Privacy Notice
1. Who this notice covers
This notice explains how Friam Ltd ("Friam", "we", "us"), the provider of FirmGuard Verify, handles personal data. It covers two kinds of data: your firm's account data, and the client data your firm submits for checks.
2. What we hold
| Category | What it is | Retention |
|---|---|---|
| Account data | Firm and user details — name, email, role, billing contact. | For the life of the account, plus standard accounting retention after closure. |
| Client-check data | The client's identity document image, biometric (selfie) match result, and sanctions/PEP screening outcome for each check your firm runs. | 5 years under a compliance retention lock, consistent with the record-keeping duty in the Money Laundering Regulations 2017 (regulation 40). |
3. Who is the controller
For client-check data, your firm is the data controller and Friam is the data processor, acting on your firm's instructions to run the check and hold the record. For account data (your firm's own users and billing details), Friam is the controller.
4. Why we process it
Client-check data is processed to carry out the identity verification and sanctions/PEP screening your firm requests, and to keep the dated evidence record your firm needs to meet its own AML obligations. Account data is processed to run the account, bill for the Service, and provide support.
5. Subprocessors
We use a small number of specialist subprocessors to run the Service:
- Amazon Web Services (AWS) — hosting and secure storage of documents and records.
- Stripe — payment processing for subscriptions.
- Twilio — SMS delivery where used in the verification flow.
- Resend — transactional and account email delivery.
Each subprocessor is bound by a data-processing agreement and only processes data as needed to provide its function.
6. Your rights
Under UK GDPR, an individual whose data we hold has the right to request access, correction, erasure, or restriction of that data, and to object to certain processing — subject to our record-keeping obligations under the Money Laundering Regulations 2017, which can lawfully limit early deletion of a check record. Where your firm is the controller for client data, a client's request should generally go to your firm first; we support your firm in responding.
You can complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk.
7. Contact
Questions about this notice, or to make a data-rights request: hello@firmguard.uk.