Legal
Shared Wealth Technology, a brand division of Shared Wealth International Ltd
Version 1.0.0 · Effective 3 August 2026
This DPA forms part of the Terms of Service and applies when Shared Wealth International Limited (“Processor”, “we”) processes personal data on behalf of a Customer organisation using SWT Asset Management (“Customer”, “Controller”).
This DPA is intended to meet Article 28 UK GDPR. It does not apply where we act as controller (see the Privacy Notice).
Effective date: 3 August 2026
Version: 1.0.0
| Item | Detail |
|---|---|
| Subject-matter | Operation of SWT Asset Management on Customer’s behalf |
| Duration | Term of Customer’s access plus retention in §9 |
| Nature / purpose | Hosting and processing Customer-entered business data for asset, capital, CRM, governance, document, and AI-assisted features |
| Types of data | Contact, account, organisational, document, and operational data Customer chooses to store |
| Data subjects | Customer staff, portfolio contacts, investors, and other individuals whose data Customer uploads |
We process personal data only on documented Customer instructions (including Platform configuration and uploads), unless required by law.
Authorised persons are under confidentiality obligations. Security measures include TLS, encryption at rest for sensitive documents, RBAC, MFA for privileged roles, IDOR controls, CSRF protection, rate limiting, audit logging, and backup procedures.
Customer authorises the sub-processors listed at /subprocessors. We will update that register before adding material new sub-processors; Customer may object on reasonable data-protection grounds.
We will assist Customer with data subject requests and notify Customer without undue delay (and within 48 hours where practicable) after becoming aware of a personal data breach affecting Customer data.
Transfers outside the UK/EEA use adequacy, UK IDTA, or SCCs with UK Addendum plus appropriate safeguards.
On termination, Customer may export data via available Platform tools. We will delete or anonymise Customer personal data within 90 days after termination or last successful export, except where law requires retention.
We will make available information reasonably necessary to demonstrate Article 28 compliance. Customer may request an audit no more than once per 12 months on 30 days’ notice, or accept a suitable third-party report.
Liability follows the commercial agreement or, if none, Terms §10. Order of precedence: commercial agreement (commercial matters) → this DPA (data protection) → Terms.
DPO: Cliff Southcombe — privacy@sharedwealth.international
This document is provided for transparency and compliance. It is not legal advice. Final reliance requires counsel sign-off.