Who we are
Finnerve Ltd is the data controller for the personal data described in this notice.
| Company name | Finnerve Ltd |
| Registration number (CRN) | 17200557 |
| Registered office | 66 Paul Street, London, EC2A 4NA, United Kingdom |
| Data protection contact | dpo@finnerve.com |
This notice is issued in accordance with Articles 13 and 14 of the UK GDPR, the Data Protection Act 2018 and, where we process data of people located in the European Economic Area, Regulation (EU) 2016/679.
Controller and processor: two distinct roles
- Finnerve Ltd as controller. For the data of website visitors, business contacts, candidates, staff and supplier representatives. This notice covers those activities.
- Finnerve Ltd as processor. When we provide BPO, SaaS, application outsourcing or systems integration and access the data of our clients’ clients. In those cases the controller is the contracting entity, processing is governed by the Data Processing Agreement signed under Article 28 of the UK GDPR, and data subjects should direct their requests to that entity.
What we process, why and on what legal basis
Website visitors
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, device and browser type, pages visited, session duration | Operate and secure the site, prevent abuse | Legitimate interest (Art. 6(1)(f)) |
| Web analytics data (if enabled) | Understand and improve site usage | Consent (Art. 6(1)(a)) |
Cookie detail is in the Cookie Policy.
Business contacts, clients and prospects
| Data | Purpose | Legal basis |
|---|---|---|
| Name, role, company, work email, phone, content of communications | Answer enquiries, prepare proposals, manage the commercial relationship | Pre-contractual steps and contract performance (Art. 6(1)(b)); legitimate interest in B2B business development (Art. 6(1)(f)) |
| Identification and verification data (ID, corporate structure, UBO, sanctions screening) | KYC/AML and anti-bribery due diligence | Legal obligation and legitimate interest (Arts. 6(1)(c) and 6(1)(f)) |
Candidates
| Data | Purpose | Legal basis |
|---|---|---|
| CV, academic and professional history, references, interview results | Assess the application | Pre-contractual steps (Art. 6(1)(b)) |
| Identity and right-to-work verification | Comply with the Immigration, Asylum and Nationality Act 2006 | Legal obligation (Art. 6(1)(c)) |
| Sanctions screening and, for critical roles, basic criminal-record checks | Protect regulated clients’ information | Legitimate interest (Art. 6(1)(f)); Art. 10 UK GDPR and Schedule 1 DPA 2018 for criminal data |
Supplier representatives
We process name, role, contact details and the due-diligence information described in our third-party policy, on the basis of contract performance and legitimate interest in managing third-party risk.
Who we share data with
- Finnerve group entities (Finnerve S.A.C. in Peru, Finnerve Chile SpA and other subsidiaries), for coordinated delivery of the services.
- Technology providers acting as processors (hosting, corporate email, CRM, analytics, e-signature), all subject to an Article 28 UK GDPR contract.
- Professional advisers (legal, tax, audit) under a duty of confidentiality.
- Public authorities and regulators, where there is a legal obligation or a legitimate request.
We do not sell personal data or share it with third parties for advertising purposes.
International transfers
Our operations span the United Kingdom, the European Union and Latin America, so data may be transferred outside the UK or the EEA. Every transfer relies on an adequacy decision, the International Data Transfer Agreement (IDTA) or the UK Addendum to the Standard Contractual Clauses, or the EU Standard Contractual Clauses (SCC). Where the destination has no adequacy decision, we carry out a documented Transfer Risk Assessment and apply supplementary measures (encryption, pseudonymisation, key control). You can request a copy of the safeguards by writing to dpo@finnerve.com.
How long we keep data
| Category | Period |
|---|---|
| Browsing and analytics data | As stated in the Cookie Policy |
| Business contacts and prospects without conversion | Up to 24 months from last contact |
| Contract and client documentation | Term of the contract plus the applicable limitation period |
| KYC/AML due-diligence records | 5 years from the end of the relationship (regulation 40, MLR 2017) |
| Accounting and corporate records | 6 years (Companies Act 2006) |
| Unsuccessful applications | 12 months, unless consent is given for a longer period |
Once the periods elapse, data is securely deleted or anonymised.
Your rights
As a data subject you have the right to access, rectify, erase, restrict processing, object (including to direct marketing, at any time), data portability, not be subject to solely automated decisions with significant legal effects (Finnerve Ltd does not make such decisions), and withdraw consent where processing relies on it.
To exercise them, write to dpo@finnerve.com. We will respond within one month, extendable by two months for complex requests. Exercising these rights is free, except for manifestly unfounded or excessive requests.
Complaints
If you believe we have handled your data improperly, you may complain to the supervisory authority:
- United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
- European Economic Area: the supervisory authority of your Member State of residence or work.
We would be grateful for the chance to resolve your concern first, by writing to dpo@finnerve.com.
Security
We apply technical and organisational measures aligned with ISO/IEC 27001:2022 and NCSC guidance: least-privilege access control, multi-factor authentication, encryption in transit and at rest, activity logging, backups and formal incident management. In the event of a personal-data breach, we notify the ICO within 72 hours where required, and affected individuals where the risk is high.
Changes to this notice
We may update this notice to reflect legal or operational changes. The date of the latest review appears in the document header. Substantial changes will be highlighted on the website.