Oxford Risk Ltd provides technology and analytics tools to banks, wealth managers, investment providers and financial advisers. These organisations use our tools to help assess the suitability of financial products and services for their customers and to support better financial decision-making.
We usually do not have a direct relationship with end customers. In most cases, your bank, adviser, wealth manager or investment provider decides what personal data is collected, why it is used, and how long it is kept. They are usually the controller of your personal data. Oxford Risk usually acts as their processor and processes personal data only on their instructions.
Oxford Risk Ltd is registered in England and Wales with company number 04571309. Our registered office is Camburgh House, 27 New Dover Road, Canterbury, Kent, CT1 3DN. If you have questions about this notice, you can contact us at privacy@oxfordrisk.com.
This notice is for individuals whose information may be processed through Oxford Risk tools because they are customers, prospective customers or clients of a bank, financial adviser, wealth manager, investment provider or similar intermediary. We refer to those organisations in this notice as your “adviser”.
Your adviser should provide you with its own privacy information. That privacy information should explain how it uses your personal data, the lawful basis it relies on, and how you can exercise your rights. This notice explains Oxford Risk’s role where your data is processed using our systems.
In most cases, Oxford Risk receives limited data from or on behalf of your adviser. This commonly includes a unique customer ID, together with information relevant to financial suitability, risk tolerance, investment preferences, behavioural finance, financial planning or portfolio analysis.
We do not usually receive your name, email address, postal address or other direct contact details. Where those details are provided for a particular service or deployment, we process them only as needed for that service and in accordance with the agreement with your adviser.
Some information may be anonymised before it reaches Oxford Risk. Some information may be pseudonymised, meaning that it is linked to a code or customer ID and cannot be attributed to you by Oxford Risk without additional information held separately by your adviser or another party. Pseudonymised data may still be personal data under UK GDPR, but it reduces privacy risk because Oxford Risk does not usually hold the information needed to identify you directly.
We process data to provide technology services to your adviser. These services may help your adviser assess suitability, understand financial attitudes and decision-making preferences, consider portfolio or planning information, identify areas where further advice or guidance may be appropriate, and support record keeping and compliance.
Oxford Risk does not give personal financial advice to end customers. Your adviser remains responsible for any advice, recommendation, suitability assessment or decision made about you.
Where Oxford Risk acts as a processor, your adviser determines the lawful basis for using your personal data. Oxford Risk processes the data on your adviser’s documented instructions and under a data processing agreement.
In limited cases, Oxford Risk may use de-identified, pseudonymised, aggregated or anonymous data for our own legitimate interests, such as maintaining, testing, improving and developing our products, analytics, security and service performance. Where we do this with personal data, we apply safeguards including data minimisation, pseudonymisation, access controls and aggregation where possible.
Our tools may generate scores, indicators, analysis or outputs that help your adviser understand investment preferences, risk tolerance, financial behaviour, suitability or related matters. Oxford Risk does not make investment recommendations to you and does not make solely automated decisions about you that have legal or similarly significant effects.
Your adviser may use outputs from our tools as part of its own advice process, suitability assessment or decision-making workflow. Your adviser’s privacy information should explain if and how it uses automated decision-making or profiling in relation to you.
Where we act as processor, we retain personal data for the period instructed by your adviser or required under our agreement with them. At the end of that period, we delete, return, anonymise or archive the data in accordance with the adviser’s instructions and applicable law.
Where long-term pseudonymised or anonymised information is retained for analytics, product development, longitudinal analysis or service improvement, we review the continuing need for that data and the risk of identifiability.
We may share or make data available to your adviser, authorised users of our services, hosting providers, IT support providers, security providers, professional advisers, auditors, regulators, public authorities, and other service providers who support the operation of our systems.
Where we appoint sub-processors, we put appropriate contractual, technical and organisational safeguards in place. We do not sell end customer personal data.
Our services are generally hosted in the UK, the EEA or another location agreed with your adviser. If personal data is transferred outside the UK or EEA, we use appropriate safeguards where required, such as an adequacy regulation, standard contractual clauses, an international data transfer agreement or another lawful transfer mechanism.
Under UK GDPR, you may have rights to be informed, access your personal data, correct inaccurate data, ask for data to be erased, restrict processing, object to processing, receive data in a portable format, and challenge certain automated decisions.
Because your adviser is usually the controller and usually holds the information that directly identifies you, you should normally contact your adviser first to exercise your rights. We will support your adviser in responding to rights requests where we are required to do so.
If we only hold pseudonymised data linked to a unique customer ID, we may not be able to locate information about you unless your adviser provides the relevant identifier or other information needed to match the request.
We use technical and organisational measures designed to protect data processed through our services. These measures include access controls, confidentiality obligations, secure hosting, monitoring, encryption or equivalent protections where appropriate, and separation of identifying information from other data where possible.
We use technology, including artificial intelligence, to help produce the risk profile and/or behavioural assessment associated with your account.
What we use. We use our own proprietary risk-profiling technology, built and controlled in-house. This is not a general-purpose AI chatbot or generative language model — it is a purpose-built analytical tool designed specifically to assess financial risk tolerance and behavioural characteristics.
What data it uses. The technology processes pseudonymised data derived from the information provided about you by [your adviser/financial institution] and/or information you provide directly. Pseudonymisation means your data is processed without direct identifiers such as your name or contact details attached, reducing the risk to you if the data were ever misused.
What it produces and how it's used. The output is a risk profile and/or behavioural assessment. This output is provided to your adviser as one input among others they use when forming their own professional judgement about advice or recommendations for you; no decision about you is made by the technology alone.
What we don't do. We do not use generative AI tools (such as Claude or ChatGPT) to process your personal data. Where our staff use such tools for internal business purposes, this is limited to general administrative and drafting support and does not involve your personal or pseudonymised data.
Your rights. You can find out more about the logic, significance and envisaged consequences of this processing, and about your wider data protection rights, by contacting us at privacy@oxfordrisk.com.
If you have questions or concerns about how your data is used, please contact your adviser first. You may also contact Oxford Risk at privacy@oxfordrisk.com.
You also have the right to complain to the UK Information Commissioner’s Office. The ICO can be contacted by phone on 0303 123 1113.