Privacy Statement- last updated 22/5/18
AT mortgages (AT Financial Solutions Limited) is committed to protecting personal data. This privacy statement describes why and how we collect and use personal data and provides information about your rights in relation to it. It applies to personal data provided to us, both by you or by others. We may use personal data provided to us for any of the purposes described in this privacy statement or as otherwise stated at the point of collection.
Personal data is any information relating to an identified or identifiable living person. AT mortgages processes personal data for numerous purposes, and the means of collection, lawful basis of processing, use, disclosure, and retention periods for each purpose may differ.
When collecting and using your data, our policy is to be transparent about why and how we process it. To find out more about our specific processing activities, please go to the relevant sections of this statement.
WHAT INFORMATION DO WE GATHER?
To be able to provide you with the best service possible, we will need to gather certain personal information from you when you contact or interact with us. We will also use this information for security, identification and verification purposes.
We will only ever collect information that helps us provide our services to you. We will keep your information for as long as is needed and only for the following purposes:
- legitimate business activities
- statutory or legal obligations
- auditing and regulatory purposes
When you make an enquiry with us about any of the services we offer, we’ll ask you to provide some contact information. This may include some or all of the following:
- full name
- previous names
- current home address
- previous residential addresses
- date of birth
- landline and mobile phone number
- email address
If you give personal information about someone else (such as a joint applicant), you must have their permission to do so.
Once we have gathered information from you and you subsequently make contact with us, we will use specific pieces of your information to help us identify you and verify that we are dealing with the right person.
Where we offer other products such as insurance, we will need to collect and process information that is “sensitive”. This type of information includes details about your health and any criminal convictions you have. Before we gather this type of information we will explain to you why it is required and will always store this information securely.
Throughout your relationship with us, we will hold your personal information securely in our systems. This will include any information provided by you or others (for example, if you’re making a joint application) in various ways, including (but not limited to):
- in applications, emails and letters, during telephone calls and conversations in our offices, when registering for services, in customer surveys, when you participate in competitions and promotions, when using our website, and during fact find reviews and interviews.
- from analysis (including the creation of profiles used to uniquely identify you when you use our online, mobile and telephony services) which are used to help us combat fraud and other illegal activity; and
- information we receive from or through other organisations (for example, credit reference agencies, mortgage lenders, insurance companies, comparison websites, social networks, and fraud prevention agencies) whether in the course of providing products and services to you or otherwise, and from information we gather from your use of and interaction with our internet and the devices you use to access them
If there is a change to any of your personal information and you notify us, we will update your records in our systems. Where we have introduced you to another organisation, we are unable to update your details with them and you will need to contact them personally to notify them of these changes.
If someone gives information about you – or you give us details about someone else – we may add it to the personal information we already hold about you or them. This will only be used in the ways we describe in this privacy notice.
When arranging a mortgage or insurance for you, we will need to ask you for your direct debit details to pass onto the lender or insurance provider so it can collect payments. Where we charge a fee for arranging a mortgage, or the mortgage we are arranging carries a cost – for example, a valuation fee – we will need to ask you for payment information such as your debit card or credit card details.
Sometimes we may pass your information on to third parties who provide services to us. When we do this it is on the understanding that they care for your information as carefully as we do, keep it confidential and use it only for the agreed purposes above.
Using our website
If you use our website, we will collect information about the devices you’re using – or ask third parties to do this for us. As this involves using technologies such as cookies, please read our Cookies policy.
AT mortgages is the sole owner of the information collected via our website (www.atmortgages.co.uk) and also any information you provide in relation to an enquiry when you speak to or communicate with one of our advisers or staff. We may use your data together with that of other users and this may be aggregated to build statistical and analytical tables. At no time will your data be individually identifiable in such tables.
When you visit our website, we collect certain data automatically. This may include (but isn’t limited to) the following:
- how you connect to the internet (including your IP address)
- how you use our site, for example your screen resolution and browser data stored on your device (such as cookies – see our Cookies policy for more on this)
- information about the device software you use, such as your internet browser
- location data such as the city or region of the IP address you used when accessing our online services.
Please remember, that whilst we have security measures in place to protect your personal information, the internet is not 100% secure. We cannot therefore guarantee the security of any information you send us online. We are also not responsible for any loss or damage you or others may suffer as a result of losing the confidentiality of your information.
Recording phone calls
To help us train our staff to provide a quality service, check that we have done what you asked us to do correctly and resolve any queries or issues, we record and monitor our phone calls with you. We also monitor phone calls for regulatory purposes and to help detect and prevent fraud and other crimes.
HOW DO WE USE YOUR PERSONAL INFORMATION?
We use your personal information in various ways.
We will use it to confirm that you are who you say you are when you contact us. We will use it to verify your name and address by checking your details against our databases and to check against information held by credit reference agencies and the electoral roll. We will also use the personal information we gather from you to formulate our advice and recommendations for the services we offer and to submit applications to lenders and product providers.
Before we submit any transaction to a lender or product provider, the law requires us to have verified your identity. This makes it harder for criminals to use financial systems, or to use false names and addresses to steal the identities of innocent people. Checking everyone’s identity is an important way of fighting money laundering and other criminal activities. We will therefore also ask you to provide us with documents that confirm your identity.
The law requires us to comply with a number of regulations. Where necessary, we use your personal data to allow us to fulfil our legal and regulatory requirements.
We will only share personal information with others when we are legally permitted to do so. When we share data with others, we put contractual arrangements and security mechanisms in place to protect the data and to comply with our data protection, confidentiality and security standards. We use third parties to help us run our business. To fulfil our contractual obligations, we may share your personal data with these third parties:
• Mortgage lenders
• Insurance providers (e.g. Life & Critical Illness insurance)
• General insurance providers (e.g. Home insurance)
• Estate agents (if you have given your prior consent to do so)
• Lead suppliers (for the purposes of feedback only on initial details provided by them, we will never share other personal details with them which you have provided subsequently)
• Smartsearch & Proexe Ltd (for identity checking)
• Conveyancers (if you have given your prior consent to do so)
Your personal data may be transferred to these authorised parties:
Third party organisations that provide IT services and applications, administrative functions and support.
We use third parties to support us in providing our services and to help provide, run and manage our internal IT systems. For example, providers of information technology, cloud based software as a service providers, identity management, website hosting and management, data analysis, data back-up, security and storage services. The servers powering and facilitating that cloud infrastructure are located in secure data centres around the world, and personal data may be stored in any one of them.
Third party organisations that otherwise assist us in providing goods, services or information.
We use third parties acting on our behalf such as contractors, suppliers and/or agents (including, without limitation, customer care teams and processing centres) for the purposes of administration, income, credit and risk assessment, statistical research, marketing, product suitability and product sourcing in respect of products or services you have requested.
Auditors and other professional advisers.
We engage auditors and professional advisers to perform specific work that helps us meet our legal, regulatory and statutory responsibilities. Any auditors or professional advisers that we use will have contractual arrangements and security mechanisms in place to protect data and to comply with our data protection, confidentiality and security standards.
Law enforcement or other government and regulatory agencies or to other third parties as required by, and in accordance with, applicable law or regulation.
We perform anti-fraud, credit and security checks using your details and receive information about you from other sources (such as credit reference agencies) which will be added to the personal information which we already hold about you.
We may use your information for fraud investigation, detection and prevention measures and in order /’to provide suitable security for your account and your information that we hold (such as to enable us to prevent others logging in to your account without your permission from unknown devices). We may also use your information for the investigation, detection and prevention of crime (other than fraud).
If we have your consent, we will use your information to identify other products and services we offer that we believe you might want to know about. Sometimes we may contact you to take part in market research. If you take part, we’ll use any feedback you give us to improve the way we communicate with you and the service we offer. From time to time we may run prize draws, competitions, promotions and surveys. If you take part in these promotional activities, we’ll use the personal data you provide for these activities.
By knowing more about who our customers are we are able to improve the services we offer. We will use your data for reporting and analytical purposes. We will also collect data on how you use our website, so we can better understand your interests and improve its performance and our overall service.
Sometimes we may use performance tracking technology within our emails to capture information including (but not limited to) the time and date you open our emails and the type of device you used to open them. This allows us to know whether our emails are opened, and what links our customers click on within them. We use this information to improve the emails we send to you and the services we provide.
We may share any of the information we gather with other organisations (for example, mortgage lenders) to help them improve their own interactions with you. We won’t pass your data to any third parties for marketing purposes unless you have an existing relationship with them and you have given your consent for them to contact you in this way.
See our Cookies policy for more information about how we collect data about your online activity.
We use social media and are keen to understand our customers and what people are saying about us. We may use the information we gather to research public comments made on social networking sites such as Twitter and Facebook.
Resolving complaints and disputes
If we are informed that you may be dissatisfied with the service or advice we have provided you, we will use the information we have about you to help us resolve things for you.
If you do not wish to receive information from us as explained above, you can update your preferences by contacting us as below:
AT mortgages, 19A London Road, Southampton, Hampshire, SO15 2AE
Call: 02380 420701
To ensure you have the best possible experience when you contact us, we’ll use your information to ensure our team has the knowledge and expertise to meet your needs.
If we ever have to use your personal information for any purposes that we haven’t described in this policy, you’ll hear from us. We’ll let you know exactly what we’ll use it for before we go any further and, where appropriate, obtain your consent.
Please note this policy does not cover companies, services or applications that we do not own or control, or people that we do not employ or manage, including (without limitation) third party websites or applications (e.g. from “social media” platforms such as Facebook or Twitter) which we may link to or offer via our services. Also, it does not cover certain pages and services provided which are hosted, managed and operated by other parties. These services, applications and third parties may have their own privacy policies and/or terms and conditions of use, which we recommend you read before using any such services. These third parties and services are wholly independent of us and are solely responsible for all aspects of their relationship with you and any use you may make of such services.
WHAT IS THE LEGAL BASIS FOR HANDLING PERSONAL INFORMATION?
Data protection laws require that, to process your personal data, we must meet at least one prescribed basis for it. We rely on the following basis for the activities we carry out.
We rely upon this basis because you will provide us with your personal data as you want to use our services. This means that our use of your information is governed by contract terms. It is your choice to give us this information, however if you choose not to provide it, we may not be able to offer some or all of the services you require.
Under this basis we process your data in the following scenarios:
• understanding your circumstances and requirements
• assessing risks
• formulating our advice and recommendations to you
• updating, consolidating, and improving the accuracy of our records
• enabling you to access our website and use our services
• confirming your identity and verifying the information you provide
• providing and improving customer support
• sending you service communications
• responding to your enquiries and complaints
• providing you with products and services and keeping you up to date with important changes and developments to their features and how they work
• managing offers, competitions and promotions
Where we collect other information from you – or when third parties do so for us – we always ask for your consent first. For example, before you use our website you’ll be asked to consent to us using cookies to collect data about the device you’re using. If you don’t want to give consent, or you remove your consent at a later point, we may not be able to provide some or all of the services you require.
We also seek your consent in the following scenarios:
• Marketing – To help you explore all your options, from time to time we’d like to let you know about products, services and offers that may be of interest to you
• Market research – We invite you to participate in market research (more on this below). Any feedback you provide is used with your consent.
• Referral to 3rd party specialists- With your consent we will refer you to relevant 3rd party specialists who can provide you with targeted advice for areas that we do not specialize in. This can be for any relevant professional service but may include certain types of protection policies & investment/pension advice.
In the United Kingdom, organisations can use personal information where the benefits of doing so are not outweighed by the interests or fundamental rights or freedoms of individuals. The law calls this the “Legitimate Interests” basis for processing.
We rely on this basis for processing personal data for the following benefits:
• Helping to prevent and detect crime such as fraud and money laundering – Fraud and money laundering cost the British economy billions of pounds every year. This cost ultimately reaches the public in the form of higher prices. We can help stop this from happening by using your personal data to avoid fraud and identity theft.
• Complying with legal and regulatory requirements – We must comply with various legal and regulatory requirements. We are regulated by the Financial Conduct Authority and sometimes we may be required to provide information to it as part of our regulatory responsibilities.
• Ongoing service – When the product or service that we have recommended to you expires or is due for renewal, we will contact you beforehand to notify you of this so we can start to explore the current options available to you.
• Training our staff – To offer you the best possible standards of service, we use the information we collect to train our staff so they can assist you better.
• Marketing services – Like any commercial organisation, we run a business and – where necessary process information that helps us do this. We have various safeguards in place to make sure that the individuals whose personal information we handle are not disadvantaged by the way we use their personal data. These include making sure people can access the information they need to understand how their personal data will be used by us. We also try to make sure people are aware of the rights they have to obtain the information we hold and to have their information corrected or restricted – and how to complain if they’re unhappy.
• Reporting and analytical purposes – We process this personal information to help us analyse the service we are providing and identify ways to improve.
• Tracking activity – We like to know how people use our website or get in touch with us so we can identify ways to improve our services.
• Maintaining our records and other administrative purposes – We always strive to provide the most accurate information to our customers and clients.
• Resolving complaints and disputes – If you have a reason to make a complaint, we will use your information to look into things for you.
• Improving data accuracy and completeness – When you register for our services you may give us additional information about yourself. We’ll use this to improve the accuracy and completeness of our data.
• Email tracking – This helps us to improve our communications to our customers.
• Invitations to take part in market research – To make the service we offer even better, we may ask you to participate in market research. It’s entirely up to you whether you chose to do so.
HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION FOR?
We’ll keep your personal information securely stored for as long as we need it to provide you with the services you want from us. We also keep it to comply with our legal and regulatory obligations, as also to help us to resolve any issues or disputes that may arise.
Depending on what information we hold and what products or services you are signed up to, we may need to retain certain details for longer than others. In every case, we regularly reassess whether we need to hold your personal information and securely dispose of any information that we no longer need.