Aries Wealth Management Limited ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal information you provide to us, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Aries Wealth Management Limited is the data controller responsible for your personal data.
- Registered office: 3 Greengate, Cardale Park, Harrogate, North Yorkshire, HG3 1GY
- Contact / office address: Windsor House, Cornwall Road, Harrogate, North Yorkshire, HG3 1SF
- Companies House number: 10838364
- FCA Firm Reference Number: 784483
- ICO registration number: ZA811908
- Data protection contact: Oliver Foster — info@arieswealth.co.uk · 01423 209040
2. What personal information we collect
Depending on your relationship with us, we may collect the following categories of personal data:
Identity and contact information
- Full name, title, date of birth, gender
- Home address, email address, telephone numbers
- Identification documents (e.g. passport, driving licence) for anti-money-laundering (AML) checks
- National Insurance number
Financial information
- Income, expenditure, assets, and liabilities
- Existing pensions, investments, savings, and protection arrangements
- Employment status, occupation, and employer details
- Tax status and residency
- Bank account details (for facilitating fees and product applications)
Family and lifestyle information
- Marital status, dependants, and beneficiaries
- Health and medical information where relevant to protection or annuity advice
- Lifestyle and retirement objectives
Special category and criminal-conviction data
Where relevant — for example, when advising on protection products, enhanced annuities, or vulnerable clients — we may process information about your physical or mental health. We process this only where you have given explicit consent or where processing is necessary for reasons of substantial public interest under UK GDPR Article 9 / Schedule 1 of the Data Protection Act 2018.
Website usage data
- IP address (collected via analytics in anonymised form)
- Browser type, device type, operating system
- Pages visited, time spent on pages, referring URL
- Information you submit through forms or our booking application
3. Our lawful basis for processing
Under the UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following bases:
- Contract — to provide the financial advice services you have engaged us for, or to take steps before entering into such a contract.
- Legal obligation — to comply with our obligations under FCA rules, the Money Laundering Regulations 2017, HMRC requirements, the Companies Act 2006, and other applicable law.
- Legitimate interests — to operate, manage, and develop our business; to keep records of advice given; to manage client relationships; and to maintain the security of our systems. These interests are balanced against your rights and freedoms.
- Consent — for non-essential cookies, marketing communications, and processing of special category data such as health information.
Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. How we use your information
We use your personal data for the following purposes:
- Providing financial advice and ongoing service to you, including suitability assessments, recommendations, reviews, and reports
- Carrying out identity verification and anti-money-laundering checks
- Processing applications and instructions to product providers, platforms, and other third parties on your behalf
- Administering your account, fees, and ongoing relationship
- Maintaining records required by the FCA and HMRC
- Communicating with you about your plan, market events, and our services
- Improving our website, services, and client experience
- Investigating and resolving complaints
5. Who we share your information with
We will never sell your personal data. We share it only where necessary to provide our services or where we are legally obliged to do so. Recipients may include:
- Product providers and platforms — to set up and administer the products you take out (e.g. pension, investment, or protection providers)
- Research and planning tools — Defaqto Engage (whole-of-market research), Selectapension (pension comparison), and CashCalc (cashflow forecasting)
- HMRC and other regulators — including the Financial Conduct Authority and Information Commissioner's Office where required
- Identity-verification providers — to meet our anti-money-laundering obligations
- Professional advisers acting for you — such as your solicitor or accountant, with your express permission
- Our IT and back-office service providers — including secure cloud hosting (Microsoft 365), email, and document storage providers, all of whom act as data processors under written agreements
- Booking and communication tools — Microsoft (via Microsoft Graph) — to create and manage appointment bookings on our behalf
- Auditors, compliance consultants, and our professional indemnity insurer — where reasonably required
- Successor firms or buyers — in the event of a sale or transfer of our business, subject to confidentiality and continuity of these protections
- Law-enforcement agencies and courts — where compelled by law
Where personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place — for example, transfers to providers operating under UK adequacy decisions or under Standard Contractual Clauses approved by the ICO.
6. How long we keep your information
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, and to meet legal and regulatory requirements. In practice this means:
- Client files and advice records — at least six years from the end of our relationship with you, in line with FCA record-keeping requirements. Records relating to pension transfers and similar long-tail advice are kept indefinitely, in line with FCA expectations.
- Anti-money-laundering records — five years from the end of the business relationship, as required by the Money Laundering Regulations 2017.
- Tax records — six years, plus the current tax year, in line with HMRC requirements.
- Marketing-related data — until you withdraw consent or ask us to stop.
- Website and analytics data — typically up to 26 months for analytics, and per the cookie schedule in our Cookie Policy.
7. Your rights under UK GDPR
You have the following rights in relation to your personal data:
- Right to be informed — to know what personal data we hold and how we use it (this policy is part of how we provide that information)
- Right of access — to receive a copy of the personal data we hold about you (commonly known as a "subject access request")
- Right to rectification — to have inaccurate or incomplete data corrected
- Right to erasure — to ask us to delete your data, subject to our regulatory record-keeping obligations
- Right to restrict processing — to limit how we use your data while a query is investigated
- Right to data portability — to receive certain data in a portable, machine-readable format
- Right to object — including to direct marketing and to processing based on legitimate interests
- Rights relating to automated decision-making and profiling — we do not currently use automated decision-making in a way that produces legal or similarly significant effects on you
- Right to withdraw consent — at any time, where processing is based on consent
To exercise any of these rights, contact us at info@arieswealth.co.uk. We will respond within one calendar month. There is normally no charge, although we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive.
8. How we keep your information secure
We take the security of your personal data seriously. Measures include:
- Encryption of data in transit and at rest
- Secure cloud-based document storage with access controls
- Multi-factor authentication on business systems and email
- Restricted access on a need-to-know basis
- Regular review of our information-security and business-continuity practices
- Written data-processing agreements with all third-party processors
9. Cookies and analytics
Our website uses cookies and similar technologies to make the site work, to remember your preferences, and (with your consent) to help us understand how the site is used. For full details, including how to manage your preferences, please see our Cookie Policy.
What our analytics records
Where you have given consent, we use Google Analytics 4 (property ID G-MXY1WKZS7N) to understand how visitors use the site. The information we record is pseudonymised and does not, on its own, identify you. Specifically:
- Page views — which pages and articles are visited, in what order, and how long is spent on each
- Site search — terms entered into any on-site search (we do not currently run one, but the event is reserved)
- Outbound link clicks — when a visitor clicks a link to an external website (e.g. the FCA Register or the Financial Ombudsman Service)
- File downloads — clicks on PDFs or other downloadable documents
- Scroll depth — whether visitors reach the bottom of long pages such as articles
- Video engagement — play, pause, and completion events for any embedded videos (none at present, but the event is reserved)
- Form interactions — when contact or booking forms are started and completed (we record the interaction, not the contents)
- Approximate location — country and region only, derived from a truncated IP address. We do not record city-level data and full IP addresses are not retained.
- Device information — browser type, operating system, and screen size, so we can ensure the site works well across devices
Google Analytics is configured with IP anonymisation enabled and Google Signals (cross-device tracking and advertising features) disabled. Data is retained for 14 months and is not shared with advertising networks. We do not use Google Analytics for marketing or remarketing.
You can opt out at any time using the "Manage cookies" link in our footer, or by installing Google's Analytics Opt-out browser add-on.
10. Complaints
If you have a concern about how we have handled your personal data, please contact us first using the details above. We will do our best to resolve the matter quickly. You also have the right to complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The "Last updated" date at the top shows when it was last revised. We encourage you to review it periodically.
