PRIVACY POLICY
Last Updated: [INSERT DATE]
1. Introduction
[INSERT COMPANY NAME] (“we”, “us”, “our”) is committed to protecting and respecting your personal data.
This Privacy Policy explains how we collect, use, store and protect your personal data in accordance with:
The UK General Data Protection Regulation (“UK GDPR”)
The Data Protection Act 2018
The Privacy and Electronic Communications Regulations (“PECR”)
[INSERT COMPANY NAME] is registered in England and Wales (Company No. [INSERT COMPANY NUMBER]) with its registered office at:
[INSERT REGISTERED OFFICE ADDRESS]
For the purposes of UK GDPR, [INSERT COMPANY NAME] is the Data Controller.
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact:
Email: [INSERT PRIVACY EMAIL ADDRESS]
Telephone: [INSERT TELEPHONE NUMBER]
Address: [INSERT CONTACT ADDRESS IF DIFFERENT]
2. Personal Data We Collect
We may collect personal data directly from you, from third parties involved in property transactions, and from publicly available sources where necessary.
Identity Data
Full name
Date of birth
Nationality
Marital status (where relevant to a transaction)
Contact Data
Residential address
Email address
Telephone numbers
Financial & Transaction Data
Bank account details (for rent payments, deposits or refunds)
Income and expenditure information
Mortgage details
Sale and purchase information
Tenancy records
Compliance Data (AML & Legal Requirements)
To comply with legal obligations, including Anti-Money Laundering regulations, we may collect:
Photographic identification
Proof of address
Source of funds documentation
Sanctions and PEP screening results
Right to Rent documentation
Right to Let documentation
Property Data
Property addresses
Photographs and marketing materials
Floor plans
EPC ratings
Inventories
Survey reports
Technical Data
IP address
Device and browser information
Website usage data
Cookie identifiers
Communications Data
Email correspondence
Telephone call recordings
Enquiry records
CCTV Data
CCTV footage captured at our premises for security purposes
3. How We Use Your Personal Data (Lawful Basis)
We only process your personal data where we have a lawful basis to do so.
Contractual Necessity
To:
Arrange property viewings
Market properties
Negotiate and manage sales
Negotiate and manage tenancies
Manage rental payments
Administer tenancy deposits
Legal Obligation
To comply with:
Anti-Money Laundering legislation
Right to Rent requirements
HMRC obligations
Court or regulatory requirements
Accounting regulations
Legitimate Interests
For our legitimate business interests, including:
Fraud prevention
Risk management
Staff training and quality monitoring
CCTV security
Business analytics
Client relationship management
You may request further information about our legitimate interests assessments.
Consent
We rely on consent where required, including:
Marketing communications
Non-essential cookies
Certain third-party referrals
You may withdraw consent at any time.
4. Automated Decision-Making
We may use automated systems for tenant referencing or Anti-Money Laundering screening.
Where automated decision-making significantly affects you, you have the right to request human review and to challenge the decision.
5. Sharing Your Personal Data
We may share your personal data with:
Tenant referencing providers
Mortgage brokers and financial advisers
Conveyancers and solicitors
Surveyors and valuers
Energy assessors
Deposit protection schemes
Contractors and maintenance providers
Utility companies
IT and CRM providers
Marketing service providers
Accountants and auditors
Regulatory authorities and law enforcement
We require all third parties to process personal data lawfully and securely.
6. International Transfers
If personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place, such as:
UK International Data Transfer Agreements (IDTA)
UK adequacy regulations
Approved Standard Contractual Clauses
7. Data Retention
We retain personal data only for as long as necessary and in line with legal requirements.
Typical retention periods:
Sales and tenancy files: 6 years after completion or termination
AML records: 5 years (as required by law)
Financial records: 6 years
Call recordings: up to 12 months
CCTV footage: typically 30 days unless required for investigation
Marketing data: until consent is withdrawn or you opt out
We may retain data for longer where required for legal claims.
8. Your Rights
Under UK GDPR, you have the right to:
Access your personal data
Rectify inaccurate data
Request erasure (subject to legal obligations)
Restrict processing
Object to processing
Data portability (where applicable)
Not be subject to solely automated decision-making
To exercise your rights, contact:
[INSERT PRIVACY EMAIL ADDRESS]
We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues:
Website: www.ico.org.uk
Telephone: 0303 123 1113
9. Marketing Communications
We may send marketing communications based on:
Your consent; or
Our legitimate interests where permitted by law.
You may opt out at any time via the unsubscribe link in communications or by contacting us.
10. Cookies
Our website uses cookies in accordance with PECR.
We use:
Strictly necessary cookies
Analytics cookies
Marketing cookies (subject to consent)
You can manage cookie preferences via our website banner.
11. Security Measures
We implement appropriate technical and organisational measures including:
Secure cloud-based systems
Role-based access controls
Encryption
Staff training
Confidentiality agreements
While we take appropriate safeguards, no internet transmission can be guaranteed completely secure.
12. CCTV & Call Recording
CCTV operates at our premises for security and crime prevention.
Telephone calls may be recorded for:
Training
Compliance
Dispute resolution
Fraud prevention
13. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website.