Last updated: 10 September 2026
Finvisor Limited ("Finvisor", "we", "us" or "our") is a specialist regulatory compliance consultancy incorporated in Ireland, with its registered office at Owlpen, The Mayne, Clonee, Co. Meath, D15 P656, Ireland. We are the data controller for the personal data described in this notice. This notice explains what personal data we collect through www.finvisor.global and www.finvisor.ie (the "Site") and in the course of our consulting and RegTech business, why we collect it, how long we keep it and the rights you have. It is written to meet the requirements of the General Data Protection Regulation (EU) 2016/679 (GDPR), the Irish Data Protection Acts 1988 to 2018 and, for our United Kingdom activities, the UK GDPR and the Data Protection Act 2018.
1. Who to contact
We have not appointed a statutory Data Protection Officer because our processing does not meet the thresholds in Article 37 GDPR. Responsibility for data protection sits with our Managing Director. For any question, request or complaint about personal data, contact us at info@finvisor.global or by post at the address above, marking your correspondence "Data Protection".
2. The personal data we collect
We collect and process the following categories of personal data.
- Enquiry and contact data. Name, business email address, company, job title, telephone number and the content of your message when you contact us, request a briefing or ask for a maturity assessment through the Site or by email.
- Subscription data. Your email address when you subscribe to receive our regulatory briefings and insights.
- Client and engagement data. Contact details, role information and correspondence relating to the directors, officers, employees and advisers of our clients and prospective clients; and personal data contained in documents our clients provide to us in the course of an engagement (for example board minutes, organisation charts, policies, customer files selected for audit testing and regulatory correspondence).
- Fitness and probity data. Where we support a client's authorisation application or a Pre-Approval Controlled Function or Senior Manager appointment, we may process the CVs, qualifications, employment history, regulatory references and, where lawfully required by the client's regulator, information on criminal convictions or regulatory sanctions of the individuals concerned. We process this only on the client's instructions and only to the extent required by the Central Bank of Ireland, the Financial Conduct Authority, the Bank of Lithuania or another competent authority.
- Recruitment data. Information you provide when you apply to work with us, including your CV, right-to-work documents and references.
- Technical data. IP address (anonymised for analytics), browser type, device type, pages visited and referral source, collected through the cookies described in our Cookie Policy and only where you have consented to analytics.
We do not knowingly collect personal data from anyone under 18, and the Site is not directed at them.
3. Why we process personal data and our lawful bases
- To respond to enquiries and provide our services to clients and prospective clients. Lawful basis: performance of a contract, or steps taken at your request before entering a contract (Article 6(1)(b)); where you are an employee or officer of a client, our legitimate interest in delivering the services the client has engaged us to provide (Article 6(1)(f)).
- To send regulatory briefings and insights you have subscribed to. Lawful basis: your consent (Article 6(1)(a)), which you can withdraw at any time by using the unsubscribe link in any email or by contacting us.
- To support authorisation applications and controlled-function appointments on behalf of clients. Lawful basis: performance of our contract with the client and the client's legal obligations to its regulator (Article 6(1)(c)). Where criminal conviction data is involved, we rely on the client's obligations under the relevant regulatory regime and process the data only as the client's processor or, where we act as controller, under Article 10 GDPR and section 55 of the Data Protection Act 2018.
- To administer our business, including invoicing, accounting, audit, insurance and professional-standards obligations. Lawful basis: legal obligation (Article 6(1)(c)) and legitimate interest (Article 6(1)(f)).
- To improve the Site through anonymised analytics. Lawful basis: consent (Article 6(1)(a)).
- To recruit staff and consultants. Lawful basis: steps taken at your request before entering a contract (Article 6(1)(b)) and legal obligation in relation to right-to-work checks (Article 6(1)(c)).
- To establish, exercise or defend legal claims and to comply with requests from regulators, courts or law-enforcement authorities. Lawful basis: legal obligation and legitimate interest.
Where we rely on legitimate interests we have assessed that those interests are not overridden by your rights and freedoms. You can ask us for a summary of that assessment.
4. Where personal data comes from
Most personal data comes directly from you or from the client that has engaged us. We may also receive personal data from publicly available sources such as company registers, regulatory registers and professional networking sites, and from third parties acting for a client, such as its lawyers or auditors.
5. Who we share personal data with
We share personal data only where necessary and with appropriate safeguards, with:
- Service providers who process data on our behalf under written contracts meeting Article 28 GDPR, including our website host (Webflow Inc.), email and productivity provider, document-management and secure file-transfer providers, analytics provider (Google LLC, only with your consent) and our accountants, IT support and insurers.
- Regulators and competent authorities, including the Central Bank of Ireland, the Financial Conduct Authority and the Bank of Lithuania, where we submit applications or correspondence on a client's behalf and on the client's instructions, or where we are legally required to do so.
- Professional advisers, including our lawyers and auditors, where necessary to obtain advice or to comply with our legal obligations.
- Group companies within the Finvisor group, where necessary to deliver our services.
- A purchaser or investor in the event of a sale, merger or reorganisation of our business, subject to confidentiality obligations.
We do not sell personal data and we do not share it with third parties for their own marketing.
6. International transfers
We operate from Ireland, the United Kingdom and Lithuania. Personal data may be transferred between these locations. Transfers from the EEA to the United Kingdom are covered by the European Commission's adequacy decision for the UK. Where a service provider processes personal data in the United States or another country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), supplemented where appropriate by the UK International Data Transfer Addendum, or on the provider's certification under the EU-US Data Privacy Framework and the UK Extension to it. We carry out transfer risk assessments where required. You can request a copy of the relevant safeguards by contacting us.
7. How long we keep personal data
- Client and engagement records: for the duration of the engagement and for seven years after it ends, reflecting our obligations under the Companies Act 2014, tax legislation and our professional-indemnity insurance requirements. Documents provided by a client for audit or assessment purposes are returned or securely deleted at the end of the engagement unless the client instructs otherwise.
- Enquiries that do not lead to an engagement: 24 months from our last contact with you.
- Subscription data: until you unsubscribe or we cease publishing briefings, after which it is deleted within 30 days.
- Recruitment data: six months after the conclusion of the recruitment process for unsuccessful candidates, unless you agree to a longer period.
- Analytics data: Google Analytics 4 retains event data for 14 months; the cookies themselves expire after two years.
- Legal claims: where a claim is contemplated or in progress, relevant data is retained until the matter is concluded and any limitation period has expired.
8. Security
We apply technical and organisational measures appropriate to the risk, including access controls, multi-factor authentication, encryption in transit and at rest for our core systems, secure file-transfer channels for client documents, staff confidentiality obligations and documented incident-response procedures. Where we identify a personal-data breach likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, notify you without undue delay.
9. Your rights
Subject to the conditions and exemptions in data-protection law, you have the right to:
- be informed about how we use your personal data (this notice);
- access the personal data we hold about you and receive a copy;
- have inaccurate or incomplete data rectified;
- have your data erased where there is no good reason for us to continue processing it;
- restrict our processing in certain circumstances;
- receive the data you provided to us in a structured, machine-readable format and have it transmitted to another controller (portability);
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not carry out such decision-making.
To exercise any right, contact us at info@finvisor.global. We will respond within one month, which may be extended by two further months for complex requests, and we will tell you if that is the case. We may need to verify your identity before acting on a request. There is no fee unless a request is manifestly unfounded or excessive.
10. Complaints
We would welcome the opportunity to resolve any concern directly. You also have the right to lodge a complaint with a supervisory authority. In Ireland this is the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 (www.dataprotection.ie). If you are in the United Kingdom you may complain to the Information Commissioner's Office (ico.org.uk), and if you are in Lithuania to the State Data Protection Inspectorate (vdai.lrv.lt).
11. Changes to this notice
We review this notice at least annually and whenever our processing changes materially. The date at the top of the page shows when it was last updated. Where a change significantly affects you, we will take reasonable steps to bring it to your attention.