Legal
Privacy notice
We built Lombard Private to need as little personal data as possible. This notice explains the little we do process, why we process it, how long we keep it and the rights you have over it.
Last updated 9 October 2026
In brief
We never ask for your name, identity documents, email address or phone number. Our website sets no cookies, runs no analytics and our servers do not record IP addresses. The only name we see is the beneficiary of the bank account you ask us to pay, because a bank transfer requires one.
Who is responsible for your data
The controller of the personal data described in this notice is Lombard Private. You can contact us about your data at any time by secure message from your client area, choosing the topic “Privacy”.
What we process
Depending on how you use our services, we process the following data:
| Data and source | What it includes |
|---|---|
| AccountGenerated when you open and use your account | Your 16-digit account number, a one-way hash of your password (never the password itself), the data needed to verify a passkey or an authenticator app if you add one, and the date and time of your sign-ins and open sessions, so that you can review and close them. |
| Payout detailsProvided by you | The name of the beneficiary, the account number or IBAN, the bank identifier (such as the BIC or sort code) and the bank’s country, as required by the payment system. |
| Loans and paymentsCreated as you use our services | Loan terms, amounts drawn and repaid, interest, fees, margin calls, liquidations, payment references and statements. |
| Blockchain dataProvided by you and recorded on public blockchains | The deposit address of each loan, the transactions crediting or returning collateral, and the return addresses you designate. |
| MessagesProvided by you | The content of your secure messages with our advisors, including complaints and requests. |
You do not have to give us any information that is not needed for the service you request. Do not include unnecessary personal information in your messages.
What we do not collect
- Identity documents, selfies or video calls, date of birth or home address.
- Email addresses and telephone numbers.
- Credit checks, payslips or information from credit reference agencies.
- IP addresses: our servers do not record them.
- Cookies, analytics, advertising identifiers or tracking pixels, on our website or through third parties. See our no-tracking statement.
We do not sell personal data, and we do not use it for advertising or marketing profiles.
Why we process it, and on what basis
| Purpose | Legal basis |
|---|---|
| Opening and running your account; making, managing and closing loans; paying loans and receiving repayments; holding and returning collateral; alerts, margin calls and liquidations; answering your messages | Performance of the contract with you |
| Protecting your account and our services against unauthorised access, fraud and attacks | Our legitimate interest in the security of our services and of our clients’ assets; legal obligations where they apply |
| Keeping accounting records, complying with sanctions laws and answering lawful requests from authorities | Compliance with our legal obligations |
| Handling complaints and establishing, exercising or defending legal claims | Our legitimate interests; legal obligations where they apply |
Automated decisions
Early warnings, margin calls and liquidations are triggered automatically when your loan-to-value reaches the thresholds set out in your loan and pledge agreement. This automation is necessary to perform the agreement, and it applies the same published thresholds to every loan. You can ask an advisor to explain any decision taken on your loan and to review it.
Who receives it
We share personal data only where it is necessary, with:
- the banks and payment service providers that execute your payouts and repayments, which receive the payment details and amounts;
- trading venues or liquidity providers, only when collateral is sold in a liquidation, and only the transaction data needed for the sale;
- the providers that host and operate our infrastructure, acting on our instructions under contracts that protect your data;
- our professional advisers, such as auditors and lawyers, who are bound by confidentiality;
- public authorities and courts, when the law requires us to disclose data to them;
- a successor, if all or part of our business is transferred, subject to this notice.
International transfers
Some recipients may be located in other countries, including outside the European Economic Area or the United Kingdom. Where data protection law requires it, we transfer data only with appropriate safeguards, such as an adequacy decision or standard contractual clauses approved by the competent authorities.
How long we keep it
We keep your data for as long as your account is open and you have loans with us. After that, we keep the records we must keep for the periods required by the accounting, tax and other laws that apply to us, and for as long as necessary to establish, exercise or defend legal claims. Session and security records are kept for a limited period only. When data is no longer needed, we delete it or anonymise it.
Public blockchains
Deposits and returns of collateral are recorded on public blockchains, which anyone can consult and which nobody can modify. We cannot erase or rectify information recorded on a blockchain. Addresses are not names, but they can sometimes be linked to a person by analysing transactions; consider this when you choose the addresses you send collateral from and to.
Your rights
Subject to the conditions and exceptions set by law, you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data rectified, for example your payout details;
- have your data erased, when we no longer need it or no longer have a lawful basis to keep it;
- restrict the processing of your data, or object to processing based on our legitimate interests;
- receive the data you provided to us in a structured, commonly used and machine-readable format (portability);
- not be subject to a decision based solely on automated processing that significantly affects you, except where it is necessary for the contract, and in that case obtain human review.
How to exercise your rights
Send your request by secure message from your client area, choosing the topic “Privacy”. Because we do not know who you are, signing in to your account is how we verify that a request comes from you: we cannot act on requests about an account that are made by any other means. If you have lost access, restore it with your recovery kit first.
We answer within the time limits set by data protection law, generally one month, which can be extended where a request is complex; we will tell you if that is the case. Exercising your rights is free of charge.
Complaints to a supervisory authority
If you believe we have not handled your data lawfully, you may lodge a complaint with the data protection supervisory authority of the country where you live or work, or where the alleged infringement took place. We would appreciate the opportunity to address your concern first, through your client area.
Security
Our website and client area are served only over encrypted connections. Passwords are stored as one-way hashes, and access to personal data within Lombard Private is limited to the people who need it for their work. No system is perfectly secure: keep your own credentials and recovery kit safe, and read our account protection guidance.
Minors
Our services are reserved for adults. We do not knowingly process data relating to anyone under 18.
Changes to this notice
We may update this notice to reflect changes in our services or in the law. We publish each new version on this page with its date and, where a change affects you significantly, we tell you in your client area before it takes effect.