Skip to content
Legal · Data protection

Privacy notice

How MPS Compare handles personal data. Written in plain English, kept short deliberately, designed to be readable rather than legally exhaustive.

Last updated 12 August 2026

Who we are

MPS Compare is a research, comparison and document-preparation platform for FCA-authorised firms and their advisers, focused on Model Portfolio Service (MPS) and DFM portfolio due diligence. It is not available to retail investors. MPS Compare is a trading name of LFM Intelligence Limited, and the platform is operated from the United Kingdom. For data-protection enquiries, email privacy@mpscompare.co.uk .

What we collect

The only personal data MPS Compare holds is the information adviser users provide about themselves when they create an account or use the platform:

  • Account profile: email address, display name (optional), job title (optional), phone number (optional).
  • Firm membership: which firm an account belongs to, role within that firm (admin, IFA, paraplanner), invitation history.
  • Authentication metadata: password hash (we never see or store the plaintext), session timestamps, multi-factor authentication state, and a security event log (sign-ins, failed sign-in attempts, lockouts and two-factor changes, each with timestamp and IP address). Security events for a firm's seats are visible to that firm's admins to support the firm's own access monitoring.
  • Activity audit trail: for every PDF a user generates, we record who, when, the calculation engine version, the parameters supplied, and a hash of the output. This is how our customer firms evidence their FCA record-keeping obligations (SYSC 9.1).

We do not collect client identifiers of any kind. The platform does not ask for, accept, or store the names, dates of birth, addresses, national-insurance numbers or any other personal data of an adviser's end clients. PDFs are referenced by acting user, firm and timestamp only. This is enforced at the schema level: no column on any table accepts a client-attributable value.

Why we hold it

  • To run the service: account profile and firm membership are required to authenticate users and scope what they can see. Legal basis: performance of contract.
  • To maintain the audit trail: export records are retained so an adviser can reproduce a recommendation they made to a client and evidence its basis to their regulator. Legal basis: legitimate interests (maintaining a tamper-evident record of documents generated through the service, and enabling our customer firms to meet their own FCA record-keeping obligations under SYSC 9 and COBS 9 / 9A). Where your firm is the controller of those records, we hold them as its processor on documented instructions under the data processing agreement .
  • To keep the service secure: authentication metadata lets us detect compromised accounts and respond to incidents. Legal basis: legitimate interests (operating a secure service).

Where it lives and international transfers

All personal data and all generated PDFs are stored in Supabase (eu-west-2 / London region). Email is delivered through the Supabase transactional-email path; outgoing senders are reputable UK / EU providers.

One service provider processes limited data outside the United Kingdom. Anthropic processes AI-feature requests in the United States; those requests are designed to carry no personal data (see the next section), and as a safeguard our agreement with Anthropic incorporates the ICO's International Data Transfer Addendum (version B.1.0) to the EU Standard Contractual Clauses. No other processing leaves the UK / EEA. The full list is on the sub-processor register .

AI features

Subscriptions include optional AI drafting and insight features powered by Anthropic's Claude API. When you use one, the platform sends Anthropic anonymised strategy catalogue data, figures the platform has already computed, and your drafting instructions. No platform input field accepts client-identifying information, and users are instructed not to enter any. Anthropic acts as our processor: under our commercial terms it deletes API inputs and outputs within 30 days and does not use them to train its models. AI output is session-only and is not stored by the platform.

Legal basis: legitimate interests (providing optional drafting aids that users invoke on request). No solely automated decision with legal or similarly significant effect is made about any person; every AI output is a draft reviewed by a professional user before any use.

How long we keep it

  • Audit trail and stored PDFs: retained for a minimum of seven years from the date the export was generated, in line with the financial-services record-keeping obligations that apply to our customer firms (FCA SYSC 9, COBS 9 / 9A) and the limitation period for legal claims. Database grants do not permit in-place deletion of audit rows; removal would require a privileged migration with its own audit footprint.
  • Account profile: retained while the account is active. On request, we will redact identifying fields from the profile while preserving the audit trail of actions taken under that account (this is what the FCA expects of our customer firms' records).
  • Authentication metadata: session timestamps are retained for 90 days for incident investigation, then purged.

Sub-processors

MPS Compare relies on a small number of sub-processors:

  • Supabase: database, authentication, and object storage. Region: eu-west-2 (London).
  • Vercel: application hosting and edge runtime. Region pinned to Europe.
  • Anthropic: AI drafting and insight features (requests designed to carry no personal data; processed in the United States under the safeguards described above).

The authoritative register, including each provider's DPA and our change-notification process, is published at /legal/sub-processors .

Your rights

Under UK GDPR you can ask us to access, correct, transfer or restrict the personal data we hold about you, and to delete it where there is no overriding reason to keep it (the audit-trail retention described above is one such reason). Send any request to privacy@mpscompare.co.uk and we will respond within one month.

Complaints

If you are unhappy with how we have handled your personal data, you can complain to us directly by emailing privacy@mpscompare.co.uk with the subject line “Data protection complaint”. We will acknowledge your complaint within 30 days and inform you of the outcome without undue delay. This route is provided under section 164A of the Data Protection Act 2018 (inserted by the Data (Use and Access) Act 2025).

You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk at any time.

Cookies and similar technologies

We set only strictly necessary cookies and equivalent browser storage, used for authentication, session management and CSRF protection. These are exempt from the consent requirement under the Privacy and Electronic Communications Regulations 2003, as amended by the Data (Use and Access) Act 2025. We do not run third-party analytics, advertising pixels or marketing trackers on the application surface.

Changes to this notice

Material changes will be communicated to logged-in users via an in-app banner, and the “Last updated” date at the top of this page will be revised.