SJB Global Privacy Policy
How we collect, use, share and protect personal data when you visit our website, contact us or receive services through an SJB Global financial adviser.
Last updated: 18 August 2026
This policy explains how SJB Global handles personal data, the lawful reasons for using it, the organisations with which it may be shared and the rights available to individuals.
ABOUT THIS PRIVACY POLICY
This Privacy Policy explains how SJB Global collects, uses, shares and protects personal data when you visit our website, request information, download a guide, attend an event, communicate with us or receive services through an SJB Global financial adviser.
It also explains the rights available to you and how you can contact us about the use of your personal data.
This Privacy Policy should be read alongside our Cookie Policy, which explains how cookies and similar technologies are used on our website:
“Personal data” means information relating to an identified or identifiable individual. It does not include information that has been anonymised so that an individual can no longer reasonably be identified.
WHO WE ARE
SJB Global/BFMI is a trading name of Blacktower Financial Management (International) Limited (“BFMI”), a company incorporated in Gibraltar under company number 87309.
The financial advisers trading under SJB are members of Nexus Global. Nexus Global is a division of BFMI. All approved members of Nexus Global are Appointed Representatives of BFMI. BFMI is licensed and regulated by the Gibraltar Financial Services Commission under licence number 3647.
For the personal data covered by this Privacy Policy, BFMI will generally act as the data controller unless you are told that another organisation is responsible for a particular activity, product or service. A product provider, platform, insurer, investment manager or other professional firm may act as a separate data controller for information it receives and will provide its own privacy information where appropriate.
BFMI’s registered address is:
Blacktower Financial Management (International) Limited
Waterport Place
Floor 2, Unit 2.3
Europort Road
Gibraltar GX11 1AA
Questions about this Privacy Policy or the use of your personal data can be sent to:
Privacy Manager
SJB Global
Andasol Business Center
Avenida Andasol
Elviria
Marbella 29604
Spain
Email: [email protected]
Enquiries: +34 951 127 210
Administration: +34 951 120 111
WHEN WE COLLECT PERSONAL DATA
We may collect personal data when you:
- visit or interact with our website;
- submit a contact, callback, guide-download, webinar or event form;
- communicate with us by email, telephone, video call, post or social media;
- meet or speak with an SJB Global financial adviser;
- complete a fact-find, risk questionnaire, client agreement or other onboarding document;
- request information about a product or service;
- become, or apply to become, a client;
- subscribe to a newsletter or other marketing communication;
- attend an event or webinar;
- provide identity, residence, financial or source-of-funds documentation; or
- otherwise provide information to us in connection with our business.
We may also receive personal data from advisers, introducers, professional representatives, product providers, investment platforms, insurers, identity-verification providers, fraud-prevention services, sanctions and politically exposed person screening services, public registers, social-media platforms and other organisations where the disclosure is lawful.
If you provide information about another person, you should ensure that you are authorised to do so and that the person has been given appropriate information about how their data will be used.
PERSONAL DATA WE MAY COLLECT
Depending on your relationship with us, we may collect:
- Identity data, including your name, title, date of birth, nationality, marital status and identification documents.
- Contact data, including your residential or correspondence address, email address and telephone number.
- Residence and tax data, including your country of residence, tax residence, tax identification number and citizenship information.
- Financial data, including information about your income, expenditure, assets, liabilities, investments, pensions, bank accounts, financial objectives and source of funds or wealth.
- Transaction and service data, including information about products, services, payments, recommendations and communications relating to your relationship with us.
- Professional data, including your occupation, employer, business interests, employment history and professional experience.
- Family and beneficiary data, including information about dependants, beneficiaries, attorneys, trustees and other people connected with your financial arrangements.
- Identification and compliance data, including identity-verification results, sanctions screening, politically exposed person status, anti-money laundering risk information and records needed to meet legal or regulatory obligations.
- Technical and usage data, including your IP address, browser and device information, approximate location, referral source and information about how you use our website.
- Profile and preference data, including your interests, communication preferences, feedback and survey responses.
- Marketing data, including your marketing choices, consent records and responses to communications.
- Communication data, including emails, correspondence, meeting notes and, where applicable, recordings of telephone or video communications.
Some financial-planning, insurance, vulnerability-assessment or compliance activities may require information that is treated as special-category data, such as health information. Compliance checks may also identify information relating to political exposure or criminal allegations and convictions. We will process this information only where it is necessary and where an appropriate legal condition applies.
IF YOU DO NOT PROVIDE INFORMATION
You are not required to provide personal data simply to browse our website, apart from limited technical information needed to operate and secure it.
Where information is required by law, by a regulator or to enter into or perform a contract, we may be unable to provide a requested service if you do not provide it. We will explain when information is mandatory and the likely consequences of not providing it.
HOW AND WHY WE USE PERSONAL DATA
We process personal data only where we have a lawful basis. The bases most likely to apply are:
- Contract: processing is necessary to take steps at your request before entering into a contract or to perform a contract with you.
- Legal obligation: processing is necessary to comply with laws, regulatory rules, court orders or requests from competent authorities.
- Legitimate interests: processing is necessary for our legitimate business interests or those of another organisation, provided those interests are not overridden by your rights.
- Consent: you have given clear consent for a particular use, and you may withdraw that consent at any time.
- Legal claims and other special conditions: where sensitive information is involved, an additional legal condition may apply, including the establishment or defence of legal claims, substantial public interest conditions or explicit consent where appropriate.
We may use personal data for the following purposes:
Responding to enquiries
We use identity, contact and enquiry information to respond to requests, provide requested information and arrange introductory discussions. This is generally necessary to take steps at your request or for our legitimate interest in responding to enquiries.
Providing and administering services
We use client, financial, transaction and communication information to understand your circumstances, provide agreed services, administer your relationship with us and communicate about your arrangements. This is generally necessary to enter into or perform a contract and to meet regulatory obligations.
Financial planning and recommendations
Where you become a client, we may use information about your finances, objectives, experience, risk profile, residence and family circumstances to assess suitability and prepare financial-planning analysis or recommendations. This processing may be required to perform our contract with you and comply with regulatory obligations.
Identity verification, fraud prevention and regulatory compliance
We use identity, residence, financial and compliance data for client due diligence, anti-money laundering checks, sanctions screening, fraud prevention, record keeping and regulatory reporting. This processing is generally necessary to comply with legal and regulatory obligations and for our legitimate interest in protecting our business and clients.
Operating and securing the website
We use technical and usage data to operate, maintain, troubleshoot and secure our website, prevent misuse and understand its performance. Strictly necessary processing is based on our legitimate interests and legal obligations. Non-essential analytics and advertising technologies are used only in accordance with applicable consent requirements.
More information about cookies, analytics, advertising technologies and how to manage your choices is available in our Cookie Policy:
Service improvement and business administration
We may analyse feedback, service information and appropriately aggregated data to improve our website, communications, systems and services. We may also use data for auditing, training, quality assurance, complaints handling, business continuity and internal reporting. This is generally based on our legitimate interests, legal obligations or the performance of our contract with you.
Communications monitoring and recording
Telephone, video or electronic communications may be monitored or recorded where permitted by law for training, quality assurance, evidence of instructions, fraud prevention, security and regulatory compliance. Where recording takes place, we will provide an appropriate notice.
Marketing
We may send information about guides, events, insights or services where you have consented or where another lawful electronic-marketing basis applies. Marketing communications will include a way to unsubscribe.
You can change your marketing preferences at any time by using the unsubscribe option in a message or contacting us. Withdrawing from marketing will not prevent us from sending necessary service, legal, security or regulatory communications.
COOKIES AND SIMILAR TECHNOLOGIES
Our website uses cookies and similar technologies to operate securely, remember preferences, measure use and, where permitted, support marketing activities.
Non-essential cookies and similar technologies are not intended to be activated until the required consent has been obtained. You can accept, reject or manage categories through the cookie controls available on the website.
The current categories, providers, purposes and available controls are explained in our Cookie Policy:
AUTOMATED PROCESSING AND PROFILING
We may use screening and risk-assessment tools to support identity verification, fraud prevention, sanctions checks, politically exposed person checks and anti-money laundering compliance. These tools may generate alerts or risk indicators for review by appropriately authorised personnel.
We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects unless the processing is permitted by law and appropriate safeguards are in place. If this changes, we will provide the information required by applicable data-protection law, including information about the logic involved, likely consequences and your relevant rights.
Product providers and other independent organisations may operate their own automated processes and should provide separate privacy information about them.
SHARING PERSONAL DATA
Where necessary and lawful, we may share personal data with:
- Nexus Global, BFMI personnel and approved advisers involved in providing or administering services;
- pension trustees, pension administrators, investment platforms, fund managers, discretionary managers, insurers, banks and other product providers;
- professional advisers, including lawyers, accountants, tax professionals, auditors and compliance consultants;
- identity-verification, anti-money laundering, sanctions-screening and fraud-prevention providers;
- technology, hosting, communications, document-management, customer-relationship-management and cybersecurity providers;
- website, analytics, marketing and event-service providers, subject to applicable consent requirements;
- regulators, tax authorities, law-enforcement bodies, courts and other competent authorities where required or permitted by law;
- prospective purchasers, investors or advisers in connection with a business sale, restructuring or reorganisation; and
- other parties where you request or authorise the disclosure.
Some recipients process personal data on our instructions as processors. Others, including many regulated product providers and professional advisers, act as independent controllers and are responsible for their own use of the data.
We require processors to protect personal data, maintain confidentiality and use it only for agreed purposes.
We do not sell personal data.
INTERNATIONAL DATA TRANSFERS
SJB Global operates internationally, and some recipients or service providers may be located outside the country in which your data was collected. This may involve transfers between Gibraltar, the European Economic Area, the United Kingdom, the United States and other countries.
Where an international transfer is restricted by applicable law, we will use an approved transfer mechanism. Depending on the circumstances, this may include:
- a transfer to a country covered by an applicable adequacy decision;
- the EU–US Data Privacy Framework where the relevant US recipient is an active participant and the framework applies;
- approved Standard Contractual Clauses or another recognised contractual safeguard;
- binding corporate rules or another approved mechanism; or
- a specific legal derogation where its conditions are satisfied.
Where required, we will assess whether supplementary safeguards are needed. You may contact us for further information about the mechanism relevant to your data and, where available, a copy of the applicable safeguards.
RETENTION
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including to satisfy legal, regulatory, accounting, tax, complaints-handling and reporting requirements.
Retention periods vary according to the information and relationship involved. In determining a period, we consider:
- the nature and sensitivity of the information;
- the purpose for which it is used;
- whether the purpose can be achieved in another way;
- applicable limitation periods;
- anti-money laundering, financial-services and other record-keeping requirements;
- the need to establish, exercise or defend legal claims; and
- regulatory guidance or instructions.
Client, advice and anti-money laundering records will normally be retained for the period required under applicable financial-services and anti-money laundering rules after the relationship or relevant transaction ends. Enquiry and marketing information is retained for a shorter period appropriate to the purpose, unless you become a client or continued retention is required by law. Where you opt out of marketing, we may retain limited suppression information to ensure your preference is respected.
Data may be anonymised for statistical or research purposes, in which case it may no longer constitute personal data.
SECURITY
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures may include access controls, authentication, encryption in transit, network protection, malware protection, backups, secure disposal, staff training, confidentiality obligations and incident-response procedures. Access is restricted to people who need the information for an authorised purpose.
No internet transmission or storage system can be guaranteed to be completely secure. If you believe information sent to or from us may have been compromised, contact us promptly using the details in this policy.
Where a personal-data breach occurs, we will assess it and notify the relevant authority and affected individuals where required by law.
YOUR RIGHTS
Depending on the law applying to the processing, you may have the right to:
- receive information about how your personal data is used;
- request access to the personal data held about you;
- request correction of inaccurate or incomplete information;
- request erasure in circumstances where continued retention is not required;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to processing for direct marketing;
- receive certain data in a structured, commonly used and machine-readable format and request its transfer where technically feasible;
- withdraw consent at any time where processing is based on consent; and
- request safeguards relating to qualifying solely automated decisions.
These rights are not absolute. Legal, regulatory and record-keeping obligations may require us to continue holding or processing certain information.
To exercise a right, contact us using the details in section 2. We may request information reasonably necessary to confirm your identity and authority. We will ordinarily respond within one month, although the period may be extended where permitted for complex or multiple requests. We will explain any permitted extension or refusal.
There is normally no fee. A reasonable fee may be charged, or a request refused, where permitted by law because the request is manifestly unfounded or excessive.
COMPLAINTS
Please contact us first if you have concerns about how your personal data has been handled. We will investigate the matter and try to resolve it.
You also have the right to lodge a complaint with an applicable data-protection supervisory authority.
For Gibraltar, the supervisory authority is the Gibraltar Regulatory Authority acting as Information Commissioner:
Gibraltar Regulatory Authority
Information Rights Division
2nd Floor, Eurotowers 4
1 Europort Road
Gibraltar
Telephone: +350 20074636
Website: GRA complaints procedure
Where EU data-protection law applies, you may also be entitled to complain to the supervisory authority in the country where you live or work, or where you believe an infringement occurred.
CHILDREN
Our website and services are intended for adults and are not directed at children. We do not knowingly use the website to solicit personal data from children. If you believe a child has provided personal data to us without appropriate authority, please contact us so that we can investigate and take appropriate action.
THIRD-PARTY WEBSITES AND SERVICES
Our website may contain links to websites, plug-ins, applications or services operated by other organisations. Those organisations are responsible for their own privacy practices. We encourage you to read their privacy information before providing personal data or enabling a connection.
CHANGES TO THIS POLICY
We may update this Privacy Policy to reflect changes in our activities, technology, legal requirements or regulatory guidance. The current version will be published on this page with its last-updated date.
Where a change materially affects how existing personal data is used, we will provide additional notice where required.