Privacy Policy
Our Commitment to Data Protection
​
RBIM Investment Management places the highest priority on safeguarding personal data. We are committed to handling information responsibly, transparently, and in compliance with all applicable laws and regulations, including:
-
UK General Data Protection Regulation (UK GDPR)
-
Data Protection Act 2018
-
FCA Handbook and Consumer Duty
-
MiFID II requirements
This policy applies to all personal data processed in connection with our services, including discretionary portfolio management, adviser engagement, recruitment, and digital interactions.
​
Who We Are
​
RBIM Investment Management Limited is an FCA-authorised discretionary fund manager.
Registered Office: Greville House, 10 Jury Street, Warwick, Warwickshire, CV34 4EW
Company No: 16333138 | FCA No: 1035655
Email: mail@rbim.co.uk
​
Categories of Data We Process
​
We collect and process personal data relevant to our operations, which may include:
-
Professional Contacts & Advisers: Name, business details, regulatory credentials, correspondence.
-
Clients (via advisers): Contact details, investment objectives, risk profiles, platform information, suitability documentation.
-
Website Users: IP addresses, cookies, browsing preferences, enquiry details.
-
Employees & Applicants: CVs, employment history, right-to-work documentation, references.
We do not collect data directly from retail clients without adviser involvement.
​
Why We Process Your Data
​
Personal data is processed for legitimate purposes, including:
-
Delivering discretionary portfolio services and investment oversight.
-
Meeting contractual obligations with advisers and platforms.
-
Complying with regulatory requirements (AML, KYC, MiFID II, FCA rules).
-
Communicating updates, reports, and service notices.
-
Enhancing website functionality and user experience.
-
Recruitment and HR administration.
Processing is always based on lawful grounds under UK GDPR, such as contractual necessity, legal obligation, legitimate interests, or consent where applicable.
​
Use of AI and Analytics
​
RBIM may employ AI-driven tools for operational efficiency and investment analysis, including:
-
Risk modelling and portfolio performance monitoring.
-
Summarising market commentary and internal reports.
-
Data tagging and sentiment analysis for internal use.
Important safeguards:
-
No automated decisions with significant legal effects.
-
AI tools operate under Data Protection Impact Assessments (DPIAs).
-
All outputs are reviewed by qualified staff.
-
Client personal data is never used to train AI models or retained by external AI platforms.
​
Sharing Your Data
​
We may share data with:
-
Your financial adviser or platform provider.
-
Third-party service providers (IT, compliance, secure storage).
-
Regulatory bodies (e.g., FCA) when required.
-
Professional advisers (auditors, legal counsel).
All third parties are bound by data processing agreements and UK GDPR standards. We do not sell or rent personal data.
​
Call Recording
​
In compliance with MiFID II and FCA COBS 11.8, RBIM records calls relating to:
-
Investment discussions and portfolio oversight.
-
Transaction instructions received via advisers.
-
Internal investment committee decisions.
Recordings are retained securely for 5 years (or 7 years where legally required) and used for compliance, quality assurance, and dispute resolution.
​
International Transfers
​
Where data is transferred outside the UK or EEA (e.g., cloud hosting), RBIM ensures:
-
Standard Contractual Clauses and UK Addendum safeguards.
-
Risk assessments and compliance checks.
​
Data Security
​
We apply robust technical and organisational measures, including:
-
Encryption of data in transit and at rest.
-
Role-based access controls.
-
Regular penetration testing and security audits.
-
Mandatory staff training on confidentiality and data protection.
​
Data Retention
​
Personal data is retained only for as long as necessary to fulfil:
-
Regulatory requirements (typically 5–7 years for investment services).
-
Contractual obligations.
-
Legitimate business needs.
After this period, data is securely deleted or anonymised.
​
Your Rights
​
Under UK GDPR, you have the right to:
-
Access and obtain a copy of your data.
-
Request correction of inaccurate information.
-
Request deletion where lawful.
-
Restrict or object to processing.
-
Request data portability (where applicable).
-
Lodge a complaint with the ICO.
To exercise your rights, contact: mail@rbim.co.uk
​
Policy Updates
This policy may be updated periodically to reflect regulatory changes or operational improvements. The latest version will always be available on our website.