Privacy Policy

Last updated: 28 July 2026

1. Who We Are

Bloom is a practice management platform for UK financial advisers, operated by Arthur Browns Wealth Management Ltd (FCA 825843), registered in England and Wales. We are the data controller for personal data processed through the Bloom platform.

ICO registration:Arthur Browns Wealth Management Ltd is registered with the Information Commissioner's Office as a data controller.

Contact: For any data protection queries, contact us at privacy@bloomflow.app

2. What Data We Collect

We collect and process the following categories of personal data:

Adviser users:

  • Name, email address, phone number
  • Firm name, FCA number, role
  • Login credentials (passwords are hashed, never stored in plain text)

Client data (entered by advisers):

  • Name, date of birth, address, contact details
  • National Insurance number, tax status
  • Employment and income details
  • Financial information: pensions, investments, debts, properties, insurance policies
  • Risk profile and attitude to risk
  • Health and vulnerability information (where relevant to financial advice)
  • Meeting recordings and transcripts (where the adviser uses this feature)

3. Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Contract: Processing necessary to provide the Bloom platform to adviser users and to manage client relationships
  • Legal obligation: FCA regulatory requirements including record-keeping under SYSC 9, COBS 16, MiFID II (5-7 year retention)
  • Legitimate interest: Platform improvement, analytics, security monitoring
  • Consent: Marketing communications (you can unsubscribe at any time)

4. Where We Store Your Data

Our primary data stores are in the United Kingdom (AWS eu-west-2, London) through our technology partners:

  • Supabase (database and authentication) — London, UK (eu-west-2)
  • Vercel (application hosting and serverless functions) — London, UK (lhr1)

Some specific features involve transfers outside the UK: AI-assisted drafting and fact extraction (Anthropic, US) and meeting transcription (OpenAI, US), as set out in the sub-processor table below. These transfers are safeguarded by Standard Contractual Clauses with the UK Addendum incorporated in each provider's data processing agreement. If you do not use those features, that data is not sent.

5. Sub-Processors

We use the following third-party services to operate Bloom:

ServicePurposeLocation
SupabaseDatabase, authentication, file storageLondon, UK
VercelApplication hosting, serverless functionsLondon, UK
Anthropic (Claude AI)AI-assisted drafting and fact extraction. Data sent includes the client information the feature needs (e.g. the facts a letter is drafted from). Not used to train Anthropic's models.US (SCCs + UK Addendum)
OpenAI (Whisper)Meeting transcription. Not used to train OpenAI's models.US (SCCs + UK Addendum)
Recall.aiMeeting recording bot (joins video meetings when recording is enabled)US (SCCs + UK Addendum)
ResendTransactional email (invites, notifications, signing requests)US/EU
PostHogProduct analytics; session replay for consenting test users onlyUS/EU
SentryError monitoringUS/EU
XeroAccounting integration (if enabled)UK/EU

6. How Long We Keep Your Data

We retain data for as long as necessary to provide our services and meet regulatory requirements:

  • Client financial records: Minimum 7 years from the end of the advice relationship (FCA requirements)
  • Suitability letters and advice records: Minimum 5 years (MiFID II)
  • Meeting recordings and transcripts: Retained until deleted by the adviser, subject to regulatory minimums
  • Account data: Retained while your account is active, then deleted within 90 days of account closure (unless regulatory retention applies)

7. Your Rights

Under UK GDPR, you have the right to:

  • Access — Request a copy of the personal data we hold about you (Subject Access Request). We will respond within 30 days; where we need to verify your identity or ask you to clarify your request, the time spent waiting for your reply pauses that deadline.
  • Rectification — Ask us to correct inaccurate data
  • Erasure — Ask us to delete your data (subject to FCA retention requirements)
  • Portability — Request your data in a machine-readable format
  • Restriction — Ask us to limit how we process your data
  • Objection — Object to processing based on legitimate interest

To exercise any of these rights, email privacy@bloomflow.app. If you are not satisfied with our response, see the complaints section below.

8. Complaints

If you have a concern about how we handle personal data, you can complain to us directly. Email privacy@bloomflow.app with the subject line “Data protection complaint”. We will acknowledge your complaint within 30 days (our target is 5 working days), investigate it, and respond without undue delay — our target is within 30 days of acknowledgement, and we will tell you if a complex complaint needs longer. Our Data Protection Complaints Procedure explains the process in full. Making a complaint will never affect the service you or your firm receive from us.

You also have the right to complain at any time to the Information Commissioner's Office (ICO) — 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

If you are a client of a financial advice firm that uses Bloom, complaints about the advice itself go to your advice firm under its FCA-regulated complaints process; this procedure covers how personal data is handled on the platform.

9. Security

We take the security of your data seriously:

  • All data is encrypted in transit (TLS/HTTPS) and at rest (AES-256)
  • Every request is authorised server-side against the requesting user's firm and role, with automated tests enforcing that coverage across all API routes
  • Passwords are hashed using bcrypt
  • Access to production systems is restricted and logged
  • We use static IP addresses for platform integrations to enable IP whitelisting

10. Data Breaches

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and notify affected individuals without undue delay.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of any material changes by email. The latest version will always be available at this page.