Compliance

Data Protection Impact Assessment

A DPIA is a UK GDPR requirement (Article 35) when processing is likely to result in high risk to individuals. This template documents the AdviserFlow platform's own DPIA and provides a starting point for your firm's DPIA.

1. Description of processing

Nature: AdviserFlow captures lead enquiries, seminar registrations and referrals for UK financial advice firms; segments contacts; sends compliance-approved follow-up emails; and stores CRM notes, tasks and pipeline data.

Scope: Personal data of prospective and existing clients of participating firms (name, email, phone, enquiry notes, IP address, consent state) and of firm staff (name, email, role).

Context: B2B SaaS; each firm is data controller for its own customer records; Pinnacle Reach Limited is the processor.

Purpose: Client acquisition, compliance-aware follow-up, regulatory recordkeeping.

2. Necessity and proportionality

  • Lawful basis: consent for marketing follow-up; legitimate interests for operational messages and enquiry response; legal obligation for financial recordkeeping.
  • Data minimisation: only name, email, phone, enquiry text and consent state captured by default.
  • Retention: 12 months post-termination for account data; firm-configurable for customer records.
  • Data subjects can exercise rights at /privacy/request.

3. Risks to individuals

  • Unauthorised access to prospect data → mitigated by row-level security scoped to firm membership, encrypted transport, audit log.
  • Sending marketing without consent → mitigated by explicit consent capture (IP + timestamp) and financial-promotion approval gate on every send.
  • Cross-firm data leakage → mitigated by mandatory firm_id scoping and policy tests.
  • Data retention beyond purpose → mitigated by documented retention schedule and firm-level export/delete tooling.
  • Third-country transfers → data stored in UK/EEA managed cloud; sub-processors listed on request.

4. Measures to reduce risk

  • UK GDPR compliant consent capture (lawful basis, IP, user agent, timestamp).
  • PECR-compliant one-click unsubscribe on every marketing email.
  • Financial-promotion approval gate on every sequence step.
  • Row-level security in the database with firm-scoped policies.
  • Immutable audit log for all write operations on customer data.
  • Regular automated backups (see internal Backup & Restore Runbook).
  • Access to production data is role-scoped and logged.
  • Data subject request flow at /privacy/request.

5. Sign-off

This DPIA is reviewed at least annually and whenever the processing changes materially. Firms using AdviserFlow should complete their own DPIA covering their end-client processing.

Controller (platform): Pinnacle Reach Limited · Contact: privacy@pinnaclereach.co.uk

← Back to AdviserFlow