Services provided as a tied agent of Crito Capital, Empresa de Investimento, S.A.
Version 1.0 · 31 July 2026 · Data protection under the EU General Data Protection Regulation (GDPR)
At a glance
This notice explains who is responsible for your personal data, what we collect, why we use it, who we share it with, how long we keep it, and the rights you have. The detail follows below.
- Who is responsible: Crito Capital ("Crito"), our Principal, is responsible for the regulated advice and orders provided in its name; Centry is responsible for its own services (tax advice, accounting and legal coordination, our technology platform and monitoring, our relationship with you, and any marketing). See section 1.
- What we do that affects your data: we advise you and transmit your orders to your own custodian, provide tax advice and coordinate your accounting and legal affairs, verify your identity and prevent financial crime, monitor your plan, and use software (including AI) built by our parent company to help prepare your advice. A person always decides.
- Your main rights: to access your data, correct it, object to some uses, and complain to the CNPD. See section 10.
- Contact: henry.tucker@centry.capital.
1. Who we are and who is responsible for your data
Centry, Unipessoal LDA, trading as Centry Capital ("Centry", "we", "us"), is a Portuguese company (NIPC 518824110). We provide client-facing investment advice and receive and transmit your orders as a tied agent (agente vinculado) of Crito Capital, Empresa de Investimento, S.A. (NIPC 517676494) ("Crito" or "the Principal"), an investment firm authorised and supervised by the Comissão do Mercado de Valores Mobiliários (CMVM).
Centry is a wholly owned subsidiary of Centry Cognitive Capital Pte. Ltd, a company incorporated in Singapore (UEN 202514224H), which builds and operates our technology platform, including its AI systems, for us as our processor. Client personal data is not accessible from Singapore: the platform is operated from within the European Economic Area (EEA) and Switzerland (see sections 7 and 8).
Who is responsible for your personal data depends on the activity:
- Regulated services in Crito's name. For investment advice and the reception and transmission of your orders to your own custodian, Crito is the controller of your personal data and Centry acts on its behalf.
- Centry's own services. For our tax advice, accounting and legal coordination service, the operation of our technology platform including monitoring, our management of your relationship with us, and any marketing, Centry is the controller.
- Joint activities. Where Centry and Crito decide together how and why your data is used for a particular activity, we are joint controllers and have an arrangement under Article 26 GDPR. You can ask us for the essence of that arrangement, and you can exercise your rights against either Centry or Crito.
Discretionary portfolio management is not part of the tied-agent service Centry provides. Where portfolio management is offered, it is provided by Crito, in Crito's name and under Crito's authorisation, and Crito's own privacy information applies to it. Insurance-based investment products are distributed only once the necessary insurance-distribution registration with the Autoridade de Supervisão de Seguros e Fundos de Pensões (ASF) is in place; until then, references in this notice to insurance products do not apply.
Crito's own privacy information applies to the services provided in its name. This notice explains Centry's processing and, where Centry acts for Crito, how your data is handled. For data protection, the relevant supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD).
2. The personal data we process
Depending on your circumstances and the services you take, we process the following categories of personal data:
- Identity and contact details: name, date of birth, nationality, identification and tax numbers, a copy of your ID or passport, address, email and telephone number.
- Family and relationship details: marital status and, where relevant to your plan or required by law, information about your spouse or partner, dependants, and connected persons such as beneficial owners, representatives or additional account holders.
- Financial and wealth information: your assets, liabilities, income, investments, financial statements, source of wealth and source of funds, investment objectives, risk tolerance and capacity for loss.
- Tax information: your tax residence and domicile and related documents, which support the tax advice service.
- Suitability information: your knowledge and experience of investments and your sustainability preferences.
- Health and vulnerability information: information about your health or personal circumstances that you choose to share with us, or share in response to an open question in our fact-find, where it is relevant to your plan or to how we should adjust our service to treat you fairly. We only record and use it with your explicit consent (see section 5).
- Records of our dealings with you: correspondence, meeting notes, and recordings of the telephone and electronic communications relating to your orders, which we are required by law to keep.
- Monitoring information: signals from your portfolio and circumstances that we monitor against your plan, and the results of that monitoring.
- Financial-crime screening information: the results of checks against sanctions, politically-exposed-person and adverse-media sources. These may include information about criminal convictions or offences, or information revealing political exposure (see section 5).
- Platform and technical information: the identifiers and audit logs our platform creates as you are served.
3. Where we get your data from
We collect personal data:
- from you, when you enquire, are onboarded, and receive our services;
- from the tax practice or person who introduced you to us;
- from your custodian bank(s) and, for insurance-based products, the insurer;
- from the specialist providers who carry out identity and financial-crime screening for us; and
- from public sources, including the Portuguese central register of beneficial ownership (Registo Central do Beneficiário Efetivo) and sanctions, politically-exposed-person and adverse-media databases.
If you give us information about other people (for example connected persons or beneficial owners), please share this notice with them.
4. Why we use your data and our legal basis
We only use your personal data for a specific purpose, and only the data we need for it. The table sets out each purpose and the legal basis under the GDPR that we rely on.
Where we rely on legitimate interests, we have weighed them against your rights, and you can object (see section 10). Where we rely on your consent, you can withdraw it at any time without affecting earlier use. If you do not give us information we need to meet a legal obligation or to provide a service, we may be unable to act for you, and we will tell you if so.
| Purpose | Personal data used | Legal basis (GDPR) |
|---|---|---|
| 1. Checking your identity and onboarding you | Identity, contact, financial, tax | Performing our contract with you (Art 6(1)(b)); complying with legal obligations, including anti-money-laundering law (Art 6(1)(c)) |
| 2. Preventing financial crime: sanctions, PEP and adverse-media screening, monitoring and reporting | Identity, screening results, financial | Legal obligation (Art 6(1)(c)); for special-category and criminal-offence data, substantial public interest under Union and Portuguese law (Art 9(2)(g), Art 10) |
| 3. Giving advice, assessing suitability, and transmitting your orders | Identity, financial, tax, suitability, monitoring | Performing our contract (Art 6(1)(b)); the suitability, disclosure and record-keeping duties under MiFID II (Art 6(1)(c)) |
| 4. Recording the communications about your orders | Communications and order records | Legal obligation under Article 16(7) MiFID II (Art 6(1)(c)) |
| 5. Providing tax advice and accounting and legal coordination services | Identity, financial, tax | Performing our contract with you (Art 6(1)(b)) |
| 6. Ongoing monitoring of your portfolio and plan, suitability review, and the profiling this involves | Financial, suitability, monitoring | Our legitimate interest in delivering the ongoing service and identifying risks to your plan before they cause harm (Art 6(1)(f)); the duty to review suitability (Art 6(1)(c)) |
| 7. Recording and responding to health or vulnerability information you share with us, so our advice and service treat you fairly | Health and vulnerability information | Your explicit consent (Art 9(2)(a)), collected through a separate consent form; you can withdraw at any time |
| 8. Managing our relationship with you, handling complaints, keeping records | Identity, contact, records | Contract (Art 6(1)(b)); legal obligations (Art 6(1)(c)); our legitimate interest in running and evidencing our service (Art 6(1)(f)) |
| 9. Improving our services and governing our technology and models (testing, error and bias monitoring) | Platform data; other data where needed, anonymised or de-identified wherever possible | Our legitimate interest in a safe, accurate and well-controlled platform (Art 6(1)(f)) |
| 10. Sending you marketing about our services by electronic means | Contact, relationship | Your consent (Art 6(1)(a)) and, for electronic marketing, Lei 41/2004; you can withdraw at any time |
| 11. Establishing or defending legal claims; responding to authorities and courts | Any relevant data | Legal obligations (Art 6(1)(c)); our legitimate interest in protecting our legal position (Art 6(1)(f)); Art 9(2)(f) for special-category data |
| 12. A sale, merger or reorganisation of our business | Relevant data, kept to a minimum | Our legitimate interest in carrying out the transaction (Art 6(1)(f)) |
5. Special-category and criminal-offence data
We do not routinely collect health data. If you provide health or vulnerability information relevant to the service, we will use it only where necessary and where a valid GDPR condition applies.
Where explicit consent is the condition relied on, we will obtain it separately. You may withdraw consent at any time. Withdrawal does not affect prior processing or records we must retain by law. Access is restricted, and this information is not used for marketing.
Separately, the financial-crime checks the law requires us to run, against sanctions, politically-exposed-person and adverse-media sources, can return information about criminal convictions or offences, or information that reveals political exposure. We process this only so far as needed to meet our anti-money-laundering and sanctions obligations, on the basis of substantial public interest laid down in Union and Portuguese law (Articles 9(2)(g) and 10 GDPR, and Lei 83/2017), and we apply additional safeguards and access controls to it.
6. Automated processing, profiling and our use of AI
We may use software, including AI-enabled tools, to organise information, prepare draft analysis and support agreed monitoring. This may involve profiling, meaning automated analysis of information such as financial circumstances, objectives and preferences. The relevant technology provider acts under contractual and technical controls.
We do not make decisions about you solely by automated means where those decisions have legal or similarly significant effects. A qualified person reviews recommendations before they are issued, and staff review financial-crime alerts.
The tools may identify relevant information, draft material for adviser review and flag events requiring attention. They do not execute transactions or issue recommendations automatically. Your adviser remains responsible for the advice provided to you.
AI-enabled tools do not process health or vulnerability information unless Centry has documented a lawful, controlled exception.
You may ask for an explanation of a recommendation and object to profiling based on legitimate interests (see section 10).
7. Who we share your data with
We share personal data only where needed, and we do not sell it. Depending on the services you take, we share it with:
- Centry Cognitive Capital Pte. Ltd, our parent company, which builds and runs our technology platform (including the AI systems described in section 6) for us as our processor under a written contract; its personnel access personal data only from within the EEA or Switzerland, its staff in Singapore work only with anonymised or synthetic data, and it does not use your personal data for its own purposes, including to train models for other customers;
- specialist providers acting as our processors, including identity, sanctions, PEP and adverse-media screening, source-of-wealth tooling, market, fund, corporate-actions and ESG data, and our outsourced internal auditor;
- your own custodian bank(s), and for insurance-based products the insurer, who act as separate controllers of the data they receive;
- our professional advisers, such as lawyers and auditors;
- competent authorities and public bodies where the law requires or permits, including the CMVM, the CNPD, Banco de Portugal, the ASF, the tax authority, the financial-intelligence unit, and courts;
- Crito, in connection with the regulated services provided in its name; and
- a buyer or partner, and their advisers, in connection with a sale, merger or reorganisation of our business, subject to appropriate confidentiality and data-protection safeguards.
We require our processors to protect your data under a written contract and to act only on our instructions. Where Crito is the controller, the same processors act within a chain that Crito has authorised.
8. Where your data is processed
Personal data is hosted and processed in the EEA, Switzerland and may include jurisdictions recognised as adequate by the European Commission.
9. How long we keep your data
We retain personal data only for as long as necessary for the purpose, legal retention requirements and any applicable limitation period. Key periods are:
- advice, suitability, order and relevant communications records: at least 5 years and, where required, up to 7 years;
- anti-money-laundering records: 7 years from the relevant statutory trigger; and
- other records: for the relevant legal, tax, commercial or claims period.
Our retention schedule records the applicable periods. You may ask which period applies to a particular category of record.
10. Your rights
You have the following rights over your personal data, which you can exercise free of charge by contacting us (section 11):
- to be informed about how we use your data (this notice);
- to access a copy of your data;
- to have inaccurate or incomplete data corrected;
- to have your data erased in certain circumstances;
- to restrict how we use your data in certain circumstances;
- to object to processing based on our legitimate interests, including the profiling in our ongoing monitoring, and to object to direct marketing at any time;
- to receive certain data in a portable format, or have it sent to another provider, where we rely on your consent or on our contract with you; and
- to withdraw consent at any time, where we rely on it, without affecting earlier use.
In relation to solely automated decisions with legal or similarly significant effects, Article 22 GDPR gives additional safeguards. As explained in section 6, we do not make such decisions, because a person always decides.
These rights are not always absolute, and exemptions can apply, for example where we must keep information to meet a legal obligation. We will normally verify your identity, respond within one month, and explain our reasons if we cannot meet a request in full. For the regulated services provided in Crito's name, we will pass your request to Crito, or you can contact Crito directly.
11. How to contact us and how to complain
For any question about this notice, or to exercise your rights, contact henry.tucker@centry.capital.
If you are not satisfied with how we have handled your personal data, please tell us first so we can put it right. You can also complain to the Portuguese supervisory authority:
Comissão Nacional de Proteção de Dados (CNPD)
+351 213 928 400 · geral@cnpd.pt · www.cnpd.pt
Your information is also protected by the duty of professional secrecy (segredo profissional) that applies to us under the Portuguese Securities Code (Código dos Valores Mobiliários).
12. Changes to this notice
This is version 1.0, dated 31 July 2026. We may update this notice, and we will make the current version available to you and tell you about significant changes.