Perennial Financial Management Limited is committed to protecting the privacy of all individuals that it interacts with, and we therefore ask that you read this fair processing notice carefully. This explains how Perennial Financial Management Limited, and its Appointed Representatives collect, process, and use your personal information.
Perennial Financial Management Limited
Our services are provided through personal, face to face and telephone advisory services to Perennial Financial Management Limited clients. We ensure that any financial advisory services that we provide to you are delivered in accordance with the applicable regulatory requirements. Perennial Financial Management Limited is also responsible for managing any complaints that may be made by you in respect of the services we provide.
This Privacy Policy explains when and why we collect your personal information as part of our provision of financial advice and explains how we use your information. If requested, we will provide you with a copy of this Privacy Policy for your records.
“We”, “Us” “Our” refers to Perennial Financial Management Limited.
Where you are referred to a St. James’s Place partner practice, they will use your personal data, for example by conducting review meetings. This will be governed by their own Privacy Policy.
Appointed Representative firms of Perennial Financial Management Limited
Perennial Financial Management Limited acts as principal in its relationship with Appointed Representative firms, which means that we provide services and the regulatory and compliance framework in which they operate.
Where you have an adviser at one of our Appointed Representative firms, your adviser firm will provide your services and will process your personal information in accordance with its own Privacy Policy, which is available on their website.
Perennial Financial Management Limited will collect personal information about you as part of its role as principal, in order to ensure that our Appointed Representatives are compliant with applicable financial regulations. We do this by providing shared services, conducting audits, as well as dealing with any complaints you may have regarding individual firms.
1. About Us
For us to deliver such financial services and deal with any correspondence that may arise, we need to collect and process personal information. This makes us a “data controller”.
As the principal firm, Perennial Financial Management Limited will also have access to all personal information that our Appointed Representative firms collect and use; this means that Perennial Financial Management Limited is the joint “data controller” of your personal information along with your individual Appointed Representative firm and adviser.
2. Our processing of your personal information
Depending on our relationship with you (whether you are a prospective or existing client or a business partner), we will collect and use different personal information about you for different reasons.
Sometimes we will request or receive “special categories of personal information” (which is information relating to your health, genetic or biometric data, criminal convictions, sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership). For example, to better understand your current and potential future circumstances and recommend appropriate financial investments, we may need access to information about your health. Details about your health might also be needed for us to make reasonable adjustments when providing our services to you.
We also use details of any unspent criminal convictions for fraud prevention purposes.
Where you provide personal information to us about other individuals (for example, members of your family or other dependents) we will also be data controller of their personal information and responsible for protecting their personal information and using it appropriately. This notice will therefore apply to those individuals, and you should refer them to this notice.
To make this notice as user friendly as possible, we have split it into different sections. Please click on the section below that best describes your relationship with us.
2.1 Prospective Clients
This section will apply if you are a prospective client, and we will need certain information about you to carry out pre-client identification and compliance checks and to set you up as a client on our client relationship management system.
What personal information may we collect?
- General information such as your name, address, phone numbers and email addresses, date of birth and gender.
- Identification information including passport, driving licence, national identity card (for non-UK nationals), government issued ID verification and address verification documents such as council tax letters, bank statements and evidence of benefit entitlement.
- Employment information such as job title, employment history and professional accreditations.
- Financial information:
- Bank details
- Financial reviews (fact finds)
- Information relating to your personal finances such as your financial liabilities and assets, income, and outgoings
- Information obtained from carrying out identification checks and checking sanction lists and politically exposed persons (PEP) screening, including bankruptcy orders.
- Information relevant to the services we provide such as:
- previous and current investments
- information about your lifestyle
- attitude to investment risk
- existing plan details
- objectives
- copies of your will
- information about any trusts you have
- Information about your family including information about your dependants.
- Information such as IP address and browsing history obtained through our use of cookies. (You can find more information about this in our cookies policy in section 8 below).
- Information obtained during telephone recordings.
- Information we may have gathered from publicly available sources such as the electoral roll, internet search engines and social media sites such as LinkedIn where you have been flagged as a PEP and we need to carry out enhanced due diligence.
What special categories of personal information may we collect?
- Details about any criminal convictions and any related information which have been obtained from our sanctions checks and PEP screening. This will include information relating to any offences or alleged offences you have committed or any court sentences which you are subject to.
- We may collect details about your health which are relevant to your application (e.g., as part of a pension or income protection need, we may ask you about any medical conditions that affect you to establish whether you are deemed to be a vulnerable client) or where you have disclosed such information to us because it explains your risk appetite for investments.
- In limited circumstances, we may also collect other special categories of data as detailed on a separate consent form.
How will we collect your personal information?
We will collect information directly from you when:
- you enquire about or apply to receive our financial advice services; and
- you contact us by email, telephone and through other written and verbal communications.
We will also collect your personal information from:
- Your Adviser directly, and/ or Authorised Representative firm, if applicable
- Publicly available sources such as the electoral roll, court judgments, insolvency registers, internet search engines and social media sites.
- Product Providers and Product Provider Platforms
- Your St. James’s Place Partner, if applicable
- St. James’s Place group companies who will process your personal data in accordance with their Privacy Policy which can be found at www.sjp.co.uk/site-services/privacy
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “Lawful Basis” when we process your “personal information”:
- We need to use your personal information to enter into the client agreement, for example, we need to use your personal information to assess whether we can provide services to you and to set you up as a client on our client relationship management system.
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have a valid business reason to use your personal information, and which is necessary for our everyday business operations and activities, for example to keep records of investments and the reasoning behind such investments, to maintain business records, to carry out due diligence, to review our business models and undertake strategic and operational business analysis.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
When we use your “special categories of personal information”, we must have an additional “lawful basis” and we will rely on the following lawful basis in these circumstances:
- You have given your explicit consent to our use of your special categories of personal information. In some cases, we are not able to offer you certain advice or financial products unless we have your health information.
- There is a substantial public interest in the prevention and detection of unlawful acts, such as where we suspect fraud.
- We need to use such special categories of personal information to establish, exercise or defend legal rights, such as when we are facing legal proceedings or want to bring legal proceedings ourselves.
- It is in the substantial public interest to comply with regulatory requirements relating to unlawful acts and dishonesty – such as carrying out fraud, credit, and anti-money laundering checks
Purpose for processing
Purpose for processing | Lawful Basis for using your personal information | Lawful Basis for using your special categories of personal information |
---|---|---|
To verify your information | • It is necessary to enter into or perform your client agreement. • We have a valid business reason (to verify your identity). | • You have given us your explicit consent. • It is in the substantial public interest to prevent or detect unlawful acts (where we suspect fraud). • We need to establish, exercise, or defend legal rights. |
To comply with our legal or regulatory obligations. | • We need to use your information in order to comply with our legal obligations. | • We need to use your information in order to establish, exercise or defend legal rights. • It is in the substantial public interest to prevent or detect unlawful acts (where we suspect fraud). |
To set you up as a client on our client relationship management systems and to communicate with you in respect of your application and service preferences. | • It is necessary to enter into or perform your client agreement. • We have a valid business reason (to establish you as a client). | • You have given us your explicit consent. • It is in the substantial public interest to prevent or detect unlawful acts (where we suspect fraud). |
For business purposes and activities including maintaining business records, file keeping and strategic business planning. | • We have a valid business reason (to run our business efficiently and effectively). | • You have given us your explicit consent. • We need to use your information in order to establish, exercise or defend legal rights. |
To provide marketing information where you have provided your consent. | • You have given us your explicit consent. | • Not applicable |
To provide marketing information by post, by telephone and in other circumstances where we don’t require your consent. | • We have a valid business reason (to send you selected communications about other products and services we offer). | • Not applicable |
To provide improved quality, training, and security (for example, through recorded or monitored phone calls to our contact numbers or carrying out customer satisfaction surveys). | • We have a valid business reason (to develop and improve the products and services we offer). | • You have given us your explicit consent. |
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid purpose as set out above and we will only disclose it to the following parties:
- Your Adviser directly, and/ or Authorised Representative firm, if applicable
- Product Providers and Product Provider Platforms.
- Your St, James’s Place Partner, if applicable.
- St. James’s Place group companies, who will process your personal data in accordance with their Privacy Policy which can be found at www.sjp.co.uk/site-services/privacy.
- Third parties who provide sanctions checking services including SmartSearch.
- Compliance consultants including SJP Acquisition Services Limited and ‘The Consulting Consortium’ (TCC).
- Financial crime and fraud detection agencies.
- Our regulators including the Financial Conduct Authority and the Financial Ombudsman Service.
- Selected third parties in connection with any sale, transfer, or disposal of our business.
- Our insurers.
- The police, HMRC and other crime prevention and detection agencies.
- Third parties including self-employed contractors who we have entered into contractual arrangements with to provide services we need to carry out our everyday business activities such as business administration, partner support specialists who assist us with day to day business operations, document management providers, back office system providers, storage warehouses, IT suppliers, actuaries, auditors, lawyers, outsourced business process management providers, our subcontractors and tax advisers.
2.2 Existing clients
This section will apply if you currently receive financial services from us. This section will set out how we use your information.
What personal information may we collect?
- General information such as your name, address, phone numbers and email addresses, date of birth and gender.
- Identification information including passport, driving licence, national identity card (for non-UK nationals), government issued ID verification and address verification documents such as council tax letters or bank statement and evidence of benefit entitlement.
- Employment information such as job title, employment history and professional accreditations.
- Financial information:
- Bank details
- Financial reviews (fact finds)
- Information relating to your personal finances such as your financial liabilities and assets, income, and outgoings
- Information obtained from carrying out identification checks and checking sanction lists and politically exposed persons (PEP) screening, including bankruptcy orders or where you have been flagged as a PEP.
- Information relevant to the services we provide, such as:
- previous and current investments
- information about your lifestyle
- attitude to investment risk
- existing plan details
- objectives
- copies of your will
- information about any trusts you have
- Information contained in client review meeting records and file notes
- Information contained in any records held by previous independent financial advisers (otherwise known as IFAs) with whom you were previously a client, and which have been transferred to us when that IFA was acquired by St. James’s Place group companies, (For example, Perennial Financial Management Limited).
- Information about your family including information about your dependants.
- Information obtained during telephone recordings where applicable.
- Information such as IP address and browsing history obtained through our use of cookies. (You can find more information about this in our cookies policy in section 8 below).
- Your marketing preferences and details of your customer experience with us.
- Information which we have gathered from publicly available sources such as the electoral roll, internet search engines and social media sites where you have been flagged as a PEP and we need to carry out enhanced due diligence.
What special categories of information will we collect?
- Details about any criminal convictions and any related information which have been obtained from our sanctions checks and PEP screening. This will include information relating to any offences or alleged offences you have committed or any court sentences which you are subject to.
- We may collect details about your health which are relevant to your application (e.g. as part of a pension need we may ask you about any medical conditions that affect you to establish whether you are deemed to be a vulnerable client or where we are applying for income protection insurance we will need to ask you about any medical conditions and information about lifestyle choices such as whether you drink alcohol or smoke so that appropriate insurance can be obtained) or where you have disclosed such information to us because it explains your risk appetite for investments.
- In limited circumstances, we may also collect other special categories of data as detailed on a separate consent form.
How will we collect your personal information?
We will collect information directly from you when:
- you register to receive our services and complete and return to us all applicable application forms; and
- you contact us by email, telephone and through other written and verbal communications.
We will also collect your personal information from:
- Your Adviser directly, and/ or Authorised Representative firm, if applicable
- Publicly available sources such as the electoral roll, court judgments, insolvency registers, internet search engines and social media sites.
- Any records held by previous independent financial advisers (otherwise known as IFAs) with whom you were previously a client and any advisers of that IFA which have been transferred to us when that IFA was acquired by St. James’s Place group companies, including Perennial Financial Management Limited.
- Your St. James’s Place Partner, if applicable.
- Product Providers and Product Provider Platforms.
- St. James’s Place group companies.
- Third parties such as SmartSearch who provide anti money laundering and fraud prevention services who we have appointed to carry out electronic ID checks, sanctions and politically exposed persons checking services.
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “Lawful Basis” when we process your “personal information”:
- We need to use your personal information to enter into or perform the client agreement that we hold with you. For example, we need to use your personal information to provide our services, to arrange and implement recommendations, review your ongoing suitability of current arrangements and handle claims.
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have a valid business reason to use your personal information which is necessary for our everyday business operations and activities, for example to keep records of investments and the reasoning behind such investments, to maintain business records, to carry out due diligence, to review our business models and undertake strategic and operational business analysis.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
When we use your “special categories of personal information”, we must have an additional “lawful basis” and we will rely on the following Lawful Basis in these circumstances:
- You have given your explicit consent to our use of your special categories of personal information. In some cases, we are not able to offer you certain advice or financial products unless we have your relevant health information.
- There is a substantial public interest such as prevention and detection of fraud.
- We need to use such special categories of personal information to establish, exercise or defend legal rights, such as when we are facing legal proceedings or want to bring legal proceedings ourselves.
Purpose for processing
Purpose for processing | Lawful Basis for using your personal information | Lawful Basis for using your special categories of personal information |
---|---|---|
To carry out identification checks and checks against sanction lists and politically exposed persons (PEP) screening | • It is necessary to enter into your client agreement. • We have a valid business reason (to carry out necessary compliance checks). • We have a legal and regulatory obligation. | • It is in the substantial public interest to prevent or detect unlawful acts (where we suspect fraud). • We need to establish, exercise, or defend legal rights. • You have given us your explicit consent. |
To verify your information throughout the course of our services. | • It is necessary to enter into or perform your client agreement. • We have a legal and regulatory obligation. • We have a valid business reason (to verify your identity and to undertake client due diligence throughout the course of our relationship). | • You have given us your explicit consent. • It is in the substantial public interest to prevent or detect unlawful acts (where we suspect fraud). • We need to establish, exercise, or defend legal rights. |
To set you up as a client on our client relationship management system and to communicate with you in respect of your service preferences. | • It is necessary to enter into or perform your client agreement. • We have a valid business reason (to establish you as a client). | • You have given us your explicit consent. • It is in the substantial public interest to prevent or detect unlawful acts (where we suspect fraud). |
To provide services in accordance with your client agreement. | • It is necessary to enter into or perform your client agreement. • We have a valid business reason (to ensure that we fulfil our contractual obligations to clients). | • You have given us your explicit consent. • We need to use your information in order to establish, exercise or defend legal rights. |
To arrange and implement any of our recommendations e.g., investing into certain funds or arranging a product or insurance policy for you. | • It is necessary to enter into or perform your client agreement. • We have a valid business reason (to ensure that we fulfil our contractual obligations to clients). | • You have given us your explicit consent. • We need to use your information in order to establish, exercise or defend legal rights. |
To carry out annual reviews and reviews of ongoing suitability of your current arrangements | • It is necessary to enter into or perform your client agreement. • We have a valid business reason (to ensure that we are providing appropriate services according to your circumstances). | • You have given us your explicit consent. • We need to use your information in order to establish, exercise or defend legal rights. |
To prevent and investigate fraud. | • It is necessary to enter into or perform your client agreement. • We have a valid business reason (to prevent and detect fraud and other financial crime). | • We have a substantial public interest to prevent fraud • We need to use your information in order to establish, exercise or defend legal rights. |
To comply with our legal or regulatory obligations. | • We need to use your information in order to comply with our legal obligations. | • We need to use your information in order to establish, exercise or defend legal rights. • It is in the substantial public interest to prevent or detect unlawful acts (where we suspect fraud). |
To communicate with you and resolve any complaints that you might have. | • It is necessary to enter into or perform your client agreement. • We have a valid business reason (to communicate with you, record and investigate complaints and ensure that complaints are handled appropriately). • We need to use your information in order to comply with our legal and regulatory obligations. | • We need to use your information in order to establish, exercise or defend legal rights. |
To provide improved quality, training, and security (for example, through recorded or monitored phone calls to our contact numbers or carrying out customer satisfaction surveys). | • We have a valid business reason (to develop and improve the products and services we offer). | • You have given us your explicit consent. |
For business purposes and activities including maintaining business records, file keeping and strategic business planning. | • We have a valid business reason (to run our business efficiently and effectively). | • You have given us your explicit consent. • We need to use your information in order to establish, exercise or defend legal rights. |
To apply for and claim on our own insurance. | • We have a valid business reason (to maintain appropriate insurance) | • We need to use your information in order to establish, exercise or defend legal rights. |
To provide marketing information where you have provided your consent. | • You have given us your explicit consent. | • Not applicable |
To provide marketing information by post, by telephone and in other circumstances where we don't require your consent. | • We have a valid business reason (to send you selected communications about other products and services we offer) | • Not applicable |
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid purpose as set out above and we will only disclose it to the following parties:
- Third parties who provide a service in relation to the management of your investments or facilitate the arrangement of products we recommend such as product providers, portfolio and fund managers, insurers where you are buying income protection products. Where we have shared your personal information with these third parties, they will also be a data controller and responsible for how they use your personal information. Their uses of your personal information will be governed by their own fair processing notices.
- Your Appointed Representative firm, if applicable.
- Your St. James’s Place Partner, if applicable.
- Product Providers and Product Provider Platforms.
- St. James’s Place group who will process your personal data in accordance with their Privacy Policy which can be found www.sjp.co.uk/site-services/privacy
- Third parties who provide sanctions checking services including SmartSearch.
- Compliance consultants including SJP Acquisition Services Limited and ‘The Consulting Consortium’ (TCC)
- Financial crime and fraud detection agencies.
- Our regulators including the Financial Conduct Authority and the Financial Ombudsman Service.
- Selected third parties in connection with any sale, transfer, or disposal of our business.
- Our insurers.
- The police, HMRC and other crime prevention and detection agencies. Third parties and self-employed contractors who we have entered into contractual arrangements with to provide services we need to carry out our everyday business activities such as business administration, adviser support specialists who assist us with day to day business operations, document management providers, back office system providers, secure login and email providers, storage warehouses, IT suppliers, actuaries, auditors, lawyers, outsourced business process management providers, our subcontractors and tax advisers.
2.3 Clients’ family members, business associates or beneficiaries
This section will apply if your personal information has been provided to us by a client to explain their lifestyle and approach to investments and wealth management (for example if you are a spouse or partner, dependant mentioned in a will or trust document, another beneficiary a business partner) and will set out how we use your information.
What personal information may we collect?
- General information such as your name, address, phone numbers and email addresses, date of birth and gender.
- Your relationship to our client.
- Financial information relating to your financial liabilities, such as a property portfolio which is owned jointly between you and our client.
Any information which is relevant to the services we provide for our client.
What special categories of personal information may we collect?
- We may collect details about your physical and mental health which are relevant to the services we provide for our client (for example where you are the client’s partner, and you have a medical condition which means that you are unable to work and therefore our client has a higher need for investment return and a lower risk appetite).
- Information contained in any records held by previous independent financial advisers (otherwise known as IFAs) with whom your family member or business associate was previously a client, and which have been transferred to us when that IFA was acquired by St. James’s Place group companies.
- In limited circumstances, we may also collect information concerning your sex life or sexual orientation for example where you are in a civil partnership with our client.
How will we collect your personal information?
- Directly from our client.
- From documents directly provided to us by our client, such as wills or trust documents where you are listed as a dependant or employment related documents, and you are listed as a business partner of our client.
- From any records held by previous independent financial advisers (otherwise known as IFAs) with whom your family member or business associate was previously a client and from any advisers of that IFA which have been transferred to us when that IFA was acquired by St. James’s Place group companies, including Perennial Financial Management Limited.
- Their Adviser directly and/ or Appointed Representative firm, if applicable.
- Their St. James’s Place Partner, if applicable.
- St. James’s Place group companies who will process your personal data in accordance with their Privacy Policy which can be found at www. sjp.co.uk/site-services/privacy.
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “Lawful Basis” when we process your “personal information”:
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have a valid business reason to use your personal information which is necessary for our everyday business operations and activities, for example to keep records of investments and the reasoning behind such investments, to maintain business records, to carry out due diligence, to review our business models and undertake strategic and operational business analysis.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
When we use your “special categories of personal information”, we must have an additional “lawful basis” and we will rely on the following Lawful Basis in these circumstances:
- You have given your explicit consent to our use of your special categories of personal information which may have been provided to us by your family member, spouse, partner, or business associate who is our client.
- There is a substantial public interest such as prevention and detection of fraud.
- We need to use such special categories of personal information to establish, exercise or defend legal rights, such as when we are facing legal proceedings or want to bring legal proceedings ourselves.
Purpose for processing
Purpose for processing | Lawful Basis for using your personal information | Lawful Basis for using your special categories of personal information |
---|---|---|
To provide services to our clients | • We have a valid business reason (to fulfil our contractual obligations to our clients and advise on the most appropriate investments for their personal circumstances) | • You have given us your explicit consent, and this has been provided to us by our client. |
To prevent and investigate fraud. | • We have a valid business reason (to prevent and detect fraud and other financial crime). • We need to use your information in order to comply with our legal obligations. | • We have a substantial public interest to prevent fraud. • We need to use your information in order to establish, exercise or defend legal rights. |
To comply with our legal or regulatory obligations. | • We need to use your information in order to comply with our legal obligations. | • We need to use your information in order to establish, exercise or defend legal rights. • It is in the substantial public interest to prevent or detect unlawful acts (where we suspect fraud). |
For business purposes and activities including maintaining business records, file keeping and strategic business planning. | • We have a valid business reason (to run our business efficiently and effectively) | • You have given us your explicit consent, and this has been provided to us by our client. • We need to use your information in order to establish, exercise or defend legal rights. |
To provide marketing information where you have provided your consent. | • You have given us your explicit consent. | • Not applicable |
To provide marketing information by post, by telephone and in other circumstances where we don't require your consent. | • We have a valid business reason (to send you selected communications about other products and services we offer) | • Not applicable |
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid purpose as set out above and we will only disclose it to the following parties:
- Third parties who provide a service in relation to the management of our client’s investments or facilitate the arrangement of products we recommend such as product providers, portfolio and fund managers, insurers where our client is buying income protection products. Where we have shared your personal information with these third parties, they will also be a data controller and responsible for how they use your personal information. Their uses of your personal information will be governed by their own fair processing notices.
- Their Adviser and/ or their Appointed Representative firm, if applicable.
- Their St. James’s Place Partner, if applicable.
- Product Providers and Product Provider Platforms.
- St. James’s Place group companies, who will process your personal data in accordance with their Privacy Policy which can be found www.sjp.co.uk/site-services/privacy
- Compliance consultants including SJP Acquisition Services Limited and ‘The Consulting Consortium’ (TCC).
- Financial crime and fraud detection agencies.
- Our regulators including the Financial Conduct Authority and the Financial Ombudsman Service.
- Selected third parties in connection with any sale, transfer, or disposal of our business.
- Our insurers.
- The police, HMRC and other crime prevention and detection agencies. Third parties and self-employed contractors who we have entered into contractual arrangements with to provide services we need to carry out our everyday business activities such as business administration, adviser support specialists who assist us with day to day business operations, document management providers, back office system providers, secure login and email providers, storage warehouses, IT suppliers, actuaries, auditors, lawyers, outsourced business process management providers, our subcontractors and tax advisers.
2.4 Other Business Partners
If you are a business partner such as a products provider, portfolio or fund manager or contractor who carries out business functions on our behalf, this section will be relevant to you and sets out our uses of your personal information.
What personal information may we collect?
- General information such as your name, address, business phone numbers and email addresses.
- Employment information such as job title, business cards and professional accreditations.
- Information about your clients, your employees and the services and products you offer.
- Your bank details and information obtained from checking sanction lists and credit checks.
- Information which we have gathered from publicly available sources such as internet search engines and generally obtained as part of the due diligence process conducted by St. James’s Place group companies.
How will we collect your information?
- Directly from you.
- Our Adviser directly, or Appointed Representative, if applicable.
- St. James’s Place group companies.
- Publicly available sources such as internet search engines.
- From service providers who carry out sanctions checks.
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “Lawful Basis” when we process your “personal information”:
- We need to use your personal information to enter into or perform the contract that we hold with you.
- We have a legal or regulatory obligation to use such personal information. For example, we may be required to carry out certain background checks.
- We have a valid business reason to use your personal information which is necessary for our everyday business operations and activities, for example to keep records of investments and the reasoning behind such investments, to maintain business records, to carry out due diligence, to review our business models and undertake strategic and operational business analysis including reviewing the performance of our business partners.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
Purpose for Processing
Purpose for processing | Lawful Basis for using your personal information | Lawful Basis for using your special categories of personal information |
---|---|---|
To carry out fraud, credit, and anti-money laundering checks on you | • It is necessary to enter into a contract with you. • We have a valid business reason (to assess your suitability as a business partner). • We need to use your information in order to comply with our legal obligations. | • Not applicable |
To carry out due diligence on you. | • We have a valid business reason (to ensure that you can provide guarantees in terms of confidentiality and security measures you implement to protect the information we are sharing with you about our clients) | • Not applicable |
To comply with our legal or regulatory obligations. | • We need to use your information in order to comply with our legal obligations, for example to pay your invoices for the services you have provided. | • Not applicable |
For business purposes and activities including maintaining business records, file keeping and strategic business planning. | • We have a valid business reason (to run our business efficiently and effectively). | • Not applicable |
For compliance and monitoring purposes. | • It is necessary to enter into a contract with you. • We have a valid business reason (to ensure we are compliant and carrying out appropriate monitoring activities). | • Not applicable |
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid reason as set out above and we will only disclose it to the following parties:
- Perennial Financial Management Limited who will process your personal data in accordance with this Privacy Policy which can be found at http://www.perennial-financial.co.uk/privacy.
- St. James’s Place group companies, who will process your personal data in accordance with their Privacy Policy which can be found https://www.sjp.co.uk/site-services/privacy.
- Our agents or employees as appropriate.
- Third parties who provide sanctions checking services including SmartSearch.
- Our regulators including the Financial Conduct Authority and the Financial Ombudsman Service.
- Selected third parties in connection with any sale, transfer, or disposal of our business.
- Our insurers.
- Third parties including self-employed contractors who we have entered into contractual arrangements with to provide services we need to carry out our everyday business activities such as document management providers, back-office system providers, storage warehouses, IT suppliers, actuaries, auditors, lawyers, outsourced business process management providers, our subcontractors and tax advisers.
2.5 Users of our website
If you use our website, this section will be relevant to you and sets out our uses of your personal information.
What personal information may we collect?
- General information submitted via the website, for example where you provide your details in the contact section such as your name, contact details and company name.
- Information such as IP address and browsing history obtained through our use of cookies. You can find more information about this in our cookies policy in section 8 below.
How will we collect your personal information?
We will collect your information directly from our website.
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “lawful basis” when we process your “personal information”:
- We have a valid business reason to use your personal information, necessary for our everyday business operations and activities, for example to maintain business records and to monitor usage of the website.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid purpose as set out above and we will only disclose it to:
- Our financial Adviser and/ or Appointed Representative firm, if applicable.
- Your St. James’s Place Partner, if applicable.
- St. James’s Place group companies, who will process your personal data in accordance with their Privacy Policy which can be found www.sjp.co.uk/site-services/privacy.
- Third parties who we have entered into contractual arrangements with to provide services we need to carry out our everyday business activities such as IT suppliers and website providers.
3. Where you are a job applicant
This section will apply if you are a job applicant within Perennial Financial Management Limited.
What personal information may we collect?
- We have set out below the main categories of candidate personal information which we process in connection with our recruiting activities on a day-to-day basis:
Personal contact information (including your name, home address, personal telephone number(s) and personal e-mail address)
- Work history and other relevant experience including information contained in CV, cover letter or job application form
- Education information including degrees awarded, transcripts and other information provided in support of the job application
- Remuneration history
- Information collected during phone screenings and interviews
- Details regarding the type of employment sought, desired salary, willingness to relocate, job preferences, and other information related to compensation and benefits
- Reference information and information received from background checks (where applicable) including information provided by third parties
- Information related to previous applications to us or previous employment history with us
- Documents evidencing your right to work (including information about your immigration status where relevant)
- Date of birth
- Gender
- Information gathered through our monitoring of our IT systems, building access records and CCTV recording in relation to your communications with us and attendance at our premises
- Personal information which you otherwise voluntarily provide during the course of the recruitment process
- The majority of the personal information to be provided by you is mandatory in connection with our recruiting activities. Failure to provide mandatory personal information may affect our ability to accomplish the purposes stated in this Notice, including considering your suitability for employment and/or entering into an employment contract with you.
The list set out above is not exhaustive, and there may be other personal information which Perennial Financial Management Limited collects, stores and uses in the context of the application and recruitment process. Perennial Financial Management Limited will update this Notice from time to time to reflect any notable changes in the categories of personal information which it processes.
The majority of the personal information which we process will be collected directly from you. However, your personal information may also be provided to us by third parties, such as recruitment agencies, former employers, official bodies (such as regulators or the Disclosure and Barring Service) and/or medical professionals
What background checking do we undertake?
As part of our referencing and vetting procedures, we will contact certain third parties in order to verify your personal information (including personal information that you provide as part of the application and recruitment process). These third parties will include:
- Former employers, in order to verify your previous employment history
- Universities and/or other establishments for higher education that you attended, in order to verify your education history
- For specific roles we will undertake electronic ID checks, sanctions and politically exposed persons checks via a third-party agency
- We will also gather data from publicly available sources such as the electoral roll, court judgments, insolvency registers, internet search engines and social media sites.
We will only conduct background checking in relation to successful candidates that have accepted a conditional offer of employment with us, and we will specifically inform such candidates that we will be contacting these third parties in advance of doing so.
What will we use your personal information for?
Perennial Financial Management Limited uses your personal information for a variety of purposes to take steps necessary to enter into an employment contract with you, to comply with legal obligations or otherwise in pursuit of its legitimate business interests. We have set out below the main purposes for which candidate personal information is processed:
- To identify and evaluate job applicants, including assessing skills, qualifications, and experience
- Verifying candidate information and carrying out employment, background (including criminal records) and reference checks, where applicable, and in order to prevent fraud
- Communicating with you about the recruitment process and your application
- To comply with our legal, regulatory, or other corporate governance requirements
In addition to using your personal information to consider you for the role you applied for, we will retain and process your personal information for six months to inform you about, and to consider you for other roles that may be appropriate for you. If you do not want us to consider you for other roles which we consider may be appropriate for you, please inform your recruitment contact.
Again, this list is not exhaustive, and Perennial Financial Management Limited may undertake additional processing of personal information in line with the purposes set out above. Perennial Financial Management Limited will update this Notice from time to time to reflect any notable changes in the purposes for which its processes your personal information.
When will we share candidate personal information?
Perennial Financial Management Limited will share candidate personal information with other parties only in limited circumstances where this is necessary for the purposes of entering into an employment contract, to comply with a legal obligation, or otherwise in pursuit of its legitimate business interests as follows:
- recruitment agencies
- background vetting specialists
- occupational health providers and other medical professionals
- HMRC and/or any other applicable government body
- accountants, lawyers, and other professional advisers
- The Financial Conduct Authority and/or the Prudential Regulatory Authority and/or any other applicable regulatory body
- specialists undertaking psychometric & personality tests
Personal information is shared under the terms of a written agreement between Perennial Financial Management Limited and the third party which includes appropriate security measures to protect the personal information in line with this Notice and our obligations. The third parties are permitted to use the personal information only for the purposes which we have identified, and not for their own purposes, and they are not permitted to further share the data without our express permission.
What special category (sensitive) data do we collect?
Certain categories of data are considered “special categories of personal information” and are subject to additional safeguards. Perennial Financial Management Limited limits the special categories of personal information which it processes as follows:
Health Information
We may process information about a candidate’s physical or mental health in the course of the recruitment process. In particular:
- We will process information about an individual candidate’s physical or mental health to comply with our obligations to make reasonable adjustments for disabled employees as part of the recruitment process.
- as part of our pre-employment screening, successful candidates may be asked to complete a medical questionnaire administered by Health Assured Limited in order that we can take account of any medical issues relating to a new employee, including our obligation to make reasonable adjustments in the workplace. Health Assured Limited will only share information from this questionnaire with us with your express consent.
We will always treat information about health as confidential and it will only be shared internally where there is a specific and valid purpose to do so. We have implemented appropriate physical, technical, and organisational security measures designed to secure your personal information against accidental loss and unauthorised access, use, alteration, or disclosure.
If a candidate is successful, any health information processed as part of the recruitment process that is relevant to Perennial Financial Management Limited’s compliance with its obligations in connection with employment will be retained and processed in accordance with the Employee Privacy Notice. If a candidate is unsuccessful, any health information obtained as part of recruitment processes will be deleted with the rest of the candidate’s personal information within six months of their rejection.
How long do we keep personal information for?
Perennial Financial Management Limited’s policy is to retain personal information only for as long as needed to fulfil the purpose(s) for which it was collected, or otherwise as required under applicable laws and regulations. Under some circumstances we may anonymise your personal information so that it can no longer be associated with you. We reserve the right to retain and use such anonymous data for any legitimate business purpose without further notice to you.
For unsuccessful candidates:
- We will retain personal information collected during the recruitment process for a maximum period of 6 months from the end of the process subject to any exceptional circumstances and/or to comply with particular laws or regulations.
If you are offered and accept employment with us, some of the personal information we collected during the application and recruitment process will become part of your employment record and we may use it in connection with your employment in accordance with the Employee Privacy Notice. The remaining data will be stored for a period of 6 months then deleted.
4. What marketing activities do we carry out?
We carry out the following marketing activities depending on the relationship that we have with you:
Where you are a prospective client
We will use your personal information to provide you with information about our financial services and any newsletters and event invites where you have provided your consent for us to do so.
Where you are an existing client
We will use your personal information to provide you with information about our financial services and any newsletters and event invites where it is part of the ongoing financial advice services we offer or where you have provided your consent for us to do so.
General marketing practices
If you wish to opt out of marketing, you may do so by contacting us, responding to any marketing email communication confirming you would like to opt out or telling us when we call you. Otherwise, you can always contact us using the details set out in section 11 to update your contact preferences.
Please note that, even if you opt out of receiving marketing messages, we may still send you communications in connection with the services we offer you.
5. How long do we keep personal information for?
We will only keep your personal information for as long as reasonably necessary to fulfil the purposes set out in section 2 above, to comply with our legal and regulatory obligations or for as long as necessary to respond to concerns you raise with the advice you received. As a financial service firm, we are regulated by the Financial Conduct Authority (the FCA) who imposes certain record-keeping rules which we must adhere to.
If you would like further information regarding the periods for which your personal information will be stored, please contact us using the details set out in section 11.
6. What is our approach to sending your personal information overseas?
There are a small number of instances where your personal information is transferred to countries outside of the European Economic Area (“EEA“) such as when we transfer information to our other companies in the SJP group or to third party suppliers who are based outside the EEA or when third parties who act on our behalf transfer your personal information to countries outside the EEA. Where such a transfer takes place, we will take the appropriate safeguarding measures to ensure that your personal information is adequately protected. We will do so in a number of ways including:
- Entering into data transfer contracts and using specific contractual provisions that have been approved by European data protection authorities otherwise known as the “standard contractual clauses”. You can find out more about standard contractual clauses at https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en;
- We will only transfer personal information to companies in non-EEA countries who have been deemed by European data protection authorities to have adequate levels of data protection for the protection of personal information. You can find out more about this https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en
We are also entitled under European data protection laws to transfer your personal information to countries outside the EEA where it is necessary for the performance of the contract, we have with you.
Depending on our relationship and your particular circumstances, we might transfer personal information anywhere in the world.
If you would like further information regarding our data transfers and the steps, we take to safeguard your personal information, please contact us using the details set out in section 11.
7. How do we protect your information?
At Perennial Financial Management Limited, we take our responsibility to look after your personal information and privacy seriously. In today’s world, we have all seen a growing trend in cybercrime and security breaches. We have a number of security measures in place to help prevent fraud and cybercrime.
If we become aware that a personal data breach has occurred and is likely to result in a high risk to the rights and freedoms of our clients, advisers, or employees, we will inform them without undue delay.
We have a dedicated group, the ‘Information Security Oversight Committee’, that provides oversight and guidance to our information security and privacy programme.
The executive body responsible for privacy and data security is the Information Security Oversight Committee (ISOC) – chaired by the Data Protection Officer. ISOC has a reporting line that enables effective escalation of issues up to the Board where appropriate.
We educate and train our employees, Appointed Representatives and contractors on their information security, fraud prevention and privacy obligations annually.
Our employees and contractors take part in an annual Information Security training and awareness program and must agree to adhere to the Data Protection Act and our own Information Security Policy that are designed to keep your information safe. These are refreshed each year to reflect the current trends that are being observed across the information security landscape. Information Security awareness also forms part of our new employee induction program.
We also educate our employees in identifying potential financial crime and internal fraud; any suspicious activity is reported to our Financial Crime Prevention team.
We will always interact with you in a safe, secure, and consistent manner
To keep your information secure and to protect our clients from fraud, Perennial Financial Management Limited will only interact with you in the following ways. If in doubt, please call your Perennial Financial Management Limited or Appointed Representative Adviser directly for further information.
When interacting with you, we will:
- Only send funds that you have requested to be withdrawn to a verified bank account in your name.
- Verify who you are when speaking to you on the phone, by asking you security questions.
We will not:
- Ask you for your password over the phone.
- Ask you for credit card details by email or telephone.
- Call you to notify you of a problem, and then request you call us back immediately to discuss the problem further.
We continually review our physical and logical security controls in place across the business.
Physical controls – As well as protecting your digital information, Perennial Financial Management Limited also protects their premises and physical locations where personal data may be used and stored. These measures include security entrances, secure disposal of confidential waste and hardware, locks on doors and file storage cabinets, with a ‘clear desk’ policy to ensure all information is locked away and protected.
Logical controls – Perennial Financial Management Limited uses technical security measures to make sure our systems where we store and use personal information are protected from unauthorised access. Tools such as authentication controls, antivirus, firewalls, malware detection and back-up procedures are used across the business.
All employee emails and devices are encrypted to enable secure transfer and storage of personal information.
We conduct security testing of our applications and services in a controlled testing environment before they are made available for our clients to use on an ongoing basis.
We perform security risk assessments for each of our sites to identify and control risks.
External technical assessments are conducted by an independent external 3rd party.
Security audits and vendor due diligence are conducted on a continual basis.
We have a business resiliency plan with disaster recovery and business continuity testing.
The purpose of Business Continuity Management and the Perennial Financial Management Limited Business Continuity Plan is to provide an effective, predefined, and documented framework to respond to an incident affecting our activities. The key drivers in developing the business recovery plans are.
- To mitigate the risks that could lead to the significant disruption of our products and services to our clients.
- To provide a recovery plan that supports a timely and full restoration of our products and services for our clients.
However, whilst we take appropriate technical and organisational measures to safeguard your Personal Information, please note that we cannot guarantee the security of any data that you transfer over the internet to us.
8. Cookies
Our website uses cookies – small text files that are stored on your computer or in your browser – to help us to monitor how visitors use our site and allow us to maintain the optimum experience for website users. The website does not store or capture personal information about you when you visit it, it merely records traffic information. This means information about all of our visitors collectively, for example the number of visits the website receives. In order to respect our visitors’ rights of privacy, this information is anonymous, and no individual visitor can be identified from it.
You can disable and delete cookies by changing the appropriate setting within your browser’s ‘Help’, ‘Tools’ or ‘Settings’ menu.
9. Monitoring
Please note that if you communicate with us electronically, including by e-mail, telephone or fax, this communication may be randomly monitored and/or recorded to protect the interests of our business and our customers. This includes for the purposes of maintaining customer/service quality standards, detection of and/or prevention of crime and to ensure that Perennial Financial Management Limited employees comply with legal obligations and Perennial Financial Management Limited policies and procedures (including our customer relations practices).
10. Your rights
You have several rights which you can exercise at any time relating to the personal information that we hold about you and use in the ways set out in this notice. Please contact us at any time using the details set out in section 11 if you wish to exercise these rights; we will not usually charge you.
We respect your rights and will always consider and assess them but please be aware that there may be some instances where we cannot comply with a request that you make as the consequence might be that:
- in doing so we could not comply with our own legal or regulatory requirements for example we are under obligations to hold records of our dealings with you for certain periods of time; or
- in doing so we could not provide services to you and would have to cancel your client agreement, for example we could not enter into investments on your behalf if we had deleted your personal information.
We will of course inform you if any of the above situations arise and if we are unable to comply with your request.
The right to access your personal information
You are entitled to a copy of the personal information we hold about you and certain details of how we use it.
We are happy to provide you with such details but in the interests of confidentiality, we follow strict disclosure procedures which may mean that we will require proof of identify from you prior to disclosing such information.
We will usually provide your personal information to you in writing unless you request otherwise. Where your request has been made electronically (e.g., by email), a copy of your personal information will be provided to you by electronic means where possible.
It would be helpful if you could please complete the Data Subject Request Form available from Perennial Financial Management Limited directly, or your Appointed Representative firm, if applicable, to request a copy of the information we hold so that we can ensure we have all the relevant information we need to appropriately respond to your request.
The right to rectification
Please help us to keep your personal information accurate and up to date so if you believe that there are any inaccuracies, discrepancies, or gaps in the information we hold about you, please contact us and ask us to update or amend it.
The right to restriction of processing
In certain circumstances, you have the right to ask us to stop using your personal information, for example where you think that the personal information that we hold about you may be inaccurate or where you think that we no longer need to use your personal information.
The right to withdraw your consent
Where we rely on your consent to process your personal information, you have the right to withdraw such consent to further use of your personal information.
The right to erasure
You are entitled to request your personal information to be deleted in certain circumstances such as where we no longer need your personal information for the purpose for which it was originally collected it. When you exercise this right, we need to consider other factors such as our own regulatory obligation, to assess whether we can comply with your request.
The right to object to direct marketing
You have a choice about whether or not you wish to receive marketing information from us and you have the right to request that we stop sending you marketing messages at any time. You can do this by contacting us using the details set out in section 11.
Please note that, even if you opt out of receiving marketing messages, we may still send you communications which are relevant to the nature of services we offer you.
The right to object to processing
In certain circumstances, where we only process your personal data because we have a legitimate business need to do so, you have the right to object to our processing of your personal data.
The right to data portability
In certain circumstances, you can request that we transfer personal information that you have provided to us to a third party.
When you exercise this right, we need to consider other factors such as our own regulatory obligations, to assess whether we can comply with your request
Rights relating to automated decision-making
We do not carry out any automated decision making to provide products and services to you.
The right to make a complaint with the ICO
If you believe that we have breached data protection laws when using your personal information, you have a right to complain to the Information Commissioner’s Office (ICO).
You can visit the ICO’s website at https://ico.org.uk/ for more information. Please note that lodging a complaint will not affect any other legal rights or remedies that you have.
11. Contacting us
If you would like any further information about any of the matters in this notice or if you have any other questions about how we collect, store, or use your personal information, you may contact our Principal firm’s Data Protection Officer at Perennial Financial Management Limited, St. James’s Place House, 1 Tetbury Road, Cirencester, Gloucestershire, GL7 1FP, [email protected] or 01285 878 453.
12. Updates to this notice
From time to time, we may need to make changes to this notice, for example, as the result of changes to law, technologies, or other developments. We will provide you with the most up to date notice.
This notice was last updated on 13th May 2022.