Intuitive Support Services Limited is not regulated by the Financial Conduct Authority (FCA). However, we directly support firms that are.
Where a regulated financial advice firm outsources activities to us, the firm remains responsible for its own regulatory obligations and oversight of the outsourced activity. Intuitive also has its own legal and contractual responsibilities, including those arising under UK data protection legislation.
Consumer Duty
The financial advice firm remains responsible for meeting its obligations under the FCA’s Consumer Duty, including where activities are outsourced to Intuitive.
When providing administrative support, we work in accordance with your instructions, procedures and requirements and recognise the importance of supporting good outcomes for retail customers.
Data Protection Responsibilities
When processing your client data on your instructions in connection with our outsourced administration services, you will generally act as the data controller and Intuitive will act as your data processor.
Our Service Agreement includes the data-processing provisions required under UK GDPR.
Data controllers are required to use processors that provide sufficient guarantees that appropriate technical and organisational measures are in place to protect personal data.
Our Due Diligence document provides detailed information on our systems, controls and procedures and is available on request.
How We Access & Handle Client Data
We only access and use client data on your instructions and for the purposes of providing our services.
Access may be granted by you through a variety of systems, including:
• Back-office systems
• Cloud-based storage
• Investment platforms
• Research software
• Client portals
• Email accounts hosted on your domain
• Your own servers or hosted desktops
During the course of providing our services, client data may be accessed through systems that you provide us access to, received into an Intuitive email account, or temporarily downloaded where necessary to carry out an administrative task. Our working practices are designed to minimise the storage of client data locally on company laptops.
Access to client information is restricted according to business need and, wherever the relevant system permits, individual user access is used rather than shared credentials. Client information is kept logically separated according to the advice firm being supported.
Our team work from within the UK and are not permitted to work from overseas.
When our services end, access to your systems is removed and client data held by Intuitive is returned or securely deleted in accordance with our contractual obligations and documented disengagement procedures.
Third-Party Service Providers & Sub-processors
We do not sell your client data or disclose it to third parties for their own marketing purposes.
We may use carefully selected third-party service providers to support the delivery, security and operation of our services. Where those providers process personal data on our behalf, appropriate data protection and contractual arrangements are maintained.
We only process or disclose client data in accordance with your instructions, our agreement with you and applicable legal requirements.
Systems & IT Security
Our team works from company-owned laptops which are professionally configured and managed by our specialist IT provider, Cloud Geeni.
Our IT environment incorporates a range of security controls, including:
• Multi-Factor Authentication (MFA)
• Device encryption
• Managed endpoint protection
• Email security
• Role-based access controls
• Managed security updates and patching
• Security monitoring
Further technical information is available within our Due Diligence document.
Secure Transmission of Data
When confidential information is sent from an Intuitive email account, we use the security controls and secure transmission methods available within our managed Microsoft 365 environment, where appropriate.
Where we use an email account or system provided by your firm, you are responsible for determining and providing the appropriate method for the secure transmission of confidential information, for example through your email encryption solution or secure portal. We will follow the procedures and instructions you provide.
Where necessary, we are also happy to work with you to agree alternative methods for securely exchanging confidential information.
Software & Tools
We use a range of approved software and technology to support the delivery of our services. Where a tool involves the processing of personal data, its use is subject to our information security and data protection procedures.
Certain optional third-party tools may also be used to assist with specific administrative tasks, for example:
• ILovePDF – PDF editing tool
• 4Admin – LoA data analysis
You may ask us not to use these optional tools when supporting your firm. Where you require us to work within your own systems, software or approved platforms, we are generally happy to do so, subject to appropriate access being provided.
Internal Policies & Staff Controls
We operate under documented internal policies, including:
• Data Protection and Security Policy
• Computer Systems and Internet Policy
• Company Standards and Rules Policy
• Telephone Usage Policy
These cover areas such as:
• Secure transmission of information
• Secure home-working practices
• Password, authentication & user access controls
• Company device and printer security
• Information security incident reporting
Staff confirm their understanding of, and compliance with, these policies on an annual basis.
Staff Training
All staff complete annual training and testing in:
• Anti-Money Laundering & Financial Crime
• Data Protection
• Cyber Security
• Vulnerable Clients
• Health & Safety
Additional training is provided where required to reflect changes in legislation, technology, systems or our internal procedures.
Operational Controls & Business Continuity
We maintain documented operational procedures and best-practice guidelines. When supporting your firm, we will follow your relevant procedures and requirements where applicable, whilst also complying with Intuitive’s own policies and procedures and maintaining appropriate audit trails.
We also maintain a documented Business Continuity Plan, which is reviewed and updated regularly and following significant changes to our business or systems.
Registrations, Certifications & Confidentiality
• Intuitive Support Services Limited is registered with the Information Commissioner’s Office (ICO) LINK
• Intuitive Support Services Limited holds Cyber Essentials Plus certification LINK
• Confidentiality obligations form part of both our Service Agreement and Contracts of Employment
• We are also happy to sign your own NDA if required.

Privacy Policy
HERE