Privacy Policy
How Aimgold Limited collects, uses, stores, shares and protects personal information.
1. About this Privacy Policy
This Privacy Policy explains how Aimgold Limited ("Aimgold", "we", "our" or "us") collects, uses, stores, shares and protects personal information when individuals interact with our products, services, websites, applications and platforms.
This Privacy Policy may apply to consumers and other individual users; business customers and their personnel; dealers, jewellers, pawnbrokers and other professional users; prospective customers; website and application users; individuals involved in transactions or services supported by Aimgold; and other individuals whose personal information we process in connection with our business.
Aimgold PRO is a product and trading name operated by Aimgold Limited. Aimgold Limited is registered in England and Wales under company number 15242854. Our registered office is 15 Half Moon Street, London, W1J 7DZ.
Aimgold is a controller of personal information where we determine the purposes and means of processing that information. Other organisations involved in providing or supporting our services may, depending on the circumstances, act as independent controllers, joint controllers or processors.
Privacy contact: Contact us
Aimgold Limited, 15 Half Moon Street, London, W1J 7DZ
ICO registration number: ZC222932
2. About Aimgold
Aimgold is a UK technology company operating within the jewellery and precious metals sector. Our purpose is to help raise standards, trust and transparency within the sector through technology, professional processes and better information and record keeping.
We provide and develop technology, products and related services for consumers, businesses and other participants within the sector. Our services may include digital platforms, applications, transaction-support services, identity verification, testing and analysis services, equipment-related services, record-management tools, customer and business support, training, integrations and other related services.
Our products and services may evolve over time. This Privacy Policy is intended to apply broadly across Aimgold's services. Where necessary, we may provide additional or more specific privacy information in connection with a particular service or processing activity.
3. Our services
Aimgold may process personal information where necessary to provide and operate its services, verify users, maintain appropriate records, support users and participating businesses, prevent and detect fraud, meet legal and regulatory requirements, and develop and improve its products and services.
Where other organisations are involved in providing a service or completing a transaction, those organisations may process personal information in their own capacity and may have their own data-protection responsibilities.
4. Information we collect
The personal information we collect depends upon how you interact with Aimgold and which services you use.
4.1 Identity and verification information
- name, date of birth, nationality
- government-issued identification and information extracted from it
- photographs, selfies and verification images
- identity-verification results, reference information, dates and status
- other information reasonably required to establish or verify identity
4.2 Contact information
- residential or business address
- email address and telephone number
- address-validation information
4.3 Financial, account and transaction information
- bank account and payment-related information
- transaction records, quotations and valuations
- payment status, invoices and billing information
- account and subscription information
Where third-party payment providers are used, Aimgold may not receive or retain complete payment-card information.
4.4 Business and professional information
Where you interact with Aimgold on behalf of a business or in a professional capacity, we may process business or trading name, company and registration information, business address, VAT information, business contact information, professional role, authorised-user and operator information, account permissions, service information, training and support information, activity associated with use of our services, and relevant compliance information.
4.5 Item, testing and analysis information
Our services may process information relating to items, materials and associated testing or analysis, including photographs and videos, descriptions, markings and hallmarks, weight and measurements, composition and purity information, testing and analysis results, X-ray fluorescence (XRF) data, density or conductivity information, valuations and quotations, and related records.
Information relating solely to an object is not necessarily personal information. However, where it is associated with an identifiable individual, account or transaction, it may form part of a personal-data record.
4.6 Photographs, video and other records
Where appropriate, we may collect photographs, video or other evidence relating to individuals, items, activities or transactions where reasonably necessary to provide our services, maintain records, prevent fraud, investigate concerns or protect users and participating businesses.
4.7 Fraud, security and compliance information
This may include identity-verification information, fraud and risk indicators, information concerning suspicious or unusual activity, account or transaction risk information, screening information where applicable, information concerning disputed or potentially unlawful activity, security information, device or account risk information, and information obtained or generated in connection with investigations, disputes or lawful enquiries.
4.8 Technical and usage information
This may include IP address, device information, operating system, browser, application version, device identifiers, log-in information, audit and activity logs, usage information, security logs, diagnostics, and crash and performance information.
4.9 Communications
We may process communications between you and Aimgold, including emails, telephone communications, in-app communications, support requests, complaints, feedback and other correspondence. Calls may be recorded where appropriate, where we have informed you and where we have an appropriate lawful basis.
4.10 Location information
Where relevant to a service, we may process approximate location derived from technical information, addresses or locations provided in connection with a service, and precise device location where you have enabled the relevant permission.
5. Identity verification and biometric processing
Aimgold may use specialist identity-verification providers to verify the identity of individuals using certain services. Identity verification may involve capturing a government-issued identity document, taking a selfie or liveness image or video, checking the authenticity of identity information, comparing an individual with the photograph contained within an identity document, and performing related verification, security and fraud checks.
Our identity-verification providers may use biometric technology as part of this process. Where biometric information is processed for the purpose of uniquely identifying an individual, it constitutes special category personal data under UK data-protection law. Where such processing occurs, Aimgold will identify an appropriate lawful basis under Article 6 UK GDPR and an appropriate condition under Article 9 UK GDPR. Where explicit consent is relied upon, it will be obtained in accordance with applicable law.
Our current identity-verification arrangements provide for biometric calculations generated for identity verification to be deleted following completion of the verification process. Separate images, verification outcomes and other records may be retained where reasonably necessary for the purposes for which they were collected.
Aimgold's current intended retention period for a seller's selfie and relevant identity-verification evidence is up to five years following the seller's last transaction, subject to applicable law and periodic review. Such information may be retained for purposes including identity and transaction records, fraud and crime prevention, investigation of suspected unlawful activity, handling disputes, responding to lawful enquiries, establishing, exercising or defending legal claims, and satisfying applicable legal or regulatory requirements.
Different retention periods may apply to identity-document images, extracted information and other verification records according to their purpose and necessity. Aimgold may delete or redact information earlier where it is no longer reasonably required.
6. How we obtain information
6.1 Directly from you
For example when you create or use an account, use our websites, applications or services, verify your identity, provide information in connection with a service or transaction, interact with a participating business, subscribe to or purchase a service, contact us, request information, attend an event, or otherwise interact with Aimgold.
6.2 Automatically
We may automatically collect technical, security and usage information when our websites, applications, platforms or other digital services are used.
6.3 From businesses using or participating in our services
Businesses may provide information to Aimgold where necessary in connection with use of our services.
6.4 From third parties
We may receive information from identity-verification providers, payment and financial-service providers, address-verification providers, fraud-prevention and security providers, logistics and delivery providers, technology providers, professional advisers, public sources and registers, authorities and law-enforcement bodies, and other organisations where receipt of the information is lawful.
7. How and why we use personal information
7.1 Providing and administering our services
Including to create and manage accounts, verify users, provide and administer services, support transactions and interactions, maintain appropriate records, administer payments and billing, manage business and customer relationships, provide customer and technical support, communicate with users, and perform our contractual obligations.
7.2 Fraud prevention, safety and security
Including to prevent and detect fraud and crime, identify suspicious or potentially unlawful activity, protect users and participating businesses, protect our systems and services, investigate concerns, manage operational and financial risk, resolve disputes, and establish, exercise or defend legal claims.
7.3 Legal, regulatory and governance purposes
Including to comply with applicable laws and regulations, maintain required business and financial records, respond to lawful requests, protect legal rights, and manage governance, audit and compliance requirements.
7.4 Operating, improving and developing our business
Including to operate and improve our services, understand how they are used, improve functionality and user experience, conduct testing and quality assurance, perform research and development, conduct analytics, improve fraud prevention and security, develop technology and automated systems, develop new products and services, and improve business and operational processes.
Special category information will not be used for unrelated purposes unless we have an appropriate lawful basis and, where required, an appropriate condition under Article 9 UK GDPR.
7.5 Communications and marketing
Including to provide service communications, security or account notifications, respond to enquiries, provide relevant information concerning our services, and send marketing where permitted by law.
8. Our lawful bases
Aimgold processes personal information only where we have an appropriate lawful basis. Depending upon the processing activity, we may rely upon:
- Contract — where processing is necessary to enter into or perform a contract with you.
- Legal obligation — where processing is necessary for us to comply with an applicable legal obligation.
- Legitimate interests — where processing is necessary for our legitimate interests or those of another person and those interests are not overridden by your rights and freedoms.
- Consent — where we ask for your consent for a particular activity.
Our legitimate interests may include operating and improving our business and services, protecting our users, participating businesses and systems, preventing and detecting fraud and crime, maintaining appropriate records, managing business relationships, resolving disputes, conducting research and development, protecting our legal rights, and developing our business, products and technology. Where appropriate, we assess our reliance on legitimate interests.
You may withdraw consent where processing is based upon consent, although withdrawal does not affect processing already lawfully undertaken. Where we process special category personal information, we will also identify an appropriate condition under Article 9 UK GDPR.
9. Automated technologies
Aimgold may use automated technologies to support the operation, security, analysis, development and improvement of its products and services. These may assist with fraud and risk detection, security, analysis, service operation, quality assurance, workflow automation, product and service improvement, and research and development.
Where a decision is based solely on automated processing and produces legal or similarly significant effects on an individual, we will comply with applicable requirements and provide appropriate safeguards. Those safeguards may include, where applicable, the ability to request human intervention, express your point of view and challenge a decision.
10. Anonymised and aggregated information
Aimgold may anonymise or aggregate information so that individuals are no longer identifiable. Where information has been effectively anonymised, it is no longer personal data for the purposes of UK GDPR.
We may use anonymised and aggregated information for lawful business purposes including analysis, research, statistical purposes, benchmarking, service improvement, product and technology development, business intelligence, understanding trends and reporting. We may share, publish or otherwise use genuinely anonymised or aggregated information where individuals cannot reasonably be identified from it.
Aimgold does not sell personal information.
11. Who we may share personal information with
We do not sell personal information. Where reasonably necessary and lawful, we may share personal information with the following categories of recipient.
11.1 Businesses involved in our services
Information may be shared with businesses involved in providing, supporting or participating in an Aimgold service where necessary for the relevant purpose. Such organisations may act as independent controllers, joint controllers or processors. Where another organisation acts as an independent controller, its own privacy information may also apply.
11.2 Service providers
Including identity-verification providers, payment and financial-service providers, cloud and infrastructure providers, software and technology providers, communications providers, accounting and administrative providers, logistics providers, analytics providers, security and fraud-prevention providers, insurers, and technical and professional support providers. Where an organisation acts as our processor, we require appropriate contractual and data-protection safeguards.
11.3 Professional advisers
Including legal advisers, accountants, auditors, insurers, consultants and other professional advisers.
11.4 Public authorities and other lawful recipients
We may disclose information where required or permitted by law, including to law-enforcement bodies, courts and tribunals, tax authorities, regulators, government bodies and other authorised organisations.
11.5 Business and corporate purposes
Information may be disclosed where reasonably necessary in connection with investment, financing, corporate transactions, restructuring, acquisition, merger, sale or transfer of a business or assets, or related due diligence. Appropriate safeguards will be used where required.
12. International transfers
Some organisations that process personal information for us may be located outside the United Kingdom. Where personal information is transferred internationally, Aimgold will use safeguards required by applicable data-protection law.
Depending upon the circumstances, these may include transfers to countries or territories covered by UK adequacy regulations, approved contractual safeguards, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or other legally recognised transfer mechanisms. Where required, we will also undertake appropriate transfer assessments.
13. How long we keep personal information
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, regulatory, accounting, security, fraud-prevention and dispute requirements.
| Category | General retention approach |
|---|---|
| Seller selfie and identity-verification evidence | Up to 5 years following the seller's last transaction |
| Biometric calculations used for identity verification | Deleted following completion of verification under our current arrangements |
| Identity-document information | Retained only for so long as reasonably necessary for the applicable verification, evidential, fraud-prevention or legal purpose |
| Transaction and service records | Retained for an appropriate period having regard to legal, accounting, dispute and business requirements |
| Financial and accounting records | Retained in accordance with applicable legal and accounting requirements |
| Business and contractual records | Retained for an appropriate period following the end of the relevant relationship |
| Support, complaint and communication records | Retained according to the nature and potential relevance of the matter |
| Technical, audit and security information | Retained for periods proportionate to the relevant operational, audit and security purpose |
| Marketing information | Retained while appropriate for the relevant purpose, subject to applicable rights and legal requirements |
Information may be retained for longer where law requires it, an investigation is ongoing, a dispute or legal claim exists or is reasonably anticipated, fraud, security or crime-prevention considerations require it, or another lawful reason justifies continued retention.
When personal information is no longer required, it will be deleted, redacted, anonymised or otherwise securely disposed of as appropriate.
14. Data security and privacy by design
We take appropriate technical and organisational measures designed to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction, alteration or disclosure. Measures may include encryption, access controls, authentication, logging and monitoring, secure infrastructure, backup and recovery measures, confidentiality requirements, supplier and service-provider controls, incident-management procedures, and appropriate organisational policies and processes.
Aimgold applies data-protection-by-design and data-protection-by-default principles when developing or materially changing systems and services involving personal information. Where processing is likely to result in a high risk to individuals' rights and freedoms, we will undertake appropriate data-protection assessments where required by law.
No electronic or information system can be guaranteed to be completely secure. Where a personal-data breach occurs, we will investigate and make notifications to regulators and affected individuals where required by applicable law.
15. Cookies and similar technologies
Our websites, applications and other digital services may use cookies and similar technologies for purposes including essential functionality, authentication, security, remembering settings and preferences, analytics, performance measurement and marketing.
Where consent is required under applicable law, we will seek appropriate consent before using non-essential cookies or similar technologies. More detailed information may be provided through a separate Cookie Policy or cookie-management interface.
16. Marketing
Aimgold may communicate with individuals about products, services and other relevant matters where permitted by law. Where consent is required for marketing, we will obtain it.
You may unsubscribe from electronic marketing communications using the method provided in the communication or by contacting us. Administrative, security, transactional and other service-related communications are not marketing communications and may continue where reasonably necessary.
17. Your data protection rights
Depending upon the circumstances and applicable law, you may have rights including:
- Access — to obtain information about and copies of personal information we hold about you
- Rectification — to have inaccurate or incomplete information corrected
- Erasure — to request deletion in certain circumstances
- Restriction — to request restriction of processing in certain circumstances
- Objection — to object to certain processing, including direct marketing
- Data portability — to receive certain information in a portable format where the right applies
- Automated decision-making rights — in relation to certain decisions made solely by automated means
- Withdrawal of consent — where processing is based upon consent
These rights are not absolute and may be subject to conditions and exemptions under applicable law. To exercise a right, contact us or write to us at the address in section 21. We may request information reasonably necessary to verify your identity before responding, and will respond within the timescales required by applicable law.
18. Complaints
If you have concerns about how Aimgold processes personal information, please contact us so that we can investigate. You also have the right to make a complaint to the UK's data-protection regulator.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
ico.org.uk
19. Children and young people
Aimgold's consumer services involving the sale of jewellery, precious metals or other items are intended for individuals aged 18 or over. Certain business or professional services may be used by authorised personnel under the age of 18 where permitted by applicable law and by the organisation responsible for that individual.
Where Aimgold processes personal information relating to an individual under 18 in connection with a business or professional service, we will process that information only where appropriate and in accordance with applicable data-protection law. We do not knowingly permit individuals under 18 to use services where an adult is required. If we become aware that personal information has been collected contrary to these requirements, we will take appropriate steps.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, including where our products or services change, our processing activities change, our business develops, legal or regulatory requirements change, or we otherwise consider an update appropriate.
The current version will be made available through our website, applications or other appropriate channels. Where changes materially affect how personal information is processed, we will provide appropriate notice and obtain consent where required by law.
21. Contact us
Aimgold Limited
15 Half Moon Street, London, W1J 7DZ
Company number: 15242854
ICO registration number: ZC222932
Contact us
22. Data protection roles
The role of Aimgold and other organisations involved in our services may differ depending upon the circumstances and the particular processing activity.
Where Aimgold determines the purposes and means of processing personal information, Aimgold acts as a controller. Another organisation involved in our services may act as an independent controller where it determines its own purposes and means of processing. In other circumstances, Aimgold or another organisation may process personal information on behalf of a controller and therefore act as a processor.
Where appropriate, these relationships may be governed by additional contractual data-protection terms or privacy information. Nothing in this Privacy Policy is intended to determine a controller or processor relationship where that status is determined differently under applicable data-protection law.

