InterposeInvest

Privacy Policy

Last updated 22 August 2026

In short

We collect what you send us — your name, work email, firm, and anything you type into a form — plus basic technical information about the visit. We use it to reply to you and to run the product.

This marketing site sets no cookies and runs no advertising or cross-site tracking. We do not sell or share personal information.

Where an advisory firm uses Interpose to serve its own clients, that firm is the controller of its clients' data and we act on its instructions.

1.Who we are

Interpose (“Interpose”, “we”, “us”) provides portfolio management and client-experience software to investment advisory firms and other financial institutions. This policy covers this website, the self-serve trial, and the Interpose platform.

Questions, requests, or anything you think is wrong here: hello@interposehq.com.

2.Two different roles, and why the difference matters

Interpose handles personal information in two distinct capacities, and your rights run differently in each. This is the most important section of this policy.

As a controller — for people who visit this site, contact us, or sign up for a trial. We decide what is collected and why. Requests under §8 come to us directly.
As a processor / service provider — for the end-client data an advisory firm loads into the platform (account holders, positions, tax lots, documents). The firm is the controller. We process that data only on the firm's documented instructions, never for our own purposes, and never to train models or build products. If you are a client of a firm that uses Interpose, direct privacy requests to your advisory firm; we will support them in responding, and we will not act on such a request without the firm's instruction.

3.What we collect

CategoryWhat it isWhere it comes from
Contact and enquiry dataName, work email, firm name, your message, and any optional qualifying answers you choose to give (assets under management band, custodians, incumbent system, timeline).The contact form on this site.
Trial account dataName, work email, company, and the credentials issued for the trial tenant.The self-serve signup on /start.
Attribution dataThe first page of your visit, the referring website, and any campaign parameters in the link you followed.Stored in your browser's session storage on arrival, and sent to us only if and when you submit a form.
Technical dataIP address and browser user-agent string, recorded with form submissions.Your request, automatically. Kept for security and abuse triage.
Platform usage dataLogin records, actions taken in the portal, and application logs.Your use of the product, if you become a customer or trial user.
Customer contentWhatever an advisory firm loads: account records, holdings, tax lots, transactions, documents. May include end-client personal and financial information.The firm. Processed under §2 as a processor.

4.What we do not do

  • No cookies on this site. The attribution described above uses your browser's session storage and is cleared when you close the tab. The signed-in portal at app.interposehq.com does use a strictly necessary session cookie to keep you logged in.
  • No advertising networks, no cross-site tracking, no data brokers.
  • No sale or sharing of personal information as those terms are defined under the California Consumer Privacy Act and comparable state laws. We have not sold or shared personal information in the preceding twelve months.
  • No training of machine-learning models on customer content. Where an AI feature is used, the relevant text is sent to the provider named in §6 for that single request under an agreement that prohibits training on it.
  • No third-party analytics unless deliberately enabled. If aggregate analytics is switched on, it is a cookieless product that collects no personal data and builds no cross-site profile. This page will name it here when that happens.

5.Why we use it

PurposeLegal basis (UK/EU GDPR)
Replying to your enquiry and running a sales conversationLegitimate interests — responding to a request you initiated.
Providing and operating the platform for a customerPerformance of a contract.
Provisioning and supporting a trialSteps taken at your request prior to a contract.
Security, abuse prevention and service integrityLegitimate interests — protecting the service and its users.
Meeting our own record-keeping and legal obligationsLegal obligation.

Where we act as a processor (§2), the legal basis for the underlying processing is the advisory firm's to establish, not ours.

6.Who we share it with

We use a small number of sub-processors to run the service. We do not sell data to anyone, and none of these are advertising businesses.

Sub-processorWhat it doesData it can reach
DigitalOceanCloud hosting and managed PostgreSQL. All application data lives here.All platform data.
AnthropicGenerates meeting briefings, summaries and portfolio commentary where a firm enables AI features.The specific content sent for that request. Not used for training.
SentryApplication error monitoring, where enabled.Diagnostic data and error context, which may incidentally include identifiers.
Polygon.io / FinnhubMarket data — prices, reference data, corporate actions.Security identifiers only. No personal information is sent.
Plausible AnalyticsAggregate, cookieless site analytics — only if enabled (§4).Aggregate page-level statistics. No personal data, no cross-site profile.

We will also disclose information where we are legally required to, and to professional advisers under confidentiality. If we are ever party to a merger or acquisition, we will give notice before any personal information becomes subject to a different policy.

A current sub-processor list is maintained for customers and is available on request for a vendor due-diligence review.

7.How long we keep it

DataRetention
Enquiries and contact recordsUp to 24 months from the last contact, then deleted, unless you become a customer.
Trial tenantsThe trial runs 30 days. After it expires the login stops working but the data is retained for a further 15 days so a trial can be resumed after a conversation. After that grace period it is purged.
Customer contentFor the life of the agreement. On termination, exported on request and then deleted per the agreement's terms.
Records we are required to keepCertain records — including business correspondence — are retained for the period the applicable financial regulations require, which may be up to seven years, and are held in a form that cannot be altered.
Security and abuse logs12 months.

8.Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected or deleted, to receive a portable copy, to object to or restrict processing, and to withdraw consent where we relied on it. In California you additionally have the right to know, to delete, to correct, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising any of them.

Write to hello@interposehq.com. We will respond within the period the applicable law requires and will not charge you for it. We may need to verify your identity first, and we may be unable to delete records we are legally required to retain — we will tell you if that applies.

If you are an end client of an advisory firm using Interpose, please send your request to that firm (see §2). If you are in the UK or EU and are unhappy with our response, you may complain to your local supervisory authority.

9.Security

Data is encrypted in transit using TLS. Access to production systems is restricted and authenticated, application data is segregated by firm, and the platform enforces tenant isolation on every request rather than at the user interface. Backups are taken on a schedule and retained.

No system is perfectly secure and we will not claim otherwise. Where we are required to notify you or a regulator of a personal data breach, we will do so within the period the applicable law requires, and our customer agreements set out the notice we give advisory firms.

10.Financial privacy

Where we handle nonpublic personal information about the customers of a financial institution, we do so as that institution's service provider under the Gramm-Leach-Bliley Act and SEC Regulation S-P. We use it only to perform the services the institution has engaged us for, and we do not disclose it except as permitted by that engagement or as required by law.

11.International transfers

We operate from the United States and our infrastructure is located there. If you contact us from outside the United States, your information will be transferred to and processed in the United States. Where such a transfer is from the UK or EEA, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) with the relevant parties.

12.Children

This site and the platform are business tools sold to financial institutions. They are not directed to children and we do not knowingly collect personal information from anyone under 18. If you believe we have, contact us and we will delete it.

13.Changes

We will update this page when our practices change, and will revise the date at the top. Where a change materially affects how we handle information we already hold, we will give notice to affected customers before it takes effect.