LEGAL & PRIVACY
Data Protection Policy
Last Updated: September 2026
How Ironstone Commercial Finance Ltd handles and protects personal and corporate financial data collected through its commercial introduction services.
1. Purpose
This policy sets out how Ironstone Commercial Finance Ltd (“Ironstone,” “we,” “us”) handles and protects the personal and corporate financial data we collect as part of our commercial introduction services. It complements our published Privacy Policy by setting out our internal data handling standards.
2. Scope
This policy applies to all data collected from clients (UK Limited Companies and LLPs) and their representatives, in connection with our role as a B2B commercial introducer and business management consultancy.
3. Data We Handle
In line with our Privacy Policy, this includes Identity & Contact Data (director names, business addresses, phone numbers and emails), Corporate Financial Data (bank statements via Open Banking or direct upload, filed accounts, turnover figures and company registration details), and Technical Data (IP address, browser type and website usage).
4. How We Protect Data
Access to client financial data is restricted to those directly involved in preparing and progressing an introduction. Data submitted via intake forms or Open Banking is transferred and stored using secure, encrypted methods. We do not store card payment details or banking credentials — Open Banking access is handled via regulated third-party integrations, not held directly by us. Physical or digital copies of financial documents are not shared or duplicated beyond what is necessary to complete a client’s introduction to our partner panel.
5. Data Sharing
Corporate financial packages are shared exclusively with vetted commercial lenders, asset finance providers and commercial finance partners (including platform partners such as Swoop) for the sole purpose of progressing a funding introduction. We do not sell or share data for marketing or any unrelated purpose.
6. Data Retention
In line with our Privacy Policy, business financial data is retained for up to 6 years to satisfy UK corporate record-keeping standards and compliance obligations, after which it is securely deleted or anonymised.
7. Data Breach Procedure
In the event of a data breach affecting client data, Ironstone will assess the risk to affected parties, notify the Information Commissioner’s Office (ICO) where required under UK GDPR (within 72 hours of becoming aware, where feasible), and inform affected clients without undue delay where the breach poses a risk to their rights.
8. Client Rights
As set out in our Privacy Policy, clients may request access, correction, deletion or object to processing of their data, subject to our statutory record-keeping duties, by contacting khushi@ironstonecf.co.uk.
9. Review
This policy is reviewed periodically to reflect changes in our operations, partner relationships or UK data protection law.