Legal

Privacy Policy

Codecia Ltd Last updated: June 2026 UK GDPR compliant
Contents
  1. 1.Who We Are
  2. 2.Data We Collect
  3. 3.How We Use Your Data
  4. 4.Legal Bases for Processing
  5. 5.KYC, AML and Escrow Data
  6. 6.Sharing Your Data
  7. 7.International Transfers
  8. 8.Data Retention
  9. 9.Your Rights
  10. 10.Security
  11. 11.Cookies
  12. 12.Children
  13. 13.Changes to this Policy
  14. 14.Contact & Complaints

Summary: Codecia collects personal data to deliver advisory and escrow services, meet AML/KYC legal obligations, and communicate with clients and enquirers. We do not sell your data. We retain KYC records for a minimum of five years as required by the UK Money Laundering Regulations 2017. You have rights to access, correct, and in certain cases delete your data.

01

Who We Are

Codecia Ltd ("Codecia", "we", "us", "our") is a company registered in England and Wales (Company No. 07656907) with its registered address at 125 Hawfinch House, 1 Moorhen Drive, London NW9 7BX.

We are the data controller for personal data processed in connection with our advisory and paymaster/escrow services and website at codecia.com.

We can be contacted at: enquiries@codecia.com

02

Data We Collect

The personal data we collect depends on the nature of your relationship with us. We collect data through our website, by email, and through our paymaster and escrow onboarding platform.

Enquiry and Contact Data

Advisory and Transaction Data

KYC and AML Data (Paymaster & Escrow)

For paymaster and escrow transactions, we are legally required to collect and verify:

Technical and Usage Data

03

How We Use Your Data

PurposeData UsedLegal Basis
Responding to enquiries and onboarding new clientsContact and identity dataLegitimate interests / pre-contractual steps
Delivering advisory services under an engagement letterIdentity, transaction, and correspondence dataPerformance of contract
KYC and AML verification for escrow transactionsFull KYC dataset including identity documentsLegal obligation (UK MLR 2017)
Sanctions screening and PEP checksFull name, nationality, date of birthLegal obligation (UK MLR 2017 / OFSI)
Escrow account management and fund disbursementIdentity, bank account, and transaction dataPerformance of contract / legal obligation
Transaction dashboard access (OTP and IP validation)Email, IP address, session dataPerformance of contract / legitimate interests
Regulatory reporting and record-keepingKYC documents and transaction recordsLegal obligation
Fraud prevention and securityIP address, session data, identity dataLegitimate interests
Communications about your transaction or engagementContact dataPerformance of contract / legitimate interests
Improving our website and servicesTechnical and usage dataLegitimate interests
04

Legal Bases for Processing

We rely on the following legal bases under the UK GDPR when processing your personal data:

Where we process special category data (such as data that may reveal nationality or political exposure status), we rely on Article 9(2)(g) (substantial public interest — prevention of financial crime) and Article 9(2)(b) (employment and social security obligations) as applicable.

05

KYC, AML and Escrow Data

Important: Our collection of KYC and AML data is a legal obligation under the UK Money Laundering Regulations 2017. Failure to provide complete information will prevent us from opening or completing an escrow transaction.

Why we collect it

Codecia is required by law to conduct customer due diligence (CDD) on all parties to escrow and paymaster transactions. This includes verifying the identity of individuals, beneficial owners, directors, trustees, and corporate entities before receiving or releasing funds.

Enhanced Due Diligence

Transactions above £10,000 (or equivalent), transactions involving PEPs, or transactions presenting higher risk factors are subject to enhanced due diligence (EDD). This may involve requesting additional documentation, independent verification, or senior management approval.

Source of Funds

We are required to verify the legitimate origin of all funds deposited into escrow. You will be asked to provide a written narrative describing the origin of funds, supported by documentary evidence such as bank statements, sale proceeds documentation, audited accounts, or similar financial records.

IP Address and Location Logging

When you access the transaction dashboard, your IP address is recorded at login and verified on each action. This is a security measure to prevent unauthorised access to your transaction data and to ensure that actions are completed only by the party to whom they are assigned. We do not use this data for any other purpose.

Sanctions and PEP Screening

We conduct screening against OFAC, UN, EU, and FATF consolidated sanctions lists, and against PEP databases. Screening is conducted at onboarding and may be repeated periodically or when circumstances change. A match or potential match will be escalated in accordance with our internal procedures and may be reported to the National Crime Agency.

Suspicious Activity

If we have knowledge or suspicion that funds are connected to money laundering or terrorist financing, we are legally obliged to submit a Suspicious Activity Report (SAR) to the National Crime Agency. We cannot notify you if a SAR has been submitted as this may constitute "tipping off" under the Proceeds of Crime Act 2002.

06

Sharing Your Data

We share personal data only where necessary and appropriate. We do not sell your data to third parties.

We may share your data with:

All third-party data processors are subject to written data processing agreements and are required to process data only on our documented instructions.

07

International Transfers

Where your transaction involves counterparties, counsel, or financial institutions outside the United Kingdom or the European Economic Area, personal data may need to be transferred internationally to complete the transaction. Such transfers will only be made:

You may request details of the specific safeguards in place for any international transfer by contacting us at enquiries@codecia.com.

08

Data Retention

Data CategoryRetention PeriodBasis
KYC documentation and identity recordsMinimum 5 years from end of business relationshipUK MLR 2017, Regulation 40
Escrow transaction records and correspondenceMinimum 5 years from closingUK MLR 2017; limitation periods
AML screening records and SAR documentationMinimum 5 yearsUK MLR 2017; POCA 2002
Engagement letters and advisory correspondence6 years from end of engagementLimitation Act 1980 (contract claims)
Enquiry and pre-engagement data12 months from last contact if no engagement followsLegitimate interests
IP address and session logs (dashboard)12 months from transaction closeSecurity / fraud prevention
Website analytics and usage data13 monthsLegitimate interests

We may retain data beyond these periods where required by law, where proceedings are threatened or commenced, or where there is a continuing legitimate business reason. Retained data is stored securely and access is restricted.

09

Your Rights

Under the UK GDPR and the Data Protection Act 2018, you have the following rights in respect of your personal data:

To exercise any of these rights, please contact us at enquiries@codecia.com with "Data Subject Request" in the subject line. We will respond within one calendar month. We may ask you to verify your identity before processing your request.

We will not charge a fee for reasonable requests. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline to respond, with written reasons.

10

Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and, where required, notify affected individuals without undue delay.

You should immediately notify us at enquiries@codecia.com if you believe your transaction dashboard credentials have been compromised.

11

Cookies

Our website uses a small number of technically necessary cookies required for session management and security. We do not use advertising, tracking, or behavioural profiling cookies.

You may disable cookies through your browser settings, but this may prevent you from using the transaction dashboard.

12

Children

Our services are directed at businesses and adults. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have collected data relating to a child, please contact us immediately at enquiries@codecia.com and we will take steps to delete it.

13

Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or regulatory requirements. The "last updated" date at the top of this page will be revised accordingly. Where changes are material, we will notify active clients by email.

We encourage you to review this Policy periodically. Continued use of our services after changes are published constitutes acceptance of the updated Policy.

14

Contact & Complaints

If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or have a complaint about how we have handled your data, please contact us:

Data Controller
Codecia Ltd
Email
enquiries@codecia.com
Address
125 Hawfinch House, 1 Moorhen Drive, London NW9 7BX
Company Number
07656907 · Registered in England and Wales

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the supervisory authority for data protection in the United Kingdom:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Website
ico.org.uk
Helpline
0303 123 1113