Privacy Policy
How Aurora Finspire collects, uses, stores and shares your personal data, and how you can control it. This policy applies to visitors to this website and to account holders in the United Kingdom, and it is written to meet UK GDPR and the Data Protection Act 2018.
1. Key terms
Personal data means any information that identifies you or can be linked to you, such as your name, email address or phone number. Usage data is information collected automatically when you use the site, such as your device type, pages viewed and time spent. Cookies are small files stored on your device that help a site work and remember settings. The controller is the organisation that decides why and how personal data is used. For this website, the controller is Aurora Finspire, and any service provider that handles data on our instructions is a processor.
2. What we collect and why
When you register or contact us we collect your first name, last name, email address, mobile number and the content of your message or request. If you go on to verify your account we also collect identity and address documents, as described in our KYC and AML policy.
We use this information to answer enquiries, to open and run your account, to let your personal manager contact you, to meet our legal duties, to keep the platform secure and to improve our services through analysis of how they are used.
3. Legal bases
We rely on different legal bases under UK GDPR. Contract: we need your details to provide the service you asked for. Legal obligation: we must verify identity and keep records under anti-money-laundering law. Legitimate interests: we protect the platform from fraud and misuse and analyse how it is used, after weighing this against your rights. Consent: we ask separately before sending marketing messages and you may withdraw it at any time.
4. Usage data and cookies
The site records technical information such as your IP address, browser, pages visited and the date and time of visits. Essential cookies keep forms and security features working. Analytics cookies are only set if analytics is switched on for the site and you can refuse them in your browser settings or in the notice shown on your first visit.
5. How long we keep data
Enquiry details are kept for up to two years after our last contact. Account and verification records are kept for five years after the relationship ends, which is the period anti-money-laundering rules require. Technical logs are kept for up to twelve months. When a period ends we delete the data or anonymise it so that it can no longer identify you.
6. Who we share data with
We share personal data only where needed: with the licensed or regulated entity that holds your trading relationship, with affiliated companies, with technology and hosting providers, with identity-verification and payment providers, and with regulators, law enforcement and other authorities where the law requires. We do not sell your personal data.
7. Transfers outside the UK
Some providers work from outside the United Kingdom. When data is sent abroad we use a safeguard approved under UK law, such as an adequacy decision or the International Data Transfer Agreement or addendum, so that your information receives equivalent protection.
8. Disclosure
We may disclose data if a court, regulator or law enforcement body lawfully requires it, to protect our rights or the safety of others, or in connection with a business reorganisation, in which case the new owner must honour this policy.
9. Security
Data is encrypted in transit and at rest, access is limited to staff who need it and activity is logged. No system is perfectly secure, so we also tell you how to protect your account on the Security page. If a breach puts your rights at risk we will inform you and the Information Commissioner's Office as the law requires.
10. Your rights
You may ask us for a copy of your data, ask us to correct it, ask us to erase it, ask us to restrict how we use it, object to certain uses and, where applicable, receive it in a portable format. You can withdraw consent to marketing whenever you like. Write to [email protected]. We reply within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office.
11. Service providers
We use carefully chosen providers for hosting, email delivery, customer support tools, identity checks and payment processing. Each is bound by a written contract to use data only on our instructions and to protect it.
12. Analytics
Where enabled, analytics tools tell us which pages are read, where visitors come from and which parts of a form cause difficulty. We use the results to improve the site, not to build profiles that decide anything about you.
13. Advertising and retargeting
If we use advertising tools, they may set cookies that recognise your browser so that we can measure campaigns and show relevant adverts elsewhere. You can opt out through your browser settings or the controls offered by advertising networks, and doing so will not affect your use of the platform.
14. Links to other websites
Our site links to exchanges, regulators and other third parties. We do not control their sites and are not responsible for their privacy practices, so please read their policies before sharing information.
15. Children
Our services are for people aged 18 and over. We do not knowingly collect data from children, and if we learn that we have, we will delete it promptly.
16. Changes to this policy
We may update this policy as our services or the law change. The new version takes effect when published on this page, and we will tell registered users about material changes by email.
17. Contact us
For any privacy question, write to Aurora Finspire, 42 Bishopsgate, London EC2N 4AH, United Kingdom, or email [email protected].