Data Processing & Privacy Policy
At Find Peace of Mind Limited we take your privacy very seriously and are committed to protecting it. This policy sets out when and why we collect your personal information, how we use it and keep it secure, as well as your rights and choices in relation to your information.
Any changes we may make to this policy in the future will be posted on this website so please check this page occasionally. This policy was last updated in July 2026.
1. About this policy
Find Peace of Mind Ltd ("FPoM", "we", "us", "our") is committed to protecting the privacy and confidentiality of our clients and contacts. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights available to you under UK data protection law.
We are a directly authorised independent financial planning and mortgage advice firm, regulated by the Financial Conduct Authority (FCA No. 510117). As a data controller, we are registered with the Information Commissioner's Office (ICO).
This policy applies to current and prospective clients, website visitors, and other individuals whose personal data we process in connection with our services. It should be read alongside any additional notices we provide at the point of data collection.
2. Personal information we collect
2.1 Information you provide to us
We collect information you share with us directly, including:
-
Identity information: full name, date of birth, national insurance number, passport or driving licence details
-
Contact details: postal address, email address, telephone numbers
-
Financial information: income, expenditure, assets, liabilities, pensions, investments, insurance policies, credit history, and tax position
-
Employment and business details
-
Family and dependant information relevant to your financial planning
-
Health information where relevant to protection or long-term care planning (treated as special category data)
-
Expressed preferences, goals, values, and risk appetite
2.2 Information we generate during our relationship
In the course of providing financial planning and advice services, we create and maintain:
-
Suitability reports, meeting notes, research records, and correspondence
-
Recommendations and ongoing reviews of your financial arrangements
-
Records of instructions and transactions
2.3 Recordings and transcripts of meetings and calls
We record telephone calls, video calls, and in-person meetings (where a recording device is used) as part of our advice process. This applies to initial consultations, ongoing review meetings, and other substantive discussions about your financial affairs.
We do this for the following purposes:
-
To create an accurate record of your instructions and circumstances, reducing the risk of misunderstanding
-
To support the preparation of suitability reports and meeting notes
-
To assist with regulatory compliance and the FCA requirement to maintain adequate records of advice
-
To assist in resolving any queries or complaints
We will inform you at the start of any recorded call or meeting that recording is taking place. If you object to being recorded, please let us know; however, please note that in some circumstances we may be unable to proceed with the meeting on an unrecorded basis if doing so would prevent us from meeting our regulatory obligations.
2.4 AI-assisted analysis of recordings
We use the following AI-powered tools to assist with the processing of recorded meetings and calls:
-
Saturn: used for in-person meetings and for video calls conducted via Microsoft Teams or Zoom. Saturn joins the call or processes the recording and produces a transcript and draft meeting notes. Where appropriate, audio recordings obtained from a recording device are uploaded to Saturn, which produces an automated transcript and draft meeting summary.
-
Claude (Anthropic): used by our advisers as an AI assistant to analyse transcripts, identify key points, and assist with drafting meeting notes and client correspondence.
The workflow for telephone calls is as follows: all calls made through our VoIP telephony system (Merlin Telecom) are recorded automatically. Where a recorded call contains substantive advice content, our advisers may download the recording and upload it to Saturn for transcription. The resulting transcript may then be used as the basis for meeting note production, with assistance from Claude.
In all cases, AI-generated outputs are reviewed and approved by a qualified human adviser before any document is finalised or any action is taken. We do not use automated decision-making in a way that produces legal or similarly significant effects on you without human review.
UK-based processing
Our telephony recording (Merlin Telecom), meeting intelligence platforms (Saturn), and AI assistant (Claude, Anthropic) are used by FPoM staff operating within the United Kingdom. FPoM subscribes to Claude for Enterprise, under which Anthropic provides UK data processing commitments, ensuring that personal data processed through Claude is handled in accordance with UK GDPR requirements. We do not transfer your data to any non-UK jurisdiction in connection with telephony recording or Saturn processing.
3. Lawful basis for processing
We rely on the following lawful bases under UK GDPR, depending on the nature of the processing:
-
Contractual necessity; Processing required to provide the financial planning and advice services you have engaged us to deliver, including the preparation of suitability reports and the maintenance of advice records.
-
Legal obligation; Processing required to comply with our regulatory obligations under the Financial Services and Markets Act 2000, FCA rules (including COBS), anti-money laundering legislation, and tax reporting requirements.
-
Legitimate interests; Recording and AI-assisted analysis of meetings and calls, where our legitimate interest is the accurate capture of client instructions and the quality of our advice process. We have assessed that this interest is not overridden by your rights and freedoms, given the safeguards described in this policy.
-
Consent; Where we rely on consent — for example, for marketing communications — we will ask for your agreement separately and you may withdraw it at any time.
-
Vital interests / Legal claims; Occasionally we may process data to protect vital interests or to establish, exercise, or defend legal claims.
For special category data (such as health information), we rely on the explicit consent condition or, where applicable, the substantial public interest condition under Schedule 1 of the Data Protection Act 2018.
4. How we use your personal information
We use your personal information to:
-
Carry out an assessment of your financial circumstances, needs, and objectives
-
Provide advice on financial planning, investments, pensions, protection, and mortgages
-
Prepare and deliver suitability reports and supporting documentation
-
Execute instructions and arrange financial products on your behalf
-
Conduct ongoing reviews of your financial arrangements
-
Meet our regulatory and legal obligations, including record-keeping and compliance monitoring
-
Respond to queries and manage complaints
-
Prevent fraud and meet our anti-money laundering obligations
-
Communicate with you about your financial planning, including reminders and service updates
-
Improve the quality of our advice processes, including through the use of AI-assisted tools described in section 2.4
5. Systems and service providers
We use a number of technology systems to deliver our services and operate our business. Where these involve third parties processing personal data on our behalf, they act as data processors under written agreements that require them to protect your data in accordance with UK data protection law.
Our principal systems include:
-
Zoho CRM; Client relationship management system — stores client records, tasks, communications, and service history. Data processed in accordance with Zoho's UK data processing terms.
-
Zoho Books; Accounting and invoicing platform — processes billing and payment information. Data processed in accordance with Zoho's UK data processing terms.
-
Merlin Telecom; Our VoIP telephony provider. All telephone calls are recorded at the network level. Recordings are downloaded by FPoM and, where appropriate, uploaded to our meeting intelligence platforms for transcription and analysis (see section 2.4).
-
Saturn; AI meeting intelligence platform used for transcription and note production from in-person meetings and from video calls (Microsoft Teams and Zoom). Audio recordings are uploaded by FPoM for processing. See section 2.4.
-
Claude (Anthropic); AI assistant used by our advisers to assist with analysis of transcripts and drafting of meeting notes and client correspondence. All outputs are reviewed and approved by a qualified adviser before use. FPoM subscribes to Claude for Enterprise, which includes UK data processing commitments from Anthropic. See section 2.4.
-
Microsoft Teams / Zoom; Video conferencing platforms used for remote client meetings.
-
Microsoft 365; Email and calendar used for client correspondence and appointment management.
-
Zoho Sign; Electronic signature platform used for the delivery and execution of client documents. Data processed in accordance with Zoho's UK data processing terms.
-
Adobe Sign; Electronic signature platform used for the delivery and execution of certain client documents.
-
Financial planning and research tools; We use a range of specialist software platforms to support advice delivery, including: FinCalc, Voyant (cash flow modelling), Fintegrate, Evalue (attitude to risk), Oxford Risk (risk profiling), and Selectapension (pension analysis). We also submit data to and receive information from product providers in the course of arranging and administering financial products on your behalf.
Data processor commitments
All processors used by FPoM are required to process personal data only on our documented instructions, to implement appropriate technical and organisational security measures, and to assist us in meeting our obligations to individuals under UK GDPR.
6. Who we share your information with
We share your personal data only where necessary and with appropriate protections in place. Recipients may include:
-
Product providers: insurers, investment platforms, pension providers, mortgage lenders, and other financial institutions to whom we submit applications or instructions on your behalf
-
The Financial Conduct Authority and other regulators, where required by law
-
HM Revenue and Customs, where required by law or with your authority
-
Our compliance consultants or supervisory network, for the purposes of regulatory oversight
-
Our professional indemnity insurers, in connection with a claim or potential claim
-
Legal or other professional advisers, where required to protect our interests or yours
-
Successor businesses, in the event of a sale or transfer of all or part of our business
We do not sell your personal data. We do not share it with third parties for their own marketing purposes.
7. International data transfers
Our preference is to process all personal data within the United Kingdom. Where we use cloud-based services, we select providers who process and store data in the UK wherever possible.
If any processing does take place outside the UK — for example, where a software provider routes data through non-UK infrastructure, we ensure that an appropriate transfer mechanism is in place, such as the UK's International Data Transfer Agreement (IDTA) or an adequacy decision by the UK Government. We will notify you of any material change in this position.
In particular, as described in section 2.4, all recording and AI analysis of your meetings and calls is performed on UK-based systems.
8. How long we keep your information
We retain personal data only for as long as necessary for the purposes set out in this policy and to meet our legal and regulatory obligations. Our standard retention periods are:
-
Advice records and suitability reports; A minimum of 5 years from the date of advice (or longer where required by FCA rules, e.g. pension transfer advice: indefinitely)
-
Meeting recordings and transcripts; Retained for the same period as the underlying advice record to which they relate
-
Anti-money laundering records; 5 years from the end of the business relationship
-
Marketing consent records; Until consent is withdrawn, plus 1 year
-
Complaints records; 5 years from resolution
-
General correspondence; 5 years from the end of the client relationship
At the end of the relevant retention period, personal data is securely deleted or anonymised.
9. How we protect your information
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures, including:
-
Encryption of data in transit and, where supported by our systems, at rest
-
Access controls limiting access to personal data to those members of our team who require it for their role
-
Password policies and multi-factor authentication on key systems
-
Regular review of access rights, including upon changes in team membership
-
Contractual data protection obligations imposed on all third-party processors
-
An incident response procedure in the event of a data breach, including notification to the ICO and to affected individuals where required
Despite these measures, no system is entirely risk-free. If you have concerns about the security of your data, please contact us.
10. Your rights
Under UK GDPR, you have the following rights in relation to your personal data:
-
Right of access; To request a copy of the personal data we hold about you (commonly known as a subject access request).
-
Right to rectification; To request correction of inaccurate or incomplete personal data.
-
Right to erasure; To request deletion of your personal data in certain circumstances — note this right is limited where we are required to retain data by law or regulatory obligation.
-
Right to restriction; To request that we restrict the processing of your personal data in certain circumstances.
-
Right to data portability; To receive a copy of data you have provided to us in a structured, machine-readable format, where processing is based on consent or contract.
-
Right to object; To object to processing based on legitimate interests or for direct marketing purposes.
-
Rights re. automated decisions; To request human review of any decision made solely by automated means that has a significant effect on you. As noted in section 2.4, we do not make such decisions without human review.
-
Right to withdraw consent; Where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us using the details in section 11. We will respond within one calendar month of receiving your request. We may need to verify your identity before responding.
If you are not satisfied with how we handle your request, or with our data practices generally, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office (ICO)
Website: www.ico.org.uk | Helpline: 0303 123 1113 | Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
11. Contact us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or wish to raise a concern, please contact:
Data Controller; Find Peace of Mind Ltd
Contact; Emily Macpherson FPFS, Managing Director
Email; emily@findpeaceofmind.co.uk
Post; Find Peace of Mind Ltd, Pitney, Langport, Somerset
Telephone; 01749 676625
12. Changes to this policy
We review this Privacy Policy at least annually and following any material change to our systems or processing activities. When we make significant changes, we will notify you by email or by providing a prominent notice on our website. We will always publish the current version of this policy and make it available to clients on request.
This policy was last reviewed in July 2026.
