ASTUTE
Privacy Policy
How astuteapp.io collects and uses personal data (UK GDPR & DPA 2018)
v1.0
1. Who we are
This Privacy Policy explains how Jennifer Odore Ltd (trading as “Astute”; company no. TBC) (“Astute”, “we”, “us”, “our”) collects, uses and protects personal data when you use our website astuteapp.io and the Astute platform and services (the “Service”). We are the data controller for this personal data.
Registered address: Foundry Building, 6 Brindley Place, Birmingham B1 2JB. ICO registration number: application in progress — number to be added on issue. Data-protection contact: info@astuteapp.io / Legal & Compliance Officer.
2. Scope of this policy
This policy covers people who visit our website, register an account, use the platform as a start-up fund seeker, deal originator or investor, or use our credit-profile service. Where we link to third-party sites or services, their own privacy notices apply.
3. The personal data we collect
- Account & identity data: name, email, phone number, password, user type (fund seeker, deal originator, investor).
- Profile & business data: company details, pitch/listing information, documents and deal information you submit.
- Investor-status data: information you give to certify as a high-net-worth or sophisticated investor, including income and net-worth declarations.
- Verification (KYC) data: identity documents and the results of identity, sanctions and politically-exposed-person checks, collected for anti-money-laundering and fraud prevention.
- Credit-profile data: where you use the “Fix Your Credit Profile” service, information relating to your credit file, your credit-file information obtained from Creditsafe, the identity details used to retrieve it, and the reports and correspondence generated in delivering the service.
- Payment data: billing details for subscriptions and fees, processed via our payment provider Stripe; we do not store full card numbers.
- Communications data: messages, support requests and your contact preferences.
- Usage & device data: IP address, device and browser information, and pages visited (see our Cookie Notice).
- Data from other sources: for example, identity-verification and sanctions providers, credit reference agencies (Creditsafe), and publicly available sources.
4. How we use your data, and our lawful bases
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Create and manage your account and provide the Service | Performance of a contract |
| Match fund seekers, deal originators and investors | Performance of a contract; legitimate interests |
| Verify identity and carry out AML / sanctions checks | Legal obligation; legitimate interests |
| Assess and record investor eligibility / self-certification | Legal obligation; legitimate interests |
| Provide the credit-profile service | Performance of a contract; consent where required |
| Take payment of fees and subscriptions | Performance of a contract |
| Send service and security messages | Performance of a contract; legitimate interests |
| Send marketing and newsletters | Consent, or the “soft opt-in” for existing users |
| Improve, secure and analyse the platform | Legitimate interests |
| Comply with legal and regulatory obligations | Legal obligation |
Legitimate interests: where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and you can object at any time (see section 11).
5. Financial and sensitive information
Some data we handle is financial or sensitive in nature (for example, investor net-worth declarations and credit-profile data). We apply additional care to this information and only use it for the purposes set out above. Identity verification uses biometric data (facial matching and liveness) through our verification provider; this is special-category data under Art. 9. We rely on Art. 9(2)(g) (substantial public interest) with the DPA 2018 Schedule 1 conditions on preventing unlawful acts and fraud, supported by an Appropriate Policy Document.
6. Marketing and your choices
We will only send you marketing where you have consented, or under the “soft opt-in” where you are an existing user and we offer similar services, and you have not opted out. Every marketing message includes an unsubscribe link, and you can change your preferences at any time by contacting us at info@astuteapp.io or using your account settings.
7. Who we share your data with
- Service providers (processors) acting on our instructions — for example, hosting, email, analytics, identity-verification/KYC, and payment providers.
- Our authorised principal firm (once Astute operates as an Appointed Representative), and professional advisers.
- Regulators, law enforcement or other authorities where we are legally required to disclose, or to prevent fraud and financial crime.
- A buyer or successor entity in the event of a corporate transaction.
We do not sell your personal data.
8. International transfers
We aim to keep personal data in the UK or EEA. Where a provider processes data outside the UK, we use an approved safeguard — such as UK ‘adequacy’ regulations, the UK International Data Transfer Agreement (IDTA), or the IDTA addendum to the EU Standard Contractual Clauses. Providers that may process personal data outside the UK are Twilio, Cloudflare, LeadConnector/HighLevel, Stripe, Google and Meta; each transfer is covered by the IDTA or UK Addendum and, where applicable, the UK Extension to the EU-US Data Privacy Framework.
9. How long do we keep your data
We keep personal data only for as long as necessary for the purposes above and to meet legal and regulatory requirements. For example, anti-money-laundering records are generally kept for five years after the end of the business relationship. Key periods: account data — life of the account plus 12 months; KYC/AML records — 5 years after the relationship ends; investor-eligibility certifications — 5 years; payment and tax records — 6 years plus the current year; credit-service records — 6 years; marketing preferences — until you opt out. Full details are in our Retention Schedule.
10. How we protect your data
We use appropriate technical and organisational measures — including access controls, encryption in transit, multi-factor authentication, and supplier due diligence — to protect personal data, and we keep these measures under review.
11. Your rights
You have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and, where we rely on consent, to withdraw it at any time. You also have rights in relation to automated decision-making (see section 12).
To exercise any of these rights, contact us at info@astuteapp.io. We will respond within one month. You can also complain to the Information Commissioner’s Office (ico.org.uk), although we would welcome the chance to resolve any concern first.
12. Automated decisions and profiling
We use matching and ranking to suggest relevant connections between fund seekers, deal originators and investors. Screening and matching outcomes are reviewed by people: no decision producing legal or similarly significant effects is made solely by automated means, and you can always request human review.
13. Children
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18.
14. Cookies, changes and contact
Our use of cookies is described in our separate Cookie Notice & Policy. We may update this Privacy Policy from time to time and will post changes here with a revised date. For any privacy questions, contact info@astuteapp.io / Legal & Compliance Officer. Last updated: 8 July 2026.
