Skip to content

Legal

Privacy notice

Last updated: 2026-05-25

This privacy notice describes how PWA — Private Wealth Advisory (PWA Advisory Ltd.) collects, uses, retains, and protects personal data processed through https://private-wealth-advisory.com. Our advisory engagements are governed by separate, executed engagement letters and confidentiality agreements, which contain additional data-protection provisions specific to the engagement.

1. Who we are

PWA Advisory Ltd., trading as PWA — Private Wealth Advisory, is the data controller for personal data processed via https://private-wealth-advisory.com. If you have any questions about this notice or our data practices, please book a meeting with our team.

2. What we collect

We may collect and process the following categories of personal data:

  • Inquiry data: the name, email address, message, and optional referral information you submit through the inquiry form on our contact page.
  • Calendar data: when you book a call via our scheduling tool (Cal.com), the platform processes your name, email, and time-zone under its own privacy policy. PWA receives the resulting booking record.
  • Server logs: Cloudflare automatically processes IP addresses, request URLs, timestamps, HTTP method, response status codes, and browser user-agent strings for routing, DDoS protection, and abuse prevention. We do not link server logs to inquiry data.
  • Privacy-preserving analytics: we use Cloudflare Web Analytics, a cookieless, privacy-first analytics service that does not track individuals across sites and does not collect personally identifiable information.
  • Tracking and marketing data: with your consent (provided via our cookie banner), we may deploy Google Analytics, Meta Pixel, and LinkedIn Insight Tag. These technologies may collect device identifiers, browsing behaviour, pages visited, referral sources, ad interactions, and approximate geographic location for the purposes of analytics, remarketing, and audience building.
  • Device and browser information: cookies and similar technologies deployed with your consent may collect information about your device type, operating system, browser version, screen resolution, and language preferences.

3. What we do not collect

We do not collect financial account details, investment portfolio information, or transactional data through this website. We do not collect Social Security numbers, tax identification numbers, or national identity numbers. We do not use any data submitted through this website to train artificial intelligence or machine learning models. We do not sell, rent, lease, or otherwise transfer your personal data to third parties for their own marketing purposes.

4. Purpose of processing

We process your personal data for the following purposes:

  • Responding to inquiries: to read, assess, and reply to messages and booking requests you submit through our contact page.
  • Website analytics and improvement: to understand how visitors use our website, identify technical issues, and improve content and user experience.
  • Marketing, remarketing, and audience building: where you have given consent, to deliver relevant advertisements, build custom and lookalike audiences, and measure campaign effectiveness via Google Ads, Meta Ads, and LinkedIn Ads.
  • Website security and abuse prevention: to protect the website against automated abuse, spam, DDoS attacks, and other malicious activity.
  • Legal compliance: to comply with applicable legal obligations, regulatory requirements, and lawful requests from public authorities.

5. Legal basis (GDPR / UK GDPR)

Where the General Data Protection Regulation (EU) 2016/679 or the UK GDPR applies, we rely on the following legal bases:

  • Consent (Article 6(1)(a)): for the deployment of non-essential cookies and tracking technologies (provided via our cookie consent banner) and for processing data you voluntarily submit through our contact form.
  • Legitimate interest (Article 6(1)(f)): for website security and abuse prevention, privacy-preserving analytics (Cloudflare Web Analytics), and responding to inquiries initiated by you. Our legitimate interest is balanced against your rights and freedoms, and you may object at any time.
  • Contractual necessity (Article 6(1)(b)): for processing pre-engagement inquiries where you request information about our services with a view to entering into an advisory relationship.

You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent or object to processing, please book a meeting with our team.

6. Cookies and tracking technologies

We use cookies and similar tracking technologies on this website. These fall into three categories:

  • Strictly necessary cookies: essential for the website to function correctly (e.g., security tokens, session management). These do not require consent.
  • Analytics cookies: help us understand website usage patterns and improve our content. Deployed only with your consent.
  • Marketing cookies: used to deliver relevant advertisements and measure campaign performance across platforms such as Google, Meta, and LinkedIn. Deployed only with your consent.

You can manage your cookie preferences at any time through our cookie consent banner. For full details on the specific cookies we use, their purposes, and retention periods, please see our Cookie Policy.

7. Retention

We retain personal data only as long as necessary for the purposes described in this notice:

  • Inquiry data: retained for twelve (12) months from the date of submission if the inquiry does not lead to an engagement. If the inquiry leads to an engagement, the data becomes part of the engagement record.
  • Engagement records: retained as required by professional, contractual, and legal obligations applicable to our advisory activities.
  • Analytics data: retained per each provider's default retention periods — Google Analytics retains data for up to 14 months; Meta retains event data for up to 180 days.
  • Server logs: retained by Cloudflare for up to 30 days.

When personal data is no longer needed, it is securely deleted or anonymised.

8. Recipients and sub-processors

We share personal data only with the following categories of recipients, each acting as a data processor or independent controller as applicable:

  • Cloudflare, Inc. — website hosting, content delivery, Web Application Firewall (WAF), DDoS protection, Turnstile CAPTCHA, and Web Analytics.
  • Resend, Inc. — transactional email delivery for forwarding inquiry form submissions.
  • Cal.com, Inc. — online scheduling and calendar booking.
  • Google LLC — Google Analytics and Google Ads (where consent is given).
  • Meta Platforms, Inc. — Meta Pixel for analytics and remarketing (where consent is given).
  • LinkedIn Corporation — LinkedIn Insight Tag for analytics and audience building (where consent is given).

This list may be updated from time to time. The current list of sub-processors is available upon request — please book a meeting with our team to request it.

9. International transfers

Some of our sub-processors are located in, or process data in, the United States and other countries outside the European Economic Area (EEA) and the United Kingdom. Where such transfers occur, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • the EU-US Data Privacy Framework, where the recipient is a certified participant;
  • adequacy decisions issued by the European Commission or the UK Secretary of State, where applicable.

You may request further details about the safeguards in place by booking a meeting with our team.

10. Your rights

Subject to applicable data-protection law (including the GDPR, UK GDPR, and the Portuguese Lei n.º 58/2019), you have the following rights:

  • Access: the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of it.
  • Rectification: the right to have inaccurate personal data corrected and incomplete data completed.
  • Erasure (right to be forgotten): the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent.
  • Restriction: the right to request that we restrict processing of your personal data in certain circumstances.
  • Data portability: the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
  • Objection: the right to object to processing based on legitimate interest or for direct marketing purposes.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Automated decision-making: the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.

To exercise any of these rights, please book a meeting with our team. We will respond to your request within one month, or inform you if an extension is needed.

You also have the right to lodge a complaint with a supervisory authority. For residents of Portugal, the relevant authority is the Comissão Nacional de Proteção de Dados (CNPD). For residents of the United Kingdom, the relevant authority is the Information Commissioner's Office (ICO). For other EU residents, you may lodge a complaint with the data-protection authority of your member state of habitual residence.

11. Automated decision-making and profiling

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. No decisions about your eligibility, suitability, or access to our services are made by automated means without human involvement.

12. Children's privacy

This website and our services are not directed at persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected personal data from a person under 18, we will take prompt steps to delete that data. If you believe we may have collected data from a minor, please book a meeting with our team so we can investigate and take appropriate action.

13. Security measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • HTTPS-only connections — all data transmitted between your browser and our website is encrypted in transit using TLS.
  • Cloudflare Web Application Firewall (WAF) and DDoS protection to defend against malicious traffic.
  • Cloudflare Turnstile — a privacy-preserving, no-cookie CAPTCHA to mitigate automated abuse without tracking users.
  • Access controls — inquiry data and engagement records are accessible only to authorised personnel within PWA.
  • Encryption in transit — all communications with sub-processors use encrypted channels.

No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.

14. Third-party links

This website may contain links to third-party websites, platforms, or services that are not operated or controlled by PWA Advisory Ltd.. We are not responsible for the privacy practices, content, or security of those external sites. We encourage you to review the privacy policies of any third-party website before providing personal data or engaging with their services.

15. Changes to this notice

We may update this privacy notice from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, the revised notice will be posted on this page with an updated "Last updated" date. Your continued use of the website after any changes constitutes your acceptance of the revised notice. We encourage you to review this page periodically to stay informed about how we protect your data.

16. Contact and complaints

For any privacy-related questions, concerns, or to exercise your data-protection rights, please book a meeting with our team.

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:

  • Portugal: Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt
  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • Other EU member states: the data-protection authority of your country of habitual residence, place of work, or place of the alleged infringement.

— Next step

Begin with a confidential conversation.

Thirty minutes, no agenda, no obligation. Enough to see whether the architecture you are looking for is the architecture we build.