Everything firms ask us about data protection, hosting, ID verification, and security, in one place. If your question isn't here, email [email protected].
Firmcheck Limited is registered in London, England (company number 11997004), at 20-22 Wenlock Road, London N1 7GU. Our parent company is Connectworks Limited, based in New Zealand.
Yes, registration reference ZB428150.
Matt Barnett, our Chief Operating Officer. You can reach him at [email protected].
UK GDPR and the Data Protection Act 2018, plus the EU GDPR and the New Zealand Privacy Act where they apply.
Yes, and there's nothing to sign. Our DPA is executed as part of our Terms of Service (clause 6.3.1) on every plan, and both documents are public.
Yes. The DPA is already in force through our Terms, but if your due diligence process needs a signed copy, ask us at [email protected] and we'll sort it.
No, we work from ours. It's already built around UK GDPR and how the platform actually works, and it applies consistently to every firm.
In our Privacy Policy, with each sub-processor's purpose and data location. We keep it current as things change.
Biometric matching is provided by BioVerify, hosted in New Zealand, using IDVerse, a provider certified under the UK Digital Identity and Attributes Trust Framework (DIATF). PEP, sanctions and adverse media checks come through APLYiD, hosted in Ireland, with the underlying data supplied by GBG.
Yes. On reasonable notice you can audit and inspect our technical and organisational measures and our compliance with the DPA. We're a distributed team without a central office, so audits are normally conducted remotely: documentation, questionnaire responses, and a call with the people who own the controls. Audits are at your cost.
Not currently; they're on our radar. What we do have is AWS UK hosting, encryption in transit (TLS 1.2+) and at rest, least-privilege access controls, continuous monitoring, and two-factor authentication. We're happy to walk through our controls in detail with your team.
Yes, send it to [email protected]. Most of what firms ask is answered on this page, so it's worth checking here first.
The United Kingdom. Firmcheck is hosted on AWS UK.
No. UK hosting is the standard for every firm, which is what UK practices need.
We don't have any Australian entities. Our parent company Connectworks is in New Zealand, and New Zealand is covered by UK adequacy, so no IDTA is required for transfers there.
Where a country isn't recognised by the UK as adequate, we put the UK International Data Transfer Agreement or Addendum in place. Where the EU GDPR applies instead, we use the European Commission's standard contractual clauses. New Zealand and Ireland are both covered by adequacy, so no additional mechanism is needed there.
Yes. Firmcheck runs on AWS UK, and your data is backed up automatically as part of that infrastructure. Backups are encrypted and held in the UK, in line with the rest of your data.
No derived biometric template is retained by Firmcheck, and there's no configurable retention setting. What is retained is the biometric report in the client's record, which includes a copy of the passport image and the selfie. It stays in your account until you delete it or your subscription ends. On the matching side, BioVerify retains biometric data for 90 days and then strips it of personally identifiable information.
You are. You decide the check is needed to meet your MLR obligations, and we process on your instruction. The Article 9 condition and the DPIA are yours to establish, and we'll give you what you need for both; just ask. IDVerse's UK DIATF certification, via BioVerify, is a useful starting point as supporting evidence.
Yes. Clients can upload identity and proof of address documents for biometric checks, and complete passport chip scans for cryptographic checks. You can also upload documents on their behalf. More client upload functionality is on our product roadmap.
Only your firm. Results aren't shared with third parties.
Human review is built into the workflow. Your team reviews and can override check results, so nothing is a solely automated decision in the Article 22 sense.
Yes. OCR combined with OpenAI extracts and pre-populates data from manually uploaded ID and proof-of-address documents, and Anthropic's models support parts of our processing pipeline. Both appear on our published sub-processor list.
No. We access these models under commercial API terms that exclude training on customer data, so nothing you or your clients put into Firmcheck is used to improve anyone's models.
Yes. Extraction pre-populates fields for your team, and verification results can be reviewed and overridden by your staff.
There's no separate switch for it; AI-assisted extraction is part of how document upload works. But if you'd rather not use it, you can enter client details manually instead of uploading documents, and nothing goes near AI processing.
It's worth saying what the feature actually does: it reads uploaded ID and proof-of-address documents and pre-fills fields for your team to check. It doesn't make decisions, and nothing it produces reaches a client record without your staff reviewing it.
While you're a customer, for as long as needed to provide the service. When your subscription ends, we auto-delete your data under our Terms (clause 10.3.3), and in any event we remove your personal data from the service within 30 days. You can also delete data from within the app at any time.
Regulation 40 requires you to keep CDD records for five years from the end of the business relationship, then delete them unless another legal ground applies. You decide when that five-year period ends and when records are deleted. We don't auto-delete at the five-year mark, but you can delete records in the app whenever you need to.
The right to erasure isn't absolute. Where you have a legal obligation under the MLRs to retain records, that generally takes priority. That decision is yours to make.
Yes. You can export client data from within the app on a client-by-client basis, at any time, not just when you're leaving. Because our Terms auto-delete your data once a subscription ends, export anything you need to keep before that point.
Completing in-app training generates a certificate with CPD credits for each course. Certificates can be downloaded, and your MLRO can see and download every staff member's certificates.
Yes, in transit using TLS 1.2 or higher, and at rest.
Yes, 2FA is available for extra account security.
On least privilege. Our team and systems only get the minimum access needed, with strong authentication and regular permission reviews.
Only when you ask us to. Our support team accesses your account when you invite us in to help with a specific issue, and only for that purpose.
Yes. Permissions and roles are set by your firm administrator, so you decide who can see and do what.
Yes. Everyone handling personal information is under confidentiality obligations and is trained on how to handle it properly.
Yes.
Yes. Under section 5 of our DPA, we notify you without undue delay and, where feasible, within 72 hours of becoming aware of a breach affecting your data.
The nature of the breach, the categories and numbers of data subjects and records affected, any unlawful recipient we know of, the likely consequences, and the mitigation steps we're taking. Enough for you to meet your own ICO obligations.
No. Firmcheck has never had a personal data breach.
No. If a client receives something that looks like it's from us asking for a password or payment, treat it as suspicious and let us know.