In short
This notice explains how Edale UK Management Ltd (“Edale”, “we”, “us”, “our”) collects and uses your personal information when you use the Edale Wealth Hub at wealth.edale.co, and the rights you have over that information.
- We are the data controller. We decide how and why your information is used, and we are responsible for looking after it under the UK GDPR, the Data Protection Act 2018, and — for marketing and cookies — the Privacy and Electronic Communications Regulations 2003 (PECR).
- We use your information only for defined purposes, each with a lawful basis — running your membership, verifying your identity as the law requires, delivering the planning tools, giving you regulated advice, taking payment, keeping the records our regulator requires, and keeping the service secure. Consent is the basis for only a few things (marketing to non-customers, non-essential cookies, storing a card if auto-renewal is ever switched on). Consent is not the basis for the service as a whole.
- Some of what we do, the law requires — in particular checking your identity to prevent money laundering, and keeping records of any regulated advice we give you. This means we cannot always delete your information when you ask, and we explain when.
- We never hold your full card number. Payments are handled by Stripe.
- We do not sell your data, and we found no advertising, analytics or social-media tracking tools on the Hub.
- You have rights over your information, including the right to a copy of it and the right to complain to the Information Commissioner’s Office (ICO).
The rest of this notice sets all of this out in full. If anything is unclear, please ask us using the details in section 1.
Contents
- Who we are and how to contact us
- What this notice covers
- The personal information we collect
- Where we get your information from
- How and why we use your information — and our lawful basis
- Special category and criminal-offence information
- Profiling and automated decision-making
- Marketing and your choices
- Who we share your information with
- Sending information outside the UK
- How long we keep your information
- How we keep your information secure
- Your rights
- Cookies
- Children
- If you die, lose capacity, or ask someone to act for you
- Changes to this notice
- How to complain
- Version and date
1. Who we are and how to contact us
The Edale Wealth Hub is operated by Edale UK Management Ltd, the data controller for the personal information described in this notice.
| Legal entity | Edale UK Management Ltd (registered in England and Wales) |
| Company number | 08865887 |
| VAT number | 501714728 |
| Registered office | 58 Castle Walk, Reigate, RH2 9PX, United Kingdom |
| Regulator | Authorised and regulated by the Financial Conduct Authority (FCA), firm reference number 812332 |
| Data-protection contact (email) | hq@edale.co |
| Post | Data Protection, Edale UK Management Ltd, 58 Castle Walk, Reigate, RH2 9PX |
| Telephone | 0207 99 35 360 |
| Data Protection Officer | FAO Data Protection Officer |
| ICO registration number | ZA515577 |
If you have any question about how we use your information, or you want to exercise any of your rights, please contact us using the data-protection details above.
2. What this notice covers
The Wealth Hub is two things in one place, and it helps to keep them apart, because the information involved and our reasons for holding it are different:
- The online planning tools — cashflow planning, risk profiling, tax record-keeping, and a market monitor. Using the tools is not a regulated activity.
- One-to-one advice sessions — where one of our advisers may give you regulated financial advice. This is regulated by the FCA and produces records we are legally required to keep.
This notice covers both. It complements — but does not replace — the separate privacy information of our advisory business at edale.co. Being a Hub member does not make you an advisory client of edale.co. We shall only share your Hub information with the advisory business, or the reverse, where you have asked us to or where it is necessary to deliver something you requested. All data remains within the same firm.
This notice does not cover other organisations’ own dealings with you — for example your bank, or a product provider — even where we introduce you to them. They have their own privacy notices.
3. The personal information we collect
We collect and hold the following categories of personal information. Not all of it applies to every member — for example, we only hold suitability and advice records if you take an advice session.
Account and identity information
- Your name, email address, telephone number and nationality.
- Tax identification numbers, such as your National Insurance number and, where relevant, other tax reference numbers.
- Your login credentials, and your user and membership records.
Financial planning information (held in your cashflow plans and their edit history)
- Detailed personal financial information you enter — income, assets, pensions, savings and expenditure.
- Cross-border UK/US account details, where you provide them, and inherited-asset details. This information is highly sensitive to you in a financial sense, although it is not “special category” data under the UK GDPR (see section 6). We also keep an audit log of changes to your plan data.
Risk-profiling information
- Your answers to an attitude-to-risk questionnaire, and the risk-profile description produced from them.
Tax records and tax-support information
- UK and, where relevant, US tax information you record in the tax tools, including information the tools use to reference IRS / FinCEN reporting for US-connected clients.
Advice and suitability records
- Where we give you a personal recommendation, the fact-find, the suitability assessment, the written suitability report, and our record of the advised session.
Support-needs / vulnerability information
- Where you tell us (or it becomes apparent) that you have a support need — for example ill-health, a disability, bereavement, caring responsibilities or financial difficulty — we record what we need to make reasonable adjustments and to meet the FCA’s Consumer Duty (Terms of Service clause 24.1). Some of this may be health information — see section 6.
Booking information
- Appointment details and availability.
- Where a session is delivered by video, the meeting link and associated calendar entry (currently via Google Meet / Google Calendar).
Payment information
- Your Stripe customer and payment identifiers, and the amount and date of each payment. This covers membership and bundle purchases and, where you take a personal recommendation, any separately agreed adviser charge (Terms of Service clauses 5.7 and 9.16).
- If and when auto-renewal is switched on and you opt into it: the card brand, the last four digits and the expiry date of your card, together with the timestamp and IP address recorded when you give your recurring-payment mandate. Auto-renewal is built but not yet switched on (Terms of Service clause 9.13), so we do not hold any card-on-file data today.
- We never receive or store your full card number or your security code (CVV). Stripe holds those, not us.
Activity and consent logs
- A log of actions taken in the portal, linked to user IDs, and — for consent events such as an auto-renewal mandate — the IP address recorded at the time.
Correspondence and preferences
- Your marketing preferences.
- Emails, letters and telephone contact with us. Calls and meetings may be recorded or monitored for training, quality and compliance purposes.
4. Where we get your information from
Most of the information we hold comes directly from you — when you register, complete your profile, use the tools, enter your financial or tax information, book and attend sessions, make a payment, or contact us.
We also obtain some information from other sources:
- Stripe, which confirms the outcome of your payments and, where auto-renewal is enabled and you opt in, provides the card brand, last four digits and expiry date described above.
- Publicly available sources and registers, where necessary to meet our AML and regulatory obligations.
- People who act for you — for example an attorney, deputy, or a trusted person you have nominated (section 16).
5. How and why we use your information — and our lawful basis
The law requires us to have a “lawful basis” for everything we do with your information. Our bases are:
- Contract — using your information to provide the service you signed up for.
- Legal obligation — where the law requires us to process the information (for example anti-money-laundering law, and FCA record-keeping rules).
- Legitimate interests — where we have a genuine business reason that is not overridden by your rights (we explain the interest in each case).
- Consent — where we ask for your specific, freely given agreement, which you can withdraw at any time.
Where special category or criminal-offence information is involved, we also need an additional condition — see section 6.
| Purpose | Information used | Lawful basis | Retention driver (see section 11) |
|---|---|---|---|
| Create and administer your account and membership; log you in; provide the portal | Account and identity information; login credentials; activity logs | Contract | Life of your membership, then a reasonable period |
| Verify your identity, carry out due diligence and ongoing monitoring (AML/CDD) | AML/CDD information; identity and tax reference numbers; nationality | Legal obligation — Money Laundering Regulations 2017 (including the ongoing-monitoring duty) | 5 years after our relationship ends (MLR 2017) |
| Screen against sanctions and adverse-media / financial-crime sources | Identity information; screening results (may include criminal-offence information) | Legal obligation, plus a DPA 2018 Schedule 1 condition for any criminal-offence data — see section 6 | AML record-keeping, as above |
| Provide the self-service planning tools (cashflow planner, risk profiler, tax tools) and generate their outputs | Financial planning information; risk-profiling information; tax records | Contract | Life of your membership; then available for export for at least 30 days after your account closes, unless a regulatory hold below applies |
| Deliver advice sessions, assess suitability, and produce suitability reports | Advice and suitability records; financial, risk and tax information; booking information; support-needs information | Contract, and Legal obligation for the records the FCA requires us to keep | FCA record-keeping (see section 11) — applies to the advice file, not to unregulated tool data |
| Book, reschedule and manage appointments, including by video | Booking information; meeting links and calendar entries | Contract | Short-term operationally; advised-session records kept under FCA rules |
| Take and reconcile payments; provide receipts; charge any agreed adviser fee | Payment information (Stripe IDs, amount, date) | Contract; and Legal obligation for tax and accounting records | Tax / accounting record-keeping 5 years |
| Operate auto-renewal and store a card on file (only if the facility is switched on and you opt in) | Card brand, last four, expiry; mandate consent timestamp and IP | Consent to store the card; the recurring charge itself relies on Contract | Card details deleted as soon as you cancel auto-renewal |
| Make reasonable adjustments and meet the Consumer Duty for members with support needs | Support-needs / vulnerability information (may include health data — section 6) | Contract / Legal obligation (FCA rules); plus an Article 9 condition for any health data — section 6 | Life of your membership; advice-file elements under FCA rules |
| Keep the records the FCA and other law require | Advice, suitability, transaction, complaint and communication records; call recordings where made | Legal obligation | FCA record-keeping (see section 11) |
| Record or monitor calls and (if applicable) video sessions for training and quality | Correspondence; call / session recordings | Legitimate interests — training, quality assurance and evidencing what was discussed. (Once a recording forms part of an advice file, we then keep it under our Legal obligation to retain advice records.) | 5 years |
| Keep the service secure; detect, prevent and investigate fraud, misuse and incidents | Activity and consent logs; IP addresses; account information | Legitimate interests — protecting you, other users and our systems, and preventing fraud | 5 years |
| Handle and resolve complaints; establish, exercise or defend legal claims | Correspondence; relevant account, advice and payment records | Legal obligation (FCA complaint-handling rules), and our Legitimate interests in defending claims | Until resolved, plus the limitation period for legal claims |
| Send you service and transactional messages (renewal reminders, payment notices, booking confirmations, changes to terms) | Account and contact information | Contract / Legal obligation | Life of your membership |
| Market our own similar services to you as an existing customer | Contact details; marketing preferences | Legitimate interests (the PECR “soft opt-in” — see section 8) | Until you object or unsubscribe |
| Market to you where you are not yet a customer | Contact details; marketing preferences | Consent (as PECR requires) | Until you withdraw consent |
| Administer, analyse and improve the service | Usage and account information | Legitimate interests — running and improving the Hub | |
| Respond to regulators, courts and lawful authority requests | Whatever is lawfully required | Legal obligation | As required by the relevant law |
About “legitimate interests”. Where we rely on legitimate interests, we have weighed our interest against your rights and are satisfied our use is fair and not overridden by them. You can ask us for more detail about that balancing, and you can object (section 13).
About “consent”. Consent is the basis for only a few specific things — marketing to non-customers, non-essential cookies, and storing a card on file for auto-renewal (if that facility is switched on). Where we rely on consent you are free to say no, and free to change your mind later, without affecting anything done beforehand.
A note on the tools and the advice boundary. The self-service tools are not a regulated activity, and FCA record-keeping does not attach to the data you keep in them. FCA retention applies only to information that becomes part of an advice / suitability file.
Do you have to provide it? Some information is a statutory or contractual requirement. If you do not provide the identity information the AML rules require, we are not permitted to provide a regulated service, and may have to refuse or close your account (in which case we refund you as set out in the Terms of Service). If you do not provide the information we need to assess suitability, we may not be able to advise you. Using the planning tools is optional, but they cannot produce useful outputs without the figures you choose to enter. Marketing and auto-renewal are entirely optional.
6. Special category and criminal-offence information
Some information needs extra legal protection. We keep it to a minimum, and please do not send us more of it than we ask for.
Special category information (particularly sensitive information, such as about your health). We do not need it to run the Hub, and you should not enter it into the tools. But you may sometimes share it with us — for example if you ask about ill-health early retirement or a health-related annuity, or if you tell us about a health condition so we can make reasonable adjustments (section 3). Where we process it, we need both a lawful basis under Article 6 (usually contract or legal obligation) and a condition under Article 9.
7. Profiling and automated decision-making
We want to be clear about this, because our tools produce automated outputs.
- The tools generate their outputs automatically from what you enter. The cashflow planner, risk profiler and tax tools calculate results from your inputs, without a person reviewing them first. These are information and illustrations to help you think — not predictions, recommendations, or decisions we make about you, and they have no legal or similarly significant effect on you.
- The risk profiler involves profiling. It analyses your questionnaire answers to describe your attitude to investment risk. We tell you about it here because it is a form of profiling under the UK GDPR. The output is a description; it does not, by itself, decide anything or recommend any investment.
- We do not make solely automated decisions that have a legal or similarly significant effect on you. Any personal recommendation is made by a qualified human adviser, who uses your risk profile and other information as one input into assessing what is suitable for you. Because a person is always involved, the automated-decision restrictions in Article 22 of the UK GDPR do not apply.
If you would like to understand how the risk profiler reached its result, please ask us.
8. Marketing and your choices
- If you are already our customer, we may send you information about our own similar services by email, relying on our legitimate interests under the PECR “soft opt-in” — meaning we can contact existing customers about similar things unless you tell us to stop. Every message includes a one-step unsubscribe.
- If you are not yet our customer, we will only market to you where you have given consent, which you can withdraw at any time.
- We do not sell your information, and we do not share it with third parties for their own marketing.
To change your preferences or opt out, use the unsubscribe link in any message, change your preferences in the portal, or contact us. Opting out of marketing does not stop the service messages we must send to run your account (receipts, renewal notices, security alerts and the like).
9. Who we share your information with
We share your information only where necessary, and only with organisations bound to protect it. We do not sell it, and we found no advertising, analytics or social-media tracking tools on the Hub.
Service providers (“processors”) who handle information on our behalf and under our instructions:
- Stripe — payment processing and, if auto-renewal is switched on and you opt in, secure storage of your card. Stripe holds your full card details; we do not.
- Google — Google Meet and Google Calendar, used to schedule and deliver advice sessions by video (meeting links and calendar entries).
- Kinsta — website and database hosting (Kinsta runs on Google Cloud Platform).
- Google Workspace — sending transactional and service emails.
- Cloudflare — as our content delivery network
- the market monitor is fed by market and price data only and does not use your personal information.
We put a written contract in place with each processor requiring it to protect your information and use it only on our instructions.
Others we may share with, where the law allows or requires:
- The National Crime Agency (NCA) — where anti-money-laundering law requires us to report a suspicion. The law may prohibit us from telling you that we have made such a report.
- Regulators and authorities — including the FCA, HMRC, and the ICO — where we are legally required to provide information, and law enforcement and the courts where lawfully required.
- The Financial Ombudsman Service (FOS) and the Financial Services Compensation Scheme (FSCS) — if you complain or make a claim, we share the personal information needed to deal with it.
- Our professional advisers and insurers — our lawyers, auditors, compliance advisers and professional-indemnity insurers, where necessary and under a duty of confidentiality.
- US tax authorities or your own US tax advisers — only where relevant to a US-connected client’s own tax position and reporting, and only as necessary. We do not file or report to tax authorities on your behalf.
- A buyer or successor — if our business is reorganised or transferred, on terms that protect your information.
We do not share your Hub information with the edale.co advisory business, or the reverse, except where you have asked us to or where it is necessary to deliver something you requested.
10. Sending information outside the UK
Some of the organisations we use are based outside the UK, or store or process information outside it. Whenever information is transferred outside the UK, the law requires us to make sure it is properly protected — either because the destination has “adequate” data-protection rules recognised by the UK, or by putting an approved safeguard in place. Approved safeguards include the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or a certification under the UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”).
- Stripe is headquartered in the United States, so paying involves an international transfer. The safeguard relies on UK–US Data Privacy Framework certification and/or the UK IDTA / Addendum.>
- Google (Meet / Calendar, and any email / document platform) may process information outside the UK.
- Hosting Data is hosted in a UK.
- US-connected tax information — where relevant to a US-connected client’s own filing, information may be shared as described in section 9.
You can ask us for more detail about these transfers, and for a copy of the relevant safeguards, using the contact details in section 1.
11. How long we keep your information
We keep your information only for as long as we need it for the purposes above, and for as long as the law requires. Because we are a regulated financial firm, several periods are set by regulation, and we cannot delete the information early even if you ask (see section 13). The main drivers are:
| Type of record | How long we keep it | Why |
|---|---|---|
| AML / Customer Due Diligence records (identity, due diligence, source of funds / wealth) | 5 years after our business relationship ends, then deleted unless another legal ground below requires longer | Money Laundering Regulations 2017 (regulation 40) |
| Advice and suitability records | The period the FCA requires — commonly at least 5 years for investment advice, and longer for some pension advice | FCA record-keeping rules |
| Payment, tax and accounting records | 5 years | Tax and accounting law |
| Complaint records | Until resolved, plus the period FCA rules and legal-claim limitation require | |
| Account, tool and planning data not under a regulatory hold | Life of your membership; available for export for at least 30 days after your account closes (Terms of Service clause 13.8), then deleted or anonymised | Contract; storage limitation |
| Call / session recordings | 5 years | Training / quality; and advice record-keeping where part of an advice file |
| Security and activity logs | 5 years | Security and fraud prevention |
| Marketing preferences and consent records | While you remain a contactable member, and for a reasonable period afterwards to evidence your choices | — |
We do not keep records of defined-benefit or other safeguarded-benefit pension-transfer advice, because we do not give that advice — it is outside our permissions (Terms of Service clause 4.1(h)).
When a retention period ends, we securely delete or anonymise the information.
12. How we keep your information secure
We take the security of your information seriously and use appropriate technical and organisational measures to protect it, which are expected to include:
- encryption of data in transit;
- restricting access to those who need it to do their job;
- storing card details with Stripe, a PCI-DSS-compliant payment processor, rather than in our own systems, so we never hold your full card number;
- account-security features including a strong password and, where available, two-factor authentication;
- logging significant actions in the portal;
- choosing service providers who are contractually required to keep your information secure.
No online service can be guaranteed completely secure, so please keep your login details confidential and tell us straight away if you think your account has been accessed by someone else. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the ICO, and you where the law requires it.
(This section describes our security measures. It does not, and is not intended to, limit or exclude any responsibility we owe you.)
13. Your rights
Under UK data-protection law you have the following rights over your information. They are normally free to exercise, and we will respond within one month (we can extend by up to two further months for complex requests, and will tell you if we do). We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain if that ever applies.
- The right to be informed — which this notice provides.
- The right of access — to a copy of the information we hold about you.
- The right to rectification — to have inaccurate information corrected and incomplete information completed.
- The right to erasure — to ask us to delete your information in certain circumstances. This right is limited where we must keep information to meet a legal obligation (for example the AML and FCA record-keeping rules in section 11). We will explain when that applies.
- The right to restrict processing — to ask us to pause certain uses of your information in certain situations.
- The right to data portability — for information you gave us that we process by consent or under our contract, and by automated means, you can ask for it in a common, machine-readable format, or ask us to send it to another organisation where technically feasible. You can also ask us for a copy of your data at any time, including after your membership ends, and we will provide it free of charge (Terms of Service clause 13.8).
- The right to object — you can object to processing based on our legitimate interests, and you have an absolute right to object to direct marketing at any time, which we will always honour. (The right to object does not apply to processing we carry out to perform our contract or to meet a legal obligation.)
- Rights relating to automated decision-making and profiling — see section 7.
- The right to withdraw consent — where we rely on your consent (marketing to non-customers, non-essential cookies, storing a card for auto-renewal, or any special category information based on explicit consent), you can withdraw it at any time, without affecting anything done beforehand.
A limit set by anti-money-laundering law. If we have reported, or are considering reporting, a suspicion about you to the authorities, the law may prevent us from confirming this or from giving you access to the related information, because doing so could “tip off” and is a criminal offence. Where that applies we may not be able to meet an access or erasure request in full, and may not be able to tell you why.
To exercise any of these rights, contact us using the details in section 1. We may need to confirm your identity first, to protect your information. If we cannot fully meet a request, we will tell you why and remind you that you can complain to the ICO (section 18). You also have the right to an effective judicial remedy.
14. Cookies
The Hub uses cookies and similar technologies that are necessary to make the site work, keep you logged in, and keep it secure. Where we use any non-essential cookie, we will ask for your consent first, as PECR requires, and you can change your choice at any time. Full details are in our Cookie Policy.
15. Children
The Wealth Hub is a service for adults. It is not directed at, and we do not knowingly collect information from, anyone under 18. All members must be at least 18 (Terms of Service clause 7.1). If you believe a child has given us personal information, please contact us and we will delete it.
16. If you die, lose capacity, or ask someone to act for you
You can nominate a trusted person to deal with us on your behalf, or act through an attorney or deputy. Where you do, we will collect and hold the information needed to deal with them, and we may share your information with them so far as the law and your instructions allow (Terms of Service clauses 24.2–24.3). If you die, we will make your information available to your personal representatives so far as the law allows. Where we hold information about a person you nominate, we rely on our legitimate interests (and yours) in acting on your instructions.
17. Changes to this notice
We may update this notice from time to time — for example to reflect changes in the law, in our providers, or in how the service works. When we make a significant change, we will tell you (for example by email or through the portal) and update the version and date below. Previous versions are available on request. Because this is a transparency document and not a contract term, updating it does not change your contract with us.
18. How to complain
If you are unhappy with how we have handled your information, please tell us first, using the contact details in section 1 — we would like the chance to put it right.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data-protection regulator, at any time:
Information Commissioner’s Office — ico.org.uk Telephone: 0303 123 1113.
Complaining to the ICO is free and does not affect any other right you have. A complaint about our financial services (as opposed to our data handling) is dealt with under section 22 of the Terms of Service and may be referred to the Financial Ombudsman Service.
19. Version and date
Version 1.0 dated 21 July 2026. Controller: Edale UK Management Ltd (FCA FRN 812332).