Your privacy is important to us at Stewart. We respect your privacy regarding any
information we may collect from you across our website.
Effective date: 30 August 2025
Table of contents
Back to top
Steward AI, Inc. (“Steward”, “we”, “us”, “our”) builds AI-powered Anti-Money Laundering (AML) solutions that streamline onboarding, periodic reviews, and ongoing monitoring for investment services firms.
This Privacy Policy explains how we collect, use, disclose, and protect personal data across our websites, products, and services.
This notice applies when you:
Visit our websites,
Use our AI-driven compliance platform, or
Interact with our support and customer teams.
It does not apply to third-party websites or services outside our control.
When we act as a controller: for our own websites, analytics, events, direct marketing as use of the “Steward Profile” feature.
When we act as a processor: when we process personal data on behalf of our customers (e.g., AML/KYC/KYB/KYI checks). In these cases, our customers are the controllers and determine the purposes and means of processing. We process according to their instructions and our data processing agreements.
If you are an investor, beneficial owner, director, officer, or other individual whose data we process on behalf of a customer, please direct requests to that customer (the controller). We will assist them as required by law.
“Affiliates” means legal entities owned or controlled by Steward AI, Inc.
“Personal data” means any information relating to an identified or identifiable individual (e.g., name, email, ID numbers; or device data when linkable to you).
Data you provide to us (directly or via our Affiliates)
Identity, contact, and - where relevant - financial details (e.g., name, address, date of birth; investor or directorship information).
Biometric data (e.g., face images/liveness checks) where identity verification is required by a customer.
Family, lifestyle, education, and employment details where relevant to the service.
Information about other named applicants or related parties (you must have authority to share this and share this notice with them first).
Device and usage information (e.g., IP address, device attributes) when accessing our sites/services.
Data we receive from third parties you interact with Fund administrators, transfer agents, funds, brokers, intermediaries, wealth managers, banks, introducers, and other financial institutions.
Data we create or collect in the course of services include records and logs from our platform and CRM; audit trails; training/quality-assurance call recordings where lawful; and records of investments/payments that relate to our services.
Data from other sources include fraud-prevention agencies, insolvency practitioners, tracing agents, commercial/public databases, corporate registries, sanctions/PEP lists, and other publicly available sources.
On behalf of our customers (processor activities)
To help customers assess eligibility to invest under applicable laws and policies (all determinations are made by our customers).
To verify identity, prevent fraud or money laundering, detect false/inaccurate information, and support regulatory reporting.
Ongoing monitoring and periodic reviews or other AML/KYC services agreed with our customers.
For our own purposes (controller activities)
Audit & compliance: to meet our legal, regulatory, and audit obligations.
Analytics & research: to improve, test, and enhance our services (we use anonymised/aggregated data where possible).
Service communications: operational messages about the services you use.
Marketing: to send product updates or event invites where permitted. You can opt out at any time (see Marketing choices).
To provide and maintain your Steward Profile (account set-up, identity re-verification, and other AML/KYC services agreed with you from time to time).
We rely on one or more of the following grounds:
Contract – to perform services you or your organization have engaged us for, or further to a services agreement or engagement letter you have entered into with one of our customers.
Legal obligation – such as AML, CTF, and sanctions compliance to ensure that regulatory and legal rules have not been breached.
Legitimate interests – improving services, maintaining security, preventing abuse, and communicating relevant updates (balanced against your rights).
Audit – to carry out audits or regulatory reviews.
Consent – for certain marketing or optional features, which you may withdraw at any time.
Special category/biometric data: Where identity verification involves biometric data used for unique identification, our customers (as controllers) typically rely on an applicable exemption (e.g., substantial public interest/AML where permitted by law) or obtain explicit consent; we process such data on their instructions and implement heightened safeguards.
Our platform uses AI models and rules to flag potential risks (e.g., suspicious activity or sanctions/PEP matches). Human spot checking is the norm. If any outcome is based solely on automated processing with legal or similarly significant effects, you may request human intervention, express your view, or contest the decision, where applicable.
We may share personal data with:
Our Affiliates;
Service providers/contractors (cloud hosting, security, analytics, identity verification, auditors, legal advisors) under confidentiality and data protection terms;
Credit reference and fraud-prevention agencies;
Government bodies/regulators (US, UK, EU, and other jurisdictions) when required;
Prospective buyers and their advisors in connection with a corporate transaction;
Where necessary to protect rights, safety, or vital interests; and
Where otherwise required by law or legal process.
Notes on credit reference & fraud-prevention agencies: These agencies may create/search records related to your business and key individuals, verify identities, record enquiry “footprints”, and share information with other organisations to prevent fraud and money laundering. Records may be retained for up to six years as permitted by law.
We operate globally. Where personal data is transferred outside the EEA/UK, we ensure appropriate safeguards, such as:
European Commission Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement/Addendum;
EU-US Data Privacy Framework (DPF) (and UK Extension), where applicable; and
Other mechanisms recognised by data protection law.
You can request details of relevant safeguards (including copies of SCCs) via compliance@getsteward.ai.
This website may use cookies to collect information about you. If you use this website, then you accept that we can use the cookies set out as stipulated in our Cookies Notice.
We apply strict administrative, technical, and organisational measures, including, but not limited to:
Access controls and encryption (in transit and at rest),
Secure coding and vulnerability management,
Monitoring and auditing,
Vendor risk assessments,
Staff training on confidentiality and compliance.
We retain personal data only for as long as necessary for the purposes described, including to meet legal, regulatory, accounting, or reporting requirements. For AML/CTF obligations, records are often kept for at least five years after the end of the relationship or the relevant transaction, unless a longer period is required by law or permitted to establish, exercise, or defend legal claims.
Depending on your jurisdiction, you may have the right to:
Access and receive a copy of your personal data,
Correct or update inaccurate data,
Request deletion of your information (where permitted),
Restrict or object to processing,
Withdraw consent at any time,
Request portability of your data,
File a complaint with your data protection authority.
We may need to verify your identity before responding.
Compliance Team / Data Protection Officer
8 The Green STE B, Dover, Delaware, 19901 United States
Where legally necessary, we appoint local representatives in the EU and/or UK. Contact details are available on request at compliance@getsteward.ai.
If you have concerns, please contact us first. If unresolved, you have the right to raise a complaint with your local data protection authority.
We may revise this Privacy Policy periodically. Significant changes will be communicated appropriately, and the latest version will always be available on our website.
You can opt out of marketing communications at any time by following the unsubscribe link in our messages or by emailing compliance@getsteward.ai.
We will continue to send essential service communications.
Product