1. Who We Are
This Privacy Policy explains how Bertolini & Co. Ltd, a company registered in England and Wales under company number 16935983, trading as Brücke (“Brücke”, “we”, “us”, “our”), collects, uses, shares and protects your personal data.
We are the data controller in respect of the personal data described in this Policy.
- Registered office: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
- Privacy contact (all privacy matters): privacy@brucke.co.uk
- Website: https://brucke.co.uk
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Because our clients and their documents frequently originate in Brazil, we also observe the principles of the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, Law 13.709/2018 — “LGPD”) in respect of data subjects located in Brazil.
2. Scope
This Policy applies to the personal data of:
- Visitors to our website and individuals who complete our enquiry forms;
- Individual clients of our personal dossier services;
- Representatives, shareholders, directors and ultimate beneficial owners of corporate clients;
- Business contacts, partners and suppliers.
3. Personal Data We Collect
3.1 Website and enquiry data
Name, email address, telephone or WhatsApp number, preferred language, intended destination country, service objective, timeframe, any free-text message, and campaign attribution data. We also collect technical data such as IP address, browser type and pages visited, and cookie data (see Section 10).
3.2 Individual client data (dossier services)
To deliver our services, we process:
- Identity data: name, date of birth, nationality, marital status, identification numbers (including CPF, national identity documents and passport), and address.
- Financial data: income tax returns (including the Brazilian IRPF declaration), proof of income, bank statements, assets and holdings, credit reports and banking references.
- Source-of-funds data: documentation evidencing the origin of your wealth, such as asset sales, inheritance, or corporate distributions.
- Family data: where required by your objective, such as family reunification or school enrolment of dependants.
3.3 Criminal offence data and special category data
Where your chosen service requires it — most commonly visa and residence applications — we process criminal record certificates (police clearance). Under Article 10 of the UK GDPR, personal data relating to criminal convictions and offences is subject to enhanced protection.
We process this data solely on the basis of your explicit consent, and exclusively for the purpose of preparing the dossier you have engaged us to deliver. You may withdraw that consent at any time, although doing so may prevent us from completing the service.
We may also process health-related data (for example, vaccination records) where an educational institution or immigration authority requires it, again solely on the basis of your explicit consent.
3.4 Corporate client data
Corporate documents (constitutional documents, shareholding structure), financial statements and regulatory certificates. Necessarily, this includes personal data of shareholders, directors and ultimate beneficial owners (UBOs), as required by the know-your-customer and anti-money-laundering procedures of the receiving financial institutions.
3.5 Third-party data you provide
If you provide us with personal data relating to another person (a spouse, child, business partner or guarantor), you confirm that you have the authority or consent to do so, and you undertake to make them aware of this Policy.
4. Why We Use Your Data and Our Legal Basis
| Purpose | Legal basis (UK GDPR) | Legal basis (LGPD) |
|---|---|---|
| Responding to enquiries and providing quotations | Steps prior to entering a contract; legitimate interests | Preliminary procedures; legitimate interests |
| Preparing and delivering your dossier | Performance of a contract (Art. 6(1)(b)) | Performance of a contract (Art. 7, V) |
| Processing criminal record certificates and other special category data | Explicit consent (Art. 9(2)(a); Art. 10 UK GDPR and Schedule 1, Data Protection Act 2018) | Specific and highlighted consent (Art. 11, I) |
| Coordinating apostille, sworn translation and audit services | Performance of a contract | Performance of a contract |
| Submitting documentation to banks, funds, consulates, educational institutions, landlords or notaries on your behalf and at your request | Performance of a contract | Performance of a contract |
| Taking payment for our services | Performance of a contract; legal obligation | Performance of a contract; legal obligation |
| Meeting legal, tax, accounting and anti-money-laundering obligations | Legal obligation (Art. 6(1)(c)) | Compliance with a legal obligation (Art. 7, II) |
| Marketing and commercial communications | Consent (withdrawable at any time) | Consent |
| Security, fraud prevention and defence of legal claims | Legitimate interests | Regular exercise of rights |
We never sell your personal data.
5. Who We Share Your Data With
We share your data only to the extent necessary to deliver the service you have engaged us to provide.
5.1 Recipients of your dossier (at your request and on your behalf)
Banks and financial institutions; investment and credit funds; consulates and immigration authorities; educational institutions; landlords and letting agents; notaries and public registries; and, for corporate services, commercial suppliers.
Please note: the purpose of a dossier is to be presented to these counterparties. By engaging our services, you instruct us to prepare and, where applicable, transmit your documentation to them.
5.2 Service providers (processors)
- Sworn and certified translators in the destination countries (United Kingdom, Ireland, Spain, France, Italy, Germany, Switzerland)
- Notaries and apostille services in Brazil
- Credit bureaux and, with your authorisation, the credit information system of the Central Bank of Brazil
- Independent auditors and valuers (corporate services)
- Accountants and lawyers supporting the engagement
- Stripe, our payment processor, which processes payment data on our behalf. We do not store your full payment card details.
- Technology providers: website hosting, customer relationship management, email and secure cloud storage
All processors are bound by contractual obligations of confidentiality and security, and may process your data only on our documented instructions.
5.3 Authorities
Where required by law, court order or regulatory obligation.
6. International Transfers of Data
By the very nature of our services, your data will be transferred across borders — typically from Brazil to the United Kingdom, and onward to countries in the European Union or Switzerland.
Such transfers are inherent and necessary to the performance of the service you have engaged us to provide. For example, delivering a German dossier requires sending your Brazilian documents to a sworn translator in Germany and then to a German bank.
Where we transfer personal data outside the United Kingdom, we ensure an appropriate safeguard is in place, which may include:
- UK adequacy regulations, where the destination country has been recognised as providing an adequate level of protection (which includes the European Economic Area and Switzerland);
- The International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, where no adequacy decision applies;
- Your explicit instruction or consent, where the transfer is necessary for the performance of your contract with us.
You may request further information about the safeguards applied to a specific transfer by contacting us at privacy@brucke.co.uk.
7. How Long We Keep Your Data
| Category | Retention period |
|---|---|
| Enquiries that do not become engagements | 24 months from the last contact |
| Client documentation and dossiers | For the duration of the engagement and thereafter for the applicable statutory period — typically 6 years, to meet tax, accounting and anti-money-laundering requirements |
| Criminal record certificates and special category data | Deleted as soon as the purpose has been fulfilled, unless a legal obligation requires otherwise |
| Tax and accounting records | As required by law |
| Marketing data | Until you withdraw consent |
At the end of the applicable period, data is securely deleted or anonymised.
8. Data Security
We implement appropriate technical and organisational measures, including encryption in transit and at rest; access restricted on a need-to-know basis; a secure data room for the submission of documentation (we will never ask you to send sensitive documents through insecure channels); confidentiality agreements with our suppliers; and incident response procedures.
In the event of a personal data breach presenting a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you, within the statutory time limits.
9. Your Rights
You have the right to: access your data; request rectification of inaccurate data; request erasure; request restriction of processing; object to processing; request data portability; withdraw consent at any time (without affecting the lawfulness of processing carried out beforehand); and not to be subject to solely automated decisions producing significant effects.
Under the LGPD, data subjects in Brazil additionally have the right to obtain confirmation that processing is taking place, and to request the anonymisation or blocking of unnecessary data, and information about data sharing.
To exercise your rights, contact us at privacy@brucke.co.uk. We will respond within one month (UK GDPR) or 15 days (LGPD), extendable where legally permitted.
Right to complain. If you are dissatisfied with how we have handled your data, you may lodge a complaint with the competent authority:
- United Kingdom: the Information Commissioner's Office (ICO) — https://ico.org.uk
- European Union: the supervisory authority of your country of residence
- Brazil: the Autoridade Nacional de Proteção de Dados (ANPD) — https://www.gov.br/anpd
10. Cookies
We use cookies that are strictly necessary for the website to function and, subject to your consent, analytics and marketing cookies, including those associated with our advertising campaigns.
You may manage your preferences at any time through our cookie banner or your browser settings. A detailed list of the cookies we use is available in our cookie banner.
11. Children
Our services are not directed at minors. Where we process the data of a minor (for example, a child included in a family reunification or school enrolment application), we do so solely on the instruction and with the consent of the holder of parental responsibility, and only to the extent necessary for the service.
12. Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. The analysis and preparation of every dossier involves human assessment.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated by email or by prominent notice on our website. The date of the most recent update appears at the top of this document.