Legal
Privacy Policy
Effective date: 2 August 2026 Last updated: 25 August 2026
Our approach
Scott & Vale is a private members firm. Discretion is not a courtesy we extend — it is the condition on which the firm operates.
We do not publish member names. We do not confirm or deny whether an individual is a member. We do not discuss mandates, itineraries, holdings or household arrangements outside the small team engaged on the work. Where a mandate requires a third party to act — a charter operator, a property agent, a driver — that party receives only what is required to perform, and is not told more about the member than the task demands.
This policy explains what information we hold, why we hold it, who may see it, and the rights you have over it. It applies to members, prospective members, principals and the members of their households and travelling parties, introducers and referral partners, supplier contacts, and visitors to scottnvale.com.
1 Who is responsible for your information
Scott & Vale (“Scott & Vale”, “we”, “us”) is the controller of the personal information described in this policy. We decide what is collected, why, and for how long it is kept. No other entity determines those questions on our behalf.
Questions about this policy, or any request concerning your information, should go to info@scottnvale.com.
2 Information we collect
Identity and contact information. Name, title, date of birth, nationality, contact details, preferred channels and languages, and the identity documents described at section 4.
Membership and engagement information. Your application and the information supporting it, your member reference, the terms of your engagement, correspondence with us, and our internal notes on your requirements and standards.
Mandate information. What is required to execute the work you instruct. Depending on the mandate this may include travel documents and passport details, flight and vessel preferences, accommodation and property requirements, dietary and accessibility requirements, event and access preferences, vehicle and ground movement details, and details of the assets or acquisitions concerned.
Information about other people. Mandates commonly involve people other than the member — family members, guests, household staff, principals’ assistants, travelling parties. Where you provide their information to us, section 3 applies.
Financial and payment information. Billing details, payment instructions, card authorisation mandates where you have given one, invoice and settlement records, and the source-of-funds information described at section 4.
Compliance information. The records generated by our identity verification, sanctions and financial crime screening, and mandate acceptance decisions.
Introducer and partner information. Contact and professional details, the introductions made, and the commercial arrangements between us.
Website information. Enquiry form submissions, and the technical and usage information described at section 11.
Special category information. We do not seek information revealing health, religious belief or similar sensitive matters. Some of it reaches us anyway in the ordinary course of a mandate — a dietary restriction, a medical requirement affecting travel, an accessibility need. Where it does, we use it only to execute the mandate concerned, we do not retain it longer than that mandate requires, and we rely on your explicit consent, which you may withdraw at any time.
3 Information you give us about other people
Where you provide us with information about another person — a family member, a guest, an assistant, a member of your household — you confirm that you are entitled to do so and that they are aware their information will be shared with us and used as described here.
Where it is appropriate and practical, we will make this policy available to them directly. If you would prefer that we did not contact them, tell us and we will not.
4 Identity verification, source of funds, and financial crime checks
Before we accept a member or execute certain mandates, we carry out identity verification and financial crime checks. This is the most sensitive information we hold, and we want to be precise about it.
What we collect. Government-issued photographic identification, proof of address, information about the source of the funds involved in an engagement or transaction and the evidence supporting it, and where relevant the ownership and control structure of any entity involved.
What we do with it. We verify identity, screen against sanctions, politically exposed person and adverse media sources, assess the mandate against our acceptance policy, and record the decision.
Who we use. We may use specialist verification and screening providers to perform these checks. They act on our instructions and under contract.
What we will not do. We do not collect identity documents on a pretext, or collect them for a purpose other than the one for which they were requested. If someone asks you for identity documents in the name of Scott & Vale outside a mandate we have confirmed to you in writing, treat that request as fraudulent and tell us.
Retention. Records created for these purposes are subject to the retention rules at section 8 and — importantly — are not deletable on request during the mandatory retention period.
Legal basis. Compliance with legal obligations to which we are subject, and our legitimate interest in protecting the firm and its members from financial crime.
5 Why we use your information, and on what legal basis
Where UK or EU data protection law applies, we rely on the following:
| What we do | Legal basis |
|---|---|
| Assess a membership application and decide on admission | Steps taken at your request prior to a contract; our legitimate interest in maintaining the standards of the membership |
| Provide the services you instruct and execute mandates | Performance of our contract with you |
| Instruct and coordinate third parties to fulfil a mandate | Performance of our contract with you |
| Communicate with you, including outside business hours | Performance of our contract with you |
| Identity verification, sanctions screening and financial crime checks | Legal obligation; legitimate interest in protecting the firm and its members |
| Invoice, take payment and keep accounting records | Performance of contract; legal obligation |
| Maintain records of mandates, standards and preferences | Legitimate interest in delivering a consistent service |
| Manage introducer and partner relationships | Performance of contract; legitimate interest |
| Establish, exercise or defend legal claims | Legitimate interest; legal obligation |
| Understand how the website is used | Consent, where required |
| Send you information about the firm where you have asked for it | Consent; legitimate interest in existing relationships |
Where we rely on legitimate interests, we have considered the effect on you and are satisfied our interest does not override your rights. You may ask us to explain that assessment, and you may object — see section 9.
Where information reaches us about people other than the member — household members, guests, travelling parties — the legal basis is our legitimate interest in performing the mandate we have been instructed to carry out.
6 Who we share information with
We do not sell personal information. We do not share it for anyone else’s marketing.
We disclose it to the following categories of recipient:
Suppliers and operators engaged on a mandate. Aviation operators and brokers, yacht managers and brokers, hotels and private residences, ground transport operators, property agents, art specialists, event and access providers, and similar. They receive only what is required to perform, and no more.
Consistent with how the firm operates, we contract with these parties ourselves. We do not, as a matter of course, disclose our supply arrangements to members, and we do not disclose our members to a supplier beyond what performance requires.
Professional advisers. Lawyers, accountants, auditors and insurers, under professional duties of confidence.
Verification and screening providers. As described at section 4.
Financial institutions and payment providers. Banks, payment processors and treasury providers, for settlement and for their own regulatory obligations.
Technology and infrastructure providers. Communications, secure document exchange, scheduling, storage, hosting and business systems, including the platform that hosts this website and receives its enquiry form submissions. Sensitive documents are exchanged over an encrypted channel we specify, not over ordinary email.
Introducers and referral partners. Where an introduction has been made, and only to the extent required to administer that relationship.
Authorities and regulators. Where we are required to disclose by law, court order or regulatory demand, or where disclosure is necessary to prevent or report financial crime. In some cases the law prohibits us from telling you that such a disclosure has been made.
A successor. If the firm or part of it is reorganised, transferred or acquired, information may pass to the successor entity under equivalent confidentiality terms.
Each recipient is engaged under contractual confidentiality and data protection terms.
7 International transfers
The firm operates across the United Kingdom, the United States, Europe, the Gulf, Southern Africa and selected Asian markets. Executing a mandate in one of those markets necessarily involves transferring information to it.
Where we transfer personal information out of the United Kingdom or the European Economic Area to a country without an adequacy decision, we put in place an appropriate safeguard — ordinarily the UK International Data Transfer Agreement or Addendum, or the European Commission’s Standard Contractual Clauses — together with any additional measures the transfer requires.
You may request details of the safeguard applying to a particular transfer by contacting us.
8 How long we keep information
We keep information for as long as the relationship and the law require, and no longer.
- Membership and mandate records: for the duration of your membership and for six years after it ends, reflecting the limitation period for contractual claims.
- Identity verification, source of funds and financial crime records: for five years from the end of the business relationship or the completion of the transaction, as anti-money laundering law requires. This period is mandatory. We cannot delete these records on request while it runs, and a deletion request will not shorten it.
- Financial and accounting records: for the period required by applicable tax and company law.
- Applications that do not proceed: for twelve months, unless you ask us to remove them sooner or we have a legal reason to keep them.
- Special category information reaching us through a mandate: for the duration of that mandate only.
- Website enquiries: for twelve months, unless a relationship follows.
Where we are required to retain a record but no longer need it operationally, we restrict access to it rather than continue to use it.
9 Your rights
Subject to the retention obligations at section 8, you may ask us to:
- Access the personal information we hold about you, and receive a copy.
- Correct information that is inaccurate or incomplete.
- Delete information where we no longer have a lawful basis to keep it.
- Restrict how we use information while a question about it is resolved.
- Object to use we base on legitimate interests, including profiling.
- Port information you provided to us, where we hold it on the basis of contract or consent.
- Withdraw consent at any time, where consent is the basis we rely on. Withdrawal does not affect anything done before it.
Write to info@scottnvale.com. We will respond within one month, and will tell you promptly if a request is complex enough to need longer.
We may need to verify your identity before we act — a necessary step, given what we hold.
If you are in South Africa, you have equivalent rights under the Protection of Personal Information Act, including the right to complain to the Information Regulator. Our Information Officer can be reached at info@scottnvale.com.
If you are a California resident, you have rights to know, delete, correct and opt out under the CCPA as amended. We do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising. We will not discriminate against you for exercising a right.
10 Security
Sensitive documents are exchanged over an encrypted, access-controlled channel that we will specify to you — not over ordinary email. Access to member information inside the firm is limited to those engaged on the relevant mandate. Team members and contractors are bound by written confidentiality obligations that survive the end of their engagement. Devices and accounts are protected by multi-factor authentication and encryption at rest.
No transmission or storage method is perfectly secure and we do not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where the risk is high, you — without undue delay.
If you receive a communication purporting to come from Scott & Vale that asks for payment to unfamiliar account details, or for identity documents outside a mandate you have confirmed with us, do not act on it. Contact us on a number or address you already hold.
11 Cookies and analytics
Our website uses cookies that are strictly necessary for it to function. These do not require your consent.
We do not run analytics, tag managers or any other non-essential cookies on this site, so there is nothing here for you to consent to or refuse. Our host records ordinary server request information — including IP address, browser and the pages requested — for the security and delivery of the site.
We do not use advertising cookies and we do not sell personal information.
12 Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Screening tools may flag a matter for review, but admission and mandate decisions are made by people.
13 Children
Our services are directed at adults. We do not knowingly collect information about children other than where a member provides it in connection with family travel or household arrangements, in which case it is used only for that purpose and retained only for the duration of that mandate.
14 Changes to this policy
We may update this policy. Where a change materially affects how we use your information, we will tell members directly rather than rely on a website notice.
Any question about this policy is answered by the firm, not by a form. info@scottnvale.com