Group Privacy Notice
Definitions used in this privacy policy are as follows
“Client” means an investor in our products or a recipient of our services, who may be an individual investor, or an employee, director, officer, trustee, beneficiary, or representative of an institutional or intermediary client of Benchmark.
"Data Protection Laws” means the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy Electronic Communications (EC Directive) Regulations 2003 (“PECR”), the Data (Use and Access) Act 2025, the EU General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) where applicable, and any other applicable laws, regulations, regulatory requirements, guidance or codes of practice relating to privacy, confidentiality or the processing of personal data, in each case as amended, updated, extended or replaced from time to time.
“Benchmark”, “we” or “us” means Benchmark Capital Limited with its registered office at Broadlands Business Campus, Langhurst Wood Road, Horsham, West Sussex, RH12 4QP or any of its subsidiaries or affiliates, details of which can be found on the Benchmark Website. Together these are also referred to as the Benchmark Group.
“Benchmark Website(s)” means the website(s) operated by Benchmark Capital.
“Benchmark Products and Services” means the products and services that we offer to our clients, including through our related support, mobile or cloud-based services.
“Personal Data” means any information relating to an identified or identifiable living individual. An individual may be identified directly or indirectly, for example by reference to a name, identification number, location data, online identifier, or one or more factors specific to that individual. Personal Data includes factual information about an individual, as well as expressions of opinion and indications of intention relating to that individual.
“You” means everyone to whom this notice is addressed, who may be:
(a) a Client or prospective Client of ours;
(b) a visitor to the Benchmark Website; or
(c) an employee, director, officer or representative of another organisation with which we have a business relationship.
1. Background information
1.1 Benchmark collects and uses certain Personal Data. The relevant entity within the Benchmark Group with which you have, or are considering entering into, a relationship (for example as a client, prospective client, adviser, introducer, supplier, visitor to our website or premises, or other business contact) acts as the controller of your Personal Data and is responsible for ensuring that it is processed in accordance with Data Protection Laws.
1.2 This Privacy Policy is directed to individuals whose Personal Data we handle while carrying on our commercial activities. Those individuals could be clients or prospective clients or their representatives, agents or appointees, or an employee, director, officer or representative of another organisation with which we have a business relationship. This Privacy Policy is also directed to visitors to Benchmark Websites.
1.3 We may share Personal Data with fraud prevention agencies, credit reference agencies and other organisations involved in the prevention and detection of fraud, financial crime and money laundering, and to verify your identity where necessary. If fraud or financial crime is detected, certain services, facilities, employment opportunities or other relationships may be refused. Further information about how Personal Data is used by these organisations, and your data protection rights, can be found at the following link Fair Processing Notices for Cifas (‘National Fraud Database’).
1.4 Further additional terms, conditions and commitments may also govern how the different entities of the Benchmark Group collect and use your Personal Data. Such additional terms should be read in conjunction with this Privacy Policy. In case of inconsistencies, the provisions of this Privacy Policy (as updated from time to time) shall prevail.
2. Overview of circumstances in which we handle your personal data
2.1 Benchmark gathers information about you in the following ways:
(a) Information we receive while providing products or services to you. This information may be provided directly by you or obtained from third parties, including fraud prevention agencies, credit reference agencies, identity verification providers, anti-money laundering screening providers, and other organisations that assist us in meeting our legal, regulatory and contractual obligations.
(b) Information we receive as part of your interest in our products or services or interaction with Benchmark Websites. This is information is provided by you and may include enquiries, requests for information, attendance at events, interactions with our representatives, visits to our premises, and your use of Benchmark Websites. Details of how we handle the information we receive through Benchmark Websites are set out in paragraph 10 of this Privacy Policy.
(c) Information we receive in connection with services that you provide to us, our clients or other companies within the Benchmark Group. This information may include contact information or other details relating to the relevant service or relationship with you. We may combine Personal Data collected directly from you with information obtained from other sources, including Benchmark Websites and third parties, where permitted by law.
3. The type of personal data we collect
3.1 The nature of our relationship with you will determine the kind of Personal Data we may process. These types of Personal Data we process may include:
- Identification data: first name; surname; date of birth; age; sex and/ or gender; nationality; citizenship; place of birth; National Insurance number; passport or other identification number; occupation; job title; marital or civil status; identification documents (including photographs); signature; and CCTV images.
- Contact data: postal address; email address; telephone number; mobile telephone number; and other contact details you provide us.
- Technical data: information relating to your use of our websites, portals, applications and online services, including IP address, browser type, device information, login details, cookie identifiers, online activity information and website usage data (see further section 10 below).
- Financial data: bank account details; payment information; client reference numbers; financial circumstances; income and expenditure information; assets and liabilities; tax identification numbers; tax residency information; invoices; fees and charges information; and transaction-related information.
- Contractual data: Records relating to our relationship with you, including client records, suitability assessments, communications, instructions, meeting notes, advice provided, service history, products and services received, complaints, contractual arrangements and information relating to the performance of our contractual and pre-contractual obligations (including any information regarding the dealing in shares (subscription, conversion, redemption and transfer as well as balance or value at year-end and total gross amount paid or credited in relation to the shares, including redemption proceeds)s.
- AML/KYC data: source of wealth and source of funds information, sanctions screening results, politically exposed person (PEP) information, identify verification information, power of attorney, fraud prevention information and information relating to connected persons.
- Special Category Personal Data: Personal Data revealing an individual’s racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data; biometric data processed for the purpose of uniquely identifying an individual; data concerning an individual’s health; data concerning an individual’s sex life or sexual orientation; and, where permitted by law, information relating to criminal convictions and offences.
- Communication data: records of communications with us, including telephone calls, emails, letters, messages, meeting notes and other interactions, which may be monitored or recorded for quality assurance, training, complaint handling, fraud prevention, legal and regulatory purposes.
You are not obliged to provide Personal Data to us. However, where Personal Data is necessary for us to comply with legal or regulatory obligations, enter into a contract with you, or provide products and services to you, we may be unable to establish or continue a relationship with you if the required information is not provided.
3.2 The Personal Data listed above is collected from the following sources:
Information provided directly by you
This includes information that you provide to us when you enquire about, apply for, purchase or use our products or services, communicate with us, attend events, visit our premises, complete forms, participate in surveys, or otherwise interact with us. Depending on the nature of our relationship with you, this may include identification data, contact data, financial data, contractual data, special category personal data and criminal offence data.
Information provided by third parties acting on your behalf
This includes information supplied by financial advisers, attorneys, trustees, beneficiaries, authorised representatives, intermediaries, employers, family members or other individuals acting on your behalf in connection with our products and services.
Information collected or generated by us
This includes information created during the course of our relationship with you, such as records of communications, suitability assessments, meeting notes, service records, account information, transaction information, complaints, and information relating to the provision and administration of our products and services.
Information obtained from third parties and public sources
We may receive information about you from third parties were permitted by law, including fraud prevention agencies, anti-money laundering and sanctions screening providers, identity verification providers, credit reference agencies, professional advisers, introducers, marketing and business intelligence providers, publicly available sources, regulatory bodies, government agencies, Companies House, the FCA Register and other public registers and databases.
Information obtained through our websites and online services
When you use our websites, portals or online services, we may collect technical information about your device and usage of those services, including through cookies and similar technologies. Further information is set out in section 10 of this Privacy Policy.
Personal Data relating to other individuals
Where you provide us with Personal Data relating to another individual (for example a beneficiary, dependant, attorney, trustee or authorised representative), you should ensure that the individual is aware of the information contained in this Privacy Policy and, where required, has authorised you to provide their Personal Data to us.
4. How we use your information
4.1 We will only process your Personal Data where we have a lawful basis to do so. Depending on the circumstances, we may process your Personal Data:
- to enter into or perform a contract with you;
- to comply with our legal and regulatory obligations;
- to establish, exercise or defend legal claims;
- where you have provided your consent;
- for our legitimate business interests, provided that those interests are not overridden by your rights and interests; or
- where otherwise permitted or required by applicable law.
Where we intended to use your Personal Data for a purpose that is materially different from the purpose for which it was originally collected, we will provide you with further information as required by applicable Data Protection Laws.
4.2 Your Personal Data may be collected, stored and processed by us for the following purposes. Depending on the circumstances, we may rely on one or more lawful bases for processing, including the performance of a contract, compliance with legal obligations, our legitimate interests, your consent, or another lawful basis permitted under applicable Data Protection Laws.
To provide products and services and manage our relationship with you
Categories of Personal Data | Purposes |
|
|
To comply with legal and regulatory requirements
Categories of Personal Data | Purposes |
|
|
To pursue our legitimate business interests
Categories of Personal Data | Purposes |
|
|
To manage communications and marketing activities
Categories of Personal Data | Purposes |
|
|
4.3 Within the Benchmark Group, your Personal Data is accessed only by personnel, contractors and authorised representatives who have a need to access it for the purposes described in this Privacy Policy.
4.4 Benchmark may use Artificial Intelligence (AI) tools and technologies in connection with its business activities. Where Personal Data is processed using AI tools or technologies, such processing will be subject to appropriate oversight, governance, security controls and safeguards in accordance with applicable Data Protection Laws.
5. Disclosure of your information to third parties
5.1 We may share your Personal Data within the Benchmark Group for the purposes described above.
5.2 We may also share your Personal Data outside of the Benchmark Group as further described below:
- with business partners of ours and with representatives, agents, custodians, intermediaries and/or other third-party product providers appointed by a Client or prospective Client (such as accountants, professional advisors, custody service providers and product providers);
- with third party agents and contractors for the purposes of them providing services both to us (for example, Benchmark’s accountants, professional advisors, IT and communications providers, background screening providers, credit reference agencies and debt collectors) and to Clients or prospective Clients.;
- with any depository, stock exchange, clearing or settlement system, counterparties, dealers and others where disclosure of your Personal Data is reasonably intended for the purpose of effecting, managing or reporting transactions or establishing a relationship with a view to such transactions;
- where you are a joint account or portfolio holder (or otherwise one of multiple persons holding an account or portfolio), we may disclose your Personal Data to the other joint account or portfolio holder;
- to the extent required by law or regulation, for example if we are under a duty to disclose your Personal Data in order to comply with any legal obligation (including, without limitation, in order to comply with tax reporting requirements and disclosures to regulators, auditors or public authorities), or to establish, exercise or defend its legal rights; and
- if we sell any part of our business or our assets or reorganise our business, in which case we may need to disclose your Personal Data to a prospective buyer or other third party for purposes related to such sale or reorganisation.
The above recipients of Personal Data (“Recipients”) may disclose the Personal Data to their agents and/or delegates (the “Sub-Recipients”), which shall process the Personal Data for the purposes of assisting the Recipients in providing their services to the Benchmark entity acting as controller and/or assisting the Recipients in fulfilling their own legal obligations.
The Recipients and Sub-Recipients may process the Personal Data as processors (when processing the Personal Data upon instructions of the controller and/or the Recipients), or as distinct controllers (when processing the Personal Data for their own purposes, namely fulfilling their own legal obligations).
6. International transfers of personal data
6.1 In connection with the provision of our products and services and the operation of our business, we may transfer Personal Data to organisations located outside the United Kingdom and, where applicable, outside the European Economic Area (“EEA”).
6.2 Where we transfer Personal Data internationally, we will ensure that appropriate safeguards are in place to protect it and that the transfer is carried out in accordance with applicable Data Protection Laws. Depending on the circumstances, this may include:
- transferring Personal Data to countries recognised as providing an adequate level of protection for Personal Data under applicable Data Protection Laws;
- using appropriate contractual safeguards, including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the European Commission’s Standard Contractual Clauses, or other approved transfer mechanisms recognised under applicable Data Protection Laws;
- transferring Personal Data to organisations participating in recognised international transfer frameworks, including the UK Extension to the EU-US Data Privacy Framework, where applicable; or
- in limited circumstances, relying on an exception permitted by applicable Data Protection Laws, including where you have provided your explicit consent.
6.3 You may request further information regarding international transfers of Personal Data and the safeguards applied to such transfer by contacting us using the details set out in section 12.
7. How we safeguard your personal data
7.1 We maintain appropriate technical, organisational, physical and administrative security measures designed to protect Personal Data against unauthorised or unlawful processing, accidental loss, destruction or damage, and unauthorised access, alteration or disclosure. Access to Personal Data is restricted to individuals who have a legitimate business need to access it and who are subject to appropriate confidentiality obligations.
7.2 We regularly review and test our security measures and maintain controls designed to identify, prevent, detect, respond to and recover from security incidents, cyber threats and other events that may affect the confidentiality, integrity, or availability of Personal Data and our systems.
8. How long we keep your personal data
8.1 The period for which we retain Personal Data depends on a number of factors, including:
- the purposes for which it was collected and is used;
- our legal, regulatory, tax, accounting and record-keeping obligations; and
- the needs to establish, exercise or defend legal claims, or otherwise protect our legal rights and interests.
We will retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by law. Retention periods may vary depending on the nature of the information and the purpose for which it is processed.
8.2 You may request further information about our retention practices and the periods for which we retain specific categories of Personal Data by contacting us using the details set out in section 12.
8.3 Once Personal Data is no longer required for the purposes for which it was collected, and retained, we will securely delete, destroy or anonymise it in accordance with applicable laws, regulations and our record retention procedures.
8.4 Where Personal Data has been irreversibly anonymised so that individuals can no longer be identified, directly or indirectly, the information will no longer constitute Personal Data. We may retain and use such anonymised information indefinitely for statistical, analytical, research, service improvement and other legitimate business purposes.
9. Your rights
9.1 Depending on the circumstances and the lawful basis relied upon for processing, you may have the following rights in relation to your Personal Data.
Right to be Informed
You have the right to be informed about how we use your Personal Data. This means that we should provide you with clear information about how we collect, use, share and protect your Personal Data, the reasons why we use it, and the rights available to you. This Privacy Policy is designed to help you understand this information.
Right of Access
You have the right to request information about how we process your Personal Data and to obtain a copy of the Personal Data we hold about you, referred to as a Subject Access Request (SAR).
Right to Rectification
You have the right to request that we correct or update your Personal Data that is inaccurate or incomplete.
Right to Erasure
You have the right to request the deletion of your Personal Data in certain circumstances. This right is not absolute and may not apply where we are required or permitted by law to retain the information.
Right to Restrict Processing
You have the right to request that we restrict our use of Personal Data in certain circumstances. This means that you can ask us to limit how we use your Personal Data for a period of time. For example, you may ask us to restrict processing if you believe that the Personal Data, we hold about you is inaccurate, has been processed unlawfully, is no longer needed for the purposes for which it was collected, or if you have objected to our processing and we are considering your request.
Where processing is restricted, we will continue to store your Personal Data but will only otherwise process it were permitted by applicable Data Protection Laws. Restricting our use of your Personal Data may affect our ability to provide certain products or services to you while the restriction remains in place.
Right to Object
You have the right to object to our processing of your Personal Data in certain circumstances. You also have the right to object at any time to the processing of your Personal Data for direct marketing purposes.
Right to Data Portability
In certain circumstances, you have the right to receive Personal Data that you have provided to us in a structured, commonly used and machine-readable format, or to request that we transfer that Personal Data to another organisation where technically feasible.
Rights Relating to Automated Decision Making and Profiling
You have rights in relation to automated decision-making and profiling.
Automated decision-making means a decision made solely by automated means, without human involvement. Profiling means the automated processing of Personal Data to evaluate certain personal aspects relating to an individual, such as preferences, interests, behaviour or circumstances.
Where applicable, you have the right to obtain information about these types of processing, to express your point of view, to request human intervention, and to challenge a decision made solely by automated means where that decision produces legal effects or similarly significant effects on you.
Further information about any automated decision-making or profiling carried out by Benchmark, including how it may affect you and the safeguards that apply, will be provided where required by applicable Data Protection Laws.
Right to Withdraw Consent
Where we rely on your consent to process Personal Data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out before consent was withdrawn.
9.2 To exercise any of your rights, please contact us using the details set out in section 12.
Please note that these rights are not absolute and may be subject to limitations, exemptions or conditions under applicable Data Protection Laws.
10. Benchmark websites and other websites
10.1 When you use a Benchmark Website, we may collect information through cookies and similar technologies, including analytics and tracking technologies, as described in our Cookie Notice. Through our cookie preference centre, you can manage your preferences and choose which categories of cookies you wish to accept, subject to those that are strictly necessary for the operation of the website.
Where you consent to the use of analytics or tracking technologies, we may collect information about how you interact with our websites and online services. In certain circumstances, where you have chosen to identify yourself to us, we may be able to associate this information with other information we hold about you in order to improve our websites, products, services and user experience.
We may use information collected through cookies and similar technologies to:
- provide and maintain website functionality;
- understand how our websites, content, products and services are used;
- improve the performance, security and user experience of our websites;
- analyse trends and usage patterns; and
- provide content, products and services that may be relevant to you, where permitted by law.
We may also collect aggregated, statistical or de-identified information about the use of our websites and online services for analytical, reporting and service improvement purposes.
10.2 If you follow a link from a Benchmark Website to another website or online service, that website or service may have its own privacy notice and terms. We are not responsible for the privacy practices of third-party websites and recommend that you review their privacy information before providing any Personal Data.
11. Changes to this privacy policy
11.1 We may update this Privacy Policy from time to time. The latest version will always be available on our website and will indicate the date on which it was last updated. Where changes materially affect how we collect, use or otherwise process your Personal Data, we will take reasonable steps to notify you.
12. Questions and concerns
12.1 If you have any questions about this Privacy Policy, our use of Personal Data, or if you wish to exercise any of your data protection rights, please contact us using the details below:
Benchmark Capital Limited
Broadlands Business Campus
Langhurst Wood Road
Horsham
West Sussex
RH12 4QP
United Kingdom
Email: dataprotection@benchmarkcapital.co.uk
You may withdraw your consent to receive marketing communications at any time by using the unsubscribe link included in our communications or by contacting us using the details above.
We are usually able to resolve privacy questions and concerns promptly and effectively.
If you are not satisfied with how we have handled your concern, you have the right to lodge a complaint with the Information Commissioner's Office ("ICO"): https://ico.org.uk/make-a-complaint/
If you raise a concern, we may:
- request additional information from you to verify your identity and understand your request;
- consult with relevant internal teams, service providers, professional advisers or other third parties where necessary to investigate and resolve your concern; and
- retain records of your request and any actions taken in response,
in each case in accordance with applicable Data Protection Laws and our legal and regulatory obligations.