Privacy Policy
Hedosophia Services Limited
Registered Office: Yalding House, 152 Great Portland Street, London, W1W 6AJ
Registered: England and Wales
Registration Number: 09369134
Hedosophia Services Limited (“we”, “us”, “our”) are committed to protecting and respecting your privacy.
This policy (together with our terms of use and any other documents referred to in it) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it. By visiting www.hedosophia.com (“our site”) you are accepting and consenting to the practices described in this policy. You can withdraw such consent at any time.
For the purpose of the Data Protection Act 2018 (“the Act”) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “General Data Protection Regulation” or “GDPR”), the data processer and controller is Hedosophia Services Limited of 152 Great Portland Street, London, W1W 6AJ.
As used in this policy, the term “Regulations” shall include, together, the Act and the General Data Protection Regulation, each of them, as from time to time applicable, amended, restated or supplemented.
1. INFORMATION WE MAY COLLECT FROM YOU
1.1 Information we may collect about you
-
technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform; and
-
information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from our site (including date and time); services you viewed or searched for; page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page and any phone number used to call our customer service number.
1.2 Information we may receive from other sources
We may also work closely with third parties (including, for example, business partners, sub-contractors, analytics providers, search information providers) and may receive information about you from them.
2. USES MADE AND PROCESSING OF THE INFORMATION
We may use information held about you (information we collect about you and information we receive from other sources) in the following ways:
2.1 Information we may collect about you
We may process information that we collect about you:
-
to administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
-
to improve our site to ensure that content is presented in the most effective manner for you and for your computer;
-
as part of our efforts to keep our site safe and/or secure;
-
to collect broad demographic information for aggregate use; and
-
in co-operation with your internet provider, to identify you if we feel it is necessary to enforce compliance with our terms or use or to protect our service, site, users or others.
The legal basis for this processing is our legitimate interests and business and, the proper administration of our website and business.
2.2 Information we may receive from other sources
We may combine information that we receive about you from other sources and information we collect about you. We may use this information and the combined information for the purposes set out above (depending on the types of information we receive).
3. WHERE WE STORE YOUR PERSONAL DATA
The data that we may collect from you may be stored physically or transferred to, and stored on a cloud base service, that may be a destination outside the European Economic Area (“EEA”). By submitting your data, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy and in compliance with the Regulations.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk.
We cannot prevent the use (or misuse) of such personal data by others.
Privacy Notice
1. Introduction
This Privacy Notice explains how Gravity Group Limited and its associated entities (together, “Gravity Group”, “we”, “us”, or “our”) collect, use, store, share, and protect personal data, and explains your rights under applicable data protection laws. It is structured by category of Data Subject to make it easier to identify how we process your Personal Data depending on our relationship with you.
We are committed to complying with all applicable laws (the "Relevant Data Protection Laws"), including:
-
Regulation (EU) 2016/679 General Data Protection Regulation ("GDPR"),
-
Data Protection (Bailiwick of Guernsey) Law, 2017,
-
Data Protection (Jersey) Law 2018,
-
UK General Data Protection Regulation ("UK GDPR"),
-
UK Data Protection Act 2018,
-
South Africa’s Protection of Personal Information Act, 2013 ("POPIA"), and
-
Luxembourg Data Protection Act of 1 August 2018, as enforced by the Commission Nationale pour la Protection des Données ("CNPD").
Because of the broad definition of "Processing", we will in many cases need to start Processing Personal Data about you before you or an entity with which you are associated or otherwise connected, become(s) a client, employee, supplier or formal relationship. Therefore, where the context allows, references in this Privacy Notice to "clients", “employee”, "suppliers", and others are to be read as including references to potential clients, suppliers, and so on, even if you or they never actually become(s) a "client", “employee” or a "supplier" and so on.
This notice applies where Gravity Group acts as a Data Controller. Where we act as a Data Processor on behalf of a client, the client’s privacy notice and/or relevant contractual terms apply.
2. Key Definitions
“Data Subject” means an identified or identifiable individual who is the subject of Personal Data.
“Data Controller” means the entity which determines the purposes and means of the processing of personal data. For the purposes of this Privacy Notice, Gravity Group acts as a data controller where it decides how and why personal data is processed.
“Data Processor” means an entity which processes personal data on behalf of a data controller and in accordance with the controller’s documented instructions.
“Personal Data” means any information relating to an identified or identifiable natural person.
“Processing” means any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
“Sub-Processor” means a data processor engaged by another Data Processor to carry out specific Processing activities on behalf of the original Data Controller.
“Special Category Personal Data” includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health data, or data concerning sex life or sexual orientation.
3. Categories of Data Subjects covered by this Privacy Notice
This notice applies to the following categories of individuals:
-
Employees, officers, contractors; and applicants;
-
Clients and individuals associated with clients;
-
Suppliers, Service Providers, and other Business Contacts or Relationships; and
-
Enquirers, website visitors, social media users and marketing contacts.
Each category is addressed separately below.
4. Employees, officers, contractors; and applicants
4.1. Who this applies to
This section applies if you:
-
Are a current, prospective or previous employee, officer, contractor, or intern (paid or unpaid); or
-
Are an employee, contractor, sub-contractor or intern (paid or unpaid) of a current, prospective or previous supplier or service provider of Gravity Group, and you are providing outsourced services to us as a result of their relationship or agreement with us using our systems.
4.2. Personal Data We Collect
We may collect personal data directly from you and, where lawful, from third parties such as recruiters, referrers, referees, suppliers, service providers, or public authorities.
Categories include:
-
Identification and contact details
-
Emergency contact and family or dependent details
-
Education, qualifications, and employment history
-
Employment and contractual details (job title, start/end dates, performance reviews)
-
Payroll, benefits, tax, and social security information
-
Leave, absence, and working-time records
-
Health information and workplace adjustments
-
Equal opportunity monitoring data
4.3. Purposes and Legal Bases
We process this data to:
-
Recruit and assess candidates
-
Manage and monitor employee, officer, intern, contractor and sub-contractor relationships
-
Meet legal and regulatory obligations
-
Operate payroll and benefits
-
Ensure workplace health and safety
Legal bases include contractual necessity, legal obligation, legitimate interests, and explicit consent (where required for Special Category Data).
4.4. Retention
Applicant data is retained for up to 6 months following an unsuccessful application, unless you request longer retention. Employee data is retained in accordance with our Record Retention Policy and applicable employment and regulatory requirements.
5. Clients and Client-Related Individuals
5.1. Who this applies to
This section applies if you:
-
Are a current, prospective or previous individual client;
-
Are associated with a current, prospective or previous corporate client (e.g. director, officer, employee, contractor); or
-
Are a beneficial owner, investor, settlor, trustee, protector, or beneficiary of a current prospective or previous client,
5.2. Personal Data We Collect
We may collect personal data directly from you and your agents and, where lawful, from third parties such as clients, clients’ agents or other service providers, previous service providers, suppliers, business partners, referees or public authorities, including:
-
Identification and contact details
-
Due diligence, regulatory and compliance information (including Anti-Money Laundering (“AML”) and Know-your-customer (“KYC”) data)
-
Tax residency and tax identification information
-
Source of wealth and source of funds information
-
Professional and employment details
-
Records of correspondence and communications
-
Special Category Data and criminal offence data
5.3. Purposes and Legal Bases
We process this data to:
-
Propose, negotiate and contract for services
-
Provide, monitor and manage services
-
Conduct due diligence, risk assessments, governance activities and regulatory checks
-
Perform automated screening and monitoring, including AML, Countering the Financing of Terrorism (“CFT”), sanctions, Politically Exposes Person (“PEP”) and adverse media screening using third-party compliance platforms. Screening may be conducted both during onboarding and on an ongoing basis to meet continuing regulatory obligations.
-
Comply with legal and regulatory obligations
-
Manage and monitor client relationships and billing
-
Improve services and internal operations
Legal bases include legal obligation (in particular AML/CTF requirements), contractual necessity, legitimate interests, and explicit consent (where required for special category data).
6. Suppliers, Service Providers, and other Business Contacts or Relationships
6.1. Who this applies to
This section applies if you:
-
Are an individual supplier, service provider, vendor, business relationship or business partner, including prospective suppliers, vendors or business partners; or
-
Are associated with a prospective or current supplier, service provider, vendor, business relationship or business partner (e.g. director, officer, employee, contractor, beneficial owner, investor, settlor, trustee, protector, or beneficiary).
6.2. Personal Data We Collect
We may collect personal data directly from you and your agents and, where lawful, from third parties such as suppliers, prospective clients, clients, client’s agents or other service providers, business partners, referrers, referees, or public authorities, including:
-
Identification and contact details
-
Due diligence, regulatory and compliance information (including Anti-Money Laundering (“AML”) and Know-your-customer (“KYC”) data)
-
Tax residency and tax identification information
-
Professional, business and employment details
-
Education, qualifications, and employment history
-
Records of correspondence and communications
-
Payment and invoicing details
6.3. Purposes and Legal Bases
We process this data to:
-
Engage, monitor and manage suppliers and service providers
-
Perform initial and ongoing due diligence, including background and compliance checks
-
Support compliance, risk management, risk assessment, compliance and governance activities
-
Obtain professional advice and services
-
Process payments
-
Meet legal and regulatory obligations
Legal bases include contractual necessity, legal obligation, and legitimate interests.
7. Enquirers, Website Visitors, Social Media Users and Marketing Contacts
7.1. Enquiries and Communications
If you contact us, we will process the personal data you provide to respond to your enquiry and manage our relationship.
7.2. Website Data and Cookies
When you visit our website, we may automatically collect technical data such as IP address, browser type, device information, and usage data. For further information, please refer to our Cookie Policy.
7.3. Social Media
When you visit our social media, we may automatically collect technical and other personal data such as contact and identification details, IP address, general location information, browser type, device information, and usage data. This is used for marketing and/or recruitment purposes with legitimate interest as a legal basis.
For further information about communication via social media please see 7.1 Communications above.
7.4. Marketing Communications
We may send marketing communications where:
-
You have given consent; or
-
We have a legitimate interest and are permitted to do so by law.
You may opt out at any time using the unsubscribe mechanism or by contacting us. Even if you withdraw consent or object to receiving marketing, we may continue to process your Personal Data where necessary for the provision of our services or compliance with legal or contractual obligations.
8. Children’s Personal Data
Gravity Group does not offer services directly to children and does not intentionally collect Personal Data from children for the purpose of marketing or providing services to them.
However, in the course of our activities, we may process limited Personal Data relating to children where this is necessary and lawful, including:
-
where children are listed as dependants or beneficiaries for the purposes of employee benefits, emergency contacts, or employment-related administration; and
-
where children are beneficiaries or related parties in connection with services provided to our clients, including for regulatory, compliance, governance, tax, or fiduciary purposes.
Such Personal Data is typically provided to us by a parent, guardian, client, or authorised representative, and is processed only to the extent necessary for the relevant purpose. We apply appropriate safeguards to protect children’s Personal Data and do not use it for specific marketing or profiling purposes.
9. Sharing your Personal Data
We may share Personal Data with:
-
Other Gravity Group entities
-
Trusted Sub-Processors, service providers and advisers
-
Regulators, tax authorities, courts, and law enforcement
Where we act as a Data Processor, Personal Data is shared only in accordance with the relevant client agreement and our documented instructions.
All recipients are required to implement appropriate confidentiality and security measures.
10. International Transfers
Where Personal Data is transferred outside your jurisdiction, we use appropriate safeguards, including:
-
Standard Contractual Clauses (“SCCs”)
-
UK International Data Transfer Agreement (“IDTA”)
-
Binding Corporate Rules (“BCRs”)
11. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. Access is restricted on a need-to-know basis.
As complete data security cannot be guaranteed for communication via e-mails, instant messaging, and similar means of communication, we would recommend sending any particularly confidential information by an alternative secure means.
We may use secure authentication mechanisms, including device-based biometric features (such as fingerprint or facial recognition), to control access to our systems. Where such biometric features are used, biometric data is processed locally on the user’s device and is not accessed, stored, or processed by Gravity Group.
12. Data Retention
We retain Personal Data only for as long as necessary for the purposes for which it was collected, including compliance with legal, regulatory, and contractual obligations. In most cases, this will be for a period of up to 10 years following the end of the relevant relationship, unless a longer retention period is required or permitted by law.
13. Automated Decision-Making and Profiling
We may use automated tools and systems to support compliance screening, risk assessment, and monitoring activities, including automated checks against sanctions lists, PEP databases, and adverse media sources.
No decision producing legal or similarly significant effects concerning you is taken solely on the basis of automated processing. All such outcomes are subject to appropriate human review.
Where required under applicable law, we will inform individuals when Artificial Intelligence (“AI”) supported systems are used in a manner that is not obvious from the context.
These processes may involve profiling. Where required by law, you have the right to:
-
Request meaningful information about the logic involved
-
Request human intervention
-
Express your point of view
-
Contest a decision
14. Your Rights as Data Subjects
Depending on your location, you may have the right to:
-
Access your Personal Data
-
Request rectification or erasure
-
Restrict or object to processing
-
Data portability
-
Withdraw consent
-
Object to direct marketing
-
Not be subject to certain automated decision-making
In some cases, providing Personal Data is a legal or contractual requirement. If you do not provide such data, we or our client may be unable to enter into or perform a contract with you or an entity with which you are associated.
Requests may be made by contacting us using the details below.
15. EU and UK Representatives
Where required under Relevant Data Protection Laws, Gravity Group has appointed representatives within the European Union and the United Kingdom for the purposes of Article 27 GDPR / UK GDPR. Details of the relevant representative will be made available upon request.
16. Contact Details and Complaints
Privacy Officer
Gravity Group
3rd Floor, Weighbridge House
Lower Pollet, St Peter Port
Guernsey, GY1 1WL
Email: privacy@gravity-group.com
You also have the right to lodge a complaint with your local supervisory authority, including:
-
EU: European Data Protection Board – list of national supervisory authorities (https://www.edpb.europa.eu/about-edpb/about-edpb/members_en) edpb.europa.eu
-
UK: Information Commissioner’s Office (https://ico.org.uk)
-
Guernsey: Office of the Data Protection Authority (https://www.odpa.gg)
-
Jersey: Jersey Office of the Information Commissioner (https://jerseyoic.org/) jerseyoic.org
-
Luxembourg: Commission nationale pour la protection des données (https://cnpd.public.lu)
-
South Africa: Information Regulator (https://www.justice.gov.za/inforeg/)
17. Updates to this Privacy Notice
We may update this Privacy Notice from time to time. The latest version will always be available on our website, and the revision date will be shown below.
This Privacy Notice was last updated in June 2026.
