Date of last update: 3 July 2018
This Privacy Notice explains in detail the types of personal data we may collect about you when you interact with us. It also explains how we’ll store, handle and keep it safe. Please read it carefully: it’s important.
We hope the following sections answer any questions you have but if not, please do get in touch.
It’s likely that we’ll need to update this Privacy Notice from time to time – you can check the date last updated at the top of the page.
1. WHO ARE WE?
We are Wealth Club Limited and Clubfinance Limited. Clubfinance is a wholly owned subsidiary of Wealth Club, but both are separate companies, each registered as a data controller in its own right. In this policy, “we”, “our” or “us” means Wealth Club Limited and Clubfinance Limited.
The legal information for each entity is:
- Wealth Club Limited, website at www.wealthclub.co.uk, registered in England and Wales under company number 09831162, registered office 4 Broad Plain, Bristol, BS2 0JP. Registered with the Information Commissioner’s office under register number ZA161531.
- Clubfinance Limited, website at www.clubfinance.co.uk, registered in England and Wales under company number 04522114, registered office 4 Broad Plain, Bristol BS2 0JP. Registered with the Information Commissioner’s office under register number Z8811711.
2. UNDER GDPR, WHICH LEGAL BASES DO WE RELY ON?
From 25 May 2018 the way your personal data is collected, used and stored is governed by the GDPR, which stands for General Data Protection Regulation.
The GDPR sets out a number of different and equally valid legal bases a company might rely on to collect and process your personal data. These include:
In certain circumstances, we need your personal data to enter into, or perform, a contract with you.
For example, if you wish to invest, we will need your personal data to process your application form, and to administer and keep you updated on the investment. If you didn’t provide that data, we wouldn’t be able to process your application.
We may need to collect and process your data for legal or regulatory reasons.
For example, if you wish to invest, we may use your data to check your identity with a credit reference agency to comply with anti-money laundering rules.
We may use your data to pursue our legitimate interests, providing we do this in a way which might reasonably be expected as part of running our business and which does not materially impact your rights, freedom or interests.
For example, we will use your name and contact details to fulfil your Wealth Club membership by giving you access to investment research and sending you details of relevant offers, deals, updates and news by post and by email.
When we process your personal information for our legitimate interests, we make sure to consider and balance any potential impact on you (both positive and negative), and your rights under data protection laws.
3. DO YOU NEED TO CONFIRM YOUR CONSENT TO CONTINUE HEARING FROM US?
In the run up to 25 May 2018, the date from which the GDPR is effective, you will have probably received a flurry of emails from companies you’ve had some kind of dealings with, to check you’re happy to carry on receiving their emails. In technical terms, these companies are seeking your ‘consent’.
GDPR identifies ‘consent’ as one of the legal bases on which a company can rely to collect and process your personal data. However, it’s not the only legal basis – GDPR identifies six in total. Depending on the nature of the company and its relationship with you, a legal basis other than consent might be deemed more appropriate.
As explained above, Wealth Club collects and processes your personal data using the following legal bases, which are also valid:
- Contractual obligations
- Legal obligation
- Legitimate interest
In practice, this means there is no need for you to confirm your consent to continue receiving communications from us, including emails about products and services similar to those you have bought or requested information on, as we believe there is a legitimate interest here to fulfil your membership of Wealth Club. You can, however, choose how we use your personal information to communicate with you. Read more in the section ‘your choices over how we use your information’.
4. WHAT IS THE WEALTH CLUB MEMBERSHIP?
When you request information from us, e.g. when you download a guide or document or express an interest in an investment opportunity, you also receive complimentary membership of Wealth Club.
Membership benefits include:
- Access to exclusive deals
- Access to investment reports and information
- Preferential terms on some investments
- Investment news and alerts
- Access to free financial guides
There are no costs or obligations attached to your membership.
You can stop or cancel it at any time, or request to receive only certain benefits but not others. You can manage your preferences online – see “Your choices over how we use your information”.
5. WHEN DO WE COLLECT YOUR DATA?
We will collect your data:
- When you apply to invest through us
- When you visit our websites and download guides, application forms, reports, or other documents or express an interest in a specific investment
- When you request information from us by email, phone or post
- When you contact us by any means about questions, complaints, etc.
- When you respond to any survey we invite you to complete
- When you visit our offices (we have CCTV in operation)
- When you respond to any advert we issue – either online or offline
6. WHAT KIND OF DATA DO WE COLLECT?
- When you request information from us we may collect your name, address, details of the investments or types of investments you are interested in, email address and telephone number.
- We will record whether you are a high net worth individual or sophisticated investor (the Financial Conduct Authority (FCA) requires us to do this before we can provide further information on certain investments).
- We may also ask you for evidence of your investment knowledge and experience, to allow you to access certain kinds of deals.
- We may ask you what interests you, so we can send you more relevant information.
- When you invest, we will collect further personal details such as date of birth, nationality, National Insurance Number and gender (as per providers’ requirements on their application forms), alongside financial details.
- We’ll also use your information to prevent fraud and money laundering by running an online check with a credit reference agency, and to meet our regulatory obligations.
- We will keep a record of your transaction
- When you contact us or we contact you, we record telephone conversations and emails for the purposes of administering your account, training, demonstrating compliance with regulatory requirements, providing evidence in the event of a dispute or in court.
- If you visit our office, your image may be recorded on CCTV.
In limited circumstances we may collect sensitive information. For instance, if you apply to invest in an IHT portfolio which includes an insurance element, we may need to ask information about your health, but only after asking for your explicit consent.
7. HOW AND FOR WHAT PURPOSE DO WE USE YOUR DATA?
- If you ask a question or request information through any medium – online, by telephone or offline – we will use your data to provide a response. We will keep a record of the communication to inform any future exchanges and demonstrate how we communicated with you throughout. We do this on the basis of our contractual obligations to you, our legal obligations and our legitimate interests in providing the best service and understanding how we can improve our service based on your experience.
- If you give us your telephone number we might occasionally call you, for instance, to share time-sensitive information, to update you about current opportunities or in case of problems with your application. We do this on the basis of our legitimate interests in providing the best service and understanding how we can improve our service based on your experience.
- If you invest, we will process your personal details and the financial information you give in the application forms. We will process and keep these records under our legal obligations. We will also send the details you give us, via the application form, to the company that provides the product or service you require.
- We’ll use your data to protect our business and your investment from fraud and money laundering. This includes carrying out anti-money laundering checks. We’ll do all of this as part of legal obligations and legitimate interest.
- We will notify you about changes to our services or terms and conditions, as part of our legal obligations.
- We will use your details and your transactions to respond to any complaints you might make. This is part of our legal obligations.
- We protect our premises, visitors and staff by operating CCTV at our offices which records images for security. We do this on the basis of our legitimate interest.
- We will send you relevant, personalised communications on deals, offers, services and products for high net worth and sophisticated individuals, to fulfil the benefits of your membership of Wealth Club. We’ll do this on the basis of our legitimate interest.
- We will identify you when you visit our website, based on our legitimate interest and to make your web journey easier (for instance, so you don’t have to keep confirming you are a high net worth or sophisticated investor).
- We may also collect information about your visit to our website as this helps us optimise and improve it. However, none of this information will directly identify you. This is on the basis of our legitimate interest in generating insights that will help us operate our business.
8. HOW DO WE PROTECT AND STORE YOUR INFORMATION?
Your information will only be used for the purposes we collected it for (or a closely related purpose, such as record keeping).
We employ a variety of physical and technical measures to keep your personal data safe and prevent unauthorised access to it. Your data is stored on secure computer systems and we control who has access to them (using both physical and electronic means).
We have a data retention policy in place that should ensure we keep data only for as long as is required. For instance, FCA rules require us to keep client records, transaction details and copies of telephone calls for at least five years, whereas CCTV footage is deleted after 30 days.
9. SHARING YOUR INFORMATION
We will never sell or trade your personal information. We will share information with our suppliers and data processors and this may include your personal information, but they will only be allowed to use it for a specific purpose and there will be a written agreement which makes sure your information is protected.
For example, when we write our newsletter we use the services of a third-party mailing house to pack and post the communication to you.
We will share personal information with the investment companies in whose products you choose to invest, by sending them your completed application form. Please note, when you apply for an investment, you will also become a client of that provider and will be subject to their Privacy Notice, as well as ours. You should check the relevant privacy notice for your chosen provider(s).
We will also share your information when we are required to do so by law or by a regulator or governmental authority (for example HMRC or the FCA).
Some of our suppliers and data processors may be outside the EEA – see the section “international transfers” for details.
We currently use the following subcontractors to process your personal data and have agreements with them to govern how they may use the data:
- Amazon Web Services (AWS) – the Wealth Club database is hosted on a secure AWS server, based in Dublin.
- Cloudflare – to protect our business and our website users from denial of service attacks and to protect us from hacking attempts.
- Cognito Forms – to allow users to express interest in and make reservations for investments, or complete surveys on our website.
- Data Driven Promotions – one of the mailing houses we use to send out our newsletters and updates.
- Lexis Nexis – the credit agency we use to perform anti-money laundering checks.
- MailChimp – the email service we use to send and manage emails.
- Mailing Guy – one of the mailing houses we use to send out our newsletters and updates.
- Sumo – to provide our 'ask a question' prompts on our website.
- SurveyMonkey – to carry out surveys.
- Tawk – to provide real-time assistance and online chat to investors completing an electronic product application.
- Textlocal – to send SMS notification codes to help users log in.
- Trustpilot – to send review invitations to allow investors to review our service.
- Xero – our accounting software.
- Zapier – to create connections between other applications, for instance between Cognito Forms and MailChimp.
We also use the services of Google Analytics to see how users interact with and use our website. The data is anonymous and cannot be used to identify you.
If in future the ownership of Wealth Club or Clubfinance changes then your data may be shared with the new owners.
10. COOKIES AND SIMILAR TECHNOLOGIES
11. YOUR RIGHTS
You have the right to request:
- Access to the personal data we hold about you, free of charge in most cases.
- The correction of your personal data when incorrect, out of date or incomplete.
- That we stop using your personal data for direct marketing (either through specific channels, or all channels). We must always comply with your request.
- In certain situations, you have the right to request that your data be deleted (the right to be forgotten).
If you would like further information on your rights or wish to exercise them, please write to us or email [email protected] with details of your request.
If we decline to satisfy your request we will explain why.
If you believe that any information we hold on you is incorrect or incomplete, please contact us.
Your right to withdraw consent
Whenever you have given us your consent to use your personal data, you have the right to change your mind at any time and withdraw that consent. We occasionally rely on consent, for instance, if you provide health details as part of an insurance policy for IHT portfolios.
Where we rely on our legitimate interest
In most cases, where we process your personal data on the basis of our legitimate interest, you can ask us to stop (your right to object). We must then do so unless we believe we have a legitimate overriding reason to continue processing your personal data.
Checking your identity
To protect the confidentiality of your information, we will ask you to verify your identity before proceeding with any request you make under this Privacy Notice.
Please keep in mind there are exceptions to the rights above and, though we will always try to respond to your satisfaction, there may be situations where we are unable to do so (for example, if the information no longer exists or there is an exception which applies to your request).
12. YOUR CHOICES OVER HOW WE USE YOUR INFORMATION
You have choices about how we use your personal information to communicate with you and how we fulfil your membership of Wealth Club.
You can change how we contact you, how often and about what. You can pause or cancel your membership as well as tell us what you’d like to hear about.
You can set and change your preferences at any time and as often as you like by contacting us. You can also object to us processing your data.
Please note: if you cancel your Wealth Club membership you will stop receiving offers and deals from us, but if you’ve invested we will still send you information about your investments (as this is a contractual obligation).
13. INTERNATIONAL TRANSFERS
Except as set out below, we normally only store personal information within the European Economic Area (EEA). The EEA includes all EU Member countries as well as Iceland, Liechtenstein and Norway.
If one of our suppliers or subcontractors needs to transfer personal information of Wealth Club members outside the EEA we will take steps to make sure adequate levels of privacy protection, in line with UK data protection law, are in place. These safeguards will usually be contractual and/or the result of a European Union adequacy decision which allows the transfer (for example, a US organisation which is certified under the EU-US Privacy Shield Framework), meaning it has taken steps to ensure your information is adequately protected. You can read more on the EU-US Privacy Shield Framework online.
Please contact us if you wish to receive further details of the safeguards in place to protect your data using international organisations.
Suppliers we use based outside the EEA include:
- Cognito Forms – based in the USA, certified under the EU-US Privacy Shield Scheme.
- MailChimp – based in the USA. MailChimp’s owner (the Rocket Science Group LLC) is certified under the EU-US Privacy Shield Scheme.
- SurveyMonkey – based in the USA, certified under the EU-US Privacy Shield Scheme.
- Sumo – based in the USA, certified under the EU-US Privacy Shield Scheme.
- Tawk – based in the USA, certified under the EU-US Privacy Shield Scheme.
- Xero – based in New Zealand. Xero rely on a combination of measures to ensure compliance with EU data rules, including Model Clauses.
- Zapier – based in the USA, certified under the EU-US Privacy Shield Scheme.
14. CONTACTING THE REGULATOR
If you believe your data protection or privacy rights have been infringed, or are not happy with how we have treated your data and your rights, you should contact the UK Information Commissioner’s Office, the UK regulator for data protection. Details of how to do this can be found at www.ico.org.uk.
15. UPDATES TO THIS NOTICE
We may update this Notice at any time. When we do, we will revise the date at the top of this page. We encourage users to frequently check this page for any changes to stay informed about how we are helping protect the personal information we collect.
16. HOW TO CONTACT US
You can contact us about data protection at 4 Broad Plain, Bristol BS2 0JP, by email to [email protected] and by phone on 0117 929 0511.