1. Introduction
InvestPro Limited ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring you have a positive experience on our website and when using our investment services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at investpro.co.uk and engage with our investment programs, services, and platforms.
We are the data controller for personal data collected through our website and services. Our registered office is located at 125 Baker Street, London, W1U 6AR, United Kingdom. We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 in all aspects of our business operations.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our website or services. By accessing and using InvestPro's website and services, you acknowledge that you have read, understood, and agree to be bound by all the provisions of this Privacy Policy.
2. What Data We Collect
We collect personal information in various ways through our website and services. The types of information we collect include:
- • Contact Information: Your full name, email address, phone number, postal address, and country of residence.
- • Account Information: Username, password, account preferences, investment profile, risk tolerance assessment, and financial objectives.
- • Financial Information: Bank account details, investment history, trading preferences, portfolio composition, and financial transaction records.
- • Technical Data: IP address, browser type and version, operating system, device identifier, pages visited, time spent on pages, and navigation patterns.
- • Cookie Information: Data collected through cookies, web beacons, and similar tracking technologies for analytics and personalization purposes.
- • Communication Data: Records of your interactions with our customer support team, including emails, chat messages, and call logs.
- • Marketing Data: Your preferences regarding promotional communications, email opt-ins, and content engagement history.
3. How We Collect Data
We collect your personal information through multiple methods and sources to provide you with the best possible service experience:
- • Direct Submission: Information you voluntarily provide through registration forms, contact forms, subscription requests, and account setup processes.
- • Automated Technologies: We use Google Analytics to track website usage patterns, Hotjar for user behavior analysis, and Meta Pixel for marketing purposes.
- • Cookies and Tracking: Essential cookies for site functionality, analytics cookies to understand user behavior, and marketing cookies for targeted advertising.
- • Server Logs: Automatic collection of IP addresses, access times, pages viewed, and referral URLs from server logs.
- • Third-Party Integrations: Information received from payment processors, identity verification providers, and financial data aggregators.
- • Customer Communications: Data collected through customer support interactions, feedback forms, and survey responses.
4. Legal Basis for Processing Data
We process your personal data on the basis of lawful grounds under Article 6 of the UK GDPR. These include:
- • Consent (Article 6(1)(a)): Where you have explicitly consented to data processing, such as subscribing to our newsletter or opting into marketing communications.
- • Contract Performance (Article 6(1)(b)): Processing necessary to perform our services contract with you, including account management, investment services, and transaction processing.
- • Legal Obligation (Article 6(1)(c)): Compliance with legal and regulatory requirements applicable to financial services, including anti-money laundering and know-your-customer obligations.
- • Legitimate Interests (Article 6(1)(f)): Our legitimate business interests in fraud prevention, system security, service improvement, and marketing analytics.
5. How We Use Your Data
Your personal information is used for the following purposes:
- • Service Delivery: To provide investment services, manage your account, execute trades, calculate returns, and deliver educational content and market analysis.
- • Personalization: To tailor our website and services to your preferences, investment objectives, and risk profile.
- • Marketing Communications: To send promotional materials, investment alerts, market updates, and product information (only with your consent).
- • Analytics and Improvement: To analyze user behavior, measure service performance, conduct market research, and improve our website and services.
- • Legal and Regulatory Compliance: To comply with financial services regulations, anti-money laundering requirements, and tax obligations.
- • Fraud Prevention: To detect, prevent, and investigate fraudulent activities, unauthorized access, and other security threats.
- • Customer Support: To respond to your inquiries, resolve disputes, and provide technical assistance.
6. Data Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Specific retention periods include:
- • Account Information: Retained for the duration of your account plus 7 years after account closure for tax and regulatory purposes.
- • Contact Forms and Inquiries: Retained for 2 years or until the matter is resolved, then securely deleted.
- • Transaction Records: Retained for 7 years in accordance with UK tax and financial services regulations.
- • Analytics and Technical Data: Generally retained for 13 months in aggregated form for analytics purposes.
- • Marketing Preferences: Retained until you unsubscribe or request deletion.
- • Communication Records: Retained for 3 years for dispute resolution and quality assurance purposes.
7. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. However, we may share your data with carefully selected service providers who assist us in operating our website and conducting our business. These recipients include:
- • Payment Processors: Third-party payment gateways that securely process financial transactions on your behalf.
- • Web Hosting Providers: Infrastructure providers who host our website and store our databases.
- • Analytics Providers: Google Analytics and similar tools to measure website performance and user behavior.
- • Email Service Providers: Platforms used to deliver transactional and marketing emails.
- • Identity Verification Services: Third parties used for KYC and AML compliance verification.
- • Legal and Regulatory Authorities: When required by law, court order, or government request.
- • Business Partners: In the event of merger, acquisition, or sale of business assets, with appropriate data protection safeguards.
All third-party service providers are contractually obligated to maintain the confidentiality and security of your personal information and may only use it for the purposes specified in our agreements with them.
8. International Data Transfers
InvestPro operates primarily within the United Kingdom. However, some of our service providers may be located outside the UK or European Economic Area (EEA). When we transfer personal data internationally, we implement appropriate safeguards to protect your information, including:
- • Standard Contractual Clauses: We use EU Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office for transfers to countries without an adequacy decision.
- • Adequacy Decisions: We only transfer data to countries that have been deemed to provide an adequate level of data protection by the ICO.
- • Data Protection Agreements: Binding commitments from service providers to protect your data according to UK GDPR standards.
For more information about international data transfers or the safeguards we have in place, please contact our Data Protection Officer at [email protected].
9. Your Rights Under UK GDPR
You have several important rights regarding your personal data under the UK General Data Protection Regulation:
- • Right of Access (Article 15): You may request a copy of all personal data we hold about you in a structured, commonly used, machine-readable format.
- • Right to Rectification (Article 16): You have the right to request correction of inaccurate or incomplete personal data.
- • Right to Erasure (Article 17): You may request deletion of your personal data under certain circumstances, subject to legal and contractual obligations.
- • Right to Restrict Processing (Article 18): You may request that we limit how we use your personal data while a dispute is resolved.
- • Right to Data Portability (Article 20): You may request your data in a portable format and have it transferred to another controller.
- • Right to Object (Article 21): You may object to processing based on legitimate interests or for direct marketing purposes.
- • Right to Withdraw Consent: If processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- • Right to Lodge a Complaint: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your rights have been violated.
To exercise any of these rights, please submit a written request to [email protected] or send a letter to our registered office at 125 Baker Street, London, W1U 6AR, UK. We will respond to your request within 30 days of receipt. If we need additional information to verify your identity, we may extend the response period by up to two months.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to improve your experience on our website. Cookies are small files stored on your device that help us remember your preferences and analyze how you use our site.
Types of Cookies We Use:
- • Essential Cookies: Necessary for site functionality, user authentication, and security. Duration: Session to 12 months.
- • Analytics Cookies: Track user behavior, page visits, and performance metrics. Duration: 13 months.
- • Marketing Cookies: Enable targeted advertising and remarketing campaigns. Duration: 13 months.
- • Preference Cookies: Remember your settings and preferences. Duration: 12 months.
Managing Your Cookie Preferences:
You can control cookies through your browser settings. Most browsers allow you to refuse cookies or alert you when a cookie is being sent. However, blocking essential cookies may affect your ability to use certain features of our website. Our cookie consent banner allows you to accept or reject non-essential cookies when you first visit our site.
11. Children's Privacy
InvestPro's website and services are not directed at children under the age of 18. We do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected data from a child under 16, we will promptly delete such information and take steps to prevent further collection.
If you are a parent or guardian and believe we have collected information about your child, please contact us immediately at [email protected]. Investment services require users to be legally competent adults, and we reserve the right to verify age and identity through appropriate means.
12. Data Security
We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, and destruction. Our security practices include:
- • Encryption: All sensitive data is encrypted using industry-standard SSL/TLS encryption both in transit and at rest.
- • Access Controls: Strict access restrictions ensure only authorized personnel can view sensitive information.
- • Firewalls and Intrusion Detection: Advanced security systems monitor and prevent unauthorized network access.
- • Regular Security Audits: We conduct regular security assessments and penetration testing to identify vulnerabilities.
- • Secure Passwords: We recommend using strong, unique passwords and enable two-factor authentication for account security.
While we implement robust security measures, no system is entirely secure. We encourage you to use strong passwords and keep your login credentials confidential. If you suspect unauthorized access to your account, please contact us immediately at [email protected].
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, regulations, and other factors. We will notify you of significant changes by posting the updated policy on our website and updating the "Last Updated" date. Your continued use of our website and services following such changes constitutes your acceptance of the updated Privacy Policy.
If we make material changes that significantly affect how we use your personal data, we will provide you with at least 14 days' notice before implementing these changes, allowing you time to review and decide whether to continue using our services.
14. Contact Information
If you have any questions about this Privacy Policy, your rights, or our data practices, please contact us using the information below. We are committed to addressing your concerns promptly.
Data Protection Officer: [email protected]
Company Address: InvestPro Limited, 125 Baker Street, London, W1U 6AR, United Kingdom
Phone: +44 20 7946 0958
Response Time: We aim to respond to all data subject requests within 14 days during normal business hours.