Legal
Privacy Notice
Effective date: July 1, 2025
Zavelo Holdings Ltd (“Zavelo,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal data. This Notice explains what we collect, why, how we use it, and your rights under applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
Zavelo Holdings Ltd is the data controller responsible for your personal data. Registered address: 25 Farringdon Street, London, EC4A 4AB, United Kingdom. Contact: privacy@zaveloholdings.com.
2. Data We Collect
We collect the following categories of personal data:
Identity data
Full name, date of birth, nationality, and government-issued identification documents.
Contact data
Email address, telephone number, and residential or correspondence address.
Financial data
Bank account details, transaction history, deposit and withdrawal records, and investment portfolio data.
Verification data
Identity document images, selfies or proof-of-liveness data collected during KYC verification.
Technical data
IP address, device identifiers, browser type and version, operating system, and session data.
Usage data
Page views, feature interactions, session duration, and navigation paths within the Platform.
Communications data
Records of any correspondence you send to us, including support requests and dispute submissions.
3. How We Use Your Data
We process your personal data for the following purposes and on the following legal bases:
- Contract performance — to open and administer your account, process deposits and withdrawals, and deliver investment plan services.
- Legal obligation — to comply with AML regulations, KYC requirements, tax reporting obligations, and regulatory reporting mandates.
- Legitimate interests — to improve Platform functionality, prevent fraud, conduct security monitoring, and analyse usage patterns.
- Consent — to send you marketing communications where you have opted in (you may withdraw consent at any time).
4. Data Sharing and Disclosure
We do not sell your personal data. We may share it with:
- Identity verification providers — third-party KYC/AML technology partners who process verification data on our behalf.
- Banking and payment partners — institutions that process deposits and withdrawals in connection with your account.
- Cloud and infrastructure providers — hosting, storage, and security service providers operating under strict data processing agreements.
- Regulatory and law enforcement authorities — where required by applicable law, court order, or government mandate.
- Professional advisers — legal, audit, and compliance professionals bound by professional confidentiality obligations.
All third-party processors are required to implement appropriate technical and organisational security measures.
5. Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, and accounting obligations. Identity and financial records are typically retained for a minimum of five years following account closure, in compliance with AML legislation. Technical and usage data is retained for a shorter period unless required for security or legal purposes.
6. Your Rights
Under applicable data protection law, you have the right to:
- Access a copy of the personal data we hold about you;
- Rectification of inaccurate or incomplete data;
- Erasure (the “right to be forgotten”) in certain circumstances;
- Restriction of processing in defined situations;
- Portability of data you provided in a structured, machine-readable format;
- Objection to processing based on legitimate interests; and
- Withdrawal of consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, please email privacy@zaveloholdings.com. We will respond within 30 days. If you are dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
7. Security
We implement industry-standard technical and organisational security measures, including AES-256 encryption at rest, TLS 1.3 in transit, access controls, multi-factor authentication for staff, and regular penetration testing. No data transmission over the internet is entirely secure; however, we work to protect your information using commercially reasonable safeguards.
8. Cookies
We use strictly necessary cookies to maintain session state and authentication. We use analytics cookies (with your consent) to understand how the Platform is used and improve it. You can control cookie preferences via your browser settings or our consent management interface. Disabling strictly necessary cookies will prevent the Platform from functioning correctly.
9. International Transfers
Where we transfer personal data outside the UK or European Economic Area, we do so only where adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the ICO or the European Commission, or where the destination country benefits from an adequacy decision.
10. Changes to This Notice
We may update this Notice from time to time. When we do, we will revise the effective date and notify you by email or in-platform alert. We encourage you to review this Notice periodically.