1. Who controls the data
The service provider identified in the engagement letter is the controller for client-project data. The website operator identity is pending verified owner details. Privacy requests may be sent to the address below. This policy covers website visitors, prospective clients, clients and persons connected with a proposed entity.
2. Data we collect
We may collect contact details, communications, business activity and ownership information, owner tax-residence information, service preferences, and technical or security logs. After a matter is accepted, proportionate KYC/KYB information may include identity, address, beneficial ownership, source-of-funds or source-of-wealth evidence. Sensitive documents are not requested through the public enquiry form.
3. Purposes and lawful basis
We use data to answer enquiries, assess conflicts and risk, define and perform an agreed service, coordinate instructed applications, keep records, secure the service, invoice, and comply with legal duties. Depending on the operator and activity, processing may rely on steps requested before a contract, performance of a contract, legal obligations, legitimate interests, or consent where required. The correct basis must be confirmed during legal review.
4. AML, KYC and recipients
Information may be checked for identity, beneficial ownership, sanctions, politically exposed person status, adverse media and business-risk purposes. Where instructed and necessary, data may be shared with company registries, banks, EMIs, payment providers, notaries, translators, registered agents, accountants, qualified local professionals, hosting/form providers and public authorities. Each third party may act under its own privacy notice.
5. International transfers
A cross-border project can require data to be accessed or processed outside the person’s country. The operator must assess the destination and use an applicable transfer mechanism or safeguard where law requires one. No transfer guarantee is made before the parties and jurisdictions are known.
6. Retention and security
Data is kept only as long as reasonably required for enquiry handling, the engagement, professional records, AML/KYC duties, disputes, tax/accounting records and security. Different categories may have different periods. Access controls, least-privilege practices, service-provider due diligence, backups and secure channels are used at a proportionate level, but no internet transmission is risk-free.
7. Your rights
Depending on applicable law, a person may request access, correction, deletion, restriction, portability, objection or withdrawal of consent, and may complain to the competent authority. Rights can be limited by legal-retention, AML, privilege, fraud-prevention or third-party obligations. Identity may be verified before a request is fulfilled.
8. Cookies, children and updates
Cookie and analytics practices are described in the Cookie Policy. The service is intended for adults acting for themselves or a business and is not directed to children. Material changes will be posted with a new review date; where appropriate, affected clients will be notified.
9. Questions or requests
Send a non-sensitive summary to warming-89-heels@icloud.com. Privacy requests may also be sent to warming-89-heels@icloud.com.