments (TRAs) for high-risk AI use cases as required by Article 35 of the UK and EU GDPR. Findings from DPIAs and AI risk assessments are recorded and, where relevant, integrated into our ISMS risk register, informing control selection, monitoring activities, and updates to our Statement of Applicability. 

5.4 AI-Specific Safeguards. We implement the following AI-specific safeguards: explainability mechanisms are implemented to ensure transparency of AI decision-making; bias detection frameworks are embedded in model evaluation and validation processes; model version control and audit trails are maintained to ensure accountability and traceability; and human-in-the-loop review is implemented where AI processing may have legal or significant effects on individuals. 

6. DATA SHARING AND THIRD PARTIES 

6.1 Data Sharing when FinregE operates as Controller. When FinregE operates as a controller, we may share personal data with the following categories of recipients in accordance with applicable data protection laws: 

a. Group Companies and Affiliates. Personal data may be shared with FinregE group companies and affiliates for administrative, operational, and business purposes. 

b. Service Providers. Third-party service providers engaged by FinregE, such as cloud hosting providers, analytics platforms, customer support systems, and IT infrastructure providers. See Schedule 1 for the different service providers which may apply to various commercial endeavours. 

c. Professional Advisers. Legal, financial, and other professional consultants engaged by FinregE. 

d. Regulatory Bodies: where required by law or regulatory obligation, personal data may be disclosed to supervisory authorities, law enforcement or other governmental bodies, in accordance with statutory exemptions under the DPA 2018.  

e. Business Transfers. In the event of a merger, acquisition, or sale of assets, personal data my be transferred as part of the transaction, subject to appropriate safeguards. 

As controller, all third parties engaged by FinregE are contractually bound to comply with data protection obligations equivalent to those set out in this Notice. Data protection and security clauses are embedded in all contracts with processors and sub-processors.   

6.2 Data Sharing when FinregE operates as Processor. Where FinregE operates as a processor on behalf of a client (who operates as the controller), the following restrictions to data sharing apply:  

a. No Independent Sharing. FinregE does not share, disclose, or transfer client personal data to any third party except as expressly authorised by the client or as required by applicable law.  

b. Authorised Sub-Processors. Personal data may only be shared with sub-processors that have been disclosed and approved by the client under the relevant Data Processing Agreement or associated sub-processor schedule.  

c. Equivalent Obligations. All approved sub-processors are contractually bound to comply with data protection and security obligations no less protective than those imposed on FinregE under the Data Processing Agreement.  

d. Audit Rights. Clients retain the right to audit or request assurance reports (e.g. SOC 1 or 2, ISO 27001) regarding sub-processor compliance.  

6.3 Supplier Due Diligence. FinregE conducts due diligence assessments before onboarding any vendor or sub-processor, with a focus on data security posture. Ongoing vendor audits and compliance monitoring are performed. Supplier and processor risk assessments, including data protection and information security considerations, are documented and, where they identify significant risk, are reflected in our ISMS Risk Register and supplier monitoring plans. 

6.4 Restrictions on Further Processing. Where FinregE receives personal data as a processor, we do not further process such data except: (a) on documented instructions from the controller; (b) as required by applicable law to which FinregE is subject; or (c) where explicitly authorised in the Data Processing Agreement. Any proposed change in processing purposes will be communicated to the controller prior to implementation.  

7. INTERNATIONAL DATA TRANSFERS  

7.1 Transfer Safeguards. If we transfer personal data outside of the UK or the European Economic Area (EEA), we ensure appropriate safeguards are in place. Depending on the arrangement, those safeguards may include the UK Addendum to the EU Standard Contractual Clauses (EU SCCs) in supplementation of the EU-US Data Privacy Framework (DPF), International Data Transfer Agreements (IDTAs), where adequacy decisions are not available or applicable. 

7.2 Transfer Risk Assessment. Transfers are subject to transfer risk assessments or transfer impact assessments and ongoing monitoring to ensure lawful and secure data flaws. Third parties are subject to EU SCCs or IDTAs for cross-border / international data transfers.  

7.3 Transfer Documentation. All international transfers are documented in our Records of Processing Activities (ROPA) and are subject to periodic review to ensure continued compliance with applicable transfer requirements.  

8. DATA RETENTION  

8.1 Retention Periods. We retain personal data for as long as necessary to fulfil the purposes for which it was collected (e.g. for client accounts where personal data is collected, we will retain it for the life of the account, or as required by law, and will look to return and/or destroy provided data in accordance with the data protection and privacy framework and our retention policies, including any relevant client commercial agreements.  

8.2 Secure Disposal. When personal data is no longer needed, it is deleted or anonymised in accordance with our data retention guidelines. Data Retention and Disposal Policies enforce secure destruction or anonymisation of personal data when no longer required. Automated data purging is implemented for outdated or redundant personal data. 

9. TECHNICAL AND ORGANISATIONAL MEASURES 

9.1 Security Framework. In accordance with Article 32 of both the UK and EU GDPR, FinregE implements appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk presented by its data processing activities, including AI-based operations. These controls are aligned with industry standards including ISO/IEC 27001 and NIST CSF and are reviewed regularly. 

9.2 Access Control. Access to personal data is restricted through role-based access control (RBAC) based on the principle of least privilege. Multi-factor authentication (MFA) is required for all administrative and privileged accounts. User access reviews are conducted at regular intervals. Separation of environments (development, staging, production) is maintained to prevent data leakage. 

9.3 Encryption and Data Protection. Data in transit is protected using TLS 1.2 or higher. Data at rest is encrypted using AES-256 or equivalent encryption standards. Key management policies are in place and follow industry best practices. Sensitive logs are redacted or encrypted. 

9.4 Network Security. Networks and network devices are secured, managed, and controlled to protect information in systems and applications. Network segregation is achieved using distinct Azure subscriptions, resource groups, security groups, and application environments. Web access from corporate endpoints is controlled using Microsoft Defender, Entra ID, and landlord network security features. 

9.5 Monitoring and Incident Response. Continuous monitoring of systems is conducted for suspicious activity or policy violations. A documented and tested incident response plan is in place, including breach notification procedures in line with Articles 33 and 34 of GDPR. Security event logs are established to store messages about system crashes, unsuccessful login attempts, and unsuccessful changes to access privileges. 

9.6 Intrusion Detection. Intrusion detection mechanisms are employed for critical business applications, information systems, and networks. Intrusion detection software is updated automatically and within defined timescales. Suspected intrusions are analysed and potential business impact is assessed. 

9.7 Malware Protection. Malware protection software is installed on systems exposed to malware. Malware protection software is configured to be active at all times and perform scheduled scanning. Results from malware protection activities are recorded and correlated with other security events. 

9.8 Secure Development. Security and privacy requirements are integrated into all stages of design, build, and deployment. Static code analysis is performed using Microsoft Security Code Analysis (MSCA) extension in Azure DevOps. Secure coding guidance follows OWASP secure development standards. Test data is appropriately selected, protected, and managed, with synthetic or anonymised datasets used by default. 

9.9 Business Continuity. Business continuity and disaster recovery plans are produced for all mission-critical information, applications, systems, and networks. Our SaaS platform operates on resilient Azure infrastructure with geo-replication and hourly backups. Backup restoration is tested at appropriate intervals. 

10. DATA SUBJECT RIGHTS 

10.1 Individual Rights. Under UK and EU GDPR, individuals have the following rights in relation to their personal data: the right to access and obtain a copy of personal data; the right to rectification to correct inaccurate or incomplete data; the right to erasure to request deletion of data (right to be forgotten); the right to restrict processing to limit how data is used; the right to data portability to receive data in a structured, machine-readable format; the right to object to processing based on legitimate interests or direct marketing; the right not to be subject to automated decision-making including profiling; the right to withdraw consent at any time where processing is consent-based; and the right to lodge a complaint with the ICO (UK) or local EU Supervisory Authority. 

10.2 Exercise of Rights. To exercise your rights, please contact our Data Protection Officer in accordance with Section 14.2 of this Notice. We will verify the identity of any individual requesting data under these rights and respond within statutory timeframes. 

10.3 Right to Lodge a Complaint. You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at www.ico.org.uk  or your local EU Supervisory Authority based on residence. 

11. MARKETING COMMUNICATIONS 

11.1 Marketing Basis. We may send direct marketing communications to you in the following circumstances:  

a. Consent-Based Marketing: Where you have provided your explicit consent (opt-in) to receive marketing communications. You may withdraw this consent at any time. 

b. Soft Opt-In (Prospective and Existing Commercial Relationships): where we have obtained your contact details in the course of a sale or negotiations for a sale of products or services to you, we may send you direct marketing communications relating to our similar products or services, provided that:  

i. You were given a clear opportunity to opt-out of marketing at the time your details were collected;  

ii. You have not subsequently opted out of receiving such communications; and  

iii. Each marketing communication includes a clear and straightforward opt-out mechanism.  

c. Corporate Subscribers (Limited Companies and LLPs): Where the contact details are for a generic corporate email address that does not identify an individual (for example, [email protected] or [email protected]), we may rely on legitimate interests to send electronic marketing materials. If a corporate subscriber’s email address contains personal data, then we will rely on another lawful basis, either Section 11.1(a) or (b), where applicable.  

11.2 Opt-Out Rights. You may withdraw consent or opt out at any time by: (a) clicking the “unsubscribe” link included in our electronic marketing communications; (b) updating your communication preferences through your account settings, where applicable; or (c) by contacting us at [email protected]. 

11.3 Third-Party Marketing. We do not share your personal data with third parties for their marketing purposes.  

12. COOKIES AND TRACKING 

12.1 Cookie Usage. Our website and platforms may use cookies and similar technologies for functionality, analytics, and personalisation. 

12.2 Cookie Policy. For details, please refer to our separate Cookie Policy, which includes information about cookie types, purpose, and how to manage preferences. 

13. INCIDENT MANAGEMENT AND BREACH NOTIFICATION 

13.1 Incident Reporting. All breaches of this Policy and all other information security incidents shall be reported to the Incident Response Core Team/CTO. 

13.2 Incident Response Process. Our incident response process includes identification through user reports, system logs, or monitoring alerts; classification based on severity, impact, and urgency; containment to prevent further damage; investigation including root cause analysis and impact assessment; eradication and recovery; lessons learned through post-incident review and documentation; and communication with stakeholders including management, customers, and users. 

13.3 Breach Notification. In the event of a personal data breach, we will notify the ICO (UK) or the relevant EU Supervisory Authority within 72 hours, where required. Affected data subjects will be notified where there is high risk to their rights and freedoms. 

13.4 Forensic Preservation. If required as a result of an incident, data will be isolated to facilitate forensic examination. This decision shall be made by the CTO. 

14. ACCOUNTABILITY AND GOVERNANCE 

14.1 Records of Processing. We maintain comprehensive Records of Processing Activities (RoPA) under Article 30 of GDPR. Outputs from ROPA reviews, data protection risk assessments, and DPIAs are shared with our information security and risk management functions. 

14.2 Data Protection Officer. We have designated a Data Protection Officer (DPO) responsible for oversight and compliance. The DPO may be contacted at [email protected]. For questions, concerns, or data access requests, please contact our DPO directly. 

14.3 ISMS Management Review. Outputs from privacy risk assessments are considered during ISMS Management Reviews. This ensures that privacy risks, control gaps, and improvement opportunities are systematically tracked, prioritised, and addressed within our overall information security governance. 

14.4 Audit and Compliance. Internal audits are conducted to ensure policy compliance and control effectiveness. External audits include ISO 27001 surveillance and recertification audits, Cyber Essentials assessments, and SOC 2 preparation activities. Findings are tracked through ISMS nonconformity and corrective action processes. 

15. POLICY CHANGES 

15.1 Updates. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations.  

15.2 General Enquiries. For general enquiries, please contact us at [email protected] or telephone +44 (0) 204 537 08 60. Our address is One Canada Square, Canary Wharf, London, E14 5AB, United Kingdom. 

 

 

Downloads Alert