Compliant Paraplanning Services for UK adviser firms
Security by separation

The public website is not the client-data workspace.

WordPress is used only for public information and firm-level business enquiries. It does not accept case uploads or identifiable client information.

01

Public website

Marketing pages and firm-level enquiry forms only. No case submission, client login or document upload capability.

02

Business administration

Approved-firm contracts, invoicing and supplier records are kept outside the public website with access limited to the business purpose.

03

Case workspace

A separate Microsoft 365 business tenant is planned before the first live case, with named guest access, MFA and audit controls.

Planned case controls

What must be in place before client data is accepted.

  • Microsoft 365 Business Premium tenant configured for the business
  • Named Entra B2B guest accounts and mandatory multi-factor authentication
  • Authenticated-only SharePoint sharing; no anonymous links
  • Separate workspace or restricted area for each adviser firm
  • Least-privilege access, audit logging and documented access reviews
  • 90-day working-file retention and secure deletion process
  • Controller-processor terms, DPIA and approved subprocessor record
  • Tested breach, continuity and access-revocation procedures
Access to firm systems

Named access, never shared credentials.

Some working arrangements may require a firm email address, provider correspondence or access to an approved platform. That access must remain attributable and controlled by the adviser firm.

  • A separate named account for the individual user
  • Multi-factor authentication wherever the service supports it
  • Only the permissions and case areas needed for the agreed work
  • A firm-provisioned mailbox where provider communication requires one
  • Prompt suspension or removal when the engagement or need ends
Current status

The adviser case workspace is not yet open.

Until the business-grade environment, contracts and tests are complete, do not send any client names, documents, health information, identification, bank details or case facts to CPS.

Data-protection roles

The intended default is that the adviser firm acts as controller for end-client data and CPS acts as its processor for the contracted paraplanning work. This must be confirmed in writing for each engagement; CPS may be an independent controller for its own legal, security, accounting and business-administration records.

The adviser’s permission to share information is important, but it does not replace the firm’s lawful-basis assessment, transparency obligations, data-minimisation duties or the written processor terms required for an outsourced service.

Retention

The planned default is deletion of CPS working copies 90 days after case completion, subject to legal holds, disputes and a documented contractual exception. The engaging firm remains responsible for the regulatory record.