# Customer Privacy Notice — Mortgage Lolly
## 1. About this Privacy Notice
This Privacy Notice explains what personal information we collect, how we use it, why we use it, who we share it with, how long we keep it and what rights you have under data protection law.
It applies to customers, prospective customers, website users, complainants and other individuals whose personal information we process in connection with our mortgage, protection and related financial services.
## 2. Who we are and how to contact us
Mortgage Lolly is responsible for deciding how and why your personal information is used. This means we are the data controller for the personal information described in this notice, unless we tell you otherwise.
| Contact route | Details |
|—|—|
| **Post** | 54 Claypond Gardens, London W5 4RE |
| **Telephone** | +44 (0)208 798 2726 |
| **Email** | warren@mortgagelolly.co.uk |
| **FCA firm reference number** | 1033769 |
| **ICO registration number** | Z6076055 |
| **Company registration number** | 17018163 |
## 3. What information we collect, use and why
We only collect and use personal information where we have a lawful reason to do so. The information we use will depend on the service you ask us to provide and your circumstances.
| Purpose | Information we may use | Lawful basis |
|—|—|—|
| Providing mortgage, protection and related financial services | Name, contact details, address, date of birth, employment details, income, expenditure, financial commitments, credit history, property details, family or dependant information, policy needs, application details, lender or insurer decisions, correspondence, call recordings, client notes and documents you provide. | Contract, legal obligation and legitimate interests. |
| Protection, insurance and related advice | Information about your health, lifestyle, smoker status, occupation, family history where relevant, financial needs, existing cover and application answers. | Contract, legal obligation, legitimate interests and explicit consent where special category health information is used. |
| Identity, fraud, sanctions, anti-money laundering and financial crime checks | Name, contact details, date of birth, address history, identification documents, bank details, source of funds information, credit reference information, fraud prevention information and information from public sources. | Legal obligation and legitimate interests. |
| Service updates and customer communications | Name, contact details, case information, service preferences, correspondence history and communication records. | Contract, legal obligation and legitimate interests. |
| Marketing and relationship management | Name, contact details, marketing preferences, enquiry information, website interaction information and records of consent or opt-out. | Consent or legitimate interests, depending on the type of communication and applicable marketing rules. |
| Dealing with queries, complaints or claims | Name, contact details, case records, advice records, call recordings, correspondence, complaint details, financial information, health information where relevant, investigation notes and outcome records. | Legal obligation and legitimate interests. Explicit consent or legal claims may apply where special category information is used. |
| Legal, regulatory, audit and reporting requirements | Information required to meet FCA, HMRC, anti-money laundering, complaint handling, record keeping, audit, professional indemnity and other legal or regulatory requirements. | Legal obligation and legitimate interests. |
| Website, cookies and similar technologies | Device information, browser information, IP address, pages visited, cookie preferences, user journeys, form interactions, accessibility settings and changes you make while using the website. | Consent, legitimate interests, or a PECR/DUAA exception where applicable. See the separate Cookie Policy for more information. |
## 4. Special category and criminal offence information
Some personal information is treated as more sensitive under data protection law. This includes information about health, medical history, lifestyle and other special category information.
We may collect or use health information where it is necessary for protection or insurance advice, quotes, applications, underwriting, claims support, complaint handling, legal claims or regulatory requirements. We will only use this information where we have a valid lawful basis and a special category condition, such as your explicit consent, where required, or where the information is needed for legal claims or regulatory purposes.
We may also process information relating to suspected fraud, sanctions, financial crime, criminal offences or allegations where this is necessary and permitted by law, for example to comply with anti-money laundering requirements or to protect customers, the firm and others from fraud or financial crime.
## 5. Lawful bases and your data protection rights
Under UK data protection law, we must have a lawful basis for collecting and using your personal information. The lawful basis we rely on may affect which rights apply.
| Lawful basis | What this means |
|—|—|
| **Contract** | We need to use the information to enter into or perform a contract with you, or to take steps at your request before entering into a contract. |
| **Legal obligation** | We need to use the information to comply with a legal or regulatory obligation. |
| **Legitimate interests** | We use the information because it is necessary for our legitimate interests, or those of another organisation, and we have balanced this against your rights and freedoms. |
| **Consent** | You have given us clear permission to use your information for a specific purpose. You can withdraw consent at any time. |
| **Legal claims** | In limited cases, we may need to use information to establish, exercise or defend legal claims. |
## 6. Your rights
You have rights under data protection law. These rights are not absolute and may not apply in every situation. We will explain if an exemption applies.
– **Right of access** — you can ask for a copy of your personal information.
– **Right to rectification** — you can ask us to correct information you think is inaccurate or incomplete.
– **Right to erasure** — you can ask us to delete your personal information in certain circumstances.
– **Right to restriction** — you can ask us to limit how we use your personal information in certain circumstances.
– **Right to object** — you can object to us using your personal information in certain circumstances, including where we rely on legitimate interests or use your information for direct marketing.
– **Right to data portability** — you can ask us to transfer personal information you gave us to another organisation, or to you, in certain circumstances.
– **Right to withdraw consent** — where we rely on consent, you can withdraw that consent at any time.
– **Rights relating to automated decision-making** — you have rights where decisions are made solely by automated means and have legal or similarly significant effects.
We will respond to data protection rights requests without undue delay and in any event within one month, unless the law allows us to extend the time because the request is complex or we have received multiple requests.
**Your right to object:** If you object to direct marketing, we will stop using your personal information for that purpose. If you object to other processing based on legitimate interests, we will consider your request and explain our decision.
To make a data protection rights request, please contact us using the contact details in section 2.
## 7. Where we get personal information from
– Directly from you, including forms, applications, documents, calls, emails and meetings.
– Advisers, appointed representatives, introducers or other parties involved in your enquiry or application.
– Lenders, insurers, mortgage clubs, protection providers, surveyors, solicitors, estate agents and professional advisers.
– Credit reference agencies, fraud prevention agencies, sanctions screening providers and identity verification providers.
– Publicly available sources, such as Companies House, the Land Registry, the electoral register or public registers where relevant.
– Our website, cookie banner, online forms and system providers.
## 8. Who we share personal information with
We may share personal information where it is necessary, lawful and proportionate. This may include sharing with:
– lenders, insurers, mortgage clubs, protection providers and product providers;
– appointed representatives, advisers, administrators and other parties involved in providing the service;
– credit reference agencies, fraud prevention agencies, identity verification providers and sanctions screening providers;
– solicitors, conveyancers, surveyors, accountants, estate agents and professional advisers where relevant;
– IT providers, CRM providers, case management systems, secure document platforms, email and communication providers;
– auditors, consultants, compliance support providers and professional indemnity insurers;
– regulators, the FCA, the Financial Ombudsman Service, the Financial Services Compensation Scheme, HMRC, law enforcement bodies and other public authorities where required;
– other parties where you have asked us to share information or where we are legally required or permitted to do so.
## 9. How long we keep information
We will keep personal information only for as long as necessary for the purposes described in this notice, including to meet legal, regulatory, complaint handling, professional indemnity, audit and record keeping requirements.
| Type of record | Indicative retention period / criteria |
|—|—|
| Mortgage, protection and related advice records | Usually kept for at least 6 years after the end of the customer relationship, case closure or policy/application end, and longer where required for regulatory, complaint, claim, audit or professional indemnity purposes. |
| Protection policy and underwriting records | May be kept for the life of the policy and for a further period after the policy ends, where necessary to support complaints, claims, regulatory requirements or legal claims. |
| Complaints and dispute records | Usually kept for at least 6 years after the complaint is closed, and longer where necessary for ongoing regulatory, legal or ombudsman matters. |
| AML, identity and financial crime records | Usually kept for 5 years after the end of the business relationship or transaction, unless a longer period is required or permitted by law. |
| Marketing records and preferences | Kept until you withdraw consent, object, opt out, or the information is no longer needed. Suppression records may be kept to make sure we respect your choices. |
| Website and cookie information | Kept in line with the duration shown in the Cookie Policy or cookie banner. |
| General enquiries that do not proceed | 12 to 24 months, unless a longer period is needed. |
## 10. Marketing
We may send you marketing or information about relevant services where we have your consent or where the law allows us to do so. You can opt out of marketing at any time by using the unsubscribe option in the communication or by contacting us.
We will not sell your personal information to third parties for their own marketing purposes.
## 11. Automated decision-making and profiling
We do not make decisions about you that are based solely on automated processing and that have legal or similarly significant effects, unless we tell you separately and the law allows us to do so.
Lenders, insurers, credit reference agencies and fraud prevention agencies may use automated checks or scoring as part of their own processes. Where they are independent controllers, their own privacy notices will explain how they use your information.
## 12. Website, cookies and similar technologies
When you use our website, we may collect information through cookies and similar technologies. This may include device information, browser information, IP address, pages visited, user journeys, cookie preferences, accessibility settings and changes you make while using the website.
Some cookies are necessary for the website to work. Other cookies or similar technologies may require consent, unless a PECR exception applies. Further information is set out in our separate Cookie Policy.
## 13. How to complain
If you have concerns about how we use your personal information, you can make a data protection complaint to us using the details below.
| Complaint route | Details |
|—|—|
| **Email** | Complaints@themoney-group.co.uk |
| **Telephone** | 01709 242927 |
| **Post** | 27 Bridgegate, Rotherham, South Yorkshire, S60 1SN |
We will acknowledge receipt of a data protection complaint within 30 days. We will take appropriate steps to investigate and respond without undue delay, and we will keep you informed where appropriate.
This is separate from any complaint you may have about regulated financial services. If your complaint relates to advice, service, a product, or financial loss, it may also need to be handled under our financial services complaints procedure.
If you remain unhappy with how we have used your personal information after raising a complaint with us, you can complain to the ICO:
– **Post:** Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
– **Helpline:** 0303 123 1113
– **Website:** https://www.ico.org.uk/make-a-complaint
## 14. Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in how we use personal information, changes to our services, changes to law or regulation, or changes to ICO guidance. Where changes are material, we will take appropriate steps to bring them to your attention.