Version: Draft 0.1 · 1 August 2026
These Adviser Terms of Business ("Adviser Terms") and the Data Processing Agreement in Part B (the "DPA") together govern the provision of the Wealth365 platform (the "Platform") by Wealth365 Ltd, a company registered in Northern Ireland (company number NI740485) with its registered office at 19 Milltown Street, Warrenpoint, Co. Down BT34 3PS ("Wealth365", "we", "us"), to a professional adviser firm (the "Firm", "you"). The consumer Terms and Conditions apply to individual consumer accounts and do not govern the Firm's use of the Platform for its clients; where a Firm's client also holds their own Wealth365 login, the consumer terms govern that individual relationship separately.
For personal data of the Firm's clients that the Firm (or its staff) enters, uploads, or causes to be processed on the Platform ("Firm Client Data"), the Firm is the controller and Wealth365 is the processor. The DPA in Part B applies to all such processing. For the Firm's own account data (staff logins, billing), and for data of individuals who hold their own consumer relationship with Wealth365, Wealth365 is an independent controller as described in the Privacy Policy.
Wealth365 processes Firm Client Data for the duration of the Adviser Terms, solely to provide the Platform's financial-planning, client-management, onboarding/KYC record-keeping, meeting, and reporting features to the Firm. The categories of data subjects, categories of personal data, lawful-basis mapping, and retention periods are those recorded in the platform's Records of Processing Activities (processor activities register) and the data-retention schedule, copies of which are available to the Firm on request (dpo@wealth365.co.uk).
Wealth365 shall process Firm Client Data only on the Firm's documented instructions, including with regard to international transfers, unless required to do so by UK law (in which case Wealth365 shall inform the Firm of that legal requirement before processing, unless the law prohibits it). The Adviser Terms, the Firm's configuration of the Platform, and the Firm's use of Platform features constitute the Firm's documented instructions. Wealth365 shall immediately inform the Firm if, in its opinion, an instruction infringes UK GDPR.
Wealth365 ensures that persons authorised to process Firm Client Data are bound by contractual or statutory obligations of confidentiality, and that access is restricted on a need-to-know basis.
Wealth365 implements appropriate technical and organisational measures, including: TLS encryption in transit; field-level encryption at rest (Fernet, AES-128-CBC with HMAC-SHA256) for sensitive personal and financial fields; bcrypt password hashing; PII scrubbing before any error-monitoring event leaves the environment; append-only audit logging; and access controls. Section 10 of the Privacy Policy describes these measures.
Wealth365 shall notify the Firm without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Firm Client Data, providing the information described in Article 33(3) UK GDPR so far as available (nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken or proposed). Wealth365's internal incident-response policy operationalises the Article 33/34 decision path. As between the parties, the Firm is responsible for any notification to the ICO or to data subjects in respect of Firm Client Data; Wealth365 will provide reasonable cooperation.
Wealth365 shall make available to the Firm information reasonably necessary to demonstrate compliance with this DPA (including the ROPA extract for processor activities, retention schedule, sub-processor list, and security summaries), and shall allow for and contribute to audits, including inspections, conducted by the Firm or its mandated auditor — no more than once per 12 months except following a personal data breach, on 30 days' notice, during business hours, without access to other customers' data.
Routine hosting and processing take place in the EEA (covered by the UK adequacy regulations); ancillary access and specific sub-processor flows from the United States are covered by Article 46 safeguards, as described in Privacy Policy Sections 6.2 and 7. Wealth365 shall not transfer Firm Client Data outside the UK/EEA other than as described there without the Firm's prior written instruction.
Liability under this DPA is subject to the limitations in the Adviser Terms, save that nothing limits either party's liability where UK GDPR prohibits such limitation. In the event of conflict between the DPA and the Adviser Terms concerning processing of Firm Client Data, the DPA prevails.
Wealth365 Ltd — Registered in Northern Ireland, company number NI740485
19 Milltown Street, Warrenpoint, Co. Down BT34 3PS
Data protection enquiries: dpo@wealth365.co.uk