Legal

Privacy Notice

Effective date: July 1, 2025

Zavelo Holdings Ltd (“Zavelo,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal data. This Notice explains what we collect, why, how we use it, and your rights under applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

Zavelo Holdings Ltd is the data controller responsible for your personal data. Registered address: 25 Farringdon Street, London, EC4A 4AB, United Kingdom. Contact: privacy@zaveloholdings.com.

2. Data We Collect

We collect the following categories of personal data:

Identity data

Full name, date of birth, nationality, and government-issued identification documents.

Contact data

Email address, telephone number, and residential or correspondence address.

Financial data

Bank account details, transaction history, deposit and withdrawal records, and investment portfolio data.

Verification data

Identity document images, selfies or proof-of-liveness data collected during KYC verification.

Technical data

IP address, device identifiers, browser type and version, operating system, and session data.

Usage data

Page views, feature interactions, session duration, and navigation paths within the Platform.

Communications data

Records of any correspondence you send to us, including support requests and dispute submissions.

3. How We Use Your Data

We process your personal data for the following purposes and on the following legal bases:

  • Contract performance — to open and administer your account, process deposits and withdrawals, and deliver investment plan services.
  • Legal obligation — to comply with AML regulations, KYC requirements, tax reporting obligations, and regulatory reporting mandates.
  • Legitimate interests — to improve Platform functionality, prevent fraud, conduct security monitoring, and analyse usage patterns.
  • Consent — to send you marketing communications where you have opted in (you may withdraw consent at any time).

4. Data Sharing and Disclosure

We do not sell your personal data. We may share it with:

  • Identity verification providers — third-party KYC/AML technology partners who process verification data on our behalf.
  • Banking and payment partners — institutions that process deposits and withdrawals in connection with your account.
  • Cloud and infrastructure providers — hosting, storage, and security service providers operating under strict data processing agreements.
  • Regulatory and law enforcement authorities — where required by applicable law, court order, or government mandate.
  • Professional advisers — legal, audit, and compliance professionals bound by professional confidentiality obligations.

All third-party processors are required to implement appropriate technical and organisational security measures.

5. Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, and accounting obligations. Identity and financial records are typically retained for a minimum of five years following account closure, in compliance with AML legislation. Technical and usage data is retained for a shorter period unless required for security or legal purposes.

6. Your Rights

Under applicable data protection law, you have the right to:

  • Access a copy of the personal data we hold about you;
  • Rectification of inaccurate or incomplete data;
  • Erasure (the “right to be forgotten”) in certain circumstances;
  • Restriction of processing in defined situations;
  • Portability of data you provided in a structured, machine-readable format;
  • Objection to processing based on legitimate interests; and
  • Withdrawal of consent at any time, without affecting the lawfulness of prior processing.

To exercise any of these rights, please email privacy@zaveloholdings.com. We will respond within 30 days. If you are dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

7. Security

We implement industry-standard technical and organisational security measures, including AES-256 encryption at rest, TLS 1.3 in transit, access controls, multi-factor authentication for staff, and regular penetration testing. No data transmission over the internet is entirely secure; however, we work to protect your information using commercially reasonable safeguards.

8. Cookies

We use strictly necessary cookies to maintain session state and authentication. We use analytics cookies (with your consent) to understand how the Platform is used and improve it. You can control cookie preferences via your browser settings or our consent management interface. Disabling strictly necessary cookies will prevent the Platform from functioning correctly.

9. International Transfers

Where we transfer personal data outside the UK or European Economic Area, we do so only where adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the ICO or the European Commission, or where the destination country benefits from an adequacy decision.

10. Changes to This Notice

We may update this Notice from time to time. When we do, we will revise the effective date and notify you by email or in-platform alert. We encourage you to review this Notice periodically.