Privacy Policy
This policy is made for and applies to anyone who is a Grey Epoch customer or subscriber, or anyone who is visiting our website, or anyone whose personal data we process in the course of our business communications.
When you first visit our Site, our cookie banner lets you choose to accept only essential cookies, or additional categories as well - see the Cookies section below for how these work and how to change your choices at any time. This notice is provided for your information: it explains how we collect and use your personal data and the rights you have.
Feel free to email us at dpo@greyepoch.com if you have questions or concerns.
We may update our privacy policy from time to time. Any changes we make will be posted on this page and, where appropriate, and if we have an up-to-date email address for you on record, we will send you an email to confirm the changes as well.
Definitions
Grey Epoch, or “we”, “us” or “our” means us, Grey Epoch;
“Service” or "Services” means Grey Epoch’s products, software, services, and Website (including but not limited to text, graphics, images, and other material and information) as accessed from time to time by the user, regardless if the use is in connection with an account or not;
“Website” or “Site” means www.greyepoch.com and www.app.greyepochtrading.com
“Agreement” means this Privacy Policy, updated from time to time as described herein;
“UK GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018;
“Data Protection Regulation” means UK Data Protection Act 2018, and the UK GDPR.
Our Contact Details and About Us
Grey Epoch Europe
Name: Grey Epoch Europe Limited
Business & contact address: 37-41 Mortimer House, Mortimer Street, London, W1T 3JH, UK
Registered address: 40 Gracechurch Street, London, EC3V 0BT, UK
Phone Number: +44 20 7038 7691
Grey Epoch Europe is registered with the UK Information Commissioner's Office (registration number ZB297369); the Data Protection Officer is Edmund Lehmann. You can contact Edmund by email at: dpo@greyepoch.com
Grey Epoch Europe Limited (FRN: 959638) is an appointed representative of Thornbridge Investment Management LLP (FRN: 713859), which is authorised and regulated by the Financial Conduct Authority.
Grey Epoch Trading
Name: Grey Epoch LLC
Business & contact address: 141 W. Jackson Suite 2270 Chicago, IL 60604, USA
Registered address: C/O VCorp Services, LLC, 108 W. 13TH Street, Suite 100, 19801 Wilmington, Delaware, USA
Data Controller
Grey Epoch Europe Limited is the data controller in relation to any personal data of UK data subjects that you provide to us. This means we decide how and why your personal data is processed, and we are responsible for processing and sharing it in line with the requirements of the applicable data protection laws. We only share personal data with third parties where there is a lawful basis to do so.
Personal Information We Collect
Personal information is the term we use to describe information which we collect and which can be used to personally identify someone. For example, a name, a personal address or even an IP address.
Here is a list of the types of personal data we collect:
Information you give to us (e.g. on contact forms, questionnaires)
Contact details - such as your name, address, email address, phone number, marital status, gender, job title;
Responses to surveys or promotions;
Any updates to the information you provide to us;
Employment and recruitment data - where you apply for a role with us, your CV, application, references, qualifications, right to work documents, and the outcome of pre-employment screening.
This is essential information for us to provide the best service we can to you and to comply with our legal and regulatory obligations. If you ask us to delete this information, it’s possible we may no longer be able to provide our services to you.
Information we collect automatically when you visit our Website
Technical information - such as your IP addresses, domain names, the country you’re visiting from, files requested, your browser type and version, time zone setting, browser plug-in types and versions, operating system and platform;
Information on your visit - such as the full URL clickstream to, through and from our Website (including date and time), length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs) and methods used to browse away from the page.
We make reasonable efforts to keep this information anonymous, to protect your privacy.
Information you give us as part of contacting us on our Website, including:
Most of the categories above come directly from you, for example through onboarding forms, your correspondence with us, and our website. You may also give us:
Communications and recordings - emails, letters, chat and instant messages, voice recordings and metadata of telephone and video calls, meeting notes, records of visits and hospitality, and the content of your correspondence with us.
Responses to surveys or promotions
Any updates to the information you provide to us
Information we receive from other sources
Advertising networks and information providers - we work closely with advertising networks, analytics and search information providers, and we sometimes receive information about you from them.
How do we use the information?
We use your information in line with Data Protection Regulation. In short, this means we only use it where we have a legal basis to do so. These are the general legal basis for which we use your information:
Consent - you have given clear consent to us to process your personal information.
Our contract - processing your personal information is necessary for a contract you have with us, or because we have asked you to take specific steps before entering into that contract.
Legitimate interests - processing your personal information is necessary for our legitimate interests or those of a third party. Our legitimate interests include keeping our systems and our clients’ data secure, preventing fraud, recovering debts owed to us, understanding how our Website is used so that we can improve it, and operating our business efficiently. You have the right to object to processing based on legitimate interests - see Your choices and rights below.
Legal obligation - processing your personal information is necessary for us to comply with the law and our regulatory obligations, including FCA record-keeping rules and anti-money-laundering requirements.
We do not make any decisions about you based solely on automated processing which would produce legal or similarly significant effects on you - our staff review all significant decisions.
At a glance: what we collect, why, and our lawful basis
As a business-to-business firm, the personal data we handle mainly consists of professional contact information about individuals at our clients, prospective clients and suppliers. Here are some reasons we process your personal information:
| What we use your information for | Personal data involved | Lawful basis |
|---|---|---|
| Providing our services, responding to your enquiries, and managing our relationship with you, including keeping you informed about changes to our services, fees and charges | Business contact details (name, job title, work email and phone); account and transaction information | Our contract with you (or legitimate interests where you are not yet a client) |
| Regulatory record-keeping and anti-money-laundering checks | Records of telephone and electronic communications; identity and verification information; transaction records | Legal obligation |
| Keeping our systems secure, preventing fraud and recovering debts | Technical information (such as IP addresses and logs); account and correspondence records | Legitimate interests |
| Understanding and improving our Website | Technical information and details of your visit | Legitimate interests (analytics cookies are set only with your consent) |
| Staff use of third-party AI tools to assist our business activities | Business contact details and correspondence; information contained in documents and messages processed by these tools | Legitimate interests |
| Marketing our services to you | Business contact details; your marketing preferences | Consent & legitimate interests |
| Statistical analysis and market research | Aggregated or minimised business information | Legitimate interests |
Sharing your information
We may share your personal information with the following categories of third parties, including:
our service providers and sub-contractors, including but not limited to payment processors, suppliers of technical, analytical and support services, third-party artificial intelligence (AI) service providers, and cloud service providers;
companies that assist us in our marketing, advertising and promotional activities;
compliance, we may disclose your personal data where necessary to comply with regulations which apply to us, or the law;
analytics and search engine providers that assist us in the improvement and optimisation of our Website;
any third parties that you have agreed that we may share your personal information with for marketing purposes;
our affiliated companies;
our principal, Thornbridge Investment Management LLP, which supervises our activities as its appointed representative and receives information about our clients for oversight and compliance purposes.
Finally, we may also disclose your personal information to third parties in certain exceptional circumstances as follows:
if we are required by any applicable law, regulation or law enforcement organisation to do so;
in order to enforce or apply our terms of service or any other agreement or to respond to any claims, to protect our rights or the rights of a third party, to protect the safety of any person or to prevent any illegal activity;
to protect the rights, property, or safety of Grey Epoch Europe Limited and its affiliated companies, our customers or other persons. This may include exchanging information with other organisations for the purposes of fraud protection and credit risk reduction;
in the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets; or
if Grey Epoch Europe or substantially all its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
We do not disclose information about identifiable individuals to our advertisers, but we may provide them with aggregate information about our users (for example, we may inform them that 500 are of a particular gender, aged under 30 and have clicked on their advertisement on any given day). We may also use such aggregate information to help advertisers reach the kind of audience they want to target (for example, women in SW1). We may make use of the personal data we have collected from you to enable us to comply with our advertisers' wishes by displaying their advertisement to that target audience.
Transfers of information
The personal data we collect is processed at our offices and in any data processing facilities operated by third-party providers that we use. Technology businesses, including the ones we have as providers, often use third parties to help them host their application, communicate with customers, power their emails, etc. It may be necessary for us to share your data with them in order to allow these services to work. Your data is shared when necessary and according to the safeguards and good practices detailed in this Privacy Policy.
Below is a list of the main third-party providers we use:
Analytics - Google Analytics, LinkedIn Analytics;
Communications - Mailchimp, Zoom, Calendly, Global Relay;
CRM - Salesforce;
Productivity & Collaboration - Microsoft (including Microsoft 365), Monday.com;
Website hosting platform - Squarespace;
AI services - used to assist our staff with our business activities; personal data processed using this service is not used to train the provider’s models.
Transfer of Personal Data
Our business may require us to transfer your Personal Data to countries outside of the European Economic Area ("EEA"), outside of the UK or your country of origin, including to countries that may not provide the same level of data protection as your home country. An example of this is the need to transfer your information to our parent company Grey Epoch LLC, which is based in the USA. This transfer would be made, for example, so that we can fulfil a contract with you, or in line with our legitimate interests.
We take reasonable steps to ensure that recipients of your Personal Data remain subject to the same standards as are set out in the Data Protection Legislation; however, there is no way for us to guarantee this in practice. Therefore, we cannot guarantee that if we transfer your data outside your country of origin, the UK or EEA, that it will be protected to equivalent standards as those inside your country of origin, the UK or EEA.
By agreeing to this Privacy Policy, you recognise that your personal data may be transferred outside your country of origin, and consent to such a transfer (including outside the EEA or UK), and you acknowledge that as a result you may not enjoy the same levels of protection of your data as if that data had not been transferred.
How long we store your data for
Recordings and electronic communications are kept for at least 5 years after our business relationship ends - and up to 7 years where regulation requires - to comply with FCA record-keeping rules. We retain other categories of personal data only for as long as necessary, with retention periods based on the purpose of the processing, our legal and regulatory obligations, and the limitation periods for legal claims. When personal data is no longer required, we securely delete or anonymise it.
Cookies
Our Website uses cookies and similar technologies to make the Site work, understand how it’s used, and – where you’ve given consent – support our marketing. When you first visit our Site, our cookie banner asks you to Accept or Decline non-essential cookies, and to choose your preferences by category if you prefer.
Strictly necessary cookies - These keep the Site and client portal secure and functioning (for example, maintaining your session, protecting forms against cross-site attacks, and keeping you logged in to the portal). They don’t require consent and can’t be switched off through our cookie banner, though you can block them via your browser settings, which may affect how the Site works.
Analytics cookies - With your consent, we use Google Analytics to understand how visitors use our Site, so we can improve it.
Advertising and marketing cookies - With your consent, we use LinkedIn’s Insight Tag and Google Ads to measure the effectiveness of our marketing and to show relevant content on other platforms.
Preference cookies - We use cookies to remember the choices you make in our cookie banner.
You can manage or withdraw your cookie consent at any time using the cookie settings link at the bottom of our website, or through your browser settings. Turning off cookies may affect how our Site and Services work for you.
Your choices and rights
Marketing - we will only send you direct marketing where the law allows - with your consent or, for business contacts, where we have a legitimate interest in telling you about our services, and you have not objected. You can opt out at any time. If you have given consent and change your mind, you can withdraw it at any time by using the unsubscribe link in any marketing email or by contacting us at dpo@greyepoch.com. Withdrawing consent does not affect any other processing described in this policy, or the lawfulness of anything done while your consent was in place.
Your rights - you can contact us at dpo@greyepoch.com at any time to ask us to:
provide you with a copy of the personal data we hold about you, free of charge;
correct any personal information that is out of date or inaccurate;
delete personal information we hold about you;
restrict the way we process your personal information;
object to our processing, including processing based on our legitimate interests; or
provide your personal information to you or another provider in a portable format.
How we handle requests- we will respond within one month. If your request is complex, or you have made several requests, we may extend this by up to two further months and will tell you why. If we reasonably need clarification to respond effectively, we may ask for it, and the time until we receive your answer does not count towards the response period. We may charge a reasonable fee, or decline to act, only where a request is manifestly unfounded or excessive.
These rights are not absolute - in some cases the law allows or requires us to refuse a request. In particular, as an FCA-regulated firm we must keep certain records (such as telephone and electronic communications, identity verification and transaction records) for a minimum period, even if you ask us to delete them. Where this applies, we will tell you, explain which data we must keep and why, and delete anything we are not required to retain. If you ask us to stop holding or processing information we need to perform our contract with you, we may no longer be able to continue providing our services, and we will discuss what this means for our engagement with you before acting on your request.
Third-party websites
Our Services may, from time to time, contain links to websites operated by third parties. We do not accept any responsibility or liability for the policies of third-party websites that are linked to from our website.
Third party websites have their own terms and conditions and privacy policies, and you should read these carefully before you submit any personal information to these websites. We don’t endorse or accept any responsibility for the content of those third-party websites or third-party terms and conditions or policies.
Contact us
Questions, comments and requests about this privacy policy or how we handle your personal information should be emailed to our Data Protection Officer, Edmund Lehmann, at dpo@greyepoch.com, or sent in writing to the address in the "Our Contact Details" section above.
Complaints
If you have a concern about how we have handled your personal data, you can make a complaint by emailing dpo@greyepoch.com with “complaint“ in the subject line. We will acknowledge your complaint within 30 days and respond without undue delay, taking appropriate steps to investigate and address it. If you are not satisfied with our response, or at any time, you have the right to complain to the Information Commissioner's Office (the 'ICO') at https://ico.org.uk/.