Note. The full Privacy Policy is drafted by counsel. The skeleton below provides the section structure, indicative wording, and the disclosure points required for a UK GDPR-compliant notice for a UK financial-services intermediary. Counsel sign-off mandatory before launch.
1. Who we are
znobia Ltd (Companies House [TBD]), registered office [TBD], is the data controller for personal data processed via znobia.com and in the course of its professional engagements. ICO registration: [TBD].
2. What personal data we collect
Identification data, contact data, professional context (employer, role), risk-brief content submitted via RFI, technical data (IP, device, session), portal usage data, communications.
3. Lawful bases for processing
Contract (engagement performance), legitimate interest (responding to enquiries, business operations), legal obligation (regulatory record-keeping), consent (newsletter).
4. Why we process your data
Responding to enquiries, conducting professional engagements, regulatory record-keeping, security and fraud prevention, newsletter (consent).
5. How long we keep your data
Enquiry data: 24 months from last contact unless an engagement commences. Engagement data: 7 years post-engagement (regulatory record-keeping). Newsletter: until you unsubscribe.
6. Who we share your data with
Carriers and Lloyd's syndicates in the course of placement; sub-processors (named in §11); regulators on lawful request; counsel and auditors as required. No marketing partners. No advertising trackers.
7. International transfers
Data may be transferred to carriers and sub-processors outside the UK; transfers are governed by UK IDTA, EU SCCs, or adequacy where available.
8. Your rights
Access, rectification, erasure, restriction, objection, portability, withdrawal of consent. Contact [email protected]. ICO complaint right.
9. Cookies
See Cookies policy.
10. Security
[Encryption posture, access controls, audit logging, incident-response posture summary.]
11. Sub-processors
[Named list — hosting, email, analytics if any, payments if any, MFA provider, etc. Counsel to populate.]
12. Changes to this policy
We publish material changes with a changelog entry on the Legal hub at least 30 days before they take effect.
13. Contact
Data Protection Officer · [email protected] · [postal address].