How we collect, use, and protect your personal information
SCO AMERICA ("SCO AMERICA," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our institutional custody services, digital platform, and related financial services.
When you access our Digital Platform, we automatically collect IP addresses, device identifiers, browser type and operating system, access times, login credentials and session data, and platform usage patterns for security and performance purposes.
We maintain comprehensive records of all custody and settlement transactions, including securities holdings and movements, cash transactions and FX exchanges, corporate action elections, and all settlement instructions and confirmations.
We use your information to verify identity, detect and prevent fraud, conduct sanctions screening and PEP checks, maintain platform security, and manage operational, credit, and market risk across our business.
Under UK GDPR, we process your data under the following legal grounds:
We share data with sub-custodians, central securities depositories (Euroclear, Clearstream, CREST), payment systems (SWIFT, CHAPS), technology providers, professional advisors, and KYC/AML screening providers. All third parties operate under strict confidentiality obligations and data processing agreements.
We disclose information to the FCA, PRA, HMRC, ESMA, and other financial regulators as required. We will never sell your personal data to third parties for commercial purposes.
All third parties with whom we share your information are contractually obligated to maintain equivalent data protection standards and use your information solely for specified purposes. We conduct annual due diligence reviews of all data processors.
As a global custody bank, we transfer personal data outside the UK to sub-custodians and CSDs in jurisdictions where your securities are held. All international transfers comply with UK GDPR through adequacy decisions, Standard Contractual Clauses, or other approved transfer mechanisms. A full list of transfer safeguards is available on request.
Under UK GDPR, you have the following rights in relation to your personal information:
Request a copy of the data we hold about you.
Correct inaccurate or incomplete information.
Request deletion, subject to legal retention requirements.
Limit how we use your data in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests.
To exercise any right, contact our Data Protection Officer. Note that some rights are limited where we have overriding legal obligations to retain data.
We protect your information with AES-256 encryption at rest, TLS 1.3 in transit, multi-factor authentication with hardware token support, 24/7 Security Operations Centre monitoring, intrusion detection and prevention systems, ISO 27001 certification, and SOC 2 Type II compliance. All staff with data access undergo background checks and annual security training.
Our Digital Platform uses strictly necessary cookies for session management, security cookies to prevent fraud and unauthorised access, and optional analytics cookies to improve platform performance. You can manage cookie preferences via your browser settings, though disabling functional cookies may limit Platform capability.
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated by email to registered contacts, via a prominent notice on the Digital Platform, and by updating the effective date. Continued use of our services constitutes acceptance.
Company Registration: SCO AMERICA is registered in England and Wales (Company No. 02280926). Authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and PRA (FRN 144206). Registered office: 1 London Wall Place, London, England, EC2Y 5AU