0161 791 4601
Introduction
The Company needs to gather and use certain information about individuals.
This can include customers, suppliers, business contacts, employees and other people the organisation has a relationship with or may need to contact.
This policy describes how this personal data must be collected, handled and stored to meet the company’s data protection standards — and to comply with the law.
Why this policy exists
This data protection policy ensures the company;
Data protection law
The General Data Protection Regulations (GDPR) describe how organisations— must collect, handle and store personal information. These rules apply regardless of whether data is stored electronically or otherwise.
To comply with the law, personal information must be;
Record Keeping
A range of information must be detailed in our internal records of processing activities. Such areas include;
The company ensures that records of these activities are kept and are updated accordingly. Individuals’ data is kept on file for 6 years in line with the Financial Conduct Authorities record keeping rules. After which point, personal data is retracted to the point it is unidentifiable and used for statistical purposes only.
Lawful Basis for Processing Data
Under GDPR, it is a requirement that the company has a valid lawful basis to process personal data, this should be documented. Most lawful bases require that processing is ‘necessary’.
The lawful bases for processing are set out in Article 6 of the GDPR. At least one of these must apply whenever the company process personal data:
Processing is lawful under GDPR as:
(a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose.
(b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.
(c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations).
(d) Vital interests: the processing is necessary to protect someone’s life.
(e) Public task: the processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.
(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.
The company has chosen this basis for processing data as it is requested from the individuals that we capture data before entering into a contract (e.g. provide a quote for finance).
Special categories of data may be captured by the company for example, information about an individual’s:
You need to identify both a lawful basis for general processing and an additional condition for processing this type of data.
If you are processing criminal conviction data or data about offences, you need to identify both a lawful basis for general processing and an additional condition for processing this type of data.
Responsibilities
The company acts as a data Controller and data Processor. All staff are responsible for ensuring that the highest data standards and best practices are met on a continual basis.
Although a Data Protection Officer (DPO) has not been appointed as the company does not fall within the scope, the Directors and Owners of the Business are accountable and responsible for compliance with GDPR and will take on the tasks appointed to them as if they were a DPO.
Data Protection Impact Assessments (DPIA)
The company has a general obligation to implement technical and organisational measures to demonstrate that data protection is integrated into our processing activities. A Data Protection Impact Assessment is conducted each time the company consider implementing using new technologies.
The DPIA will pertain at least;
Individuals Rights
Individuals now have more rights under GDPR, the company, these are;
The company provides every customer with a Privacy Notice at the point data is captured.
The information supplied in this notice demonstrates how the company is transparent over our data processing. The notice is;
We include details of (but not limited to);
the Data Controller, the lawful reason for processing data, if any third parties have legitimate interests, categories of personal data, categories of recipients such as banks and credit unions, the data retention periods,
the individuals’ rights; including the right to withdraw, where the individual can complain about how the data is processed with a supervisory authority, source of data when it comes from a third party and where personal data is part of a contractual requirement or obligation.
Rectification
Individuals are entitled to have personal data rectified if it is inaccurate or incomplete. If the company has disclosed the personal data in question to third parties, then we will inform them of the rectification where possible.
The company will respond to this request within one month or extended by two months where the request for rectification is complex.
Erasure
Individuals have a right to have personal data erased and to prevent processing in specific circumstances;
The company may refuse to comply with a request for erasure where the personal data is processed for the following reasons;
If the company has disclosed the personal data in question to third parties, a notification will be sent, informing them about the erasure of the personal data, unless it is impossible or involves disproportionate effort to do so.
Restrict processing
The company will restrict the processing of personal data in the following circumstances;
if any data has been disclosed to third parties, the company will notify them about the restriction on the processing of the personal data, unless it is impossible or involves disproportionate effort to do so.
Portability
For personal data an individual has provided to a controller; where the processing is based on the individual’s consent or for the performance of a contract; and when processing is carried out by automated means, the company must provide the personal data in a structured, commonly used and machine-readable form. Open formats include CSV files. Machine readable means that the information is structured so that software can extract specific elements of the data. This enables other organisations to use the data.
The company must provide this service free of charge.
If the individual requests it, we may be required to transmit the data directly to another organisation if this is technically feasible. The company will respond without undue delay, and within one month or extended by two months where the request is complex or receive many requests.
Objecting
If an individual has objected to processing data or direct marketing, the company will cease to process the data.
Individuals must have an objection on “grounds relating to his or her particular situation”.
The company will stop processing the personal data unless;
This is brought to the attention of the data subject at the first point of communication and in our privacy notice. This is separated out from any other information.
Direct marketing purposes
As soon as an objection is received, the company will stop processing personal data for direct marketing purposes. This will be actioned at any stage and is free of charge.
Automated decision making including profiling
The company understand that any form of automated processing of personal data intended to evaluate certain personal aspects relating to a natural person, or to analyse, or predict that person’s performance at work, economic situation, location, health, personal preferences, reliability, or behaviour falls under this right. Where this is conducted, the rules and guidance of the ICO will be adhered to and followed. To date, The company does not conduct automated decision making including profiling.
Subject Access Requests (SAR)
Individuals who are the subject of personal data held by the company are entitled to;
Individuals contacting the company requesting this information, this is called a Subject Access Request.
The company will provide a copy of the information free of charge. However, a ‘reasonable fee’ may be charged when a request is manifestly unfounded or excessive, particularly if it is repetitive.
A reasonable fee may also be charged to comply with requests for further copies of the same information. The fee is based on the administrative cost of providing the information only.
Once the identity of the person making the request has been verified, the information will be provided within 1 month, this will be extended to 2 months if the request is complex. Notification will be made to the individual if this is the case.
Complaints
It is made clear that data subjects who wish to complain about how their personal data has been processed can raise this with the company complaints procedure. If the data subject is still not happy, then the complaint can be referred to the Information Commissioners Office.
Data Security and Storage
When data is stored on paper, it should be kept in a secure place where unauthorised people cannot see or have access to it. These guidelines also apply to data that is usually stored electronically but has been printed out for some reason;
When data is stored electronically, it must be protected from unauthorised access, accidental deletion and malicious hacking attempts;
The point that personal data is accessed is when it can be at greatest risk of loss, corruption, theft, unlawful access, the company will;
when working with personal data, employees should ensure the screens of their computers are always locked when left unattended;
Finspire Finance Limited act as a commercial finance broker of non-regulated finance for our customers.
Finspire Finance Limited is an Authorised Representative (AR) of White Rose Finance Group Ltd who are Authorised and Regulated by the Financial Conduct Authority Firm Reference Number 630772. Finspire Finance Limited is authorised under the Firm Reference Number 931020.
How we will use the information about you
Here at Finspire Finance Limited we take your privacy seriously and will use your personal information in several ways which will
help us;
1. make lender decisions,
2. for fraud prevention,
3. for audit,
4. for statistical analysis,
5. credit reference checks
We may share your information with, and obtain information about you from, credit reference agencies or fraud prevention agencies.
We will not disclose your information to any company outside of White Rose Finance Group Ltd except to help prevent fraud or if required by law to do so.
For further information on how your information is used, how we maintain the security of your information and your rights to access/alter and change the information we hold on you, please contact Curtis@FinspireFinance.co.uk
Additional marketing
However, from time to time we would like to contact you with detail of other products and services we provide.
Please make us aware if you do not wish to be contacted.
What we need
Finspire Finance Limited will be what is known as the ‘controller’ and the ‘processor’ of the personal data you provide to us. We collect personal data about you which may also include any special types of information or location-based information.
Your Personal Data May Include
Title, names, date of birth, gender, nationality, civil/marital status, contact details, addresses and documents that are necessary to verify your identity.
Employment and remuneration information, (including salary/bonus schemes/overtime/sick pay/other benefits), employment history.
Bank account details, tax information, loans and credit commitments, personal credit history, sources of income and expenditure, family circumstances and details of dependents.
Any pre-existing financial products and the terms and conditions relating to these.
Why we need it
We need to know your basic personal data to provide you with an accurate recommendation for your personal circumstances.
We will not collect any personal data from you we do not need to provide and oversee this service to you.
For the processing of data to be lawful under GDPR Finspire Finance Limited use;
(a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose.
(b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take
specific steps before entering into a contract.
(c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations).
(d) Vital interests: the processing is necessary to protect someone’s life.
(e) Public task: the processing is necessary for you to perform a task in the public interest or for your official functions, and the
task or function has a clear basis in law.
(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless
there is a good reason to protect the individual’s personal data which overrides those legitimate interests.
What we do with it
Automated Decision Making: Finspire Finance Limited will pass your data captured to lenders who may use automated decision making in respect of your application for finance. We will only collect the minimum amount of data needed and have a clear retention policy for the profiles we create.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or any significant effects. You can request human intervention and challenge a decision made this way by contacting Curtis@FinspireFinance.co.uk
All the personal data we use is controlled by Finspire Finance Limited in the UK, however, for the purposes of IT hosting and maintenance, this information is located on servers within the European Union. No 3rd parties have access to your personal data unless the law allows them to do so. We have a Data Protection regime in place to oversee the effective and secure processing of your personal data. More information on this framework can be obtained on request by writing to The Training and Compliance manager.
We may pass your data to other third parties to provide you with offers of products suitable to meet your customer requirements. Your data is stored electronically on our cloud encrypted server. Our server is based in the UK.
How long we keep it
We are required under regulation to keep your basic personal data, such as name, address, and contact details for a minimum of 6 years, after which time it will be destroyed unless for purposes outlined in our GDPR policy. The information used for marketing will be kept with us until you notify us that you no longer wish to receive this information.
What are your rights?
If at any point you believe retained information is incorrect you can request to see this information and even have it corrected and possibly deleted. Providing you with this information is free of charge, but charges may apply for excessive requests.
If you wish to raise a complaint on how we have handled your personal data, you can contact our Data Protection Officer who will investigate the matter.
Where relevant, you have the right to withdraw consent and object at any time and this means that we cannot process your data provided without your consent.
More information about your rights can be found on the Information Commissioners website. https://ico.org.uk/
If you are not satisfied with our response or believe we are processing your personal data not in accordance with the law you can complain to the Information Commissioner’s Office (ICO).
Our Data Protection officer is Curtis and you can contact them at Curtis@FinspireFinance.co.uk
Consent
We will share your details with companies who will process your information, in turn allowing Finspire Finance Limited to offer suitable products that lenders may provide.
Before we can proceed, we need your consent to do this. You can withdraw your consent at any time. Please be aware though, that if you do this, we will not be able to proceed any further with your application, and depending on the stage reached we may not be able to remove all your data due to our responsibilities laid out by the Financial Conduct Authority.
It is assumed you accept these terms unless explicitly told otherwise.
250+ LENDERS
ACCESS TO LOW RATES
Our relationships with lenders and suppliers enables us to secure ‘best in class’ rates across industry sectors
You’ll share basic information about you, your business and finance requirements. Either apply online or call us on 0161 791 4601.
We’ll ask for some more information regarding your businesses and tailor the best solution to meet your needs.
Once approved, we’ll get funds to your preferred business bank account or pay a supplier on your behalf.
Copyright © 2020 Finspire Finance. All Rights Reserved.
Finspire Finance Ltd is an independent finance brokerage and not a lender, as such we can introduce you to a wide range of finance providers depending on your requirements and circumstances. We are not independent finance advisors and so are unable to provide you with independent finance advice. Finspire Finance Ltd may receive payment(s) or other benefit from the finance provider if you decide to enter into an agreement with them. We aim to provide our customers with the highest standards of service. If our service fails to meet your requirements, we will endeavour to find a resolution.
Finspire Finance is a trading style of Finspire Finance Ltd (FRN: 931020) who are credit brokers and appointed representatives of White Rose Finance Group Ltd (FRN:630772) who are directly authorised and regulated by the Financial Conduct Authority.
Please make borrowing decisions carefully, property or other assets offered as security may be at risk if you cannot keep up with repayments.