Privacy policy

Cesta Financial Planning Ltd (company number 15755399, ICO number ZB869389) is the data controller for the purposes of UK GDPR and the Data Protection Act 2018. This notice explains how we use any personal information we collect about you, whether you are simply visiting this website, getting in touch with us, or working with us as a client.

If you have a question about anything in here, ask. We would much rather you did. You can reach us on 020 8125 4829, at hello@cestafinancialplanning.co.uk, or by post at 5 St John’s Lane, London, EC1M 4BH.

01. What this notice covers

This notice applies to our website at www.cestafinancialplanning.co.uk and to the financial planning services we provide. Different parts will apply to you depending on how you deal with us:

  • Website visitors. Sections 02 to 07 cover what happens when you browse the site, use a form or sign up to hear from us.
  • Clients and prospective clients. Sections 08 onwards cover the information we collect and use to advise you.
  • People connected to a client. Section 09 explains how we handle information about family members and dependants.

02. Information we collect when you use our website

There are two kinds. Information you give us, and information collected automatically.

Information you give us

  • Your name, email address, telephone number and any message you send when you complete a form on the site or use our contact details.
  • Your email address and name if you sign up for our newsletter or ask to be kept informed.
  • Anything you choose to tell us about your circumstances or what you are looking for.

Information collected automatically

Like most websites, ours records standard internet log information when you visit. That includes your IP address, approximate location derived from it, the type of device and browser you are using, the pages you view, how long you spend on them, and the website or search you arrived from. This is collected through cookies and similar technologies, and we use it to keep the site secure and working properly, and to understand how the site is used.

03. Cookies and similar technologies

Cookies are small text files placed on your device when you visit a website. We use them to track how visitors use our website and to compile statistical reports on website activity. The cookies on our site fall into these categories:

  • Strictly necessary. Needed for the website to work, to keep it secure, and to remember your cookie choices. These are always on.
  • Analytics and performance. Tell us which pages are visited and how people move through the site, so we can improve it.
  • Personalisation. Remember your preferences so we can personalise your repeat visits to the site.

Where cookies are not strictly necessary, we ask for your consent before setting them, and you can withdraw that consent at any time. You can set your browser not to accept cookies, and www.allaboutcookies.org explains how to remove them, though in a few cases some website features may not work as a result.

04. Website analytics

We use website analytics to produce aggregated reports on how the site is used: visitor numbers, popular pages, how people arrived and what device they used. We use this to improve the site and our content. Analytics data is aggregated and we do not use it to identify individual visitors.

05. Forms and enquiries

When you complete a form or contact us through the site, we use your details to respond to you, to answer your question and, if you ask us to, to arrange a conversation about working together. We rely on our legitimate interest in responding to enquiries, and on taking steps towards entering a contract with you. Form submissions are held in our email and client management systems and kept in line with section 16 below. If you do not go on to become a client, we delete enquiry correspondence once it no longer serves a purpose.

06. Third-party content on our website

Some parts of our site rely on services provided by other organisations, for example embedded video, hosted fonts, maps and social media content. When a page containing that content loads, the provider may receive your IP address and set its own cookies, and their own privacy policy will apply to that processing. Where this content is not strictly necessary, it loads only once you have accepted the relevant cookies. Our website is hosted on our behalf by a third-party provider, which processes data only on our instructions.

07. Links to other websites

Our website contains links to other websites. This privacy notice only applies to ours, so when you follow a link elsewhere, read their privacy policy too.

08. Information we collect when you become a client

We collect information about you when you engage us for financial planning services. It relates to identifying you, and to your personal and financial circumstances. It may also include special categories of personal data, such as information about your health, where that’s necessary to provide our services.

We may also collect information when you voluntarily complete a client survey or give us feedback.

09. Information about people connected to you

We may need to gather personal information about your close family members and dependants to provide our service to you effectively. Where we do, it’s your responsibility to make sure you have their consent to pass their information to us. We’ll provide a copy of this privacy notice for them, or where appropriate ask you to pass it on.

10. Why we need to collect and use your personal data

We’re required to collect and process your data so we can provide the services you’ve asked for and meet our legal and regulatory responsibilities. The lawful bases we rely on are:

  • Performance of contract. Providing financial planning, arranging products and services, and looking after you as a client.
  • Legal obligations. Financial Conduct Authority and anti-money laundering requirements, complaints handling and record retention.
  • Legitimate interests. Business administration, file reviews, compliance monitoring, professional indemnity insurance and quality assurance, responding to enquiries, and keeping our website secure and working well.
  • Consent. Marketing, non-essential cookies, and certain special category data processing.

Where special category data is processed, we identify an appropriate lawful basis under Article 6 of UK GDPR together with an applicable condition under Article 9.

11. Who we might share your information with

If you agree, we may email you about other products or services we think might interest you. We won’t share your information with other companies for marketing purposes.

To deliver our services effectively, we may send your details to third parties such as regulatory bodies; those we engage for professional compliance, accountancy, legal and identity verification services; product and platform providers; discretionary managers; cloud storage providers; and AI and transcription providers. Our website, email, analytics and marketing providers also process data on our behalf.

Where a third party processes your data, we have a contract in place with them that makes the nature and purpose of the processing clear, places them under a duty of confidence, and requires them to act only on our written instructions.

Where your personal data has to be forwarded to a third party, we use appropriate security measures to protect it in transit: password protection for anything sent online, or secure messaging where available. To meet our obligations around preventing money laundering and other financial crime, we may send your details to third-party agencies for identity verification.

12. International transfers of your data

In some cases your personal data may need to be transferred to a country outside the United Kingdom. Where that’s necessary, we make sure appropriate safeguards are in place in accordance with UK GDPR. These may include:

  • UK adequacy decisions, where the UK Government has assessed the destination country as providing an adequate level of data protection.
  • International Data Transfer Agreements (IDTAs).
  • The UK Addendum to the EU Standard Contractual Clauses (SCCs).
  • Other appropriate safeguards recognised under Articles 46 and 47 of UK GDPR.

13. How we use technology and AI

We sometimes use AI or machine learning to improve our service and our operations. One example is an AI notetaker in client meetings. It doesn’t replace your planner’s judgement, and it doesn’t replace what matters most, which is our relationship with you.

Wherever we use AI, we apply the same rigorous data protection due diligence to make sure your data is properly protected and managed in line with data protection law and ICO guidance. The details:

The safeguards that apply to everything

AI providers act as data processors under contract. They can’t use your data to train their models, and they only process it as we instruct. If their systems are outside the UK, transfers are protected by UK GDPR safeguards, typically two or more of the methods listed under international transfers above.

We use AI systems for administration and analysis. All advice is written, checked and approved by a qualified adviser, and no automated decisions are made, so Article 22 of UK GDPR doesn’t apply.

We only use trusted, business-grade tools under formal commercial data protection agreements and UK data processing addendums. Among other things, that means we can delete your data with the AI provider if required.

Special category data, such as health details, is only handled with your explicit consent and in line with Cesta’s systems and controls.

Video meetings, recordings and transcription

We host video meetings on Microsoft Teams, which may use AI Companion features through Microsoft 365. Where they’re used, your consent and all the safeguards described here apply.

Our back-office system, Ningi, records and transcribes client meetings, whether in person, by phone or by video, to keep accurate records. If Ningi joins a video meeting, it appears as a named participant.

At the start of each meeting we’ll tell you if transcription is in use and check you’re comfortable to proceed. If you’d rather not, we’ll take notes manually and your service won’t be affected. Recordings and transcripts form part of your client file and are kept in line with our data retention policy.

Microsoft 365 Copilot and AI drafting assistants

Our office systems run on Microsoft 365, which includes the Copilot AI assistant. Copilot has access to our document environment and may process data in your client file to help our team draft documents, summarise correspondence and find information. We also use other AI tools, under our firm’s business licences, to help draft documents, summarise or analyse your client file, and assist with research.

14. How we keep your information secure

We hold your information in access-controlled systems, protect it in transit as described above, and review our security arrangements as part of our compliance monitoring. Only people who need your information in order to do their job can see it.

15. How long we keep your information

During our relationship with you, we keep the personal data we need to provide our services, and we take all reasonable steps to keep it up to date. We’re also subject to regulatory requirements to retain your data for specified minimum periods. Generally, these are:

  • Five years for investment business.
  • Three years for mortgage business.
  • Indefinitely for pension transfers and opt-outs.
  • Three years for insurance business.

Those are minimums, during which we have a legal obligation to keep your records. We reserve the right to keep data for longer where we believe it’s in our legitimate interests. Either way, we won’t keep your personal data longer than necessary after our relationship ends, in line with our data retention policy. You have the right to ask us to delete your personal data, and we’ll comply, subject to the regulatory obligations and legitimate interests above.

Website enquiry correspondence, newsletter subscriptions and analytics data are kept only for as long as they serve the purpose they were collected for. Analytics records are retained in aggregated form.

16. Marketing

We’d like to send you information about our services that we think might interest you. If you’ve agreed to receive it, you can opt out at any time, either by using the unsubscribe link in any email or by contacting us. You have the right to stop us contacting you for marketing purposes whenever you like. Just email or write to us.

17. Social media and case studies

We may use client scenarios when talking about our work on social media or through other channels. We always anonymise these examples and case studies, and we never divulge personal data.

18. Sensitive personal data, and consent

Certain categories of personal data are sensitive by nature: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and data about health. Depending on the products and services you engage us for, we may need to obtain sensitive personal data from you, particularly about your health.

By providing you with this privacy notice, we’ve given you information about the nature of our personal data processing, our retention and deletion policies, and your rights of access to the personal information we hold about you.

19. Children

Our website and our services are intended for adults. We don’t knowingly collect information from anyone under 18 through this website, other than information a client gives us about their own children or dependants as part of their financial planning.

20. Your data protection rights

In relation to your data, you have the right to:

  • Access the information we hold about you.
  • Have that information corrected.
  • Have it ported to another organisation.
  • Complain to Cesta.
  • Have your information erased.
  • Restrict how we process your data.
  • Object to how your data is being used.
  • Withdraw consent for how your data was previously used.
  • Complain to the Information Commissioner’s Office.

Getting a copy of what we hold

You can ask for a copy of the information we hold about you. If you’d like some or all of it, email or write to us using the contact details at the end of this notice. Where your personal data is processed by automated means, you can also ask us to move it to another organisation for their use. We have an obligation to keep your personal information accurate and up to date, so please ask us to correct or remove anything you think is wrong.

21. If you’re unhappy with how your data is handled

Please tell us first, so we have the chance to put it right. You also have the right to lodge a complaint with the supervisory authority for data protection. In the UK, that’s the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

22. Changes to this notice

We keep this privacy notice under regular review. We’ll publish any updates at www.cestafinancialplanning.co.uk or let you know when changes happen.

This privacy notice was last updated on 1 September 2026.

How to contact us

Cesta Financial Planning Ltd, 5 St John’s Lane, London, EC1M 4BH. Telephone 020 8125 4829. Email hello@cestafinancialplanning.co.uk.

Cesta Financial Planning Ltd is registered in England and Wales, company number 15755399. Registered office: 5 St John’s Lane, London, EC1M 4BH. Authorised and regulated by the Financial Conduct Authority, Financial Services Register number 1019862.

Cesta Financial Planning
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.