Skip to main content

Third-Party Privacy Notice

  1. INTRODUCTION

Peleh Advisors Ltd (“Peleh”, “the Company”, “we”, “us”) is committed to protecting the rights and privacy of individuals whose personal data it processes in connection with visits to our website and in the course of providing our business services. This privacy notice (“Notice”) explains how we collect, use, store, and share your personal data, and how we safeguard your privacy, in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

This Notice applies to individuals connected with our service providers, investors (including individuals investing directly or through an investment vehicle, and their representatives), and our clients (including individuals who are clients, or who act as representatives, contacts, or beneficial owners in connection with a client relationship).

This Notice does not form part of any contract for services, subscription agreement, or other contractual arrangement between you, any entity you represent, and the Company.

Where we collect your data for a specific purpose, we may give you a further, more specific notice at that time; please read this Notice together with any such further notice. We may update this Notice from time to time and will notify you when any changes are made.

  1. WHO IS THE COMPANY?

Peleh is the “controller” (as defined in UK GDPR) of the personal data we hold about you so is responsible for deciding how and why we process your personal data. In addition, where the processing of personal data is undertaken by associated companies of Peleh for their own independent purposes, these associated companies may also be “controllers” of your personal data.

  1. CATEGORIES OF PERSONAL DATA COLLECTED

“Personal data” refers to information from which a natural person can be identified, directly or indirectly, or is identifiable, including by one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.

Depending on the nature of our relationship with you or the entity you represent, we may collect and process the following types of personal data:

  • Identification data – e.g., full name, date of birth, nationality, copies of identification documents (such as passport or driving licence), and signature.
  • Contact details – e.g., business and/or home address, phone number, and email address.
  • Professional and business information – e.g., job title, employer or business name, role, and details of the entity you represent or are otherwise connected with.
  • Financial and payment information – e.g., bank account details, payment records, billing information, and tax identification numbers in connection with a transaction or fee arrangement
  • Opportunity and transaction information – e.g., details you provide about a secondary or other opportunity, including where you are named in connection with it.
  • Due diligence and verification information – e.g., identity documents, information about ownership and control, and the results of sanctions, politically exposed person (PEP) and adverse-media screening.
  • Client account and service data – e.g., account details, investment objectives and risk profile, transaction and instruction history, and portfolio holdings, to verify your investor/client status for regulatory purposes.
  • Contractual and commercial data – e.g., details of contracts, agreements, orders, invoices, and the goods or services provided to or by you or your organisation.
  • Communications data – e.g., correspondence, meeting notes, call recordings, and records of enquiries, feedback, or complaints.
  • IT and security data – e.g., records of access to our premises, systems, or platforms, IP addresses, and data captured automatically when you used our website.
  1. SPECIAL CATEGORIES OF PERSONAL DATA

To the extent permitted by applicable law, we may also collect limited amounts of “sensitive personal data” (such as health, racial or ethnic origin). The processing of special category data is carried out under one or more of the conditions set out in Article 9(2) of the UK GDPR, including processing necessary for compliance with a legal obligation, for the establishment, exercise or defence of legal claims, or where we have obtained your explicit consent.

 Criminal convictions and offences data: As part of our ongoing regulatory requirements and due diligence processes, we may be required to process information regarding criminal convictions and offences, for example as part of AML, KYC, or sanctions screening.

  1. SOURCES OF PERSONAL DATA

We collect personal data directly from you (through forms, correspondence, meetings), from your organisation or colleagues, and from third parties and public sources, including company registers such as Companies House, sanctions and screening providers, professional advisers, and other parties to a transaction. We also collect some data automatically when you use our website.

Where we are required by law or regulation to collect personal data, or where it is necessary for us to enter or perform a contract, you must provide the requested information. If you do not do so, we may be unable to establish or continue a business relationship, provide services, make investments, complete a transaction or comply with our legal and regulatory obligations.

  1. PURPOSE AND LEGAL BASIS FOR PROCESSING

We use personal data only where the law permits us to do so. We process your Personal Data for the following purposes:

Purpose Data used Lawful basis
Assessing and providing our services to you Identity, contact, professional and opportunity information Performance of a contract, or steps to enter one; our legitimate interests
Counterparty due diligence, verification and sanctions / PEP / adverse-media screening Identity, ownership and control, screening results Legal obligation (where applicable); our legitimate interests in preventing financial crime
Managing our relationship and correspondence, including internal and external reporting Contact and correspondence information Our legitimate interests; performance of a contract
Administering payments Financial data Our legitimate interests; performance of a contract
Compliance, record-keeping, and responding to regulators, authorities or legal claims Any relevant data Legal obligation; our legitimate interests
Marketing our services, research and events Identity, contact and preference information Our legitimate interests; consent where required
Ensuring the security of our premises Identity and access data Legal obligation; our legitimate interests
Operating, securing and improving our website Technical and usage information Our legitimate interests; consent for non-essential cookies

 

We rely primarily on contractual necessity, our legal obligation, and our legitimate interests as the legal bases for processing your personal data. Where consent is required, including for the processing of certain sensitive personal data, we will seek your explicit consent.

Where we rely on legitimate interests, those interests are operating and developing our business, providing and improving our services, managing our client and counterparty relationships, preventing financial crime and protecting our business, and keeping proper records. We only rely on legitimate interests where we have considered your interests, rights and expectations and are satisfied they do not override ours. You can ask us for more information about this balancing, and you can object (see section 11).

  1. DATA SHARING

We may share your Personal Data with:

  • Group companies and associates for internal administrative purposes and to provide our services.
  • Third-party service providers under appropriate contracts, including IT support, screening providers, and payment processors.
  • Regulatory authorities, law enforcement, and other authorities where required or permitted to do so by law.
  • External advisors, parties to a potential transaction, or interested third parties where relevant to progressing an opportunity for you and where we have an appropriate lawful basis.
  • Our professional advisers, such as lawyers, auditors, and accountants.
  • A buyer or successor, if we sell, transfer or reorganise our business.

We require all third parties to respect the security of your personal data and to process it in accordance with applicable laws, and we will only disclose your personal data to these parties to the extent necessary for them to provide the required services or for the relevant purpose. We do not sell your personal data.

  1. INTERNATIONAL DATA TRANSFERS

The Company is based in the UK, and we generally process your personal data here. However, if we transfer your personal date outside of the UK or the European Economic Area (EEA), we will ensure that appropriate safeguards are in place, such as UK “adequacy” regulations covering the destination country, or the ICO’s International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses). You can contact us for details of the safeguards we use.

  1. MARKETING COMMUNICATIONS

We may send you information about our services, research, and events where we are permitted to do so. You can opt out at any time by using an unsubscribe link (if applicable) or by contacting us. Where the law requires it, we will only send you electronic marketing with your consent.

  1. DATA RETENTION AND SECURITY

We retain personal data only for as long as necessary to fulfil the purposes outlined in this Notice, including to meet legal, tax, regulatory, and record-keeping requirements. Retention periods vary depending on the category of data and legal requirements but, as a minimum, we will retain your personal data for the duration of our relationship with you or your organisation, and for an appropriate period thereafter to meet our regulatory and legal obligations. After the retention period expires, we securely delete or anonymise your data.

We use appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, alteration or disclosure. These include access controls, secure storage, and confidentiality obligations on our staff and providers. We will notify you and any applicable regulator of a suspected data breach where we are legally required to do so.

  1. YOUR RIGHTS

Under data protection law you have the following rights, in certain circumstances:

  • Right to access: to be told whether we hold your personal data and to request access to it.
  • Right to rectification: to ask us to correct/complete inaccurate and incomplete data.
  • Right to erasure: to request deletion of your data under certain circumstances (i.e., where we have no legitimate reasons to keep it).
  • Right to restrict processing: to ask us to limit how we use and process your data.
  • Right to data portability: to receive certain data in a portable format, or to request that your personal data is to another controller.
  • Right to object: to object to certain types of data processing based on legitimate interests, and to direct marketing at any time.
  • Right to withdraw consent: where we rely on consent, you can withdraw it at any time.
  • Automated decisions: not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect. We do not currently make such decisions.

If you would like any further information about your rights or how to exercise them, please contact us at compliance@pelehadvisors.com.  We may need to verify your identity before we can proceed and will respond within the time limits set by law (usually within one month). Exercising these rights is normally free of charge.

  1. COOKIES

Our website uses cookies and similar technologies. Essential cookies are necessary for the website to function. Non-essential cookies, such as analytics cookies, are used only with your consent, which you can give or manage through our cookie settings. A copy of our Cookie Policy can be found on our website.

  1. CHANGES TO THIS NOTICE

We may update this Notice from time to time, and you can find the current version on our website. Where changes are material, we will bring them to your attention where appropriate. We may also notify you in other ways from time to time about the processing of your personal data.

  1. CONTACT US AND COMPLIANTS

If you have any questions, requests or complaints about how we handle your personal data, please contact us at compliance@pelehadvisors.com. You also have the right to complain to the Information Commissioner’s Office (ICO) at www.ico.org.uk. We would welcome the chance to resolve any concern before you approach the regulator.