Privacy Statement
As an Appointed Representative of Perennial Financial Management Limited, we provide personal, face to face and telephone advisory services to Dunham Wealth Limited clients. Perennial Financial Management Limited acts as principal to this firm and ensures that any financial advisory services that we provide to you are delivered in accordance with the applicable regulatory requirements. Perennial Financial Management Limited is also responsible for managing any complaints that may be made by you in respect of the services we provide.
This Privacy Policy explains when and why we collect your personal information as part of our provision of financial advice and explains how we use your information. If requested, we will provide you with a copy of this Privacy Policy for your records.
“We”, “Us” “Our” refers to Dunham Wealth Limited.
Where Perennial Financial Management Limited uses your personal data, for example by conducting audits of Appointed Representatives and dealing with any complaints that you may have, this will be governed by Perennial Financial Management Limited’s Privacy Policy. The Perennial Financial Management Limited Privacy Policy can be found at http://www.perennial-financial.co.uk/privacy/
Where you are referred to a St. James’s Place partner practice, they will use your personal data. This will be governed by their own Privacy Policy.
1. About us
For us to deliver such financial services and deal with any correspondence that may arise, we need to collect and process personal information. This makes us a “data controller”.
Dunham Wealth Limited will be acting as data controller of your personal information, jointly with Perennial Financial Management Limited.
2. Our processing of your personal information
Depending on our relationship with you (whether you are a prospective or existing client or a business partner), we will collect and use different personal information about you for different reasons.
Sometimes we will request or receive “special categories of personal information” (which is information relating to your health, genetic or biometric data, criminal convictions, sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership). For example, to better understand your current and potential future circumstances and recommend appropriate financial investments, we may need access to information about your health. Details about your health might also be needed for us to make reasonable adjustments when providing our services to you.
We also use details of any unspent criminal convictions for fraud prevention purposes.
Where you provide personal information to us about other individuals (for example, members of your family or other dependents) we will also be data controller of their personal information and responsible for protecting their personal information and using it appropriately. This notice will therefore apply to those individuals, and you should refer them to this notice.
To make this notice as user friendly as possible, we have split it into different sections.
2.1. Prospective clients
This section will apply if you are a prospective client, and we will need certain information about you to carry out pre-client identification and compliance checks and to set you up as a client on our client relationship management system.
What personal information may we collect?
- General information such as your name, address, phone numbers and email addresses, date of birth and gender.
- Identification information including passport, driving licence, national identity card (for non-UK nationals), government issued ID verification and address verification documents such as council tax letters, bank statements and evidence of benefit entitlement.
- Employment information such as job title, employment history and professional accreditations.
- Financial information:
-
- Bank details
- Financial reviews (fact finds)
- Information relating to your personal finances such as your financial liabilities and assets, income, and outgoings
- Information obtained from carrying out identification checks and checking sanction lists and politically exposed persons (PEP) screening, including bankruptcy orders.
- Information relevant to the services we provide such as:
-
- previous and current investments
- information about your lifestyle
- attitude to investment risk
- existing plan details
- objectives
- copies of your will
- information about any trusts you have
- Information about your family including information about your dependants.
- Information such as IP address and browsing history obtained through our use of cookies. (You can find more information about this in our cookies policy in section 8 below).
- Information obtained during telephone recordings.
- Information we may have gather from publicly available sources such as the electoral roll, internet search engines and social media sites such as LinkedIn where you have been flagged as a PEP and we need to carry out enhanced due diligence.
What special categories of personal information may we collect?
- Details about any criminal convictions and any related information which have been obtained from our sanctions checks and PEP screening. This will include information relating to any offences or alleged offences you have committed or any court sentences which you are subject to.
- We may collect details about your health which are relevant to your application (e.g. as part of a pension or income protection need we may ask you about any medical conditions that affect you to establish whether you are deemed to be a vulnerable client) or where you have disclosed such information to us because it explains your risk appetite for investments.
- In limited circumstances, we may also collect other special categories of data as detailed on a separate consent form.
How will we collect your personal information?
We will collect information directly from you when:
- you enquire about or apply to receive our financial advice services; and
- you contact us by email, telephone and through other written and verbal communications.
We will also collect your personal information from:
- Publicly available sources such as the electoral roll, court judgments, insolvency registers, internet search engines and social media sites.
- Product Providers and Product Provider Platforms
- Your St. James’s Place Partner, if applicable
- St. James’s Place group companies who will process your personal data in accordance with their Privacy Policy which can be found at www.sjp.co.uk/site-services/privacy
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “Lawful Basis” when we process your “personal information”:
- We need to use your personal information to enter into the client agreement, for example, we need to use your personal information to assess whether we can provide services to you and to set you up as a client on our client relationship management system.
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have a valid business reason to use your personal information and which is necessary for our everyday business operations and activities, for example to keep records of investments and the reasoning behind such investments, to maintain business records, to carry out due diligence, to review our business models and undertake strategic and operational business analysis.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
When we use your “special categories of personal information”, we must have an additional “lawful basis” and we will rely on the following lawful basis in these circumstances:
- You have given your explicit consent to our use of your special categories of personal information. In some cases, we are not able to offer you certain advice or financial products unless we have your health information.
- There is a substantial public interest such as prevention and detection of fraud.
- We need to use such special categories of personal information to establish, exercise or defend legal rights, such as when we are facing legal proceedings or want to bring legal proceedings ourselves.
- It is in the substantial public interest to comply with regulatory requirements relating to unlawful acts and dishonesty – such as carrying out fraud, credit and anti-money laundering checks.
Purpose for processing
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid purpose as set out above and we will only disclose it to the following parties:
- Perennial Financial Management Limited as our principal firm, who hold your data on our behalf for administration purposes.
- Product Providers and Product Provider Platforms.
- Your St, James’s Place Partner, if applicable.
- St. James’s Place group companies, who will process your personal data in accordance with their policy which can be found at www.sjp.co.uk/site-services/privacy.
- Third parties who provide sanctions checking services including SmartSearch.
- Compliance consultants including SJP Acquisition Services Limited and ‘The Consulting Consortium’ (TCC).
- Financial crime and fraud detection agencies.
- Our regulators including the Financial Conduct Authority and the Financial Ombudsman Service.
- Selected third parties in connection with any sale, transfer, or disposal of our business.
- Our insurers.
- The police, HMRC and other crime prevention and detection agencies.
- Third parties including self-employed contractors who we have entered into contractual arrangements with to provide services we need to carry out our everyday business activities such as business administration, partner support specialists who assist us with day to day business operations, document management providers, back office system providers, storage warehouses, IT suppliers, actuaries, auditors, lawyers, outsourced business process management providers, our subcontractors and tax advisers.
2.2. Existing clients
This section will apply if you currently receive financial services from us. This section will set out how we use your information.
What personal information may we collect?
- General information such as your name, address, phone numbers and email addresses, date of birth and gender.
- Identification information including passport, driving licence, national identity card (for non-UK nationals), government issued ID verification and address verification documents such as council tax letters or bank statement and evidence of benefit entitlement.
- Employment information such as job title, employment history and professional accreditations.
- Financial information:
- Bank details
- Financial reviews (fact finds)
- Information relating to your personal finances such as your financial liabilities and assets, income and outgoings
- Information obtained from carrying out identification checks and checking sanction lists and politically exposed persons (PEP) screening, including bankruptcy orders or where you have been flagged as a PEP.
- Information relevant to the services we provide, such as:
- previous and current investments
- information about your lifestyle
- attitude to investment risk
- existing plan details
- objectives
- copies of your will
- information about any trusts you have
- Information contained in client review meeting records and file notes
- Information contained in any records held by previous independent financial advisers (otherwise known as IFAs) with whom you were previously a client and which have been transferred to us when that IFA was acquired by St. James’s Place group companies (Dunham Wealth Limited / Perennial Financial Management Limited).
- Information about your family including information about your dependants.
- Information obtained during telephone recordings where applicable.
- Information such as IP address and browsing history obtained through our use of cookies. (You can find more information about this in our cookies policy in section 8 below)
- Your marketing preferences and details of your customer experience with us.
- Information which we have gathered from publicly available sources such as the electoral roll, internet search engines and social media sites where you have been flagged as a PEP and we need to carry out enhanced due diligence.
What special categories of information will we collect?
- Details about any criminal convictions and any related information which have been obtained from our sanctions checks and PEP screening. This will include information relating to any offences or alleged offences you have committed or any court sentences which you are subject to.
- We may collect details about your health which are relevant to your application (e.g. as part of a pension need we may ask you about any medical conditions that affect you to establish whether you are deemed to be a vulnerable client or where we are applying for income protection insurance we will need to ask you about any medical conditions and information about lifestyle choices such as whether you drink alcohol or smoke so that appropriate insurance can be obtained) or where you have disclosed such information to us because it explains your risk appetite for investments.
- In limited circumstances, we may also collect other special categories of data as detailed on a separate consent form.
How will we collect your personal information?
We will collect information directly from you when:
- you register to receive our services and complete and return to us all applicable application forms; and
- you contact us by email, telephone and through other written and verbal communications.
We will also collect your personal information from:
- Publicly available sources such as the electoral roll, court judgments, insolvency registers, internet search engines and social media sites.
- Any records held by previous independent financial advisers (otherwise known as IFAs) with whom you were previously a client and any advisers of that IFA which have been transferred to us when that IFA was acquired by St. James’s Place group companies.
- Your St. James’s Place Partner, if applicable.
- St. James’s Place group companies.
- Product providers and product provider platforms.
- Third parties such as SmartSearch who provide anti money laundering and fraud prevention services who we have appointed to carry out electronic ID checks, sanctions and politically exposed persons checking services.
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “Lawful Basis” when we process your “personal information”:
- We need to use your personal information to enter into or perform the client agreement that we hold with you. For example, we need to use your personal information to provide our services, to arrange and implement recommendations, review your ongoing suitability of current arrangements and handle claims.
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have a valid business reason to use your personal information which is necessary for our everyday business operations and activities, for example to keep records of investments and the reasoning behind such investments, to maintain business records, to carry out due diligence, to review our business models and undertake strategic and operational business analysis.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
When we use your “special categories of personal information”, we must have an additional “lawful basis” and we will rely on the following Lawful Basis in these circumstances:
- You have given your explicit consent to our use of your special categories of personal information. In some cases, we are not able to offer you certain advice or financial products unless we have your relevant health information.
- There is a substantial public interest such as prevention and detection of fraud.
- We need to use such special categories of personal information to establish, exercise or defend legal rights, such as when we are facing legal proceedings or want to bring legal proceedings ourselves.
Purpose for processing
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid purpose as set out above and we will only disclose it to the following parties:
Third parties who provide a service in relation to the management of your investments or facilitate the arrangement of products we recommend such as product providers, portfolio and fund managers, insurers where you are buying income protection products. Where we have shared your personal information with these third parties, they will also be a data controller and responsible for how they use your personal information. Their uses of your personal information will be governed by their own fair processing notices.
- Perennial Financial Management Limited.
- Your St. James’s Place Partner, if applicable.
- Product Providers and Product Provider Platforms.
- St. James’s Place group who will process your personal data in accordance with their Privacy Policy which can be found www.sjp.co.uk/site-services/privacy
- Third parties who provide sanctions checking services including SmartSearch.
- Compliance consultants including SJP Acquisition Services Limited and ‘The Consulting Consortium’ (TCC)
- Financial crime and fraud detection agencies.
- Our regulators including the Financial Conduct Authority and the Financial Ombudsman Service.
- Selected third parties in connection with any sale, transfer, or disposal of our business.
- Our insurers.
- The police, HMRC and other crime prevention and detection agencies. Third parties and self-employed contractors who we have entered into contractual arrangements with to provide services we need to carry out our everyday business activities such as business administration, adviser support specialists who assist us with day to day business operations, document management providers, back office system providers, secure login and email providers, storage warehouses, IT suppliers, actuaries, auditors, lawyers, outsourced business process management providers, our subcontractors and tax advisers.
2.3. Clients’ family members, business associates or beneficiaries
This section will apply if your personal information has been provided to us by a client to explain their lifestyle and approach to investments (for example, if you are a spouse or partner, dependant mentioned in a will or trust document, another beneficiary, a business partner) and will set out how we use your information.
What personal information may we collect?
- General information such as your name, address, phone numbers and email addresses, date of birth and gender.
- Your relationship to our client.
- Financial information relating to your financial liabilities, such as a property portfolio which is owned jointly between you and our client.
- Any information which is relevant to the services we provide for our client.
What special categories of personal information may we collect?
- We may collect details about your physical and mental health which are relevant to the services we provide for our client (for example where you are the client’s partner, and you have a medical condition which means that you are unable to work and therefore our client has a higher need for investment return and a lower risk appetite).
- Information contained in any records held by previous independent financial advisers (otherwise known as IFAs) with whom your family member or business associate was previously a client, and which have been transferred to us when that IFA was acquired by St. James’s Place group companies.
- In limited circumstances, we may also collect information concerning your sex life or sexual orientation for example where you are in a civil partnership with our client.
How will we collect your personal information?
- Directly from our client.
- From documents directly provided to us by our client, such as wills or trust documents where you are listed as a dependant or employment related documents, and you are listed as a business partner of our client.
- From any records held by previous independent financial advisers (otherwise known as IFAs) with whom your family member or business associate was previously a client and from any advisers of that IFA which have been transferred to us when that IFA was acquired by St. James’s Place group companies.
- Your St. James’s Place Partner, if applicable.
- St. James’s Place group companies who will process your personal data in accordance with their Privacy Policy which can be found at www. sjp.co.uk/site-services/privacy.
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “Lawful Basis” when we process your “personal information”:
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have a valid business reason to use your personal information which is necessary for our everyday business operations and activities, for example to keep records of investments and the reasoning behind such investments, to maintain business records, to carry out due diligence, to review our business models and undertake strategic and operational business analysis.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
When we use your “special categories of personal information”, we must have an additional “lawful basis” and we will rely on the following Lawful Basis in these circumstances:
- You have given your explicit consent to our use of your special categories of personal information which may have been provided to us by your family member, spouse, partner, or business associate who is our client.
- There is a substantial public interest such as prevention and detection of fraud.
- We need to use such special categories of personal information to establish, exercise or defend legal rights, such as when we are facing legal proceedings or want to bring legal proceedings ourselves.
Purpose for processing
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid purpose as set out above and we will only disclose it to the following parties:
- Third parties who provide a service in relation to the management of our client’s investments or facilitate the arrangement of products we recommend such as product providers, portfolio and fund managers, insurers where our client is buying income protection products. Where we have shared your personal information with these third parties, they will also be a data controller and responsible for how they use your personal information. Their uses of your personal information will be governed by their own fair processing notices.
- Perennial Financial Management Limited.
- Your St. James’s Place Partner, if applicable.
- Product Providers and Product Provider Platforms.
- St. James’s Place group companies, who will process your personal data in accordance with their Privacy Policy which can be found www.sjp.co.uk/site-services/privacy
- Compliance consultants including SJP Acquisition Services Limited and ‘The Consulting Consortium’ (TCC).
- Financial crime and fraud detection agencies.
- Our regulators including the Financial Conduct Authority and the Financial Ombudsman Service.
- Selected third parties in connection with any sale, transfer, or disposal of our business.
- Our insurers.
- The police, HMRC and other crime prevention and detection agencies. Third parties and self-employed contractors who we have entered into contractual arrangements with to provide services we need to carry out our everyday business activities such as business administration, adviser support specialists who assist us with day to day business operations, document management providers, back office system providers, secure login and email providers, storage warehouses, IT suppliers, actuaries, auditors, lawyers, outsourced business process management providers, our subcontractors and tax advisers.
2.4. Other business partners
If you are a business partner such as a products provider, portfolio or fund manager or contractor who carries out business functions on our behalf, this section will be relevant to you and sets out our uses of your personal information.
What personal information may we collect?
- General information such as your name, address, business phone numbers and email addresses.
- Employment information such as job title, business cards and professional accreditations.
- Information about your clients, your employees and the services and products you offer.
- Your bank details and information obtained from checking sanction lists and credit checks.
- Information which we have gathered from publicly available sources such as internet search engines and generally obtained as part of the due diligence process conducted by St. James’s Place group companies.
How will we collect your information?
- Directly from you
- St. James’s Place group companies.
- Publicly available sources such as internet search engines.
- From service providers who carry out sanctions checks.
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “Lawful Basis” when we process your “personal information”:
- We need to use your personal information to enter into or perform the contract that we hold with you.
- We have a legal or regulatory obligation to use such personal information. For example, we may be required to carry out certain background checks.
- We have a valid business reason to use your personal information which is necessary for our everyday business operations and activities, for example to keep records of investments and the reasoning behind such investments, to maintain business records, to carry out due diligence, to review our business models and undertake strategic and operational business analysis including reviewing the performance of our business partners.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
Purpose for processing
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid reason as set out above and we will only disclose it to the following parties:
- Dunham Wealth Limited who will process your personal data in accordance with this Privacy Policy.
- Perennial Financial Management Limited who will process your personal data in accordance with their Privacy Policy which can be found at http://www.perennial-financial.co.uk/privacy.
- St. James’s Place group companies, who will process your personal data in accordance with their Privacy Policy which can be found https://www.sjp.co.uk/site-services/privacy.
- Our agents or employees as appropriate.
- Third parties who provide sanctions checking services including SmartSearch.
- Our regulators including the Financial Conduct Authority and the Financial Ombudsman Service.
- Selected third parties in connection with any sale, transfer, or disposal of our business.
- Our insurers.
- Third parties including self-employed contractors who we have entered into contractual arrangements with to
provide services we need to carry out our everyday business activities such as document management providers, back-office system providers, storage warehouses, IT suppliers, actuaries, auditors, lawyers, outsourced business process management providers, our subcontractors and tax advisers.
2.5. Users of our website
If you use our website, this section will be relevant to you and sets out our uses of your personal information.
What personal information may we collect?
- General information submitted via the website, for example where you provide your details in the contact section such as your name, contact details and company name.
- Information such as IP address and browsing history obtained through our use of cookies. You can find more information about this in our cookies policy in section 8 below.
How will we collect your personal information?
We will collect your information directly from our website.
What will we use your personal information for?
There are a number of reasons we use your personal information and for each use we need to have a “lawful basis” to do so.
We will rely on the following “lawful basis” when we process your “personal information”:
- We have a valid business reason to use your personal information, necessary for our everyday business operations and activities, for example to maintain business records and to monitor usage of the website.
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
Purpose for processing
Who will we share your personal information with?
We will not sell or transfer your personal information to anyone unless we have a valid purpose as set out above and we will only disclose it to:
- Perennial Financial Management Limited.
- Your St. James’s Place Partner, if applicable.
- St. James’s Place group companies, who will process your personal data in accordance with their Privacy Policy which can be found www.sjp.co.uk/site-services/privacy
- Third parties who we have entered into contractual arrangements with to provide services we need to carry out our everyday business activities such as IT suppliers and website providers.
3. Where you are a job applicant?
This section will apply if you are a job applicant within Dunham Wealth Limited.
What personal information may we collect?
- We have set out below the main categories of candidate personal information which we process in connection with our recruiting activities on a day-to-day basis:
- Personal contact information (including your name, home address, personal telephone number(s) and personal e-mail address)
- Work history and other relevant experience including information contained in CV, cover letter or job application form
- Education information including degrees awarded, transcripts and other information provided in support of the job application
- Remuneration history
- Information collected during phone screenings and interviews
- Details regarding the type of employment sought, desired salary, willingness to relocate, job preferences, and other information related to compensation and benefits
- Reference information and information received from background checks (where applicable) including information provided by third parties
- Information related to previous applications to us or previous employment history with us
- Documents evidencing your right to work (including information about your immigration status where relevant)
- Date of birth
- Gender
- Information gathered through our monitoring of our IT systems, building access records in relation to your communications with us and attendance at our premises
- Personal information which you otherwise voluntarily provide during the course of the recruitment process
- The majority of the personal information to be provided by you is mandatory in connection with our recruiting activities. Failure to provide mandatory personal information may affect our ability to accomplish the purposes stated in this Notice, including considering your suitability for employment and/or entering into an employment contract with you.
The list set out above is not exhaustive, and there may be other personal information which Dunham Wealth Limited collects, stores and uses in the context of the application and recruitment process. Dunham Wealth Limited will update this Notice from time to time to reflect any notable changes in the categories of personal information which it processes.
The majority of the personal information which we process will be collected directly from you. However, your personal information may also be provided to us by third parties, such as recruitment agencies, former employers, official bodies (such as regulators or the Disclosure and Barring Service) and/or medical professionals
What background checking do we undertake?
As part of our referencing and vetting procedures, we will contact certain third parties in order to verify your personal information (including personal information that you provide as part of the application and recruitment process). These third parties will include:
- Former employers, in order to verify your previous employment history
- Universities and/or other establishments for higher education that you attended, in order to verify your education history
- For specific roles we will undertake electronic ID checks, sanctions and politically exposed persons checks via a third-party agency
- We will also gather data from publicly available sources such as the electoral roll, court judgments, insolvency registers, internet search engines and social media sites.
We will only conduct background checking in relation to successful candidates that have accepted a conditional offer of employment with us, and we will specifically inform such candidates that we will be contacting these third parties in advance of doing so.
What will we use your personal information for?
Dunham Wealth Limited uses your personal information for a variety of purposes to take steps necessary to enter into an employment contract with you, to comply with legal obligations or otherwise in pursuit of its legitimate business interests. We have set out below the main purposes for which candidate personal information is processed:
- To identify and evaluate job applicants, including assessing skills, qualifications, and experience
- Verifying candidate information and carrying out employment, background (including criminal records) and reference checks, where applicable, and in order to prevent fraud
- Communicating with you about the recruitment process and your application
- To comply with our legal, regulatory, or other corporate governance requirements
In addition to using your personal information to consider you for the role you applied for, we will retain and process your personal information for six months to inform you about, and to consider you for other roles that may be appropriate for you. If you do not want us to consider you for other roles which we consider may be appropriate for you, please inform your recruitment contact.
Again, this list is not exhaustive, and Dunham Wealth Limited may undertake additional processing of personal information in line with the purposes set out above. Dunham Wealth Limited will update this Notice from time to time to reflect any notable changes in the purposes for which its processes your personal information.
When will we share candidate personal information?
Dunham Wealth Limited will share candidate personal information with other parties only in limited circumstances where this is necessary for the purposes of entering into an employment contract, to comply with a legal obligation, or otherwise in pursuit of its legitimate business interests as follows:
- recruitment agencies
- background vetting specialists
- occupational health providers and other medical professionals
- HMRC and/or any other applicable government body
- accountants, lawyers, and other professional advisers
- The Financial Conduct Authority and/or the Prudential Regulatory Authority and/or any other applicable regulatory body
- specialists undertaking psychometric & personality tests
Personal information is shared under the terms of a written agreement between Dunham Wealth Limited and the third party which includes appropriate security measures to protect the personal information in line with this Notice and our obligations. The third parties are permitted to use the personal information only for the purposes which we have identified, and not for their own purposes, and they are not permitted to further share the data without our express permission.
What special category (sensitive) data do we collect?
Certain categories of data are considered “special categories of personal information” and are subject to additional safeguards. Dunham Wealth Limited limits the special categories of personal information which it processes as follows:
Health Information
We may process information about a candidate’s physical or mental health in the course of the recruitment process. In particular:
- We will process information about an individual candidate’s physical or mental health to comply with our obligations to make reasonable adjustments for disabled employees as part of the recruitment process.
- As part of our pre-employment screening, successful candidates may be asked to complete a medical questionnaire administered by Health Assured Limited in order that we can take account of any medical issues relating to a new employee, including our obligation to make reasonable adjustments in the workplace. Health Assured Limited will only share information from this questionnaire with us with your express consent.
We will always treat information about health as confidential and it will only be shared internally where there is a specific and valid purpose to do so. We have implemented appropriate physical, technical, and organisational security measures designed to secure your personal information against accidental loss and unauthorised access, use, alteration, or disclosure.
If a candidate is successful, any health information processed as part of the recruitment process that is relevant to Dunham Wealth Limited’s compliance with its obligations in connection with employment will be retained and processed in accordance with the Employee Privacy Notice. If a candidate is unsuccessful, any health information obtained as part of recruitment processes will be deleted with the rest of the candidate’s personal information within six months of their rejection.
How long do we keep personal information for?
Dunham Wealth Limited’s policy is to retain personal information only for as long as needed to fulfil the purpose(s) for which it was collected, or otherwise as required under applicable laws and regulations. Under some circumstances we may anonymise your personal information so that it can no longer be associated with you. We reserve the right to retain and use such anonymous data for any legitimate business purpose without further notice to you.
For unsuccessful candidates:
- We will retain personal information collected during the recruitment process for a maximum period of 6 months from the end of the process subject to any exceptional circumstances and/or to comply with particular laws or regulations.
If you are offered and accept employment with us, some of the personal information we collected during the application and recruitment process will become part of your employment record and we may use it in connection with your employment in accordance with the Employee Privacy Notice. The remaining data will be stored for a period of 6 months then deleted.
4. What marketing activities do we carry out?
We carry out the following marketing activities depending on the relationship that we have with you:
Where you are a prospective client
We will use your personal information to provide you with information about our services and any newsletters and event invites where you have provided your consent for us to do so.
Where you are an existing client
We will use your personal information to provide you with information about our services and any newsletters and event invites where it is part of the ongoing services we offer or where you have provided your consent for us to do so.
General marketing practices
If you wish to opt out of marketing, you may do so by contacting us, responding to any marketing communication confirming you would like to opt out or telling us when we call you. Otherwise, you can always contact us using the details set out in section 11 to update your contact preferences.
Please note that, even if you opt out of receiving marketing messages, we may still send you communications in connection with the services we offer you.
5. How long do we keep personal information for?
We will only keep your personal information for as long as reasonably necessary to fulfil the purposes set out in section 2 above, to comply with our legal and regulatory obligations or for as long as necessary to respond to concerns you raise with the advice you received. As a financial service firm, we are regulated by the Financial Conduct Authority (the FCA) who imposes certain record-keeping rules which we must adhere to.
If you would like further information regarding the periods for which your personal information will be stored, please contact us using the details set out in section 11.
6. What is our approach to sending your personal information overseas
There are a small number of instances where your personal information is transferred to countries outside of the European Economic Area (“EEA“) such as when we transfer information to our other companies in the SJP group or to third party suppliers who are based outside the EEA or when third parties who act on our behalf transfer your personal information to countries outside the EEA. Where such a transfer takes place, we will take the appropriate safeguarding measures to ensure that your personal information is adequately protected. We will do so in a number of ways including:
- Entering into data transfer contracts and using specific contractual provisions that have been approved by European data protection authorities otherwise known as the “standard contractual clauses”. You can find out more about standard contractual clauses at https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en;
- We will only transfer personal information to companies in non-EEA countries who have been deemed by European data protection authorities to have adequate levels of data protection for the protection of personal information. You can find out more about this https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en
We are also entitled under European data protection laws to transfer your personal information to countries outside the EEA where it is necessary for the performance of the contract, we have with you.
Depending on our relationship and your particular circumstances, we might transfer personal information anywhere in the world.
If you would like further information regarding our data transfers and the steps, we take to safeguard your personal information, please contact us using the details set out in section 11.
7. How do we protect your information?
At Dunham Wealth Limited, we take our responsibility to look after your personal information and privacy seriously. In today’s world, we have all seen a growing trend in cybercrime and security breaches. We have a number of security measures in place to help prevent fraud and cybercrime.
If we become aware that a personal data breach has occurred and is likely to result in a high risk to the rights and freedoms of our clients, advisers, or employees, we will inform them without undue delay.
We have a dedicated group, the ‘Information Security Oversight Committee’, that provides oversight and guidance to our information security and privacy programme.
The executive body responsible for privacy and data security is the Information Security Oversight Committee (ISOC) – chaired by the Data Protection Officer. ISOC has a reporting line that enables effective escalation of issues up to the Board where appropriate.
We educate and train our employees, Partners and contractors on their information security, fraud prevention and privacy obligations annually.
Our employees and contractors take part in an annual Information Security training and awareness program and must agree to adhere to the Data Protection Act and our own Information Security Policy that are designed to keep your information safe. These are refreshed each year to reflect the current trends that are being observed across the information security landscape. Information Security awareness also forms part of our new employee induction program.
We also educate our employees in identifying potential financial crime and internal fraud; any suspicious activity is reported to our Financial Crime Prevention team.
We will always interact with you in a safe, secure, and consistent manner
To keep your information secure and to protect our clients from fraud, Dunham Wealth Limited will only interact with you in the following ways. If in doubt, call your Dunham Wealth Limited Adviser directly.
When interacting with you, we will:
- Only send funds that you have requested to be withdrawn to a verified bank account in your name.
- Verify who you are when speaking to you on the phone, by asking you security questions.
We will not:
- Ask you for your password over the phone.
- Ask you for credit card details by email or telephone.
- Call you to notify you of a problem, and then request you call us back immediately to discuss the problem further.
We continually review our physical and logical security controls in place across the business.
Physical controls – As well as protecting your digital information, Dunham Wealth Limited also protects their premises and physical locations where personal data may be used and stored. These measures include secure entrances, secure disposal of confidential waste and hardware and locks on doors and file storage cabinets, with a ‘clear desk’ policy to ensure all information is locked away and protected.
Logical controls – Dunham Wealth Limited uses technical security measures to make sure our systems where we store and use personal information are protected from unauthorised access. Tools such as authentication controls, antivirus, firewalls, malware detection and back-up procedures are used across the business.
All employee emails and devices are encrypted to enable secure transfer and storage of personal information.
We conduct security testing of our applications and services in a controlled testing environment before they are made available for our clients to use on an ongoing basis.
We perform security risk assessments for each of our sites to identify and control risks.
External technical assessments are conducted by an independent external 3rd party.
Security audits and vendor due diligence are conducted on a continual basis.
We have a business resiliency plan with disaster recovery and business continuity testing.
The purpose of Business Continuity Management and the Dunham Wealth Limited Business Continuity Plan is to provide an effective, predefined, and documented framework to respond to an incident affecting our activities. The key drivers in developing the business recovery plans are.
- To mitigate the risks that could lead to the significant disruption of our products and services to our clients.
- To provide a recovery plan that supports a timely and full restoration of our products and services for our clients.
However, whilst we take appropriate technical and organisational measures to safeguard your Personal Information, please note that we cannot guarantee the security of any data that you transfer over the internet to us.
8. Cookies
Our website uses cookies – small text files that are stored on your computer or in your browser – to help us to monitor how visitors use our site and allow us to maintain the optimum experience for website users. The website does not store or capture personal information about you when you visit it, it merely records traffic information. This means information about all of our visitors collectively, for example the number of visits the website receives. In order to respect our visitors’ rights of privacy, this information is anonymous, and no individual visitor can be identified from it.
You can disable and delete cookies by changing the appropriate setting within your browser’s ‘Help’, ‘Tools’ or ‘Settings’ menu.
9. Monitoring
Please note that if you communicate with us electronically, including by e-mail, telephone or fax, this communication may be randomly monitored and/or recorded to protect the interests of our business and our customers. This includes for the purposes of maintaining customer/service quality standards, detection of and/or prevention of crime and to ensure that Dunham Wealth Limited employees comply with legal obligations and Dunham Wealth Limited policies and procedures (including our customer relations practices).
10. Your rights
You have several rights which you can exercise at any time relating to the personal information that we hold about you and use in the ways set out in this notice. Please contact us at any time if you wish to exercise these rights; we will not usually charge you.
We respect your rights and will always consider and assess them but please be aware that there may be some instances where we cannot comply with a request that you make as the consequence might be that:
- In doing so we could not comply with our own legal or regulatory requirements for example we are under obligations to hold records of our dealings with you for certain periods of time; or
- In doing so we could not provide services to you and would have to cancel your client agreement, for example we could not enter into investments on your behalf if we had deleted your personal information.
We will of course inform you if any of the above situations arise and if we are unable to comply with your request.
The right to access your personal information
You are entitled to a copy of the personal information we hold about you and certain details of how we use it.
We are happy to provide you with such details but in the interests of confidentiality, we follow strict disclosure procedures which may mean that we will require proof of identify from you prior to disclosing such information.
We will usually provide your personal information to you in writing unless you request otherwise. Where your request has been made electronically (e.g. by email), a copy of your personal information will be provided to you by electronic means where possible.
It would be helpful if you could please complete the Data Subject Request Form, available from Dunham Wealth Ltd directly, to request a copy of the information we hold so that we can ensure we have all the relevant information we need to appropriately respond to your request.
The right to rectification
Please help us to keep your personal information accurate and up to date so if you believe that there are any inaccuracies, discrepancies or gaps in the information we hold about you, please contact us and ask us to update or amend it.
The right to restriction of processing
In certain circumstances, you have the right to ask us to stop using your personal information, for example where you think that the personal information we hold about you may be inaccurate or where you think that we no longer need to use your personal information.
The right to withdraw your consent
Where we rely on your consent to process your personal information, you have the right to withdraw such consent to further use of your personal information.
The right to erasure
You are entitled to request your personal information to be deleted in certain circumstances such as where we no longer need your personal information for the purpose we originally collected it. When you exercise this right, we need to consider other factors such as our own regulatory obligation, to assess whether we can comply with your request.
The right to object to direct marketing
You have a choice about whether or not you wish to receive marketing information from us and you have the right to request that we stop sending you marketing messages at any time. You can do this by contacting using the details set out in section 11.
Please note that, even if you opt out of receiving marketing messages, we may still send you communications which are relevant to the nature of services we offer you.
The right to object to processing
In certain circumstances, where we only process your personal data because we have a legitimate business need to do so, you have the right to object to our processing of your personal data.
The right to data portability
In certain circumstances, you can request that we transfer personal information that you have provided to us to a third party.
When you exercise this right, we need to consider other factors such as our own regulatory obligations, to assess whether we can comply with your request
Rights relating to automated decision-making
We do not carry out any automated decision making to provide products and services to you.
The right to make a complaint with the ICO
If you believe that we have breached data protection laws when using your personal information, you have a right to complain to the Information Commissioner’s Office (ICO).
You can visit the ICO’s website at https://ico.org.uk/for more information. Please note that lodging a complaint will not affect any other legal rights or remedies that you have.
11. Contacting us
If you would like any further information about any of the matters in this notice or if you have any other questions about how we collect, store, or use your personal information, you may contact our Principal firm’s Data Protection Officer at Perennial Financial Management Limited, St. James’s Place House, 1 Tetbury Road, Cirencester, Gloucestershire, GL7 1FP, dpo@sjp.co.uk or on 01285 878 453.
12. Updates to this notice
From time to time we may need to make changes to this notice, for example, as the result of changes to law, technologies, or other developments. We will provide you with the most up to date notice.
This notice was last updated on 12th May 2022.
Contact Us
Peak House, 6 Oxford Road, Altrincham, Cheshire, WA14 2DY
Telephone: 0161 676 2380 Email: enquiries@dunhamwealth.co.uk