Gold Star Bullion Security Legal & compliance Privacy notice
Privacy notice
What we do with personal data, why we are allowed to, how long we keep it, and what you can make us do about it.
Who is responsible
Gold Star Bullion Security, 144 Houndsditch, London EC3A 7BX, United Kingdom, is the controller of the personal data described here. We decide why and how it is processed.
- Company number
- to be supplied
- ICO registration
- to be supplied
- Data protection contact
- info@goldstarbullionsecurity.com
- Supervisory authority
- Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow SK9 5AF
A blank above is a registration we have not yet published. Ask us for it and we will send the certificate rather than a claim.
What we collect, and why we are allowed to
Every category below is tied to a lawful basis under Article 6 of the UK GDPR. Where the basis is legitimate interests, we have balanced that interest against your rights and can show the assessment on request.
| Data | Why | Lawful basis | Kept for |
|---|---|---|---|
| Enquiry form: name, email, telephone, message | To answer you and to keep a record of what was asked and answered | Legitimate interests (responding to a request you made) | 24 months from the last contact |
| Client account: name, company, email, telephone, address, country | To operate a storage account and a carriage booking | Performance of a contract | 6 years after the account closes |
| Identity records: identity documents seen, verification notes, nationality | Customer due diligence | Legal obligation (Money Laundering Regulations 2017) | 5 years after the business relationship ends |
| Depositor photograph (optional) | To identify the person who physically deposited an item | Consent, which you may withdraw at any time | Until you withdraw consent, or the account closes |
| Holdings, movements, invoices | To keep the register of what is held for whom | Performance of a contract; legal obligation | 6 years after the account closes |
| Consignment records: shipper, consignee, addresses, milestones | To move goods and to satisfy customs | Performance of a contract; legal obligation | 6 years (customs records) |
| Sign-in records and audit log: IP address, timestamps, actions | To secure accounts and to show who changed a record | Legitimate interests (security and accountability) | 12 months for sign-in attempts; 6 years for the record audit trail |
| Notice list: email address | Rate notices and service bulletins | Consent | Until you unsubscribe |
The depositor photograph
A photograph of an identifiable person is personal data, and holding one next to a record of their gold makes it sensitive in practice even where it is not a special category under Article 9. So it is optional, never a condition of opening an account, and treated accordingly:
- Re-encoded on upload, which strips EXIF metadata including any GPS coordinates and device identifiers.
- Stored outside the public web root and released only to you or to an operator, never from a guessable address.
- Deleted on request, immediately, with no effect on the account.
What we do not do
- We do not sell personal data, ever, to anyone.
- We do not use it for automated decision-making or profiling that produces legal effects.
- We do not run advertising or analytics trackers on this website.
- We do not load fonts, scripts or images from third-party servers, so your IP address is not disclosed to anyone simply by reading a page here.
Who else sees it
We share personal data only where the work cannot be done otherwise:
- Vault operators
- Where a vault is run by a third party, to admit you and to record what is held. operators to be published
- Carriers and agents
- Airlines, shipping lines, customs brokers and delivery agents, limited to what a waybill or entry requires.
- Customs and tax authorities
- HM Revenue & Customs and equivalents abroad, where an import or export requires it.
- Insurers and surveyors
- On a claim, or where cover is arranged. underwriter to be published
- Law enforcement and regulators
- Where we are legally obliged, including suspicious activity reporting, which we may be prohibited from telling you about.
- Our hosting and email providers
- As processors, under written terms, acting only on our instructions. providers to be published
Sending data outside the UK
Carriage is international, so a consignment to Zurich or Singapore means the consignee details travel with it. Where personal data leaves the UK we rely on UK adequacy regulations where they exist, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment on file.
Your rights
Under the UK GDPR you may ask us to:
- Give you a copy of the personal data we hold about you, free of charge, normally within one month.
- Correct it where it is wrong or incomplete.
- Erase it, though not where we are legally required to keep it: for identity records that means five years after the relationship ends.
- Restrict what we do with it while a dispute about accuracy is resolved.
- Port it to another provider in a machine-readable form, where processing is by consent or contract.
- Object to processing based on legitimate interests, including any direct marketing, which we will stop on request without argument.
- Withdraw consent at any time where consent is the basis, such as the notice list or a depositor photograph.
Write to info@goldstarbullionsecurity.com. We may ask you to confirm your identity first, because handing someone else's holdings record to the wrong person would be a far worse outcome than a short delay.
Complaining
Tell us first and we will try to put it right. See the complaints procedure. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. You do not have to come to us first.
Security
Passwords are stored hashed and are never recoverable in plain text. Sign-in is rate-limited. Every change to a holding, an account or a consignment is written to an append-only audit trail with the operator and the time. Records are transmitted over TLS. Private files are held outside the web root and released only after an authorisation check.
If a breach occurs that is likely to risk your rights and freedoms, we will report it to the ICO within 72 hours and tell you without undue delay.
Changes
When this notice changes materially we will say so on this page and, where the change affects how we use data you have already given us, tell account holders directly.
Questions about this document go to info@goldstarbullionsecurity.com, or write to Gold Star Bullion Security, 144 Houndsditch, London EC3A 7BX, United Kingdom.