PEVestIQ
Draft under legal review. This policy is published so you can always see how your data is handled, but it has not yet completed independent solicitor review. It will be replaced by the reviewed version, and any material changes will be flagged per its own section 13. Version: PRIVACY-UK-2.0 (draft, pending solicitor review), last synced 2026-08-01.

PEVestIQ Privacy Policy

Document version: PRIVACY-UK-2.0 · Supersedes PRIVACY-UK-1.0 (VestIQ) · Effective date: [DATE] · Jurisdiction: United Kingdom (UK GDPR and Data Protection Act 2018)

DRAFT FOR SOLICITOR REVIEW — NOT YET IN FORCE.

Change record — v2.0 (21 July 2026): product renamed VestIQ → PEVestIQ; service domain vestiq.co.com → pevestiq.co.uk; contact addresses updated to @pevestiq.co.uk. No substantive changes to rights, obligations, or data practices — this version exists solely to reflect the rebrand. The rename does not constitute or replace the outstanding solicitor review.


1. Who we are

In plain English: CTIO101 Limited runs PEVestIQ and is responsible ("data controller") for how your personal data is used, as described here.

CTIO101 Limited, a company registered in England and Wales (company number [●], registered office [●]), trading as "PEVestIQ", is the data controller for personal data processed as described in this policy. The service is provided at pevestiq.co.uk.

Data protection queries: [privacy@pevestiq.co.uk] or in writing to our registered office, marked "Data Protection". (Confirm mailbox and whether a DPO appointment is required — see Open Questions.)

For Benchmark Studio tenants: where a business customer uploads documents containing personal data of its own clients or their employees, PEVestIQ processes that data as processor on the customer's behalf under a Data Processing Addendum; this policy covers processing for which PEVestIQ is controller.

2. What we collect

In plain English: Your account details, the equity information you enter or that's extracted from documents you upload, your consent records, referral activity, and — only if you opt in — the details needed to introduce you to a partner.

Category Examples Source
Account data Name, email, Google sign-in identifier if used, MFA status You, via Clerk
Equity scheme data Company name, scheme type, share counts, strike price, FMV, vesting schedule, leaver terms Entered by you, or extracted (with your review and approval) from documents you upload or paste
Uploaded documents/text Option agreements, CFO letters, emails you paste for analysis You
Payment data (business customers only) Billing contact, invoicing records; card details are handled by Stripe and never stored by PEVestIQ You / Stripe
Consent and audit records Timestamps, disclosure version (e.g. "UK-1.0") for each consent event; delegate action logs Generated by the platform
Delegated-access verification LPA registration details, grant of probate, death certificate, delegate identity The delegate
Referral data Your referral link activity; for referred users, a hashed identifier of the email address for attribution Generated by the platform
Partner-introduction data Name, email, phone, equity value — only for a category you have opted into You
Technical/usage data Log data, device/browser information, security events Generated by the platform

We do not intentionally collect special category data. Do not include health or similar information in documents you upload; if a document contains it incidentally, it is processed only as part of the document you asked us to analyse.

3. Why we use it, and the legal basis for each purpose

In plain English: The core service runs because you signed up for it (contract), not because you ticked a consent box — so there's no "consent toggle" for it; if you object to it, the answer is deleting your account and data. AI document analysis and partner introductions are different: those run only on your specific consent, which you can withdraw at any time.

Purpose What we do Legal basis (UK GDPR)
Core equity analysis Store and process your account and equity scheme data to provide valuation, vesting tracking, modelling and benchmarking to you Art 6(1)(b) — necessary for our contract with you. This processing is not consent-based and has no opt-out toggle. If you object to it, your remedy is erasure of your account and data (section 8), not "withdrawal of consent" — no consent was ever the basis.
AI-assisted document analysis (Smart Intake) Send documents/text you submit to Anthropic's Claude API to extract data points with confidence scores, which you then review and approve Art 6(1)(a) — consent, captured just-in-time on first use, timestamped with the disclosure version in force. Withdrawable at any time in Settings: withdrawal blocks AI extraction (a manual-entry form remains available); data you have already reviewed and accepted is untouched.
Partner introductions Share your name, email, phone and equity value with one matched partner in a category you chose (wealth management, tax advice, private banking, lifestyle, benchmarking data sharing, partner marketing emails) Art 6(1)(a) — consent meeting Art 7 conditions: per category, specific, informed, never bundled, and immediately withdrawable in Settings. Withdrawal stops future sharing in that category.
Billing (business customers) Process subscription payments via Stripe, issue invoices Art 6(1)(b) — contract; Art 6(1)(c) — legal obligation (tax/accounting records)
Security, fraud prevention, referral-programme integrity Authentication, MFA, abuse detection, referral qualification checks (including hashed-email duplicate/self-referral detection), delegate verification Art 6(1)(f) — legitimate interests (protecting the platform, users and the referral programme). (LIA to be documented — see Open Questions.)
Service improvement and support Diagnose issues, respond to support requests, improve features using feedback Art 6(1)(f) — legitimate interests
Legal compliance Retaining records required by law; responding to lawful requests Art 6(1)(c) — legal obligation

Automated decision-making: we do not make decisions producing legal or similarly significant effects about you by solely automated means. AI extraction is suggestion-only: you review and approve every field before anything is saved. Referral qualification uses automated checks, but flagged cases receive human review and outcomes are disputable (Referral Terms, clause 8).

4. The benchmark dataset (anonymised data)

In plain English: Once you approve your scheme data, an anonymised, aggregated version joins our market benchmark. It can't identify you, and it isn't "personal data" any more — so it sits outside your export and deletion rights. The step of anonymising it is itself something we do lawfully.

4.1 Approved equity scheme data is anonymised and aggregated into PEVestIQ's benchmark dataset. Anonymised, aggregated data that can no longer identify any individual is not personal data under UK GDPR.

4.2 The act of anonymising your data is processing we carry out on the basis of Art 6(1)(f) legitimate interests [alternatively Art 6(1)(b) — see Open Questions], applying [describe standard: aggregation thresholds, suppression of small cells, removal of direct/indirect identifiers]. (Solicitor + technical sign-off required on the anonymisation standard against ICO guidance — see Open Questions.)

4.3 The benchmark dataset is the property of CTIO101 Limited and is excluded from data exports and deletion (because it contains no personal data).

5. Who we share data with

In plain English: Trusted service providers who run pieces of the platform — named below — plus, only where you've opted in, a specific matched partner. We don't sell personal data.

Processors (service providers acting on our instructions):

Provider Role Location of processing
Clerk Authentication and account management [US — confirm region/safeguard]
Stripe Payment processing (business customers); PEVestIQ never stores card details [US/UK — confirm entity and safeguard]
Neon Postgres database hosting AWS eu-west-2 (London, UK)
Vercel Application hosting [Confirm regions — see Open Questions]
Resend Transactional email [US — confirm safeguard]
Anthropic AI document processing (Claude API), only when you have consented to Smart Intake US (see section 6)

Recipients acting in their own right:

  • Matched third-party partners — only for a category you have opted into, and only the fields listed in section 2. The specific partner is identified to you at or before the introduction. Once introduced, the partner is an independent controller of what you share with them.
  • Professional advisers, insurers, regulators, courts — where necessary and lawful.
  • A purchaser or successor of our business — with safeguards, and this policy would continue to apply.

We do not sell personal data and do not share it with third parties for their own advertising.

6. International transfers

In plain English: Most of your data lives in a London database. Some providers — including Anthropic, which powers the AI features — process data in the United States. UK law requires a recognised safeguard for that; the specific mechanism for each provider is listed here once confirmed.

6.1 Your equity data at rest is stored in the UK (Neon on AWS eu-west-2, London).

6.2 Some processors process personal data outside the UK, principally in the United States (Anthropic, and potentially Clerk, Vercel, Resend and Stripe entities). Transfers are made only with a UK-recognised safeguard: the UK Extension to the EU–US Data Privacy Framework (where the provider is certified) or the UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, together with any required transfer risk assessment.

6.3 [Per provider, insert the confirmed mechanism. For Anthropic specifically: confirm which Anthropic data-processing terms are in place for your API account — Anthropic's Commercial Terms/DPA, the transfer mechanism it relies on, whether the account is configured for zero data retention or the default retention, and whether inputs are excluded from model training — and reflect the confirmed position here. See Open Questions.]

7. How long we keep data

In plain English: As long as your account is active, plus limited periods afterwards for legal and audit reasons. When you leave, section 8's clean-exit commitments apply.

Data Retention
Account and equity scheme data Life of the account; deleted within 90 days of exit-extract delivery on closure
Uploaded documents submitted for AI extraction [Deleted after extraction is approved/rejected, or retained while the account is active — confirm product behaviour]
Consent and disclosure-version records [6 years] after the relevant consent ends, to evidence compliance
Delegate verification documents (LPA, probate, death certificate) [Duration of delegated access + ● years]
Billing and tax records (business customers) 6 years from the end of the relevant financial year
Referral attribution (hashed identifiers) and payout records [6 years] for fraud-audit and tax purposes
Security logs [12 months]

(All bracketed periods are business decisions to confirm — see Open Questions.)

8. Your rights

In plain English: You can ask for a copy of your data, correct it, delete it, restrict or object to some uses, and take your data elsewhere. Consent-based features (Smart Intake, partner introductions) can be switched off in Settings at any time. For the core service there's no toggle — the equivalent remedy is closing your account, which triggers export and deletion.

Under UK GDPR you have the right to: access your personal data; rectify inaccurate data; erasure; restriction of processing; data portability (your export under the clean-exit commitment is delivered in a portable format within 30 days of account closure, with deletion warranted within 90 days thereafter); and objection to processing based on legitimate interests.

How the rights map onto how PEVestIQ actually works:

  • Smart Intake / partner introductions: withdraw consent instantly in Settings — no request needed.
  • Core equity analysis: this runs on contractual necessity, so there is no consent to withdraw and no opt-out toggle; if you no longer want it, close your account (Settings or by contacting us) and the clean-exit export and deletion commitments apply.
  • Anonymised benchmark contributions: these contain no personal data and are outside the scope of access, portability and erasure.

To exercise any right, use Settings where available or contact [privacy@pevestiq.co.uk]. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity. Exercising rights is free unless a request is manifestly unfounded or excessive.

You may complain to the Information Commissioner's Office (ico.org.uk / 0303 123 1113). We'd appreciate the chance to resolve any concern first.

9. Delegated access and data of deceased users

In plain English: Attorneys and executors can be given verified access. Their actions are logged under their own identity. UK data protection law applies to living people — but we still treat a deceased user's records with care and only release them to a verified personal representative.

Verification documents provided by delegates (LPA, grant of probate, death certificate) are processed to verify authority (legitimate interests / legal claims). Delegate actions are audit-logged under the delegate's identity. UK GDPR rights attach to living individuals; on a user's death, access to the account is provided only to a verified personal representative, and the delegate's own personal data is protected under this policy.

10. Cookies and tracking

In plain English: We use strictly necessary cookies to keep you signed in and secure. Any analytics beyond that will only run with your consent via a banner.

10.1 Strictly necessary cookies (session/authentication via Clerk, security, load balancing) are used without consent, as permitted by PECR.

10.2 [Confirm what analytics/monitoring is actually deployed — e.g. Vercel Analytics, error monitoring. If any non-essential cookies or equivalent technologies (including localStorage-based identifiers) are used, PECR requires prior consent and a banner/settings surface. See Open Questions.]

11. Security

We apply appropriate technical and organisational measures, including encryption in transit and at rest, role-based access control (including a locked-down referrer role), MFA where enforced, audit logging (including per-delegate logging), and UK-region data hosting. No system is perfectly secure; we will notify you and the ICO of personal data breaches where the law requires.

12. Children

PEVestIQ is for adults. We do not knowingly process data of anyone under 18; referrers are prohibited from targeting under-18s.

13. Changes and versioning

Each version of this policy carries a jurisdiction-namespaced version string (this document: PRIVACY-UK-2.0 · Supersedes PRIVACY-UK-1.0 (VestIQ)). Every consent you give is recorded with the version in force at that moment, so the exact disclosure you consented to is always identifiable later. Material changes will be notified by email or in-app notice before they take effect, with a new version string.