Privacy Policy
- Document reference
- FGL-LEG-04
- Version date
- 1 July 2026
- Applies to
- Fratres Limited
1.Interpretation and definitions
- Company
- Fratres Limited, a company registered in England and Wales, being the controller of the Personal Data described in this Policy.
- Policy
- this Privacy Policy, as amended and republished on the Website from time to time.
- UK GDPR
- the retained EU law version of Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland, read together with the DPA 2018.
- DPA 2018
- the Data Protection Act 2018.
- Personal Data
- has the meaning given in Article 4(1) UK GDPR: any information relating to an identified or identifiable natural person.
- Processing
- has the meaning given in Article 4(2) UK GDPR, and “process”, “processed” and “processes” are construed accordingly.
- Data Subject
- the identified or identifiable natural person to whom Personal Data relates.
- Special Category Data
- the categories of Personal Data listed in Article 9(1) UK GDPR, being data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data processed for the purpose of unique identification, data concerning health, and data concerning a person’s sex life or sexual orientation.
- Criminal Offence Data
- Personal Data relating to criminal convictions and offences or related security measures within Article 10 UK GDPR, including data relating to alleged offences, proceedings and their disposal.
- Due Diligence Information
- Personal Data obtained or generated in the course of client due diligence, beneficial ownership verification, sanctions and politically exposed person screening, adverse media review, and integrity assessment of counterparties.
- Processor
- a natural or legal person that processes Personal Data on behalf of the Company, as defined in Article 4(8) UK GDPR.
- Website
- the website published by the Company at fratresgroup.com, including all pages and functionality forming part of it.
- Enquiry Form
- the enquiry form published at fratresgroup.com/contact, which is the sole channel by which the Company accepts unsolicited approaches and requests under this Policy.
- Commissioner
- the Information Commissioner, being the supervisory authority for the United Kingdom for the purposes of Article 51 UK GDPR.
- Business Day
- a day other than a Saturday, Sunday or public holiday in England and Wales on which clearing banks are open for general business in London.
2.Controller, scope and contact
- (a)visitors to and users of the Website;
- (b)persons who submit an enquiry through the Enquiry Form, and persons named or described in such an enquiry;
- (c)clients and prospective clients, and the directors, officers, employees, advisers and beneficial owners of client and prospective client organisations;
- (d)counterparties, project sponsors, joint venture partners, introducers and their personnel;
- (e)suppliers, subcontractors, professional advisers and their personnel; and
- (f)applicants for engagement or employment with the Company.
Every right described in clause 13 is exercised through the same route: the Enquiry Form at fratresgroup.com/contact. A request does not need to cite this Policy, name a clause, or use any particular form of words to be valid. The Company treats any communication that in substance seeks to exercise a data protection right as a request under this Policy from the date it is received.
3.Sources of personal data
4.Categories of personal data processed
5.Purposes of processing and lawful bases
6.Special category and criminal offence data
- (a)Article 9(2)(a), explicit consent, for dietary, accessibility and comparable information volunteered in connection with a meeting, site visit or travel;
- (b)Article 9(2)(b), obligations in the field of employment law, in connection with the Company’s own personnel and the exercise of rights under the Equality Act 2010;
- (c)Article 9(2)(f), the establishment, exercise or defence of legal claims, where the Processing is necessary for that purpose; and
- (d)Article 9(2)(g), substantial public interest, in connection with due diligence, screening and financial crime prevention.
7.Legitimate interests
- —answering and properly assessing approaches made to it, so that an enquirer receives a considered response and the Company commits resource only where a mandate is capable of being delivered lawfully;
- —understanding who it is dealing with, so that it does not facilitate investment by or for a person whose funds or conduct would expose the Company, its clients or the projects concerned to legal, financial or reputational harm;
- —protecting the confidentiality of client information and identifying conflicts before they arise;
- —operating, securing and improving the Website and the Company’s systems, and preventing fraud, unauthorised access and abuse;
- —maintaining accurate business records, administering engagements and collecting fees properly due;
- —establishing, exercising and defending legal claims and responding to complaints and regulatory enquiries; and
- —communicating analysis and commentary to professionals who have indicated that they wish to receive it.
- (a)collection is limited to what is necessary for the identified purpose;
- (b)access is restricted by role and is logged where the data is sensitive;
- (c)retention is limited to the periods stated in clause 11;
- (d)Personal Data is not sold, licensed or disclosed for the marketing purposes of any third party;
- (e)the right to object under Article 21 UK GDPR is available and is drawn to the Data Subject’s attention in this Policy; and
- (f)no legitimate interests assessment is used to justify the processing of data relating to a person known to be under 18.
8.Consent and electronic communications
9.Recipients, processors and disclosure
- (a)professional advisers, including solicitors, counsel, accountants, auditors and insurers, engaged by the Company and bound by professional duties of confidentiality;
- (b)providers of information technology services, including hosting, electronic mail, document management, customer relationship management, backup and security monitoring;
- (c)providers of identity verification, sanctions and politically exposed person screening, corporate ownership data and adverse media data;
- (d)banks, payment service providers and accounting service providers, for the administration of fees and expenses;
- (e)a client, counterparty or authority to whom disclosure is necessary in order to progress an application or transaction on the instructions of the Data Subject or the organisation they represent;
- (f)law enforcement, tax and regulatory authorities, including the National Crime Agency, the Office of Financial Sanctions Implementation, HM Revenue & Customs and the Commissioner, where disclosure is required or permitted by law; and
- (g)a court, tribunal or party to legal proceedings, where disclosure is required by an order of the court or by a rule of procedure.
Naming the principal Processor specifically: this website and the enquiry form on it are hosted and operated by Netlify, Inc. When an enquiry is submitted, the information in that form is transmitted to and stored on Netlify’s infrastructure, and a notification containing it is sent to the Company. Netlify acts as a Processor on the Company’s instructions under a written data processing agreement, and processes the data in the United States and in other territories in which it operates. The safeguards applied to that transfer are described in the International Data Transfer Statement.
10.International transfers of personal data
- (a)the International Data Transfer Agreement issued by the Commissioner under section 119A of the DPA 2018 has been entered into with the recipient;
- (b)the Addendum issued by the Commissioner under that section has been entered into together with the relevant standard contractual clauses;
- (c)binding corporate rules approved under Article 47 UK GDPR apply to the recipient; or
- (d)a derogation in Article 49 UK GDPR applies, as described in clause 10.6.
11.Retention and disposal
- —enquiry and correspondence data where no engagement follows — 24 months from the date of the last substantive communication;
- —engagement records, including advice given and project documentation — six years from the end of the engagement, or twelve years where the engagement was entered into as a deed;
- —client due diligence records, including identification and verification documents and screening results — five years from the date the business relationship ends or the transaction is completed, in accordance with regulation 40 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017;
- —records relating to a suspicious activity report — five years from the date of the report, or such longer period as the National Crime Agency or a law enforcement authority requires in a given case;
- —accounting and taxation records — six years from the end of the accounting period to which they relate;
- —statutory registers and records required by the Companies Act 2006 — for the period specified by that Act;
- —unsuccessful recruitment applications — 12 months from the date the decision is communicated, unless the applicant asks to be considered for future opportunities, in which case 24 months;
- —website server and security logs — 12 months from creation; and
- —consent and suppression records — for as long as the Company processes data for the purpose to which the consent or objection relates, and for two years thereafter to evidence compliance.
12.Security and personal data breaches
13.Rights of data subjects
14.Exercising rights and permitted restrictions
A Data Subject who is dissatisfied with the Company’s handling of a request may ask for it to be reviewed by the member of senior management responsible for data protection, again through the Enquiry Form. That review does not affect, delay or replace the right to complain to the Commissioner under clause 16.2, which may be exercised at any time.