Privacy Policy

Last updated: January 2024

1. Introduction

Butler Family Investments Limited (“we”, “us”, “our” or the “Company”) is committed to protecting and respecting your privacy. We are a private limited company incorporated in England and Wales (Company No. 11650000) with our registered office at Suite 1, First Floor, 1 Duchess Street, London, W1W 6AN.

This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit our website, use our services, or otherwise interact with us. It also describes your rights in relation to your personal data and how you can exercise them.

We are the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our responsibilities under data protection legislation seriously and are committed to ensuring that the personal data we process is handled lawfully, fairly, and transparently.

By using our website or engaging with our services, you acknowledge that you have read and understood this Privacy Policy. We encourage you to read this document carefully and contact us if you have any questions.

2. Information We Collect

We may collect and process the following categories of personal data:

2.1 Personal Identification Information

  • Full name, title, and date of birth
  • Email address and telephone number(s)
  • Residential and/or business address
  • National Insurance number or other government-issued identification numbers (where required for regulatory purposes)
  • Passport or driving licence details (for identity verification and anti-money laundering compliance)
  • Nationality and country of residence

2.2 Financial Information

  • Bank account details and payment information
  • Investment history and portfolio information
  • Source of funds and source of wealth documentation
  • Tax identification numbers and tax residency status
  • Credit history and financial standing (where relevant to our services)
  • Income, net worth, and investment experience details

2.3 Technical and Usage Data

  • Internet Protocol (IP) address and browser type
  • Operating system and device information
  • Pages visited, time spent on pages, and navigation paths
  • Referring website addresses and search terms used
  • Date and time of access and frequency of visits
  • Click-stream data and interaction patterns

2.4 Cookie Data

We use cookies and similar tracking technologies to collect information about your browsing activity on our website. For detailed information about the cookies we use, please refer to Section 9 of this Privacy Policy.

2.5 Communications Data

  • Records of correspondence between you and the Company, including emails, letters, and telephone call records
  • Feedback, survey responses, and any other information you voluntarily provide to us
  • Meeting notes and records of discussions relating to our services

3. How We Use Your Information

We use the personal data we collect for the following purposes:

3.1 Provision of Client Services

  • To provide, manage, and administer our investment management, wealth management, and advisory services
  • To process applications, transactions, and investment instructions
  • To prepare and deliver portfolio reports, performance statements, and capital call notices
  • To conduct suitability assessments and ensure our services are appropriate for your circumstances
  • To manage your account and maintain accurate records

3.2 Communications

  • To respond to your enquiries, requests, and correspondence
  • To provide you with information about our services, market updates, and investment opportunities that may be of interest to you
  • To send administrative communications, including changes to our terms, policies, or services
  • To invite you to events, seminars, or other activities organised by the Company

3.3 Legal and Regulatory Obligations

  • To comply with applicable laws, regulations, and regulatory guidance, including anti-money laundering (AML) and counter-terrorist financing (CTF) requirements
  • To conduct know-your-customer (KYC) and customer due diligence (CDD) checks
  • To report to regulatory authorities, tax authorities, and law enforcement agencies as required by law
  • To maintain records as required by financial services regulations

3.4 Legitimate Business Interests

  • To improve and develop our website, services, and client experience
  • To analyse usage patterns and trends to enhance our offerings
  • To protect our business, assets, and reputation
  • To prevent and detect fraud, unauthorised access, and other illegal activities
  • To enforce our legal rights and resolve disputes

4. Legal Basis for Processing

Under the UK GDPR, we must have a valid legal basis for processing your personal data. We rely on the following legal bases:

4.1 Consent

Where you have given us clear, informed, and unambiguous consent to process your personal data for specific purposes, such as receiving marketing communications or the use of non-essential cookies. You have the right to withdraw your consent at any time by contacting us using the details provided in Section 12.

4.2 Performance of a Contract

Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes processing required to provide our investment management and advisory services.

4.3 Legal Obligation

Where processing is necessary for compliance with a legal obligation to which we are subject, including obligations under financial services regulations, anti-money laundering legislation, tax reporting requirements, and other applicable laws.

4.4 Legitimate Interests

Where processing is necessary for the purposes of our legitimate interests or those of a third party, provided that such interests are not overridden by your fundamental rights and freedoms. Our legitimate interests include the effective management and improvement of our business, the prevention of fraud, and the maintenance of the security of our systems and services.

5. Data Sharing

We take the confidentiality of your personal data seriously. We do not sell, rent, or trade your personal data to third parties for marketing purposes. We will never sell your data.

We may share your personal data with the following categories of recipients where necessary:

5.1 Legal and Regulatory Requirements

We may disclose your personal data to regulatory authorities, tax authorities, law enforcement agencies, courts, and other governmental bodies where we are required to do so by law or regulation, or where such disclosure is necessary to protect our legal rights.

5.2 Service Providers

We may share your personal data with carefully selected third-party service providers who assist us in operating our business and delivering our services. These may include IT service providers, cloud hosting providers, payment processors, custodians, fund administrators, and compliance screening providers. All service providers are contractually bound to process your data only on our instructions and in accordance with applicable data protection legislation.

5.3 Professional Advisors

We may share your personal data with our professional advisors, including lawyers, accountants, auditors, and insurers, where necessary for the provision of their professional services to us.

5.4 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy.

6. International Transfers

Your personal data may be transferred to, stored in, or processed in countries outside the United Kingdom and the European Economic Area (EEA). Where such transfers occur, we will ensure that appropriate safeguards are in place to protect your personal data in accordance with the UK GDPR, including:

  • Transfers to countries that have been deemed to provide an adequate level of data protection by the UK Secretary of State
  • The use of standard contractual clauses approved by the Information Commissioner’s Office (ICO) or the European Commission
  • Binding corporate rules or other legally recognised transfer mechanisms
  • Where applicable, your explicit consent to the transfer

You may request further information about the safeguards we have in place for international data transfers by contacting us using the details in Section 12.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, accounting, or reporting requirements.

In determining the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, whether we can achieve those purposes through other means, and applicable legal, regulatory, and contractual requirements.

As a general guide:

  • Client records and transaction data: We are required to retain these for a minimum of five years after the end of the business relationship, in accordance with anti-money laundering regulations. Certain records may be retained for longer periods where required by other regulatory obligations.
  • Marketing and communications data: We retain this data until you withdraw your consent or unsubscribe, after which we will retain only sufficient information to ensure we respect your preferences.
  • Website usage data: We typically retain this data for up to 26 months from the date of collection.
  • Recruitment data: We retain unsuccessful applicant data for up to 12 months following the conclusion of the recruitment process, unless you consent to a longer retention period.

When your personal data is no longer required, we will securely delete or anonymise it in accordance with our data retention and disposal procedures.

8. Your Rights

Under the UK GDPR, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to certain conditions and exemptions:

8.1 Right of Access

You have the right to request a copy of the personal data we hold about you, together with information about how and why we process it. This is commonly known as a “subject access request”. We will respond to your request within one month of receipt, unless the request is complex or numerous, in which case we may extend this period by a further two months.

8.2 Right to Rectification

You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete personal data completed.

8.3 Right to Erasure

You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw your consent, or where the data has been unlawfully processed. Please note that this right is not absolute, and we may be required to retain certain data to comply with legal or regulatory obligations.

8.4 Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where the processing is unlawful, or where we no longer need the data but you require it for the establishment, exercise, or defence of legal claims.

8.5 Right to Data Portability

Where we process your personal data on the basis of your consent or for the performance of a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

8.6 Right to Object

You have the right to object to the processing of your personal data where we rely on legitimate interests as our legal basis, or where we process your data for direct marketing purposes. Where you object to processing for direct marketing, we will cease such processing immediately.

8.7 Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently make decisions based solely on automated processing.

To exercise any of these rights, please contact us using the details provided in Section 12. We may need to verify your identity before processing your request. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

9. Cookies

Our website uses cookies and similar tracking technologies to distinguish you from other users, to enhance your browsing experience, and to help us improve our website.

9.1 Essential Cookies

These cookies are strictly necessary for the operation of our website. They enable core functionality such as security, network management, and accessibility. You cannot opt out of these cookies as the website cannot function properly without them.

9.2 Analytics Cookies

We use analytics cookies to collect information about how visitors use our website, including the number of visitors, the pages they visit, and the sources from which they arrived. This data helps us understand how our website is being used and to identify areas for improvement. All information collected by these cookies is aggregated and therefore anonymous.

9.3 Preference Cookies

These cookies allow our website to remember choices you make, such as your language preference or the region you are in, and to provide enhanced, more personalised features. The information collected by these cookies may be anonymised and they cannot track your browsing activity on other websites.

9.4 Managing Cookies

You can manage your cookie preferences through your browser settings. Most browsers allow you to refuse or accept cookies, delete existing cookies, and set preferences for certain websites. Please note that disabling certain cookies may affect the functionality of our website. You can also manage your cookie preferences using the cookie banner displayed when you first visit our website.

10. Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include, but are not limited to:

  • Encryption of personal data in transit and at rest using industry-standard protocols
  • Secure access controls, including multi-factor authentication and role-based access permissions
  • Regular security assessments, penetration testing, and vulnerability scanning
  • Staff training on data protection and information security best practices
  • Incident response procedures to address any data breaches promptly and effectively
  • Physical security measures at our offices and data storage facilities
  • Regular review and updating of our security policies and procedures

While we strive to protect your personal data, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your data, but we are committed to maintaining the highest practicable standards of data security.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. Any changes will be posted on this page with an updated “Last updated” date. Where changes are significant, we will endeavour to notify you directly, for example by email or through a prominent notice on our website.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website or services following the posting of changes constitutes your acceptance of those changes.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer:

If you are not satisfied with our response to any data protection concern you may have, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection. The ICO can be contacted at:

  • Website: ico.org.uk
  • Telephone: 0303 123 1113
  • Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF