LEGAL & PRIVACY

Data Protection Policy

Last Updated: September 2026

How Ironstone Commercial Finance Ltd handles and protects personal and corporate financial data collected through its commercial introduction services.

1. Purpose

This policy sets out how Ironstone Commercial Finance Ltd (“Ironstone,” “we,” “us”) handles and protects the personal and corporate financial data we collect as part of our commercial introduction services. It complements our published Privacy Policy by setting out our internal data handling standards.

2. Scope

This policy applies to all data collected from clients (UK Limited Companies and LLPs) and their representatives, in connection with our role as a B2B commercial introducer and business management consultancy.

3. Data We Handle

In line with our Privacy Policy, this includes Identity & Contact Data (director names, business addresses, phone numbers and emails), Corporate Financial Data (bank statements via Open Banking or direct upload, filed accounts, turnover figures and company registration details), and Technical Data (IP address, browser type and website usage).

4. How We Protect Data

Access to client financial data is restricted to those directly involved in preparing and progressing an introduction. Data submitted via intake forms or Open Banking is transferred and stored using secure, encrypted methods. We do not store card payment details or banking credentials — Open Banking access is handled via regulated third-party integrations, not held directly by us. Physical or digital copies of financial documents are not shared or duplicated beyond what is necessary to complete a client’s introduction to our partner panel.

5. Data Sharing

Corporate financial packages are shared exclusively with vetted commercial lenders, asset finance providers and commercial finance partners (including platform partners such as Swoop) for the sole purpose of progressing a funding introduction. We do not sell or share data for marketing or any unrelated purpose.

6. Data Retention

In line with our Privacy Policy, business financial data is retained for up to 6 years to satisfy UK corporate record-keeping standards and compliance obligations, after which it is securely deleted or anonymised.

7. Data Breach Procedure

In the event of a data breach affecting client data, Ironstone will assess the risk to affected parties, notify the Information Commissioner’s Office (ICO) where required under UK GDPR (within 72 hours of becoming aware, where feasible), and inform affected clients without undue delay where the breach poses a risk to their rights.

8. Client Rights

As set out in our Privacy Policy, clients may request access, correction, deletion or object to processing of their data, subject to our statutory record-keeping duties, by contacting khushi@ironstonecf.co.uk.

9. Review

This policy is reviewed periodically to reflect changes in our operations, partner relationships or UK data protection law.