Privacy & Cookie Policy

At Torc Wealth, we attach great importance to data security and data protection. As a responsible and reliable partner, we see it as our duty to ensure both the security of data transmission and the completely confidential handling of your personal data.

We require and process your personal data in order to provide you with our website and its functions and to process your inquiries.

In the following, you will find detailed information on how we process your data when you browse our website or send us your data as part of an inquiry.

For the data collection and data processing responsible in the sense of the General Data Protection Regulation is the:

Christopher Everitt

Torc Wealth (Datenschutzbeauftragter)

Your data are always collected, processed and used in compliance with relevant German and European data protection legislation.

Where we use your personal data for a purpose that requires your consent under the law, we will always request your explicit consent. Should you not give your consent, please note that you may be unable to use the service concerned.

If you use our service and/or create a customer account, a contractual relationship arises between you and Torc Wealth according to our terms of use. The legal basis for the processing of your data and the transmission of your data to third parties takes place in principle to perform our contractual obligations or to be able to offer you the desired service.

Privacy and Data Retention Policy

1. Purpose and Legal Framework

This policy sets out how Torc Wealth collects, processes, stores, reviews, anonymises and deletes personal data. It is designed to ensure full compliance with the following legislation:

• EU General Data Protection Regulation
• German Federal Data Protection Act
• German Commercial Code
• German Fiscal Code

The objectives of this policy are to ensure that personal data is processed lawfully, fairly and transparently, that it is not retained longer than necessary, that a lawful basis for processing and storage is documented, that clear retention and deletion schedules are applied, and that regulatory and statutory retention obligations are fulfilled.

This policy also establishes internal controls to reduce regulatory and legal risk exposure.

2. Scope

This policy applies to all personal data processed by Torc Wealth in the course of its financial planning, advisory and insurance intermediation activities.

It applies to personal data relating to:

• Clients
• Former clients
• Prospects
• Dormant prospects
• Introducers
• Marketing contacts

It covers data stored in:

• Customer relationship management systems
• Email systems
• Cloud based document storage
• Financial planning software
• Paper files
• Backup systems

3. Collection and Use of Personal Data

3.1 Visiting the Website

Individuals may visit the Torc Wealth website and obtain information without actively providing personal data.

When a page is accessed, technical connection data transmitted by the user’s internet browser may be processed. This may include the date of access, time spent on a page, browser type, operating system, IP address and the name of the internet service provider. Such data is processed for technical administration, system security and website optimisation purposes and is not combined with other data sources to identify a specific individual unless required for security or legal reasons.

The legal basis for this processing is legitimate interest pursuant to Article 6 paragraph 1 letter f GDPR.

3.2 Registration, Financial Planning and Insurance Applications

Where an individual wishes to obtain advice in relation to financial planning, pensions, investments, loans or insurance products, Torc Wealth must collect and process relevant personal data in order to provide suitable and compliant advice.

If required information is not provided, Torc Wealth may not be able to offer advice or arrange products.

Data collected may include:

• Identification data such as first name and surname
• Contact details including email address and telephone number
• Citizenship and tax residency information
• Confirmation of tax status in Germany
• Occupational status
• Income information
• Years until retirement
• Information regarding co borrowers
• Marital status and number of children
• Details of equity capital and home ownership
• Existing loans and financial commitments
• Property information including location, property type, size, year of construction, purchase price and intended use
• Desired monthly loan payments
• Pension, investment and insurance information

Registration on the website may require provision of an email address and or telephone number to create a secure user account.

The legal basis for processing this data is:

• Article 6 paragraph 1 letter b GDPR for contractual necessity and pre contractual measures
• Article 6 paragraph 1 letter c GDPR for compliance with legal obligations
• Article 6 paragraph 1 letter f GDPR for legitimate interests where applicable
• Article 6 paragraph 1 letter a GDPR where consent is required

Only information that is relevant for advisory suitability, regulatory compliance, underwriting requirements or lender requirements will be requested.

3.3 Processing and Disclosure

Torc Wealth collects, stores and uses personal data to perform contracts, respond to enquiries, provide advisory services, obtain product offers, transmit applications to partner institutions and manage ongoing client relationships.

Personal data may be transmitted to product providers, lenders, insurers, platform providers and other contractual partners where necessary to fulfil advisory or contractual obligations.

Third party service providers engaged for hosting, document storage, IT services or administrative support will receive only the data necessary for their function and are contractually obliged to maintain confidentiality and data protection standards.

Personal data will be disclosed to public authorities only where legally required, such as upon lawful request from investigative or supervisory authorities.

4. Data Security

All personal data entered on the Torc Wealth website is transmitted via encrypted connections using secure socket layer technology.

Technical and organisational measures are implemented to protect data against unauthorised access, loss, destruction or alteration. These measures include access controls, secure storage environments, restricted permissions, secure password policies and controlled data transfer processes.

Data security measures are reviewed regularly and adapted where necessary to reflect technological developments and risk assessments.

5. Data Retention Principles

Torc Wealth applies the following principles:

• Personal data is retained only where a lawful basis exists
• Data is not retained without defined purpose
• Sensitive financial, pension and investment data requires a documented advisory or contractual purpose
• Data is deleted or anonymised once no longer required
• Retention periods are proportionate, legally defensible and documented

6. Retention Categories and Periods

6.1 Active Clients

Legal Basis
Article 6 paragraph 1 letter b GDPR and Article 6 paragraph 1 letter c GDPR

Retention Period
Ten years following the end of the client relationship in order to comply with statutory retention obligations under German commercial and tax law.

This includes advisory documentation, pension analysis, investment recommendations, suitability assessments, contracts and correspondence.

6.2 Former Clients

Legal Basis
Legal obligation and legitimate interest in the defence of legal claims

Retention Period
Ten years following termination of the advisory relationship. Data may be retained beyond this period where required for ongoing legal proceedings.

6.3 Active Prospects

Individuals who have engaged in consultations or requested advice without entering into a formal contract.

Legal Basis
Article 6 paragraph 1 letter b GDPR for pre contractual measures
Article 6 paragraph 1 letter f GDPR for legitimate interest

Retention Period
Up to twenty four months following the last meaningful engagement. If further engagement occurs, the period restarts from the most recent contact.

6.4 Dormant Prospects

Prospects with no engagement for more than twenty four months and no contractual relationship.

Where no continuing legitimate interest exists, personal data must be deleted or anonymised within thirty days of identification unless a documented legal basis justifies continued retention.

6.5 Marketing Contacts

Legal Basis
Consent pursuant to Article 6 paragraph 1 letter a GDPR or legitimate interest pursuant to Article 6 paragraph 1 letter f GDPR

Retention continues until consent is withdrawn, the individual unsubscribes, or no engagement occurs for twenty four months.

7. Special Categories and Sensitive Business Data

Financial, pension, tax and investment information is treated as sensitive business data. Such data will only be retained where a lawful basis exists and a defined advisory or contractual purpose remains.

Sensitive data will not be retained indefinitely and requires documented justification for continued storage.

8. Review, Deletion and Anonymisation Procedures

8.1 Quarterly Review

A formal data review is conducted quarterly. The review identifies dormant prospects, confirms the status of active prospects and verifies retention timelines for former clients.

8.2 Deletion Procedure

Where deletion is required:

• CRM records are permanently deleted or anonymised
• Associated cloud stored documents are removed
• Email correspondence is deleted where technically feasible
• Paper files are securely destroyed

8.3 Anonymisation

Where business reporting or statistical analysis requires retention of non identifying information, personal identifiers such as name, email address, postal address and telephone number are removed so that data can no longer be attributed to an identifiable individual.

9. Deletion Log

Torc Wealth maintains a Data Review Log containing:

• Date of review
• Name of reviewer
• Number of records deleted or anonymised
• Notes on any retained data and corresponding legal basis

This log is retained for audit and compliance purposes.

10. Data Subject Rights

Data subjects have the right to:

• Access their personal data
• Request rectification of inaccurate data
• Request erasure where legally permissible
• Request restriction of processing
• Object to processing based on legitimate interest
• Withdraw consent at any time where processing is based on consent

Requests will be handled in accordance with GDPR time limits. The right to erasure may be restricted where statutory retention obligations apply or where data is required for the establishment, exercise or defence of legal claims.

Requests may be addressed to:

Christopher Everitt
Data Protection Officer
Torc Wealth
Email: [email protected]

11. Responsibility

Overall responsibility for compliance with this policy lies with:

Christopher Everitt
Managing Director
Torc Wealth

The Managing Director is responsible for ensuring implementation of this policy, conducting or delegating quarterly reviews, monitoring retention compliance and updating the policy where required.

12. Policy Review

This policy will be reviewed annually or earlier where regulatory changes occur, business processes change materially, or a data protection issue requires revision.

Information on Cookies and further Processing of Data

a. Use of cookies

We use cookies to make navigation and use of our website as user-friendly as possible. Cookies are small text files that are deposited on your hard drive when you access our services.

Cookies also serve, for example, to recognize the users of our website and not have to ask them again for their access data each time they visit the website. Cookies are also used to track visitor preferences, which can help to optimize the layout of our website. This enables us to make targeted adjustments of the content of our website to meet your needs and improve our offer to you. Cookies used by us do not store any personal data and do not enable you to be personally identified.

You can deactivate storage of these cookies and delete existing cookies in the system settings of your browser at any time. Any user can view our services without non-essential cookies. However, if you do not accept cookies, this can restrict the available functionality.

b. Use of Google Analytics/Google AdWordsGoogle-Analytics

This website uses Google Analytics, a web analysis service provided by Google Inc. (‘Google’). Google Analytics uses cookies, which enable analysis of your use of the website. Information generated by cookies about your use of this website is normally transmitted to a Google server in the USA and stored there.

However, if IP anonymisation is activated on this website, your IP address will first be shortened by Google within member states of the European Union or in other countries that are signatories of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there. Google will use this information on behalf of the provider of this website to evaluate your use of the website, to compile reports on website activity, and to provide other services regarding website usage and internet usage for the website provider.

The IP address transmitted by your browser for Google Analytics will not be associated with any other data held by Google. You can prevent these cookies being stored by selecting the appropriate settings in your browser; however, please note that doing so may make you unable to use the full functionality of this website.

You can also prevent the data generated by the cookies about your use of the website (including your IP address) being sent to and processed by Google by downloading and installing the browser plugin available from the following link:
http://tools.google.com/dlpage/gaoptout?hl=en

Please note that we also use the extended Google Analytics remarketing and advertising functions, alongside the standard Google Analytics functions. Based on a user’s previous visits to our website, the remarketing and advertising functions enable analysis and placement of optimised, interest-based advertising on other websites within the Google Display Network (on Google itself, on Google Ads, or on other websites). Google Analytics uses a third-party cookie from DoubleClick to evaluate data on user browsing habits on various websites. These data can provide information on topics such as demographics and the interests of website users.

DoubleClick cookies do not contain or store any personal user data; this means you cannot be personally identified at any time.

You can prevent these cookies being stored by selecting the appropriate settings in the cookie settings or in your browser. You can also deactivate interest-based advertising on Google and interest-based Google ads (within the Google Display Network) in your browser by going to https://adssettings.google.com or http://www.google.com/settings/ads/onweb/?hl=en and switching the button to ‘off’, or deactivate ads on http://www.aboutads.info/choices. You can find further information on available settings and Google data protection on https://www.google.com/intl/en/policies/privacy/?fg=1.

Google Remarketing: In addition, this website uses the Google program for interest-based advertising – the so-called Google Remarketing. Third-party providers, including Google, place ads on websites on the Internet and use stored cookies for this on the basis of a user’s previous visits to this website. You can also disable Google’s use of cookies for these purposes by visiting the Google advertising opt-out page.

Please note that Google has its own privacy policies, of which Torc Wealth GmbH is independent. We do not take any responsibility or liability for these policies and procedures.

Google AdWords

This website also uses the online advertising program “Google AdWords” and, as part of Google AdWords, the conversion tracking of Google LLC. We use the offer of Google Adwords to draw attention to our attractive offers with the help of advertising media (so-called Google Adwords) on external websites. In relation to the data of the advertising campaigns, we can determine how successful the individual advertising measures are. In this way, we pursue the interest of showing you advertising that is of interest to you, making our website more interesting for you and achieving a fair calculation of advertising costs.

The cookie for conversion tracking is set when a user clicks on an AdWords advertisement placed by Google.

These cookies usually expire after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google AdWords customer receives a different cookie. Cookies can therefore not be tracked through the websites of AdWords customers. The information obtained using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. Clients learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to identify users personally. If you do not want to take part in tracking, you can block this use in your Internet browser under user settings.

c. Use of Facebook Pixel

We use Facebook’s Pixel service, provided by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, for online advertising. Here anonymised data on browsing habits is collected. The data collected is only general and technical information of the page visited. These are not linked to or evaluated together with the user’s personal data. You can deactivate this type of data processing by opting out on the following link: http://www.youronlinechoices.com/uk/your-ad-choices. Facebook users can also deactivate this type of data processing on the following link: https://www.facebook.com/settings?tab=ads.

d. Facebook Custom Audiences Pixel

On our website, the pixel variant of Facebook Custom Audiences (without the so-called advanced matching function) is used. This tool is provided by Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA. With the help of Facebook Pixel, technical data about your use of our website can be sent to Facebook. If you are registered with Facebook, Facebook can assign the sent data to you based on an automated matching of hash values and show you interest-based advertising on your home page. Such advertising may, for example, be special offers. Facebook assures in the Custom Audience Terms of Use that it will process the collected data exclusively for this advertising purpose in our Custom Audience.

You can find out more about the advertising by Facebook and how you can influence it here under Facebook – Settings for advertisements. As a user of Facebook, you can deactivate the data processing described under the following link https://www.facebook.com/settings?tab=ads.

e. TikTok Pixel

We may use TikTok Pixel on our website. TikTok Pixel is an advertisement tool provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland and TikTok Information Technologies UK Limited, WeWork, 125 Kingsway, London, WC2B 6NH, United Kingdom (“TikTok”). This is a code that allows us to understand and track your behavior on our website. TikTok uses login or device information to identify users of this website and associate it with a TikTok user account. This data is then used by TikTok to display tailored advertisements and content of interest to its users. The collected data is anonymous and not visible to us and is only used for the purpose of measuring the effectiveness of ad placements. Your data will generally be processed within the EU or the EEA. In the event that a data transfer takes place outside the EU or the EEA, this will take place within the framework of standard contractual clauses in accordance with Art. 46 GDPR. TikTok’s privacy policy can be found here: https://www.tiktok.com/legal/new-privacy-policy?lang=de-DEf.

Use of Amazon Web Services

We additionally use the Amazon Web Services Cloud, provided by Amazon Web Services, Inc., P.O. Box 81226, Seattle, WA 98108-1226, USA. Website data and databases for the website and Torc Wealth app are stored by this service. Amazon Web services processes the data only as commissioned and instructed by Torc Wealth GmbH. Data are not transferred outside of Germany for this purpose.

g. Amplitude

We use Amplitude, a digital optimization system, on our website. The service provider is Amplitude Inc, 631 Howard Street, Floor 5, San Francisco, CA 94105, USA (“Amplitude”). Amplitude is an event tracking and product analytics system and uses in particular cookies, which enable analysis of your use of the website. This helps us to understand how you engage with our website. Information generated about your use of this website is normally transmitted to a server and stored there. Amplitude also stores and processes data on servers outside the EU or the EEA. As a basis of data transfer or data processing with recipients from third countries (in particular the USA), Amplitude uses standard contractual clauses in accordance with Art. 46 GDPR.

You can find out more here on Amplitudes Measures on Security and Privacy: https://amplitude.com/amplitude-security-and-privacy

Amplitude’s privacy policy can be found here: https://amplitude.com/privacyh. Links to third party websites

On our Internet pages you will find links that refer to Internet pages of third parties. We therefore expressly point out that we have no influence on the content and design of the linked pages. Torc Wealth GmbH assumes no responsibility or liability for their policies and procedures. On the servers, to which the external links lead, there can be other privacy policies.

Schedule a consultation with our experts today.

CUSTOMER CARE

Copyright TORC GROUP © 2024. All Rights Reserved.