Client Privacy Policy
How we handle your data
Who we are
Navigatus Limited is an outsourced paraplanning firm. We work on behalf of financial adviser firms to help them prepare research, reports and other documentation for their clients.
We are registered in England and Wales under company number 10711405. Our registered address is Suite B, 36 Endless Street, Salisbury, SP1 3UH.
Navigatus is not authorised or regulated by the Financial Conduct Authority. We do not provide financial advice.
Our role in relation to your data
If your financial adviser uses Navigatus to support the services they provide to you, your adviser may share your personal information with us so that we can carry out work on their behalf.
In this arrangement, your financial adviser (or their firm) is the data controller. They decide why and how your personal data is used. Navigatus acts as a data processor, which means we only process your data on the instructions of your adviser’s firm and in accordance with a written data processing agreement.
We do not use your personal data for our own purposes, and we will never contact you directly, unless specifically instructed by your adviser.
What personal data we may process
Depending on the work your adviser asks us to carry out, we may process some or all of the following:
- Your name, contact details, date of birth and gender
- Employment and salary information
- Financial information, including details of pensions, investments, savings and bank accounts
- Health information, where relevant to the advice being provided (for example, for protection advice or investment advice where medical underwriting is required)
- Family circumstances, including information about your partner, children, dependants or other family members, where relevant to the financial planning work
Special category data
Some of the information we process on your adviser’s behalf may include health information, which is classified as special category data under UK data protection law. This type of data is given additional protection.
We only process health information where it is necessary for the paraplanning work your adviser has asked us to carry out, and only in accordance with their instructions. Your adviser, as the data controller, is responsible for ensuring there is an appropriate legal basis for sharing this information with us.
We apply additional safeguards when handling special category data, including restricting access to team members who need it for the specific case and ensuring it is stored securely.
Why we process your data
We process your personal data solely to provide paraplanning, research and administration services to your financial adviser on their behalf. This may include preparing suitability reports, conducting investment research, carrying out pension or tax calculations, and producing other documentation to support the advice process.
The legal basis for our processing is the written contract between Navigatus and your adviser’s firm (Article 6(1)(b) of the UK GDPR, as it relates to the performance of our contract with the adviser).
Who we share your data with
In the course of providing our services, your data may be accessed by or shared with the following types of third-party service providers, each of which is bound by appropriate contractual safeguards:
- Project management and collaboration tools (used to organise and track client work)
- Customer relationship management systems (used to manage case information)
- Financial planning and cashflow modelling software
- Investment research and analysis platforms
- Pension analysis and comparison tools
- Protection quotation and comparison tools
- Accounting and time-tracking software (which may reference client names for billing purposes)
- Cloud-based document storage and email systems
- IT support providers (with access to systems for maintenance purposes)
A full list of our current sub-processors is maintained and made available to adviser firms under our client agreement. If you would like details of the specific sub-processors used in relation to your data, please contact your financial adviser in the first instance.
International transfers
Some of the tools and platforms we use may store or process data outside the UK and the European Economic Area. Where this is the case, we ensure that appropriate safeguards are in place in accordance with UK data protection law. Details of any international transfers are documented in our agreements with adviser firms.
How we keep your data safe
We take the security of your personal data seriously. We maintain appropriate technical and organisational measures to protect your data against unauthorised access, loss or damage. These measures are reviewed regularly and updated as necessary.
Navigatus holds Cyber Essentials Plus certification, which is a UK government-backed scheme that independently verifies our IT security controls. This includes testing of our systems against common cyber threats such as malware, phishing and unauthorised access.
We also hold cyber liability insurance to support our response in the unlikely event of a data security incident.
How long we keep your data
We retain your personal data only for as long as necessary to provide our services to your adviser’s firm. On termination of our agreement with your adviser, we will securely destroy all personal data we hold.
Regulatory registration
Navigatus Limited is registered with the Information Commissioner’s Office (ICO) as a data processor. Our registration number is ZA449965. You can verify our registration on the ICO’s public register at ico.org.uk.
Your rights
Under UK data protection law, you have rights in relation to your personal data, including the right to access, correct, delete or restrict the processing of your data. Because Navigatus acts as a data processor, any requests relating to your personal data should be directed to your financial adviser in the first instance. We will assist your adviser in responding to any such requests.
If you are not satisfied with how your personal data has been handled, you have the right to complain to the Information Commissioner’s Office:
- Address: Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Telephone: 0303 123 1113
- Website: ico.org.uk
Contact us
If you have any questions about how Navigatus handles personal data, you can contact us at:
- Address: Navigatus Limited Suite B, 36 Endless Street, Salisbury, SP1 3UH
- Email: hello@navigatus.co.uk
- Telephone: 01722 548 840