Cavendish Capital Markets Limited

Client Data Protection Policy

Data privacy is important to Cavendish Capital Markets and maintaining your trust is our priority. This Policy explains how we collect, store, use and share personal data that we obtain when providing our services to our actual or prospective clients.

1.ABOUT THIS POLICY

  1. In the course of our acting for you, we may receive information relating to you, your directors, shareholders, beneficial owners, employees, agents, associates and family members. In this Policy, we refer to this information as "personal data". References in this Policy to "you" or "your" are references to our actual or prospective client and the individuals whose personal data we process in connection with providing our services.
  2. This Policy also applies to our processing of personal data of individuals who could be (or could be the employees or staff of) counterparties in transactions involving our actual or prospective clients.
  3. This Policy describes the personal data that we collect and sets out the basis on which we will process this personal data. Please read the Policy carefully to understand our practices regarding personal data and how we will use it.
  4. This Policy can be accessed on our website but is not our Website Privacy Policy or Cookie Policy. Our Website Privacy Policy and Cookie Policy are accessible here www.finncap.com/privacy-policy.

2.ABOUT CAVENDISH CAPITAL MARKETS LIMITED

  1. We are Cavendish Capital Markets Limited, a limited liability company registered in England and Wales under number 06198898. Our registered office is at 1 Bartholomew Close, London, EC1A 7BL.
  2. We are part of the Cavendish Financial group of companies. Our parent company is Cavendish Financial  plc.
  3. We are the controller of your personal data, meaning we are the organisation legally responsible for deciding how and for what purposes it is used. We are registered with the UK Information Commissioner’s Office (“ICO”) under registration number Z9884968.
  4. Cavendish Capital Markets Limited is authorised and regulated by the Financial Conduct Authority (“FCA”) with Firm Reference Number 467766.
  5. References in this Policy to “Cavendish Capital Markets”, “we”, “our” and “us” are references to Cavendish Capital Markets Limited.

3.CONTACTING US

  1. If you have any questions about this Policy or your personal data, or to exercise any of your rights as described in this Policy or under applicable data protection laws, you can contact us as follows:

By post:                   The Privacy Manager, Cavendish Capital Markets Limited, 1 Bartholomew Close,  London, EC1A 7BL

By email:                 PrivacyManager@finncap.com 

By telephone:         +44 (0)20 7220 0500

4.PERSONAL DATA WE COLLECT

1. We collect the personal data as necessary to enable us to carry out your instructions, to manage and operate our business and to comply with our legal and regulatory obligations.

2. The personal data that we collect includes, but is not limited to, the following:

  • your name;
  • home and business address;
  • contact details (such as telephone numbers and email address);
  • date of birth;
  • gender;
  • marital status;
  • copies of passport, national identity card, driving licence, utility bills, bank statements and similar documents;
  • business and professional qualifications and experience;
  • immigration status and work permits;
  • financial details;
  • other personal data contained in correspondence and documents which you may provide to us;
  • data from building access controls; and
  • information we obtain from our IT and communications monitoring.

3. If you do not provide any personal data that we ask for and that we need to enable us to carry out your instructions, it may delay or prevent us from providing our services to you.

4. Where you provide personal data relating to your directors, shareholders, beneficial owners, employees, agents, associates or family members you confirm that you are authorised to provide this personal data to us. It is not always reasonably practicable for us to provide to these individuals the information set out in this Policy. Accordingly, where appropriate, you are responsible for providing this information to any such individuals.

5.HOW YOUR INFORMATION IS COLLECTED

1. We collect your personal data:

  1. directly from you when you interact with us in connection with the services that we provide; or
  2. from your company or other third parties with whom we deal in order to provide our services.

2. However, we also collect personal data:

  1. from publicly accessible sources, e.g. Companies House, social media for professional networking such as LinkedIn;
  2. directly from a third party, e.g. client due diligence providers;
  3. from a third party with your consent, e.g.:
  • your bank or building society, or other financial institution or advisor;
  • consultants and other professionals you may engage; and
  • your employer, professional body or pension administrators.

iv. via our website, mobile sites, or applications - we use cookies on our website and mobile sites and applications (for more information on cookies, please see our cookie policy at https://www.finncap.com/cookie-policy).

v. via our information technology systems, e.g.:

  • online customer relationship and document management systems;
  • building access control systems and reception logs.

6.HOW AND WHY WE USE YOUR PERSONAL DATA

  1. Our use of your personal data is subject to your instructions, data protection laws and our professional duty of confidentiality. We will only process your personal data if we have a legal basis for doing so, including where:

    1. processing is necessary for the performance of our contractual engagement with you: this relates to all personal data we reasonably need to process to carry out your instructions and provide our services to you;
    2. processing is necessary for compliance with a legal obligation to which we are subject: this relates to our legal obligations in relation to, for example, anti-money laundering; and
    3. processing is necessary for the purposes of the legitimate interests pursued by us, our client or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms: this relates to our processing for marketing purposes, for our management, accounting and administration purposes and for data security.
  2. The table below further explains the purposes for which Cavendish Capital Markets will use your personal data (excluding special categories of personal data) and our legal basis for doing so:

Purposes for which we will process the personal data

Legal basis for the processing

To provide our services to you and to carry out associated administration and accounting in connection with our services.

Where you are the client, for the performance of our contract with you or to take steps at your request before entering into a contract.

Where you are not the client, it is in our legitimate interests to carry out our client’s instructions and perform our contract with our client.

To comply with our legal and regulatory obligations.

In connection with the provision of our services, other processing necessary to comply with our professional, legal and regulatory obligations.

For the performance of our contract with you or to take steps at your request before entering into a contract.

To comply with our legal and regulatory obligations.

To comply with our anti-money laundering requirements, relevant anti-money laundering regulations, and preventing money laundering, terrorist financing and market abuse.

To comply with our legal and regulatory obligations.

To comply with our internal business policies.

It is in our legitimate interests or those of a third party to adhere to our own internal procedures so that we can deliver an efficient service to you. We consider this use to be necessary for our legitimate interests and proportionate.

For operational reasons, such as improving efficiency, training and quality control.

It is in our legitimate interests to be as efficient as we can so we deliver the best service for you.

To prevent unauthorised access and modifications to our systems.

It is in our legitimate interests to prevent and detect criminal activity that could be damaging for Cavendish Capital Markets and for you.

To comply with our legal and regulatory obligations.

For updating client records.

For the performance of our contract with you or to take steps at your request before entering into a contract.

To comply with our legal and regulatory obligations.

For marketing our services, and notifying you by email, telephone, post or SMS about important financial developments and services which we think you may find valuable, for sending you newsletters, invitations to seminars and similar marketing. We may also disclose personal data to third parties providing marketing services to us, or with whom we are conducting joint marketing exercises.

It is in our legitimate interests to market our services. We consider this use to be proportionate and will not be prejudicial or detrimental to you.

You have the right to opt out of receiving direct marketing communications from us at any time – see further section 9 below.

To carry out credit reference checks.

It is in our legitimate interests to carry out credit control and to ensure our clients are likely to be able to pay for our services.

External audits and quality checks, e.g. the audit of our accounts.

 

It is in our legitimate interests to carry out quality checks and audit to ensure that we operate at the highest standards.

To comply with our legal and regulatory obligations.

Monitoring of emails and telephone calls with us as well as Teams and Bloomberg messages. We also record telephone calls as evidence of your orders or instructions.

It is in our legitimate interest to carry out occasional spot checks or audits of such emailsand telephone calls to ensure compliance with professional standards and our internal compliance policies and for training and quality control.

To comply with our legal and regulatory obligations including in relation to prevention of market abuse.

 

3. Where we request personal data to identify you for compliance with anti-money laundering regulations, we shall process such information only for the purposes of preventing money laundering or terrorist financing, or as otherwise set out in this Policy or permitted by law.

4. A legitimate interest is when we have a business or commercial reason to use your personal data, so long as this is not overridden by your own rights and interests. Where we rely on legitimate interests as a lawful basis, we will carry out a balancing test to ensure that your rights and interests do not override our legitimate interests.

5. Where you provide consent, you can withdraw your consent at any time and free of charge, but without affecting the lawfulness of processing based on consent before its withdrawal. You can update your details or change your privacy preferences by contacting our Privacy Manager as provided in “Contacting us” above.

6. Cavendish Capital Markets will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you in a timely manner and we will explain the legal basis which allows us to do so.

7. Cavendish Capital Markets acts as a data controller in relation to the processing of personal data as set in this Policy. However, in some circumstances we may process personal data on behalf of our client as a data processor for the purposes of data protection laws. Where we process any personal data on behalf of our client as data processor, the terms set out in our data processing addendum, a copy of which is available on request from our Privacy Manager (see Contacting Us above), shall apply.

7.SPECIAL CATEGORIES OF PERSONAL DATA

  1. Certain personal data we collect is treated as a special category to which additional protections apply under data protection law. This includes personal data revealing a person’s racial or ethnic origin, religious or philosophical beliefs, or data concerning health.
  2. We do not generally seek to collect special category personal data, but this may be collected if you provide it to us or where necessary in the context of us providing our services.
  3. We process special categories of personal data for the purposes as set out in the table at section 6.2 above, which also details the corresponding legal basis we rely on to process the personal data for each purpose. In addition, we are required under data protection laws to meet a further condition to have the right to use certain special categories of personal data, such as:
    1. by asking for your explicit consent to our proposed use of that special category personal data at the time of collection, or
    2. where the processing is necessary for reasons of substantial public interest (such as compliance with regulatory requirements relating to unlawful acts and dishonesty), or
    3. where the processing is necessary to establish, exercise or defend legal claims.

8.DATA RELATING TO CRIMINAL CONVICTIONS & OFFENCES

  1. We also collect, store and otherwise process personal data relating to criminal convictions and offences (including the alleged commission of offences).
  2. We process this data for the purposes as set out in the table at section 6.2 above, which also details the corresponding legal basis we rely on to process the personal data for each purpose. In addition, we are required under data protection laws to meet a further condition to have the right to use personal data relating to criminal convictions and offences, such as:
  • by asking for your explicit consent to our proposed use of personal data relating to criminal convictions and offences at the time of collection, or
  • where the processing is necessary for reasons of substantial public interest (such as compliance with regulatory requirements relating to unlawful acts and dishonesty), or
  • where the processing relates to personal data which is in the public domain, or
  • where the processing (a) is necessary for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings), (b)is necessary for the purpose of obtaining legal advice, or (c) is otherwise necessary for the purposes of establishing, exercising or defending legal rights.

9.MARKETING

  1. We have a legitimate interest in using your personal data for marketing purposes (see above ‘How and why we use your personal data’ at section 7 above). This means we do not usually need your consent to send you marketing information. However, for email marketing to an individual subscriber (that is, a non-corporate email address) with whom we have not previously engaged as a client, we need your consent to send you unsolicited email marketing. Where you provide consent, you can withdraw your consent at any time, but without affecting the lawfulness of processing based on consent before its withdrawal.
  2. You have the right to opt out of receiving direct marketing communications from us at any time by:
  • contacting our Privacy Manager (see Contacting Us above); or
  • using the “unsubscribe” link in emails; or
  • sending us an email.

10.THIRD PARTY PROCESSORS

  1. Our information technology systems are operated by Cavendish Capital Markets but some data processing is carried out on our behalf by a third party (see section 11 on Disclosure of Personal data). Details regarding these third party data processors can be obtained from our Privacy Manager (see Contacting Us above).
  2. Where processing of personal data is carried out by a third party data processor on our behalf we endeavour to ensure that appropriate security measures are in place to prevent unauthorised use or disclosure of the personal data.

11.DISCLOSURE OF PERSONAL DATA

  1. Personal data will be retained by us and will not be shared, transferred or otherwise disclosed to any third party, save as set out in this Policy.
  2. We may disclose and share personal data with the following third parties:
    1. with our directors, staff and consultants and with other companies for the time being within the Cavendish Capital Markets group of companies, as necessary to carry out the purposes for which the personal data was provided or collected;
    2. with our auditors, lawyers, insurance brokers and other professional advisors;
    3. with our third party data processors and service providers who provide services to us including marketing, IT and compliance support services such as website hosts, data storage/back up services, disaster recovery, monitoring for prevention of market abuse. Our third party processors and service providers are subject to security and confidentiality obligations and are only permitted to process your personal data for specified purposes and in accordance with our instructions.
  3. In addition, we may disclose personal data about you in the following circumstances:
    1. if we are under a duty to disclose or share your personal data in order to comply with any legal or regulatory obligation. For instance, we may disclose personal data to the FCA and to any other regulatory authority to which we are subject and to any investment exchange on which we may deal or to its related Clearing House (or to auditors, inspectors or agents appointed by them), or to any person in power to require such information pursuant to any applicable law;
    2. in the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets, in which event the recipient of any of your personal data will be bound by confidentiality obligations;
    3. if all or substantially all of our assets are transferred to a third party, in which case personal data held by us about our clients will be one of the transferred assets. If this happens, we shall ensure that you are notified of the transfer and we shall secure a commitment from the firm or company to which we transfer personal data to comply with applicable data protection laws;
    4. if necessary to protect the vital interests of a person; and
    5. to enforce or apply our Client Agreement or to establish, exercise or defend our rights or those of our staff, clients or others.
  4. Certain laws (for example, those relating to money laundering and tax fraud) give power to authorities such as the police or the tax authorities to inspect clients’ personnel’s personal data and take copies of documents. It is possible that, at any time, we may be requested by those authorities to provide them with access to your personal data in connection with the work we have done for you. If this happens, we will comply with the request only to the extent that we are bound by law and, in so far as it is allowed, we will notify you of the request or provision of personal data.
  5. We may transfer personal data to a successor firm or company which acquires the business carried on by us

12.YOUR RIGHTS

1. Access to your personal data

You have the right to access personal data which we hold about you. If you so request, we shall provide you with a copy of your personal data which we are processing (“subject access request”).

2. Data portability

You also have the right to receive your personal data in a structured and commonly used format so that it can be transferred to another data controller in certain circumstances.

3. Right to object

You have the right to object at any time to our processing of your personal data for direct marketing purposes.

Where we process your personal data based on our legitimate interests, you also have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data which is based on our legitimate interests. Where you object on this ground, we shall no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.

4. Rectification

We want to make sure that your personal data is accurate and up to date. You have the right to have inaccurate personal data rectified, or completed if it is incomplete. You can update your details or change your privacy preferences by contacting us as provided in “Contacting us” above

5. Erasure (also known as the right to be forgotten)

In certain situations, you can request the erasure of your personal data that we hold.

6. Right to not be subject to automated individual decision making

You have the right to not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. We do not make any decisions based solely on automated processing.

13.EXERCISING YOUR RIGHTS

  1. You can exercise any of your rights as described in this Policy and under data protection laws by contacting our Privacy Manager (see Contacting Us above).
  2. Please note that the above rights are not absolute, and we may be entitled to refuse requests, wholly or partly, where exceptions under applicable law apply.
  3. Save as described in this Policy or provided under applicable data protection laws, there is no charge for the exercise of your legal rights. However, if your requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may either: (a) charge a reasonable fee taking into account the administrative costs of providing the information or taking the action requested; or (b) refuse to act on the request.
  4. Where we have reasonable doubts concerning the identity of the person making the request, we may request additional information necessary to confirm your identity.

14.SECURITY OF YOUR PERSONAL DATA

  1. We use industry standard physical and procedural security measures to prevent personal data from being accidentally lost, or used or accessed unlawfully. This includes encryption, firewalls, access controls, policies and other procedures to protect personal data from unauthorised access.
  2. We limit access to your personal data to those who have a genuine business need to access it.
  3. Where data processing is carried out on our behalf by a third party, we take steps to ensure that appropriate security measures are in place to prevent unauthorised disclosure of personal data.
  4. Despite these precautions, however, we cannot guarantee the security of personal data transmitted over the Internet or that unauthorised persons will not obtain access to personal data. We have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

15.INTERNATIONAL TRANSFERS

  1. To deliver services to you, it is sometimes necessary for us to transfer and store your personal data outside the UK or the European Economic Area (“EEA”) as follows:
    1. with our service providers located outside the UK or the EEA;
    2. if you are based outside the UK or the EEA;
    3. where there is an international aspect to the services which we have been instructed on.
  2. Where personal data is transferred to and stored outside the UK or the EEA, we take steps to provide appropriate safeguards to protect your personal data, including:
    1. transferring your personal data to a country, territory, sector or international organisation which the UK Government has determined ensures an adequate level of protection, as permitted under applicable data protection laws;
    2. entering into standard contractual clauses approved by the UK Government, obliging recipients to protect your personal data as permitted under applicable data protection laws; or
    3. if we cannot or choose not to rely on either of those mechanisms at any time, we will not transfer your personal data outside the UK or the EEA unless we can do so on the basis of an alternative mechanism or exception provided by applicable data protection laws.
  3. If you would like further information about transfers of your personal data out of the UK or the EEA, please contact our Privacy Manager using the details set out under Contacting Us above.

16.HOW LONG WE KEEP YOUR PERSONAL DATA

  1. Personal data received by us will only be retained for as long as necessary to fulfil our engagement. To determine the appropriate retention period for personal data, we consider (i) the amount, nature, and sensitivity of the personal data; (ii) the potential risk of harm from unauthorised use or disclosure of your personal data; (iii) the purposes for which we process your personal data; (iv) whether we can achieve those purposes through other means; and (v) the applicable legal, regulatory, tax, accounting, or other requirements. Following the end of the of the relevant retention period, we will delete or anonymise your personal data.
  2. Following the end of our engagement we will retain your personal data:
    1. to enable us to respond to any queries, complaints or claims made by you or on your behalf; and
    2. to the extent permitted for legal, regulatory, fraud and other financial crime prevention and legitimate business purposes.
  3. After this period, when it is no longer necessary to retain your personal data, we will securely delete or anonymise it in accordance with our Data Retention Policy. Further details regarding our data retention policy can be obtained from our Privacy Manager using the details set out under Contacting Us above.

17.COMPLAINTS

  1. If you have any questions or concerns regarding our Privacy Policy or practices, please contact our Privacy Manager as provided in “Contacting Us” above. We hope we will be able to resolve any issues you may have.
  2. You also have the right to make a complaint at any time to the UK Information Commissioner’s Office who can be contacted using the details at https://ico.org.uk/make-a-complaint or by telephone on 0303 123 1113.

18.CHANGES TO THIS POLICY

  1. We may change this Policy from time to time.  The current version of this Policy will always be available from us in hard copy or on our website. If we make any material changes to this Policy, we may notify you by email or update you by other appropriate means.

This Policy was last updated on 08 September 2023.