Avagance — Privacy Policy
Last updated: 24 August 2026
1. Introduction
This Privacy Policy explains how Avagance Limited (referred to in this policy as "Avagance", "we", "us" or "our") collects, uses, shares and protects personal data.
Avagance Limited is a company registered in England and Wales under company number 15991387, with its registered office at 128 City Road, London, EC1V 2NX.
Avagance Limited was formerly registered as Bro In Finance Ltd. The legal entity, company number and registered office are unchanged; only the name has changed.
Avagance provides software for UK financial advisers. Our platform (the "Platform") includes our public website at https://avagance.com (the "Website"), the Avagance adviser portal, the client portal, our AI assistant ("Ava"), and related applications, APIs and services.
This policy covers:
- visitors to our Website;
- individuals at prospective and existing customer firms who create accounts, receive communications from us, or otherwise interact with us; and
- the personal data we process on behalf of our customer firms in the course of providing the Platform.
We are not a financial adviser and we do not provide regulated financial advice. Avagance is a technology provider. Our customers are financial advice firms and their staff, who are responsible for the regulated advice they give to their own clients.
2. Our two roles: controller and processor
Data-protection law distinguishes between a controller (who decides why and how personal data is processed) and a processor (who processes personal data on a controller's instructions). Avagance acts in both roles depending on the data:
2.1 Where Avagance is the controller
We are the controller for personal data that we decide how to use for our own purposes, including:
- Website visitors — analytics, cookies and enquiry/contact form submissions;
- Prospects and leads — information you give us when you request a demo, start a trial, or contact our sales team;
- Customer firm users — the account, contact, billing and usage data of the advisers, administrators and other staff who use the Platform under a customer firm's subscription; and
- Suppliers and other business contacts.
Sections 3–14 of this policy describe how we handle this data.
2.2 Where Avagance is the processor
When a customer firm uses the Platform to manage information about its own clients (for example, a client's contact details, financial circumstances, portfolio, fact-find, meeting notes, documents and communications), the customer firm is the controller of that client data and Avagance is the processor. We process that data only to provide the Platform and only on the customer firm's documented instructions.
Our handling of client data in this role is governed by our Data Processing Agreement (DPA) with the customer firm, not by this policy. If you are a client of a financial advice firm that uses Avagance and you have questions about how your data is used, please contact that firm directly — they are your controller and the first point of contact for your rights.
The remainder of this policy focuses primarily on the data for which Avagance is the controller.
3. The personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
a) Identity and contact data Name, job title / role, employer or firm name, business email address, business telephone number, and (where you provide it) an FCA firm reference number.
b) Account and profile data Username, hashed password and authentication credentials, multi-factor authentication settings, user role and permissions, avatar/profile settings, language and communication preferences, and firm/team membership.
c) Subscription and billing data Plan and package selection, seat counts, AI-credit usage, billing contact details, and payment/transaction records. Card payments are processed by our payment provider (Stripe) — we do not store full card numbers on our systems.
d) Usage, device and technical data IP address, browser and device type, operating system, referring URLs, pages and features accessed, actions taken in the Platform, session logs, error/diagnostic logs, and approximate location derived from IP address.
e) Cookies and similar technologies See section 10.
f) Communications data The content of enquiries, support requests, emails, in-product messages, and records of our correspondence with you, including marketing preferences and consents.
g) Voice and meeting data (where you use those features) Where a user chooses to use voice or note-taking features, we may process audio and derived transcripts to deliver the feature. Use of these features is subject to in-product consent controls and the customer firm's own consent obligations toward its clients.
We generally do not seek to collect special category data (see section 4) about the users of our Platform in our capacity as controller.
4. Special category and vulnerability data
Some features of the Platform are designed to help customer firms record information about their clients that may include special category data under UK GDPR Article 9 (for example, health information relevant to a client's financial vulnerability).
Where such data is processed, it relates to a customer firm's clients and the customer firm is the controller — Avagance processes it only as a processor on the firm's instructions and in accordance with the DPA. The lawful basis and any Article 9 condition for processing that data are the responsibility of the customer firm.
We do not use client special category data for our own purposes.
5. How we collect personal data
We collect personal data:
- Directly from you — when you visit the Website, complete a form, request a demo or trial, create or configure an account, subscribe, contact us, or use the Platform.
- Automatically — through cookies, server logs and similar technologies when you use the Website or Platform (see sections 3(d) and 10).
- From your firm — when your employer or firm sets up your account or invites you to the Platform.
- From third parties — such as our payment provider, fraud-prevention and bot-protection services, our live-chat provider, analytics providers, and (where relevant) publicly available regulatory registers such as the FCA Register.
6. Why we use personal data, and our lawful bases
As controller, we process personal data for the purposes below. For each purpose we rely on one or more lawful bases under UK GDPR Article 6:
| Purpose | Lawful basis |
|---|---|
| Providing, operating, securing and maintaining the Platform and your account | Performance of a contract; legitimate interests |
| Authenticating users and preventing unauthorised access | Legitimate interests; legal obligation (security) |
| Processing subscriptions, billing, payments and collections | Performance of a contract; legal obligation (tax/accounting) |
| Responding to enquiries, demo/trial requests and support tickets | Legitimate interests; steps prior to entering a contract |
| Sending service, security and administrative communications | Performance of a contract; legitimate interests |
| Sending marketing communications about our products and similar services | Consent, or legitimate interests where permitted for existing business contacts (you may opt out at any time) |
| Understanding and improving how the Platform and Website are used, including analytics and product development | Legitimate interests |
| Training, evaluating and improving our AI and machine-learning features (see section 8) | Legitimate interests (and, where required, consent); subject to the safeguards in section 8 |
| Detecting, investigating and preventing fraud, abuse, and security incidents | Legitimate interests; legal obligation |
| Complying with legal, regulatory and accounting obligations, and establishing, exercising or defending legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can ask us for more information about that balancing test (see section 16). Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing.
7. Marketing communications
We may send you marketing about Avagance products and services where you have consented, or where you are an existing or prospective business contact and we are permitted to do so under applicable law.
You can opt out of marketing at any time by using the unsubscribe link in our emails or by contacting us at policy@avagance.com. Opting out of marketing does not stop service, security or transactional messages that are necessary to operate your account.
8. Artificial intelligence, "Ava", and machine learning
The Platform includes AI-assisted features — including our assistant Ava — that help users draft documents, summarise meetings, analyse portfolios, check compliance, and carry out related tasks. You should understand the following:
- AI outputs are assistive, not authoritative. AI-generated content is a draft to support a qualified adviser. It must be reviewed by a human before it is relied on or sent to a client. AI features do not replace professional judgment or a firm's regulatory obligations.
- Third-party AI processors. To deliver these features we use third-party AI and infrastructure providers (for example, OpenAI for language-model processing, and other machine-learning and speech-to-text providers). Data sent to these providers is limited to what is needed to deliver the feature and is governed by our contracts with them, including restrictions on their further use of the data.
- Model training. We do not permit our AI sub-processors to use customer client data processed through the Platform to train their own general models, except as needed to provide the service and as permitted by our DPA with the relevant customer firm. Where we use data to improve our own features (for example, quality evaluation and calibration), we apply minimisation, and use anonymised, aggregated or pseudonymised data wherever practicable.
- Automated decision-making. The Platform is designed so that a human adviser makes and is responsible for advice and other significant decisions. We do not use AI to make decisions that produce legal or similarly significant effects about you without human involvement. See section 15.
9. Who we share personal data with
We share personal data only where necessary, and subject to appropriate safeguards, with:
- Service providers and sub-processors who help us run the Platform and our business — including cloud hosting and infrastructure, database and storage, payment processing, AI and machine-learning processing, speech-to-text, email delivery, error monitoring, analytics, and bot/fraud protection. Our current key sub-processors include (illustrative — we maintain a current list and provide it on request):
- Google Cloud Platform — hosting, database and storage;
- OpenAI — AI language-model processing;
- Modal — machine-learning compute;
- Deepgram — speech-to-text for voice/note-taking features;
- Stripe — subscription billing and payments;
- Cloudflare — bot protection and security for web forms;
- Tawk.to — live chat, where you use it on the Website or in the Platform;
- our email delivery provider — transactional and, where applicable, marketing email.
- Integration partners you connect — where a customer firm chooses to connect a third-party service (for example, a CRM such as Intelliflo, cash-flow planning such as Voyant, or an e-signature service), we exchange data with that service to provide the integration, at the firm's instruction.
- Professional advisers — our accountants, auditors, insurers and lawyers, under duties of confidentiality.
- Authorities and other parties — where required to comply with a legal or regulatory obligation, to enforce our agreements, or to protect our rights, users, or the public; and in connection with a corporate transaction (such as a merger, acquisition or asset sale), subject to appropriate confidentiality protections.
We do not sell your personal data.
10. Cookies and similar technologies
The Website and Platform use cookies and similar technologies to operate, to keep you signed in and secure, to remember your preferences, and to understand and improve usage.
- Strictly necessary cookies are required for the Website/Platform to work (for example, session, authentication and security cookies, including our bot-protection provider).
- Functional cookies remember your settings and preferences.
- Analytics cookies help us understand how the Website and Platform are used.
- Live chat, where you use it, sets cookies and local storage on whichever domain you are on, including the Platform. We do not load it for anyone who has not either switched it on or clicked to open a chat, and that click is itself the request for the service.
Where required by law, we ask for your consent before setting non-essential cookies, and you can manage your preferences through our cookie banner/settings and your browser controls. Blocking some cookies may affect how the Website or Platform works.
11. International transfers
We are based in the United Kingdom and aim to store and process personal data in the UK and/or European Economic Area (EEA) where practicable. However, some of our sub-processors (for example, certain AI and infrastructure providers) may process personal data outside the UK/EEA, including in the United States.
Where personal data is transferred outside the UK, we put in place an appropriate safeguard recognised under UK data-protection law — such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or reliance on UK adequacy regulations — together with any supplementary measures needed. You can ask us for details of the safeguards that apply (see section 16).
12. How long we keep personal data
We keep personal data only for as long as necessary for the purposes described in this policy, including to provide the Platform, to meet legal, regulatory, tax and accounting requirements, to resolve disputes, and to enforce our agreements. Typical principles we apply:
- Account data — for the life of the account, and for a limited period afterwards.
- Billing and transaction records — for the period required by tax and accounting law (generally at least 6 years).
- Marketing data — until you opt out or after a period of inactivity.
- Website analytics and logs — for a limited retention period consistent with security and product needs.
When personal data is no longer needed, we securely delete or anonymise it. For client data processed as processor, retention is set by the customer firm and governed by the DPA.
13. How we protect personal data
We take appropriate technical and organisational measures to protect personal data, including encryption of data in transit and (for sensitive data) at rest, access controls and least-privilege permissions, multi-tenancy isolation so a firm's data is kept separate, network and infrastructure hardening, audit logging, secrets management, and monitoring. No system is perfectly secure, but we work to protect personal data against unauthorised access, loss, alteration or disclosure, and we maintain procedures to deal with any suspected personal-data breach, including notifying the ICO and affected individuals where legally required.
14. Children
The Platform is a business tool intended for financial-advice professionals and is not directed at children. We do not knowingly collect personal data from children through the Website or in our capacity as controller. Any processing of data about a customer firm's clients (who may in some cases include minors, such as in a Junior ISA context) is carried out as a processor on the firm's instructions.
15. Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. The Platform's AI features are designed to assist a human adviser, who remains responsible for decisions. We may carry out limited profiling for security, fraud-prevention and product-analytics purposes on the basis of our legitimate interests.
16. Your rights
Subject to the conditions and exemptions in UK data-protection law, you have the right to:
- be informed about how we use your personal data (this policy);
- access the personal data we hold about you;
- rectify inaccurate or incomplete personal data;
- erase your personal data ("right to be forgotten") in certain circumstances;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests, and to direct marketing at any time;
- data portability — receive certain data in a portable format;
- withdraw consent at any time where we rely on consent; and
- not be subject to a solely automated decision with legal or similarly significant effects (see section 15).
To exercise any of these rights, contact us at policy@avagance.com. We will respond within the timeframes required by law (usually one month). We may need to verify your identity first.
If you are a client of an advice firm that uses Avagance, the firm is your controller. Please direct your request to the firm; if we receive it, we will refer you to the relevant firm and assist the firm as its processor.
17. Third-party websites
The Website and Platform may link to third-party websites and services that we do not control. This policy does not apply to those sites. We encourage you to read the privacy notices of any third-party site you visit.
18. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Please review this policy periodically.
19. How to contact us, and your right to complain
Data controller: Avagance Limited Registered office: 128 City Road, London, EC1V 2NX Company number: 15991387 (England and Wales) Privacy/data-protection contact: policy@avagance.com Data-protection lead: We have assessed that we are not required to appoint a statutory Data Protection Officer under Article 37 UK GDPR. A named member of our leadership is accountable for data protection and is reachable at policy@avagance.com. ICO registration: Avagance Limited is registered with the Information Commissioner's Office. Our entry on the ICO register is currently recorded under our former name, Bro In Finance Ltd, and is being updated to reflect the change of name. The legal entity and company number are unchanged.
If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 · ico.org.uk