This policy describes how Prospera Investments collects, uses and protects the personal data of visitors and investors. The definitive document will be published after review under UK GDPR / Data Protection Act 2018 and Brazilian LGPD.
- Document version:
- 2026-07-draft-01
- Last reviewed:
- 2026-07-27
1. Data controller
This section is a technical draft to shape the page. The definitive wording must be approved by legal counsel before publication.
Prospera Investments — full company details are published in the site footer.
2. Data we collect
We collect only the data required to respond to enquiries, deliver advisory services and meet regulatory duties (KYC/AML).
- Identification data: name, email, phone, country, city.
- Professional information voluntarily provided in the investment assessment.
- Anonymised browsing data, when statistical cookies are accepted.
- We never request passwords, full bank account details or account credentials.
3. Lawful basis
This section is a technical draft to shape the page. The definitive wording must be approved by legal counsel before publication.
We process personal data on the basis of pre-contractual steps, legal obligations, explicit consent (for marketing) and advisory legitimate interests.
4. Purpose of processing
Data is used solely to respond to your contact, deliver the investment assessment, present opportunities, comply with regulation and, where authorised, share informative communications.
5. Retention
This section is a technical draft to shape the page. The definitive wording must be approved by legal counsel before publication.
Definitive retention periods will be confirmed by legal counsel, in line with UK accounting and anti-fraud obligations.
7. Your rights
This section is a technical draft to shape the page. The definitive wording must be approved by legal counsel before publication.
You can request access, rectification, erasure, portability, withdrawal of consent and restriction of processing at any time. Requests are handled within the applicable legal deadlines.
8. International transfers
This section is a technical draft to shape the page. The definitive wording must be approved by legal counsel before publication.
As we operate between Brazil and the United Kingdom, your data may be transferred between servers in both jurisdictions under appropriate contractual safeguards.
9. Security
We adopt reasonable technical and organisational controls: encryption in transit, role-based access control and internal audit. No system is fully invulnerable — material incidents will be communicated as required by law.
11. Changes to this policy
We may update this policy. The current version is always the one published on this page, with the date of last review shown below.
Data Protection Officer (DPO)
DPO contact details will be confirmed after legal review.
