Maintaining your privacy is important to us. You entrust us with sensitive information, and we take that responsibility seriously. We will only share your personal data as described in this policy, and we will never sell your personal data.
This Privacy Policy explains how we collect, store, use and share personal data when we provide services to our clients, when you use our websites, and when you otherwise interact with us. It should be read together with any other privacy notice or fair processing notice we give you for a specific purpose – this policy supplements those notices and does not override them.
If you have any questions after reading it, please contact us using the details in the How to contact us section.
This policy is issued on behalf of the Cosegic group of companies. When we say “we”, “us” or “our”, we mean Cosegic Limited (company number 04954156) and its group companies and brands, including FINTRAIL Ltd (company number 09937817) and the FinTech FinCrime Exchange (FFE).
Cosegic Limited is the data controller responsible for our websites (cosegic.com, fintrail.com). For the other personal data described in this policy, the controller is the group company you are dealing with. Where Cosegic Limited and FINTRAIL Ltd decide together how your data is used, they act as joint controllers (see Sharing within our group).
Depending on the service:
We are registered with the Information Commissioner’s Office (ICO):
This policy applies to anyone who shares personal data with us, including when you:
Other data controllers (including our clients) may also provide your personal data to us.
Personal data means any information from which a living individual can be identified. The types of personal data we may collect include:
We also collect aggregated data (statistical or demographic data such as the percentage of users accessing a particular website feature). Aggregated data does not directly or indirectly identify you. If we combine it with your personal data so that you can be identified, we treat the combined data as personal data.
Given the nature of our work in compliance and financial crime, we may in some circumstances process special category data (for example, data revealing racial or ethnic origin, or political opinions) and data relating to criminal convictions and offences or alleged offences – for example when delivering financial crime, anti-money laundering, fraud, sanctions or screening-related services, whether as a controller or on behalf of a client, or when carrying out pre-employment checks.
Where we do so, we will only process this data where the law allows, we will identify an appropriate lawful basis and condition for processing, and we will apply additional safeguards. Where a client provides this data to us to deliver a service, the client remains responsible as controller for having a lawful basis to share it with us.
We collect personal data:
Data protection law allows us to process your personal data only where we have a lawful basis. Depending on the situation, we rely on:
Where we need special category or criminal offence data, we will also identify an additional condition for processing as required by law.
If you have concerns about processing based on our legitimate interests, you can object using the details in How to contact us.
We may use your personal data to:
If you choose not to share certain personal data with us, or withdraw certain permissions, we may not be able to provide some of the services you have asked for.
We use your personal data to send you marketing emails about our services where the law allows us to. If we contact you at a business email address, or you are an existing client and we are telling you about similar services, we may do so on the basis of our legitimate interests, as permitted by the Privacy and Electronic Communications Regulations; otherwise, we will ask for your consent first. Every marketing message identifies us and includes a simple way to opt out. You can ask us to stop sending you marketing at any time, using the opt-out link in any message or by contacting us, and we will always act on that. Opting out will not stop service-related communications about products or services you hold with us.
We will always get your express opt-in consent before we share your personal data with any third party outside our group for their own marketing purposes.
Like most websites, our websites use cookies – small files placed on your device that let the site work and help us understand how it is used. Some cookies are essential; they are necessary for our websites to function (for example, to keep you logged in to a client portal or to remember what you have entered in a form). These are set automatically and do not require your consent.
We also use non-essential cookies, for example, to compile aggregated statistics about how our websites are used and to improve them. We only set non-essential cookies with your consent. When you first visit our websites, our cookie banner lets you accept or reject these cookies, and you can change your preferences at any time using the cookie settings on our website.
You can also set your browser to block cookies or to alert you when a site sets one, though essential cookies are needed for our websites to work properly, and some features may not function if you block others.
For full details of the cookies we use, why we use them and how long they last, please see our Cookies Policy.
Cosegic Limited and FINTRAIL Ltd are part of the same corporate group and, for certain processing activities (e.g. client relationship management), jointly determine the purposes and means of processing your personal data. Cosegic and FINTRAIL act as joint controllers for these activities.
We share personal data between group companies for purposes including client relationship management, service delivery, internal administration, and, where applicable, marketing communications and will do so based on your consent.
We have entered into a joint controller arrangement that sets out our respective responsibilities for data protection compliance, including responding to your rights requests and providing this privacy information.
You may exercise your data protection rights against either Cosegic or FINTRAIL. Please contact us at [email protected].
We also rely on our legitimate interests in sharing personal data within our group where this is necessary to operate our business efficiently, except where consent or another lawful basis is required. In this event, we operate as data processors on each other’s behalf, with a data processing agreement in place.
We do not sell your personal data. We may share it, where necessary and subject to appropriate safeguards, with:
All third-party service providers are required to take appropriate security measures and may only process your personal data for specified purposes and in line with our instructions. We may also process or disclose your personal data without your knowledge where this is required or permitted by law.
The personal data we hold about you will generally be held in the UK and the European Economic Area (EEA) but sometimes it may be necessary to transfer or store it outside the UK or EEA. Whenever we transfer personal data outside of the UK or EEA, we make sure it is protected by putting in place one of the following safeguards:
You can contact us at any time to find out what safeguards we have in place for a particular transfer.
We keep your personal data only for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, regulatory or reporting requirements. To decide how long to keep data, we consider:
As a general rule, we will not keep personal data for more than seven years after the end of our relationship or engagement with you, unless a longer period is required by law or regulation.
Under data protection law you have a number of rights, including the right to:
To exercise any of these rights, please contact us using the details below. We may ask you to verify your identity, and we may contact you for further information to help us respond.
You will not usually have to pay a fee. We will respond to requests within one month of receiving them, or of receiving any information we need to confirm your identity. If your request is complex, or you have made a number of requests, it may take us longer – in which case we will let you know and keep you updated. If a request is manifestly unfounded, repetitive or excessive, we may charge a reasonable fee or decline to act on it.
If you are unhappy with how we have handled your personal data or a request, please contact our DPL in the first instance using the details in How to contact us. We operate an internal complaints procedure: we will acknowledge your complaint and set out how we will deal with it.
You also have the right to complain to the ICO at any time (www.ico.org.uk), or to the supervisory authority in the EU or EEA state where you live or work. We would, however, appreciate the chance to address your concerns first.
We have appropriate technical and organisational measures in place to prevent your personal data from being accidentally lost, or used, altered, disclosed or accessed without authorisation. We limit access to your personal data to those who need it, and who are subject to confidentiality obligations. Information submitted through our website forms is encrypted in transit.
We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator where we are legally required to do so.
Our websites may contain links to other websites, plug-ins and applications. This Privacy Policy applies only to our websites, so when you follow a link to another site you should read that site’s own privacy policy. We are not responsible for the privacy practices of other sites.
We may update this policy from time to time. This version is dated September 2026. Where changes are significant, we will take reasonable steps to bring them to your attention.
We have appointed a Data Protection Lead (DPL) who is responsible for overseeing questions about this policy. If you have any questions about this policy, the personal data we hold about you, or you wish to exercise any of your rights, you can contact the DPL:
By email: [email protected]
By post:
Data Protection Lead,
Cosegic Limited,
4th Floor, Cannon Place,
78 Cannon Street,
London,
EC4N 6HL
If you are a member of the FFE community, you can also contact us at [email protected].
We use cookies to improve your experience and understand how our site is used. Choose which cookies we can set - you can change your mind at any time via the Cookie policy.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookies and .
Tell us a little about your firm and what you're looking to achieve. We'll arrange a personalised demo with the right product specialist and show you how our solution can meet your needs.
"*" indicates required fields
Enter your details below to access the checklist.
"*" indicates required fields