UK GDPR · Scotland
Privacy Policy
Last updated 2026.
1. Data controller
Lothian Vault Management Ltd., 10 George Street, Edinburgh, EH2 2PF, Scotland, United Kingdom, is the data controller in respect of personal data processed through this portal and through our custody operations. Privacy enquiries and data subject requests should be addressed to support@lothianvaultmanagement.com.
All data processing strictly adheres to UK GDPR guidelines, being the UK General Data Protection Regulation as retained in domestic law, together with the Data Protection Act 2018.
2. Personal data we process
Account and identity data: name, email address, telephone number where provided, authentication records, and Multi-Factor Authentication status.
Custody records: gold weight in grams and troy ounces, unique security label numbers, deposit date and time stamps, storage fee balances, and receipt generation history.
Correspondence: the content of inquiries submitted through our contact form, which is routed to our Microsoft 365 business mailbox, together with the automated acknowledgement issued to you.
Technical data: security and access logs, IP address, and device or browser information necessary to protect the portal.
3. Lawful bases for processing
Performance of a contract (UK GDPR Article 6(1)(b)) for the operation of your custody account, vault register, valuations, and receipts.
Compliance with a legal obligation (Article 6(1)(c)) for anti-money laundering, customer due diligence, record retention, and reporting obligations.
Legitimate interests (Article 6(1)(f)) for the security of the vault, fraud prevention, and the integrity of this portal, balanced against your rights and freedoms.
Consent (Article 6(1)(a)) where you voluntarily submit an inquiry or optional information; consent may be withdrawn at any time without affecting other lawful bases.
4. Recipients and processors
We share personal data only with processors and professional parties who need it to deliver the service: our cloud database and authentication provider, our Microsoft 365 business email and calendaring provider, our insurers and independent auditors, and our legal advisers.
Market price data is retrieved from a third-party gold spot price feed. No personal data is transmitted to that feed.
We do not sell personal data and we do not use it for third-party advertising. Where a processor is located outside the United Kingdom, transfers are made under UK adequacy regulations or the International Data Transfer Agreement or Addendum.
5. Retention
Custody and transaction records, including security label numbers and deposit timestamps, are retained for the life of the account and for a minimum of five years after the relationship ends, in accordance with anti-money laundering record-keeping requirements.
Contact form submissions are retained for twenty-four months. Security and access logs are retained for twelve months. Data is then deleted or irreversibly anonymised.
6. Security measures
Data is encrypted in transit using TLS and at rest by our infrastructure provider. Access to client records is restricted by role-based access control and row-level database policies, so that a client can see only their own records and administrative access is limited to authorised vault staff.
You are required to enable Multi-Factor Authentication on your account. We will never ask you for your password, vault passcode, or authentication code, and you must never share a vault passcode with any external party.
7. Your rights under UK GDPR
You have the right of access to your personal data, and the rights to rectification, erasure, restriction of processing, data portability, and to object to processing carried out on the basis of legitimate interests. Where processing relies on consent, you may withdraw it at any time.
To exercise any right, contact support@lothianvaultmanagement.com. We respond within one month, and will explain any statutory ground on which a request must be refused, in particular where anti-money laundering law requires records to be retained.
You may lodge a complaint with the Information Commissioner's Office, the United Kingdom's supervisory authority, at ico.org.uk. We would ask that you raise the matter with us first.
8. Cookies and local storage
We use strictly necessary storage only, to maintain your authenticated session and portal preferences. We do not deploy advertising or cross-site tracking cookies.
9. Governing law
This policy and any dispute arising from it are governed by the laws of Scotland, and the Scottish courts have exclusive jurisdiction, without prejudice to your statutory rights to complain to the Information Commissioner's Office.