Privacy Policy
About this privacy notice
If you would like this privacy notice in larger print or another format, please contact us using the details below.
Chester Rose (Hampshire) Limited, trading as Chester Rose Hampshire, takes your privacy seriously. We are committed to handling your personal information lawfully, fairly and transparently in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018.
This privacy notice explains how we collect, use, share, store and protect your personal information when you:
- Visit our website;
- Contact us;
- Ask us to provide financial planning or financial advice services; or
- Otherwise interact with us.
It also explains your data protection rights, how we may use artificial intelligence or automated tools, and how you can complain about our handling of your personal information.
Who is responsible for your personal information
Chester Rose (Hampshire) Limited is the controller responsible for the personal information described in this privacy notice.
Contact details
Please contact us if you have any questions about this privacy notice or the personal information we hold about you.
Email: jane@chesterrosehampshire.co.uk
Telephone: 01329 243979
Post: Chester Rose (Hampshire) Limited, 8a The Gardens, Broadcut, Fareham, Hampshire, PO16 8SS.
What personal information we collect
When you engage us for financial planning or financial advice services, we may collect and use the following information.
Personal identifiers
This may include:
- Your name, date of birth, address and contact details;
- Your National Insurance number;
- Copies of identification documents, such as your passport or driving licence; and
- Information required to verify your identity.
Financial and professional information
This may include:
- Your income and regular expenditure;
- Details of your assets, liabilities, pensions and investments;
- Tax information;
- Bank account information;
- Employment and business information;
- Financial objectives and priorities;
- Attitude to investment risk;
- Capacity for loss; and
- Information about your existing financial arrangements.
Special-category information
Where relevant to the services we provide, we may need to process special-category information, such as health information when providing insurance or protection advice.
Where explicit consent is required, we will explain why the information is needed and obtain your consent before processing it.
Communications and regulatory records
We may retain:
- Emails and other correspondence;
- Notes of telephone conversations;
- Meeting notes;
- Financial planning and suitability records;
- Instructions and consents; and
- Records required to comply with Financial Conduct Authority requirements.
How we collect your personal information
We may collect personal information:
- Directly from you during meetings, telephone calls and email correspondence;
- Through website forms;
- Through forms, questionnaires and Initial Discovery (fact-finding) exercises;
- From financial product providers, pension providers and investment platforms;
- From professional advisers acting on your behalf;
- From identity-verification, fraud-prevention or credit-reference services; and
- From other sources where you have authorised us to obtain information.
How we use your personal information
We use your personal information to:
- Understand your circumstances, objectives and financial position;
- Provide financial planning and financial advice;
- Assess the suitability of recommendations;
- Apply for or arrange financial products and services on your behalf;
- Communicate with product providers, investment platforms and other relevant organisations;
- Carry out identity, fraud-prevention and anti-money-laundering checks;
- Maintain accurate and compliant records;
- Communicate with you about your plans, policies, investments and services;
- Administer our relationship with you;
- Meet legal and regulatory requirements;
- Investigate and respond to complaints; and
- Improve the operation and security of our services and systems.
Our lawful bases for using your personal information
We must have a valid legal reason, known as a lawful basis, for collecting and using your personal information.
Contract
We use personal information where it is necessary to provide the services you have asked us to deliver or to take steps at your request before entering into a contract.
If you do not provide information that is necessary for these purposes, we may be unable to provide the requested services.
Legal obligation
We process certain information to comply with legal and regulatory requirements. This includes identity verification, anti-money-laundering obligations, regulatory record-keeping and responding to lawful requests from regulators or authorities.
Consent
We may rely on your consent:
- When processing certain special-category information;
- Where consent is required for marketing communications; or
- In other circumstances where we have explained the purpose and requested your agreement.
You may withdraw your consent at any time. Withdrawing consent will not affect processing carried out lawfully before it was withdrawn.
Legitimate interests
We may process information where this is necessary for our legitimate business interests, provided those interests do not override your rights.
This may include:
- Managing and improving our services;
- Maintaining appropriate records;
- Checking the quality and suitability of our services;
- Responding to complaints or potential future claims;
- Meeting the requirements of our professional indemnity insurer; and
- Protecting our systems and business against fraud or misuse.
Recognised legitimate interests
In limited circumstances, we may rely on a recognised legitimate interest for purposes such as fraud prevention or safeguarding, where permitted by law.
Artificial intelligence and automated tools
We may use secure AI-assisted or automated tools to support administrative, analytical and compliance activities. This may include drafting or summarising internal documents, identifying possible errors or inconsistencies, assisting with compliance monitoring, or supporting non-decision-making risk assessments.
We do not use systems to make significant decisions about you without meaningful human involvement. Any AI-assisted output that may affect the services provided to you is reviewed and approved by an appropriately authorised member of staff.
We aim to process only the minimum personal information necessary and anonymise or pseudonymise information where reasonably possible. We require relevant suppliers to protect personal information under appropriate contractual arrangements.
We do not permit your personal information to be used to train publicly available AI models.
Where an AI supplier processes personal information outside the UK, we will ensure that an appropriate legal transfer mechanism and safeguards are in place.
Who we share your personal information with
To provide our services and comply with our obligations, we may share personal information with:
- Financial product providers;
- Pension and insurance providers;
- Investment platforms;
- Discretionary investment managers;
- Compliance consultants, auditors and professional advisers;
- IT providers and secure cloud-service providers;
- Identity-verification, fraud-prevention and credit-reference agencies;
- Chester Rose Financial Planning, where relevant to the services we provide and our regulatory arrangements;
- The Financial Conduct Authority;
- HM Revenue & Customs;
- The Financial Ombudsman Service;
- The Information Commissioner’s Office;
- Law-enforcement bodies and other authorities where required by law; and
- Other organisations where you have authorised us to share information.
We do not sell your personal information.
Where a supplier processes personal information on our behalf, we require it to protect the information and process it only in accordance with our instructions and applicable data protection law.
Transfers outside the UK
We do not transfer your personal information outside the UK unless lawful safeguards apply, including United Kingdom adequacy regulations. We have also taken reasonable steps to confirm that the processors acting on our behalf do not transfer or remotely access your personal information outside the UK unless lawful safeguards apply, including United Kingdom adequacy regulations.
How long we keep your personal information
We retain personal information only for as long as necessary for the purpose for which it was collected and to meet our legal, regulatory and legitimate business requirements.
- Investment business: five years;
- Pension transfers and opt-outs: indefinitely;
- Insurance/protections business: three years; and
- Anti-money-laundering identity records: at least five years after the relationship ends.
We may retain some information for longer where this is necessary to establish, exercise or defend legal claims, respond to complaints, or comply with another legal or regulatory requirement.
We regularly review the information we hold and do not retain personal information for longer than necessary.
Information about connected individuals
We may need information about your spouse, partner, family members, dependants, beneficiaries or other connected individuals to provide our services.
If you provide information about another person, you should ensure that you are permitted to do so and make them aware of this privacy notice.
Where you act as a trustee, attorney or other representative, we may also need information about beneficiaries, donors or the people you represent.
Cookies
We currently use only cookies that are strictly necessary for the operation and security of our website. These cookies enable essential functions and cannot be switched off through our website.
Further information about the cookies we use, their purpose and how long they remain on your device is available in our Cookie Notice.
You can control or delete cookies through your browser settings. Blocking essential cookies may affect how parts of the website operate.
Marketing
We may send you information about our services where we have an appropriate lawful basis to do so.
Where we rely on your consent, you can withdraw that consent at any time by contacting us or using the unsubscribe option included in the communication.
We will not sell your personal information to third parties for marketing purposes.
Your data protection rights
Depending on the circumstances, you may have the right to:
- Be informed about how your personal information is used;
- Request access to your personal information;
- Ask us to correct inaccurate or incomplete information;
- Ask us to erase your information;
- Ask us to restrict how your information is used;
- Object to certain processing, including direct marketing;
- Request the transfer of your information in a structured, commonly used and machine-readable format;
- Withdraw consent where consent is the lawful basis; and
- Request human review, an explanation or challenge a decision where a significant decision has been made without meaningful human involvement.
These rights are subject to legal and regulatory exceptions. For example, we may be required to retain certain information even where you request its deletion.
We aim to respond to data protection rights requests within one month. Where a request is particularly complex or a number of requests have been made, we will explain any permitted extension and keep you informed.
How to make a complaint
If you have concerns about how we have handled your personal information, you may complain to us using any of the contact details at the beginning of this notice. You do not need to use a particular form or wording.
We will acknowledge your complaint promptly, investigate it and respond without undue delay. We will keep you informed where appropriate.
You also have the right to complain to the Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website:
www.ico.org.uk/make-a-complaint
We would appreciate the opportunity to address your concerns first, but you are not required to contact us before approaching the ICO.
Protecting your personal information
We use appropriate technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration, loss or misuse.
Access to personal information is restricted to individuals and suppliers who need it for legitimate business purposes and who are subject to appropriate confidentiality and data protection obligations.
Although we take reasonable steps to protect personal information, no electronic transmission or storage system can be guaranteed to be completely secure.
Changes to this privacy notice
We may update this privacy notice to reflect changes in our services, systems, suppliers, legal obligations or regulatory requirements.
The current version will be published on our website. Where a change materially affects how we use your personal information, we will take reasonable steps to bring the change to your attention.
Last updated: 11th August 2026
