Privacy & AI-Use Notice

How [Firm name] handles your personal information, including where artificial intelligence is used.
Firm to finalise: this notice is a template. Replace the bracketed items and reconcile it with your adopted Privacy Notice and AI Governance Procedure before publishing. It is written to satisfy UK GDPR Articles 13–14 transparency, including the specific disclosure of automated tools recommended by your DPIA.

1. Who we are

[Firm name] ("we", "us") is the data controller for the personal information we hold about you. We are authorised and regulated by the Financial Conduct Authority (FCA no. [FCA number]). You can contact us at [email] or [address]. Our Data Protection point of contact is [name/role].

2. What information we hold

To provide financial advice and ongoing service we hold information such as your identity and contact details, financial circumstances (income, expenditure, assets, liabilities, pensions, protection), objectives, attitude to risk and capacity for loss, meeting notes and recordings, and — where relevant to your needs — health and vulnerability information (a special category of data).

3. How we use artificial intelligence

We use AI tools to help us work more efficiently. AI never makes decisions about your finances — a qualified adviser reviews, edits and is responsible for everything produced. Specifically:

  • Drafting documents — we use Anthropic's Claude to help draft suitability reports, review packs and meeting summaries from the information in your file. The adviser checks and finalises every document.
  • Transcribing meetings — where you consent to a meeting being recorded, we use OpenAI's Whisper to transcribe the audio into text so we can capture an accurate record.

Your data is not used to train these AI models. We use them under business terms that prohibit training on our data. Meeting audio is processed in memory to produce the transcript and is not stored; the resulting transcript is kept as part of your client record. These providers may process data outside the UK (including the United States); we rely on appropriate safeguards (such as the UK Addendum to the EU Standard Contractual Clauses / the UK Extension to the EU-US Data Privacy Framework) — [confirm the mechanism you have in place per provider].

4. Why we can use your information (lawful bases)

5. Who we share it with

We share information only as needed to serve you — for example with product and platform providers, and with our technology sub-processors (including the AI providers named above and our hosting provider). We do not sell your data.

6. How long we keep it

We keep your information for as long as you are a client and afterwards for the period required by our regulatory and legal obligations (typically at least six years, and longer for certain pension and long-term products). [Confirm your retention schedule.]

7. Your rights

You have the right to access your information, to have it corrected or erased, to restrict or object to its use, and to data portability, subject to our regulatory record-keeping duties. Where we rely on consent, you can withdraw it at any time. To exercise any right, contact us at [email]. You can also complain to the Information Commissioner's Office (ico.org.uk).

Last updated [date] · Return to sign in