Privacy Policy

Introduction.

Maintaining your privacy is important to us. You entrust us with sensitive information, and we take that responsibility seriously. We will only share your personal data as described in this policy, and we will never sell your personal data.

This Privacy Policy explains how we collect, store, use and share personal data when we provide services to our clients, when you use our websites, and when you otherwise interact with us. It should be read together with any other privacy notice or fair processing notice we give you for a specific purpose – this policy supplements those notices and does not override them.

If you have any questions after reading it, please contact us using the details in the How to contact us section.

WHO WE ARE.

This policy is issued on behalf of the Cosegic group of companies. When we say “we”, “us” or “our”, we mean Cosegic Limited (company number 04954156) and its group companies and brands, including FINTRAIL Ltd (company number 09937817) and the FinTech FinCrime Exchange (FFE).

Cosegic Limited is the data controller responsible for our websites (cosegic.com, fintrail.com). For the other personal data described in this policy, the controller is the group company you are dealing with. Where Cosegic Limited and FINTRAIL Ltd decide together how your data is used, they act as joint controllers (see Sharing within our group).

Depending on the service:

  • We act as a data controller where we decide how and why your personal data is processed – for example, when you use our websites, subscribe to our communications, apply for a role, or engage us directly for advice.
  • We act as a data processor where we process personal data on behalf of, and under the instructions of, a client – for example, when a client provides personal data to us so we can deliver a compliance, financial crime or regulatory service. In those cases, the client is the controller and their own privacy notice will also apply.

We are registered with the Information Commissioner’s Office (ICO):

  • Cosegic Limited — registration number Z8799216
  • FINTRAIL Ltd — registration number ZA177597

WHO THIS POLICY APPLIES TO.

This policy applies to anyone who shares personal data with us, including when you:

  • Visit or use our websites and complete a form;
  • Contact us by any means to enquire about us or our services;
  • Engage with our marketing emails or social media;
  • Subscribe to our newsletters or services;
  • Engage us to provide services, or access one of our client portals (for example MyCosegic, PortALL or CMP);
  • Join our community of financial crime professionals, the FinTech FinCrime Exchange (FFE);
  • Purchase a product or service from us; or
  • Apply to work with us.

Other data controllers (including our clients) may also provide your personal data to us.

THE PERSONAL DATA WE COLLECT.

Personal data means any information from which a living individual can be identified. The types of personal data we may collect include:

  • Identity and Contact Data – title, full name (and former name if applicable), date of birth, email address, telephone numbers and postal address;
  • Professional Data – your job title, employer name and membership (for example if you are an FFE member);
  • Financial and Transactional Data – bank account and related payment details, details of payments to and from you, and of the products and services you have purchased from us;
  • Behavioural and Technical Data – information about how you use our websites, products and services, and the devices and technology you use (e.g. IP address);
  • Marketing and Communications Data – your preferences for receiving marketing from us and your communication preferences;
  • Recruitment Data – information you provide when applying to work with us, such as your CV, employment history and qualifications.

We also collect aggregated data (statistical or demographic data such as the percentage of users accessing a particular website feature). Aggregated data does not directly or indirectly identify you. If we combine it with your personal data so that you can be identified, we treat the combined data as personal data.

SPECIAL CATEGORY AND CRIMINAL OFFENCE DATA.

Given the nature of our work in compliance and financial crime, we may in some circumstances process special category data (for example, data revealing racial or ethnic origin, or political opinions) and data relating to criminal convictions and offences or alleged offences – for example when delivering financial crime, anti-money laundering, fraud, sanctions or screening-related services, whether as a controller or on behalf of a client, or when carrying out pre-employment checks.

Where we do so, we will only process this data where the law allows, we will identify an appropriate lawful basis and condition for processing, and we will apply additional safeguards. Where a client provides this data to us to deliver a service, the client remains responsible as controller for having a lawful basis to share it with us.

HOW WE COLLECT YOUR PERSONAL DATA.

We collect personal data:

  • Directly from you – when you: (1) use our website or services, (2) correspond with us by post, phone, email, etc, (3) apply for our products or services, (4) subscribe to our service or newsletters, (5) request marketing communications, and (6) give us feedback;
  • Automated technologies or interactions – when we automatically collect data about your equipment, browsing behaviour and patterns when you use our website. We might use cookies and similar technologies to do this (see the Cookies section); and
  • From third parties and public sources – including our clients, publicly available sources, and background/onboarding checks (for example where you are a job applicant or where required to deliver a service).

THE LEGAL BASES WE RELY ON.

Data protection law allows us to process your personal data only where we have a lawful basis. Depending on the situation, we rely on:

  • Consent – where you have given clear consent for a specific purpose (for example, ticking a box to receive newsletters). You can withdraw consent at any time.
  • Contract – where processing is necessary to perform a contract with you, or to take steps at your request before entering into a contract (for example, managing an FCA authorisation application you have instructed us on).
  • Legal obligation – where we need to process your data to comply with our legal or regulatory obligations.
  • Legitimate interests – where processing is necessary for our legitimate business interests (or those of a third party) and your interests and rights do not override those interests. We balance any impact on you before relying on this basis, and you have the right to object.
  • Recognised legitimate interests – for a limited set of purposes defined in law (including certain crime prevention, safeguarding and public-interest purposes), we may rely on this basis without carrying out a separate balancing test, as permitted by the Data (Use and Access) Act 2025.

Where we need special category or criminal offence data, we will also identify an additional condition for processing as required by law.

If you have concerns about processing based on our legitimate interests, you can object using the details in How to contact us.

HOW WE USE YOUR PERSONAL DATA.

We may use your personal data to:

  • Provide compliance, financial crime, regulatory and related advice and services, including FCA, PRA and SEC-related work, and answer your questions;
  • Carry out our obligations under any contract between us;
  • Fulfil our legal and regulatory obligations;
  • Manage and improve our operations, services and websites;
  • Seek your views on our services and notify you of changes to them;
  • Send you communications you have requested or that may be of interest, on the basis of your consent or our legitimate interests;
  • Administer the FFE community;
  • Process a job application; and
  • For other legitimate business purposes.

If you choose not to share certain personal data with us, or withdraw certain permissions, we may not be able to provide some of the services you have asked for.

MARKETING.

We use your personal data to send you marketing emails about our services where the law allows us to. If we contact you at a business email address, or you are an existing client and we are telling you about similar services, we may do so on the basis of our legitimate interests, as permitted by the Privacy and Electronic Communications Regulations; otherwise, we will ask for your consent first. Every marketing message identifies us and includes a simple way to opt out. You can ask us to stop sending you marketing at any time, using the opt-out link in any message or by contacting us, and we will always act on that. Opting out will not stop service-related communications about products or services you hold with us.

We will always get your express opt-in consent before we share your personal data with any third party outside our group for their own marketing purposes.

COOKIES.

Like most websites, our websites use cookies – small files placed on your device that let the site work and help us understand how it is used. Some cookies are essential; they are necessary for our websites to function (for example, to keep you logged in to a client portal or to remember what you have entered in a form). These are set automatically and do not require your consent.

We also use non-essential cookies, for example, to compile aggregated statistics about how our websites are used and to improve them. We only set non-essential cookies with your consent. When you first visit our websites, our cookie banner lets you accept or reject these cookies, and you can change your preferences at any time using the cookie settings on our website.

You can also set your browser to block cookies or to alert you when a site sets one, though essential cookies are needed for our websites to work properly, and some features may not function if you block others.

For full details of the cookies we use, why we use them and how long they last, please see our Cookies Policy.

SHARING WITHIN OUR GROUP.

Cosegic Limited and FINTRAIL Ltd are part of the same corporate group and, for certain processing activities (e.g. client relationship management), jointly determine the purposes and means of processing your personal data. Cosegic and FINTRAIL act as joint controllers for these activities.

We share personal data between group companies for purposes including client relationship management, service delivery, internal administration, and, where applicable, marketing communications and will do so based on your consent.

We have entered into a joint controller arrangement that sets out our respective responsibilities for data protection compliance, including responding to your rights requests and providing this privacy information.

You may exercise your data protection rights against either Cosegic or FINTRAIL. Please contact us at [email protected].

We also rely on our legitimate interests in sharing personal data within our group where this is necessary to operate our business efficiently, except where consent or another lawful basis is required. In this event, we operate as data processors on each other’s behalf, with a data processing agreement in place.

THIRD PARTIES.

We do not sell your personal data. We may share it, where necessary and subject to appropriate safeguards, with:

  • Trusted third-party service providers who support our business;
  • Our professional advisers, auditors, insurers and regulatory bodies;
  • Our clients’ funders, where relevant;
  • Our mutual clients, where you have given permission for us to share your data with them; and
  • A third party to whom we sell, transfer or merge parts of our business or assets, or who acquires us.

All third-party service providers are required to take appropriate security measures and may only process your personal data for specified purposes and in line with our instructions. We may also process or disclose your personal data without your knowledge where this is required or permitted by law.

INTERNATIONAL TRANSFERS.

The personal data we hold about you will generally be held in the UK and the European Economic Area (EEA) but sometimes it may be necessary to transfer or store it outside the UK or EEA. Whenever we transfer personal data outside of the UK or EEA, we make sure it is protected by putting in place one of the following safeguards:

  • Transferring only to a country that the UK government (or, for EEA data, the European Commission) has decided provides an adequate level of protection; or
  • Putting in place an approved data transfer mechanism such as the UK International Data Transfer Agreement, or the Standard Contractual Clauses with the UK Addendum, along with any additional security measures needed.

You can contact us at any time to find out what safeguards we have in place for a particular transfer.

HOW LONG WE KEEP YOUR PERSONAL DATA.

We keep your personal data only for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, regulatory or reporting requirements. To decide how long to keep data, we consider:

  • the amount, nature, and sensitivity of the data;
  • the potential risk of harm from unauthorised use or disclosure of the data;
  • the purposes for which we process the data; and the applicable legal requirements.


As a general rule, we will not keep personal data for more than seven years after the end of our relationship or engagement with you, unless a longer period is required by law or regulation.

YOUR RIGHTS.

Under data protection law you have a number of rights, including the right to:

  • Be informed about how your data is used;
  • Request access to the personal data we hold about you;
  • Ask us to correct data that is inaccurate or incomplete;
  • Ask us to erase your data in certain circumstances;
  • Object to processing based on our legitimate interests, and to direct marketing;
  • Ask us to restrict processing in certain circumstances;
  • Request the transfer of your data (data portability);
  • Withdraw consent where we rely on it;
  • Not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you.

To exercise any of these rights, please contact us using the details below. We may ask you to verify your identity, and we may contact you for further information to help us respond.

You will not usually have to pay a fee. We will respond to requests within one month of receiving them, or of receiving any information we need to confirm your identity. If your request is complex, or you have made a number of requests, it may take us longer – in which case we will let you know and keep you updated. If a request is manifestly unfounded, repetitive or excessive, we may charge a reasonable fee or decline to act on it.

HOW TO MAKE A COMPLAINT.

If you are unhappy with how we have handled your personal data or a request, please contact our DPL in the first instance using the details in How to contact us. We operate an internal complaints procedure: we will acknowledge your complaint and set out how we will deal with it.

You also have the right to complain to the ICO at any time (www.ico.org.uk), or to the supervisory authority in the EU or EEA state where you live or work. We would, however, appreciate the chance to address your concerns first.

KEEPING YOUR DATA SECURE.

We have appropriate technical and organisational measures in place to prevent your personal data from being accidentally lost, or used, altered, disclosed or accessed without authorisation. We limit access to your personal data to those who need it, and who are subject to confidentiality obligations. Information submitted through our website forms is encrypted in transit.

We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator where we are legally required to do so.

LINKS TO OTHER WEBSITES.

Our websites may contain links to other websites, plug-ins and applications. This Privacy Policy applies only to our websites, so when you follow a link to another site you should read that site’s own privacy policy. We are not responsible for the privacy practices of other sites.

CHANGES TO THIS POLICY.

We may update this policy from time to time. This version is dated September 2026. Where changes are significant, we will take reasonable steps to bring them to your attention.

HOW TO CONTACT US.

We have appointed a Data Protection Lead (DPL) who is responsible for overseeing questions about this policy. If you have any questions about this policy, the personal data we hold about you, or you wish to exercise any of your rights, you can contact the DPL:

By email: [email protected]

By post:
Data Protection Lead,
Cosegic Limited,
4th Floor, Cannon Place,
78 Cannon Street,
London,
EC4N 6HL

If you are a member of the FFE community, you can also contact us at [email protected].

Table of Contents

Book a Personalised Demo

Tell us a little about your firm and what you're looking to achieve. We'll arrange a personalised demo with the right product specialist and show you how our solution can meet your needs.

"*" indicates required fields

Terms*

Fill in your details below to download your free checklist

Enter your details below to access the checklist.

"*" indicates required fields

Terms*