Privacy policy

Last updated: 19 June 2026

Introduction


Ayres Punchard Investment Management Limited is committed to protecting your privacy and handling your personal information fairly, lawfully and transparently.

This privacy policy explains how we collect, use, store, share and protect personal information about people who visit our website, contact us, become clients, receive financial planning or investment advice from us, or are otherwise connected to the services we provide.

This policy applies to personal information processed by Ayres Punchard Investment Management Limited in connection with our website, enquiries, client relationships, financial planning, investment advice, protection advice, ongoing reviews, administration, regulatory obligations and related services.

It should be read alongside any client agreement, terms of business, service agreement, suitability report, data protection notice, cookie notice, or other information we provide to you when you become a client or use our services.

Who we are


Ayres Punchard Investment Management Limited is authorised and regulated by the Financial Conduct Authority.

Ayres Punchard is a trading name of Ayres Punchard Investment Management Limited.

Company name: Ayres Punchard Investment Management Limited

Companies House number: 06746940

FCA firm reference number: 492377

Registered office: Tudor Mead, Newport Road, Niton, Isle of Wight, PO38 2DF

Telephone: 01983 730 755

Email: chriswelsford@ayrespunchard.co.uk

For data protection purposes, Ayres Punchard Investment Management Limited is the data controller for the personal information described in this policy. This means we decide how and why your personal information is used.

Data protection contact


If you have any questions about this privacy policy, how we use your personal information, or how to exercise your data protection rights, please contact:

Chris Welsford

Ayres Punchard Investment Management Limited

Tudor Mead, Newport Road, Niton, Isle of Wight, PO38 2DF

Email: chriswelsford@ayrespunchard.co.uk

Telephone: 01983 730 755

If we appoint a statutory Data Protection Officer in the future, we will update this policy with the relevant details.

Personal information we collect


The personal information we collect depends on your relationship with us and the services you ask us to provide.

We may collect and process the following categories of personal information.

1. Identity and contact details


This may include:

  • Your full name;
  • Title;
  • Date of birth;
  • Residential address;
  • Previous addresses;
  • Email address;
  • Telephone number;
  • Marital or civil partnership status;
  • Nationality;
  • Tax residency;
  • National Insurance number;
  • Identification documents, such as passport, driving licence or other proof of identity;
  • Proof of address;
  • Signatures;
  • Client reference numbers;
  • Details of attorneys, deputies, trustees, executors, beneficiaries, family members or other representatives where relevant.

2. Financial information


This may include:

  • Income;
  • Expenditure;
  • Savings;
  • Bank account details;
  • Assets;
  • Investments;
  • Pensions;
  • Protection policies;
  • Life assurance policies;
  • Debts and liabilities;
  • Tax position;
  • Capital gains information;
  • Inheritance tax information;
  • Estate planning information;
  • Existing financial products;
  • Investment platform or provider details;
  • Contribution history;
  • Withdrawal history;
  • Investment objectives;
  • Investment time horizon;
  • Attitude to risk;
  • Capacity for loss;
  • Knowledge and experience of financial products;
  • Source of funds and source of wealth;
  • Information needed for anti-money laundering checks.

3. Advice and service information


When we provide financial planning, investment advice, protection advice, ongoing service or other related services, we may collect and create information including:

  • Your goals, needs and objectives;
  • Your personal and financial circumstances;
  • Fact-find information;
  • Meeting notes;
  • Call notes;
  • Correspondence;
  • Suitability assessments;
  • Suitability reports;
  • Review documents;
  • Risk-profiling records;
  • Investment recommendations;
  • Financial planning assumptions;
  • Cashflow planning information;
  • Vulnerability assessments, where relevant;
  • Client classification records;
  • Records of instructions you give us;
  • Records of services provided;
  • Copies of forms and applications;
  • Provider correspondence;
  • Compliance records;
  • Complaint records;
  • File review records.

4. Special category personal information


In some cases, we may need to process information that receives extra protection under data protection law. This is known as special category personal information.

This may include:

  • Health information;
  • Medical information;
  • Information about disability or vulnerability;
  • Information about mental capacity, where relevant;
  • Information about care needs;
  • Information about life expectancy, where relevant;
  • Other sensitive personal circumstances that are relevant to the advice or service being provided.

This type of information is most likely to be relevant where we are arranging protection, life assurance, health-related insurance, later-life planning, vulnerability support, care-fee planning, estate planning, or where your health or personal circumstances affect the advice we provide.

We will only process special category personal information where we have both:

  • A lawful basis under UK GDPR; and
  • A specific special category condition under UK GDPR and the Data Protection Act 2018.

Where appropriate, we may ask for your explicit consent to process this information. In other cases, we may process it where necessary for legal claims, substantial public interest reasons, insurance purposes, or another condition permitted by law. We will explain this to you where it is relevant.

5. Criminal offence, sanctions or fraud-related information


In limited circumstances, we may process information relating to criminal offences, fraud prevention, sanctions screening or financial crime checks. This is most likely to happen where required for anti-money laundering, counter-terrorist financing, fraud prevention, regulatory compliance or legal obligations.

We will only process this information where permitted by law.

6. Website and technical information


When you visit our website, we may collect limited technical information, depending on your browser settings, device settings and cookie preferences.

This may include:

  • IP address;
  • Browser type and version;
  • Device type;
  • Operating system;
  • Pages visited;
  • Dates and times of visits;
  • Referral source;
  • Approximate location derived from technical data;
  • Cookie preferences;
  • Information submitted through website forms.

We do not use website browsing information to make financial advice decisions about you.

How we collect your personal information


We may collect personal information in the following ways.

1. Directly from you


This includes information you provide:

  • When you contact us;
  • When you complete forms;
  • When you meet or speak with us;
  • When you email us;
  • When you use our website;
  • When you enter into a client agreement with us;
  • During reviews or ongoing service;
  • When you provide documents or evidence;
  • When you give us instructions.

2. From product providers and platforms


Where you authorise us to do so, we may obtain information from organisations such as:

  • Investment providers;
  • Pension providers;
  • Life assurance companies;
  • Protection providers;
  • Investment platforms;
  • Custodians;
  • Discretionary fund managers;
  • Fund managers;
  • Banks and building societies;
  • Insurers.

This may include policy details, valuations, transaction histories, charges, product terms, correspondence and other information needed to provide advice or service.

3. From professional advisers and representatives


Where relevant and authorised, we may receive information from:

  • Accountants;
  • Solicitors;
  • Tax advisers;
  • Trustees;
  • Attorneys;
  • Deputies;
  • Executors;
  • Family members;
  • Employers;
  • Introducers;
  • Other professional advisers.

4. From public or regulatory sources


Where appropriate, we may obtain or verify information using publicly available or official sources, such as:

  • Companies House;
  • The Financial Conduct Authority;
  • Sanctions lists;
  • Insolvency registers;
  • Fraud prevention databases;
  • Identity verification services;
  • Anti-money laundering screening services;
  • Other public registers.

5. From service providers


We may receive information from organisations that support our business operations, such as IT providers, website providers, client management systems, secure document exchange providers, compliance consultants, paraplanners and professional advisers.

How we use your personal information


We only use your personal information where we have a lawful basis to do so.

The main lawful bases we rely on are:

Contract: where processing is necessary to enter into or perform a contract with you.

Legal obligation: where processing is necessary to comply with laws or regulatory duties.

Legitimate interests: where processing is necessary for our legitimate business interests or those of a third party, provided your rights and freedoms do not override those interests.

Recognised legitimate interests: where the law specifically recognises a public interest purpose, such as certain disclosures connected with crime prevention or public tasks, where applicable.

Consent: where we ask for your consent, for example for certain marketing, certain cookies, or certain special category information.

Explicit consent: where we need your explicit consent for special category information, such as health information, where this is the appropriate condition.

Legal claims or substantial public interest: where processing is necessary for legal claims, regulatory matters, insurance purposes, financial crime prevention, safeguarding or other legally permitted reasons.

Purposes for using your personal information


We may use your personal information for the following purposes.

1. Responding to enquiries


We use your information to respond when you contact us, ask for information, request a meeting or enquire about our services.

The lawful basis is usually legitimate interests or steps prior to entering into a contract.

2. Deciding whether we can provide services to you


We use your information to understand your needs, confirm whether our services are suitable for you, carry out initial checks, and decide whether we can act for you.

The lawful basis is usually steps prior to entering into a contract, contract, legitimate interests, or legal obligation.

3. Providing financial planning and investment advice


We use your information to understand your personal and financial circumstances, assess your objectives, assess your attitude to risk and capacity for loss, consider suitable products or strategies, and provide regulated advice.

The lawful basis is usually contract, legal obligation and legitimate interests.

4. Providing ongoing service and reviews


Where you have agreed an ongoing service with us, we use your information to provide reviews, update your circumstances, assess whether your arrangements remain suitable, provide agreed reports and maintain contact with you.

The lawful basis is usually contract, legal obligation and legitimate interests.

5. Arranging investments, pensions, protection or other financial products


We use your information to complete applications, liaise with product providers, platforms, insurers, pension providers, discretionary fund managers and other relevant organisations.

The lawful basis is usually contract, legal obligation and legitimate interests. Where special category information is required, such as health information for protection or life assurance, we will rely on an appropriate special category condition, which may include explicit consent.

6. Verifying identity and preventing financial crime


We use your information to verify your identity, carry out anti-money laundering checks, screen for sanctions, detect fraud, prevent financial crime and comply with legal and regulatory obligations.

The lawful basis is usually legal obligation, legitimate interests, and, where applicable, recognised legitimate interests or substantial public interest.

7. Meeting FCA and other regulatory obligations


We use your information to comply with obligations imposed by the Financial Conduct Authority and other regulators. This may include maintaining records, demonstrating suitability, evidencing advice, responding to regulatory queries, supporting file checks, and cooperating with audits or reviews.

The lawful basis is usually legal obligation and legitimate interests.

8. Handling complaints and disputes


We use your information to investigate and respond to complaints, data protection complaints, legal claims, regulatory enquiries and disputes.

The lawful basis is usually legal obligation, legitimate interests, and, where relevant, legal claims.

9. Business administration and record keeping


We use your information for administration, accounting, invoicing, operational management, management information, professional advice, internal reporting, compliance monitoring and business continuity.

The lawful basis is usually contract, legal obligation and legitimate interests.

10. Maintaining security


We use information to protect our systems, client files, communications, website, networks and business from misuse, cyber risk, fraud, unauthorised access or other threats.

The lawful basis is usually legitimate interests and legal obligation.

11. Website operation and improvement


We use limited technical and cookie-related information to operate our website, remember cookie preferences, understand how visitors use the website, improve website performance, and keep the website secure.

The lawful basis may be legitimate interests or consent, depending on the type of cookie or technology used. Where consent is required, we will ask for it before setting the relevant cookie or similar technology.

12. Service communications


We use your contact details to communicate with you about our services, your financial arrangements, reviews, regulatory matters, documents, deadlines, administration and other matters relevant to the service we provide.

The lawful basis is usually contract, legal obligation and legitimate interests.

13. Marketing communications


We do not sell your information and we do not share your information with third parties for their own marketing purposes.

We will only send direct marketing communications where permitted by law. Where consent is required, we will ask for your consent. You can change your marketing preferences or object to marketing at any time by contacting us.

Service communications, regulatory communications and communications necessary to provide agreed services are not treated as marketing.

If you do not provide personal information


We need certain personal information to provide regulated financial advice and related services.

If you do not provide information we reasonably require, we may be unable to:

  • Respond fully to your enquiry;
  • Assess whether our services are suitable for you;
  • Provide advice;
  • Arrange financial products;
  • Complete identity checks;
  • Comply with anti-money laundering requirements;
  • Meet our FCA obligations;
  • Continue providing an ongoing service.

We will tell you where information is required and the likely consequences of not providing it.

Who we share your personal information with


We only share personal information where necessary, lawful and proportionate.

We may share your information with the following categories of recipients.

1. Financial product providers and platforms


This may include:

  • Investment providers;
  • Pension providers;
  • Life assurance companies;
  • Protection providers;
  • Investment platforms;
  • Custodians;
  • Discretionary fund managers;
  • Fund managers;
  • Banks and building societies;
  • Insurers.

2. Professional advisers and representatives


Where relevant, we may share information with:

  • Accountants;
  • Solicitors;
  • Tax advisers;
  • Trustees;
  • Attorneys;
  • Deputies;
  • Executors;
  • Family members or representatives you authorise;
  • Other professional advisers involved in your affairs.

3. Regulatory and public authorities


We may share information with:

  • The Financial Conduct Authority;
  • The Financial Ombudsman Service;
  • The Information Commissioner’s Office;
  • HM Revenue & Customs;
  • Law enforcement agencies;
  • Courts and tribunals;
  • Fraud prevention agencies;
  • Anti-money laundering bodies;
  • Sanctions authorities;
  • Other public authorities where required by law.

4. Service providers who support our business


We may use carefully selected service providers, including:

  • IT providers;
  • Cloud storage providers;
  • Email and communication providers;
  • Secure document exchange providers;
  • Website hosting providers;
  • Client management and back-office systems;
  • Compliance consultants;
  • Paraplanners;
  • Professional indemnity insurers;
  • Accountants;
  • Auditors;
  • Legal advisers;
  • Business continuity and data backup providers.

Where a service provider processes personal information on our behalf, we require them to protect it, keep it secure, process it only on our instructions, and not use it for their own purposes.

5. Business restructuring


If our business is sold, merged, reorganised, transferred, or if we transfer client servicing arrangements to another regulated firm, we may need to share relevant information with professional advisers, purchasers, transferees, regulators or other parties involved in the process. We will only do this where lawful and necessary.

International transfers


Some of the organisations we use may process personal information outside the UK. This may happen, for example, where cloud-based software, IT support, data hosting, email services, or international service providers are involved.

Where personal information is transferred outside the UK, we will ensure that appropriate safeguards are in place. These may include:

  • UK adequacy regulations;
  • The UK International Data Transfer Agreement;
  • The UK Addendum to the EU Standard Contractual Clauses;
  • Binding corporate rules;
  • Contractual protections;
  • Transfer risk assessments;
  • Another lawful transfer mechanism permitted under UK data protection law.

You can contact us if you would like more information about the safeguards used for international transfers.

How long we keep your personal information


We keep personal information only for as long as necessary for the purposes for which it was collected, including to meet legal, regulatory, accounting, reporting, complaint-handling and FCA obligations.

Because we provide regulated financial services, we are required to keep certain records for specified periods. These periods vary depending on the type of service, product, advice, transaction and regulatory requirement.

In general:

  • Enquiry records may be kept for a limited period after the enquiry unless you become a client;
  • Client identity, advice, suitability, transaction and service records will usually be kept for at least the minimum period required by FCA rules and other legal obligations;
  • Records relating to ongoing client relationships will usually be kept for the duration of the relationship and for a further period after the relationship ends;
  • Records connected with complaints, disputes, potential claims, regulatory enquiries, long-term products, pensions, investments, protection policies or legal obligations may be kept for longer where necessary;
  • Website technical data and cookie information will usually be kept for shorter periods, depending on the type of cookie or technology used;
  • Accounting and business records will be kept for the period required by tax, company law and accounting obligations.

We maintain a retention schedule to help us decide how long different categories of information should be kept. When information is no longer required, we will securely delete, anonymise or archive it in accordance with our procedures.

How we protect your personal information


We take the security of personal information seriously and use appropriate technical and organisational measures to protect it.

These may include:

  • Access controls;
  • Password protection;
  • Multi-factor authentication where appropriate;
  • Encryption where appropriate;
  • Secure storage;
  • Secure backups;
  • Secure disposal procedures;
  • Staff confidentiality obligations;
  • Data protection training;
  • Limited access on a need-to-know basis;
  • Supplier due diligence;
  • Contractual controls with service providers;
  • Monitoring and review of security arrangements;
  • Procedures for managing personal data breaches.

Your information may be accessed by advisers, support staff, senior managers, compliance consultants, paraplanners and other authorised people where necessary to provide our services, comply with regulatory obligations, manage the business, or review the quality of advice.

Information transmitted over the internet cannot be guaranteed to be completely secure. We will take reasonable steps to protect your information once we receive it. You should also take care when sending sensitive information electronically and use secure methods where available.

If we become aware of a personal data breach that creates a risk to your rights and freedoms, we will manage it in accordance with our legal obligations. Where required, we will notify the Information Commissioner’s Office and affected individuals.

Communications with you


We will contact you using the details you provide and in the way we agree with you where possible.

This may include:

  • Email;
  • Telephone;
  • Post;
  • Video call;
  • Secure portal;
  • In-person meetings;
  • Other agreed communication methods.

We may contact you about:

  • Your enquiry;
  • Your advice;
  • Your financial arrangements;
  • Reviews;
  • Service updates;
  • Documents requiring your attention;
  • Regulatory matters;
  • Deadlines, such as tax year-end planning;
  • Changes relevant to the services we provide;
  • Complaints or data protection matters.

We may also contact you between formal review dates where we believe you should be aware of something relevant to the service we provide or action you may wish to consider.

Cookies and similar technologies


Our website may use cookies and similar technologies.

Cookies are small files placed on your device. Similar technologies may include scripts, tags, pixels, local storage and device identifiers.

We may use cookies and similar technologies to:

  • Make the website work properly;
  • Remember your cookie preferences;
  • Improve website performance;
  • Understand how visitors use the website;
  • Maintain website security;
  • Improve user experience;
  • Provide relevant website functionality.

Some cookies are strictly necessary for the website to function and can be used without consent. Some low-intrusion analytics or functionality cookies may also be used without consent where permitted by law, provided we give clear information and appropriate controls.

For non-essential cookies that require consent, such as certain analytics, advertising, behavioural tracking or profiling cookies, we will ask for your consent before setting them. You can change your cookie preferences at any time using the cookie settings available on our website.

If you disable cookies, some parts of the website may not work as intended.

Our cookie information should identify the cookies we use, what they do, how long they last, and how you can manage your preferences.

Website profiling and analytics


We may use website analytics to understand how visitors use our website and to improve its content, structure and performance.

We do not use website browsing behaviour to make financial advice decisions about you.

We do not use website analytics to decide your suitability for investments, pensions, protection products or any other regulated financial product.

If we use cookies or similar technologies that create a visitor profile, recognise returning visitors, track behaviour across pages, or monitor engagement, we will explain this clearly in our cookie information and obtain consent where required.

Financial advice profiling and risk assessment


As part of providing regulated advice, we may assess your attitude to risk, capacity for loss, investment experience, objectives, needs and personal circumstances.

This is not website behavioural profiling. It is part of the financial advice process and is used to help us assess suitability and provide appropriate advice.

Any risk-profiling tools, questionnaires, cashflow models or planning tools we use are designed to support adviser judgement. We do not rely solely on automated processing to make significant financial advice decisions about you.

Automated decision-making


We do not make decisions that have a legal or similarly significant effect on you based solely on automated processing.

Where we use tools, systems, calculators, risk questionnaires, provider systems or financial planning software, these support human review and adviser judgement. A qualified person remains involved in the advice process.

If this changes in the future, we will update this policy and provide the information required by law.

Your data protection rights


You have rights under data protection law. These rights may be subject to limitations, particularly where we have legal or regulatory obligations to retain information.

Your rights include the following.

Right of access


You can ask for a copy of the personal information we hold about you.

Right to rectification


You can ask us to correct information that is inaccurate or incomplete.

Right to erasure


You can ask us to delete your personal information in certain circumstances. This right does not apply where we need to keep information to comply with legal, regulatory, FCA, complaint-handling or other legitimate obligations.

Right to restrict processing


You can ask us to restrict the way we use your information in certain circumstances.

Right to data portability


You can ask us to provide certain information in a structured, commonly used and machine-readable format, or to transmit it to another provider, where the right applies.

Right to object


You can object to processing based on legitimate interests, including direct marketing.

Where you object to direct marketing, we will stop sending it.

Where you object to other processing based on legitimate interests, we will consider your objection and stop processing unless we have compelling legitimate grounds to continue, or the processing is needed for legal claims.

Right to withdraw consent


Where we rely on consent, you can withdraw that consent at any time.

Withdrawing consent does not affect processing already carried out before consent was withdrawn. It also does not affect processing carried out under another lawful basis.

Rights relating to automated decision-making


You have rights relating to certain significant decisions made solely by automated means. We do not currently make such decisions.

How to exercise your rights


To exercise your rights, please contact:

Chris Welsford Ayres Punchard Investment Management Limited Tudor Mead, Newport Road, Niton, Isle of Wight, PO38 2DF Email: chriswelsford@ayrespunchard.co.uk Telephone: 01983 730 755

We may need to verify your identity before responding.

We will respond within the time required by law. In most cases, this will be within one month. Where a request is complex, we may be allowed to extend the response period by up to two further months. If this applies, we will tell you.

We may refuse to comply with a request where the law permits us to do so, for example where a request is manifestly unfounded or excessive, or where we must retain information for legal or regulatory reasons.

Keeping your information accurate


We rely on accurate and up-to-date information to provide appropriate advice and service.

Please tell us promptly if your contact details, personal circumstances, financial circumstances, objectives, health, family position, tax position or other relevant information changes.

Where we provide an ongoing service, we will update your information as part of the review process. However, you should still tell us about important changes between reviews.

Data protection complaints


If you are unhappy with how we have handled your personal information, please contact us first so that we can investigate and respond.

You can make a data protection complaint by contacting:

Chris Welsford Ayres Punchard Investment Management Limited Tudor Mead, Newport Road, Niton, Isle of Wight, PO38 2DF Email: chriswelsford@ayrespunchard.co.uk Telephone: 01983 730 755

We will:

  • Acknowledge your data protection complaint within 30 days;
  • Take appropriate steps to investigate it;
  • Keep you informed where appropriate;
  • Respond without undue delay;
  • Tell you the outcome of our investigation.

If your complaint also includes a wider financial services complaint, we may handle the issues together where appropriate. Where the data protection issue can be answered sooner, we will not delay the data protection response unnecessarily.

Right to complain to the Information Commissioner’s Office


You have the right to complain to the Information Commissioner’s Office if you are unhappy with how we use your personal information or how we respond to a data protection complaint.

The ICO can be contacted at:

Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF

Telephone: 0303 123 1113

You can also use the ICO’s online complaints process.

We would appreciate the opportunity to resolve your concerns first, but you are not required to contact us before contacting the ICO.

Links to other websites


Our website may contain links to websites operated by other organisations.

This privacy policy applies only to our website and our own processing of personal information. We are not responsible for the privacy practices, security or content of other websites.

You should read the privacy policy of any external website you visit.

Changes to this privacy policy


We keep this privacy policy under review and may update it from time to time.

Where we make significant changes, we will take appropriate steps to bring those changes to your attention.

The latest version will be available on our website.

Last updated: 19 June 2026