Privacy Policy
1. Introduction
At Bonsai Wealth Ltd (“Bonsai”, “we”, “our”, “us”), we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our website, app, and services.
This policy applies to all visitors, customers, and users of our services, and has been written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Who We Are
Bonsai Wealth Ltd is registered in England and Wales with company number: [Insert Company Number], and our registered office is:
7 Bell Yard, London, WC2A 2JR
We are registered as a Data Controller with the Information Commissioner’s Office (ICO) under registration number: ZB756711. If you have any questions about this policy, or how we handle your data, you can contact our Data Protection Officer (DPO) at privacy@bonsaiwealth.io.
3. Other Relevant Policies and Terms
This Privacy Policy should be read alongside:
Our Cookie Policy, which explains how we use cookies and similar technologies.
Our Terms & Conditions, which set out your legal relationship with Bonsai when using our services.
4. What Personal Data We Collect
The types of personal data we collect include:
Identity Data – name, date of birth, National Insurance number, and identification documents.
Contact Data – email address, phone number, and residential address.
Financial Data – income, savings, investments, and account details when using our services.
Open Banking Data – transaction history and spending patterns (when you link external accounts).
Technical Data – IP address, browser type, operating system, and login data.
Usage Data – how you use our app, website, and tools.
Marketing Preferences – your preferences for receiving updates, promotions, and financial insights.
In limited cases, we may process special category data (for example, if you disclose health-related financial vulnerability) but only with your explicit consent.
5. How We Collect Your Data
We collect data in several ways:
Directly from you – when you sign up, complete your fact find, or contact us.
Automatically – through cookies, app usage tracking, and device data collection.
From Third Parties – such as open banking providers, credit reference agencies, or fraud prevention services.
6. How We Use Your Data
We use your data to:
Create personalised financial plans through our AI co-pilot.
Provide and manage your investment and savings accounts (through Seccl and Bondsmith).
Comply with legal obligations, including anti-money laundering (AML) checks.
Process payments and transfers.
Monitor and improve our products and services.
Send you relevant communications and educational content.
Deliver personalised marketing (with your consent).
7. Our Legal Bases for Processing
Under UK GDPR, we must have a lawful basis for processing your data. These include:
Performance of Contract – to deliver the services you sign up for.
Legal Obligation – for regulatory compliance, such as AML checks.
Legitimate Interest – to improve our services and provide relevant communications.
Consent – for marketing and processing any special category data.
8. Sharing Your Data
We only share your data when necessary, and always securely, with:
Our regulated partners (e.g., Seccl for investment custody, Bondsmith for cash solutions).
Payment providers and banking partners (for transfers and open banking connections).
Fraud prevention and compliance services (for legal and regulatory checks).
Marketing technology providers (for customer communications, where consented).
Regulators and law enforcement (if legally required).
We do not sell your data to third parties.
9. Data Security
We apply bank-grade security measures to protect your data, including:
Encryption of data at rest and in transit.
Multi-factor authentication for account access.
Regular penetration testing and security audits.
Strict internal access controls, limiting employee access to only what is necessary.
10. International Transfers
If we transfer data outside the UK or EEA (for example, to service providers), we will ensure adequate protection through:
UK Data Adequacy Decisions (where the receiving country has equivalent laws).
Standard Contractual Clauses (SCCs) approved by the ICO.
11. Data Retention
We keep your data for as long as necessary to provide services and meet legal obligations. This typically means:
For as long as you have a Bonsai account.
For 6 years after account closure (to meet regulatory and tax requirements).
In some cases, such as suspected fraud, we may retain data for longer.
12. Your Rights
You have a range of rights under UK GDPR, including:
Right to Access – You can request a copy of the personal data we hold about you.
Right to Rectification – You can ask us to correct incomplete or inaccurate data.
Right to Erasure – In certain circumstances, you can request deletion of your data.
Right to Restrict Processing – You can ask us to suspend processing if you contest accuracy or object to processing.
Right to Data Portability – You can request your data in a machine-readable format.
Right to Object – You can object to direct marketing or processing based on legitimate interests.
Right to Withdraw Consent – You can withdraw consent at any time for marketing communications.
To exercise any of these rights, email us at privacy@bonsaiwealth.io.
13. Cookies & Tracking
For details on how we use cookies and tracking technologies, please see our Cookie Policy.
14. Third-Party Links
Our website and app may contain links to external sites. Bonsai is not responsible for the privacy policies or practices of third-party websites.
15. Changes to this Policy
We may update this policy from time to time. Significant changes will be notified via email or in-app messages. You should check this page periodically to review any updates.
16. Complaints
If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner’s Office (ICO). Contact details:
Website: www.ico.org.uk
Phone: 0303 123 1113
Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the chance to deal with your concerns directly before you approach the ICO—please contact us at privacy@bonsaiwealth.io first.
17. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact our Data Protection Officer at:
Email: privacy@bonsaiwealth.io
Post: Data Protection Officer, Bonsai Wealth Ltd, 7 Bell Yard, London, WC2A 2JR
This Privacy Policy was last updated on 1 March 2025.