This notice applies to your use of this website and its content.
Timelineapp Tech Limited and Timeline Portfolios Limited are registered in England and Wales (Company No. 11405676 and 11557205 respectively). Our registered offices are 70 Gracechurch Street, London, EC3V 0HR. Timeline Portfolios Limited is authorised and regulated by the Financial Conduct Authority (FCA No. 840807).
The information contained in this website is intended for the use of UK residents and is not intended for the use of persons outside of the UK. By continuing to use this website you are confirming that you have the necessary right to do so.
No information in this website should be regarded as a solicitation to undertake investment business and should not be relied upon to buy or sell securities. Whilst we endeavour to ensure that any information is correct as at the time of posting, Timelineapp Tech Limited and Timeline Portfolios Limited does not warrant the accuracy and completeness of the material. Furthermore, we are not responsible for the content on external websites that may be accessed to or from our pages.
Investing in stock market based investments may not be right for all investors. Our services are accessible to UK authorised financial advisory firms. The value of an investment and any income from it can fall as well as rise and you may not get back the amount you originally invested. References to taxation are based upon our understanding of the tax rules that may change in the future and will ultimately depend on an individual’s circumstances.
To the fullest extent permitted by law, Timelineapp Tech Limited and Timeline Portfolios Limited shall not be liable for (including direct or indirect) any kind of loss or damage that may result to you or a third party from the use of this website whether arising in contract, tort (including without limitation negligence) or otherwise.
Nothing in this notice shall exclude the liability of Timelineapp Tech Limited and Timeline Portfolios Limited for death or personal injury, for liability that cannot be excluded or limited at law or for liability that cannot be excluded under the FCA Rules.
The content and the website (including text, graphics, logos, icons, images, software and computer source code) are the copyright of Timelineapp Tech Limited and Timeline Portfolios Limited.
Important information regarding your privacy.
This notice explains how we use and protect your personal data, and the rights you have. Personal data is any information that identifies you directly or indirectly. We process it in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR) and ICO guidance. Together we call these "Data Protection Laws".
"Timeline", "we", "us" and "our" means Timeline Holdings Limited (company no. 13266210; ICO no. ZB274330) and its subsidiaries, including:
These services are described in "What this notice covers" below. All three companies are registered with the Information Commissioner's Office. You can verify this at ico.org.uk. The company responsible for your personal data (the "controller") depends on the service you use (see "Our role and your relationship with us").
If you have any questions about this notice or our processing, or wish to exercise your rights, please contact:
Data Protection Officer
Timeline, 70 Gracechurch Street, London, EC3V 0HR, United Kingdom
Phone: 020 4572 9919
Email: support@timeline.co
Need this notice in another format? If you would like this notice in large print or another format, contact us and we will be happy to help.
This single group notice covers personal data we process across our services. These are:
This notice applies to everyone we may process personal data about. Throughout this notice we refer to the following groups:
Our data protection role varies based on our services:
| Relationship | Our role | What this means for you |
|---|---|---|
| You are an adviser or work at an advice firm using, trialling or enquiring about our services | Controller (for our relationship with you, onboarding, billing, support, training and marketing) | Contact us directly about your data. |
| You visit our websites, attend our events, receive our marketing or contact us directly | Controller | We decide how and why your data is used. Contact us directly. |
| Your advice firm uses Timeline Planning (including the fact find, cashflow modelling and Pennee) and enters your information as their client | Processor for your advice firm (the controller) | Your advice firm decides how your data is used. Direct any requests to your adviser first. We will support them. |
| You invest in our Model Portfolio Service or multi-asset funds through your adviser or a third-party platform, or directly with us | Controller for the data we receive to run the portfolios and provide our services, and to meet our legal obligations (e.g. AML checks and FCA record-keeping) | Your adviser or platform remains your main contact. If you invest indirectly, we may only hold limited information about you. If you have an agreement with us, contact us directly. |
| You hold investments directly on the Timeline Platform | Controller for our digital platform service and legal obligations (e.g. AML checks and record keeping). For order handling and custody, Seccl acts as a separate controller and decides how it uses your data for those activities. | Seccl handles custody, execution and related reporting. Its privacy notice applies alongside ours. Contact your adviser first, or us directly. |
| You are a connected person (e.g. a dependant, beneficiary, trustee or attorney) named in a plan, application or account | Same role as for the client concerned (processor or controller as above) | Where we are the controller, we will tell you we hold your data within one month of receiving it, or when we first contact you, unless an exemption applies. Where your advice firm is the controller, it is responsible for telling you. Contact us or the advice firm. |
A controller decides what happens to your data. A processor follows the controller's instructions. Where we act as processor, our contract with your advice firm sets out these instructions. Even where we act as processor, we remain the controller of account, login, security and usage data. We use that data to run and secure our technology, to provide support, and to improve and develop our products and services. We decide how it is used for those purposes. Their privacy notice applies alongside ours.
What we collect depends on who you are and which services you use. The groups below can overlap, for example an adviser is also a technology user.
Where advice firms use our planning tools, sensitive data such as health and vulnerability details may be recorded. Your advice firm decides what is collected as controller, and we process it on their instructions as a processor.
As a controller in our own right, we process special category data only in limited situations:
Separately, financial crime screening may reveal information about criminal convictions or alleged offences. This includes sanctions, PEP and adverse media checks. We undertake this screening to meet our anti-money laundering ("AML") obligations. We rely on the conditions in Schedule 1 to the Data Protection Act 2018 for preventing or detecting unlawful acts, for regulatory requirements relating to unlawful acts and dishonesty, and for preventing fraud. We keep an appropriate policy document explaining how we comply, which you can ask us for.
Our services are designed for adults and advice professionals. We may process limited information about children. This applies where they appear in a financial plan as dependants or beneficiaries, or where an account is held for them, such as a junior account. We do not market to children and we do not offer our services directly to them. We only use their data to run the plan or account concerned, and we apply the same protections set out in this notice.
Some information is needed to comply with the law, such as identity information for anti-money laundering checks, or to enter into and carry out our contract with you or your firm. If it isn't provided, we may not be able to open your account, process transactions, or provide the service. Where information is optional, such as health or vulnerability details, we will make that clear when we ask.
We only process personal data where Data Protection Laws allow. This table sets out our lawful basis for processing, where we are the controller. For some services, including Timeline Planning and Timeline Meeting Notes, your advice firm is the controller and we act as their processor, on their instructions (see "Our role and your relationship with us"). "What personal data we collect" sets out what we hold across all our services, including as processor.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing our investment and platform services including managing accounts, orders, custody and transfers; operating the client portal and secure messaging; providing support, handling complaints and protecting our legal rights | Identity, Financial, Account and transaction | Contract (direct agreements); legitimate interests (where you are not the contracting party, e.g. staff at a firm) |
| Digital onboarding, identity verification, KYC/AML, sanctions and fraud checks; tax reporting; regulatory record-keeping and reporting to the FCA, HMRC and other authorities | Identity, AML and screening | Legal obligation; plus, for any criminal offence data revealed by screening, the Schedule 1 conditions for preventing or detecting unlawful acts, for regulatory requirements relating to unlawful acts and dishonesty, and for preventing fraud |
| Providing and operating Timeline Planning including Pennee and the Adviser and Client Portals | Account and login, Security, Usage | Contract (direct agreements); legitimate interests (where you are not the contracting party, e.g. staff at a firm); consent (opting in to Pennee, revocable at any time) |
| Providing and operating Timeline Meeting Notes | Account and login, Security, Usage, Calendar, Meeting recordings | Contract (direct agreements); legitimate interests (account access, and our own handling of recordings); consent (calendar connection, revocable at any time) |
| Supporting you where you share, or we identify, health or vulnerability information; accessibility and dietary needs for our events | Special category | Legal obligation and legitimate interests (Article 6); explicit consent for accessibility and dietary needs, and the substantial public interest condition in Schedule 1 for the exercise of our regulated functions, or where someone is at risk of harm, the condition for safeguarding individuals at risk (Article 9) |
| Recording and monitoring communications for regulatory compliance, quality and service, training our staff, and gathering feedback to improve our products and services | Communication records, Service data | Legal obligation (where required by FCA rules); legitimate interests |
| Improving and developing our products, technology and services. This includes analytics, testing, research and understanding the firms we serve (which may involve profiling), and keeping our systems, premises and data secure | Usage, Security, Service data, Communications | Legitimate interests with a right to object for the profiling element |
| Marketing our products, services and events; measuring engagement and firm-level segmentation (which may involve profiling) | Marketing data, Event data, Usage, Communications | Consent (where you sign up); legitimate interests where you become a customer (we tell you at onboarding and you can opt out at any time); legitimate interests, with a right to object, for the profiling element |
| Recruitment including assessing applications and enquiries about working with us | Identity, Recruitment data | Legitimate interests; legal obligation; steps before entering a contract |
| Corporate transactions e.g. a merger, acquisition, restructuring or sale involving Timeline | Identity, Financial | Legitimate interests |
| Managing relationships with suppliers, partners and professional advisers | Identity, Financial | Contract; legitimate interests |
Where we rely on legitimate interests, we balance our interests against your rights and freedoms. We do not use this basis where your interests override ours. You can ask us for more information about our balancing assessments.
We record and monitor communications with you including telephone and video calls, secure messages within our technology, support chats and emails. We do this:
We may use technology, including AI tools, to transcribe, summarise or analyse recorded communications for these purposes (see "Artificial intelligence"). Copies of recorded communications are available on request.
Webinars, podcasts and events may be recorded, including questions and contributions from participants. Where a recording is for publication, we will make this clear at the time.
We market mainly to financial advice professionals in a business-to-business context. We may contact you about our products and services, research, newsletters, regulatory updates, podcasts, webinars and events (including Adviser 3.0). We do this where you have opted in. We also do this where we obtained your details while selling, or negotiating to sell, similar products or services to you, and you did not opt out at the time. This is known as soft opt in. When you opt in, you can choose which types of communication you receive, and you can change these preferences at any time.
We collect marketing data directly from you, and from your interactions with our communications and websites. We also collect it from third-party B2B data providers such as Financial Clarity. We measure engagement (such as email opens and event attendance) to keep communications relevant, and use aggregated insights to understand the firms we serve (see "Automated decision-making and profiling").
You can opt out at any time using the unsubscribe link in any marketing email or by contacting us at support@timeline.co If you do, we keep your details on a suppression list so we can honour your preference. We do not sell your personal data.
We use artificial intelligence ("AI") to enhance our services and run our business efficiently. Where AI processes personal data, it does so for the purposes and on the lawful bases set out in this notice.
Our services may use AI to suggest, summarise or automate tasks, including recording, transcribing and summarising meetings. Timeline Meeting Notes, our standalone meeting app, records meetings and processes audio recordings and transcripts using third-party AI services. This produces a transcript, summary, action items and, where relevant, financial facts and vulnerability flags. Recordings and transcripts are then available within Timeline Planning, where Pennee, our AI assistant, may also process them. Pennee's AI features are opt-in only and act on your firm's instructions. If Pennee is not switched on for an account, Pennee has no access to recordings and transcripts. These features, including Pennee, process personal data within our ecosystem and never take action without user approval.
Timeline Meeting Notes can also connect to your Google or Outlook calendar to retrieve event and participant details. Where we receive data through Google Workspace APIs, we follow the Google API Services User Data Policy, including its Limited Use requirements. We only use this data to run the calendar feature.
Where advice firms use our AI features, including Pennee, the firm remains the controller of its clients' personal data. It decides what data is used, must tell participants about this and get consent where needed.
We also use AI tools to work efficiently, including to transcribe meetings we take part in, and in our marketing, to understand the firms we serve (see "Automated decision-making and profiling"). We tell participants when a transcription tool is used.
When we test new AI features, we use synthetic data. Where AI is used for product research and analytics we may use personal data, including from calls (see ‘Recording and monitoring communications’). Personal data is not used to train AI models, including by any third-party AI providers we use. We carry out due diligence and data protection impact assessments before using AI that processes personal data. We also put contractual safeguards in place with AI providers. We do not use AI to make solely automated decisions with legal or similarly significant effects on you. We will update this notice before materially changing how AI processes personal data.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Some of our processes are automated, such as elements of identity verification and AML screening. However, before any decision that has a legal or similarly significant effect on you, a trained member of our staff with authority to change the outcome reviews the case and makes the decision. You can ask us to explain a decision and to review it again.
To understand the different types of firm we serve, we also build combined, firm-level profiles of our adviser customers. These draw on themes from our own contact with you, such as sales, support and relationship calls, and on public information about firms. We do not use data processed on behalf of advice firms through our products (such as Pennee meeting recordings) for this purpose. This profiling is designed to describe firms, not individuals. However, drawing themes from our calls involves processing recordings that contain personal data (see "Recording and monitoring communications"). Where a firm is a sole trader or small practice, its profile can itself be personal data. We rely on legitimate interests for this, and you can object at any time.
We share personal data only where needed for the purposes set out in this notice. Where a third party processes data for us, we require it by contract to meet our data protection and security standards. Our Trust Centre at trust.timeline.co lists the providers we use and the countries they operate from. Depending on the services used, we may share data with:
We store personal data mainly in the UK and the European Economic Area (EEA), which UK adequacy regulations cover. The main countries outside the UK and EEA that our providers process or access data from are the United States. Our Trust Centre at trust.timeline.co sets out the current list. Some service providers and contractors working for us from outside the UK and EEA process or access personal data. Where they do, we put equivalent protection in place. This may include:
You can contact us for more information about, or a copy of, the safeguards for a specific transfer.
Our websites use cookies and similar technologies to make them work, to understand how they are used and to support our marketing. You can manage non-essential cookies through the cookie banner on our websites and via your browser settings. Some features may not function fully if you disable them.
For details of the specific cookies we use and how long they last, see our Cookie Policy at timeline.co/legal
We take a layered approach to security across our organisation, people, processes and technology. This includes encryption in transit and at rest, access controls and authentication, monitoring, testing and staff training. Third parties processing data for us must meet contractual security and confidentiality duties. We review their controls.
During our relationship with you, we keep the personal data needed to provide our services. We take reasonable steps to keep it accurate and up to date. Some records must be kept for minimum periods required by law or regulation. These generally include:
Beyond our relationship with you and these legal minimums, we may keep data where we have a legitimate interest in doing so. We balance those interests against your rights and freedoms first. Generally, we keep data relating to our services for six years after our relationship ends. This lets us respond to queries or complaints, defend legal claims and evidence our compliance if asked. If we hold data for more than one purpose, we keep it until the longest retention period ends. We only use it for the purposes that still apply. Shorter periods apply to other categories, such as enquiries that do not proceed, marketing data and unsuccessful job applications.
Website analytics data is kept as set out in our Cookie Policy. Once the relevant period ends, we securely delete or anonymise the data. You can also ask us to delete your data at any time, subject to the retention obligations above.
For further information about our retention policy, please contact us.
Under Data Protection Laws you have the following rights:
These rights are not absolute. For example, we cannot erase records we must keep to comply with our legal and regulatory obligations. We will explain any limitation when we respond.
You can exercise your rights free of charge by contacting us (see "Who we are"). We may need to verify your identity first. We will only charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive. We have one month to respond, and may extend this by up to two further months for complex or multiple requests. We will tell you within the first month if so, and explain why. If your data was entered into our technology by your advice firm, we may need to refer your request to them as controller and will tell you if so.
You also have the right to complain to the Information Commissioner's Office at any time, although we would welcome the chance to address your concerns first:
We review this notice regularly and update it when the law, our services or our technology change. You can find the latest version on our website. If a change affects you significantly, we will take reasonable steps to let you know.
Last reviewed and updated: 7 September 2026