Privacy Policy
This policy explains what personal data Aureo Flowdex collects, why, who sees it, how long we keep it and what rights you have under UK GDPR and the Data Protection Act 2018. Aureo Flowdex is the controller of the personal data described here and can be reached at [email protected].
1. Definitions
Personal data means information that identifies you or can be used to identify you. Usage data is information collected automatically when you use the site, such as your device type and the pages you view. Cookies are small files stored on your device. The controller decides why and how personal data is used, and a processor handles it on the controller's behalf. In this policy, "we" and "us" mean Aureo Flowdex.
2. Information we collect and how we use it
When you register or contact us we collect your first name, last name, email address and mobile number, along with what you tell us in your messages or on calls. To verify your identity we also collect your date of birth, address, identity documents and a live photo. Once you trade, we process account activity, exchange connection details and payment information.
We use this information to create and run your account, to reply to your requests, to provide the service you asked for, to meet our legal duties and to keep the platform secure and working well.
3. Legal bases for using your data
We rely on contract where we need your data to provide the service you requested, on legal obligation for identity checks, record keeping and reporting under anti-money laundering law, and on legitimate interests for security, fraud prevention and improving the service, after weighing them against your rights. Marketing messages are sent only with your consent, which you can withdraw at any time.
4. Usage data and cookies
We collect technical details such as your IP address, browser type, pages visited and time spent. Strictly necessary cookies keep you signed in and the site secure and do not need consent. Under the Privacy and Electronic Communications Regulations, any analytics or marketing cookies are used only if you agree to them, and you can change your choice at any time in your browser.
5. Retention
We keep data only as long as it is needed for the purpose it was collected for. Identity and transaction records are kept for five years after our relationship ends, as the law requires. Account and contact data is kept while your account is open and for six years afterwards to deal with claims. Support emails are kept for three years, marketing preferences until you withdraw consent, and security logs for twelve months.
6. Transfers outside the UK
Some of our suppliers are located or process data outside the UK. When that happens we make sure your data keeps an equivalent level of protection, by relying on a UK adequacy decision or by using the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
7. Sharing and disclosure
We share personal data with identity verification providers, payment processors, IT and hosting suppliers, professional advisers and other companies in our group, always under contracts that limit what they can do with it. We also disclose data to regulators, the police, the National Crime Agency, HMRC or the courts where we are legally required to, and if our business is ever sold, to the buyer. We do not sell your data.
8. Security
We protect personal data with encryption in transit and at rest, access controls, staff training and regular testing. No method of transmission or storage is completely secure, so please look after your own password and see our Security page for what you can do.
9. Your rights
You have the right to access the data we hold about you, to have it corrected, to ask for it to be erased, to restrict or object to certain uses, and to receive a copy in a portable format. You can also object to direct marketing at any time. To use these rights, email [email protected]. We reply within one month. Some data, such as anti-money laundering records, must be kept by law, so we may not be able to erase it straight away.
10. Service providers
We use third-party companies to help us run the service, such as hosting, email delivery, identity verification, customer support software and payment handling. They may only use your data to carry out those services for us.
11. Analytics
If you accept analytics cookies, we may use an analytics service to understand how visitors use the site, which pages are helpful and where people get stuck. The results are used in aggregate to improve the site rather than to profile individuals.
12. Advertising and retargeting
If you consent to marketing cookies, advertising partners may show you our adverts on other websites based on your visit to ours. You can switch these cookies off in your browser or through the opt-out tools offered by the advertising platforms.
13. Links to other websites
Our site links to websites run by others. We are not responsible for their privacy practices, so please read their policies before sharing information with them.
14. Children's privacy
Our services are for people aged 18 and over. We do not knowingly collect data from children. If you think a child has given us personal data, contact us and we will delete it.
15. Changes to this policy
We update this policy when our practices or the law change. The current version is always on this page, and we will tell you about important changes by email or a notice on the site.
16. Contact us
For any privacy question, write to [email protected], quoting "Privacy" in the subject. If you are unhappy with our response, you have the right to complain to the Information Commissioner's Office, the UK data protection regulator.