Skip to main content

Compliance

Confidence comes
from control.

OIKIA’s operating approach puts verification, data minimisation, access control and traceable records into the workflow rather than treating them as an afterthought.

The control framework

Clear principles.
Visible practice.

01

KYC, AML and sanctions process

Relevant identity, anti-money-laundering, sanctions and PEP screening is completed as part of participant onboarding and recorded with the appropriate status and date.

02

UK GDPR principles

Personal data is handled for defined purposes with data minimisation, consent evidence, controlled access and appropriate retention.

03

Six-year record retention

Project contributions, payments, approvals, documents and correspondence are retained for six years by design.

04

Sensitive data as secure references

Identity documents and payment information are represented through controlled provider references rather than copied into ordinary CRM text fields.

05

Role-based access

Permissions are assigned by responsibility so internal users can access only the records and actions required for their role.

06

Audit trail

Material creation, changes, approvals, consent events and stage transitions are designed to leave a reviewable record.

07

No plain-text bank credentials

Bank passwords, card data and provider credentials do not belong in CRM records. Secure provider references support the operational link instead.

Disclaimer

Information, not legal advice.

This page describes OIKIA’s intended operational approach in general terms. It is not legal, tax, regulatory or financial advice and does not replace the governing agreement, a formal privacy notice or advice from an appropriately qualified professional.

Begin with a conversation

If the numbers do not work,
we will tell you.

It is cheaper for both of us than finding out on site. Bring us an address, or a question.

Start a conversation