Privacy policy

Last updated: August 19, 2026

AIMGOLD LIMITED
PRIVACY POLICY
Version: 2.2
Effective date: 17th May 2026
Last updated: 18 August 2026

1. About this Privacy Policy
This Privacy Policy explains how Aimgold Limited ("Aimgold", "we", "our" or "us")
collects, uses, stores, shares and protects personal information when individuals interact with
our products, services, websites, applications and platforms.
This Privacy Policy may apply to:
• consumers and other individual users
• business customers and their personnel
• dealers, jewellers, pawnbrokers and other professional users
• prospective customers
• website and application users
• individuals involved in transactions or services supported by Aimgold and
• other individuals whose personal information we process in connection with our
business.
Aimgold PRO is a product and trading name operated by Aimgold Limited.
Aimgold Limited is registered in England and Wales under company number 15242854.
Our registered office is:
Aimgold Limited
15 Half Moon Street
London
W1J 7DZ
Aimgold is a controller of personal information where we determine the purposes and means
of processing that information.
Other organisations involved in providing or supporting our services may, depending on the
circumstances, act as independent controllers, joint controllers or processors. Additional
information may be provided where appropriate.

Privacy contact:
Email: help@aimgold.co.uk
ICO registration number: ZC222932

2. About Aimgold
Aimgold is a UK technology company operating within the jewellery and precious metals
sector.
Our purpose is to help raise standards, trust and transparency within the sector through
technology, professional processes and better information and record keeping.
We provide and develop technology, products and related services for consumers, businesses
and other participants within the sector.
Our services may include digital platforms, applications, transaction-support services,
identity verification, testing and analysis services, equipment-related services, recordmanagement tools, customer and business support, training, integrations and other related
services.
Our products and services may evolve over time.
This Privacy Policy is intended to apply broadly across Aimgold's services. Where necessary,
we may provide additional or more specific privacy information in connection with a
particular service or processing activity.

3. Our Services
Aimgold provides technology and related products and services for the jewellery and
precious metals sector.
Our services may support interactions and transactions involving consumers, businesses and
other participants within the sector.
Aimgold may process personal information where necessary to provide and operate its
services, verify users, maintain appropriate records, support users and participating
businesses, prevent and detect fraud, meet legal and regulatory requirements, and develop
and improve its products and services.
Where other organisations are involved in providing a service or completing a transaction,
those organisations may process personal information in their own capacity and may have
their own data-protection responsibilities.

4. Information We Collect
The personal information we collect depends upon how you interact with Aimgold and which
services you use.

4.1 Identity and verification information
This may include:
• name
• date of birth
• nationality
• government-issued identification
• information extracted from identification documents
• photographs, selfies and verification images
• identity-verification results
• verification reference information
• verification dates and status and
• other information reasonably required to establish or verify identity.

4.2 Contact information
This may include:
• residential or business address
• email address
• telephone number and
• address-validation information.

4.3 Financial, account and transaction information
This may include:
• bank account information
• payment-related information
• transaction records
• quotations and valuations
• payment status
• invoices and billing information
• account and subscription information and
• other financial or transactional information associated with our services.
Where third-party payment providers are used, Aimgold may not receive or retain complete
payment-card information.

4.4 Business and professional information
Where you interact with Aimgold on behalf of a business or in a professional capacity, we
may process information including:
• business or trading name
• company and registration information
• business address
• VAT information
• business contact information
• professional role
• authorised-user and operator information
• account permissions
• service information
• training and support information
• activity associated with use of our services and
• relevant compliance information.

4.5 Item, testing and analysis information
Our services may process information relating to items, materials and associated testing or
analysis.
This may include:
• photographs and videos
• descriptions
• markings and hallmarks
• weight and measurements
• composition and purity information
• testing and analysis results
• X-ray fluorescence (XRF) data
• density or conductivity information
• valuations and quotations and
• related records.
Information relating solely to an object is not necessarily personal information. However,
where it is associated with an identifiable individual, account or transaction, it may form part
of a personal-data record.

4.6 Photographs, video and other records
Where appropriate, we may collect photographs, video or other evidence relating to
individuals, items, activities or transactions where reasonably necessary to provide our
services, maintain records, prevent fraud, investigate concerns or protect users and
participating businesses.
4.7 Fraud, security and compliance information
This may include:
• identity-verification information
• fraud and risk indicators
• information concerning suspicious or unusual activity
• account or transaction risk information
• screening information where applicable
• information concerning disputed or potentially unlawful activity
• security information
• device or account risk information and
• information obtained or generated in connection with investigations, disputes or
lawful enquiries.

4.8 Technical and usage information
This may include:
• IP address
• device information
• operating system
• browser
• application version
• device identifiers
• log-in information
• audit and activity logs
• usage information
• security logs
• diagnostics and
• crash and performance information.

4.9 Communications
We may process communications between you and Aimgold, including:
• emails
• telephone communications
• in-app communications
• support requests
• complaints
• feedback and
• other correspondence.
Calls may be recorded where appropriate and where we have informed you and have an
appropriate lawful basis.

4.10 Location information
Where relevant to a service, we may process:
• approximate location derived from technical information
• addresses or locations provided in connection with a service and
• precise device location where you have enabled the relevant permission.

5. Identity Verification and Biometric Processing
Aimgold may use specialist identity-verification providers to verify the identity of individuals
using certain services.
Identity verification may involve:
• capturing a government-issued identity document
• taking a selfie or liveness image or video
• checking the authenticity of identity information
• comparing an individual with the photograph contained within an identity document
and
• performing related verification, security and fraud checks.
Our identity-verification providers may use biometric technology as part of this process.
Where biometric information is processed for the purpose of uniquely identifying an
individual, it constitutes special category personal data under UK data-protection law.
Where such processing occurs, Aimgold will identify an appropriate lawful basis under
Article 6 UK GDPR and an appropriate condition under Article 9 UK GDPR. Where explicit
consent is relied upon, it will be obtained in accordance with applicable law.
Our current identity-verification arrangements provide for biometric calculations generated
for identity verification to be deleted following completion of the verification process.
Separate images, verification outcomes and other records may be retained where reasonably
necessary for the purposes for which they were collected.
Aimgold's current intended retention period for a seller's selfie and relevant identityverification evidence is up to five years following the seller's last transaction, subject to
applicable law and periodic review.
Such information may be retained for purposes including:
• identity and transaction records
• fraud and crime prevention
• investigation of suspected unlawful activity
• handling disputes
• responding to lawful enquiries
• establishing, exercising or defending legal claims and
• satisfying applicable legal or regulatory requirements.
Different retention periods may apply to identity-document images, extracted information
and other verification records according to their purpose and necessity.
Aimgold may delete or redact information earlier where it is no longer reasonably required.

6. How We Obtain Information
We may obtain personal information:

6.1 Directly from you
For example, when you:
• create or use an account
• use our websites, applications or services
• verify your identity
• provide information in connection with a service or transaction
• interact with a participating business
• subscribe to or purchase a service
• contact us
• request information
• attend an event or
• otherwise interact with Aimgold.

6.2 Automatically
We may automatically collect technical, security and usage information when our websites,
applications, platforms or other digital services are used.

6.3 From businesses using or participating in our services
Businesses may provide information to Aimgold where necessary in connection with use of
our services.

6.4 From third parties
We may receive information from third parties including:
• identity-verification providers
• payment and financial-service providers
• address-verification providers
• fraud-prevention and security providers
• logistics and delivery providers
• technology providers
• professional advisers
• public sources and registers
• authorities and law-enforcement bodies and
• other organisations where receipt of the information is lawful.

7. How and Why We Use Personal Information
We may use personal information for purposes including:

7.1 Providing and administering our services
Including to:
• create and manage accounts
• verify users
• provide, facilitate and administer services
• support transactions and interactions
• maintain appropriate records
• administer payments and billing where relevant
• manage business and customer relationships
• provide customer and technical support
• communicate with users and
• perform our contractual obligations.

7.2 Fraud prevention, safety and security
Including to:
• prevent and detect fraud and crime
• identify suspicious or potentially unlawful activity
• protect users and participating businesses
• protect our systems and services
• investigate concerns
• manage operational and financial risk
• resolve disputes and
• establish, exercise or defend legal claims.

7.3 Legal, regulatory and governance purposes
Including to:
• comply with applicable laws and regulations
• maintain required business and financial records
• respond to lawful requests
• protect legal rights and
• manage governance, audit and compliance requirements.

7.4 Operating, improving and developing our business
We may use information to:
• operate and improve our services
• understand how our services are used
• improve functionality and user experience
• conduct testing and quality assurance
• perform research and development
• conduct analytics
• improve fraud prevention and security
• develop and improve technology and automated systems
• develop new products and services and
• improve business and operational processes.
Special category information will not be used for unrelated purposes unless we have an
appropriate lawful basis and, where required, an appropriate condition under Article 9 UK
GDPR.

7.5 Communications and marketing
We may use information to:
• provide service communications
• provide security or account notifications
• respond to enquiries
• provide relevant information concerning our services and
• send marketing where permitted by law.

8. Our Lawful Bases
Aimgold processes personal information only where we have an appropriate lawful basis.
Depending upon the processing activity, we may rely upon:

Contract
Where processing is necessary to enter into or perform a contract with you.

Legal obligation
Where processing is necessary for us to comply with an applicable legal obligation.

Legitimate interests
Where processing is necessary for our legitimate interests or those of another person and
those interests are not overridden by your rights and freedoms.
Our legitimate interests may include:
• operating and improving our business and services
• protecting our users, participating businesses and systems
• preventing and detecting fraud and crime
• maintaining appropriate records
• managing business relationships
• resolving disputes
• conducting research and development
• protecting our legal rights and
• developing our business, products and technology.
Where appropriate, we assess our reliance on legitimate interests.

Consent
Where we ask for your consent for a particular activity.
You may withdraw consent where processing is based upon consent, although withdrawal
does not affect processing already lawfully undertaken.

Special category personal information
Where we process special category personal information, we will also identify an appropriate
condition under Article 9 UK GDPR.

9. Automated Technologies
Aimgold may use automated technologies to support the operation, security, analysis,
development and improvement of its products and services.
These technologies may assist with activities including:
• fraud and risk detection
• security
• analysis
• service operation
• quality assurance
• workflow automation
• product and service improvement and
• research and development.
We may use personal information and, where appropriate, anonymised or aggregated
information for these purposes.
Where a decision is based solely on automated processing and produces legal or similarly
significant effects on an individual, we will comply with applicable requirements and provide
appropriate safeguards.
Those safeguards may include, where applicable, the ability to request human intervention,
express your point of view and challenge a decision.

10. Anonymised and Aggregated Information
Aimgold may anonymise or aggregate information so that individuals are no longer
identifiable.
Where information has been effectively anonymised so that an individual is no longer
identifiable, it is no longer personal data for the purposes of UK GDPR.
Aimgold may use anonymised and aggregated information for lawful business purposes,
including:
• analysis
• research
• statistical purposes
• benchmarking
• service improvement
• product and technology development
• business intelligence
• understanding trends
• reporting and
• other lawful commercial purposes.
We may share, publish or otherwise use genuinely anonymised or aggregated information
where individuals cannot reasonably be identified from that information.
Aimgold does not sell personal information.

11. Who We May Share Personal Information With
We do not sell personal information.
Where reasonably necessary and lawful, we may share personal information with categories
of recipients including:

11.1 Businesses involved in our services
Information may be shared with businesses involved in providing, supporting or participating
in an Aimgold service where necessary for the relevant purpose.
Such organisations may, depending upon the circumstances, process information as
independent controllers, joint controllers or processors.
Where another organisation acts as an independent controller, its own privacy information
may also apply.

11.2 Service providers
We may use service providers including:
• identity-verification providers
• payment and financial-service providers
• cloud and infrastructure providers
• software and technology providers
• communications providers
• accounting and administrative providers
• logistics providers
• analytics providers
• security and fraud-prevention providers
• insurers and
• technical and professional support providers.
Where an organisation acts as our processor, we require appropriate contractual and dataprotection safeguards.

11.3 Professional advisers
We may share information where appropriate with professional advisers including:
• legal advisers
• accountants
• auditors
• insurers
• consultants and
• other professional advisers.

11.4 Public authorities and other lawful recipients
We may disclose information where required or permitted by law, including to:
• law-enforcement bodies
• courts and tribunals
• tax authorities
• regulators
• government bodies and
• other authorised organisations.

11.5 Business and corporate purposes
Information may be disclosed where reasonably necessary in connection with matters such
as:
• investment
• financing
• corporate transactions
• restructuring
• acquisition
• merger
• sale or transfer of a business or assets or
• related due diligence.
Appropriate safeguards will be used where required.

12. International Transfers
Some organisations that process personal information for us may be located outside the
United Kingdom.
Where personal information is transferred internationally, Aimgold will use safeguards
required by applicable data-protection law.
Depending upon the circumstances, these may include:
• transfers to countries or territories covered by UK adequacy regulations
• approved contractual safeguards
• the UK International Data Transfer Agreement
• the UK Addendum to approved standard contractual clauses or
• other legally recognised transfer mechanisms.
Where required, we will also undertake appropriate transfer assessments.

13. How Long We Keep Personal Information
We retain personal information only for as long as reasonably necessary for the purposes for
which it was collected and to satisfy applicable legal, regulatory, accounting, security, fraudprevention and dispute requirements.
Our retention periods depend upon the nature of the information and the purpose for which it
is processed.
Our current general approach includes:

 


Category General retention approach
Seller selfie and relevant
identity-verification evidence Up to 5 years following the seller's last transaction
Biometric calculations used for
identity verification
Deleted following completion of verification under our
current identity-verification arrangements
Identity-document information
Retained only for so long as reasonably necessary for the
applicable verification, evidential, fraud-prevention or legal
purpose
Transaction and service records Generally retained for an appropriate period having regard
to legal, accounting, dispute and business requirements
Financial and accounting
records
Retained in accordance with applicable legal and
accounting requirements
Business and contractual
records
Retained for an appropriate period following the end of the
relevant relationship
Category General retention approach
Support, complaint and
communication records
Retained according to the nature and potential relevance of
the matter
Technical, audit and security
information
Retained for periods proportionate to the relevant
operational, audit and security purpose
Marketing information Retained while appropriate for the relevant purpose, subject
to applicable rights and legal requirements
Information may be retained for longer where reasonably necessary because:
• law requires it
• an investigation is ongoing
• a dispute or legal claim exists or is reasonably anticipated
• fraud, security or crime-prevention considerations require it or
• another lawful reason justifies continued retention.
When personal information is no longer required, it will be deleted, redacted, anonymised or
otherwise securely disposed of as appropriate.

14. Data Security and Privacy by Design
We take appropriate technical and organisational measures designed to protect personal
information against unauthorised or unlawful processing and against accidental loss,
destruction, alteration or disclosure.
Measures may include, where appropriate:
• encryption
• access controls
• authentication
• logging and monitoring
• secure infrastructure
• backup and recovery measures
• confidentiality requirements
• supplier and service-provider controls
• incident-management procedures and
• appropriate organisational policies and processes.
Aimgold applies data-protection-by-design and data-protection-by-default principles when
developing or materially changing systems and services involving personal information.
Where processing is likely to result in a high risk to individuals' rights and freedoms, we will
undertake appropriate data-protection assessments where required by law.
No electronic or information system can be guaranteed to be completely secure.
Where a personal-data breach occurs, we will investigate and make notifications to regulators
and affected individuals where required by applicable law.

15. Cookies and Similar Technologies
Our websites, applications and other digital services may use cookies and similar
technologies.
These technologies may be used for purposes including:
• providing essential functionality
• authentication
• security
• remembering settings and preferences
• analytics
• performance measurement and
• marketing.
Where consent is required under applicable law, we will seek appropriate consent before
using non-essential cookies or similar technologies.
More detailed information may be provided through a separate Cookie Policy or cookiemanagement interface.

16. Marketing
Aimgold may communicate with individuals about products, services and other relevant
matters where permitted by law.
Where consent is required for marketing, we will obtain it.
You may unsubscribe from electronic marketing communications using the method provided
in the communication or by contacting us at help@aimgold.co.uk.
Administrative, security, transactional and other service-related communications are not
marketing communications and may continue where reasonably necessary.

17. Your Data Protection Rights
Depending upon the circumstances and applicable law, you may have rights including:
• access – to obtain information about and copies of personal information we hold
about you
• rectification – to have inaccurate or incomplete information corrected
• erasure – to request deletion in certain circumstances
• restriction – to request restriction of processing in certain circumstances
• objection – to object to certain processing, including direct marketing
• data portability – to receive certain information in a portable format where the right
applies
• automated decision-making rights – in relation to certain decisions made solely by
automated means and
• withdrawal of consent – where processing is based upon consent.
These rights are not absolute and may be subject to conditions and exemptions under
applicable law.
To exercise a right, please contact:
help@aimgold.co.uk
We may request information reasonably necessary to verify your identity before responding.
We will respond within the timescales required by applicable law.

18. Complaints
If you have concerns about how Aimgold processes personal information, please contact us at
help@aimgold.co.uk so that we can investigate.
You also have the right to make a complaint to the UK's data-protection regulator:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

19. Children and Young People
Aimgold's consumer services involving the sale of jewellery, precious metals or other items
are intended for individuals aged 18 or over.
Certain business or professional services may be used by authorised personnel under the age
of 18 where permitted by applicable law and by the organisation responsible for that
individual.
Where Aimgold processes personal information relating to an individual under 18 in
connection with a business or professional service, we will process that information only
where appropriate and in accordance with applicable data-protection law.
We do not knowingly permit individuals under 18 to use services where an adult is required.
If we become aware that personal information has been collected contrary to these
requirements, we will take appropriate steps.

20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, including where:
• our products or services change
• our processing activities change
• our business develops
• legal or regulatory requirements change or
• we otherwise consider an update appropriate.
The current version will be made available through our website, applications or other
appropriate channels.
Where changes materially affect how personal information is processed, we will provide
appropriate notice and obtain consent where required by law.

21. Contact Us
For questions about this Privacy Policy, exercising your data-protection rights, or Aimgold's
handling of personal information, please contact:

Aimgold Limited
15 Half Moon Street
London
W1J 7DZ

Company number: 15242854
ICO registration number: ZC222932
Email: help@aimgold.co.uk

22. Data Protection Roles
The role of Aimgold and other organisations involved in our services may differ depending
upon the circumstances and the particular processing activity.
Where Aimgold determines the purposes and means of processing personal information,
Aimgold acts as a controller.
Another organisation involved in our services may act as an independent controller where it
determines its own purposes and means of processing.
In other circumstances, Aimgold or another organisation may process personal information
on behalf of a controller and therefore act as a processor.
Where appropriate, these relationships may be governed by additional contractual dataprotection terms or privacy information.
Nothing in this Privacy Policy is intended to determine a controller or processor relationship
where that status is determined differently under applicable data-protection law.