Who we are
Emissary Holdings Ltd, trading as Emissary Partners, is a global special situations firm serving family offices and institutional investors. Headquartered in London, we operate in association with senior advisors across the United Kingdom, Europe, the Middle East, South-East Asia, and North America as our main jurisdictions. We operate generally on a global basis.
For the purposes of data protection law, Emissary Holdings Ltd is the data controller in respect of the personal data described in this policy. Our registered address is listed at Companies House.
What this policy covers
This policy explains how Emissary collects, uses, stores, and shares personal data. It applies to all individuals whose data we process — including clients, prospective clients, advisors, counterparties, and website visitors.
Our processing is governed by the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and the Data Use and Access Act 2025 (DUAA). The Data (Use and Access) Act 2025 introduces a number of reforms to the UK data protection framework. These are being implemented on a phased basis during 2026.
What data we collect
We collect personal data that is relevant to our business relationships and legal obligations. The categories we process include:
- Contact and identity data — name, email address, telephone number, and postal address
- Professional and role data — employer name, job title, seniority, and relationship history
- Technical and device data — IP address, device identifiers, browser type, and access logs
- Usage and behavioural data — pages visited, time on site, interaction patterns, and stated preferences
- Marketing preferences — whether you wish to receive communications from us and through which channels
- Financial data — bank details and VAT numbers, where required for invoicing or compliance
We do not routinely collect special category data (for example, health information, biometric data, or political opinions). Where this is unavoidable in a specific engagement, we will notify you separately and obtain consent or rely on an applicable statutory exemption.
For institutional clients, data collected typically comprises professional contact details, corporate functions, and role-related information. For private clients, we additionally collect identity and address verification documents as required by our legal and regulatory obligations.
How we obtain personal data
We receive personal data from a number of sources:
- directly from you, when you contact us, subscribe to communications, or instruct us on an engagement
- from agents acting on your behalf, such as lawyers, trustees, or fiduciaries
- from professional data providers such as Factiva, BoardEx, PitchBook, and Preqin
- from publicly available sources, including LinkedIn, Companies House, and corporate registers
- by referral or introduction from existing contacts within our network
How we use personal data and the lawful basis
We process personal data only where we have a clear purpose and a lawful basis for doing so. Our principal uses, and the bases we rely upon, are set out below.
Uses of personal data, and their lawful basis, include:
- Service delivery and relationship management — We use personal data to communicate with clients, manage engagements, and fulfil our contractual obligations. Lawful basis: contract necessity and legitimate interests. Our legitimate interests include maintaining professional networks, managing client relationships, and improving our services.
- Compliance, fraud prevention, and network security — We process data to satisfy anti-money laundering, anti-bribery, and sanctions obligations, and to protect the integrity of our systems. Lawful basis: legal obligation and legitimate interests.
- Marketing and communications — We may contact you with relevant updates, insights, and opportunities. For email marketing, we rely on either consent or the soft opt-in rule under PECR. Every communication includes a clear and immediate unsubscribe option. Lawful basis: recognised legitimate interests, subject to PECR.
- Analytics and service improvement — We use aggregated and anonymised data to understand how our website and services are used and to improve them over time. Lawful basis: legitimate interests.
Cookies and Website Analytics
Our website uses cookies and similar tracking technologies. Cookies are small text files placed on your device to support website functionality, analytics, and, where you have consented, personalised content.
Cookie categories
- Essential cookies, which are necessary for the website to function and cannot be disabled.
- Consent is obtained through our cookie banner and preference centre before any non-essential cookies are placed.
- Preference cookies, which remember choices you have made to personalise your experience
- Analytics cookies (including Google Analytics), which help us understand how visitors interact with our site.
You can manage or withdraw your consent to non-essential cookies at any time through the cookie preference centre on our website, or via your browser settings. Note that disabling certain cookies may affect how the site performs.
Google Analytics data is processed by Google LLC, acting as a data processor on our behalf, under a Data Processing Agreement that reflects standard contractual clauses for international transfers.
How and where we store data
Personal data held by Emissary is stored on secure servers managed by our technology provider. Our primary storage infrastructure is located within the United Kingdom or the European Economic Area (EEA). Where data is processed outside these jurisdictions, we ensure that appropriate transfer safeguards are in place (see International Transfers below).
We require all third-party service providers who handle personal data on our behalf to comply with UK data protection law and to maintain appropriate technical and organisational security measures. We review these arrangements periodically.
Data security
Emissary Partners holds Cyber Essentials certification. Our security framework includes encryption in transit and at rest, role-based access controls, secure system configuration, continuous monitoring, and structured vendor risk assessments.
In the event of a personal data breach that poses a risk to individuals, we will notify the ICO within 72 hours and, where required, inform affected individuals without undue delay.
We note that the DUAA aligns PECR enforcement penalties with UK GDPR fines. Our technical audit and technical compliance processes reflect this parity.
Data protection governance
Emissary maintains internal policies and procedures designed to ensure compliance with UK data protection law.
These include:
- internal data protection policies and staff guidance
- confidentiality obligations for all personnel
- due diligence and contractual controls for third-party service providers
- periodic review of security and privacy controls
- incident response and breach notification procedures
Data protection matters are overseen by senior management and reviewed periodically as part of our operational governance framework.
How long we retain data
We retain personal data for no longer than is necessary for the purpose for which it was collected, or as required by law. In practice, our retention periods are shaped by:
- the duration of our contractual relationship and any post-engagement obligations
- statutory requirements — for example, accounting records and executed contracts are retained for six years under the Limitation Act 1980
- legal proceedings or regulatory investigations where data may be relevant
- security monitoring obligations
At the end of the applicable retention period, data is securely deleted or rendered irreversibly anonymous.
How and when we share data
We do not disclose client relationship information publicly and treat all engagement information as confidential.
We do not sell personal data. We share it only where genuinely necessary:
- with Emissary group entities or specialist advisors involved in delivering a client engagement, on a need-to-know basis
- with regulated service providers — such as compliance software, CRM, or document management platforms — acting as data processors under written agreements
- with professional advisors (lawyers, auditors, or insurers) where required
- with law enforcement, regulators, or courts where we are legally required to do so
We will inform you if your data is to be shared with a third party in a manner that is not routine or reasonably expected.
International Transfers
Given Emissary’s international footprint, it may occasionally be necessary to transfer personal data to jurisdictions outside the United Kingdom. Where a transfer destination has not been granted adequacy status by UK authorities, we implement appropriate safeguards. Transfers rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
A Transfer Risk Assessment is conducted prior to any transfer where required. You may request further information about the specific safeguards applicable to your data by contacting us at the address below.
Artificial Intelligence
Emissary uses AI-assisted tools to support a defined range of internal tasks, including research, workflow analytics, and content preparation. We do not use AI to make automated decisions that produce legal or similarly significant effects without human oversight. Any AI-assisted tools operate with human oversight.
The DUAA has updated the UK’s rules on automated decision-making, preserving and in some respects clarifying individual rights. Where any automated processing could produce such effects, you have the right to:
- request meaningful human review of the decision
- express your view on the outcome, and
- contest the decision through our complaints process
We will continue to update this section as our use of AI tools evolves and as ICO guidance on DUAA implementation is finalised.
Children’s Data
Our services are directed exclusively at professionals and adult private clients. We do not knowingly collect or process personal data relating to individuals under the age of 18. If we become aware that such data has been collected, it will be deleted promptly.
Your rights
As a data subject under UK data protection law, you have the rights set out in the table below. These rights are not absolute in all circumstances, but we will respond to any request promptly and in any event within one calendar month.
| Your right | What this means in practice |
|---|---|
| Right to be informed | You are entitled to clear, plain-English information about how your data is used — which is what this policy aims to provide. |
| Right of access | You may request a copy of the personal data we hold about you (a Subject Access Request), free of charge, to verify that we are using it lawfully. |
| Right to rectification | If any information we hold is inaccurate or incomplete, you are entitled to have it corrected without undue delay. |
| Right to erasure | Sometimes called the right to be forgotten, this allows you to request deletion of your personal data where there is no overriding reason for us to retain it. Statutory and regulatory retention obligations may apply. |
| Right to restrict processing | You may ask us to suspend active use of your data — for example, while you contest its accuracy. We will retain it but not act on it, and will record the restriction. |
| Right to data portability | Where processing is based on consent or contract, you may receive your data in a structured, machine-readable format, or ask us to transfer it directly to another provider. |
| Right to object | You may object to processing carried out on the basis of legitimate interests, including for direct marketing. We will cease that processing unless we can demonstrate compelling grounds to continue. |
| Right to withdraw consent | Where our processing rests on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of any processing carried out before that point. |
| Right to complain | You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at any time. We ask that you contact us first so we can address your concern directly. |
To exercise any of these rights, please contact us at contact@emissarypartners.com. We do not charge a fee for standard requests and will not require you to justify your decision to make one.
Complaints
If you are concerned about how we have handled your personal data, we ask that you contact us first, at contact@emissarypartners.com. We take all privacy concerns seriously and aim to resolve them promptly.
The DUAA introduces a statutory requirement for UK organisations to operate a formal internal complaints process before individuals escalate to the ICO. This requirement becomes enforceable on 19 June 2026. Our complaints process is in place now.
If you remain dissatisfied after engaging with us, you retain the right to escalate your complaint to:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
ico.org.uk · 0303 123 1113
Updates to This Policy
We review this policy regularly and will update it as our practices evolve, as the regulatory landscape develops — including final ICO guidance on recognised legitimate interests, cookies, international transfers, and AI — and as our business changes.
Material changes will be communicated through our website. The version date at the top of this document reflects when it was last revised.