Mercurae Privacy Policy

MERCURAE PRIVACY POLICY

Last updated: 13 July 2026

Introduction

Welcome to Mercurae Limited's privacy policy, and thank you for using our website, mercurae.com (the “Site”).

Mercurae Limited (“Mercurae”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data. This privacy policy explains how we look after your personal data when you visit our Site (regardless of where you visit it from) or otherwise interact with us, and tells you about your privacy rights and how the law protects you.

This policy is issued under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018. Where we offer services to, or monitor the behaviour of, individuals in the European Economic Area, the EU General Data Protection Regulation may also apply to that processing. Your rights, which you can exercise free of charge, are set out in section 10, and the Glossary at section 12 explains some of the terms used in this policy.

Questions or comments may be addressed to enquiry@mercurae.com or to Mercurae Limited, 2nd Floor, 10 Rathbone Place, London W1T 1HP.

1. Important information and who we are

Purpose of this privacy policy

This privacy policy gives you information on how Mercurae collects and processes your personal data through your use of the Site, including any data you may provide through the Site, and when you contact us or instruct us as a client or prospective client.

The Site is not intended for persons under 18 years old and we do not knowingly collect data relating to children.

It is important that you read this privacy policy together with any other privacy or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you, so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and is not intended to override them.

Controller

Mercurae Limited, a company registered in England and Wales under company number 12780967 with its registered office at 2nd Floor, 10 Rathbone Place, London W1T 1HP, is the controller and is responsible for your personal data.

You have the right to make a complaint at any time to the Information Commissioner's Office (“ICO”), the UK supervisory authority for data protection issues (ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance (see section 11).

Changes to this privacy policy and your duty to inform us of changes

We keep this privacy policy under regular review. We will update the “Last updated” date at the top of this policy when changes are made.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

Third-party links

The Site may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Site, we encourage you to read the privacy policy of every website you visit.

2. The data we collect about you

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:

(a) “Identity Data”: your name and, for clients and prospective clients, information collected for client onboarding, including know-your-client and anti-money-laundering (KYC/AML) information;

(b) “Contact Data”: your email address, postal address, telephone number and organisation;

(c) “Client Data”: information provided in connection with instructions or prospective instructions, which may include personal data relating to you or to third parties;

(d) “Technical Data”: your internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Site; and

(e) “Usage Data”: information about how you use our Site, including page views and routes taken through the Site.

We also collect, use and share “Aggregated Data”, such as statistical or demographic data, for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law, as it does not directly or indirectly reveal your identity. For example, we may aggregate Usage Data to calculate the percentage of users accessing a specific Site feature. If we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data, which will be used in accordance with this privacy policy.

We do not collect any Special Categories of Personal Data about you through the Site (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data), nor any information about criminal convictions and offences. If such data is relevant to a matter on which we are instructed, it will be handled under the terms of our engagement and any specific notice we provide at the time.

If you fail to provide personal data

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide services to you or your organisation). In this case, we may have to decline to act or cease acting, but we will notify you if this is the case at the time.

3. How is your personal data collected?

We use different methods to collect data from and about you, including through:

(a) Direct interactions. You may give us your Identity, Contact and Client Data by filling in forms on the Site, or by corresponding with us by post, telephone, email or otherwise, including when you enquire about or apply for our services, request updates or marketing, or give us feedback or contact us.

(b) Automated technologies or interactions. As you interact with our Site, we automatically collect Technical Data and Usage Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies (see section 5).

(c) Third parties or publicly available sources. We may receive Technical Data from analytics providers, and Identity and Contact Data from publicly available sources (such as Companies House) or from third parties such as referrers and KYC/AML screening providers.

4. How we use your personal data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

(a) where we need to perform a contract we are about to enter into or have entered into with you;

(b) where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;

(c) where we need to comply with a legal obligation; and

(d) where you have given consent, for example to analytics cookies. You may withdraw consent at any time by contacting us at enquiry@mercurae.com.

Please see the Glossary at section 12 for more detail on these lawful bases. We do not rely on vital interests or the performance of a public task as a basis for processing.

We have set out below the purposes for which we use your personal data and the lawful bases we rely on. We may process your personal data on more than one lawful basis, depending on the specific purpose for which we are using it. Please contact us if you would like details of the specific basis we are relying on in any particular case.

Purpose or activity

Type of data

Lawful basis

To respond to an enquiry made through the Site or by email

Identity, Contact

Legitimate interests (responding to enquiries and developing our business); taking steps at your request before entering into a contract

To onboard you or your organisation as a client, including KYC/AML checks

Identity, Contact, Client

Performance of a contract; compliance with a legal obligation; legitimate interests (managing risk)

To provide our services and manage our relationship with you, including notifying you of changes to our terms or this policy

Identity, Contact, Client

Performance of a contract; compliance with a legal obligation; legitimate interests (keeping our records up to date)

To administer and protect our business and the Site, including troubleshooting, system maintenance, security and fraud prevention

Identity, Contact, Technical

Legitimate interests (running our business, network and information security); compliance with a legal obligation

To analyse how visitors use the Site, so that we can improve it

Technical, Usage

Consent (analytics cookies); legitimate interests (improving our Site and services)

To send you updates and information about our services that may be of interest

Identity, Contact

Legitimate interests (promoting our business to clients, referrers and business contacts) or consent where required; you may opt out at any time

Marketing

We may send you updates and marketing communications where permitted by law. You can ask us to stop sending these at any time by contacting enquiry@mercurae.com or by using the opt-out link in any communication.

Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to receive an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

5. Cookies

The Site uses cookies and similar technologies. Cookies are small text files placed on your device when you visit a website.

(a) Essential cookies are necessary for the Site to function, for example to remember your cookie preferences and to maintain security. These do not require your consent.

(b) Analytics cookies help us understand how visitors use the Site, for example which pages are visited most often, so that we can improve it. These are set only with your consent, which you can give or withdraw through the cookie banner on the Site.

You can also block or delete cookies through your browser settings, although parts of the Site may not function properly if you block essential cookies.

6. Disclosures of your personal data

We may share your personal data with the third parties described in the Glossary at section 12 for the purposes set out in section 4.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes, and we only permit them to process your personal data for specified purposes and in accordance with our instructions.

7. International transfers

Your personal data is stored primarily in the United Kingdom and the European Economic Area. Some of our service providers, including website hosting and analytics providers, may process personal data outside the UK and the EEA.

Whenever we transfer your personal data out of the UK, we ensure that a similar degree of protection is afforded to it by using at least one of the following safeguards: the transfer is to a country that the UK has determined provides an adequate level of protection for personal data; or we use specific contractual safeguards approved for use in the UK, such as the International Data Transfer Agreement or the UK Addendum to the European Commission's Standard Contractual Clauses. Please contact us if you would like further information about the specific safeguards we use.

8. Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach, and we will notify you and any applicable regulator of a breach where we are legally required to do so.

9. Data retention

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint, or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

In some circumstances you can ask us to delete your data (see section 10). In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

10. Your legal rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data:

(a) Request access to your personal data. You have the right to ask us for copies of your personal information.

(b) Request correction of your personal data. You have the right to ask us to rectify personal information you think is inaccurate, and to complete information you think is incomplete.

(c) Request erasure of your personal data. You have the right to ask us to erase your personal information in certain circumstances.

(d) Object to processing of your personal data. You have the right to object to the processing of your personal information in certain circumstances, including where we are relying on legitimate interests and, in all cases, where your data is processed for direct marketing.

(e) Request restriction of processing of your personal data. You have the right to ask us to restrict the processing of your personal information in certain circumstances.

(f) Request transfer of your personal data. You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.

(g) Withdraw consent. Where we are relying on consent to process your personal data, you may withdraw that consent at any time. This does not affect the lawfulness of any processing carried out before you withdraw consent.

If you wish to exercise any of these rights, please contact us at enquiry@mercurae.com or at Mercurae Limited, 2nd Floor, 10 Rathbone Place, London W1T 1HP.

No fee usually required

You will not have to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee, or refuse to comply with your request, if your request is clearly unfounded, repetitive or excessive.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data or to exercise any of your other rights. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask for further information in relation to your request, to speed up our response.

Time limit to respond

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month, if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

11. How to complain

If you have any concerns about our use of your personal information, please contact us at enquiry@mercurae.com and we will do our best to resolve them.

You can also complain to the ICO if you are unhappy with how we have used your data: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; helpline 0303 123 1113; ico.org.uk.

12. Glossary

Lawful bases

“Legitimate interests” means the interest of our business in conducting and managing our business, to enable us to give you the best service and the most secure experience. We consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you, unless we have your consent or are otherwise required or permitted to by law. You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.

“Performance of a contract” means processing your data where it is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into such a contract.

“Compliance with a legal obligation” means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to, such as anti-money-laundering legislation.

“Consent” means processing your personal data where you have given us clear, specific consent to do so, which you may withdraw at any time.

Third parties

Third parties with whom we may share personal data include: service providers who provide IT, website hosting, analytics and system administration services; professional advisers, including lawyers, bankers, auditors and insurers, who provide consultancy, banking, legal, insurance and accounting services; and HM Revenue & Customs, regulators and other authorities who require reporting of processing activities in certain circumstances.