Privacy policy
1. Who we are
Conveysure AML ("Conveysure", "we", "us") provides anti-money-laundering compliance software for law firms and licensed conveyancers in the United Kingdom. This notice explains how personal data is handled when you visit our website, register a firm account, or are asked by your solicitor or conveyancer to provide identity and financial information through our secure client portal.
You can contact us about anything in this notice at [email protected].
2. The two roles we play with your data
Under UK GDPR we act in two different capacities, and your rights are exercised differently in each:
- As a controller — for data about visitors to this website and the staff of firms that register an account (names, work email addresses, login and audit records). For this data, contact us directly.
- As a processor — for data about clients of law firms (buyers, sellers, gift donors and related parties) that is collected through the client portal or uploaded by firm staff. Here the law firm handling your transaction is the controller: it decides what is collected and why, and we process it only on the firm's instructions. If you are a client of a firm, requests about your data should go to that firm first; we will assist them in responding.
3. The data we collect and why
3.1 Firm staff and website visitors (we are the controller)
- Account data — name, work email address, role (e.g. fee earner, MLRO, admin), password (stored only as a salted hash), and firm details including SRA number.
- Usage and audit data — sign-in events, actions taken in the product (an audit trail is itself a regulatory requirement for our customers), and the IP address associated with security-relevant events such as failed logins and password resets.
- Correspondence — emails you send us.
We do not use third-party advertising or analytics cookies. The only cookie we set is a strictly necessary session cookie that keeps you signed in.
3.2 Clients of law firms (we are the processor)
When a firm uses Conveysure to run customer due diligence on a property transaction, we process on the firm's behalf:
- Identity data — name, date of birth, nationality, address, contact details, and copies of identity documents such as passports or driving licences.
- Financial data — bank statements, payslips, tax returns, gift letters and other source-of-funds evidence, together with details of the transaction (property address, purchase price, funding structure).
- Screening data — the results of checks against the UK sanctions list, politically-exposed-person (PEP) lists, Companies House records, and adverse media searches.
- Questionnaire answers and messages — information you submit through the client portal and messages exchanged with the firm.
The firm collects this data to comply with its legal obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 ("MLR 2017"). Providing it is a legal requirement of the firm acting for you — if it is not provided, the firm is unlikely to be able to act on your transaction.
4. Lawful bases for processing
| Processing | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Providing the platform to registered firms | Performance of a contract (6(1)(b)) |
| Customer due diligence, sanctions and PEP screening carried out for firms | Legal obligation of the controller firm under MLR 2017 (6(1)(c)); legitimate interests in preventing financial crime (6(1)(f)) |
| Security logging, audit trails, account lockout | Legitimate interests (6(1)(f)) and the firm's legal obligations |
| Service emails (invites, password resets, evidence requests) | Performance of a contract / legitimate interests |
Where screening reveals information about criminal convictions or allegations, it is processed in line with Art. 10 UK GDPR and the Data Protection Act 2018 Schedule 1 (preventing unlawful acts; complying with regulatory requirements about unlawful acts and dishonesty).
5. Automated analysis and AI
Conveysure uses AI models to help firms review evidence — for example summarising bank statements, drafting risk narratives, and flagging unusual credits for human review. These outputs are drafts and flags only: no decision that affects you (such as a risk rating, an escalation, or a decision to decline a transaction) is made solely by automated means. Every AI output is reviewed and confirmed or rejected by a qualified member of the firm's staff, and the firm's Money Laundering Reporting Officer signs off on escalated matters personally.
Where document analysis is performed by a third-party AI provider, only the material necessary for the analysis is sent, under contractual terms that prohibit the provider from using it to train models.
6. Who we share data with
- The law firm acting for you — all client data belongs to and is visible to your firm; that is the purpose of the service.
- Infrastructure sub-processors — hosting and managed database services located in the UK/EEA, and an email delivery provider for service emails.
- Screening data providers — searches are run against the public UK sanctions list (OFSI), Companies House, sanctions/PEP data services and news sources. A search necessarily discloses the name being searched to the provider.
- AI providers — as described in section 5.
- Authorities — a firm may be legally required to disclose information to the National Crime Agency or other authorities (for example in a Suspicious Activity Report). By law neither the firm nor we may tell you when this happens ("tipping off"). We may also disclose data where required by law or court order.
We never sell personal data.
7. How long we keep data
- Client due-diligence records — MLR 2017 Reg. 40 requires firms to keep CDD records for five years after the business relationship ends. Default retention is configurable by each firm (typically five to six years), after which records are deleted.
- Raw bank statement data — firms can configure early deletion of raw bank statement files (e.g. after six months) while retaining the compliance summary.
- Firm account data — kept for the life of the firm's subscription and deleted or returned on termination, subject to our own legal record-keeping obligations.
- Audit logs — kept for the same period as the records they relate to, because they evidence regulatory compliance.
8. How we protect data
- All traffic is encrypted in transit (TLS); documents and database contents are encrypted at rest by our hosting providers.
- Access is restricted by role and by firm — each firm's data is isolated and staff of one firm can never see another firm's matters.
- Passwords are stored only as salted hashes; repeated failed logins lock the account; sessions expire automatically.
- Client portal access uses single-use invitation links with expiry and one-time-passcode verification.
- Every access to and action on compliance records is written to a tamper-evident audit trail.
9. Your rights
Under UK GDPR you have the right to:
- access a copy of your personal data;
- have inaccurate data rectified;
- request erasure (note: data a firm must keep under MLR 2017 cannot be erased before the statutory retention period ends);
- restrict or object to processing based on legitimate interests;
- data portability for data you provided under a contract;
- not be subject to solely automated decisions with legal or similarly significant effect — as set out in section 5, we do not make such decisions.
If you are a client of a law firm, please direct requests to the firm handling your matter (the controller). If you are firm staff or a website visitor, contact us directly.
10. Contact and complaints
Questions, requests or concerns: [email protected].
You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office: ico.org.uk or 0303 123 1113.