Knowledge Base

Go to Firmcheck
See our blog for the latest updates and insights
All collectionsAccount Administration📒 Security and privacy FAQ

📒 Security and privacy FAQ

Answers to the questions firms ask us most about data protection, hosting, ID verification, AI, and security

Everything firms ask us about data protection, hosting, ID verification, and security, in one place. If your question isn't here, email [email protected].

The basics

Who is Firmcheck Limited?

Firmcheck Limited is registered in London, England (company number 11997004), at 20-22 Wenlock Road, London N1 7GU. Our parent company is Connectworks Limited, based in New Zealand.

Are you registered with the ICO?

Yes, registration reference ZB428150.

Who is your Data Protection Officer?

Matt Barnett, our Chief Operating Officer. You can reach him at [email protected].

Which data protection laws do you comply with?

UK GDPR and the Data Protection Act 2018, plus the EU GDPR and the New Zealand Privacy Act where they apply.

Contracts and paperwork

Do you offer a data processing agreement?

Yes, and there's nothing to sign. Our DPA is executed as part of our Terms of Service (clause 6.3.1) on every plan, and both documents are public.

Can we have a signed copy for our vendor file?

Yes. The DPA is already in force through our Terms, but if your due diligence process needs a signed copy, ask us at [email protected] and we'll sort it.

Can we use our own DPA instead?

No, we work from ours. It's already built around UK GDPR and how the platform actually works, and it applies consistently to every firm.

Where is your sub-processor list?

In our Privacy Policy, with each sub-processor's purpose and data location. We keep it current as things change.

Who performs biometric matching, and who supplies your PEP, sanctions and adverse media data?

Biometric matching is provided by BioVerify, hosted in New Zealand, using IDVerse, a provider certified under the UK Digital Identity and Attributes Trust Framework (DIATF). PEP, sanctions and adverse media checks come through APLYiD, hosted in Ireland, with the underlying data supplied by GBG.

Can we audit you?

Yes. On reasonable notice you can audit and inspect our technical and organisational measures and our compliance with the DPA. We're a distributed team without a central office, so audits are normally conducted remotely: documentation, questionnaire responses, and a call with the people who own the controls. Audits are at your cost.

Do you hold ISO 27001 or SOC 2?

Not currently; they're on our radar. What we do have is AWS UK hosting, encryption in transit (TLS 1.2+) and at rest, least-privilege access controls, continuous monitoring, and two-factor authentication. We're happy to walk through our controls in detail with your team.

Can you complete our security questionnaire?

Yes, send it to [email protected]. Most of what firms ask is answered on this page, so it's worth checking here first.

Where your data lives

Which region is our data hosted in?

The United Kingdom. Firmcheck is hosted on AWS UK.

Can we choose our hosting region?

No. UK hosting is the standard for every firm, which is what UK practices need.

Does our data flow to your New Zealand or Australian group entities?

We don't have any Australian entities. Our parent company Connectworks is in New Zealand, and New Zealand is covered by UK adequacy, so no IDTA is required for transfers there.

What transfer mechanism do you use for data leaving the UK?

Where a country isn't recognised by the UK as adequate, we put the UK International Data Transfer Agreement or Addendum in place. Where the EU GDPR applies instead, we use the European Commission's standard contractual clauses. New Zealand and Ireland are both covered by adequacy, so no additional mechanism is needed there.

Do you back up our data?

Yes. Firmcheck runs on AWS UK, and your data is backed up automatically as part of that infrastructure. Backups are encrypted and held in the UK, in line with the rest of your data.

ID verification and biometrics

Are the selfie image and biometric template kept after the check?

No derived biometric template is retained by Firmcheck, and there's no configurable retention setting. What is retained is the biometric report in the client's record, which includes a copy of the passport image and the selfie. It stays in your account until you delete it or your subscription ends. On the matching side, BioVerify retains biometric data for 90 days and then strips it of personally identifiable information.

Who is the controller for the biometric check, us or Firmcheck?

You are. You decide the check is needed to meet your MLR obligations, and we process on your instruction. The Article 9 condition and the DPIA are yours to establish, and we'll give you what you need for both; just ask. IDVerse's UK DIATF certification, via BioVerify, is a useful starting point as supporting evidence.

Do clients upload their ID documents directly to Firmcheck?

Yes. Clients can upload identity and proof of address documents for biometric checks, and complete passport chip scans for cryptographic checks. You can also upload documents on their behalf. More client upload functionality is on our product roadmap.

Who can see the verification result?

Only your firm. Results aren't shared with third parties.

Is screening matched automatically, or does someone review it?

Human review is built into the workflow. Your team reviews and can override check results, so nothing is a solely automated decision in the Article 22 sense.

AI and machine learning

Do you use AI in the service?

Yes. OCR combined with OpenAI extracts and pre-populates data from manually uploaded ID and proof-of-address documents, and Anthropic's models support parts of our processing pipeline. Both appear on our published sub-processor list.

Is our data used to train AI models?

No. We access these models under commercial API terms that exclude training on customer data, so nothing you or your clients put into Firmcheck is used to improve anyone's models.

Is AI output reviewed by a human?

Yes. Extraction pre-populates fields for your team, and verification results can be reviewed and overridden by your staff.

Can we opt out of AI features?

There's no separate switch for it; AI-assisted extraction is part of how document upload works. But if you'd rather not use it, you can enter client details manually instead of uploading documents, and nothing goes near AI processing.

It's worth saying what the feature actually does: it reads uploaded ID and proof-of-address documents and pre-fills fields for your team to check. It doesn't make decisions, and nothing it produces reaches a client record without your staff reviewing it.

Retention and deletion

How long do you keep our data?

While you're a customer, for as long as needed to provide the service. When your subscription ends, we auto-delete your data under our Terms (clause 10.3.3), and in any event we remove your personal data from the service within 30 days. You can also delete data from within the app at any time.

How does the five-year retention point under MLR 2017 regulation 40 work?

Regulation 40 requires you to keep CDD records for five years from the end of the business relationship, then delete them unless another legal ground applies. You decide when that five-year period ends and when records are deleted. We don't auto-delete at the five-year mark, but you can delete records in the app whenever you need to.

A client has asked us to delete their data, but we need it for AML records. What now?

The right to erasure isn't absolute. Where you have a legal obligation under the MLRs to retain records, that generally takes priority. That decision is yours to make.

Can we export our data if we leave?

Yes. You can export client data from within the app on a client-by-client basis, at any time, not just when you're leaving. Because our Terms auto-delete your data once a subscription ends, export anything you need to keep before that point.

Are AML training records exportable?

Completing in-app training generates a certificate with CPD credits for each course. Certificates can be downloaded, and your MLRO can see and download every staff member's certificates.

Security controls

Is our data encrypted?

Yes, in transit using TLS 1.2 or higher, and at rest.

Do you offer two-factor authentication?

Yes, 2FA is available for extra account security.

How do you control staff access to our data?

On least privilege. Our team and systems only get the minimum access needed, with strong authentication and regular permission reviews.

Can Firmcheck staff see our client data?

Only when you ask us to. Our support team accesses your account when you invite us in to help with a specific issue, and only for that purpose.

Can we control what our own staff can see?

Yes. Permissions and roles are set by your firm administrator, so you decide who can see and do what.

Are your staff vetted and trained on data protection?

Yes. Everyone handling personal information is under confidentiality obligations and is trained on how to handle it properly.

Do you hold cyber insurance?

Yes.

Breaches and incidents

Will you tell us if there's a data breach?

Yes. Under section 5 of our DPA, we notify you without undue delay and, where feasible, within 72 hours of becoming aware of a breach affecting your data.

What will you tell us?

The nature of the breach, the categories and numbers of data subjects and records affected, any unlawful recipient we know of, the likely consequences, and the mitigation steps we're taking. Enough for you to meet your own ICO obligations.

Have you ever had a data breach?

No. Firmcheck has never had a personal data breach.

Does Firmcheck ever ask clients for passwords or payment details?

No. If a client receives something that looks like it's from us asking for a password or payment, treat it as suspicious and let us know.

Did this answer your question?
😞
😐
😁