1.1 This Privacy Policy explains how Snowflo Capital Ltd, a company registered in England and Wales under company number 16307119 with its registered office at International House, 10 Beaufort Court, Admirals Way, London, Greater London, England, E14 9XL ("Snowflow", "we", "us", "our"), collects, uses, shares and protects personal data.
1.2 It applies to the snowflow.co.uk website, to our business accounts, personal accounts, business debit card, online payment portal, foreign exchange and crypto trading services, and to the personal data we hold about our customers, prospective customers, website visitors and business contacts.
1.3 We are the data controller of the personal data described in this policy. We are committed to complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
2.1 Our Data Protection Officer can be contacted at info@snowflow.co.uk, or in writing at the registered office address above, marked for the attention of the Data Protection Officer.
2.2 Please contact the Data Protection Officer with any question about this policy, any request to exercise your rights, or any concern about how we handle personal data.
We may collect, use, store and transfer the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Identity and verification data | Full name, date of birth, nationality, government-issued ID, photograph, proof of address, tax identification number | You / identity verification providers |
| Contact data | Email address, telephone number, residential address | You |
| Financial and transaction data | Bank account details, payment card details, transaction history, foreign exchange conversions, crypto transactions, source of funds, source of wealth | You / payment providers / banks |
| Business data | Company name, company number, registered address, directors, shareholders, beneficial owners, nature of business | You / Companies House / due diligence providers |
| Account data | Username, account reference, customer reference number, account preferences | You |
| Communications data | Emails, chat messages, support tickets, telephone call recordings | You |
| Fraud and risk data | Sanctions screening results, politically exposed person checks, credit checks, fraud prevention data | Fraud prevention agencies / screening providers |
| Website and technical data | IP address, device and browser type, pages visited, referral source, cookie identifiers | Automatically, via cookies and logs |
3.1 We do not intentionally collect special-category data about you. If you volunteer such data, for example in a support message, we ask you not to, and we will process it only as necessary to respond to you.
Under UK GDPR we must have a lawful basis for each use of personal data. Our purposes and bases are:
| Purpose | Lawful basis |
|---|---|
| Verifying your identity and complying with anti-money laundering, counter-terrorist financing, sanctions and fraud prevention obligations | Legal obligation |
| Opening, administering and managing personal and business accounts | Performance of a contract; legal obligation |
| Providing business accounts, personal accounts, business debit cards, online payment portal, foreign exchange and crypto trading services | Performance of a contract |
| Processing transactions and payment instructions | Performance of a contract; legal obligation |
| Preventing fraud, unauthorised access and financial crime | Legal obligation; legitimate interests |
| Responding to enquiries, complaints and support requests | Performance of a contract; legitimate interests |
| Sending service and administrative messages, including security, billing and changes to terms | Performance of a contract; legal obligation |
| Improving and securing the website and services | Legitimate interests |
| Meeting legal, regulatory, tax and accounting obligations | Legal obligation |
4.1 Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights and freedoms. You may ask us for details of that assessment using the contact details above.
4.2 Where we rely on consent, for example non-essential cookies, you may withdraw it at any time without affecting the lawfulness of earlier processing.
5.1 We may send you information about Snowflow products and services where we are lawfully permitted to do so. Every marketing email contains an unsubscribe link, and you can opt out at any time by using it or by contacting us.
5.2 We will not sell your personal data.
We share personal data only where necessary and under appropriate contracts. Our categories of recipient are:
6.1 We place a written contract with every processor that contains the data protection terms required by Article 28 UK GDPR.
7.1 We aim to keep personal data within the UK. Where a service provider stores or accesses data outside the UK, we ensure an appropriate safeguard is in place, such as UK adequacy regulations, the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses.
7.2 You may request details of the safeguards in place for any specific transfer by contacting info@snowflow.co.uk.
8.1 We keep personal data only for as long as necessary for the purposes for which it was collected, and to meet legal and regulatory obligations.
8.2 Account and transaction data is kept for the duration of the relationship and then for [X] years after account closure, or longer where required by law or for legal proceedings.
8.3 Financial and tax records are kept for the minimum periods required by HMRC and company law.
You have the following rights under UK GDPR:
9.1 To exercise any right, contact info@snowflow.co.uk. We will respond within one month and may ask you to verify your identity. There is normally no charge.
10.1 We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, two-factor authentication, logging and monitoring, and staff confidentiality obligations.
10.2 No method of transmission or storage is completely secure. If we become aware of a personal data breach, we will act in accordance with our legal obligations, including notifying the Information Commissioner's Office and affected individuals where required.
Our website uses cookies and similar technologies. Please see our separate Cookie Policy for full details of which cookies we use, why, and how to manage your preferences.
12.1 We may update this policy from time to time. The current version is always available on our website, and we will notify account holders of material changes.
12.2 If you are unhappy with how we handle your data, please contact our Data Protection Officer first so we can try to resolve it. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk or by calling 0303 123 1113.
Your wishlist is empty.
