Privacy statement
London & Country Mortgages (L&C) is the UK’s leading fee free mortgage broker.
L&C takes your privacy seriously and takes every reasonable precaution to safeguard the personal information you supply to it.
Privacy notice
London & Country Mortgages Limited (L&C) is the UK's leading fee free mortgage broker. This privacy notice tells you about how we use your personal information and your information rights.
We are committed to keeping your information safe and secure and ensuring that we are transparent and fair about how we use it.
1. About London and Country (L&C) and how you can contact us
This section tells you about us and how you can contact us.
London & Country Mortgages Limited (L&C) is a Company limited by shares. Our registered address is Unit 26 (2.06), Newark Works, 2 Foundry Lane, Bath, BA2 3GZ. You can find out more about us on our website at https://www.landc.co.uk/
To help ensure we meet all our obligations we have appointed a Data Protection Officer. If you have any questions or concerns about how your personal information is being used you can contact the DPO
on: 01225 408000
or: by email to TheDPO@landc.co.uk
or by writing to:
The Data Protection Officer
London & Country Mortgages Ltd
Unit 26 (2.06) Newark Works
2 Foundry Ln
Bath
BA2 3GZ
You can also obtain information and advice from the Information Commissioner who is the independent regulator appointed by Parliament to oversee compliance with data protection and information rights: https://ico.org.uk
L&C is registered with the Information Commissioner (registration number Z6282085).
2. What information we collect and how we use it
This section summarises what information we collect from you when you contact us, what information we collect from elsewhere, and how this information is used.
Information we collect directly
Mortgage Customers
Our core business is acting as a mortgage broker. This involves searching against the lenders we deal with to find the mortgage that best suits your circumstances. We do this when you contact us by asking you about your identity and contact details; your product preferences; your property and tenancy history and types and number of occupants and their relationship to you; your lifestyle; nationality and residence status; employment, income and expenditure and other financial circumstances. How you answer these questions will determine what other questions we ask you because different lenders serve different parts of the market and have different eligibility criteria. We will always explain the process to you and answer any questions you may have about why certain types of information may be needed.
When you apply for a mortgage through us we will collect your direct debit details to pass on to your lender. If the products you select involve a cost, such as a valuation fee, we will ask for your payment information.
Mortgage lenders are data controllers in their own right and have their own privacy notices. However, because lenders may automatically profile your information against their lending criteria and against Credit Reference Agencies as soon as your information is forwarded to them and this may affect your credit score, we will always bring this to your attention as part of the process so that you are forewarned. We will also make you aware in advance when lenders are likely to debit any funds from your accounts.
Insurance Customers
We routinely offer our mortgage customers life insurance and building and contents insurance. Where customers express an interest in life insurance we will also collect information about health as this is necessary so that the insurers we deal with can determine cover and premiums.
Apart from the information customers provide to us directly we may also record information about potential vulnerabilities where we think this is appropriate to meet the obligations placed on us by the Financial Conduct Authority (FCA) with regard to vulnerable customers. You can find out more about our obligations to potentially vulnerable customers here:
https://www.fca.org.uk/publications/occasional-papers/occasional-paper-no-8-consumer-vulnerability
Updating Your Details
If you are a pre-existing customer we may use the information we have on you to pre-fill forms when you apply for a new product, but we will always check that these details are accurate and up to date.
We are working with partner services such as Experian to enable us to pre-populate our on-line data collection forms with information about you that is available from accessible sources. This means there is less information for you to type in. But you have control and can change any answer.
However, if you've opened an account or policy with another organisation that we introduced you to, you will need to contact them separately to update your information.
Telephone calls
We may record incoming and outgoing calls so that we can be sure that we have captured the information you have given us accurately. This helps us to prevent fraud and resolve any disputes.
Profiling, Marketing and Market Research
We may use your information to contact you about other products that match your profile and may be of interest you. Where we seek consent to do this we make sure we are clear about what methods we can use to contact you. We make sure that you are able to opt out of marketing communications at any time in a way that is convenient to you, including the method you used to contact us.
Quite separately, if you have taken out either a mortgage or an insurance product through us we will contact you when your product is coming to an end to ensure that you are protected and can access the best rates on a new deal. If you do not want us to do this you can ask us at any time to mark your records 'do not contact'.
To help us target audiences more accurately online we share information with organisations such as Experian, who provide third party data services, and publishers such as Facebook. Data service providers can help us in a number of ways; through data matching, that provides additional data about users, and through segmentation and profiling. Segmentation is the process of aggregating normally anonymised information to create a series of 'types' which are then matched against a population which exhibit similar characteristics. Where that data matches to records held by the publisher it can be used to serve tailored online advertisements or similarly to 'suppress' or exclude that audience. Where we do so we make sure that those third party organisations cannot use our customers personal data to enrich their data. Any online advertising platforms we use will enable you to control direct marketing via their privacy settings. We also profile the information we collect from clients to help us improve the customer journey.
We may contact you to conduct market research. We occasionally run promotions, competitions and prize draws but if we ask you for your contact details we will ensure these are not used for marketing unless you are happy to consent to that separately.
Money Laundering and preventing and detecting unlawful acts
We are required by law to submit a Suspicious Activity Report to the National Crime Agency whenever we detect a risk of money laundering or fraudulent activity. The law also permits us to report suspected crime to the appropriate authorities.
We are also required to disclose personal data where required to do so by law or by the order of a court.
We have discretion to disclose personal data where this is necessary for protecting the public against dishonesty.
Cookies on our website, tracking emails, re-marketing and analytics
We use services such as Google Analytics to track how visitors use our website, to understand trends and how the business works and so that we can improve the user experience. But the reports we produce do not identify individuals.
The Cookies Section of this Privacy Notice explains what cookies we use and how you can turn off and control any advertising cookies (subject to your browser functionality).
We use email tracking technology to capture information such as (but not limited to) the time and date our emails are opened, the type of device used and any links within the email clicked on. We may share this information with the organisations listed in Section 5 (for example, mortgage lenders) for the same purposes, but stipulate that they may not use your details for direct marketing unless they have your consent or an existing relationship with you and you have not previously opted out.
We also use telephone tracking technology to capture information such as (but not limited to) the time and date a call is made, the type of device used and the source and page on our website that a customer called from.
Social Media
As a business we monitor what the public are saying about us on social media such as Facebook and Twitter, so that we can build these comments into improving our products and the ways we interact with customers.
Training and Testing
We do not use customer data for generalised training or system testing separate from case management, and always use dummy data sets for these purposes.
Information that we collect indirectly
When any of our customers apply for a product, the law requires us to check their identity. This makes it harder for criminals to use financial systems, or to use false names and addresses to steal the identities of innocent people. Checking everyone's identity is an important way of fighting money laundering and other criminal activities.
To confirm that you are who you say you are, we'll try to verify your name and address by checking your details against databases held by credit reference agencies and the electoral roll. If we can't verify your name and address in this way, we may ask you to provide us with other documents to confirm these details. This does not affect you credit history or status.
If you are a joint mortgage applicant we will record any information you give us about any other persons who are joined to the application.
If you are referred to us by an Estate Agent our data collection form includes a free form data field that some Estate Agents use to add comments about potential purchases.
Ancillary
We use the information we have about you to provide all the aspects of our service you would expect such as contacting you to prompt you with reminders about renewals and to help resolve any complaints or investigations.
We may also disclose information where permitted by law in connection with the resolution and pursuit of legal rights and disputes.
Automated Decision Making
We do not make fully automated decisions. Our service is to provide the information to lenders and insurers so they can make a decision about the product you have selected.
Reviews
If you give us a good review we may contact you to ask you if you would like us to publicise your review.
3. What are the legal grounds for handling personal information?
To be lawful we must satisfy at least one of six standard conditions to process your personal information and additionally a stricter condition where we process what is called special category data, such as information about health.
The law says we must have a legal basis for processing personal data. There are six standard data processing grounds or conditions for processing personal data. Where we process what is called 'special category data' (information about health, genetic or biometric data etc) we must additionally have a special category condition or ground for processing your personal data.
We rely on the following conditions for the activities indicated.
Legitimate Interests
In most cases, you'll provide the information covered in section 2 because you want to use our services. Ordinarily for a business this would mean that the condition for processing is contractual However, this condition only applies where a legal contract exists between the parties concerned. Because we act as an intermediary this condition is not available. We therefore rely on what is called the 'legitimate interests' ground for processing. The law provides we can use your information under this condition where our interest in using it is not outweighed by your privacy rights or interests. This means that we can use your personal data only in ways you would reasonably expect and which have a minimal impact on your privacy, or where there is a compelling justification for the processing.
We rely on this condition for the uses we identify in section 2, except where we indicate below that another condition is more relevant.
Consent
In order to use your personal data on this basis your consent must be freely given, specific, informed and unambiguous. We rely on this condition for the following purposes:
- Where we need information to provide you with additional services or features
- Direct Marketing – To let you know about products, services and offers from L&C. (We also market to customers who have enquired to use our services under the legitimate interests condition) or
- Market research – Where we invite you to participate in market research. Any feedback you provide is used only with your consent
- Administering prize draws, competitions, surveys and other promotional activities
Explicit Consent
We need what is called explicit consent where we rely on consent to process what is called sensitive or special category personal data:
- Health data in connection with life policies
- Incidental data supplied by applicants as proof of income that may reveal special category data such as trade union membership
Complying with a legal obligation
- Money Laundering reports
Public Interests Tasks
- Processing health data in connection with vulnerable customers
- Reporting fraud and other suspected crimes to the appropriate authorities
- Suspicion of terrorist financing or money laundering
- Protecting the public against dishonesty
- Insurance and data concerning the health of relatives of an insured person
Substantial Public Interest
- Processing health data in connection with vulnerable customers
- Reporting fraud and other suspected crimes to the appropriate authorities.
- Suspicion of terrorist financing or money laundering
- Protecting the public against dishonesty
- Insurance and data concerning the health of relatives of an insured person
Contract
- Processing personal data in connection with contracts that we hold with contractors, suppliers and staff.*
*We have a separate Privacy Notice for processing employee's personal data
4. Who we share your personal information with
Find out who we need to share information with to deliver our services to you and when you have a choice about who we share your information with.
To fulfil our contractual obligations, we'll also share your personal data with the following third parties (privacy policy links provided where not provided at a later stage):
- Mortgage Lenders
- Life Insurers
- Legal and General for building and contents insurance (https://www.legalandgeneral.com/privacy-policy/)
- Estate agents (if you were introduced to us by one of our estate agent partners)
- ULS who provide online platforms to support our relationship with Barratts
- Lead suppliers (if you were introduced to us by a third party)
- Rhino Home Protect to provide you with buyer protection insurance (where applicable) (https://www.rhinohomeprotect.com/privacy-policy/)
- TransUnion International for identity checking (https://www.transunion.co.uk/legal/privacy-centre)
- Our personally recommended conveyancers where you wish to proceed with a quote.
- Experian for profiling and segmentation (https://www.experian.co.uk/privacy)
- Calltracks Ltd for tracking telephone calls (https://www.calltracks.com/privacy-notice/)
- Huggg Limited to fulfil our contractual obligations to lead providers (https://www.huggg.me/privacy-policy’)
To help you benefit from the services of our expert partners, we'll also share your personal data with the following organisations – but only with your consent (privacy policy links provided):
- Money Corp for foreign currency enquiries (https://www.moneycorp.com/en-gb/legal/privacy-policy/)
- Propp for commercial, 2nd charge and bridging finance enquiries (https://propp.io/about/privacy-policy)
- Howden Life and Health for protection needs (https://www.howdenlifeandhealth.co.uk/common-page/privacy-policy/)
- Reassured for protection needs (https://www.reassured.co.uk/privacy-policy/)
- Optimus Surveys for building surveys (https://www.optimus-move.co.uk/our-privacy-policy/)
- Key Retirement Solutions if you are looking at equity release products (https://www.keyadvice.co.uk/privacy-policy)
- Chartwell Financial for commercial, and credit impaired mortgage enquiries (https://www.chartwellfs.com/privacy-policy/)
- Brilliant Solutions for credit impaired mortgage enquiries and also advice if you are living abroad (https://brilliantsolutions.co.uk/)
- Mortgage Broker Tools to check lenders’ affordability calculators (https://w3.mortgagebrokertools.co.uk/privacy-policy)
- Uinsure for building and contents insurance (https://uinsure.co.uk/customer-privacy-notice/)
- Buildstore for self build or development mortgage finance (https://www.buildstore.co.uk/privacy-policy)
If you no longer wish us to share your data with any of these organisations, you may withdraw your consent at any time.
Both the above sets of organisation are each data controllers in their own right and will have their own Privacy Notices that will tell you about how your personal data will be used by them.
We'll also share your personal data with the following data processors where necessary to fulfil our services and regulatory obligations (privacy policy links provided):
- BUYAPOWA to run our referral incentive scheme (https://www.buyapowa.com/platform-privacy-policy/)
- IRESS to provide life insurance quotations and process mortgage applications (https://www.iress.com/resources/legal/privacy-policy/)
- MBL to provide mortgage illustrations (https://www.mortgage-brain.co.uk/privacy-policy.aspx)
- Springfield Confidential Shredding to destroy our confidential waste (https://www.springfieldpapers.com/privacy-data-policy)
- Red Box who provide our call recording software (https://www.redboxvoice.com/privacy-policy)
- Survey Monkey to conduct market research (https://www.surveymonkey.co.uk/mp/legal/privacy/)
- Underwrite me for life insurance (https://www.underwriteme.co.uk/protection-platform-privacy-policy/)
- CI Expert for Critical Illness cover (https://ciexpert.uk/legal/privacypolicy/)
- reviews.co.uk for customer reviews (https://www.reviews.co.uk/front/user-privacy-policy)
- Trust Pilot for customer reviews (https://uk.legal.trustpilot.com/for-reviewers/end-user-privacy-terms)
- Landmark Analytics for valuation and property services (https://www.landmark.co.uk/privacy-policy)
- Clearswift for secure email encryption portal (https://www.helpsystems.com/privacy-policy)
- Online Advertising Platforms such as Facebook, Bing and Google and data services providers such as Experian (please see the part in Section 2 on Marketing and Market Research). (https://www.facebook.com/privacy/explanation, https://privacy.microsoft.com/en-us/privacystatement, https://policies.google.com/privacy?hl=en-GB&fg=1)
- Salesforce.com, our CRM provider (https://www.salesforce.com/company/privacy/full_privacy/)
- OwnBackup for data backup and restore services (https://www.ownbackup.com/privacy-policy)
- OneTrust for the purpose of managing your cookie consent/preferences (https://www.onetrust.com/privacy/)
- HALO to provide Service Desk tickets support to our colleagues (https://haloitsm.com/privacy-policy/)
Sharing information with these organisations allows us to better understand your needs.
5. Where in the world do we send information?
As a UK Company nearly all of our processing of personal information takes place in Europe which has strong data protection standards. Find out how your information is protected on the limited occasions it is transferred outside Europe.
As a UK based company, all the personal information we process is protected by European data protection standards.
The only personal data that is transferred outside the EEA is that processed through Survey Monkey Europe UC and Liveperson.com who have agreed standard contractual terms to protect transfers to Survey Monkey Inc and Liveperson Inc respectively, which are located in the United States and both participate in and have certified their compliance with the EU-US Privacy Shield.
6. Your information rights
This Section summarises the legal rights you have to protect your personal information and how you can exercise them and find impartial advice and further information.
The following is a list of the rights you have under Data Protection legislation. Not all these rights apply in all circumstances but we will be happy to explain this to you at the time you ask. Independent advice about your rights can be obtained from the Information Commissioner (see Section 1.)
All these rights can usually be exercised free of charge and generally speaking we must respond within one month. If we need longer to respond we will explain why this is necessary within the one month period and tell you more about any rules that affect how you can exercise your rights.
INFORMED
You have the right to be informed in a concise, transparent, intelligible and easily accessible way about how we use your personal information. We will explain why we need information (in particular any uses that are not obvious) at the time we collect information from you and make sure that all our data collection forms and letters point you to this Privacy Notice.
ACCESS
You can make what is called a subject access request for a copy of the information we hold about you.
We must also tell you why we have the information, what types of information we collect; who we share it with and whether, in particular, any of those recipients are outside the European Economic Area; how long we will keep your information for; where the information came from, if we didn't collect it from you directly; the details of any automated decision making and about your rights of complaint to the Information Commissioner.
PORTABILITY
You have the right in some circumstances to have the data you have provided to us sent to you or provided to another person or business in an electronic machine readable format. Where this applies we will download the information and send it as a CSV file.
CORRECTION
You have the right to have inaccurate information corrected and incomplete information completed. If the information we need to deliver our services to you changes please tell us about this as soon as possible.
OBJECT
You will normally have the right to object to how we intend to use your information based on your individual circumstances.
You have an absolute right to object to us using your personal information for the purpose of direct marketing at any time.
RESTRICTION
If you have objected or complained about how we have used your information or its accuracy you may not want it to be deleted until your complaint has been resolved. In certain circumstances you can ask for your data to be restricted or not used until these issues are resolved.
ERASURE
You have a right to have some or all of the information we hold about you erased in some circumstances. This is known as the right to be forgotten.
AUTOMATED DECISION MAKING
This right only applies where a decision which has a legal or similar effect is taken about a person by automated means without any human intervention.
Where such decisions are made individuals have a right to ask for the decision to be reviewed and the data controller must make sure appropriate safeguards are in place. However, L&C does not make automated decisions about any of its clients.
CONSENT
If we are processing your personal information on the basis of your consent you have the right to withdraw that consent at any time.
COMPLAINT
You have a right of complaint to the Information Commissioner (the Supervisory Authority) if you consider any aspect of L&Cs use of your personal information infringes the law. Section 1 provides the contact details.
However, L&C will want to put matters right wherever we can and we would hope that you will contact us in the first instance. You can exercise your data protection rights or complain about how we are processing your personal information by contacting the Data Protection Officer as set out in Section 1.
If your complaint is about the administration, or terms and conditions of a product sold by us but provided by a lender/insurer, you may need to contact them about it. If needed, we'll forward details of your complaint to the lender/insurer concerned, as well as giving you their contact details.
7. How we keep your personal information secure
We're committed to keeping your personal information safe and sound. In this section, you'll read about the security measures we take to protect our customers' data.
At L&C, we understand how important it is to keep your personal information secure. We use a variety of technologies and procedures to protect your personal information from accidental or unlawful breaches of security. These include physical, organisational, and technological measures.
All information we process is encrypted in transit so that your personal and financial information is secure. For example, where you share information with us online or we forward this to other organisations online we use HTTPS. Where you create an online account with us you will need to supply a username and password. To protect your account we will encourage you to use a strong password and have implemented two factor authentications.
As covered in section 4, we have to share your information with third parties to carry out some of our services, including lenders and insurers amongst others. We require every third party that we share information with to apply appropriate security safeguards and comply with all the required laws and standards for protecting personal information.
8. How long do we keep your personal information for
We only keep your personal information for as long as we need to. This section explains how long the different types of records will be kept.
To ensure that we are able to meet our legal, regulatory and customer obligations, L&C will retain client information for the following time periods:
- If you become a client of a lender/insurer as a result of the advice we provide to you, we will retain a full record of your interactions with us to enable us to meet our regulatory obligations to evidence we gave suitable advice and to enable us to answer any complaints that may arise as a result of our advice. In practice this means that we will keep your records for the term of the product applied for plus an extra 6 years.
- If, as a result of our advice, you make an application to a lender/insurer but do not ultimately become a client of that institution, we will keep a full record of your interactions with us for 6-years to meet our obligations under UK Money Laundering regulations.
- If we provide you with advice on a financial product, but you do not engage our services to make an application to a lender/insurer, we will keep a full record of your interactions with us for 3-years, to enable us to meet our regulatory record keeping obligations regarding evidencing the suitability of our advice.
- If we collect personal information from you, but are unable to provide you with suitable advice, then we will keep a full record of your interactions with us for 1-year to facilitate an easier interaction between us if you re-engage our services within this period.
- If you request we contact you in relation to our service by providing us with your name and a contact method (e.g. phone, email) through an enquiry form (either on our own, or through a 3rd party website) we will use our best endeavours to contact you as soon as possible. If we are unable to make contact with you, we will retain this information for a period of 180-days from the time we de-activate your lead in our database, to ensure we can fulfil our contractual obligations to our lead partners.
- Where our retention schedules indicate a record is otherwise no longer required but you are subscribed to marketing, we delete the record of events and attachments associated with the case but maintain the case record itself so that we know what messages are relevant to you.
We anonymise data against these retention periods on a programmed basis. A back-up copy of the data is retained for a set period to enable the anonymisation process to be validated.
9. Use of cookies
10. Changes to this privacy notice
You can check this Privacy Notice to find out about any changes to how we process your personal information.
We will continuously refine this Privacy Notice to make sure we are complying with our obligations to be transparent about how we use your personal information and that it is as concise, transparent, intelligible and as accessible as it can be. However, if we make any changes to how we process your personal information in ways that you would not reasonably expect, we will contact you and bring these changes to your attention.