Data Protection
Privacy Policy
This policy explains how Optimus Investigations Global Ltd collects, uses, shares and protects personal information when you use our website, contact us or engage our verification and investigative services.
Our commitment
We recognise that verification work may involve sensitive personal information. We apply confidentiality, necessity, proportionality and data-minimisation principles throughout the lifecycle of an instruction.
1. Who we are
Optimus Investigations Global Ltd (“Optimus”, “we”, “us” or “our”) is a UK-based cross-border verification and intelligence firm specialising in African jurisdictions.
For website enquiries and most business-administration activities, Optimus is the data controller. For professional instructions, our role may be controller, joint controller or processor depending on the circumstances and our agreement with the instructing client.
Contact: inquiries@optimusinvestigations.com
Address: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
Telephone: +44 (0)20 8798 3234
2. Scope of this policy
This policy applies when you:
- Visit or interact with our website
- Contact us by form, email, telephone or WhatsApp
- Request, instruct, receive or support our services
- Represent a client, supplier, authority or professional organisation
- Are a person whose information is lawfully considered during verification work
Specific client engagement terms or a case-specific privacy notice may provide additional information where appropriate.
3. Information we collect
The information collected depends on the nature and lawful purpose of the interaction or instruction. It may include:
- Identity and contact data: names, addresses, telephone numbers, email addresses, dates of birth and identification details
- Professional and organisation data: employer, role, professional details and authority to instruct
- Inquiry and instruction data: service requested, jurisdiction, purpose, deadlines, correspondence and case references
- Verification data: education, employment, qualifications, directorships, addresses, occupancy, civil records, affiliations and relevant history
- Documentary data: copies or details of documents supplied for authentication or verification
- Technical data: IP address, browser, device, website activity, security logs and cookie preferences
- Financial and transaction data: billing contact, invoices and payment records
- Compliance data: identity, conflict, sanctions, fraud-prevention and lawful-purpose checks
4. Where information comes from
We may obtain personal information:
- Directly from you or the organisation you represent
- From a client lawfully instructing us
- From documents and evidence provided for verification
- From Government bodies, registries, courts, educational institutions, employers, professional or regulatory bodies
- From publicly accessible records and reputable open sources
- From authorised local researchers, field agents and specialist service providers
- From witnesses, referees or other relevant sources where lawful and proportionate
- Through our website and communication systems
Where information is not obtained directly from the individual, providing a direct privacy notice may be delayed or restricted where the law permits, including where disclosure would seriously impair a lawful investigation or affect another person’s rights.
5. How and why we use personal information
| Purpose | Examples |
|---|---|
| Managing enquiries | Responding to requests, assessing feasibility and communicating next steps |
| Providing services | Document authentication, background, identity, age, address and claim verification |
| Reporting | Analysing evidence and preparing clear findings for authorised recipients |
| Client administration | Engagement, conflicts, billing, records and professional correspondence |
| Legal and compliance | Data protection, fraud prevention, sanctions, disputes and regulatory obligations |
| Security and improvement | Protecting our systems, preventing misuse and improving website performance |
We do not use personal information for purposes that are incompatible with the reason it was collected unless permitted or required by law.
6. Our lawful bases
Depending on the circumstances, we may rely on one or more of the following lawful bases under UK data-protection law:
- Contract: where processing is necessary to take steps at your request or perform a contract with you
- Legal obligation: where processing is necessary to comply with a legal duty
- Legitimate interests: where necessary for lawful verification, due diligence, fraud prevention, legal claims, security or business administration, provided those interests are not overridden by individual rights
- Consent: where consent is appropriate and has been freely given; it may be withdrawn at any time
- Vital interests or public task: only where the relevant legal requirements apply
For client-commissioned verification, we assess the purpose, necessity, proportionality and reasonable expectations relevant to the instruction. The instructing organisation remains responsible for its own lawful basis and transparency duties where it acts as controller.
7. Special-category and criminal-offence information
Some assignments may involve special-category data—such as information concerning health, ethnicity, religion, political opinions or biometric identification—or criminal-offence data.
We process such information only where an applicable legal condition is satisfied, the processing is necessary and proportionate, and appropriate safeguards are in place. Depending on the circumstances, this may include explicit consent, legal claims, substantial public interest conditions or another condition permitted by law.
Criminal-offence data is processed only under official authority or where specifically authorised by UK law, with appropriate policy and safeguards where required.
8. Who we may share information with
We share personal information only where necessary, lawful and proportionate. Recipients may include:
- The client or authorised professional who instructed the work
- Government, legal, regulatory or judicial bodies where authorised or required
- Educational institutions, employers, registries and issuing authorities
- Vetted local researchers, field agents, translators and professional advisers
- Secure technology, hosting, communication and records-management providers
- Insurers, auditors, legal advisers and law-enforcement bodies where appropriate
Service providers are required to protect information and use it only for authorised purposes. We do not sell personal information.
9. International transfers
Our Pan-African services may require personal information to be accessed, verified or processed outside the United Kingdom. Data-protection standards in the destination country may differ from UK standards.
Before an international transfer, we assess the necessity and risk and use an appropriate legal transfer mechanism where required. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or a permitted exception for a specific situation.
We also apply practical safeguards such as data minimisation, access restrictions, secure transfer methods, confidentiality requirements and limited retention.
10. Information security
We use technical and organisational measures appropriate to the nature and risk of the information processed. These may include:
- Role-based access and need-to-know restrictions
- Secure transfer, storage and communication methods
- Confidentiality obligations and supplier checks
- Device, account and system security controls
- Incident-management and breach-response procedures
- Regular review of case access and retention
No internet transmission or storage method is completely secure, but we take reasonable and proportionate steps to protect information against loss, misuse, unauthorised access, alteration and disclosure.
11. How long we keep information
We retain personal information only for as long as necessary for the purpose for which it was collected, including service delivery, evidential integrity, professional obligations, disputes, insurance, legal claims and regulatory requirements.
Retention periods vary according to the type of record, the client relationship, the sensitivity of the information and applicable legal or contractual requirements. When information is no longer required, it is securely deleted, anonymised or placed beyond routine use.
12. Your data-protection rights
Depending on the circumstances and applicable exemptions, you may have the right to:
These rights are not absolute. In verification and investigative contexts, the law may permit or require us to restrict a response—for example to protect another person’s rights, legal privilege, crime prevention, regulatory functions or the integrity of lawful enquiries.
To exercise a right, contact us using the details below. We may need to verify your identity and clarify the request. We normally respond within one month, although the law allows an extension for complex or numerous requests.
13. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about individuals solely by automated means. Professional findings are subject to human assessment and contextual review.
14. Cookies and website analytics
Our website may use essential cookies and, where permitted, analytics or preference technologies. Non-essential cookies will be used only in accordance with applicable consent requirements.
For details of the cookies used and how to control them, please read our Cookie Policy.
15. Children’s information
Our website and services are not directed at children. However, a lawful professional instruction may concern a child or young person. In those cases, we apply enhanced care, data minimisation and appropriate safeguards, taking account of the child’s best interests and the legal basis for processing.
16. Changes to this policy
We may update this policy to reflect changes in our services, legal requirements or processing practices. The current version will be published on this page with a revised effective date.
17. Contact and complaints
Questions, rights requests or privacy concerns should be sent to:
Optimus Investigations Global Ltd
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
Email: inquiries@optimusinvestigations.com
Telephone: +44 (0)20 8798 3234
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection. We would appreciate the opportunity to address your concern first.