1. Who We Are

Konfido Ltd is a company registered in England and Wales with company number 14478524, with its registered office at 30 Welbeck Street, London W1G 8ER. Konfido Ltd is a facilitator that introduces clients to regulated partners who provide a suite of financial products and services for individual and business clients.

A complete list of our partners regulatory licenses is available on the Konfido terms and conditions.


This Privacy Policy explains how Konfido Ltd (“Konfido”, “we”, “us” or “our”) collects, uses, shares, stores and otherwise processes personal data in connection with our website, communications, advisory activities, client and prospect interactions, and related business operations.


For the purposes of the UK GDPR, the EU General Data Protection Regulation (Regulation (EU) 2016/679), the Data Protection Act 2018 and, where applicable, the Italian data protection framework set out in Legislative Decree no. 196/2003 as amended by Legislative Decree no. 101/2018, Konfido Ltd is the data controller unless we expressly tell you otherwise in a more specific notice or contract.


This policy is intended to provide the information required by Articles 13 and 14 GDPR for individuals whose data we collect directly from them, indirectly from third parties, or automatically through the use of our website and digital channels.


This policy should be read together with our Cookies Policy, any engagement letter, onboarding documentation, service terms, or supplementary privacy notices that may apply to a specific product, jurisdiction or relationship.
Where another notice is more specific and conflicts with this policy, the more specific notice will usually prevail for that activity.

If you have questions about how we use your personal data, you can contact us at support@konfido.vip or to the Privacy Officer, Mario Gesue, email mg@konfido.vip.

2. Data We Collect

The personal data we collect depends on how you interact with us, the services you request, the channel through which the interaction takes place, and the legal or regulatory requirements that apply. We seek to collect only data that is relevant and proportionate for the purpose in question.

Contact and enquiry data.
If you contact us through a website form, by email, by telephone or in person, we may collect your name, email address, telephone number, organisation, role, country or jurisdiction, and the content of your message or enquiry.
We may also keep records of subsequent correspondence and any documents you choose to provide.

Newsletter and subscription data.
If you subscribe to news updates, insights or marketing communications, we may collect your email address, first name, preferences, subscription source, consent records, delivery status, opens, clicks and other engagement information associated with those communications.


Technical and usage data.
When you visit the website, we may collect technical information such as IP address, browser type and version, operating system, referring pages, timestamps, device identifiers, language settings, approximate location derived from IP, and website interaction data such as page views, clicks, dwell time and navigation paths.
Some of this information is collected through cookies and similar technologies, which are described in our Cookies Policy.

Marketing and audience data.
Where marketing tools are enabled, we may collect or receive identifiers, campaign parameters, cookie or pixel data, audience segment data, hashed contact data, ad interaction data and analytics about whether a marketing campaign or communication resulted in a visit, enquiry or other response.


Professional relationship and service data.
In the course of evaluating or delivering advisory services, we may collect information about you or your representatives such as name, title, employer, group structure, jurisdictional footprint, contact details, service requirements, financial or corporate information relevant to the Konfido Ltd-Privacy Policy engagement, correspondence, notes of meetings, and information needed to propose, structure or manage a service relationship.


Due diligence, compliance and verification data.
Where relevant to the services requested, we may collect identity details, proof of address, date of birth, nationality, source-of-funds or source-of-wealth information, sanctions or adverse-media screening results, tax residency details, beneficial ownership information, company registration information, and other compliance or onboarding materials that are necessary for anti-money laundering, know-your-customer, regulatory or risk-management purposes.


Data received from third parties.
We may receive personal data from referral partners, professional advisers, counterparties, publicly available registers, corporate registries, compliance screening providers, social media or professional networking platforms, your authorised representatives, and other sources that reasonably help us to respond to your request, conduct due diligence, maintain records, or provide our services.
When we receive data indirectly, we will use it in accordance with this policy and any additional notice provided where required.

Special category data and sensitive information.
We do not intentionally ask for special category personal data through general website contact forms.
However, depending on the nature of an engagement, correspondence or legal requirement, we may receive limited special category data or other sensitive information, for example where it is necessary to assess a client need, comply with applicable law, establish, exercise or defend legal claims, or protect vital interests. Please do not send unnecessary sensitive data to us through open channels.

Children’s data.
Our services and website are not directed to children, and we do not knowingly seek to collect personal data from individuals under the age of 18.
If you believe that a child has provided us with personal data inappropriately, please contact us so that we can take reasonable steps to delete it or otherwise address the issue. If you choose not to provide certain personal data, we may be unable to respond effectively to your enquiry, provide a requested service, carry out due diligence, or comply with our legal obligations.

3. How We Use Your Data

We use personal data for one or more of the following purposes, depending on the context in which it was collected:

  • to respond to enquiries, arrange calls or meetings, assess whether our services are relevant to you, and take steps at your request before entering into a contract;

  • to provide advisory, private client, wealth-related, corporate or partnership services, including proposal preparation, onboarding, relationship management, administration and ongoing support;

  • to conduct client due diligence, identity verification, sanctions screening, anti-money laundering checks, anti-fraud controls, conflict checks, and other regulatory or risk-management processes required by law or prudent business practice;

  • to send newsletters, thought leadership, service updates, invitations and other marketing communications where permitted by law and in line with your preferences;

  • to operate, protect, troubleshoot, secure and improve our website, systems, forms, digital journeys and business processes;

  • to measure the performance of our content, campaigns and communications, including by using analytics and marketing tools where the relevant consent has been obtained;

  • to maintain internal records, evidence transactions or communications, manage complaints, monitor quality, train staff, and ensure appropriate governance and auditability;

  • to comply with laws, regulations, court orders, requests from competent authorities, tax obligations, accounting duties, regulatory record-keeping requirements and professional conduct obligations;

  • to establish, exercise or defend legal rights and claims, including in relation to disputes, complaints, debt recovery, fraud prevention, cybersecurity incidents or contractual enforcement;

  • to consider and implement corporate transactions, internal restructurings, or business continuity arrangements where personal data may be relevant to legal and operational diligence.

4. Lawful Bases

Data protection law requires us to identify a lawful basis for each processing activity. Depending on the circumstances, we may rely on one or more of the lawful bases summarised below.

Where we rely on consent, you are free to withdraw that consent at any time.
Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn. If we need to process special category personal data, we will only do so where an additional condition under Article 9 GDPR applies, such as your explicit consent, substantial public interest under applicable law, the establishment, exercise or defence of legal claims, or where the processing is otherwise necessary and lawful in the context of the service or legal obligation.

Purpose Main data Lawful basis Notes
Responding to enquiries and arranging introductory discussions Contact and enquiry data Legitimate interests and, where you ask us to take steps before a contract, pre-contractual measures To answer requests, evaluate relevance and manage correspondence
Providing advisory or related services Professional relationship and service data Performance of a contract or steps at your request prior to entering into a contract Includes service delivery, administration and relationship management
AML / KYC / sanctions / compliance checks Verification and due diligence data Legal obligation and, where relevant, substantial public interest or other lawful Article 9 condition Used to satisfy regulatory and risk-management obligations
Newsletter and promotional emails Subscription and engagement data Consent, except where a lawful soft opt-in or similar rule is available You can unsubscribe at any time
Optional analytics and marketing technologies Technical, usage and marketing data Consent where non-essential cookies or similar technologies are used See Cookies Policy for details
Business administration, complaint handling, audit and governance Correspondence, records and operational data Legitimate interests and, in some contexts, legal obligation Supports accountability, quality control and evidential record-keeping
Website security, fraud prevention and incident response Technical and usage data Legitimate interests and legal obligation where applicable Helps protect systems, users and the business
Legal claims, enforcement and dispute management Relevant data connected to the issue Legitimate interests, legal obligation, and Article 9(2)(f) where special category data is involved To establish, exercise or defend legal claims

5. Data Sharing

We may share personal data on a need-to-know basis with carefully selected recipients where this is necessary for the purposes set out in this policy.

Within Konfido and related operating arrangements.
Personal data may be accessed by authorised personnel within Konfido who need it to manage the relationship, provide services, administer systems, handle compliance matters, or perform managerial oversight.
Where relevant to a specific service, data may also be shared with affiliated or partner organisations involved in delivering that service, but only to the extent appropriate and lawful.

Service providers.
Konfido uses third parties such as Ephelia SwissTech SA to provide its regulatory services and on-boarding of clients including ID verification.
We may use third parties to host our website, store data, manage documents, provide customer relationship management tools, run analytics, send newsletters, manage marketing campaigns, enable videoconferencing, provide cybersecurity services, perform sanctions or identity screening, assist with onboarding, or otherwise support our operations. Where these parties process personal data on our behalf and under our instructions, they act as our processors under appropriate contractual controls. Certain partners, including Ephelia SwissTech SA, determine the purposes and means of processing for their own regulated activities, such as client onboarding and identity verification, and act as controllers (or joint controllers) in their own right. Konfido is not responsible for the processing those partners carry out as controllers, which is governed by their own privacy notices.

Professional advisers and counterparties.
We may share data with legal advisers, accountants, auditors, tax advisers, corporate service providers, notaries, banks, payment or e-money providers, custodians, product partners, insurers, external compliance consultants and other professional counterparties where this is necessary to assess or implement a requested structure or service.


Public authorities and regulators.
We may disclose personal data where required by law, regulation, court order, supervisory request or other binding process, or where disclosure is reasonably necessary to prevent crime, respond to fraud, protect rights or comply with a legal obligation.


Corporate transactions and restructurings.
If we consider or carry out a merger, acquisition, reorganisation, financing, sale of assets or other corporate event, personal data may be disclosed to advisers, counterparties and prospective transferees subject to appropriate confidentiality and data protection safeguards.
We do not sell personal data in the ordinary consumer-advertising sense. We also do not disclose personal data more broadly than is reasonably required for the relevant purpose.

6. International Transfers

Because Konfido operates internationally and uses service providers that may support us from multiple jurisdictions, personal data may be transferred to, stored in or accessed from countries outside the United Kingdom or the European Economic Area.

Where this occurs, we aim to ensure that one of the recognised transfer mechanisms under applicable data protection law is used. Depending on the receiving country and the parties involved, this may include reliance on a recognised adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to the SCCs, or another lawful transfer mechanism permitted under the UK GDPR or EU GDPR.

Konfido uses Ephelia SwissTech SA (registered in Switzerland) for its regulatory and on-boarding services. In Switzerland the FDPIC enforces the Swiss Federal Act on Data Protection (FADP), which governs how data can be collected, stored, and shared.

Where appropriate, we may also carry out transfer risk assessments and implement supplementary contractual, technical or organisational measures, such as data minimisation, role-based access restrictions, encryption, pseudonymisation and vendor due diligence.

If you would like more information about the safeguards used for a particular transfer, you may contact us using the details in section 12.

7. Data Retention

We keep personal data only for as long as is reasonably necessary for the purposes for which it was collected, including to satisfy legal, regulatory, tax, accounting, professional and evidential requirements. Retention periods are determined by reference to the nature of the data, the sensitivity of the information, the purpose of processing, the relevant legal obligations and the practical need to keep records in the event of complaints, disputes or investigations.

When data is no longer needed, we aim to delete it, anonymise it, aggregate it or otherwise place it beyond use in accordance with our retention and records-management practices.

Data Category & Description Legal Retention Window Legal Basis & Compliance Rationale
Client Onboarding, Advisory Files & Relationship Records
Contracts, signed mandates, written professional advice, and file notes.
UK / EU: 7 Years

Switzerland: 10 Years
UK/EU: Aligns with the standard 6-year statutory limitation window for breach of contract or negligence claims under the UK Limitation Act 1980, plus a 1-year operational buffer.

Switzerland: Art. 958f of the Swiss Code of Obligations (CO) explicitly mandates a minimum 10-year retention period for business records and corporate correspondence.
AML / KYC / Sanctions & Regulatory Records
Passport scans, corporate verification documents, source of wealth records, and screening logs.
UK / EU: 5 Years from end of relationship

Switzerland: 10 Years (Strict Min)
UK/EU: UK Money Laundering Regulations (MLRs 2017) and EU AML Directives mandate retention for exactly 5 years from relationship termination, requiring prompt deletion thereafter to satisfy GDPR Storage Minimization unless legal actions are active.

Switzerland: Swiss Anti-Money Laundering Act (AMLA) and FINMA guidelines strictly dictate a mandatory 10-year holding period.
General Contact Enquiries & Website Forms
General sales contact forms, support tickets, and email inquiries from non-clients.
All Regions: 4 Years Justified under ‘Legitimate Interest’ to protect against potential early commercial disputes, fraudulent misrepresentation, or pre-contractual liability inquiries. Natural deletion scheduled after 4 years if no customer relationship materializes.
Newsletter Subscriptions & Marketing Preferences
Subscription records, consent timestamps, opt-out preferences, and suppression lists.
All Regions: Until unsubscribe + 26 months Suppression lists are held post-unsubscribe to defend against spam allegations and provide an audit trail proving compliance with opt-out mechanisms under PECR (UK), ePrivacy (EU), and Swiss UCA.
Analytics & Cookie-Derived Data
IP traffic logs, localized user tracking, and pseudo-anonymous browsing profiles.
All Regions: 26 Months Standard industry retention period for pseudonymous user tracking data (e.g., Google Analytics baseline), validating compliance with data minimization rules under GDPR and Swiss FADP.
Complaint Files & Internal Investigation Records
Formal grievance filings, resolution agreements, and internal compliance case files.
UK / EU: 7 Years; Switzerland: 10 Years Retained to safeguard the business against subsequent civil litigation, statutory negligence claims, or regulatory audit procedures following a formal dispute. Covers the standard 6-year UK limitation window + buffer.
Corporate Prospecting & Business Development
Cold B2B leads, marketing databases, and outreach logs.
All Regions: 3 Years Maximum acceptable window to maintain cold B2B target data under Legitimate Interest. Records must be purged or re-consented if zero meaningful engagement occurs within this timeframe.

8. Your Rights

Subject to applicable law and certain exemptions, you may have the right to request access to the personal data we hold about you, request rectification of inaccurate or incomplete data, request erasure of data in appropriate circumstances, request restriction of processing, object to processing based on legitimate interests, withdraw consent where we rely on consent, and request data portability for data processed by automated means on the basis of consent or contract.

You also have the right to object to direct marketing at any time.
If you do so, we will stop using your personal data for direct marketing purposes, although we may still retain limited suppression information so that we can respect your opt-out request in future.

Konfido does not intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals in the context of the website alone, unless this is expressly described in a more specific notice and permitted by law.
If, in a particular service context, such processing is used, you will be informed of the relevant logic, significance and envisaged consequences, together with any rights available under Article 22 GDPR.

To protect your privacy and security, we may need to verify your identity before acting on a rights request.
In most cases we will respond within the statutory timeframe required by the applicable law.

9. Data Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, misuse or access. These measures may include role-based access controls, staff confidentiality obligations, secure hosting, multi-factor authentication, encryption in transit where appropriate, device and account security controls, logging, vendor due diligence, and internal procedures for incident handling and escalation.

No internet transmission or storage environment can be guaranteed to be completely secure.
For that reason, while we work to protect personal data responsibly, we cannot promise absolute security.

If we become aware of a personal data breach, we will assess it promptly and take action in accordance with applicable law.
Where required, this may include notifying the relevant supervisory authority and, if the breach is likely to result in a high risk to affected individuals, notifying those individuals as well.

10. Children

Our website, communications and services are intended for adults and professional or business users. They are not designed for children. We do not knowingly solicit or process personal data from anyone under the age of 18 in connection with our ordinary activities. If we learn that such data has been collected inadvertently, we will seek to delete it or otherwise handle it appropriately.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the law, regulatory expectations, our business model, our service providers or our processing practices. The updated version will be published on the website together with the revised effective date. Where required, or where changes are material, we may also notify you through another appropriate channel.

12. Contact & Complaints

If you have questions about this Privacy Policy, wish to exercise your rights, or would like to raise a privacy concern, please contact us first so that we have the opportunity to review and address the matter.

Contact details:
Konfido Ltd, 30 Welbeck Street, London, England, W1G 8ER; email support@konfido.vip or to the Privacy Officer, Mario Gesue, email mg@konfido.vip.
If you are in the United Kingdom and you are dissatisfied with how we have handled your personal data, you may have the right to complain to the Information Commissioner’s Office. If you are in Italy, you may also complain to the Garante per la protezione dei dati personali. Individuals in the EEA may also complain to the supervisory authority in the Member State of their habitual residence, place of work or the place of the alleged infringement. Making a complaint to a supervisory authority does not affect any other administrative or judicial remedy you may have.