"We", "our" or "us" means Winterflood Securities Limited and its subsidiaries. For the purposes of data protection law, we are a controller in respect of your personal data. We collect and use your personal data as described below. We are responsible for ensuring that we use your personal data in compliance with data protection law.
For the purpose of this privacy notice, the terms ‘controller’, ‘process’ and ‘personal data’ shall have the meaning given in Regulation (EU) 2016/679 (GDPR).
If you have any questions about this notice, about how we process personal data or about your rights over your personal data, you can contact us via email to email@example.com in the first instance. Alternatively, our Data Protection Officer can be contacted using the details set out in the “Contact us” section below.
This notice applies to personal data we receive or otherwise create in connection with the provision of services to professional clients / eligible counterparties and their personnel, including any associated services provided via our website(s) at:
It is important that you take the time to read this notice so that you understand how we will use your personal data and your rights in relation to your personal data.
Personal data that we collect about you
We will collect and use the following information about you:
Information you give us
- We use the information about you that you provide to us, including the information that you provide when filling in fields in a contract (or related application) or when registering to use sections of our website(s) (such as your name, address, e-mail address, phone number, job title, your preferences for receiving email communications from us) and any other information or updates to your information that you provide to us when corresponding with us (by phone, e-mail or otherwise).
Informaton we collect or generate about you
- When you submit information to us, we may use this information to interact with, and provide services to, you (or your employer), and to carry out our obligations arising under or in connection with a contract.
- We may also receive information from other sources for the above purposes.
- We may record, monitor and retain any and all communications (which may include the recording and monitoring by a third party appointed by us), including facsimilie, email and other electronic messaging, telephone conversations and other electronic communications with you, for the purposes of providing services to you (or to your employer) and/or otherwise in order to comply with applicable law.
- We generate data for internal analysis and research.
If we do not receive this information we may not be able to provide certain services to you.
How we use your personal data
Your personal data may be processed by us for the following purposes:
- to provide you with services you request (or services requested by your employer) or other services reasonably ancillary thereto, and to carry out our obligations arising under or in connection with a contract;
- to administer and maintain user access to our services and/or websites;
- to communicate with you in relation to the services we provide to you (or to your employer);
- to comply with our obligations under applicable law;
- to monitor and improve our websites and services; and/or
- for internal analysis and research.
Legal basis for processing your personal data
We process your personal data pursuant to the following legal bases:
(i) where necessary to comply with a legal obligation (for example anti-money laundering, know-your-customer and counter-terrorist financing checks and the prevention and detection of fraud and other financial crime);
(ii) where necessary for the purpose of our legitimate business interests which includes:
- the provision of services to you (or your employer), the sending and receipt of communications in relation thereto and/or carrying out obligations arising in connection with a contract;
- compliance with legal and regulatory obligations (including applicable laws, rules and regulations outside of the United Kingdom and requests or requirements of competent authorities);
- contacting you with email updates in relation to services;
- generating data for internal analysis and research (including monitoring and improving our websites and services);
- marketing Winterflood’s products and services, including event invitations and the sending of branded merchandise; and
- keeping a record of what individuals are interested in hearing about from us; or
(iii) where you have separately consented for us to use your personal data to send you specific email updates and communications (by opting-in to such email updates/ communications).
You have the right to object to processing under (ii) by contacting us using the details set out in the “Contact us” section below, and you may cancel your subscription under (iii), at any time by using the ‘unsubscribe’ link within the communications you receive from us or by emailing us at firstname.lastname@example.org and requesting the same.
Please note that any instruction to unsubscribe from communications will not affect any processing pursuant to (i) in relation to compliance with a legal obligation.
Sharing your personal data
We may disclose your personal data to our affiliates (being any subsidiary undertaking or parent undertaking, or a subsidiary of any parent undertaking of Winterflood Securities Limited, as the same terms are defined in the Companies Act 2006) and to third party service providers in the circumstances described below:
- in relation to our legitimate business interests (as above);
- to facilitate the administration and maintenance of user access to our services and/or websites;
- to conduct and/or improve our business development activities; and
- to ensure the safety and security of our data (and that of third parties, including data vendors and other data sources).
We will take steps to ensure that the personal data is accessed only by persons that have a need to do so for the purposes described in this notice.
We may also share your personal data with third parties:
- if we sell any of our business or assets, in which case we may disclose your personal data to the prospective buyer for due diligence purposes;
- if we are acquired by a third party, in which case personal data held by us about you will be disclosed to the third party buyer;
- to third party agents or contractors (for example, the providers of our electronic data storage services) for the purposes of providing services to us; and
- with your consent, to our affiliates who may wish to offer you products and services which may be of interest to you.
These third parties will be subject to confidentiality requirements and they will only use your personal data as described in this notice.
We may also share your personal data with third parties (including, without limitation, regulatory, governmental, judicial and other bodies or authorities of competent jurisdiction) to the extent required by applicable law, for example if we are under a duty to disclose your personal data in order to comply with any legal or regulatory obligation, and to establish, exercise or defend our legal rights.
Transfer of personal data outside the European Economic Area
The information you provide to us will be transferred to and stored on our secure servers in the European Economic Area (“EEA”). However, from time to time, your personal data may be transferred to, stored in, or accessed from a destination outside the EEA. It may also be processed by staff operating outside of the EEA who work for us or an affiliate or for one of our suppliers.
Where we transfer your personal data outside the EEA, we will ensure that it is protected in a manner that is consistent with how your personal data will be protected by us in the EEA. This can be done in a number of ways, for instance:
- the country that we send the data to might be approved by the European Commission or a relevant data protection authority (as offering equivalent protections to those afforded in the EEA);
- the recipient might have signed up to a contract based on “model contractual clauses” approved by the European Commission, obliging them to protect your personal data;
- where the recipient is located in the US, it might be a certified member of the EU-US Privacy Shield scheme; or
- in other circumstances where the law permits us to otherwise transfer your personal data outside the EEA.
In all cases, however, we will ensure that any transfer of your personal data is compliant with data protection law.
You can obtain more details of the protection given to your personal data when it is transferred outside the EEA (including a copy of the standard data protection clauses which we have entered into with recipients of your personal data) by contacting us in accordance with the “Contact us” section below.
How long we keep your personal data
How long we hold your personal data for will vary. The retention period will be determined by various criteria including:
- the purpose for which we are using it – we will need to keep the data for as long as is necessary for that purpose (for example, to communicate with you in respect of our services for so long as you (or your employer) remain a recipient of such services); and/or
- legal and regulatory obligations – applicable laws, rules or regulations may set a minimum period for which we have to store your personal data.
You have a number of rights in relation to the personal data that we hold about you. These rights include:
- the right to object to our processing of your personal data where we process your personal data pursuant to our legitimate business interests. Please note that there may be circumstances where you object to our processing of your personal data but we are legally entitled to refuse that request;
- the right to obtain information regarding the processing of your personal data and access to the personal data which we hold about you;
- the right to withdraw your consent to our processing of your personal data at any time. Please note, however, that we may still be entitled to process your personal data if we have another legitimate reason (other than consent) for doing so;
- in some circumstances, the right to receive some personal data in a structured, commonly used and machine-readable format and/or request that we transmit such data to a third party where this is technically feasible. Please note that this right only applies to personal data which you have provided to us;
- the right to request that we rectify your personal data if it is inaccurate or incomplete;
- the right to request that we erase your personal data in certain circumstances. Please note that there may be circumstances where you ask us to erase your personal data but we are legally entitled to retain it;
- the right to request that we restrict our processing of your personal data in certain circumstances. Please note that there may be circumstances where you ask us to restrict our processing of your personal data but we are legally entitled to refuse that request;
- the right to object to the processing of your personal data for direct marketing purposes; and
- the right to lodge a complaint with the data protection regulator (details of which are provided below) if you think that any of your rights have been infringed by us.
You can exercise your rights by contacting us using the details set out in the “Contact us” section below. You can find out more information about your rights by contacting the data protection regulator, the Information Commissioner, or by visiting their website at https://ico.org.uk/.
Changes to this Privacy Notice
We keep this notice under regular review. Any changes we make to this notice in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to this notice.
Winterflood Securities Limited is a company registered in England and Wales. Our registered address is at The Atrium Building, Cannon Bridge House, 25 Dowgate Hill, London, EC4R 2GA and our company registration number is 02242204.
Please contact us if you have any questions about this notice or personal data that we may hold about you:
You can write to us at: Data Protection Team, Winterflood Securities Limited, The Atrium Building, Cannon Bridge House, 25 Dowgate Hill, London, EC4R 2GA.
By telephone: 0203 100 0000; or
By email: email@example.com
You can also contact our Data Protection Officer using the following details:
By post: Data Protection, Close Brothers, 10 Crown Place, London EC2A 4FT;
By telephone: 0333 321 6100; or
By email: firstname.lastname@example.org