Effective date: 05 December 2025

Whether you visit our website, use our mobile app, speak to one of our team or use our services more widely, you are trusting us with your information. This policy sets out how we collect, use and respect such information, and how the law protects you and your information.

Why this policy exists  
        

This privacy policy explains how we collect and process your information and what rights and options are available to you under applicable privacy laws, including the Data Protection Act 2018, the UK retained version of Regulation (EU) 2016/679 (UK GDPR) and the General Data Protection Regulation (EU) 2016/679 (EU GDPR) and relevant Financial Conduct Authority (FCA) and Information Commissioner’s Office (ICO) guidance.  All references to information in this policy, means any data which identifies a natural person or which allows that person to be identified when combined with other data.

We keep our privacy policy under regular review. The version of the policy became effective on the date shown above.

We are committed to protecting and respecting your privacy. If you have any comments or questions you can contact us by emailing info@cadro.com.

Information we collect about you and how it is used

We collect and process personal data to:

  • deliver our services;
  • operate and improve our app and website;
  • fulfil legal obligations;
  • contact you with relevant updates or marketing; and
  • maintain security and monitor compliance.

We act as a data controller in most instances.

Prospect information

We collect limited data about potential clients (e.g. name, contact details, business or portfolio-related information) either directly from you or via public sources (e.g. LinkedIn), based on our legitimate interest in offering relevant services. Your rights under this policy apply from the time of data collection.

Cadro account registration and access to Cadro services:

If you create an account or use our services, we may collect:

  • Identity verification information (e.g. government ID, nationality, tax residency)
  • Contact information (e.g. name, email, address, phone)
  • Financial and account details (e.g. bank account, national insurance number)

We use this information to perform our contract with you and meet regulatory obligations. Where required, third-party providers may assist with identity verification or data storage — only under strict contractual safeguards.

Information You Provide Voluntarily

You may give us information directly via forms, queries, phone, email or app interactions. This includes updates to personal details, support queries, or feature use. We process this data under our contract with you and our legitimate interest in service delivery.

Information Collected Automatically

When you use our website or app, we automatically collect technical and usage information, including:

  • IP address, browser type/version, device ID, operating system
  • Page visits, session duration, click patterns, scrolling, error reports
  • Interaction with app features and response times

We process this data to understand how our services are used, improve usability, monitor performance, and maintain security. This processing is based on our legitimate interest in maintaining and improving our services. 

Cookies and Similar Technologies

Our website and app use cookies and similar technologies (e.g. local storage, pixel tags) to:

  • distinguish you from other users
  • enhance performance and usability
  • remember your preferences
  • analyse traffic and usage patterns

You can usually disable cookies via your browser settings, but doing so may affect app or website functionality.

Session Recording and Analytics

To improve our services and understand user behaviour, we use analytics tools that include session recording functionality. This applies to:

  • Our Web App 
  • Our iOS Mobile App
  • Our internal Cadro Admin Portal (used by staff)

These tools allow us to:

  • understand how users navigate our apps
  • identify bugs or errors
  • troubleshoot support issues
  • test and improve new features
  • maintain audit trails (for internal admin users)

Recordings may include clicks, navigation flows, or typed inputs (excluding sensitive data like passwords). We do not use session recordings for automated profiling or decision-making.

This processing is based on our legitimate interest in improving and securing our services, and such tools are configured to avoid unnecessary or excessive data capture. Access is strictly limited to authorised personnel and retained only as long as required for analysis or diagnostics.

Who we share your information with and why

We only share your data with third parties where necessary to deliver our services or comply with legal obligations. These include:

  • IT and hosting providers
  • Identity verification partners
  • Providers of analytics or support software (including session recording tools)
  • Regulators, courts or law enforcement (where legally required)

All third-party providers are contractually bound to comply with UK data protection law and act only on our instructions. We do not sell or share your data for others’ marketing purposes.

If we undergo a business restructure, merger, or sale, your data may be transferred to the acquiring party, subject to this privacy policy.

Where we store your information

All personal data is processed and stored within the UK or the European Economic Area (EEA).

Where data is accessed or processed by trusted third parties, they are contractually obliged to meet equivalent UK GDPR standards. We do not transfer your data outside the UK or EEA.

How long we keep your information

We only retain personal data for as long as necessary:

  • to fulfil the purposes for which it was collected
  • to meet legal, regulatory, or reporting requirements
  • to resolve disputes or enforce agreements

Typically, this means retaining your data:

  • while your account is active
  • for up to six years following last contact
  • longer where required by law (e.g. financial records)

We periodically review and securely delete data that is no longer needed.

We may retain anonymised or aggregated data indefinitely for research, business intelligence, or product development.

Your rights

You have the following rights under UK data protection law:

  • Access: to see what personal data we hold about you
  • Correction: to update inaccurate or incomplete data
  • Erasure: to delete your data when no longer needed
  • Restriction: to limit how your data is processed
  • Objection: to certain types of processing (e.g. marketing or profiling)
  • Portability: to obtain and reuse your data across services
  • Withdraw Consent: where processing is based on consent

We may need to confirm your identity before fulfilling your request. We aim to respond within one month.

Marketing and Communications

Where permitted by law or with your consent, we may send you marketing updates about our services. You can opt out at any time:

  • via the unsubscribe link in emails
  • via your account preferences
  • by contacting us at info@cadro.com

Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption, access controls and regular monitoring.

While no system is fully immune to threats, we continuously assess and improve our defences in line with industry best practices and FCA expectations.

How to Contact Us

Questions, comments and requests regarding this privacy policy are welcomed and should be addressed to: info@cadro.com.

Cadro Technologies Limited is registered in England (company number 11797448) and our registered office is Berkeley Square House, Berkeley Square, London W1J 6BD.

You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO): www.ico.org.uk