Skip to content
— Legal

Privacy Policy

Finnerve Ltd · Updated August 2026 · v2.0

Who we are

Finnerve Ltd is the data controller for the personal data described in this notice.

Company nameFinnerve Ltd
Registration number (CRN)17200557
Registered office66 Paul Street, London, EC2A 4NA, United Kingdom
Data protection contactdpo@finnerve.com

This notice is issued in accordance with Articles 13 and 14 of the UK GDPR, the Data Protection Act 2018 and, where we process data of people located in the European Economic Area, Regulation (EU) 2016/679.

Controller and processor: two distinct roles

  • Finnerve Ltd as controller. For the data of website visitors, business contacts, candidates, staff and supplier representatives. This notice covers those activities.
  • Finnerve Ltd as processor. When we provide BPO, SaaS, application outsourcing or systems integration and access the data of our clients’ clients. In those cases the controller is the contracting entity, processing is governed by the Data Processing Agreement signed under Article 28 of the UK GDPR, and data subjects should direct their requests to that entity.

Website visitors

DataPurposeLegal basis
IP address, device and browser type, pages visited, session durationOperate and secure the site, prevent abuseLegitimate interest (Art. 6(1)(f))
Web analytics data (if enabled)Understand and improve site usageConsent (Art. 6(1)(a))

Cookie detail is in the Cookie Policy.

Business contacts, clients and prospects

DataPurposeLegal basis
Name, role, company, work email, phone, content of communicationsAnswer enquiries, prepare proposals, manage the commercial relationshipPre-contractual steps and contract performance (Art. 6(1)(b)); legitimate interest in B2B business development (Art. 6(1)(f))
Identification and verification data (ID, corporate structure, UBO, sanctions screening)KYC/AML and anti-bribery due diligenceLegal obligation and legitimate interest (Arts. 6(1)(c) and 6(1)(f))

Candidates

DataPurposeLegal basis
CV, academic and professional history, references, interview resultsAssess the applicationPre-contractual steps (Art. 6(1)(b))
Identity and right-to-work verificationComply with the Immigration, Asylum and Nationality Act 2006Legal obligation (Art. 6(1)(c))
Sanctions screening and, for critical roles, basic criminal-record checksProtect regulated clients’ informationLegitimate interest (Art. 6(1)(f)); Art. 10 UK GDPR and Schedule 1 DPA 2018 for criminal data

Supplier representatives

We process name, role, contact details and the due-diligence information described in our third-party policy, on the basis of contract performance and legitimate interest in managing third-party risk.

Who we share data with

  • Finnerve group entities (Finnerve S.A.C. in Peru, Finnerve Chile SpA and other subsidiaries), for coordinated delivery of the services.
  • Technology providers acting as processors (hosting, corporate email, CRM, analytics, e-signature), all subject to an Article 28 UK GDPR contract.
  • Professional advisers (legal, tax, audit) under a duty of confidentiality.
  • Public authorities and regulators, where there is a legal obligation or a legitimate request.

We do not sell personal data or share it with third parties for advertising purposes.

International transfers

Our operations span the United Kingdom, the European Union and Latin America, so data may be transferred outside the UK or the EEA. Every transfer relies on an adequacy decision, the International Data Transfer Agreement (IDTA) or the UK Addendum to the Standard Contractual Clauses, or the EU Standard Contractual Clauses (SCC). Where the destination has no adequacy decision, we carry out a documented Transfer Risk Assessment and apply supplementary measures (encryption, pseudonymisation, key control). You can request a copy of the safeguards by writing to dpo@finnerve.com.

How long we keep data

CategoryPeriod
Browsing and analytics dataAs stated in the Cookie Policy
Business contacts and prospects without conversionUp to 24 months from last contact
Contract and client documentationTerm of the contract plus the applicable limitation period
KYC/AML due-diligence records5 years from the end of the relationship (regulation 40, MLR 2017)
Accounting and corporate records6 years (Companies Act 2006)
Unsuccessful applications12 months, unless consent is given for a longer period

Once the periods elapse, data is securely deleted or anonymised.

Your rights

As a data subject you have the right to access, rectify, erase, restrict processing, object (including to direct marketing, at any time), data portability, not be subject to solely automated decisions with significant legal effects (Finnerve Ltd does not make such decisions), and withdraw consent where processing relies on it.

To exercise them, write to dpo@finnerve.com. We will respond within one month, extendable by two months for complex requests. Exercising these rights is free, except for manifestly unfounded or excessive requests.

Complaints

If you believe we have handled your data improperly, you may complain to the supervisory authority:

  • United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
  • European Economic Area: the supervisory authority of your Member State of residence or work.

We would be grateful for the chance to resolve your concern first, by writing to dpo@finnerve.com.

Security

We apply technical and organisational measures aligned with ISO/IEC 27001:2022 and NCSC guidance: least-privilege access control, multi-factor authentication, encryption in transit and at rest, activity logging, backups and formal incident management. In the event of a personal-data breach, we notify the ICO within 72 hours where required, and affected individuals where the risk is high.

Changes to this notice

We may update this notice to reflect legal or operational changes. The date of the latest review appears in the document header. Substantial changes will be highlighted on the website.