Last updated: 1 July 2026

Privacy Policy

This Privacy Policy explains how Hoist Finance ("we", "us", "our") collects, uses, shares and protects personal data when you visit our website, open an account or use our investment services. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national data protection laws.

1. Who is responsible for your data

Hoist Finance acts as the data controller for the personal data described in this policy. If you have any questions about how your data is handled, or wish to exercise any of your rights, you can reach our Data Protection Officer at any time via the contact details published on our Contact page.

2. Personal data we collect

Depending on how you use our services, we collect the following categories of personal data:

  • Identity data — full name, date of birth, nationality, and government-issued identification documents provided during account verification.
  • Contact data — email address, telephone number and residential address.
  • Financial data — bank account details, source of funds, transaction history, portfolio holdings and tax identification numbers.
  • Suitability data — information about your investment knowledge, experience and objectives, collected to comply with investor protection rules.
  • Technical data — IP address, device and browser type, operating system, and log data generated when you use our website and apps.
  • Communication data — records of correspondence with our service desk, and recordings of telephone calls where required by law.

3. Why we process your data

We only process personal data where we have a legal basis to do so. In practice, this means:

  • Performance of a contract — to open and administer your account, execute your orders and hold your assets safely.
  • Legal obligations — to verify your identity, prevent money laundering and terrorist financing, report to tax authorities and comply with financial regulation.
  • Legitimate interests — to secure our platform, prevent fraud, improve our services and defend legal claims.
  • Consent — for optional communications such as newsletters and for non-essential cookies. You can withdraw consent at any time.

4. Who we share your data with

We never sell your personal data. We share it only where necessary with: regulated partners that execute, clear and settle transactions; banks and payment institutions that process deposits and withdrawals; identity verification and screening providers; IT and cloud service providers acting under strict processing agreements; and supervisory authorities, tax authorities or law enforcement where we are legally required to do so.

5. International transfers

Where personal data is transferred outside the European Economic Area, we ensure an adequate level of protection through European Commission adequacy decisions, Standard Contractual Clauses or equivalent safeguards.

6. How long we keep your data

We retain personal data for as long as your account is active and afterwards for as long as we are legally required to keep it. Financial services regulation generally obliges us to retain client records for five to ten years after the relationship ends. Data that is no longer required is securely deleted or anonymised.

7. How we protect your data

We apply technical and organisational measures appropriate to the sensitivity of the data we hold, including encryption in transit and at rest, two-factor authentication, strict access controls on a need-to-know basis, continuous security monitoring and regular independent audits.

8. Your rights

Under the GDPR you have the following rights, which you can exercise free of charge:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — request deletion of data we are not legally required to retain.
  • Restriction — limit how we process your data in certain circumstances.
  • Portability — receive the data you provided to us in a structured, machine-readable format.
  • Objection — object to processing based on our legitimate interests and to direct marketing at any time.
  • Complaint — lodge a complaint with your national data protection authority if you believe your rights have been infringed.

9. Cookies

Our website uses cookies and similar technologies. For details on what we use and how you can control them, please see our Cookie Policy.

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our services or in the law. The current version is always available on this page, and material changes will be communicated to you before they take effect.