Legal

Privacy policy and use of cookies

Last updated
1 September 2026
Data controller
Plug Capital Ltd, company number 16771421
Contact

This policy explains how we collect, store and process personal data in the provision of services to our clients and to users of our website. We take this seriously. If you have questions please ask.

Background

The UK General Data Protection Regulation, or UK GDPR, together with the Data Protection Act 2018, regulates how individuals and organisations may collect, use and retain personal data. It is the UK implementation of the European privacy law that took effect on 25 May 2018, and it remains part of UK law following Brexit. The Information Commissioner's Office, or ICO, is the UK's independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals.

As a firm authorised and regulated by the Financial Conduct Authority, we are also subject to regulatory record keeping, reporting and notification obligations. Those obligations affect what information we are required to obtain, and how long we are required to keep it. Where our data protection duties and our regulatory duties interact, this policy explains how we approach that.

What is considered personal data

Under the UK GDPR, personal data is any information that can reasonably identify a specific living person, either alone or together with other information. This broad definition includes traditional personal data such as dates of birth, names, physical addresses and email addresses, and also location data, biometric data, financial information and more.

We are

Plug Capital Ltd, a company registered in England and Wales. Our company number is 16771421. Our registered office address is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We are authorised and regulated by the Financial Conduct Authority, firm reference number 1048102.

Contact us at hello@plugcapital.co.uk if you have any questions or have any concerns with how we use your data.

What we collect

We may collect, store and use information about you in the course of promoting and providing our services. The information which we collect relates to:

  • your name, job title and role
  • your contact information, including your email address and place of business address
  • our relationship with you
  • information about the fund, management company or business you represent, where that information identifies you
  • correspondence with you and records of the services we have provided

We may obtain further information where we are appointing a firm or an individual as an appointed representative, or where we are making submissions to the FCA or to other UK regulatory authorities. This may include date of birth, nationality, residential address history, employment and regulatory history, professional qualifications and identity documents, together with the information needed to complete fitness and propriety assessments, senior manager and certification applications, and anti money laundering and know your customer checks.

We do not collect and store any special categories of personal data. This includes details about race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic or biometric data.

Our role

We act as the controller of your information where we decide why and how it is used. That is the case for our own client and prospective client relationships, for the regulatory obligations we carry as an authorised firm and as a principal firm, and for our marketing.

Where we provide fractional CFO, fund operations, administration or reporting services and process personal data on behalf of a client, for example investor records held within a fund we service, we act as the processor and our client is the controller. In those cases we process the data on documented instructions under a written agreement, and the controller's own privacy policy will govern that data.

How we collect it

Typically we collect information from you when you contact us, or when you provide data in order for us to provide our services. We collect information when you agree to use our services and when we deliver them, usually by email, through documents you send us, or over the phone. We also collect information through this website where you provide contact information, and where you book a meeting with us through the scheduling link on this site.

We may also receive information about you from third parties, including identity verification and screening providers, the FCA Register, Companies House and publicly available professional sources.

We use data for specific purposes. Where you provide us with consent, for example if you request a call through our website or ask to receive material from us, we rely on that consent.

Where we have a contract to provide services, we collect and use the information necessary to fulfil our services.

Where we are required to obtain, hold or report information as an authorised firm and as a principal firm, including under the Financial Services and Markets Act 2000, the FCA Handbook and the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017, we rely on compliance with a legal obligation.

We may also decide that we have a legitimate interest in processing your data, and we think your interests and fundamental rights do not override those interests. We do this because we genuinely think this is relevant for our business and you would be interested in our services.

How data is processed

Personal data is processed both manually and electronically. We permit only our employees and certain third party processors to have access to your information. These include the providers who host and operate our website, our IT, email and document storage providers, our customer relationship and scheduling tools, our accounting and payment providers, and specialist providers used for identity verification and screening. We have contracts in place and all parties have terms and conditions requiring them to comply with UK data protection law.

We use software that includes artificial intelligence features to support the delivery of our services. We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Where we use these tools we do so on terms which do not permit your personal data to be used to train third party models.

Other agencies such as regulatory bodies and law enforcement may require us to share data we hold in order to comply with the law. This includes the Financial Conduct Authority, HM Revenue and Customs and the National Crime Agency. Where we are required to make a report of that kind, we may be prohibited by law from telling you that we have done so.

How long we keep it

We keep personal data for as long as we need it for the purpose for which it was collected, and for as long as we are required to keep it by law and regulation. In practice, records relating to anti money laundering and customer due diligence are kept for five years from the end of the business relationship or the completion of the transaction, records we are required to keep under FCA rules are kept for the periods those rules specify, and accounting and company records are kept for six years. Where we no longer need to hold data, we delete it or render it anonymous.

Telling you about our services

We can use your personal information to contact you where we consider that we have a legitimate interest to do so. As required by law, and because it is good practice, we assess this and make a judgement about our interests and whether it is appropriate to use your data in this way. As set out below, you can tell us to stop doing this at any time.

Transfers outside the UK

Some of the providers we use store or process data outside the United Kingdom. Where that happens, we make sure the transfer is covered by an adequacy decision, by the International Data Transfer Agreement or the UK Addendum to the European Commission standard contractual clauses, or by another lawful safeguard.

Other websites

Our website may contain links to other websites, including those of our partners and our scheduling provider. This policy only applies to our website. You should read the privacy policies of other websites to understand how they comply with the law.

Protecting your data

We have put in place appropriate security measures, policies and procedures to protect your personal data from unlawful or unauthorised processing and from accidental loss, destruction or damage.

Your rights and exercising those rights

Where processing of your personal data is based on consent, you have the right to withdraw your consent at any time. If you do withdraw your consent we will stop processing your personal data, unless there is another lawful basis we can rely on, in which case we will let you know.

Where processing of your personal data is based on our legitimate interests, you can object to this at any time.

Depending on the circumstances you may have the right to:

  • access your personal data and to be provided with certain information in relation to it, such as the purpose for which it is processed, the recipients or categories of recipient to whom it is disclosed and the period for which it will be stored
  • require us to correct any inaccuracies in your personal data without undue delay
  • require us to erase your personal data
  • require us to restrict processing of your personal data
  • receive the personal data which you have provided to us, in a machine readable format, where we are processing it on the basis of your consent or because it is necessary for your contract with us, and where the processing is automated
  • object to a decision that we make which is based solely on automated processing of your personal data

Some of these rights are qualified where we are required to retain information in order to meet a legal or regulatory obligation. Contact us at hello@plugcapital.co.uk if you would like to exercise these rights or have any concerns.

Cookies and similar technologies

A cookie, or a similar technology, is a text file containing small amounts of information that may be stored on your computer or mobile device, known as terminal equipment. For example, such technologies can be used by websites to:

  • identify visitors
  • enable the website to function efficiently
  • personalise content
  • permit online behavioural target advertising

Similar technologies include pixels, tags, local storage and device fingerprinting.

We only use necessary cookies, because they allow visitors to navigate and use key features on this site. Other cookies, such as those collecting IP addresses for analytics, are turned off. We do not currently collect analytical information and we do not use advertising or tracking cookies.

Our website loads typefaces from Google Fonts. When it does so, your browser connects to Google servers and your IP address is visible to Google as part of that request. If you book a meeting with us, the booking is handled by our third party scheduling provider on its own website and under its own privacy policy.

Complaints

If you are unhappy with how we have handled your personal data, please contact us first so that we can try to put it right. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113, or at ico.org.uk.

If your complaint relates to the regulated services we provide rather than to your personal data, our complaints procedure is set out in our regulatory disclosures.

Changes to this policy

We keep this policy under review and will update it when our practices change or when the law requires. This version was last updated on 1 September 2026. Questions about it should go to hello@plugcapital.co.uk.