Privacy Policy · GDPR

What we do with your data, and why we have to.

Our work is identity documents, source of funds and ownership records - the most sensitive material a business has. This page says exactly what we collect, what the law makes us keep, who ever sees it, and what you can demand from us.

This policy is read together with the General Terms of the service contract. The General Terms govern the engagement; this policy governs the personal data inside it.

At a glance

Eight things worth knowing before you read the rest.

A reading aid, not a substitute for the text. Where this box and a clause disagree, the clause is what binds.

The full text

Privacy Policy

1Who we are and what this covers

Top ↑
1.1

Prifinance is an international legal and corporate advisory firm. For the personal data described here we are the controller: we decide why it is processed and how. You can reach us at info.en@prifinance.com, or through any of the offices listed on our contacts page.

1.2

This policy covers three things: the personal data you give us when you engage us for Services, the personal data we collect about people connected to a client company, and the little we collect when you simply visit the website.

1.3

It is written to meet Regulation (EU) 2016/679 (the General Data Protection Regulation, or GDPR). Where an engagement also falls under the data protection law of another country, we apply that as well - but the GDPR standard is the floor everywhere, including for clients outside the European Economic Area. We do not run two different regimes.

1.4

This policy sits alongside the General Terms of the service contract. The General Terms govern the engagement; this policy governs the personal data inside it. Where the General Terms mention the data processing policy, they mean this document.

1.5

We have not appointed a Data Protection Officer: our processing does not meet the conditions in Article 37(1) GDPR that make one mandatory. Data protection questions go to the address in section 16 and are answered by a lawyer, not a mailbox.

2Definitions

Top ↑
2.1Personal data
means any information relating to an identified or identifiable living person - a name, an identity document, an IP address, a bank account, or a combination that makes someone identifiable.
2.2Processing
means anything done with personal data: collecting, storing, reading, sending, correcting, restricting or deleting it.
2.3Controller
is the party that decides why and how personal data is processed. For the data in this policy, that is us.
2.4Processor
is a party that processes personal data on our instructions and for our purposes - for example an IT provider hosting our systems.
2.5Services
means the legal, corporate, licensing, banking and immigration services we provide under the contract, as defined in the General Terms.
2.6Website
means www.prifinance.com and its language versions.
2.7AML Rules
means the laws and binding rules on the prevention of money laundering and terrorist financing, sanctions and financial crime that apply to us in each country where we operate, together with the requirements our regulators and banks impose on top of them.
2.8Entity
means the company, partnership, foundation or other legal entity we establish or service at the client's request, as defined in the General Terms. Personal data about its owners, directors and officers is covered by this policy.

3What personal data we collect

Top ↑
3.1

Identity and contact data: Name, date and place of birth, nationality, personal identification code, home address, e-mail address and telephone number.

3.2

Identification documents: Passports, national identity cards, residence permits, driving licences, birth and marriage certificates, visas, and photographs contained in them. We take copies because the AML Rules require us to verify who you are, not because we want them.

3.3

Financial data: Bank account details, payment card data, transaction records, tax residency and tax identification numbers, and the documents that evidence the source of your funds and wealth.

3.4

Business and ownership data: Certificates of incorporation, registry extracts, articles of association, shareholder and beneficial ownership records, board and officer details, group structure charts, licences and permits.

3.5

Employment and background data: Job title, employer, role description, professional qualifications and, where a regulator requires it for a fit-and-proper assessment, references and background information.

3.6

Communications: E-mails, messenger and telephone conversations, meeting notes, requests submitted through the website form, and the documents exchanged in the course of the work.

3.7

Technical data: IP address, browser and device type, operating system, language, pages visited, referring page and timestamps, recorded in our server logs and - where you have agreed to them - by the analytics tools described in section 14.

3.8

We ask for the data the Services and the AML Rules actually require, and no more. If a document you send us contains more than we need, we are entitled to redact or discard the surplus, and we do.

4Where the data comes from

Top ↑
4.1

Most of it comes from you, or from the people you authorise to act for you.

4.2

Some comes from the Entity we service for you - its registers, its accountants, its bank.

4.3

Some comes from public sources: commercial and beneficial-ownership registers, court and insolvency registers, sanctions lists, professional registers, and - where the engagement concerns digital assets - public blockchain records.

4.4

Some comes from the specialist tools we use to meet the AML Rules: identity-verification services that check a photograph of your identity document against a live image of you, and screening databases that run your name against sanctions lists, politically-exposed-person registers and adverse media. They return a confirmation or a flag - the underlying documents stay with us.

4.5

If you give us personal data about someone else - a co-shareholder, a director, a family member - you confirm that you may lawfully share it, and that you have told them their data has reached us and where to find this policy.

5Why we process it, and on what legal basis

Top ↑
5.1Performance of the contract
Article 6(1)(b) GDPR. To take the steps you ask for before the contract is signed, to provide the Services, to correspond with you, to invoice and to be paid.
5.2Compliance with a legal obligation
Article 6(1)(c) GDPR. To carry out client due diligence, verify identity and source of funds, screen against sanctions and politically-exposed-person lists, keep the records the AML Rules demand, report to the Financial Intelligence Unit where the law requires it, and meet our accounting and tax obligations. This basis is not optional for either of us.
5.3Legitimate interests
Article 6(1)(f) GDPR. To run and improve the firm, keep our systems and files secure, prevent fraud and abuse, manage our own risk before taking on an engagement, and defend or bring legal claims. We weigh these interests against your rights, and where the balance does not favour us, we do not rely on this basis.
5.4Consent
Article 6(1)(a) GDPR. Only for things you can genuinely say no to without losing the Service - marketing e-mails, newsletters, and any non-essential cookie we might set in future. You can withdraw consent at any time, and withdrawal does not affect what was lawful before it.
5.5What happens if you do not provide it
You are not obliged to give us anything. But identification and source-of-funds data is required by law, not by us: without it we may not begin or continue a business relationship, and we will have to decline or stop the engagement (Article 13(2)(e) GDPR).

6Special categories and criminal-offence data

Top ↑
6.1

Screening under the AML Rules can surface data about criminal convictions, offences, investigations or sanctions listings, and occasionally special-category data - for example political exposure implied by a public office, or health information visible in a document you send us.

6.2

We process criminal-offence data under Article 10 GDPR only where Union or national law authorises it, which the AML Rules do. Special-category data is processed under Article 9(2)(f) or 9(2)(g) GDPR - the establishment or defence of legal claims, or substantial public interest laid down in law.

6.3

This data is kept apart from ordinary file material, is visible to fewer people, and is never used for anything other than the compliance purpose that produced it.

7Who we share it with

Top ↑
7.1Inside the firm
Our own lawyers, compliance officers and accountants across our offices, on a need-to-know basis. Being in another office does not give anyone access to your file.
7.2Agents and specialists
Local counsel, notaries, auditors, translators and other specialists engaged for your matter. Each is bound by a confidentiality agreement before anything is disclosed, as the General Terms require.
7.3Financial institutions
Banks, payment institutions and electronic money institutions, where the engagement is to open or maintain an account. They apply their own due diligence and their own privacy terms.
7.4Registers and authorities
Commercial registers, licensing authorities, regulators, tax authorities and courts, to the extent the filing or the proceeding requires.
7.5Service providers
Identity-verification services, sanctions, politically-exposed-person and adverse-media screening databases, and the IT, hosting, e-mail and document-management providers that run our systems. Each acts as a processor on our written instructions, under a contract that meets Article 28 GDPR. We do not name individual vendors in this policy because they change; ask us and we will tell you who is processing your file today.
7.6Mandatory reports
Where the AML Rules require a report to the Financial Intelligence Unit, we file it. The law can forbid us from telling you that we have done so, and in that case we will not.
7.7What we never do
We do not sell personal data, we do not rent or trade it, and we never hand your client file to anyone for marketing. The advertising and analytics tags on the website are the single place where data reaches a third party for marketing purposes; they run only if you have agreed to them (section 14), and what they see is your behaviour on the website - never your file, your documents, or the fact that you are a client of ours.

8Sending data outside the EEA

Top ↑
8.1

Our offices, our clients and the authorities we file with are spread across the world, so some transfers outside the European Economic Area are unavoidable. Every one of them rests on a transfer mechanism under Chapter V GDPR.

8.2

Adequacy decisions: Where the destination has a European Commission adequacy decision, the decision is the basis and no further step is needed. As at August 2026 that covers Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, Uruguay and the European Patent Organisation.

8.3

United States: For the United States, transfers to an organisation that is certified under the EU-US Data Privacy Framework rest on Commission Implementing Decision (EU) 2023/1795. For a US recipient that is not certified, we use Standard Contractual Clauses instead.

8.4

Standard Contractual Clauses: Everywhere else we use the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, together with a transfer impact assessment and, where it is warranted, additional technical measures.

8.5

Occasional transfers: A one-off transfer that is necessary to perform your contract - filing your application with a regulator in the destination country, for instance - may instead rely on Article 49(1)(b) or (e) GDPR.

8.6

On request: Ask us and we will tell you which mechanism applies to your file and send you a copy of the safeguards.

9How long we keep it

Top ↑
9.1

Client due diligence records: At least five years after the end of the business relationship. That is the minimum the AML Rules impose in the countries we work in; a supervisory authority can require longer, and where it does, we comply.

9.2

Invoices and accounting records: For as long as the accounting and tax law applying to the invoicing entity requires - in most of the countries we work in, seven years from the end of the financial year in which the transaction was recorded.

9.3

Engagement files: Kept for at least one year after the work ends, under clause 7.1 of the General Terms, and usually longer where the matter may still need reconstruction. Any AML records inside the file follow the five-year rule above.

9.4

Correspondence and call records: Up to five years.

9.5

Marketing contact data: Until you withdraw consent or unsubscribe, whichever comes first. Withdrawal takes effect immediately and the contact data is removed from the mailing list.

9.6

Server logs: Up to twelve months, then deleted or aggregated beyond recovery.

9.7

Data needed for legal claims: Where a claim, investigation or dispute is live or foreseeable, the material relevant to it is kept until the limitation period has run out, even if a period above has expired.

9.8

When a period ends, the data is deleted or irreversibly anonymised. Anonymised data - which can no longer be linked to you - may be kept and used for statistics and service quality without limit, because it is no longer personal data.

10How we protect it

Top ↑
10.1

Access is granted on a need-to-know basis and is withdrawn when the need ends. Not everyone in the firm can open every file.

10.2

Data is encrypted in transit and at rest, systems are patched, and access to them requires individual accounts and multi-factor authentication.

10.3

Everyone who touches your data - employees, agents, specialists - is bound in writing to confidentiality, and that obligation outlives their engagement with us.

10.4

Paper documents are held in access-controlled premises and destroyed securely when their retention period ends.

10.5

If a breach occurs and it is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours under Article 33 GDPR, and if the risk to you is high, we tell you directly and without undue delay under Article 34.

10.6

No system is perfect, and we will not pretend otherwise. What we can promise is that a breach gets told, not buried.

11Automated decisions and profiling

Top ↑
11.1

We do not take decisions about you that are based solely on automated processing and that produce legal effects or similarly significantly affect you, within the meaning of Article 22 GDPR.

11.2

We do use automated screening tools against sanctions, politically-exposed-person and adverse-media sources. Those tools raise flags; they do not decide anything. A person reviews every flag, and a person makes the decision to accept, pause or decline an engagement.

11.3

If you believe an automated tool has produced a wrong result about you - a false match to a sanctions list is the common case - tell us and we will have it reviewed by a human and corrected.

12Your rights

Top ↑
12.1Access
To be told whether we process data about you and, if we do, to receive a copy of it together with the information in this policy.
12.2Rectification
To have inaccurate data corrected and incomplete data completed. If your data changes, tell us - a stale address or an expired passport creates problems for both of us.
12.3Erasure
To have data deleted where we no longer need it. This right has a real limit: where the AML Rules, the Accounting Act or a live legal claim require us to keep something, we cannot delete it, and we will tell you which obligation applies rather than give you a vague no.
12.4Restriction
To have processing restricted while a dispute about accuracy or about our legitimate interests is being resolved.
12.5Objection
To object to processing based on our legitimate interests. Against direct marketing the right is absolute - object and it stops, with no balancing exercise.
12.6Portability
To receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where that is technically feasible.
12.7Withdrawal of consent
To withdraw consent at any time, for anything we do on the basis of consent.
12.8How to use them
Write to info.en@prifinance.com. Exercising any of these rights is free. We answer within one month; if the request is complex we may extend that by up to two further months and will tell you within the first month that we are doing so (Article 12(3) GDPR). Where we have genuine doubt about who is asking, we will ask you to confirm your identity first - that protection is for you.

13Children

Top ↑
13.1

The Services are for businesses and their owners. They are not directed at children, and we do not knowingly collect personal data from a child on the website.

13.2

Article 8 GDPR sets at 16 the age from which a child can consent for themselves to the processing of their data in connection with information society services, and lets a country lower it to as low as 13. Which age applies depends on where the child is; where we are not certain, we take the stricter figure and ask the holder of parental responsibility.

13.3

Data about a minor can still reach us legitimately - a child who is a beneficiary of a trust or a shareholder by inheritance, for instance. In that case it is processed under the same rules as everyone else's, and it comes to us from the adult who is responsible.

13.4

If you believe a child has given us data without the consent that was required, write to us and we will delete it.

14The website and cookies

Top ↑
14.1Two layers, and the rule between them
The website measures its own audience, and it also uses advertising and analytics tools that belong to other companies. The first runs for everyone; the second runs only if you agree to it. Nothing that can identify you, or follow you beyond this website, is loaded before you have said yes.
14.2Audience measurement, without consent
We count visits so we know which pages are read and where people give up. This runs for everyone, and it is allowed without consent only because it is kept inside strict limits: it serves audience measurement and nothing else, it is never cross-referenced with your client file or with any other source, it works for this website alone, the last part of your IP address is discarded before the data is stored, and the identifier it uses lives no longer than 13 months. The lawful basis is our legitimate interest in knowing whether the site works. You can switch it off at any time through the same panel that controls the rest.
14.3What sits behind the banner
Everything else needs your agreement, and it is grouped so you can decide by category rather than all at once. Statistics: Google Analytics, loaded through Google Tag Manager. Behaviour: Microsoft Clarity, which records how pages are used. Marketing: Meta Pixel, LinkedIn Insight Tag and Microsoft Advertising, which measure our advertising and can build audiences on their own platforms. Call tracking: a service that shows a different telephone number to different visitors, so we can tell which campaign produced a call. These providers are outside the EEA, and those transfers rest on the mechanisms in section 8. The banner always shows the list as it stands today.
14.4Session recording, in particular
Microsoft Clarity replays how a page was used: mouse movement, clicks and scrolling. It runs only with your consent, and what you type into a field is masked in your browser before anything is sent, so form contents do not reach the recording. If you would rather not be recorded, refuse the behaviour category and everything else still works.
14.5The banner
It lets you accept or refuse by category, and refusing is exactly as easy as accepting - one click, on the first screen, no hunting through settings. It names every tool in use and says how long each cookie lasts. You can change your mind at any time through the link in the footer, and refusing costs you nothing: the site, the form and every way of reaching us work identically either way.
14.6Server logs
Whatever you decide about the above, our servers keep ordinary access logs - IP address, browser, page, timestamp - which we use to keep the site available and to investigate abuse. That rests on our legitimate interest in security rather than on your consent, it is not used to build any profile, and the logs are deleted within twelve months.
14.7Messengers
The site links to Telegram and WhatsApp so you can write to a lawyer directly. Those are third-party services with their own privacy terms: what you send through them is also processed by them, and we have no control over that part.
14.8The contact form
The form sends us only what you type into it, plus the time it was sent. It is used to answer you, and for nothing else. It is not connected to the advertising tools above.

15Changes to this policy

Top ↑
15.1

We may update this policy - the law changes, and so do the tools we use. The current version is always the one published here, with its date shown at the top of the page.

15.2

Where a change materially affects how we handle your data, we will not rely on you noticing it: we will tell you, by e-mail where we hold your address, before it takes effect.

15.3

We will not change this policy in a way that retroactively weakens the protection of data we already hold.

16Contact and complaints

Top ↑
16.1Talk to us first
Write to info.en@prifinance.com, or to any of the offices listed on our contacts page. Say what you want and we will route it to a lawyer, not to a ticket queue.
16.2The supervisory authority
If you are not satisfied, you can lodge a complaint with a data protection supervisory authority - normally the one in the EU or EEA country where you live, where you work, or where you believe the problem occurred. The current list of authorities and their contact details is published by the European Data Protection Board at edpb.europa.eu.
16.3Outside the EEA
If you live outside the European Economic Area, you can raise the matter with the data protection authority of your own country where one exists - and with us in any event. We apply the same standard to your data as to everyone else's.
16.4The courts
Nothing here limits your right to go to court - in your own country, or wherever the law otherwise lets you bring the claim.
Your data

Want to know what we hold on you?

Ask, and you get a copy plus an explanation of where each piece came from and why we still have it. Free of charge, answered within a month, by a lawyer rather than a form.

You get an answer from a named lawyer, not a shared inbox.
We're online - a lawyer replies within 2 minutes➤ Telegram