LEGAL

Privacy Policy

Last updated: 6 September 2026

At Astute Finance, we take the privacy, confidentiality and security of personal information seriously.

This Privacy Policy explains how we collect, receive, use, process, store and share personal information in connection with our website and the business process outsourcing, customer contact, lead generation, lead verification, compliance, administration and referral services we provide.

Because of the nature of our business, Astute Finance may have a different role under data protection law depending on the particular service or processing activity involved.

For some activities we act as a data controller. For others, we act as a data processor on behalf of another organisation. In some arrangements, two organisations may jointly determine the purposes and means of a particular activity and therefore act as joint controllers.

Our role is determined by what each organisation actually does with the information and the decisions it makes, rather than simply by the terminology used in a commercial agreement.

1. Who we are

Astute Finance provides specialist business process outsourcing and intermediary services, principally to organisations operating within the financial services sector.

Our services may include:

  • lead generation;
  • customer acquisition support;
  • lead verification and qualification;
  • customer communications;
  • administration;
  • data processing;
  • back-office operations;
  • customer support;
  • data-protection and compliance processes;
  • referral and introduction services; and
  • other outsourced business support services.

Legal entity: Astute Finance Limited

Trading name: Astute Finance

Registered office: C/O Burton Varley Ltd, The Counting House, 24 Richmond Road, Bowdon, Altrincham, England, WA14 2TT

Company number: 11334616

ICO registration number: ZC243600

Privacy email: info@astutefinance.co.uk

Telephone: 0161 383 6001

2. Understanding our data-protection role

Under UK data protection law, a controller determines the purposes and essential means of processing personal information.

A processor processes personal information on behalf of a controller and generally acts in accordance with that controller's documented instructions.

A joint-controller arrangement may exist where two or more organisations jointly determine the purposes and means of a particular processing activity.

An organisation is not automatically a controller or processor simply because of the type of business it operates. Its role must be considered in relation to the particular processing activity concerned.

Astute Finance may therefore be a controller for one activity and a processor for another, even where those activities form part of the same overall customer journey.

3. Where Astute Finance acts as a data controller

Astute Finance will normally act as a controller where we determine why and how personal information is being processed.

This may include circumstances where:

  • you contact Astute directly through our website;
  • you telephone or email us about our own services;
  • you make a business or partnership enquiry;
  • we manage our relationships with clients, suppliers or professional contacts;
  • we recruit or engage personnel;
  • we maintain our own corporate, compliance or accounting records;
  • we process information for our own legal or regulatory purposes; or
  • Astute independently determines the purpose for which particular customer information is being used.

Where we act as controller, Astute Finance is responsible for identifying an appropriate lawful basis, providing relevant privacy information and complying with the obligations that apply to controllers.

4. Where Astute Finance acts as a processor

In many of our business process outsourcing arrangements, another organisation determines why personal information is being processed and appoints Astute Finance to carry out particular tasks on its behalf.

For example, a client may provide us with customer or prospective-customer information and instruct us to:

  • contact customers;
  • verify information;
  • administer enquiries;
  • provide customer support;
  • process records;
  • undertake back-office administration;
  • conduct an agreed compliance process;
  • arrange appointments;
  • qualify enquiries; or
  • perform another defined business function.

Where Astute performs those activities solely on the documented instructions of the relevant controller and does not determine an independent purpose for using the information, Astute will normally act as a data processor.

A processor may make practical or technical decisions about how to perform an instructed service, such as the systems or security measures it uses, without necessarily becoming a controller. However, if a processor begins deciding the overarching purpose for which information is used, it may become a controller in relation to that processing.

5. Where Astute Finance acts as an intermediary

Astute Finance also provides intermediary, verification, compliance and referral services.

Under these arrangements, another organisation may initially generate, receive or obtain a customer enquiry and subsequently provide relevant customer information to Astute Finance.

A typical journey might be:

Referring Organisation → Astute Finance → Receiving Organisation

Astute may subsequently contact the customer in order to:

  • confirm their identity or contact information;
  • confirm or update information already provided;
  • clarify the nature of the customer's enquiry;
  • confirm that they still wish to proceed;
  • provide relevant data-protection information;
  • deliver an agreed compliance statement or disclosure;
  • record customer confirmations;
  • verify that agreed eligibility or referral criteria are met; and
  • where appropriate, introduce, refer or transfer the customer to the intended receiving organisation.

6. Responsibilities of a referring organisation

Where another organisation independently generates or collects a customer enquiry and determines the purposes and means of that original collection, that organisation will normally act as controller for the original processing.

Depending upon the particular circumstances, this can include responsibility for:

  • having an appropriate lawful basis;
  • collecting information fairly;
  • providing appropriate privacy information;
  • making clear how information may be used or shared;
  • obtaining valid consent where consent is required;
  • respecting marketing preferences and objections;
  • ensuring information is accurate;
  • maintaining appropriate records; and
  • ensuring that any onward disclosure is lawful.

7. Astute Finance's due diligence on lead and referral partners

Although Astute may not have carried out the original lead generation, we recognise the importance of taking reasonable steps to understand the source and provenance of customer information supplied to us.

Depending on the particular campaign and relationship, this may include reviewing:

  • how leads or enquiries are generated;
  • the websites, forms or advertisements used;
  • relevant privacy notices;
  • marketing and consent wording where appropriate;
  • how customers are informed about onward sharing;
  • the intended recipients of customer information;
  • the source of the information;
  • relevant direct-marketing processes;
  • suppression and opt-out procedures;
  • record-keeping;
  • data-protection processes;
  • information-security arrangements;
  • contractual obligations; and
  • evidence supporting the lawful collection and use of information.

8. Responsibility of the receiving organisation

Where a customer is introduced or transferred to another organisation, that organisation may subsequently process the customer's information for its own purposes. Where it independently determines the purposes and means of that subsequent processing, it will normally act as a controller for those activities.

9. Information we may process

The personal information we process depends upon the particular service. It may include:

  • name;
  • telephone number;
  • email address;
  • postal address;
  • date of birth where relevant;
  • information relating to a customer enquiry;
  • details of a product or service in which you have expressed an interest;
  • customer reference or case information;
  • correspondence;
  • records of telephone calls;
  • call recordings where applicable;
  • compliance records;
  • consent or marketing-preference records;
  • objections and suppression information;
  • information supplied by our clients or referral partners; and
  • technical information generated when you use our website.

10. Where we obtain personal information

Directly from you

For example, when you submit an enquiry through our website, contact us by telephone or email, communicate with one of our representatives, or provide or confirm information during a telephone conversation.

From one of our clients

A client may provide information to Astute so that we can perform an outsourced service on its behalf.

From a referring or lead-generation organisation

An organisation may generate an enquiry and provide relevant information to Astute for verification, compliance processing, qualification or onward introduction.

From public or professional sources

Where appropriate for our own business-to-business activities, we may also obtain professional contact information from legitimate publicly available or commercial business sources.

11–15. Privacy information, use of data, lawful bases & marketing

Where Astute acts as a controller and receives your personal information from another organisation, we will provide the privacy information required by applicable law unless an exemption applies. The personal information may be processed to respond to enquiries, provide BPO services, contact customers on behalf of clients, verify customer information, qualify enquiries, administer customer records, carry out compliance processes, provide required disclosures, manage customer communications, and comply with legal or regulatory obligations.

Where Astute Finance acts as controller, the lawful basis we rely upon will depend upon the particular processing activity. These may include Contract, Legitimate interests, Legal obligation, and Consent.

16. Sharing personal information

Depending upon the service and our role, personal information may be shared with:

  • the client on whose behalf Astute is providing a service;
  • a referring or originating organisation where necessary;
  • the intended receiving organisation;
  • approved IT and technology providers;
  • telecommunications providers;
  • cloud or hosting providers;
  • professional advisers;
  • compliance and audit providers;
  • authorised sub-processors;
  • regulators;
  • courts;
  • law-enforcement organisations; or
  • other organisations where disclosure is required or permitted by law.

Astute Finance does not sell personal information.

17–24. Processor contracts, joint controllers, call recording, accuracy, security, breaches, international transfers & retention

Where Astute Finance acts as a processor, appropriate contractual arrangements are put in place with the relevant controller, addressing the nature and purpose of processing, security, use of sub-processors, assistance with individual rights, personal-data breaches, and deletion or return of information.

Astute Finance uses appropriate technical and organisational measures designed to protect personal information, including access controls, authentication, role-based permissions, secure systems, staff confidentiality obligations, employee training, and incident-management processes.

We retain personal information only for as long as reasonably necessary for the purpose for which it is processed. At the end of the relevant retention period, information will be securely deleted, returned or anonymised as appropriate.

25. Your data-protection rights

Depending upon the circumstances and applicable law, you may have rights including the right to:

  • request access to your personal information;
  • request correction of inaccurate information;
  • request deletion of personal information;
  • request restriction of processing;
  • object to particular processing;
  • object to direct marketing;
  • request data portability where applicable; and
  • withdraw consent where processing is based upon consent.

26–31. Marketing objections, automated decisions, cookies, third-party sites, complaints & changes

You have the right to object to the use of your personal information for direct marketing. Astute Finance does not intend to use personal information collected through our corporate website to make decisions based solely on automated processing. Our website may use cookies and similar technologies — more information is available in our Cookie Policy.

If you have concerns about the way personal information has been handled, please contact us. You also have the right to raise concerns with the Information Commissioner's Office (ICO). We may update this Privacy Policy periodically to reflect changes in our services, processing arrangements, suppliers, technology, applicable law, or regulatory guidance.

32. Contact us

Astute Finance

Astute Finance Limited (Company No. 11334616)

C/O Burton Varley Ltd, The Counting House, 24 Richmond Road, Bowdon, Altrincham, England, WA14 2TT

Email: info@astutefinance.co.uk

Telephone: 0161 383 6001

ICO registration: ZC243600

Approved by: Gemma Clarence

Position: Operations Manager

Email: gemma@astutefinance.co.uk

Telephone: 0161 383 6001

Date: September 2026