Client Privacy Notice
At Cragside Financial Solutions, we respect your privacy and the confidentiality of your personal information.
This notice sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
This Privacy Notice explains:
- Who we are
- Your rights
- What personal information we collect
- How we use your personal information
- Who we share your information with and why
- How we keep your information secure
- How to manage your marketing consents; and
- How to contact us
In this document, “We” and “Us” refers to John Gilfillan, trading as Cragside Financial Solutions, a trading style of Blueprint Financial Solutions Limited, Quilter Financial Planning and its subsidiary companies.
Who we are
At Cragside Financial Solutions, a trading style of Blueprint Financial Solutions Limited we respect your privacy and the confidentiality of your personal information.
John Gilfillan, trading as Cragside Financial Solutions, a trading style of Blueprint Financial Solutions Limited is an appointed representative of Quilter Financial Services Limited and Quilter Mortgage Planning Limited.
John Gilfillan, trading as Cragside Financial Solutions, a trading style of Blueprint Financial Solutions Limited provide financial planning solutions and advice through experienced and qualified advisers based in the UK.
Currently, Blueprint Financial Solutions Limited and Quilter Financial Planning (Quilter) jointly determine the purposes and means of processing personal client data relating to giving advice. This means we’re joint data controllers for these core advice giving activities and therefore responsible for managing this client data and ensuring compliance.
However, Blueprint Financial Solutions Limited is solely responsible for some activities, for example any direct marketing that we undertake.
We will comply with relevant data protection law. Such laws require that the personal information we hold about you must be:
- Used lawfully, fairly and in a transparent way;
- Collected only for valid purposes that we have clearly explained to you;
- Relevant to the purposes we have told you about and limited only to those purposes;
- Accurate and kept up to date;
- Kept only as long as necessary for the purposes we have told you about; and
- Kept securely.
Your rights
We try to be as open as it can be in terms of giving people access to their personal information and therefore have outlined your rights below:
You have the right to ask us:
- whether we are processing your personal information and the purposes (the right to be informed) – this is delivered through ‘fair processing information’ such as this Privacy Notice;
- for a copy of the personal information that we hold about you (the right of access);
- to update or correct your personal information (the right to rectification);
- to delete your information (the right to erasure); and
- to restrict processing of your personal information where appropriate (the right to restrict processing).
In certain circumstances you also have the right to:
- object to the processing of your personal information (the right to object);
- object to automated decision making and profiling (the right not to be subject to automated decision-making including profiling); and
- request that information about you is provided to a third party in a commonly used, machine readable form (the right to data portability).
Exercising your rights
For information about your individual rights, including how to correct, restrict, delete, make changes to your personal information or if you wish to request a copy of the personal information we hold about you, please contact us by emailing us at .
More information about your data protection rights can be found on the Information Commissioner’s Office (ICO) website.as well as on other regulators’ websites.
If you would like to write to us, our postal address for data protection matters is:
The Office of Data Protection
Quilter Financial Planning
Senator House
85 Queen Victoria Street
London
EC4V 4AB
However, we have adopted a flexible model for working so please note that written communications will take longer to respond to.
Further information
This privacy notice was drafted with brevity and clarity in mind, however further information can be obtained by contacting us using the details in the “How to contact us” section. More information about your data protection rights can be found via:
- UK Information Commissioner’s Office (ICO)
What personal data we collect
We process your information for the following purposes.
- To perform our contract with you and to support and maintain that relationship.
- This includes the following: assessing and processing an application for our services;
- providing our products and/or services to you, including the management of our relationship with you, your firm;
- carrying out transactions you have requested or on your behalf;
- monitoring or recording communications (such as telephone and video calls) with you to resolve any queries or issues and also for training and quality purposes and, in some cases to comply with regulatory requirements;
- assessing your application for products (using automated decision-making tools when necessary);
- ensuring that a firms operation meets our expectations, and those of our regulators (such as undertaking audits and investigations into network activity);
- record keeping in order to ensure our products and/or services operate within the law and relevant regulatory requirements;
- providing other services (e.g. enhanced due diligence, underwriting, reinsurance, data hosting, online services, and payments or reporting of any tax or levy).
- To comply with legal and regulatory requirements. These requirements include the following:
- confirming your identity for security and regulatory purposes;
- detecting and preventing fraud, money laundering, terrorist financing, bribery or other malpractice;
- to meet tax reporting obligations such as Common Reporting Standards (CRS) and the US Foreign Account Tax Compliance Act (FATCA); and
- to fulfil our data protection obligations.
- For specific business purposes to enable us to provide you with appropriate products and services and a secure experience. Our business purposes include the following:
- verifying your identity for security purposes;
- sending marketing communications to you which you have opted into receiving, or which are related to similar products or services, or which we think may interest you based on the relationship you have with Us or other companies in our group;
- enhancing, modifying and personalising our services for your benefit;
- to undertake Profiling activities;
- providing communications which we think will be of relevance or interest to you;
- audit and record keeping purposes;
- enhancing the security of our network and information systems;
- maintaining effective management systems including internal reporting to our parent company and other members of our corporate group;
- ensuring the integrity of our systems (for example, during final stages of testing where it is necessary to use real data to ensure that any system improvements do not interrupt business or corrupt the data);
- providing reports and other communications to you where we are required to do so; and
- customer satisfaction research, statistical analysis and wider market research to capture the views and opinions of our customers.
We may also process your personal data as part of an acquisition or sale. Should this happen, you’ll be notified about any change to processing or data controller arising as a result of this activity.
You have the right to object to us processing your personal information for some of the business purposes listed above but, if you do so, this may impact on our ability to provide some or all of our services to you.
We won’t process your employee’s data for the business purposes above. Our contractual relationship is with you and therefore any processing of data for business purposes will be undertaken with your data, not your employee’s.
Profiling
Profiling involves the use of basic identifiers about you such as your name and address and matching this with information from Experian Marketing Services to create demographics and infer customer ‘types’. This helps us define groups based on factors like interests, age, location and more so we can better understand our customers to adapt and improve our products and services. If you would like to know more about the information we get from Experian Marketing Services, you can visit their Consumer Information Portal which explains who Experian Marketing Services are, what they do and why.
Lawful basis
We operate under a number of legal bases as required under the regulations. These include:
- Consent;
- Legitimate Interests;
- Performance of a Contract; and
- Compliance with a Legal Obligation.
How we use your personal information
We process your information in order to support and maintain our contractual relationship with you and to comply with legal and regulatory requirements. This includes the following:
- Providing our advice, products or services to you
- Carrying out transactions you have requested
- Confirming and verifying your identity for security purposes
- Credit scoring and assessment, and credit management (where applicable)
- Detecting and preventing fraud, crime, money laundering or other malpractice.
- To investigate any complaint or enquiry raised in regards to your adviser or the advice given
We also process your data for specific business purposes to enable us to give you the best products and services and the best and most secure experience. For example, we process your information to send you marketing that is tailored to your interests.
Our business purposes include the following:
- Enhancing, modifying, and personalising our services for the benefit of our customers
- Providing communications which we think will be of interest to you
- Market or customer satisfaction research or statistical analysis
- Audit and record keeping purposes
- Enhancing the security of our network and information systems.
- Supporting the testing and maintenance of systems
You have the right to object to this processing if you wish, please see “Your Rights” section below. Please bear in mind that if you object this may affect our ability to carry out the tasks above for your benefit.
We may also process your personal data as part of an acquisition or sale. Should this happen, you will be notified about any change to processing or data controller arising as a result of this activity.
Who we share your information with and why
We share your information with trusted third parties and service providers who perform tasks for us and help us to provide our products and/or services to you, and with other agencies where required by law, court order or regulation. These may include:
- Companies within the Quilter Plc Group
- for administrative, analytical and statistical purposes;
- for testing the information systems operated by our companies
- for producing a consolidated view of our relationship with you in order to meet our regulatory obligations and to enhance the services we can offer you.
- for handling complaints and fulfilling data subjects’ rights (such as the Right of Access)
- Companies appointed by Us (these third parties may be based in countries outside the UK or EU)
- with third parties or service providers who perform tasks for us to help us provide our services to you or to allow us to meet legal and regulatory requirements, including any necessary tax reporting, verifying your identity, source of wealth financial crime prevention or other requirements (this may involve carrying out checks with credit reference databases);
- with third parties or service providers who provide additional data about you in order to enhance our ability to design and develop new products and services that can be marketed and sold which meet the needs of our identified consumer groups and are targeted accordingly;
- with credit reference agencies to check the financial suitability of the products and services;
- with debt collection agencies for tracing and recovery of debts;
- with payment service providers to allow payments to be completed;
- with our accountants to produce tax statements and in support of statutory reporting;
- with our appointed legal or regulatory advisers or auditors;
- with information technology and information security providers;
- with a prospective buyer (or its advisors), for due diligence purposes, if we are considering a sale of any of our business or assets;
- with third parties or service providers to conduct market research on our behalf, to help us improve and develop the products and services we provide to you and our other customers;
- with third parties or service providers to conduct quality checks on the interactions between us, Quilter and you; and
- with any successor to all or part of our business. For example, in the event of a merger, acquisition, divestiture, change of control or liquidation of Cragside Financial Solutions, a trading style of Blueprint Financial Solutions Limited or part of its business (or in anticipation of such an event), we may share your personal data as part of that transaction where required in order to fulfil our obligations in this Notice.
- Organisations and parties appointed by you or authorised by you
- with third parties where you have given your consent to receive marketing information;
- with your accountants to produce tax statements and in support of statutory reporting
- with an appointed discretionary asset manager or custodian to meet their legal or regulatory requirements; and
- with third parties or service providers who ask for that information in order to allow us to make investments on your behalf or to continue to provide our services to you.
- Statutory authorities
- with organisations, including the police authorities and fraud prevention agencies, to prevent and detect fraud;
- with regulatory or governmental agencies such as the UK Financial Conduct Authority, UK Information Commissioner’s Office and HM Revenue and Customs;
- with professional bodies; and
- with other agencies where required by law, court order or regulation.
If you would like further information regarding the specific named recipients that we share data with, please contact us using the information in the “How to contact us” section.
How we keep your information secure
We’re committed to ensuring the confidentiality of the personal information that we hold, and we continue to review our security controls and related policies and procedures to ensure that your personal information remains secure.
When we contract with third parties, we impose appropriate security, privacy and confidentiality obligations on them to ensure that personal information is kept secure and prevented from unauthorised or accidental access, processing, copying, modification, erasure, loss or use.
If we work with third parties in countries outside the United Kingdom, we ensure these are countries that the UK Government and the European Commission has confirmed have an adequate level of protection for personal information, or the organisation receiving the personal data has provided adequate safeguards and agrees to treat your information with the same level of protection as we would.
We also utilise UK International Data Transfer Agreements and EU Standard Contractual Clauses for transfers outside of the United Kingdom or European Economic Area.
In limited circumstances, data may be accessed outside of the UK i.e. by employees when they travel. In these circumstances, we ensure there are appropriate information security measures in place to safeguard your information.
How To Manage Your Marketing Consents
You may give and withdraw consent to the receipt of marketing information at any time. If you wish to change your preferences regarding the receipt of marketing or other communications from us, the simplest way is to use the ‘unsubscribe’ link at the bottom of any marketing communication.
Alternatively, you can contact us using any of the mechanisms included in the ‘How to contact us” section of this notice.
How to contact us
If you have questions about this notice, or need further information about our privacy practices, or wish to raise a complaint about how we have handled your personal data, you can contact our Data Protection team who will investigate the matter.
The Office of Data Protection
Quilter Financial Planning Limited
Senator House
85 Queen Victoria Street
London EC4V 4AB