July 21, 2025
We have updated our Privacy Policy on our website. You can find it here or read it in full below.
Effective Date:
18-06-2021 Version: 1
20-05-2021 Version: 2
Main change: The Cookie Policy and list of sub-processors separated from this policy.
11.11.2022 (Date of latest review) Version: 3
Added clauses with respect to the use and grounds for processing of personal data, data protection measures, data subject’s rights, types of processed personal data;
14.03.2023 Version: 4
Added PDPA (Singapore) related clauses.
21.07.2025 Version: 5
Amendments related to the adoption of the EU AI Regulation; refinements in the legal basis for processing of Personal data; added references to UK and Swiss personal data protection legislation; updated list with Trustmoore entities;
Privacy is a fundamental human right and persons engaging with Trustmoore must trust that their Personal data is handled with care. Therefore, protection of privacy and security of Personal Data is very important to Trustmoore. Any processing of Personal data relating to identified or identifiable natural person may only be processed in accordance with this Policy.
GR&CB | The Global Risk & Compliance Board is Trustmoore’s highest decision-making and executive body deciding on all risk and compliance matters that impact Trustmoore. |
CF | Compliance Function |
Client | Natural person or company with which TM enters into a business relationship or for which a trust service is performed. |
Data Controller[1] | The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing of Personal Data; |
Data Processor | Natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Controller. |
Consent | It is any freely given, specific, informed and unambiguous indication of the data subject by which he or she agrees with the processing of their Personal Data. |
Personal Data Breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, compromise, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed by or on behalf of TMG, and which triggers regulatory obligations. |
Personal Data Incident | An event that involves or could involve Personal Data and which has the potential to become a Personal Data Breach. For the purpose of this Policy, Personal Data Incident may also refer to potential Personal Data Breach. |
Data Protection Laws |
The legislation regarding data privacy which may be applicable, based on the location of the TM service provider and of the Data Subject, such as the EU General Data Protection Regulation 2016/679 ("GDPR"), UK GDPR, Personal Data Protection Act (PDPA) Singapore, or any other applicable data protection, privacy laws or privacy regulations. |
Data Subject | A natural person to whom Personal Data relates and who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, etc. |
DPO | Data Protection Officer |
Joint Controllers | Entities that jointly determine the “means and purposes” of the processing of Personal Data. |
KYC | Know-your-client |
Personal Data |
Any information that relates to an identified or identifiable living individual (“Data Subject”). Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data. Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data. |
Processing of Personal Data |
Any operation or set of operations performed on Personal Data or on sets of Personal Data, whether by automated means, such as collecting, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. |
Recipient | Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. |
Sub Processor | The legal or natural person appointed by the processor to process Personal Data on behalf of the Controller. |
Third Party | An individual or a company (i.e. consultants, agents, intermediaries, representatives, subcontractors, suppliers) that performs work, provides a service or sells goods to TM. |
TMG Staff (Employee) | Natural person who works part time or full time under a contract of employment (employment agreement) with a TMG entity or a natural person providing managerial services to TMG based on an agreement between TM and the natural person directly or via a management company indirectly, as well as other persons who act on behalf of TMG within the scope of its business activities and who are therefore in a similar position to the TMG staff, but who are not employed by TMG (e. g. self-employed or temporary workers). |
UBO | Ultimate beneficial owner |
[1] Controller, Joint Controller and Processor, and DPO are terms based on the GDPR, which will be only used for jurisdictions outside the European Union in those cases where GDPR is applicable or the local legislation implements similar terms (such as the PDPA in Singapore or UK GDPR).
Terms that are capitalized, but not defined in this Policy have the same meaning as in the TMG Compliance Charter and the TMG Compliance Risk Control Framework.
In this policy, “Trustmoore” or “TM” for short, “our”, “we” or “us” refers to the global group of entities within the Trustmoore Group, each of which is a separate legal entity, or refers to one or more of those entities. The controllers of your Personal Data are one or more of the Trustmoore entities listed in Annex I hereto “List of TM Entities & Data protection authorities and legislation”, depending on the type of service and jurisdiction in which you engage with Trustmoore.
TM entities in countries outside the European Union (EU) have appointed Trustmoore Coöperatief U.A., company number 34324881, with seat and registered address at De Lairessestraat 145 B, 1075 HJ Amsterdam, the Netherlands, as representative in the EU.
TM recognizes the expectations of the Data subjects, and the inherent risk regarding the privacy, confidentiality and security of their Personal data when it resides within TM.
This Data Privacy Policy describes the privacy practice standards of TM for mitigating the risk regarding the processing of Personal Data: what type of Personal Data TM collects, why and how TM collects, uses and stores it; the legal basis for processing it; and TM’s rights and obligations in relation to such processing.
TM entities globally apply this Policy as a minimum standard for protecting Personal Data. Simultaneously, each TM entity will ensure the application of local Data protection laws ensuring highest standard of privacy, security and transparency.
In particular, TM entities will ensure that data privacy and protection is methodically embedded into relevant business processes and procedures and integrated into affected IT systems and applications (privacy by design and by default). TM entities consider the state of the art, cost of implementation and the nature, scope, context and purposes of processing, as well as the severity and likelihood of risks to the rights and freedoms of Data subjects posed by the processing. Thus, TM entities implement appropriate technical and organizational measure (e. g. pseudonymization and data minimization) in an effective manner and integrate the necessary safeguards into the processing of Personal data.
TM processes Personal data for a variety of purposes. We collect this personal data directly from you, for example, if you work for TM, engage us to provide services to you as a Client, if you visit our website, if you submit your contact details to receive marketing communications from us, if you submit event-related data to attend TM events, you provide services to TM, or submit a job application via the TM careers website.
Alternatively, we process your personal data in the context of providing professional services to an entity that you represent or of which you are a UBO.
Finally, we obtain your personal data via publicly available sources, such as LinkedIn, or through screening platforms in compliance with our KYC obligations. This privacy notice and related privacy statements (Website privacy statement and TMG Employee privacy notice) are intended to cover all of the above-mentioned scenarios.
The purposes, types of Personal Data that TM processes, legal grounds, and concerned Data subjects, depend on the type and scope of the activities engaged:
In providing our services (Corporate Expansion Services, Fund Services; Private Wealth Solutions; Capital Markets Services), TM entities will process information and documents that contain Personal data, such as personal identification documents, bank statements, company records and protocols, accounting and tax data, etc., of the Client, UBO and related parties.
More specifically, but not exhaustively, the Data subjects concerned in Personal data processing related to our services, can be the following:
Examples of categories of processed Personal data in relation to our services are:
Trustmoore processes personal of job candidates, employees and managers in compliance with the TMG Employee privacy notice.
Trustmoore processes personal data about Third parties to manage the contractual relationship with the respective party and/or to perform the respective due diligence checks as required by law.
Generally, the personal data processed in this relation is limited to representative (directors or authorised individuals) and contact information, such as:
In some cases, we also may use Third parties’ personal data to check any potential conflicts of interest and perform due diligence (background) checks required by law (e.g. adverse media, bribery and corruption, crimes, etc.).
In few cases, as some of the Trustmoore entities are licensed and regulated under a strict set of rules, e.g. when applying enhanced due diligence measures as per the applicable AML&CTF legislation and performing background checks and screenings thereunder, TM may process special categories of Personal data such as Personal data relating to:
Trustmoore will implement appropriate technical and organizational safeguards to protect such data, including restricted access, data minimisation, and the use of Data Protection Impact Assessments (DPIAs) where applicable.
In principle, Trustmoore does not process Personal data of minors (below the age of 16). There can be cases where a minor, through their parents or guardians, uses Trustmoore’s services as a way to benefit their economical status. In such cases, Trustmoore processes Personal data of minors only with the parents’/guardians’ explicit consent.
Trustmoore does not knowingly collect data related to religious or philosophical beliefs, sex life, sexual orientation, political views, information about genetic. If such data is accidentally received, it will be deleted from TM’s systems.
Trustmoore is obligated under the respective AML&CTF laws, outsourcing regulations and other applicable legal obligation to perform KYC and background checks on individuals with which Trustmoore engages. Such checks can be performed on any individual as mentioned in the previous section 3 using the data listed there. The legal grounds for such processing is Trustmoore’s legal obligations under the AML&CTF legal acts and other applicable legislation in force, as well as Trustmoore’s internal KYC procedures.
When a Client engages Trustmoore with the provision of professional services, Trustmoore will collect and use Personal data when Trustmoore has a valid business reason to do so, in connection with those services. In the context of providing professional services to Clients, Trustmoore processes Personal data of individuals who are not directly Trustmoore’s Clients (for example: Client’s employees, customers or suppliers, Ultimate Beneficial Owners, Client’s directors or shareholders, business associates, others as the case may require). The legal grounds for processing such Personal data are:
TM processes data of its employees and job applicants for HR and payroll purposes. Legal basis and purposes are described in details in Trustmoore’s Employee privacy notice.
TM processes personal data about Third parties in order to manage TM’s relationship and contract with them, and to receive services from the respective suppliers. Legal grounds for processing personal data of Third parties is the legitimate interest in managing receipt of the services, payments, fees and charges; understanding any conflict of interest, conducting or defending in legal proceedings; safeguarding against dealing with the proceeds of criminal activities or assist in any other unlawful or fraudulent activities.
TM shall not store, transfer, modify, amend or alter, disclose or permit the disclosure, or process the Personal data in any other way other than as appointed above. In cases where processing is required, but not explicitly envisaged in this Policy, then the affected Data subject will be notified accordingly and without undue delay.
Personal data will be kept for the duration of the relationship with Trustmoore and the years after for as long as the latter is needed for complying with all legal, regulatory, and internal policy purposes as defined in Trustmoore’s Data Retention policy and Retention schedules thereto, where in general cases Personal data will not be retained for longer than 10 years after termination of the respective relationship with the Data subject, unless there is a reason for keeping the data for a longer period (e.g. legal proceedings, etc.). After expiration of respective retention period, the corresponding data are routinely deleted and any hard copies of them are destroyed. For more information regarding specific retention periods, contact TMG DPO at privacy@trustmoore.com.
TM may be required to appoint certain sub-processors to provide part of the services to its Clients or Employees, or assist with provision of the services, or render technical support, to which Personal data may be disclosed. Also, TM may share Personal data with authorized Recipients for the due performance of its activities. Such sub-processors or recipients can be: entities within the Trustmoore Group; I.T. service providers; banks and financial institutions; accountancy and legal firms; auditors or other suppliers as required by law or contract.
Each TM entity maintains an extensive third-party register and outsourcing register. In case a query with respect to these registers is made, the DPO at privacy@trustmoore.com can provide the relevant information.
Sub-processors are in each case subject to the terms and conditions laid down by Trustmoore, which are no less protective than those set out in this Policy. With each Sub-processor will be concluded a respective data processing agreement regulating the rights and obligations under the Data protection laws.
Trustmoore utilises Artificial Intelligence (AI) tools to enhance its services, including the use of the following tools:
Trustmoore leverages Artificial Intelligence (AI) to support specific business processes, improve operational efficiency, enhance security, and ensure regulatory compliance — particularly in areas such as:
Legal Basis and Safeguards
Any use of AI systems that involves automated processing of personal data is conducted based on a valid legal basis under Article 6 GDPR, such as:
Trustmoore does not make solely automated decisions that would have a legal or similarly significant effect on individuals without appropriate human oversight.
Trustmoore ensures that all AI-based processing is subject to:
Trustmoore takes appropriate measures to comply with Data Protection Laws in order to ensure Data Subjects rights. In case Data Subjects have any questions, requests or complaints regarding their rights, they are encouraged to contact Trustmoore via privacy@trustmoore.com. Any written question, request or complaints should have a clear subject related to the rights of the Data Subjects.
Subject to the applicable local legislation, all Data Subjects will have at least the following rights with respect to their Personal data:
Personal Data Incidents and Personal Data Breaches are handled according to the Data Protection Laws and in accordance with TMG Data Breach Procedure whereunder Trustmoore entities (Data Controllers) and Data Processors have implemented and maintain effective processes to ensure timely notification to the DPO and respective Data protection authorities.
TM keeps the Personal data confidential and will ensure its employees, managers and Sub-processors are bound by the same confidentiality obligation.
Trustmoore ensures proper level of awareness of this Policy and Trustmoore’s obligations under the Data protection laws by means of providing trainings and awareness sessions to Employees and Sub-processors. Each Trustmoore Employee must adhere to and comply with this Policy.
Trustmoore has adopted and implemented the following technical measures, but are not limited to:
Trustmoore entities operate in more than one jurisdiction. Certain aspects of Trustmoore infrastructure are centralized, including information technology services provided to Trustmoore entities. In addition, where engagements with TM Clients span more than one jurisdiction, certain information will need to be accessed by all those within TM who are working on the matter on a need-to-know basis. Therefore, Personal Data may be made available or transferred to and stored outside the country in which Data subjects are located. This may also include countries outside the European Economic Area (EEA).
TM ensures appropriate security and legal precautions to protect the safety and integrity of Personal data that is transferred within the Trustmoore Group by entering into respective standard data protection clauses (SCCs) as adopted by the European Commission with all third-parties outside the EEA.
Any other data transfer will be performed under the most suitable safeguarding measure e.g. adequacy decisions or SCCs, ensuring at least the same level of security as stated in this Policy.
TM discloses your personal data:
TM does not share any Personal Data for advertising or direct marketing purposes without the Data subject’s explicit consent.
Data Subjects have the right to lodge a complaint to the respective data protection authority in their country. List of data protection authorities in the jurisdictions within which TM operates is indicated in Annex I “List of TM Entities & Data protection authorities and legislation & Data protection authorities and legislation”. Complaints may also be submitted to privacy@trustmoore.com.
Group DPO is Katya Mihaylova available at privacy@trustmoore.com. The DPO advises on all topics related to Data privacy and protection laws, regulations, regulatory guidance, as well as compliance therewith and must support and liaise with other functions on related topics. The DPO liaises with authorities, regulators, associations and other stakeholders on matters related to Data privacy and protection, monitors TM entities’ implementation and adherence to this Policy in conjunction with other relevant functions at TM or through independent reviews, maintains and updates the Data Privacy Policy and notifies TM entities of any such changes without undue delay.
Country | TM Entity | Address | Local Data protection comission | Local legislation |
Netherlands | Stichting Administratiekantoor Trustmoore;Stichting Administratiekantoor Trustmoore Investments;
Trustmoore Coöperatief U.A.; Trustmoore Netherlands B.V.; TM Administration Services B.V.; TM Support Netherlands B.V.; Premises B.V.; TM Fund Services (Netherlands) B.V.; Trustmoore SFCM Netherlands B.V.; Trustmoore SFCM Trustee & Management NL B.V.; Freeland Corporate Advisors N.V.; Trustmoore Liquidation Services Netherlands B.V.
|
De Lairessestraat 145, 1075 HJ AmsterdamNetherlands | Autoriteit Persoonsgegevens Website: https://www.autoriteitpersoonsgegevens.nl |
https://www.autoriteitpersoonsgegevens.nl/themas/basis-avg/privacy-en-persoonsgegevens/privacywetgeving |
Luxembourg | Trustmoore Luxembourg S.A.;TM Regulatory Services S.à r.l.;
TM Luxembourg Director S.à r.l.; Square Investment Company S.A.; Funds Avenue S.A.
|
6 Rue Dicks L-1417 Luxembourg Grand Duchy of Luxembourg |
National Comission for Data ProtectionWebsite: https://cnpd.public.lu/en.html | https://cnpd.public.lu/en/legislation/droit-lux.html |
Luxembourg | TM Administration Services Luxembourg S.à r.l.; | 8 Rue Dicks L-1417 Luxembourg Grand Duchy of Luxembourg |
National Comission for Data ProtectionWebsite: https://cnpd.public.lu/en.html | https://cnpd.public.lu/en/legislation/droit-lux.html |
Malta | Trustmoore Corporate Services (Malta) Limited;Trustmoore Malta Limited;
TM Admin (Malta) Limited |
97, Level 1, Windsor Street Sliema, SLM 1853 Malta |
Information and Data Protection Commisioner Website: https://idpc.org.mt/ |
Data Protection Act
|
Switzerland | Trustmoore Switzerland AG | Bodmerstrasse 7 8002 Zurich Switzerland |
Federal Data Protection and Information Commissioner https://www.edoeb.admin.ch/en |
https://www.edoeb.admin.ch/en/legal-basis-data-protection |
Curaçao | TM Fund Services Curaçao NV;Trustmoore (Curaçao) N.V.;Trusthouse Holding N.V.;
Trustmoore Private Management N.V.; Trustmoore Global Trustee Services N.V.; Trustmoore Corporate & Administrative Services N.V.;
|
Landhuis Groot Kwartier Groot Kwartierweg 12 Willemstad, Curaçao |
Data Protection Board | https://irp-cdn.multiscreensite.com/9e98b338/files/uploaded/Landsverordening-bescherming-persoonsgegevens-Curacao-4-9-2010.pdf |
Bulgaria | Trustmoore Bulgaria EOOD | 105 Knyaz Boris I Str., 1000 Sofia, Bulgaria | Commission for Personal Data Protection
Website: https://www.cpdp.bg
|
Personal Data Protection Act https://www.cpdp.bg/en/index.php?p=rubric&aid=2 |
Ireland | Trustmoore Ireland LimitedTrustmoore Nominee Services (Ireland) Limited
Trustmoore Trustee (Ireland) Limited Trustmoore Corporate Secretary (Ireland) Limited |
31-32 Leeson Street Lower Dublin 2,D02 KA62 , Ireland | Data Protection Comission https://www.dataprotection.ie/en |
https://www.dataprotection.ie/en/dpc-guidance/law/data-protection-legislation#Legislation |
United Kingdom | Trustmoore (UK) LtdTrustmoore UK Trustees Ltd
Trustmoore Nominee Services UK Ltd Trustmoore Nominee Services UK 1 Ltd Trustmoore Nominee Services UK 2 Ltd Trustmoore Nominee Services UK 3 Ltd Trustmoore Nominee Services UK 4 Ltd Trustmoore Nominee Services UK 5 Ltd Trustmoore UK Officer Ltd
|
Central House, 20 Central Avenue, St Andrews Business Park, Norwich, England, NR7 0HR | Information Commissioner’s Office https://ico.org.uk/ |
https://www.gov.uk/data-protection |
Singapore | Trustmoore Singapore Private Limited | 83B Tanjong Pagar Rd Singapore 088504 |
Personal Data Protection Commission
|
https://www.pdpc.gov.sg/overview-of-pdpa/the-legislation/personal-data-protection-act |
Reach out to us today
© 2025 TRUSTMOORE. All rights reserved.