Privacy Policy

Last updated: March 2026


  1. Contents

Document Control Page. 2

1. Contents. 3

2. Definitions. 4

3. Objective. 5

4. Ownership. 5

5. Updating the Document 5

6. Data Security. 5

7. Data Collection and Usage. 5

8. Greengage Privacy Policy. 6




  1. Definitions
ClientAn existing client of the Firm, a potential client of the Firm or a past client where fiduciary or other duties remain in place.
Company and/or FirmGreengage
ConsentWhere an individual or client has agreed to Greengage collecting personal data including where appropriate sensitive data.
COOChief Operating Officer
CTOChief Technology Officer
Data BreachA security incident leading to accidental or unlawful access, loss, or disclosure of personal data
Data ControllerThe entity that determines the purposes and means of processing personal data
Data ProcessorAn entity that processes personal data on behalf of the controller
Data SubjectA natural person whose personal data is processed
GreengageGreengage & Co Group PLC
Legal obligationA legal responsibility to collect and store your personal data
Personal DataAny information relating to an identified or identifiable individual
ProcessingAny operation performed on personal data (e.g., collection, storage, use)
ProfilingAutomated processing of personal data to evaluate certain aspects of an individual
















  1. Objective

The purpose of this document is to outline Greengage’s privacy policy noting that Greengage is committed to protecting all relevant personal data held within its various systems. Greengage may use data for several different purposes including the provision of its services and in meeting its legal and regulatory requirements.

  1. Ownership

The Data Protection Officer is responsible for creating awareness of the policy and the related policy standards in this document through such means as induction for new joiners, training for employees and other forms of communication.

  1. Updating the Document

The Data Protection Officer supported by other members of the Firm has primary responsibility for reviewing and proposing amendments to this Policy which has a target to be reviewed every six months.

  1. Data Security

Greengage is committed to respecting privacy and safeguarding personal data. In compliance with applicable legislation Greengage should only retain data for as long as is necessary and must always dispose of it safely. If Greengage is required by law to share data with other organisations it must do so securely and should not share more than it needs to.

If Greengage asks another company to process data on its behalf or it outsources any process it should ensure that the supplier follows similarly high standards and has appropriate security measures in place. Greengage should ensure that suitable safeguards are in place before any personal data is transferred to other countries.

Greengage should implement and adhere to information retention policies relating to personal data and should ensure that personal data is securely disposed of at the end of the appropriate retention period. Greengage should also ensure that it has appropriate physical and technological security measures to protect personal data regardless of where it is held.

  1. Data Collection and Usage

Data should be used to process transactions safely and securely. Data can also help Greengage to personalise a client’s experience and develop new services whilst at the same time being used to help identify and mitigate fraud. Data can also help Greengage to focus on the needs of clients and in particular when dealing with or identifying vulnerable clients. Greengage should always be clear and open about how and why it is using an individual’s data ensuring that privacy notices are easily identifiable and readily available.

When considering Data and its usage Greengage should:

  1. Only collect and use personal data where it has lawful grounds and legitimate business reasons to do so. Any legitimate interest should be reasonable when balanced against your human rights and freedoms.
  2. Should be transparent in its dealings with any individual advising how it collects and uses personal data
  3. If Greengage has collected personal data for a particular purpose it should not use it for anything else unless the individual has been informed and where relevant given consent for it to be used
  4. Greengage should not ask for more personal data than is needed for the purposes for which it is collecting it
  5. Greengage should update its records when it has been informed that details have changed
  6. Greengage should on an ongoing basis review and assess the quality of any personal data that it holds
  7. Greengage should observe the rights to all individuals under applicable privacy and data protection laws and ensure that queries relating to privacy issues are promptly and transparently dealt with.
  8. Greengage Privacy Policy

(for the Protection of Personal Information)

1. Introduction

At Greengage (Greengage & Co Group PLC and all group companies), maintaining your privacy is extremely important to us and we are committed to protecting your personal data. Your relationship with us is built on a foundation of trust and we are committed to preserving that trust. This privacy policy applies where we are acting as a data controller with respect to your personal data — that is, where we determine the purpose and means of its processing. In some situations, Greengage may act as a joint controller with carefully selected third parties. Where this applies, we will make the nature of that relationship and shared responsibilities clear to you. This policy will inform you as to how we look after your personal data when you visit our website (regardless of where you visit it from) and tell you about your privacy rights and how the law protects you.

Greengage will:

  1. Always keep your personal data safe and private
  2. Never sell your personal data

2. Important information and who we are

Purpose of this privacy policy

This privacy policy aims to give you information on how we collect and process certain personal data through your use of our website. When we say personal data we mean:

  1. information that we know about you which may be provided when applying or using our services or products,
  2. information about you provided to us by third parties as part of applying or using our services or products,
  3. Information that we have obtained either via consent or legitimate interest,
  4. can be used to personally identify you (an example may be a combination of your name and postal address)

It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you (including and in particular the specific privacy policies of our investment vehicles) so that you are fully aware of how and why we are using your data. This privacy policy supplements such other notices and privacy policies and is not intended to override them.

We will collect your personal data when you use:

  1. Our website at www.Greengage.co
  2. The Greengage app
  3. Any of our service available to you through our app or website
  4. We may also collect your personal data from third parties in the course of you being classified as a prospective client (see below).

You should note that Data protection laws do not apply to information about legal entities however they do apply to individuals as such this policy only applies to personal data it does not apply to company information. Where Greengage provides products and services, we will process the personal data of individuals authorised to set the account up and give us instructions about the account. We may also process personal data about other individuals and clients of the company that receive or make use of Greengage products and services.

Controller

Greengage ("we", "us" or "our" in this privacy policy) is the data controller and is responsible for your personal data — that is, we determine the purposes and means of its processing. In certain limited cases, Greengage may act as a joint controller with trusted third parties (such as service providers or partner institutions). Where this applies, we will clearly inform you of the nature of that relationship and the allocation of responsibilities between the parties.

“You” or ““Your” means you as an individual, more than one individual if authorised to give instructions on behalf of a company or the company itself.

We have established a data protection group (the “DPG”), which is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact the DPG using the details set out below.

Contact details

If you have any questions about this privacy policy or our privacy practices, please contact our DPG in the following ways:

Full name of legal entity: Greengage & Co Group PLC

Email address: info@greengage.co

Postal address: Painters' Hall, 9 Little Trinity Lane, London, EC4V 2AD

You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance. You may make a complaint to us directly at any time using the contact details above. We operate an internal complaints procedure, will acknowledge your complaint within 30 days of receipt, and will investigate and respond to it in accordance with applicable data protection law.

Changes to the privacy policy and your duty to inform us of changes.

We keep our privacy policy under regular review. This version was last updated on 9th November 2022. Historic versions can be obtained by contacting the DPG as above.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

​​Third-party links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

Digital Legacy App:

For details on how we handle any personal data you provide in relation to the Greengage Digital Legacy App, please see the Greengage Digital Legacy App Privacy Notice on our website.

3. The types of personal data we collect

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect and process the following personal data about you:

  1. Information that you provide to us. By “information” we mean all of the personal and financial information about you that we collect, use, share and store. This includes information about you that you provide to us. Such information may include (by way of a non-exhaustive list) basic personal data such as first name; family name; job title; company name; company email address; business phone number; business address; city; postcode; and country. Most of the information collected by us is information which you have provided to us directly, whether this is from you signing up online to receive information from us or by your providing information to us should you become a client of ours.
  2. Information that we collect or generate about you. This includes (by way of a non-exhaustive list):
  3. transaction data which may include details about payments between us as a service supplier and other details of purchases made by you.
  4. technical data which may include internet protocol addresses, browser type and version, browser plug-in types and versions, time zone setting and location, operating system and platform and other technology on the devices that you use to access the Greengage site.
  5. a file with your client records and contact history to be used for enquiry purposes.
  6. correspondence with us or taking part in online discussions or promotions.
  7. responses to any of our surveys.
  8. speaking with a staff member (via our social media, website, on the phone or through the Greengage app).
  9. details of site and marketing/communication preferences.
  10. Government-issued identification (passport, driving licence).
  11. Financial account details.
  12. Communication preferences.
  13. Cookies and device fingerprinting data.
  14. Usage data from apps and web interfaces.
  15. information uploaded or shared within the Greengage Smart Data Room, including documents, declarations, financial data, or third-party materials submitted for evaluation purposes. Where documents are uploaded by third parties on behalf of others (e.g. introducers), Greengage relies on those parties to ensure lawful collection and sharing of any personal data provided.
  16. Contacting us for any other reasons.
  17. Information we obtain from other sources. This includes:
  18. Cookies. When you visit our website, cookies are used to collect information about the services that you use, and how you use them. Cookies are essentially a small amount of data which is transferred to and sometimes updated on your computer or other devices by our web servers. For more information on the cookies used by Greengage please see our Cookie Policy.
  19. Anonymised data. In addition to the categories of personal data described above, we will also process further anonymized information and data that is not processed by reference to a specific individual. Your information may be converted into statistical or aggregated data which cannot be used to re-identify you. It may then be used to produce statistical research and reports which may be shared within Greengage.
  20. Third parties or publicly available sources: We may receive personal data about you from various third parties and public sources including Government networks.
  21. We do not routinely collect Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Where our anti-money laundering, sanctions and fraud-prevention obligations require it, we may process personal data relating to criminal convictions and offences (including alleged offences), in reliance on a condition in Schedule 1 to the Data Protection Act 2018. Where our identity-verification processes involve biometric data, we will process it only where an appropriate condition under Article 9 UK GDPR applies.

​​4. How we use your personal data

​4.1 Your personal data may be stored and processed by us in the following ways and for the following purposes:

  1. for ongoing review and improvement of the information provided on our websites to ensure they are user friendly and to prevent any potential disruptions or cyber-attacks;
  2. to conduct analysis required to detect malicious data and understand how this may affect your IT system;
  3. for statistical monitoring and analysis of current attacks on devices and systems and for the on-going adaptation of the solutions provided to secure devices and systems against current attacks;
  4. to understand your needs and interests;
  5. for the management and administration of our business;
  6. to communicate with you in order to provide you with services or information about the Greengage group of companies and its products and services; or
  7. in order to comply with and in order to assess compliance with applicable laws, rules and regulations, and internal policies and procedures.
  8. To support decision-making processes (including credit brokerage evaluations) using proprietary tools such as the Greengage Smart Data Room, which is designed to organise, analyse and present relevant data in support of regulated and commercial assessments.

​4.2 However we use personal data we make sure that the usage complies with law and the law allows us and requires us to use personal data for a variety of reasons, including but not limited to the following:

  1. To perform our contractual obligations, for example when onboarding you as a client, managing your account, or providing you with our services;
  2. Where we have obtained your consent, such as for sending marketing communications where required by law;
  3. To comply with our legal and regulatory obligations, including anti-money laundering checks, fraud detection, sanctions screening, and tax reporting;
  4. Where necessary to establish, exercise, or defend legal rights, for example in the context of disputes, regulatory investigations, or litigation;
  5. Where processing is necessary for our legitimate interests, provided these are not overridden by your fundamental rights and freedoms. This includes:
  6. operating and improving our business and services;
  7. maintaining records, analysing trends, and developing new features;
  8. protecting against unauthorised access and misuse of our systems;
  9. supporting customer service and relationship management;
  10. maintaining compliance with internal policies and procedures, including data security, staff conduct, record-keeping, and operational integrity requirements.

Greengage will take steps to ensure that your personal data is accessed only by Greengage employees that have a need to do so for the purposes described in this Privacy Notice.

4.3 If you sign up to use the Greengage products and services, and were allowed to do so by law, we will assume you want to be notified by us by post, push notification, email or SMS text message with information about Greengage services, products or other relevant information. Where laws require us to obtain your consent to send direct marketing information, we will do so in advance. We reserve the right to use your personal data to tailor our communications to you. Our legal basis for this is our legitimate interest (to provide information relevant to your interests and to send you marketing information) and your consent (where required by law to collect your consent).

Cookies

You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please refer to our Cookie Policy. We set non-essential cookies (such as analytics and marketing cookies) only where you have given your consent through our cookie banner, which you can withdraw or change at any time. Certain low-risk cookies, including those used solely for website functionality and, where the applicable exemption applies, low-risk analytics, may be set without consent in accordance with the Privacy and Electronic Communications Regulations as amended.

Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

5. Disclosures of your personal data

​5.1 We may share your personal data within Greengage for the purposes described above. We may also share your data with Greengage group companies in order to:

  1. ensure that you obtain the best service
  2. protect you, our clients and our systems from fraud or harmful behaviour
  3. improve existing, or develop new products and services
  4. aid you in signing up to use other Greengage products and services
  5. inform you about Greengage and Greengage Group products and services that we think you may be interested in hearing about

​5.2 We may also share your personal data outside of Greengage for the following purposes:

  1. As part of our account opening and monitoring process, we may need to undertake a number of initial and ongoing checks. These include (but are not limited to) Know Your Business (KYB) verification, anti-money laundering (AML) checks, sanctions screening, identity verification, and address validation. Legal basis: legal obligation; performance of a contract; legitimate interests (compliance and fraud prevention).
  2. Where necessary to facilitate a payment into or out of your Greengage account, we may share certain personal data with relevant financial institutions or payment partners. Legal basis: performance of a contract.
  3. To monitor your account for fraud, suspicious activity or financial crime. We may use both internal and third-party tools to detect and investigate such activity. Legal basis: legal obligation; legitimate interests (fraud detection and prevention).
  4. With third-party agents and contractors (e.g. accountants, professional advisors, IT support and communications providers) for purposes related to service provision, technical support, compliance or platform hosting. These third parties are subject to appropriate data protection and confidentiality obligations and may only process your personal data in accordance with our written instructions. Legal basis: legitimate interests; performance of a contract.
  5. With communications service providers, such as WhatsApp, Telegram, and Slack, where these platforms may be used by Greengage staff to interact with clients or prospective clients. These services may process or store personal data in jurisdictions outside the UK or EEA, including the United States. Where Greengage uses such platforms, we take steps to minimise the personal data shared, assess the associated data protection risks, and limit their use to appropriate circumstances. You should be aware that such platforms operate under their own privacy terms and may not be subject to direct contractual obligations from Greengage. We therefore advise that sensitive or confidential information should not be shared via these channels unless properly encrypted or otherwise protected. Legal basis: legitimate interests (efficient communication); consent (where required).
  6. In connection with co-branded products, services, or promotions offered in partnership with carefully selected third parties. In these cases, we will always ensure that you are informed of how your personal data is shared and used. Legal basis: consent (where applicable); legitimate interests.
  7. Where we are required by law, including disclosures to tax authorities, regulators (e.g. FCA, ICO), courts or enforcement agencies. We will only do so in accordance with applicable legal requirements. Legal basis: legal obligation.

6. Credit Checks

Greengage may share your personal data with credit reference agencies or other providers of credit information, this is so that we can:

  1. confirm the details that you have provided when requesting or applying for a Greengage service or products
  2. make an assessment about whether to accept a service or product application

The data that we may share and receive in relation to any credit check will vary on the country of the individual making the application. Our legal basis for this is our legal obligation, consent (where we are required to collect your consent by law) and monitoring and enforcing contracts between you and us.

7. Prospective Clients

We may collect and use your personal data in order to provide services to you. This includes:

  1. your name;
  2. your email address and phone number (that you use for professional purposes);
  3. your employment details such as your employer and your job title; and
  4. records of our discussions (including records of phone calls).

We may obtain this personal data directly from you however we may also collect this personal data from other service providers or from public sources. Where we collect this information from other sources, we have due diligence processes in place to establish whether the information provided to us has been collected and shared fairly and lawfully. We collect and use your personal data because we have a legitimate interest in collecting and using it and this is reasonable when balanced against your right to privacy.

We provide you with the same legal rights as our clients and will only keep your personal data for as long as we need it for legitimate purposes. We will delete it promptly once we have deemed, we no longer have a legitimate interest in your personal data. We may use automated systems, including AI-based screening, to help assess and prioritise prospective client enquiries. Where this results in a significant decision about you made solely by automated means, we apply the safeguards described in section 8 (Automated decisions), including your rights to meaningful information about the decision, to make representations, to obtain human intervention, and to contest it.

8. Automated decisions

Greengage may use automated systems and services that evaluate your personal circumstances and other factors to assist in decisions related to the provision of services or products. These automated processes, often referred to as profiling, help us to deliver services that are efficient, consistent, and fair, using both data provided by you and other sources (such as risk databases or credit information).

We aim to offer bespoke services that are provided by people and empowered by technology. While automation can improve efficiency, we recognise that such techniques have inherent limitations — including risks that they may fail to fully understand the context or correlate information accurately. We acknowledge there is always a margin of error in these models and a balancing exercise is required when weighing up risks based on automated inputs.

Where the law permits, we may make decisions about you that produce legal or similarly significant effects based solely on automated processing — that is, without meaningful human involvement — in order to provide faster and more consistent decisions as we develop our use of technology. Where we do so, we act in accordance with Articles 22A to 22D of the UK GDPR (as substituted by the Data (Use and Access) Act 2025) and apply the safeguards set out below. Where such a decision would be based wholly or partly on special category data, or on personal data relating to criminal convictions and offences, we will make it on a solely automated basis only where a condition under Article 22B of the UK GDPR and an appropriate condition under Article 9 UK GDPR or Schedule 1 to the Data Protection Act 2018 applies.

Examples of automated elements within our workflows include client onboarding risk scoring, credit assessments, fraud screening and data analysis using the Greengage Smart Data Room. As our use of these tools develops, some of these decisions may be made on a solely automated basis. Where we make a significant decision about you based solely on automated processing, you have the right to be given meaningful information about the decision, to make representations about it, to obtain human intervention from a member of our staff who has the authority and competence to review and, where appropriate, change the outcome, and to contest the decision. To exercise any of these rights, please contact us using the contact details set out above.

9. Storage, transfers and retention

The information that we collect from you may be transferred to, and stored at, a destination outside the United Kingdom or the European Economic Area (the “UK/EEA”). It may also be processed by staff or systems operating outside these regions who work for one of our suppliers or service providers.

International transfers

Where we transfer your personal data outside the UK/EEA, we ensure that it is protected and transferred in a manner that complies with applicable data protection laws. This may include the use of:

  1. Adequacy regulations issued by the UK Government or European Commission (e.g. for countries deemed to provide an adequate level of protection);
  2. Standard Contractual Clauses (SCCs) or International Data Transfer Agreements (IDTAs), where appropriate;
  3. Other recognised legal transfer mechanisms or exemptions under UK GDPR.

Greengage may use certain communication platforms such as WhatsApp, Telegram, or Slack in limited circumstances to interact with clients or stakeholders. These platforms may store or route personal data through jurisdictions outside the UK or EEA, including the United States.

Greengage does not have direct contractual control over these third-party platforms. As such, we limit use of these channels to informal, non-sensitive interactions and strongly advise against sharing confidential or special category personal data over them unless protected through encryption or similar safeguards. Users should be aware that these platforms process data under their own terms of service and privacy policies.

10. Data storage and security

Greengage is committed to respecting your privacy and safeguarding your personal data. We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, disclosure, alteration, or destruction.

We store your personal data in secure environments, which include encryption (both in transit and at rest), access controls, secure backups, and system monitoring. Access to personal data is limited to authorised personnel on a need-to-know basis, and we regularly review our security policies and controls to ensure they remain effective and up to date.

Where data is uploaded to the Greengage Smart Data Room, it is handled in accordance with this Privacy Policy. Access is restricted to authorised personnel for the purpose of evaluating commercial or regulatory decisions, such as credit brokerage opportunities. All documents uploaded to the platform are retained and processed in line with our data security and retention procedures. Users should avoid submitting unnecessary personal data unless specifically requested or required for the decision-making process.

Some of our third-party service providers — including cloud infrastructure, collaboration tools, and IT platforms — may store or process personal data in jurisdictions outside the UK or EEA, including the United States. Where Greengage has a direct contractual relationship with the provider (for example, Amazon Web Services (AWS), Google (including Google Meet), Microsoft (including Microsoft Teams), or Slack Technologies Inc.), we ensure appropriate safeguards are in place. These may include Standard Contractual Clauses (SCCs), UK International Data Transfer Agreements (IDTAs), or UK adequacy decisions, as applicable. These providers are selected following due diligence and are subject to contractual and technical safeguards designed to ensure the protection and confidentiality of your personal data.

In limited cases, Greengage or its staff may use publicly available communication platforms such as WhatsApp and Telegram, which operate under non-negotiable standard terms of service and are not subject to Greengage’s direct contractual control. These platforms may be used to facilitate communication with clients or other parties. While we do not prohibit such use, we do not recommend using these channels for the exchange of personal, financial, or confidential information, and we strongly encourage clients to use secure alternatives where available. Greengage does not accept liability for the use or processing of data once it leaves our systems and enters third-party messaging tools, except where explicitly agreed or where required by applicable law.

As a condition of employment, Greengage employees are required to comply with all applicable laws, internal data protection policies, and information security standards. Unauthorised use or disclosure of confidential personal data is strictly prohibited and may result in disciplinary action, up to and including termination of employment.

We will notify you and any relevant supervisory authority (such as the Information Commissioner’s Office (ICO)) of a data breach where we are legally required to do so.

11. Data retention

How long will you use my personal data for?

Greengage retains your personal data only for as long as necessary to fulfil the purposes for which it was collected — including to comply with applicable legal, regulatory, tax, accounting, and reporting obligations and to establish or defend legal rights.

Retention periods vary depending on the type of personal data, the legal basis for processing, and the operational or regulatory context. We apply retention schedules in line with statutory obligations (such as anti-money laundering and financial conduct requirements) and we regularly review the data we hold to ensure that it remains necessary and proportionate.

Examples of our retention periods include:

  1. Client due diligence and identity verification records: typically retained for seven (7) years after the end of the client relationship, in accordance with anti-money laundering (AML) and Know Your Customer (KYC) requirements under UK and EU financial regulations. In some cases, such records may be retained for up to ten (10) years, where required by law (e.g. FCA rules, HMRC audit requirements) or in accordance with internal risk or audit policies.
  2. Website usage and cookie data: retained for a duration specified in our Cookie Policy, typically up to 3 years, depending on the category and purpose of the cookie. Analytics and behavioural data may be retained longer in anonymised form for product development, performance analysis, and fraud prevention purposes.

Some personal data — particularly technical logs or metadata — may be processed or stored by third-party providers located outside the UK or EEA, including in the United States, where Greengage does not have direct contractual control (e.g. publicly available communications platforms or third-party web analytics tools). In such cases, we take appropriate steps to minimise retention, restrict usage and apply data minimisation practices to reduce risk.

At the end of the applicable retention period, we will either securely delete your personal data, anonymise it so it can no longer be linked to you, or archive it with restricted access where further retention is required for legal reasons (e.g. for litigation or regulatory investigations).

12. Your legal rights

In all the above cases in which we collect, use or store your personal data, you may have the following rights and, in most cases, you can exercise them free of charge. You have the right, among other things, to:

  1. Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  2. Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected. We may need to verify the accuracy of the new data you provide to us.
  3. Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Please note that there may be circumstances where you ask us to erase your information but we are legally entitled to retain it;
  4. Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
  5. Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
  6. If you want us to establish the data's accuracy.
  7. Where our use of the data is unlawful but you do not want us to erase it.
  8. Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
  9. You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  10. Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  11. Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain services or products to you. We will advise you if this is the case at the time you withdraw your consent.
  12. If you wish to exercise any of the rights set out above, please contact the DPG as detailed above.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time in response to changing legal, regulatory, operational or technological developments, or to reflect changes in our services and processing activities.

When we make updates, we will revise the “last updated” date at the top of this notice and, where appropriate, notify you through our usual communication channels.

The latest version of this Privacy Policy will always be available at: www.greengage.co/privacy-policy

We encourage you to review this page periodically to stay informed about how we protect your personal data.

Fees

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). Greengage reserves the right to charge a reasonable fee if your request is manifestly unfounded or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

Our requirements from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Response times

We endeavour to respond to all legitimate requests within one month. That period runs from the later of our receipt of your request, our receipt of any information we reasonably request to confirm your identity, and payment of any fee we are entitled to charge; if we ask you for information to clarify the scope of your request, the period is paused until you provide it. Occasionally it may take us longer than one month if your request is particularly complex or you have made a number of requests, in which case we may extend the period by up to a further two months. We will notify you within one month and keep you updated of our progress and expected response timeframes.