Last updated: 30 July 2026 · Version: 1.0
1. Controller Identity and Scope
JT FINANCIAL CONSULTANTS LIMITED (the “Firm”, “we”, “us”), a private company limited by shares registered in England and Wales under company number 09543431, whose registered office is at 6 Brook Street, Wymeswold, Loughborough, LE12 6TU, United Kingdom, is the data controller in respect of the personal data described in this notice for the purposes of the UK General Data Protection Regulation (UK GDPR), being Regulation (EU) 2016/679 as it forms part of the law of England and Wales by virtue of the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018 (DPA 2018).
This notice applies to personal data processed through this website, through our enquiry and onboarding processes, in the course of delivering advisory, asset management, business development, exit strategy, venture capital and wealth management services, and in connection with our supplier, marketing and recruitment activities. It should be read alongside our Terms & Conditions and any privacy provisions in an executed engagement letter.
Where we process personal data solely on documented instructions from a corporate client — for example, employee or investor data supplied to us for the purposes of a transaction — we act as a processor and the client remains the controller. In such cases the processing is governed by Article 28 UK GDPR terms set out in the relevant engagement documentation.
2. Categories of Personal Data We Process
- Identity and contact data: full name, title, date of birth, nationality, job title, employer, postal address, email address, telephone numbers.
- Verification and compliance data: passport, driving licence or national identity card images, proof-of-address documents, tax identification numbers, National Insurance number, beneficial-ownership and control declarations, politically exposed person (PEP) status, sanctions and adverse-media screening results.
- Financial and suitability data: source of funds and source of wealth, income, assets, liabilities, bank account details, investment objectives, knowledge and experience, risk tolerance and capacity for loss.
- Transaction and relationship data: mandates, instructions, holdings, correspondence, meeting notes, call records and file notes.
- Enquiry data: the name, email address, telephone number, subject and message content you submit through our contact form, together with the submission timestamp.
- Technical and usage data: IP address, device and browser type, operating system, referring URL, pages viewed, and approximate location derived from IP, collected by our hosting and security infrastructure in server logs.
- Marketing and communications data: your preferences in receiving communications from us and your consent or objection records.
Special category data and criminal offence data. We do not routinely seek special category data (Article 9 UK GDPR). Where anti-money-laundering screening reveals data relating to criminal convictions, alleged offences or politically exposed status, we process it in reliance on the substantial public interest conditions in Schedule 1 Part 2 DPA 2018, including the “preventing or detecting unlawful acts” and “regulatory requirements relating to unlawful acts and dishonesty” conditions, under an appropriate policy document.
3. Sources of Personal Data
We obtain personal data directly from you; from your professional advisers, employer or corporate group; from publicly accessible sources such as Companies House, the FCA Register, the Land Registry, the Insolvency Register and press and internet searches; and from third-party electronic identity-verification, credit-reference, sanctions-screening and adverse-media providers.
4. Purposes and Lawful Bases
- Responding to enquiries submitted via our contact form — Article 6(1)(b) (steps prior to entering a contract) and Article 6(1)(f) (legitimate interests in responding to business enquiries).
- Client onboarding, due diligence and provision of the Services — Article 6(1)(b) (performance of a contract) and Article 6(1)(c) (compliance with a legal obligation).
- Anti-money-laundering, counter-terrorist-financing, sanctions and anti-bribery compliance, and suspicious activity reporting — Article 6(1)(c), and for special category or criminal offence data the conditions in Schedule 1 DPA 2018 referred to above.
- Maintaining records, accounting, tax and statutory filings — Article 6(1)(c) and Article 6(1)(f).
- Establishing, exercising or defending legal claims, and managing complaints, insurance and professional-indemnity notifications — Article 6(1)(f) and Article 9(2)(f) where relevant.
- Website security, fraud prevention, service integrity and abuse monitoring — Article 6(1)(f).
- Direct marketing of professional services to business contacts — Article 6(1)(f), or Article 6(1)(a) (consent) where required by the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). You may opt out at any time.
Where we rely on legitimate interests, we have carried out a legitimate interests assessment (LIA) balancing our interests against your rights and freedoms. A summary of the relevant LIA is available on request.
5. Automated Decision-Making and Profiling
We use automated screening tools for sanctions, PEP and adverse-media checks. These tools produce match alerts which are always subject to meaningful human review by a member of our compliance team before any decision is taken. We do not carry out solely automated decision-making producing legal or similarly significant effects within the meaning of Article 22 UK GDPR.
6. Recipients, Disclosures and Processors
We disclose personal data on a need-to-know basis to: our personnel and professional advisers; identity-verification, screening and data-enrichment providers; IT hosting, database, email, backup and cybersecurity providers acting as processors under Article 28-compliant agreements; auditors, insurers and brokers; banks and payment providers; and, where required, HM Revenue & Customs, the National Crime Agency, the Financial Conduct Authority, the Information Commissioner’s Office, law-enforcement agencies, courts and other competent authorities.
We may also disclose personal data to a prospective purchaser, investor or successor in connection with a merger, acquisition, reorganisation or transfer of all or part of our business, subject to appropriate confidentiality undertakings.
We do not sell personal data, and we do not share it with third parties for their own independent direct-marketing purposes.
7. International Transfers
Personal data is primarily stored and processed within the United Kingdom and the European Economic Area. Where a processor transfers personal data to a country not covered by UK adequacy regulations, we ensure an appropriate safeguard under Article 46 UK GDPR is in place — typically the International Data Transfer Agreement (IDTA) or the European Commission’s Standard Contractual Clauses as supplemented by the UK Addendum — together with a documented transfer risk assessment (TRA) and, where necessary, supplementary technical measures such as encryption in transit and at rest. A copy of the relevant safeguards may be requested using the contact details below.
8. Retention Periods
- Contact-form enquiries that do not lead to an engagement: up to 24 months from last contact.
- Client due-diligence records: five (5) years from the end of the business relationship or the completion of the occasional transaction, as required by regulation 40 of the MLRs, extendable to ten (10) years where required by law.
- Engagement files, advice and deliverables: six (6) years from the end of the engagement, reflecting the primary limitation period under the Limitation Act 1980, extended where a deed or an ongoing dispute applies.
- Accounting and tax records: six (6) years from the end of the accounting period, per the Companies Act 2006 and HMRC requirements.
- Server and security logs: typically 30 to 90 days.
- Marketing consent and objection records: for as long as required to evidence compliance with your preferences.
At the end of the applicable period we securely delete or irreversibly anonymise the data, save where a legal hold, regulatory investigation or live dispute requires continued retention.
9. Security Measures
In accordance with Article 32 UK GDPR we implement appropriate technical and organisational measures proportionate to the risk, including encryption of data in transit (TLS) and at rest, role-based access control on a least-privilege basis, row-level access restrictions on our database so that enquiry submissions cannot be read from the public website, multi-factor authentication for administrative access, secure backups, vendor due diligence, confidentiality undertakings and staff training.
No transmission over the internet can be guaranteed to be completely secure. Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours, and will notify affected individuals directly where the breach is likely to result in a high risk.
11. Your Rights as a Data Subject
- Right of access (Article 15) — to obtain confirmation of processing and a copy of your personal data.
- Right to rectification (Article 16) — to have inaccurate data corrected and incomplete data completed.
- Right to erasure (Article 17) — the “right to be forgotten”, subject to our overriding legal and regulatory retention duties.
- Right to restriction of processing (Article 18).
- Right to data portability (Article 20) — where processing is based on consent or contract and carried out by automated means.
- Right to object (Article 21) — including an absolute right to object to direct marketing at any time.
- Right to withdraw consent (Article 7(3)) — where processing is based on consent, without affecting the lawfulness of prior processing.
- Rights in relation to automated decision-making (Article 22).
To exercise any right, contact us using the details below. We will respond within one month, extendable by a further two months where the request is complex or numerous, and we will tell you if an extension applies. We may need to verify your identity before acting. Requests are free of charge unless manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, giving reasons.
12. Consequences of Not Providing Data
Provision of identity, verification and financial data is a statutory and contractual requirement for onboarding. If you decline to provide it, we will be unable to complete customer due diligence and will be legally prohibited from establishing or continuing a business relationship with you.
13. Children’s Data
Our website and services are directed at business and professional audiences and are not intended for children under 18. We do not knowingly collect personal data relating to children other than where it arises incidentally in the context of trust, estate or succession planning instructed by an adult client.
14. Changes to This Notice
We review this notice at least annually and whenever our processing activities materially change. The version and date at the top of this page indicate the current issue. Material changes will be notified to clients directly where appropriate.
15. Contact and Complaints
Data protection enquiries and rights requests should be addressed to the Director at Info@jtfinuk.com, by telephone on 020 7315 4294, or in writing to 2nd Floor, Berkeley Square House, Berkeley Square, London W1J 6BD, United Kingdom. We have not appointed a statutory Data Protection Officer as we are not required to do so under Article 37 UK GDPR.
If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, at ico.org.uk. We would appreciate the opportunity to address your concerns first.
