2plan Privacy Policy

Data protection is taken seriously at 2plan Wealth Management Limited ("2plan") and safeguarding the privacy of our website visitors and clients in general is very important to us.

We will always use your personal data in accordance with applicable data protection laws, for example, the UK General Data Protection Regulation ("UK GDPR").

Our Privacy Policy provides details on how any personal information we may collect from you, or you provide to us, will be processed and used by us in connection with our wealth management services (the "Services"), and when you visit our website, "www.2plan.com" (our "website").

It is 2plan's intention to always be transparent in providing clear and unambiguous information on who we are and what we do.

About us

For the purposes of this Privacy Policy, "we", "our" and "us" shall refer to 2plan and "Partner" shall refer to your 2plan adviser.

2plan, which was launched in 2007, is one of the leading wealth management firms in the United Kingdom, providing wealth management advice from outstanding financial advisers.

Our primary focus is on the provision of wealth management services for private investors and corporate clients throughout the UK. The range of services covers all aspects of pensions, investments, insurance, and mortgage business.

Our wealth management services are provided through personal and experienced advisors, through our 2plan Client Portal, face to face, and hybrid meetings.

2plan is a company incorporated under the laws of England and Wales with the Company registration number 05998270. Its registered office is at 3rd Floor Bridgewater Place, Water Lane, Leeds, West Yorkshire, LS11 5BZ. We are registered with the Information Commissioner’s Office (“ICO”) under the number Z9770624.

For the purposes of applicable data protection law, in particular the UK GDPR, the data controller of your personal information will be either 2plan or the Partner you have instructed, which is providing services to you or communicating with you, and each of us is acting as an independent data controller with respect to the processing of your personal data.

2plan will collect personal information about you as part of its role as Principal, in order to ensure that the 2plan Partners are compliant with applicable financial regulations. As Principal, we also have access to all personal information that Partners collect and use. 2plan and its Partners are acting as independent controllers for the processing of your personal information with respect to these purposes.

How we collect your personal data

We will collect your personal data in the following ways:

  • Directly from you when you:
    • provide information by filling out forms on our website. This includes information provided at the time of registering to use and updating via our Client Portal on our website, subscribing to our products and services, posting material, or requesting further products and services. We may also ask you for information when you report a problem with our website.
    • contact us by email, telephone, messaging via our Client Portal, and through other written and verbal communications.
    • complete our in-depth information gathering, either remotely or face to face with one of our Partners in relation to offering you advice on financial products and services you have asked us about.
  • Via your I.P. address when you visit our website and make any acknowledgement of a document via our Client Portal.
  • If you contact us, we may keep securely a record of that correspondence (including email and phone conversations), including your name, address, telephone numbers, email address, and other information that you supply to us.
  • We may also ask you to complete, from time to time, surveys or questionnaires that you have agreed to that we use for regulatory or research purposes or to improve our relationship with our clients.

We will also collect your personal information from:

  1. Tenet (TenetConnect Limited/TenetConnect Services Limited) or any other previous advice network, if your personal data was collected by your Tenet Independent Financial Adviser or other former advice firm (as applicable) prior to that Adviser becoming an appointed representative of 2plan.
  2. Your 2plan Partner where applicable.
  3. 2plan Client Portal.
  4. Publicly available sources.

Information we may collect from you

The following are examples of types of personal data that we may collect if you visit our website, we set you up as a client or you otherwise engage with us (for example, as a supplier). The specific kind of information collected by us will depend on the services provided:

Contact Data:

  • First name, Last name, Email address, Phone number, Address, Company, and Job title.

Financial Data:

  • Billing address, bank account information.
  • Annual income.

Profile Data:

  • Demographic information.
  • Biometric data, such as voice recordings.
  • Your location.
  • Your interests and preferences.

Job Applicant Data:

  • Curriculum Vitae Information.

Technical Data:

  • Details about your computer, devices, applications, and networks (including IP address, browser characteristics, device ID, operating system, or language preferences)

Usage Data:

  • Activities on our websites (including referring URLs or dates and times of website visits). Please see our Cookie Policy (below) for further information.

Special Categories and Sensitive Data

We may collect the following information as part of our regulatory requirements:

  • Mental and physical health, including vulnerability
  • Any other personal information that you choose to share with us, such as political or religious views and criminal convictions and judgements
  • Nationality
  • Details for conducting Politically Exposed Person and Sanctions checks against relevant lists
  • Criminal convictions and judgements relating to, or resulting from, the above checks or which you have told us about

In limited circumstances, we may also collect information that relates to your trade union membership (for example, when gathering your employment details), genetic or biometric data, or data concerning your sex life or sexual orientation where you instruct us on joint products.

Uses made of the information

We may use information held about you in the following ways:

  • To ensure that content from our website is presented in the most effective manner for you and your computer.
  • To provide you with information, products, or services that you request from us or that we feel may be of interest to you, where you have consented to be contacted for such purposes. You may ask us to cancel this consent at any time, and you will only then receive information specifically about your account activity with 2plan.
  • To carry out our obligations arising from any contract entered into between you and us and that may involve providing some of your information to a third party to carry out necessary background checks (including but not limited to Identity Verification / Anti Money Laundering / Fraud Prevention / Residency Confirmation).
  • To provide some or all of your personal information (as required) to one or more financial product providers in order to fulfil a detailed proposal for the services you have asked 2plan about.
  • To provide some or all of your personal information (as required) to one or more financial product providers in order to fulfil a request to purchase a financial product.
  • To carry out a form of profiling that gives us a clear view of your circumstances, and that is part of the advice process. Where this is done, you will be shown its recommendations and will be provided with the opportunity to review and amend its output to indicate your attitude to risk.
  • For training purposes, quality assurance, or to record details about the products and services you ask us about.
  • To satisfy and meet our legal and regulatory requirements with the FCA and ICO, or as requested by UK security services.
  • To notify you about changes to our products and services or terms and conditions.

The lawful bases we rely on

We have set out below, in table format, a description of all the ways we plan to use your personal data and which of the legal bases we rely on to do so. We have also identified what legal basis would apply when processing special categories or sensitive data.

Note that we may process your personal data for more than one lawful reason, depending on the specific purpose for which we are using it.

PURPOSE/ACTIVITY TYPE OF DATA LAWFUL BASIS FOR PROCESSING
To carry out our obligations arising from any contract entered into between you and us and that may involve providing some of your information to a third party to carry out necessary background checks (including but not limited to Identity Verification / Anti Money Laundering / Fraud Prevention / Residency Confirmation).
  1. Contact
  2. Financial Data

It is necessary to enter into your client agreement.

In relation to a special category of data:

  • It is in the substantial public interest to comply with regulatory requirements relating to unlawful acts and dishonesty.
  • We have your explicit consent.
  • We need to establish, exercise, or defend legal rights.
To establish and manage your account.
  1. Contact
  2. Financial Data
Necessary as part of our performance of a contract or for our legitimate interests to provide our services under a contract.
To provide services in accordance with your product agreement.
  1. Contact
  2. Financial
  • It is necessary to enter into or perform your product agreement.
  • We have a valid business reason based on legitimate interest (to ensure that we fulfil our contractual obligations to clients).

In relation to a special category of data:

  • You have given us your explicit consent.
  • We need to use your information in order to establish, exercise, or defend legal rights.
To prevent and investigate fraud.
  1. Contact
  2. Financial
  • It is necessary to enter into or perform your client agreement.
  • We have a valid business reason based on legitimate interest (to prevent and detect fraud and other financial crime).

In relation to a special category of data:

  • We need to use your information in order to establish, exercise, or defend legal rights.
  • We have a substantial public interest in preventing or detecting unlawful acts (where we suspect fraud).
  • It is in the substantial public interest to comply with regulatory requirements relating to unlawful acts and dishonesty.
  • We have your explicit consent.
Communicate with you in relation to the information you have provided by filling in forms on any of our websites; this includes posting material, making any inquiries through the “Contact Us” section of our websites, or requesting further services.
  1. Contact
  2. Financial
Legitimate interests, to respond to your queries and provide information.
To provide some or all of your personal information (as required) to one or more financial products providers in order to (1) fulfil a detailed proposal for the services you have asked 2plan about, or (2) fulfil a request to purchase a financial product.
  1. Contact
  2. Financial
  • It is necessary to enter into or perform your product agreement.
  • We have a valid business reason based on legitimate interest (to ensure that we fulfil our contractual obligations to clients).
To provide you marketing information on products or services that you request from us or that we feel may be of interest to you, where you have consented to be contacted for such purposes. You may ask us to cancel this consent at any time, and you will only then receive information specifically about your account activity with 2plan.
  1. Contact
  • You have given us your explicit consent.
  • We have a valid business reason based on legitimate interests (to send you selected communications about other products and services we offer).
To carry out annual reviews and reviews of the ongoing suitability of your current choices as required.
  1. Contact
  2. Financial
  • It is necessary to enter into or perform your client agreement.
  • We have a valid business reason (to ensure that we are providing appropriate services according to your circumstances).

In relation to a special category of data:

  • You have given us your explicit consent.
  • We need to use your information in order to establish, exercise, or defend legal rights.
To process and communicate with you in relation to your job application.
  1. Contact
  2. Job Applicant
Necessary for our legitimate interests to consider employing you and (if successful) taking steps to enter into a contract with you.
To ensure that content from our website is presented in the most effective manner for you and your computer.
  1. Technical
  2. Usage
Necessary for our legitimate interest to provide you with the best client experience.
To notify you about changes to our products and services or terms and conditions.
  1. Contact
  2. Profile
  3. Usage
Necessary as part of fulfilling any contractual obligations or legitimate interest in updating you and providing you with a good service.
To comply with our legal or regulatory obligations, in particular with the FCA and the ICO, or as requested by UK security services.
  1. Contact
  2. Financial
  • Performance of a contract with you.
  • Necessary to comply with a legal obligation.
  • Necessary for our legitimate interests, to keep our records updated, and to study how clients use our products and services.

In relation to a special category of data:

  • We need to use your information in order to establish, exercise, or defend legal rights.
  • We have a substantial public interest in preventing or detecting unlawful acts (where we suspect fraud).
  • It is in the substantial public interest to comply with regulatory requirements relating to unlawful acts and dishonesty.
  • We have your explicit consent.
To carry out a form of profiling that gives us a clear view of your circumstances, and that is part of the advice process. Where this is done, you will be shown its recommendations and will be provided with the opportunity to review and amend its output to indicate your attitude to risk.
  1. Contact
  2. Financial
  3. Profile
  4. Usage
  • Necessary as part of fulfilling any contractual obligations or legitimate interest in updating you and providing you with a good service.

In relation to a special category of data:

  • You have given us your explicit consent.
For training purposes, quality assurance, or to record details about the products and services you ask us about.
  1. Contact
  2. Profile
  3. Technical
  • We have a valid business reason (to develop and improve the products and services we offer).

In relation to a special category of data:

  • You have given us your explicit consent.
To communicate with you and resolve any queries or complaints that you might have (adviser behaviour monitoring calls).
  1. Contact
  2. Call recordings
  • It is necessary to enter into or perform your client agreement.
  • We have a valid business reason (to communicate with you, record and investigate complaints, and ensure that complaints are handled appropriately).
  • We need to use your information in order to comply with our legal and regulatory obligations.

In relation to a special category of data:

  • We need to use your information in order to establish, exercise, or defend legal rights.

If you wish to object to our reliance on Legitimate Interests for any purpose, please contact data.protection@2plan.com

Disclosure of your information

We may disclose your personal information to any member of the 2plan group of companies in order to fulfil any obligations to you.

We will not sell or transfer your personal information to anyone unless we have a valid purpose as set out above, and we will only disclose it to the following parties:

  • Third parties who facilitate the arrangement of products that you purchase from us, such as product providers, where we have shared your personal information with these third parties, they will also be a data controller and responsible for how they use your personal information. Their use of your personal information will be governed by their own privacy notices.
  • Your Partner, so that the product you have purchased can be integrated into the wealth management service provided to you by your Partner.
  • Third parties who have entered into contractual arrangements with us to provide services we need to carry out our everyday business activities such as partner support specialists, document management providers, back-office system providers, secure login and email providers, storage warehouses, IT suppliers, actuaries, auditors, lawyers, outsourced business process management providers, our subcontractors, and tax advisers.
  • Compliance consultants.
  • Financial crime and fraud detection agencies.
  • Our regulators include the Financial Conduct Authority and the Financial Ombudsman Service.
  • Selected third parties in connection with any sale, transfer, or disposal of our business.
  • Our insurers.
  • The police, HMRC, and other crime prevention and detection agencies.

International Data Transfers

For your security, 2plan has made the conscious decision to only manage, host, and process personal information in the UK.

There are a small number of instances where your personal information may be transferred to countries outside the UK and part of the European Economic Area ("EEA"), such as when we transfer information to our other companies in the 2plan group or to third party suppliers who are based in the EEA or when third parties who act on our behalf transfer your personal information to countries part of the EEA.

Marketing

We may use your personal information to provide you with information about our products or services which may be of interest to you, if you have provided your consent for us to do so.

If you wish to opt out of marketing, you may do so by clicking on the "unsubscribe" link that appears in all emails that are sent by your Partner or by telling us when we contact you. Otherwise, you can always contact us using the details set out in the section How to Contact Us to update your contact preferences.

Please note that, even if you opt out of receiving marketing messages, you may still receive communications from your Partner in connection with the products we offer you.

Third-party Links

We have a website that provides the public with information on our company and the services we provide, as well as other sites that facilitate transactions, either through financial advice or execution only business.

2plan is not responsible for any information provided by any other source once you leave our website. Any links from our website to other websites are provided merely for your convenience and do not imply our endorsement of the content or the provider. If you follow a link to any of these websites, you do so at your own risk, and we do not accept any responsibility or liability for the content of such websites.

By using our website or by registering for any of the products and services we offer through it, you are confirming to us that you understand and accept that your personal information may be used by us in the manner described below. We may keep details of your visits to our website, including, but not limited to, traffic data, location data, and web logs.

If your visit also includes your registration for one or more of our products or services, you may unsubscribe from them at any time.

How we secure your personal data

In accordance with our internal policies, we are committed to protecting any personal data divulged to us. We have implemented appropriate security measures, technologies, and procedures in order to protect your personal data from loss, misuse, alteration, or destruction. Our management team, employees, and partners are required to keep personal data confidential.

Unfortunately, the transmission of information via the internet (by way of email or other means) is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our websites; any transmission is at your own risk. Once we have received your information, we will use internal procedures and security features to prevent unauthorised access.

Where we have given you (or where you have chosen) a password that enables you to access certain parts of our websites or services, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.

Data retention information

The duration for which we retain your personal data will vary depending on the type of personal data and our reason for collection and processing.

We will retain your personal data for legitimate business purposes or for legal purposes. We will not hold information for a period longer than is reasonably necessary to fulfil the purposes for which it was collected, unless prescribed by law. If you would like further information about our retention periods, please contact us using the contact details below.

When deciding how long to retain your personal information, we take into account our legal and regulatory obligations, the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information described above, and whether we can achieve those purposes through other means. We may also retain your personal information to investigate or defend against potential legal claims in accordance with the limitation periods of countries where legal action may be brought.

Your rights

As an individual, you may have the following rights in regard to the protection of your personal data, which you may exercise. If you wish to request to exercise any of these rights, please contact us using the contact details below.

  • Right to be Informed of how we process your data (as set out in this Privacy Policy).
  • Right of Access – You have the right to access your personal data and supplementary information.
  • Right of Rectification – You have the right to have personal data rectified if it is inaccurate or incomplete.
  • Right to Erasure – You have the right to have your personal information deleted where there is no compelling reason for its continued processing.
  • Right to Restrict Processing – You have the right to block or suppress the processing of your personal data. This means that 2plan is permitted to store the personal data it holds but not further process it.
  • Right to Data Portability – You have the right to move, copy, or easily transfer your personal data from one IT environment to another in a safe and secure way, without hindrance to usability. In this event 2plan will provide your personal data to you in a structured, commonly used, and machine-readable form.
  • Right to Object – You have the right to object to the processing of your personal data:
    • based on legitimate interests or the performance of a task in the public interest or the exercise of official duty.
    • for direct marketing.
    • for the purpose of scientific and historical research and statistics.
  • Rights in Relation to Automated Decision Making and Profiling – We may use automated decisioning based on the information that you provide. You have the right to request that any such automated decision be reviewed by an individual within 2plan.
  • Right to Withdraw Consent (if you have given us your consent to use your personal data).

Some of these rights only apply in certain circumstances, so we may not be able to fulfil every request, and we reserve all of our rights available to us at law in this regard. Where a request is made, we may request certain confirmation that you are authorised to exercise this request or ask for proof of your identity before responding to your request.

How to contact us

If you have comments or any questions about our Privacy Policy or our Cookie Policy, please contact us by email at data.protection@2plan.com or by post:

The Data Protection Officer
2plan wealth management ltd
3rd floor Bridgewater Place
Water Lane
Leeds
LS11 5BZ

We regularly review our policies, and any changes will be posted on our website.

If you have comments or any questions about our GDPR, Privacy & Cookies Policy please contact: data.protection@2plan.com

Your right to complain

If you are unhappy about how we have handled your personal information, you can make a complaint to our data protection officer here, who will investigate the matter and report back to you.

If you are still not satisfied with our response or believe we are not using your personal information in line with the law, you have the right to complain to the Information Commissioner, the regulator in the UK. You can find details of how to contact them on their website at https://ico.org.uk/.

Changes to this Privacy Notice

We may update this Privacy Policy, at any time we deem appropriate. It is important that you check this Privacy Policy from time to time to ensure that you have reviewed the most current version of this notice.