Effective Date: 24 August 2026
Clyde Resources Ltd, which uses the name “Clyde Offices” on its website and at its premises, takes privacy seriously. This Privacy Policy explains how Clyde Resources Ltd collects, uses, stores and shares personal data, including information used for identity verification and Customer Due Diligence where required.
This Privacy Policy explains how Clyde Resources Ltd processes personal data and the rights individuals have under applicable data protection law.
1. Who We Are
Clyde Resources Ltd
48 West George Street
Glasgow, G2 1BP
Company No: SC353174
Email: info@clydeoffices.co.uk
Data Controller contact: Director at Clyde Resources Ltd
For personal data processed for Clyde Resources Ltd’s own purposes, including Customer Due Diligence, account administration, billing, fraud prevention, security and legal or regulatory compliance, Clyde Resources Ltd is the Data Controller.
For some services, such as certain call answering or administrative support activities, Clyde Resources Ltd may process personal data solely on behalf of a customer. In those circumstances, the customer may be the Data Controller and Clyde Resources Ltd may act as a Data Processor in accordance with the applicable service terms.
2. What Data We Collect
We collect and process personal data depending on your relationship with us, the service requested, the checks required and the circumstances. This may include:
- Contact and account information – such as name, email address, phone number, postal address, company name and account details.
- Identity verification information – where required, this may include photo identification, proof of address, photographs, selfies, facial images, video or liveness captures, verification results, fraud indicators and related device or technical information.
- Company and ownership information – where relevant, this may include information relating to directors, Persons with Significant Control (PSCs), beneficial owners, authorised representatives and company ownership or control.
- Compliance information – where required, this may include sanctions and Politically Exposed Person (PEP) screening results, risk-assessment information, source-of-funds or source-of-wealth information, and other information reasonably required for Customer Due Diligence or enhanced checks.
- Payment and billing information – payment details are processed through third-party payment providers such as Stripe. We may retain payment references, invoices, billing records and refund records.
- Service and communications information – emails, support enquiries, telephone messages, call recordings where calls are recorded, mail-handling records, scanned mail and information supplied or generated in the course of providing administrative services.
- Website and security information – such as IP address, browser or device information, pages visited, security logs and usage information used for analytics, fraud prevention and website security.
We do not require every category of information from every customer. The information requested will depend on the service, the legal or regulatory requirements that apply, and the level of verification or due diligence reasonably required in the circumstances.
3. Where We Obtain Personal Data
We may obtain personal data:
- directly from you;
- from a person authorised to act for you or on behalf of an organisation;
- from Companies House and other public or official registers;
- from sanctions, PEP, fraud-prevention and compliance databases;
- from identity verification, payment and other service providers; and
- from correspondence, callers, mail senders or other sources connected with the services we provide, where lawful and relevant.
4. Why We Collect and Use Personal Data
We may process personal data for the following purposes, depending on the circumstances:
- to provide and administer our services, including address, mail-handling, call-answering and administrative support services;
- to carry out identity verification, Customer Due Diligence and ongoing monitoring where required;
- to carry out sanctions, PEP, fraud-prevention or other compliance checks where required;
- to prevent fraud, misuse, unlawful activity and security incidents;
- to comply with legal, regulatory, tax, accounting and record-keeping obligations;
- to manage accounts, payments, invoices, refunds, debt recovery and customer service;
- to communicate with customers and respond to enquiries, complaints, data protection requests or regulatory enquiries;
- to establish, exercise or defend legal claims; and
- to operate, protect and improve our website, systems and internal processes.
5. Legal Grounds for Processing
Under UK data protection law, the legal basis we rely on depends on the purpose and circumstances of the processing. These may include:
Legal obligation – where processing is necessary to meet applicable Customer Due Diligence, anti-money laundering, regulatory, tax, accounting or other legal requirements.
Contract – where processing is necessary to take steps at your request before entering into a contract or to provide and administer services you have requested.
Legitimate interests – where necessary for purposes such as fraud prevention, information and network security, service administration, debt recovery, business management and the establishment, exercise or defence of legal claims, provided those interests are not overridden by your rights and interests.
Consent – where we specifically rely on consent for a particular optional activity, such as certain marketing or cookie-related processing where required by law. Where processing is based on consent, you may withdraw it at any time.
Where special-category biometric information is processed for identity verification, Clyde Resources Ltd will process it only where an appropriate condition under Article 9 UK GDPR and the Data Protection Act 2018 applies.
6. Electronic Identity Verification and Customer Due Diligence
Clyde Resources Ltd is required to carry out Customer Due Diligence.
We use Didit as a specialist electronic identity verification provider. Depending on the circumstances and the checks required, Didit may process information such as identity documents, photographs, selfies, facial images, video or liveness information, device or network information, verification results and fraud indicators on our behalf.
Not every customer will be asked to provide all of these types of information. The verification process used will depend on the nature of the customer, the service requested and the checks reasonably required in the circumstances.
Where facial or other biometric information is technically processed for the purpose of uniquely identifying or verifying an individual, it may constitute special-category biometric data under UK data protection law and is subject to additional legal safeguards.
Certain identity and Customer Due Diligence information must be provided before we can activate or continue regulated services. If information reasonably required for these purposes is not provided, or if we cannot satisfactorily complete the required checks, we may be unable to provide, activate or continue the relevant service.
Automated tools may assist with document verification, facial matching, liveness checks, fraud detection and compliance screening. Where required, verification results may be reviewed by authorised personnel before a decision is made.
7. Who We Share Personal Data With
We only share personal data where necessary and lawful. Depending on the circumstances, recipients may include:
- Didit – for electronic identity verification, document verification, liveness and fraud-prevention checks where used;
- payment providers such as Stripe – for payment processing;
- accounting, CRM, communications, secure storage, hosting and operational service providers used to administer our business and services;
- professional advisers – such as accountants, solicitors, auditors or other advisers where reasonably necessary;
- government, regulatory and law-enforcement bodies – such as HMRC, the National Crime Agency, Companies House, police or other authorities where disclosure is required or permitted by law; and
- other third parties where necessary to provide a service requested by you or where you have authorised the disclosure.
We do not sell personal data. We do not provide personal data to third-party marketing companies for them to market their own products or services to you.
8. How Long We Keep Personal Data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, taking account of legal, regulatory, accounting, security and dispute-resolution requirements.
Customer Due Diligence and AML compliance records are normally retained for five years from the end of the relevant business relationship or other applicable statutory starting point. They will then be deleted unless continued retention is required or permitted by law.
Other records, including payment, accounting, contractual and correspondence records, may be retained for different periods where this is necessary to meet applicable legal obligations, manage the customer relationship or establish, exercise or defend legal claims.
Where physical mail has been scanned, customers should request the original within 14 days. After that period Clyde Resources Ltd may securely destroy the original without further notice. Physical originals may remain securely held for up to 30 days as part of our routine destruction process.
9. How We Keep Personal Data Safe and International Transfers
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or destruction. These measures include access controls, restricted staff permissions, secure systems and appropriately vetted service providers.
We use third-party systems and service providers, which may include services such as Stripe, Dropbox, Xero and Airtable, as well as other secure hosting, storage, communication and operational providers. We do not encourage sensitive identity documents to be sent by unprotected email and may provide secure upload or verification methods where appropriate.
Some service providers may process personal data outside the United Kingdom. Where personal data is transferred internationally, we use an appropriate transfer mechanism recognised under UK data protection law, which may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful safeguard, as applicable.
We do not publish detailed security architecture or technical configurations where doing so could itself undermine the security of our systems or those of our providers.
10. Your Rights
Depending on the circumstances, you may have the right to:
- request access to personal data we hold about you;
- ask us to correct inaccurate or incomplete personal data;
- request erasure of personal data;
- request restriction of processing;
- object to certain processing, including direct marketing;
- receive certain personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint with the UK Information Commissioner’s Office (ICO).
These rights are not absolute. In particular, Clyde Resources Ltd may be required or permitted to retain certain information notwithstanding an erasure request, including where retention is necessary for Customer Due Diligence or AML obligations, tax or accounting requirements, other legal obligations, or the establishment, exercise or defence of legal claims.
We will normally respond to a valid data protection rights request within one month, subject to any extension or exemption permitted by law.
To exercise your rights, contact us at info@clydeoffices.co.uk.
11. Communications and Direct Marketing
We may send service-related communications and, where permitted by applicable data protection and electronic marketing law, marketing or enquiry follow-up communications. You can object to direct marketing or use the unsubscribe method provided in the relevant communication at any time.
12. Cookies and Website Use
We may collect limited information when you browse our website, such as IP address, device or browser information and usage statistics, for purposes including website operation, analytics and security. Please see our Cookie Policy for further information and available choices.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal or regulatory requirements, technology or business practices. The latest version will be published at clydeoffices.co.uk/privacy-policy/. Where a change materially affects how we use personal data, we will take reasonable steps to bring the change to the attention of affected individuals where required by law.