PRIVACY NOTICE

Confidentiality and data protection

It should go without saying that we take confidentiality very seriously and will always respect and protect your privacy and the data we hold.

Introduction

ContinuityPoint is a trading style of Active Business Protection Limited (“we”, “us”, “our”).


Active Business Protection Limited is the controller of the personal information described in this Privacy Notice and is responsible for deciding how and why your personal information is used.


We are an appointed representative of Active Mortgage Services Limited, which is authorised and regulated by the Financial Conduct Authority, reference number 473140.


This Privacy Notice explains how we collect, use, share, retain and protect personal information across our services, website and professional business activities.

Who This Applies To

This Privacy Notice applies to:


  • Visitors to our website.

  • Individuals who are our clients, prospective clients or former clients and their representatives.

  • Directors, shareholders, partners, members and employees of our clients and prospective clients.

  • Individuals named, or to be named, on an insurance policy, will, trust, shareholder agreement, cross-option agreement, power of attorney or other document relevant to the services we provide or coordinate.

  • Professional advisers, introducers and other business contacts.

  • Prospective professional introducers and other professional contacts with whom we may seek to establish a business relationship.

Information We Collect

The personal information we collect depends upon our relationship with you and the services or activities involved.


This may include your name, address, email address, telephone numbers, date of birth, National Insurance number, passport details, identification documents and information about your employment, business interests, directorships or shareholdings.


Where relevant to the services we provide, we may also collect information about your income and expenditure, assets and liabilities, insurance policies, professional advisers, will, powers of attorney and other legal or financial arrangements.


We may need to collect information about close family members and dependants where this is relevant to the services we provide.


Where you are a professional adviser, business contact or prospective professional introducer, we may process limited professional information including your name, organisation, professional role, business email address, business telephone number, publicly accessible professional profile and information about your professional responsibilities relevant to our reason for contacting you.


We seek to collect and use only the personal information reasonably necessary for the relevant purpose.

Special Category Data

In delivering our services, we may need to collect and process special-category personal data, principally medical and health information required for insurance underwriting, claims or complaint resolution with insurers.


We only process special-category personal data where we have identified an appropriate lawful basis under Article 6 UK GDPR and an applicable condition under Article 9 UK GDPR and the Data Protection Act 2018.


Where our processing requires explicit consent, we obtain that consent before processing the information.


We apply additional safeguards to special-category information, including appropriate encryption, restricted access and secure storage.


We do not use health or other special-category information for marketing or professional-introducer acquisition.


Special-category information may occasionally arise incidentally within an approved recording or transcription service, such as Littlebird, where health or other sensitive information is mentioned during a meeting or conversation. Where this occurs, we process that information only where the appropriate Article 6 lawful basis and Article 9 condition have been established and appropriate contractual, technical and organisational safeguards are in place.


We apply data minimisation and pseudonymisation before using general-purpose AI services such as OpenAI or Anthropic and do not intentionally provide those services with information that directly identifies the individual concerned.


We do not intentionally submit identifiable special-category personal data to OpenAI or Anthropic.

How We Use Your Data

We use personal information where we have an appropriate lawful basis, including:


  • To comply with the Anti-Money Laundering Regulations and other legal obligations.

  • To take steps at your request before entering into a contract and to meet our contractual obligations to you.

  • To provide our services, including insurance advice and arrangement where applicable.

  • To comply with our regulatory duties to the Financial Conduct Authority.

  • To maintain appropriate records of our dealings and communications with you.

  • To assist us and you in resolving any dissatisfaction or complaint about our service.

  • To operate and protect our business, systems and information and to establish, exercise or defend legal rights.

  • Where appropriate, to pursue our legitimate interests in operating and developing our business, provided those interests are not overridden by your rights and interests.


Professional relationships and business development


We may process limited professional business information about professional advisers, business contacts and prospective professional introducers in order to identify and develop relevant professional relationships and communicate with people where we reasonably believe ContinuityPoint’s services may be relevant to their professional responsibilities or their clients.


Our lawful basis for this processing is our legitimate interests in developing our business and establishing relevant professional relationships.


Before relying upon legitimate interests, we consider the purpose of the processing, whether it is necessary and proportionate, and the potential effect upon the individual.


Where permitted by law, we may use business contact information for targeted professional business-to-business direct marketing. Where electronic marketing is sent to corporate subscribers, we comply with the Privacy and Electronic Communications Regulations 2003 (PECR). Where business contact information identifies an individual, UK data-protection law also applies.


If you tell us that you do not want to receive direct marketing from us, we may retain limited information on a suppression list so that we can continue to respect your request.

Use of Artificial Intelligence and Automated Tools

We use approved artificial-intelligence and AI-enabled technology to assist with aspects of our business, including research, analysis, drafting, summarisation, meeting and conversation transcription, administration, customer-relationship management and workflow support.


We remain responsible for the use of personal information within these processes. We assess the purpose of the processing, the information required, the applicable lawful basis and whether the purpose can reasonably be achieved using less personal information.


We apply data minimisation, access controls and other appropriate safeguards according to the nature of the information and the technology being used.


Littlebird


We use Littlebird as an approved recording, transcription and AI-enabled service. Littlebird may process identifiable personal information contained within recordings, transcripts and associated records on our behalf under a data-processing agreement and appropriate technical and organisational safeguards.


Littlebird does not intentionally collect or process special-category personal data. However, such information may occasionally arise incidentally during a meeting or conversation. Where this occurs, we ensure that an appropriate lawful basis under Article 6 UK GDPR and an applicable condition under Article 9 UK GDPR and the Data Protection Act 2018 have been established.


HubSpot and Breeze


We use HubSpot as our customer relationship management system and use certain HubSpot Breeze AI-enabled features to assist with managing, analysing, summarising and working with information held within our CRM.


Depending on the functionality being used and the permissions we have enabled, Breeze may process identifiable personal information held within HubSpot, including information relating to clients, prospective clients, professional contacts and business relationships.


Our HubSpot account has its Sensitive Data controls enabled. As a result, our account is opted out of HubSpot AI model training and customer data from our account is not used to train HubSpot’s AI models.


HubSpot may use approved third-party AI service providers to deliver some AI functionality. HubSpot states that those providers are not permitted to use customer data for model training and that data retention by those providers is minimised, including zero-data-retention arrangements where available.


We control which Breeze functionality is enabled and the information made available to it, and we apply appropriate access controls and human oversight.


We do not rely upon Breeze to make solely automated decisions about individuals which produce legal effects or similarly significant effects.


OpenAI and Anthropic


We may use approved services provided by OpenAI and Anthropic to assist with research, analysis, drafting, summarisation and similar professional or administrative tasks.


Before information is submitted to these services, we pseudonymise the material to remove or replace direct identifiers and keep information capable of reconnecting the material to an individual separately from the information provided to the AI service.


We do not intentionally provide OpenAI or Anthropic with information that directly identifies our clients or other individuals when using these services.


Pseudonymisation is an additional privacy and security safeguard. Where the information remains capable of being attributed to an individual using additional information held by us, we continue to treat it as personal data and apply the requirements of UK data-protection law.


We do not intentionally submit identifiable special-category personal data to OpenAI or Anthropic. Where material concerning a client is used with those services, identifying information is removed or replaced before processing and the information required to reconnect the material with the individual is retained separately by us.


Human Oversight


AI-generated material is used as an aid rather than as an unquestioned source of fact or professional judgement. Material outputs relevant to our clients or regulated activities are subject to appropriate human review.


We do not make decisions about individuals based solely on automated processing where those decisions would produce legal effects or similarly significant effects.


Where an AI or technology provider processes personal information on our behalf, we assess matters including its data-protection arrangements, security, contractual safeguards, subprocessors, retention and deletion arrangements, support for data-subject rights and international data transfers.


Personal information processed through an AI-enabled service may, depending upon the service and task, exist within recordings, transcripts, prompts, uploaded material, CRM records, generated outputs or associated service records. We take this into account when responding to applicable data-protection rights.

How We Collect Your Data

We may obtain personal information directly from you, including when you contact us, complete a form, attend a meeting, apply for insurance or otherwise provide information to us.


We may also obtain information from insurers, underwriters, professional advisers, introducers, identity-verification or fraud-prevention services, regulatory sources, service providers and other people or organisations involved in providing or coordinating services.


Where you are a professional adviser, business contact or prospective professional introducer, we may obtain professional business information from publicly accessible sources including Companies House, the website of your employer or professional firm, professional directories and publicly accessible professional networking profiles.


We may also obtain or verify professional business contact information using business research, search and data-enrichment providers.


Where we obtain your personal information from someone other than you, we provide the privacy information required by data-protection law within the applicable period unless an exemption applies.

Data Sharing and Disclosure

We will never sell your personal information or share it with a third party for that third party’s own marketing purposes.


To comply with applicable financial-crime requirements, we may share information with third parties used to verify identity or perform other anti-money-laundering or fraud-prevention checks.


To meet our contractual, legal and regulatory obligations and provide or coordinate our services, we may share relevant information with:


  • Active Mortgage Services Limited in its capacity as our FCA principal.

  • Insurers, underwriters and insurance-service providers.

  • Accountants, solicitors and other professional advisers or specialists involved in providing or coordinating services.

  • Customer-relationship-management, communications, document-management, information-technology and other service providers processing information for us.

  • Identity-verification, fraud-prevention and regulatory service providers.

  • Regulators, public authorities, courts or law-enforcement organisations where required or permitted by law.

  • Another party where you ask or authorise us to disclose information.

  • Littlebird, where it provides approved recording, transcription and AI-enabled services on our behalf.

  • HubSpot, which provides our customer-relationship-management system, communications functionality and Breeze AI-enabled services and may process identifiable CRM information on our behalf.

  • OpenAI and Anthropic, where approved AI services are used with material that has first been pseudonymised in accordance with our internal controls.


Where another organisation processes personal information on our behalf, we take appropriate steps to ensure suitable contractual, confidentiality and data-protection arrangements are in place.


Some organisations and technology providers we use may process personal information outside the United Kingdom. Where this involves a restricted transfer, we use an appropriate mechanism permitted by UK data-protection law, which may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. This includes transfers arising from our use of technology and AI-enabled service providers where their infrastructure, group companies or subprocessors are located outside the United Kingdom.


You can contact us for further information about safeguards applicable to a particular international transfer.

Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, regulatory, contractual and record-keeping requirements.


Information relating to regulated financial-services activities will be retained for the period required or appropriate under applicable Financial Conduct Authority and other regulatory requirements.


When deciding how long information should be retained, we consider its nature and sensitivity, why it was obtained, whether we continue to have a relationship with you, applicable legal and regulatory requirements, relevant limitation periods and whether continued retention is necessary to establish or defend legal rights.


Professional-prospect information will not be retained indefinitely merely because it may be useful for future marketing. We periodically review whether there remains a legitimate reason to retain it.


Where you object to direct marketing, we may retain the minimum information necessary on a suppression list for as long as necessary to ensure that your objection continues to be respected.


Where personal information has been processed using an external technology or AI-enabled service, our retention and deletion processes take account of relevant recordings, transcripts, prompts, uploaded material, CRM records, generated outputs and provider systems to the extent that those records contain personal information and are within our control.

Your Rights

You have rights under data-protection law which, depending upon the circumstances, may include:


  • The right to access your personal information.

  • The right to correct inaccurate or incomplete information.

  • The right to request erasure in certain circumstances.

  • The right to restrict processing in certain circumstances.

  • The right to object to processing based upon legitimate interests.

  • The right to object at any time to processing for direct-marketing purposes.

  • The right to data portability where applicable.

  • The right to withdraw consent where processing is based upon consent, without affecting processing carried out before withdrawal.

  • The right to complain to the Information Commissioner’s Office.


These rights are not absolute in every circumstance. We may sometimes be entitled or required to retain or continue processing information despite a request.


Please contact us if you wish to exercise any of these rights.


Your right to object to direct marketing


You have an absolute right to object at any time to our use of your personal information for direct-marketing purposes.


You can exercise this right by replying to any marketing email, using any unsubscribe facility provided, or contacting us using the details below.


If you object, we will stop using your personal information for direct marketing. We may retain the minimum information necessary on a suppression list so that we can continue to respect your request and do not inadvertently contact you again for direct-marketing purposes.

How We Protect Your Data

We implement appropriate technical and organisational measures designed to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction, alteration or disclosure.


These measures include:


  • Encrypted storage and secure transfer where appropriate.

  • Access controls and role-based permissions.

  • Additional controls for particularly sensitive information, including medical and health information.

  • Appropriate system and device security.

  • Backup and recovery arrangements.

  • Procedures for identifying and responding to data-security incidents.

  • Regular review of our data-protection practices.

Updates

We may update this Privacy Notice to reflect changes in our activities, services, technology, legal requirements or data-protection practices.


The current version will be published on our website. Where a change materially affects how we use personal information, we will take appropriate steps to bring that change to the attention of affected individuals.


Last updated: 2 October 2026

Contact and Complaints

For questions about this Privacy Notice, to exercise your data-protection rights, or to make a complaint about how we have used your personal information, contact:


Active Business Protection Limited / ContinuityPoint
4 Highcliff View
Westgate
Guisborough
TS14 6AY


Email: hello@continuitypoint.co.uk
Telephone: 01287 555 455


Our ICO Registration Reference is ZB566050.


If you make a data-protection complaint to us, we will acknowledge and investigate it in accordance with our data-protection complaints procedure and provide an outcome without undue delay.


You also have the right to complain to the Information Commissioner’s Office:


Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF


Telephone: 0303 123 1113