Data protection
Data Privacy Notice
Version: 2.04
Introduction
We take your privacy very seriously and we ask that you read this privacy notice carefully as it contains important information on who we are, how and why we collect, store, use and share personal data, your rights in relation to your personal data and on how to contact us and supervisory authorities in the event you have a complaint.
Words shown in the Glossary of Terms at the end of this document have the meaning set out there.
Most of this notice describes how we handle personal data about our clients. If you have visited our website or contacted us but are not a client, the section headed “Visiting our website and contacting us” sets out what applies to you.
Who we are
Long Row Wealth Advisory Ltd collects, uses and is responsible for certain personal data about you. When we do so we are required to comply with data protection regulation and we are responsible as a data controller of that personal data for the purposes of those laws.
When we mention “LRWA”, “we”, “us” or “our” we are referring to Long Row Wealth Advisory Ltd.
LRWA is a company registered in England and Wales (company number 10556587) whose registered office is at Thatched House, High Street, Little Milton, OX44 7PU. Long Row Wealth Advisory Ltd is authorised and regulated by the Financial Conduct Authority. Long Row Wealth Advisory Ltd’s Financial Services Register number is 978338.
We provide you with advice on and facilitation of a range of pension, investment, and financial protection products.
The personal data we collect and use
In the course of providing our service to you we may collect the following personal data when you provide it to us:
- contact information
- identity information
- financial information
- employment status
- lifestyle information
- health information
- data about criminal convictions or offences
- details of any vulnerability
- details of your dependents and/or beneficiaries under a policy (If you are providing information about another person we expect you to ensure that they know you are doing so and are content with their information being provided to us. You might find it helpful to show them this privacy notice and if they have any concerns, please contact us in one of the ways described below.)
- product details
Information collected from other sources
Information we get from other organisations
We also obtain personal data from other sources in the course of providing our intermediary services. Where we obtain this information from another party it is their responsibility to make sure they explain that they will be sharing personal data with us and, where necessary, ask permission before sharing information with us.
The personal data we obtain from other sources may include the following:
From lenders and/or product providers:
- product details
From identification and verification checking agencies:
- identity information
- sanction check information
How we use your personal data
Every purpose we use your information for, and our legal basis for each
The below table sets out:
- how we use your personal data
- the lawful bases upon which we collect and use your personal data
- who we routinely share your personal data with
| Rationale/Reason for Processing | Lawful basis for processing | 3rd party recipients linked to activity |
|---|---|---|
| To provide you with intermediary services | Performance of a contract | Our compliance and business support services provider for financial advice firms, based in the United Kingdom; our client relationship management provider, based in the United Kingdom; our cloud productivity provider (email, document storage and collaboration) |
| To apply for quotations for protection and/or general insurance products on your behalf. To apply for products on your behalf. To manage your investments on an ongoing basis, including portfolio valuations, transactions, rebalancing, and related correspondence | Performance of a contract | FCA-authorised investment platform providers who administer and custody your investments on an ongoing basis, including processing valuations, transactions, rebalancing, and correspondence. These platforms act as independent data controllers for the personal data they hold. The specific platform(s) used will depend on your individual circumstances and the recommendation made to you; a current list is available on request. UK-authorised insurance providers who underwrite and administer protection policies (life, critical illness, and/or income protection) on your behalf. These providers act as independent data controllers. Where an application involves special category data such as health information, the identity of the receiving provider will be confirmed to you at the point of application. The specific insurer(s) recommended will depend on your individual circumstances; a current list of providers we work with is available on request. |
| To identify, record and respond to any characteristics of vulnerability or support needs you may have, and to adapt how we deliver our advice and our service to you accordingly | Our legal and regulatory obligations (FCA rules on the fair treatment of customers in vulnerable circumstances). Where the information includes health information, we rely on the establishment, exercise or defence of legal claims - see “Special category data” below | None routinely. Our client relationship management provider and our cloud productivity provider hold the record as our processors, and our AI service providers where the record forms part of a meeting transcript, file note or summary |
| To notify you of changes to our service | Our legal and regulatory obligations | None |
| To prevent and detect fraud, money laundering and other financial crimes | Our legal and regulatory obligations | Identity verification and sanctions screening agencies, based in the United Kingdom |
| To meet our general legal and regulatory obligations | Our legal and regulatory obligations | Our compliance support consultancy, based in the United Kingdom |
| To manage your client relationship, maintain records, and facilitate electronic document signing | Performance of a contract / our legitimate interests | Our client relationship management provider, based in the United Kingdom; our electronic signature provider; our cloud productivity provider (cloud hosting, email, document storage) |
| To conduct investment research and portfolio monitoring on your behalf | Performance of a contract | Our investment research and portfolio monitoring provider, based in the United Kingdom |
| To use AI-based tools to transcribe recordings of client meetings, to assist in the preparation of financial analysis, reports, and client communications, and to index and search our own internal documents | Performance of a contract / our legal and regulatory obligations / our legitimate interests (for indexing and searching our own internal documents). Where the information includes special-category information such as health information, we rely on the establishment, exercise or defence of legal claims, because the record of our advice is what we would rely on if the advice were ever questioned | Our AI service providers, each acting as our data processor - they may use your personal data only to deliver the service to us, on our instructions. A cloud and artificial intelligence platform provider headquartered in the United States, for transcribing recordings of client meetings, preparing summaries, file notes and draft documents, and indexing our own internal documents so that we can search them, all of which run inside our own subscription with it. An artificial intelligence developer headquartered in the United States, for an AI assistant we use for advisory, drafting and administrative work and for an AI model that we run through our own cloud subscription to draft summaries and file notes from meeting transcripts - and for that model the data processor is the AI developer itself, not the cloud provider whose infrastructure the model runs on. Where each service stores and processes your data, the transfer safeguards we rely on for each, and the providers’ separate commitments not to use your data to train their models, are set out under “Use of artificial intelligence tools” below |
| To host and operate our proprietary client web application, databases, and supporting infrastructure used in the delivery of our services | Performance of a contract / our legitimate interests (secure and reliable service delivery) | A cloud infrastructure provider headquartered in the United States, in a United Kingdom region. LRWA operates a proprietary web application and associated databases on that provider’s infrastructure. It acts as our data processor under our data processing agreement with it. This is a separate processing activity from the AI tools described above and from the cloud productivity services (email, document storage) listed elsewhere in this table |
| To provide you with details of products and services from us and third parties that may be of interest to you, according to your preferences. For more information, see “Marketing” below | Consent | None |
| To provide household-level financial advice and servicing under a household Client Agreement, including using one household member’s data as an input to analysis and recommendations touching another member, and (where you have consented) sharing your data with other adult household members in joint meetings or written communications. See the “Household servicing” section for the full description | Performance of a contract / our legitimate interests / consent (for cross-household sharing) | Other adult household members under your household servicing arrangement, where you have provided Information Sharing Consent. Internal recipients within Long Row Wealth Advisory Ltd; the processors described elsewhere in this table (our client relationship management provider, our cloud productivity provider, our electronic signature provider, our investment research provider and our AI service providers); FCA-authorised investment platforms and UK-authorised insurance providers (independent data controllers) where engaged on the household’s behalf |
How we describe the recipients in this table
We describe the organisations we share your personal data with by what they do and, where it makes a difference to you, where they are - rather than by name. Where an organisation is outside the United Kingdom we say so, and the countries involved and the safeguards we rely on are set out under “International transfers of your personal data” below.
Two recipients are treated differently, and the reason is a real one. The investment platforms that hold your investments, and the insurers that underwrite your protection policies, are independent data controllers in their own right: they decide for themselves how they use the personal data they hold about you, and you may need to exercise your data-protection rights directly against them rather than against us. So we will tell you on request which platforms and which insurers hold your data - and where health information is involved we confirm the insurer’s identity to you at the point of application in any event.
Every other recipient in the table is our processor. A processor may use your personal data only to deliver its service to us, on our instructions, and it may not use your data for its own purposes. Your rights in relation to that data are exercised against us, and we remain responsible for it.
Special category data
Health and other sensitive information, and when we can use it
Certain types of personal data are considered more sensitive and so are subject to additional levels of protection under data protection legislation. These are known as ‘special categories of data’ and include data concerning your health, racial or ethnic origin, genetic data, and sexual orientation. Data relating to criminal convictions or offences is also subject to additional levels of protection.
We may process:
- health information and lifestyle information when providing intermediary services in relation to a protection insurance product; and/or
- criminal conviction or offence information when providing intermediary services in relation to a general insurance product; and/or
- health information, and other special category data, where it is relevant to understanding and responding to any characteristics of vulnerability or support needs you may have, so that we can adapt our advice and the way we deliver our service to you; and/or
- health information where your health affects the advice we give you, even where no insurance product is involved - for example where a health condition affects when you can afford to retire, what income your pension can sustain, whether an enhanced annuity is available to you, or how you should plan for care costs
For the last two of these, we process the information for the establishment, exercise or defence of legal claims: the record of what we understood about your circumstances, and of what we did about it, is what we would rely on if our advice or our service to you were ever questioned.
Where we need to share health information or other special category data with a protection insurance provider for the purposes of underwriting or administering your policy, that provider will act as an independent data controller for the data it receives. Given the sensitivity of this data, we will confirm the identity of the specific provider to you at the point of application, before any special category data is shared.
In addition to the lawful basis for processing this information set out in the above table, we will be processing it either (i) for the purpose of advising on, arranging, or administering an insurance contract or (ii) for the establishment, exercise, or defence of legal claims.
In the course of our activities relating to the prevention, detection and investigation of financial crime, we may process criminal conviction or offence information. Where we do so, in addition to the lawful basis for processing this information set out in the above table, we will be processing it for the purpose of compliance with regulatory requirements relating to unlawful acts and dishonesty.
Household servicing
How we advise a household, and what we share between its members
If you have signed a household Client Agreement with us - for example with a spouse, partner, parent, adult child, or other household member - your personal data is processed by us within a household servicing arrangement. This section explains what that means and what your rights are.
Who counts as a household member, and who controls your data
A household member, for our purposes, is any adult who has signed the same household Client Agreement as you, or who you have asked us to include in the arrangement - for example an adult child who has joined it after their 18th birthday. Children under 18 are not part of household servicing in their own right; their data is processed under separate arrangements with their parent or guardian.
We are the data controller for all the personal data we process about you in the course of providing our advisory services, including data that is shared with us by, or about, other household members. The other members of your household are not controllers of your data; they are clients of ours, just as you are. So you exercise your data-protection rights directly with us, whatever the household arrangement and whoever else is party to it.
Our lawful bases, and what we share within your household
Where we provide household servicing under a household Client Agreement, our lawful bases are:
- performance of contract - for processing each household member’s data within the scope of their own Client Agreement, including using one member’s data as an input to household-level analysis that informs that same member’s recommendations;
- legitimate interests - as a secondary basis for internal sub-uses such as model development, management information and supervisory file review, where these do not fit cleanly under performance of contract;
- explicit consent - for sharing data between household members in joint meetings or written communications. This consent is captured separately on our Information Sharing Consent form, which sits alongside your Client Agreement;
- legal obligation - where retention or sharing is required by FCA rules, anti-money-laundering rules, or other regulatory or statutory duties.
Sharing within a household takes two forms, and both need your consent. In a joint meeting, where you and one or more household members attend a review or planning meeting together, we may discuss each person’s portfolio, financial circumstances and recommendations in front of the others. In a written communication, where a household-level summary is useful, we may send it to all the named adult household members. We do either only with the consent of each member whose data is shared, and the Information Sharing Consent form lets each member set out what they consent to, who may receive it and in what circumstances - so the arrangement can run one way only, if that is what a member wants.
Our own analysis is different, and is not sharing. When we prepare a household-level plan we may use data about other household members in analysing your situation, even where the analysis is never shown to them - in modelling a couple’s retirement, both partners’ pension data informs the recommendation, although that recommendation is for one of them. We rely on the contractual basis of your household Client Agreement for that internal use.
Special-category information: the one choice that is yours
Some personal data - particularly health information, and family-circumstance information that touches on health or other protected characteristics - carries extra protection under data-protection law. It matters for household advice in real ways: a health condition can affect retirement timing, protection-insurance need and how we plan for care funding, and a household plan sometimes needs one member’s special-category information in the analysis that informs another member’s recommendations. The conditions we rely on in order to process it are those set out under “Special category data” above.
Our default is that we do not share it across your household. We will not assume your consent. We share or use your special-category information across the household only where you have actively agreed - and that is what data-protection law calls explicit consent, a higher standard than ordinary consent because the data is more sensitive. You can agree upfront, on the Information Sharing Consent form that sits alongside your Client Agreement; you are not obliged to, and if you do not, we ask you at the moment the question actually arises - by email or through the client portal - for your consent to that particular use, which then covers that use only.
You can withdraw your consent at any time, in writing, with immediate effect. We stop the relevant disclosures from that point forward; disclosures already made, which were lawful when they were made, remain so. We keep a record of what consent we hold for you, and you can ask us at any time to confirm it and to tell you what we have shared on the basis of it.
Your rights within a household
Your data-protection rights - access, rectification, erasure, restriction, objection, portability - are yours individually, not jointly with your household. When you make a subject access request, or any other rights-based request, we answer you about your data: we do not pass your request to other household members, and we do not include their personal data in your response unless it is inseparable from yours and they have consented to its inclusion. If you and another household member make related but different requests, we handle each separately.
You can also object to any processing of your data that we have justified on our legitimate interests, including household analysis where it rests on legitimate interests rather than on contract. Where you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for the establishment, exercise or defence of legal claims.
Marketing
We may use personal data we hold about you to help us identify, tailor, and provide you with details of products and services from us that may be of interest to you. We will only do so where we have a legitimate business reason to do this and will do so in accordance with any marketing preferences you have provided to us.
In addition, where you provided your consent, we may provide you with details of products and services of third parties where they may be of interest to you.
You can opt out of receiving marketing at any time. If you wish to amend your marketing preferences, please contact us:
- By email: info@longrowwealth.com
- By post: Long Row Wealth Advisory Ltd, Thatched House, High Street, Little Milton, OX44 7PU
Visiting our website and contacting us
Our website, our contact form, and cookies
This section is for anyone who visits our website or sends us an enquiry, whether or not you are a client of ours. If you are a client, the rest of this notice applies to you as well.
Our website is hosted for us by a cloud platform provider headquartered in the United States, acting as our data processor and permitted to use the personal data the site handles only to provide that hosting to us, on our instructions. Where the hosting involves a transfer of your personal data outside the United Kingdom, the safeguards described under “International transfers of your personal data” below apply.
If you fill in the contact form on our website, we collect the contact details you enter and whatever you choose to tell us about your enquiry. The form sends your submission into the client relationship management system we use, where it is held as an enquiry, and notifies us by email that it has arrived. Three processors are involved: our client relationship management provider, based in the United Kingdom, which stores the enquiry; our website hosting provider, which hosts the form; and our cloud productivity provider, which carries the notification and any reply we send you. We share enquiries with nobody else unless you become a client and the sharing is described elsewhere in this notice.
We use what you send us to reply to you and, where you are asking about our services, to take the steps needed before we could enter into a contract with you. Our lawful bases are those steps taken at your request before entering into a contract, and our legitimate interests in responding to people who contact us and in keeping a record that we did so. Sending us an enquiry does not make you a client and does not create a client record. If your enquiry does not lead to us working together, we keep it for twelve months from the date of our last contact with you; after that period ends we delete it, at the next review of our records. If you do become a client, your enquiry becomes part of your client record and is kept for the periods set out under “How long your personal data will be kept” below.
We use no analytics, advertising or tracking technologies on our website, so we set nothing on your device that needs your permission, which is why the site does not ask you for any; anything stored there is only what is strictly necessary to make the site and the contact form work. That is the position as at the date of this notice: if we ever add analytics or anything similar, we will ask for your consent before setting it, and you will be able to change or withdraw your choice at any time.
The section headed “Whether information has to be provided by you, and if so why” below concerns the information we need in order to provide you with intermediary services as a client. It does not apply to a website enquiry: you decide what, if anything, to tell us.
Whether information has to be provided by you, and if so why
We will tell you if providing some personal data is optional, including if we ask for your consent to process it. In all other cases you must provide your personal data in order for us to provide you with intermediary services. This applies to the information we need in order to advise you and to look after your products; if you are not a client and are simply making an enquiry, you choose what to tell us - see “Visiting our website and contacting us” above.
How long your personal data will be kept
How long we keep your information
We will hold your personal data for differing periods of time depending upon the reason we have for processing it. These retention periods are set out below:
- Six years for investment business (in line with COBS 9.5 and the standard limitation period for financial services complaints)
- Indefinitely for pensions transfer and opt-out business
- Three years for financial protection business
For pension transfer and opt-out business, and for protection business, these are the minimum periods FCA rules require us to keep your records for. The six-year period for investment business is our own policy and is longer than the FCA minimum: a claim can be brought against us for up to six years, and your file is what we would rely on to answer one. We reserve the right to retain data for longer where we believe it is in our legitimate interests to do so.
Where we record a client meeting, the recording itself is kept for six years from the date of the meeting and is then deleted, whatever period applies to the file it relates to. The transcript and the file note or summary we produce from the recording are part of the record of your advice, and they are kept for the period that applies to that record.
Where our AI service providers hold your information, and for how long, is a separate question from the periods above, and is described under “Use of artificial intelligence tools” below.
If you have made an enquiry but have not become a client, how long we keep it is set out under “Visiting our website and contacting us” above.
You have the right to request deletion of your personal data. We will comply with this request, subject to the restrictions of our regulatory obligations and legitimate interests as noted above.
International transfers of your personal data
When your information goes outside the UK, and how it is protected
Some of the service providers we use to deliver our services to you are based outside the United Kingdom. This means that your personal data may be transferred to, and processed in, countries outside the UK. Where this happens, we ensure that your data is protected to a standard that is not materially lower than the protection it would receive under UK data protection law. For some cloud services - including two of the AI services described below - the provider stores data in the United Kingdom but does not tell us the country in which the processing itself takes place. Where that is the case we say so rather than imply otherwise, and we rely on the provider’s own transfer safeguards, which we have assessed.
We rely on one or more of the following safeguards when transferring your data internationally:
- UK adequacy regulations - where the UK government has determined that a country provides an adequate level of data protection, we may transfer your data to that country without additional safeguards. This currently includes the European Economic Area and certain other countries.
- UK-US Data Bridge - for transfers to organisations in the United States that are certified under the UK Extension to the EU-US Data Privacy Framework, we rely on the UK-US Data Bridge as the lawful transfer mechanism. We verify each provider’s certification status before transferring any personal data.
- Standard contractual clauses or the UK International Data Transfer Agreement - where a transfer is not covered by an adequacy decision or the Data Bridge, we use contractual safeguards approved by the Information Commissioner’s Office to ensure that your rights are protected.
We also carry out transfer risk assessments where required to confirm that the level of protection in the destination country is not materially lower than the protection provided under UK law. Where necessary, we implement supplementary safeguards such as encryption, data minimisation, and contractual restrictions on how your data may be used.
You can ask us for a copy of the safeguards we rely on for any international transfer of your personal data, and for further information about them, and we will provide it. Please contact us using the details set out at the end of this notice.
Your rights
Your rights over your information, and how to use them
You have legal rights under data protection regulation in relation to your personal data. They are set out in the subsections below.
Your data-protection rights are individual to you and exercisable directly with us, regardless of your household servicing arrangement. See the “Household servicing” section above for how we handle requests within a household context.
We may ask you for proof of identity when making a request to exercise any of these rights. We do this to ensure we only disclose information or change your details where we know we are dealing with the right individual.
We will not ask for a fee, unless we think your request is unfounded, repetitive or excessive. Where a fee is necessary, we will inform you before proceeding with your request.
We aim to respond to all valid requests within one month. It may however take us longer if the request is particularly complicated or you have made several requests. We will always let you know if we think a response will take longer than one month. To speed up our response, we may ask you to provide more detail about what you want to receive or are concerned about.
We may not always be able to fully address your request, for example if it would impact the duty of confidentiality we owe to others, or if we are otherwise legally entitled to deal with the request in a different way.
To access personal data
You can ask us to confirm whether or not we have and are using your personal data. You can also ask to get a copy of your personal data from us and for information on how we process it.
To rectify / erase personal data
You can ask that we rectify any information about you which is incorrect. We will be happy to rectify such information but would need to verify the accuracy of the information first.
You can ask that we erase your personal data if you think we no longer need to use it for the purpose we collected it from you.
You can also ask that we erase your personal data if you have either withdrawn your consent to us using your information (if we originally asked for your consent to use your information), or exercised your right to object to further legitimate use of your information, or where we have used it unlawfully or where we are subject to a legal obligation to erase your personal data.
We may not always be able to comply with your request, for example where we need to keep using your personal data in order to comply with our legal obligation or where we need to use your personal data to establish, exercise or defend legal claims.
To restrict our use of personal data
You can ask that we restrict our use of your personal data in certain circumstances, for example
- where you think the information is inaccurate and we need to verify it;
- where our use of your personal data is not lawful, but you do not want us to erase it;
- where the information is no longer required for the purposes for which it was collected but we need it to establish, exercise or defend legal claims; or
- where you have objected to our use of your personal data, but we still need to verify if we have overriding grounds to use it.
We can continue to use your personal data following a request for restriction where we have your consent to use it; or we need to use it to establish, exercise or defend legal claims, or we need to use it to protect the rights of another individual or a company.
To object to use of personal data
You have a right to object to how we use your personal data. You can object to any use of your personal data which we have justified on the basis of our legitimate interest, if you believe your fundamental rights and freedoms to data protection outweigh our legitimate interest in using the information. If you raise an objection, we may continue to use the personal data if we can demonstrate that we have compelling legitimate interests to use the information, or if we need it for the establishment, exercise or defence of legal claims. You can also tell us at any time to stop using your personal data for direct marketing, and we will stop.
To request a transfer of personal data
You can ask us to provide your personal data to you in a structured, commonly used, machine-readable format, or you can ask to have it transferred directly to another data controller (e.g. another company).
You may only exercise this right where we use your personal data in order to perform a contract with you, or where we asked for your consent to use your personal data. This right does not apply to any personal data which we hold or process outside automated means.
To contest decisions based on automatic decision making
If we made a decision about you based solely by automated means (i.e. with no human intervention), and the decision made by us produces a legal effect concerning you, or significantly affects you, you may have the right to contest that decision, express your point of view and ask for a human review. These rights do not apply where we are authorised by law to make such decisions and have adopted suitable safeguards in our decision-making processes to protect your rights and freedoms.
You can contact us for more information
Asking us for more information than this notice gives
If you are not satisfied with the level of information provided in this privacy notice, you can ask us about what personal data we have about you, what we use your information for, who we disclose your information to, whether we transfer it abroad, how we protect it, how long we keep it for, what rights you have, how you can make a complaint, where we got your data from and whether we have carried out any automated decision making using your personal data.
If you would like to exercise any of the above rights, please:
- email or write to our Data Privacy Manager at info@longrowwealth.com or Thatched House, High Street, Little Milton, OX44 7PU;
- let us have enough information to identify you, e.g. name, address, date of birth;
- let us have proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill); and
- let us know the information to which your request relates.
Use of artificial intelligence tools
How we use AI tools, and what happens to your information
We use AI-based tools in three ways: to transcribe recordings of client meetings; to prepare summaries, file notes, financial analysis, reports and draft communications; and to index and search our own internal documents.
Keeping a proper record of the advice we give you, and of the meetings in which we discuss it, is part of the service you have contracted for and is also required of us by FCA rules. That is the basis on which we do this work: the tools are how we do it, not why we are allowed to do it, and the companies that provide them act only as our processors, on our instructions.
Where we record a client meeting, the meeting platform we use tells everyone present that the meeting is being recorded, as soon as the recording starts, and we say the same thing in the meeting invitation, so nothing is recorded without your knowledge.
All outputs produced by AI tools that relate to your financial advice, suitability assessments, or recommendations are reviewed and approved by a qualified financial adviser before any recommendation is made to you or any action is taken on your behalf. We do not rely solely on automated processing to make decisions that have legal or similarly significant effects on you.
Our AI service providers, and where your information goes
Our AI service providers act only as our data processors: each is engaged under a data processing agreement, and each may use your personal data only to deliver its service to us, on our instructions, and not for its own purposes.
A cloud and artificial intelligence platform provider headquartered in the United States runs, inside our own subscription with it, the transcription, the drafting and the internal-indexing work described above. Transcription takes place in the United Kingdom: we require a United Kingdom region for the transcription service, for the storage that holds the recording, and for the application that requests the transcript. For the rest of that work, the data the provider stores stays in the United Kingdom but the processing itself may take place in another country, and the provider does not specify which; for those transfers we rely on that provider’s certification under the UK Extension to the EU-US Data Privacy Framework and, where it moves data to its own infrastructure in another country, on its own transfer safeguards, which are set out in the data protection addendum under which it acts as our processor.
An artificial intelligence developer headquartered in the United States provides an AI assistant that we use for advisory, drafting and administrative work, supplied from the United States under an enterprise agreement, and an AI model that we run through our own cloud subscription - which we require to be deployed in a region within the European Economic Area - to draft summaries and file notes from meeting transcripts. For that model the AI developer is our data processor in its own right, and the cloud provider whose infrastructure the model runs on is not, so the developer’s own agreement with us governs what happens to the content. That developer is not certified under the UK-US Data Privacy Framework, so for the United States element we rely on the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; transfers to the European Economic Area are covered by UK adequacy regulations, so no additional safeguard is needed for that leg.
We check that a provider’s certification is current before we transfer personal data to it, and you can ask us for a copy of the safeguards we rely on - see “International transfers of your personal data” above.
Each provider gives us its own contractual commitment not to use your personal data to train its AI models. Each commitment covers only that provider’s own services, and none of them covers another provider’s.
The specific services in each category, the terms that apply to each and the settings we apply are recorded in a register we keep and review at least once a year.
Data minimisation, and how long your information is held
When we use AI tools we provide only the personal data the task needs. Some work cannot be done without identifying you - preparing a suitability assessment, drafting your correspondence, processing an insurance application - and removing your name from a meeting transcript would not make it anonymous either, because the content itself identifies you. So for regulated advice work we rely on encryption, access controls and contractual restrictions rather than on stripping out identifying details.
How long a provider holds your information differs by service, and we record what each provider publishes rather than assume a position. The recording of your meeting is held in our own storage in the United Kingdom, not a provider’s, and the transcription service reads it from there. The transcript it produces is written to that provider’s own short-term storage; we collect it and delete the provider’s copy immediately, and in any event that copy expires automatically after six hours - the shortest period the service allows. For the AI assistant we use under an enterprise agreement, the provider retains the content of our conversations so that the service can function; we asked whether a no-retention option was open to us, and it is not available to a firm of our size. A provider may also keep a copy of material that its automated safety systems have flagged; that copy is held in the United Kingdom, and its staff see it only where it has been flagged. No provider publishes how long it keeps this material, so we do not state a period we cannot verify. We review what each provider publishes at least once a year, and whenever a provider changes its terms.
How we make and keep the record of your advice
When we meet you, we record the meeting and use the AI services described above to produce a transcript and a summary of it. The transcript and the summary become part of the record of the advice we have given you, alongside our file notes, your suitability report and the rest of your file.
This is how the record is made, and keeping a proper record is something FCA rules require of us - so it is not an optional part of the service and it is not something we ask you to agree to. If our advice were ever questioned, by you or by anyone else, that record is what we would rely on to show what we discussed and why the advice was right for you. It is as much your protection as ours.
What we do instead of asking is take care with it, and the safeguards are set out above: we give these services only the information the task needs, every output that relates to your advice is read and approved by a qualified adviser before it is used, the providers are contractually barred from using your information for their own purposes or to train their models, and your meeting recording is held in our own United Kingdom storage.
The record itself we cannot delete on request, because we are required to keep it - see “How long your personal data will be kept” above for the periods that apply. You can still ask us to delete personal data we no longer need, and we deal with that in the same way as any other erasure request.
There is one choice about your special-category information that is yours, and it is a different one: whether we may share your health and similar information with another member of your household when we are advising you both. Our client agreement asks that separately, and if your agreement predates it we will ask you the next time we update your paperwork. You can change your answer in writing at any time, and it makes no difference to how we record our meetings with you - see “Household servicing” above.
If any of this concerns you, please tell us. We would rather talk it through than have you wonder.
Keeping your personal data secure
How we keep your information secure
We have appropriate security measures in place to prevent personal data from being accidentally lost or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Data protection complaints
If you have a concern about how we have handled your personal data, you can raise a data protection complaint with us directly. We have an internal data protection complaints procedure which is available on request. Please contact our Data Privacy Manager using the details set out below and we will investigate your concern promptly.
Our supervisory authority
If you are not happy with the way we have handled your data protection complaint, or if you wish to complain directly to the regulator, you have the right to lodge a complaint with the Information Commissioner’s Office. The ICO has enforcement powers and can investigate compliance with data protection law. You can contact the ICO at www.ico.org.uk or by calling 0303 123 1113.
We ask that you please attempt to resolve any issues with us before contacting the ICO.
How to contact us
Please contact our Data Privacy Manager if you have any questions about this privacy notice or the information we hold about you.
If you wish to contact our Data Privacy Manager, please send an email to info@longrowwealth.com or write to Thatched House, High Street, Little Milton, OX44 7PU.
Version history
Which version this is
This is version 2.04 of this notice, published in September 2026.
Glossary of Terms
What the terms in this notice mean
| Term | Meaning |
|---|---|
| data controller | the person or company that decides how and why personal data is processed. We are the data controller for the personal data we hold about you |
| data protection regulation | applicable data privacy and protection laws |
| FCA | the Financial Conduct Authority, the independent regulator of financial services |
| health information | information relating to your medical history, including symptoms, diagnoses, procedures and outcomes, your height and weight, and previous, current or persistent medical conditions and family medical history |
| intermediary services | the services we provide to you in relation to pension and investment products and non-investment insurance business, which include advising on them, arranging them and looking after them for you |
| lifestyle information | your work and leisure behaviour patterns. Most relevant to your products may be your smoker status, alcohol consumption, health, retirement age and exercise habits |
| sanction check information | this is information relating to your politically exposed persons (PEPs) status and Her Majesty’s Treasury financial sanctions status, which is recorded to prevent fraud and money laundering |
| vulnerability | a vulnerable consumer is someone who, due to their personal circumstances, is especially susceptible to detriment, and more likely to suffer severe detriment if something goes wrong. Details of vulnerability fall into four categories: health; resilience (financial); life events; and capability (financial knowledge and confidence) |
| UK adequacy regulations | regulations made by the UK Secretary of State recognising that a particular country or territory provides an adequate level of protection for personal data, meaning that data can be transferred there without additional safeguards |
| UK-US Data Bridge | the UK Extension to the EU-US Data Privacy Framework, a mechanism that allows UK organisations to transfer personal data to US organisations that have self-certified their compliance with the Data Privacy Framework Principles. The Data Bridge took effect on 12 October 2023 |
| standard contractual clauses | pre-approved contractual terms that provide appropriate safeguards for international transfers of personal data. In the UK these are the UK International Data Transfer Agreement (UK IDTA) and the UK Addendum to the EU Standard Contractual Clauses, both approved by the ICO |