Data Privacy Policy

Here at Lindsay Finance Limited we are committed to protecting and respecting your privacy by ensuring that any personal data that we collect and use is done so transparently and lawfully.

This Privacy Notice explains:
• Who we are
• What personal data is
• When and how we collect data about you
• How we use the data we collect
• The conditions under which we may disclose it to others
• How we keep the information secure
• Your rights with regards to data privacy
• How to contact either Lindsay Finance Limited regarding your personal data privacy or the Information Commissioner’s Office (ICO)

1. Who we are

Lindsay Finance Limited are primarily Finance Brokers, procuring and providing finance facilities across the UK for all types of businesses. We also provide business advice through our Castlestrong brand and source and supply vehicles, plant & equipment via our United Equipment brand.

Lindsay Finance Limited (“LFL”), Company Registration number is 04991452, ICO Number: Z8450101 and our Registered Office address is Cawley House, 149-155 Canal Street, NOTTINGHAM, NG1 7HR.

LFL is a “Data Controller”. This is a legal term which means that we make decisions about how and why we use your personal data. As the “Data Controller,” we are responsible for making sure that your personal data is used in accordance with applicable data protection laws. As Data Controller, we are required by law to give you the information in this notice.
However, on occasions there may be other Data Controllers involved in processing your data as further explained in this policy, or as you may be advised at the time your information is to be processed.

We have included details of contact points, including those for our Data Protection Officer, which you can use if you wish to ask us for further information or to exercise your rights.

You will see at the end of this policy that we mention the privacy notices of Fraud Prevention Agencies and Credit Reference Agencies. We do need to share these with you. Please read them carefully and contact those organisations if you have questions.

2.What is personal data?

Personal data is considered to be any information that either alone, or in combination with other information, would identify you as a living individual. An example would be, your name or your date of birth.

3. Have you been introduced to us by a third party or another intermediary?

When a Third Party or other intermediary processes your personal data on our behalf, this privacy policy will apply, and you should contact our Data Protection Officer to exercise your rights under data protection laws. When a third party or other intermediary processes your personal data as a data controller in its own right, its own privacy policy will apply, and you should ask them for a copy if you do not have one by the time you are introduced to us.

4. How do we collect your information?

Directly from you:
We will generally collect your personal data from you directly, including:
• Information entered into our website(s) when you register to use our site or subscribe to our newsletter(s)
• Information entered when you apply for our products or services, either via our website(s) or via paper application forms
• Face-to-face contact, telephone calls, video conferences, emails, letters and other correspondence you have with us. We may monitor or record phone calls with you to check we have carried out your instructions, to resolve queries or disputes, to improve the quality of our services or for regulatory or fraud prevention purposes
• Material you post on our social media pages
• Details of transactions you carry out through our site
• Information we have gathered from asking you to respond to surveys, should you choose to complete them
• If you take part in our competitions or promotions

Data from third parties we work with:
• Individuals, Partnerships & Companies that introduce you to us
• Accountants**, Advisers, Brokers & Referral Partners
• Banks & Finance Companies and other Lenders
• Business Consultants
• Publications and Advertisers
• Credit Reference Agencies (CRAs, see below)
• Manufacturers, Retailers & Suppliers
• Internet & Social networks
• Fraud Prevention Agencies (FPAs)
• Public information sources such as Companies House
• Agents working on our behalf
• Government and law enforcement agencies

**We may also require a statement signed by an independent qualified accountant as to your financial worth which may include information such as your gross and net worth, your assets and liabilities and information as to your available collateral or security. You will be asked to consent to the provision of this information.

Data we collect when you use our services:
• Payment data: for example, the amount, origin, frequency, history and method of your payments
• Transaction data: for example, the sort of products you are selecting, the length of term, the types of assets you are looking at financing, business type and geographical location
• We will also collect information derived from cookies, which will include your IP Address unless you have set your browser not to accept cookies
• We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration and to report aggregated information to our advertisers. This is statistical data about our users’ browsing actions and patterns and does not identify you as an individual
• By using our websites or applications you agree that cookies may be forwarded from the relevant website or application to your computer or device
• The cookie will enable us to know that you have visited the website or application before and will identify you. We may also use the cookie to prevent fraud

From Credit Reference Agencies (CRAs):
In addition, we will obtain your personal data from Credit Reference Agencies (CRAs) which we use to verify your identity and credit worthiness (see the section below titled “Sharing Information with Credit Reference Agencies”), Fraud Prevention Agencies, your employer, landlord, other lenders, HMRC, DWP, publicly available directories and information (e.g. telephone directory, social media, internet, news articles).
Some of the personal data obtained from Credit Reference Agencies will have originated from publicly accessible sources. Credit Reference Agencies draw on court decisions, bankruptcy registers and the electoral register/roll. We explain more about this below.

5. What personal data do we collect from you?

This depends on the products and services you enquire about, apply for, and obtain from us. Generally speaking; the personal data we process about you falls into three main categories:

Who you are
• Where you live and how to contact you
• Your full name and any alias’s
• Your date of birth and/or age (so that we can, for example, make sure that you are eligible to apply for the product and it is suitable for you)
• Your address and correspondence address (where different from address) and address history
• Details about you that are stored in documents in different formats, or copies of them. This could include things like your passport, driving license or birth certificate, if this is necessary for us to comply with our legal and regulatory requirements
• Your marital status, family, lifestyle or social circumstances if relevant to the application (for example, the number of dependents you have or if you are a widow or widower)
• What we learn about you from letters, emails and conversations between us
• Details on the devices and technology you use
• Usage data about how you use our products and services
• Personal data which we obtain from Fraud Prevention Agencies (see the section on ‘Fraud Prevention Agencies’ below)
• Some special categories of personal data such as information about your health

Your employment status and sources of income
• Whether you are employed, retired, or receive benefits
• Your financial position, status, and history
• Your salary and other sources of income
• Any savings

Your financial commitments
• Existing borrowings and loans
• Details about payments to and from your accounts
• Household expenditure
• Personal data about your credit history which we will obtain from Credit Reference Agencies including data which originates from Royal Mail (UK postal addresses), local authorities (electoral roll), the insolvency service, Companies House, other lenders and providers of credit who supply data to the CRA’s, court judgments, decrees and administration orders made publicly available through public registers (see information on CRA’s below)

Special Category Data
In the course of your interactions with LFL you may share information that is classified as ‘Special Category Data’. This could include, but not limited to data about:

• Race
• Ethnic origin
• Politics
• Religion

Where you do share information relating to any of these categories e.g., when you may share information about your health or a characteristic of vulnerability LFL will always seek explicit consent from you to store and process such information.

6. Joint Applicants, Guarantors and Powers of Attorney

If you make a joint application with your spouse, partner or family member, or if you apply for a service or product with a guarantor, we will also collect the personal data mentioned above about that person. You must show our privacy policy to any other applicants and ensure they confirm they know you will share their personal data with us for the purposes described in it.

If there is somebody who has power of attorney over your affairs, that person will also need to view our privacy policy when we make contact with him/her directly.

7. Ultimate Beneficiary Owners

If you make an application for your business, we will also collect the personal data mentioned above about all individuals who you have a financial link with, for example other directors or officers of your company, who you must include on the application form.

You must show this policy to any other applicants (including all ultimate beneficial owners and directors) and ensure they know you will share their personal data with us for the purposes described in it.

In order to assess your company’s suitability for the product, we need to verify that:
• All applicants are included
• The identity for all applicants is verified
• All applicants are UK tax payers

To do this, we or our nominated Lenders may use an external agency to check all directors are included and gather publicly held data to run authentication and world checks.
If the data we gather is insufficient to allow us to run these checks, we will request them directly from you.

8. Witnesses

Some of our products and services including mortgages and business finance, require witness signatures (to comply with execution formalities as a matter of law) and include the name and address of individuals who have acted as a witness for you. These details are kept on the application forms and stored with your account documents in line with our retention procedures

9. Our lawful basis for processing personal data

Under Data Protection law we are only allowed to process personal data if we have a proper reason to do so. The law allows us to process your data for one or more of the following reasons:
• To fulfil a contract that we have with you
• When it is our legal duty
• When it is a legitimate interest i.e., when we have a business or commercial reason to use your information. The reason must not unfairly go against whit is right and best for you
• When you consent to

The table below shows the ways we may use your personal data and why:

What we use your personal data for The reason(s) why we can use your personal data
• To verify your identity
• To manage our relationship with you
• To find new ways to meet our customers’ needs and to grow our business
• To develop and carry out marketing activities
• To understand how our customers use our products and services
• Fulfil a contract
• Legal duty
• Legitimate interest
• Your consent
• To develop and manage our products and services
• To manage how we work with other companies that provide services to us and our customers
• Fulfil a contract
• Legal duty
• Legitimate interest
• To deliver products and services
• To enable debt recovery
• Fulfil a contract
• Legal duty
• Legitimate interest
• To respond to complaints and seek to resolve them
• To detect, investigate and seek to prevent financial crime
• To comply with laws and regulations that apply to us
• To manage risk for our customers and ourselves
• To prevent fraud and money laundering
• Legal duty
• Legitimate interest
• To exercise our right set out in our agreements and contracts • Fulfil a contract

 

10. Who do we share your personal data with and why?

We may share your personal data with the following parties:
• With agents and advisers who we use to help run your accounts and services, collect what you owe, and explore new ways of doing business
• With valuers and ither organisations involved in the provision of valuation services to enable them to carry out valuations of your property or assets
• With HM Revenue & Customs, regulators and other authorities to assess whether you meet the eligibility criteria for a mortgage or loan
• Credit Reference Agencies to carry out credit checks and record details of your repayment history. The CRA’s have drafted a notice called ‘Credit Reference Agency Information Notice’ (CRAIN) which sets out how your data will be processed.

The CRA’s we normally use are:
– Experian, Consumer Help Service, PO Box 8000, Nottingham, NG1 5GX, and their CRAIN can be read in full at http://www.experian.co.uk/crain
– Red Flag Technology Group Ltd, 49 Peter Street, Manchester, M2 3NG Their CRAIN can be read at www.redflagalert.com/privacy-centre

If you would like to know what information these CRA’s holds about you, please contact them directly.

• Fraud Prevention Agencies (including the National Crime Agency, Action Fraud and the Home Office) to protect us from fraud and money laundering. We may also pass information to financial and other organisations involved in fraud prevention including law enforcement agencies who may also access and use this information to detect, investigate and prevent crime. We may automatically decide that you pose a fraud or money laundering risk or if our processing reveals your behaviour to be consistent with that of known fraudsters or money launderers; or is inconsistent with your previous submissions, or you appear to have deliberately hidden your true identity. If you give false or inaccurate information and we suspect fraud we will record this. Please go to www.cifas.org.uk/fpn to read the Cifas privacy notice in full
• If you use direct debits, we will share your data with the Direct Debit Scheme
• If you have a mortgage or second charge mortgage with us, we may share information with other lenders who also hold a charge on the property
• Any party linked with you or your business’s product or service
• Companies we have a joint venture or agreement to co-operate with
• Organisations that introduce you to us
• Companies that we introduce you to
• Market researchers
• Price comparison websites and similar companies that offer ways to research and apply for financial products and services
• Companies you ask us to share your data with
• Third-party suppliers for supply of goods and services as part of providing service to you, our customer
• Your personal data may also appear on the V5, service history, manufacturers record, insurance documentation or within receipts in relation to the asset which may be shared by us with third parties who store, transport, advertise, sell, express interest in purchasing, own or later hire the asset
• If, in the future, we sell, transfer or merge all or part of our business or assets, including the acquisition of other businesses, we may share your data with other parties. We will only do this if they agree to keep it safe and private and to only use it in the same ways as set out in this notice
• Other members of the Lindsay Finance Group

11. Possible consequences of us processing your personal data

If we, or a fraud prevention agency, determine that you pose a fraud or money laundering risk, we may refuse to provide services and financing that you have requested, or we may stop providing existing services to you.

A record of any fraud or money laundering risk will be retained by the fraud prevention agencies, and may result in others refusing to provide services, finance, or employment to you. If you have any questions regarding this, please contact us.

12. Marketing

LFL understands that with the introduction of the Consumer Duty, it is likely the level of communications issued by our business will increase. This will be necessary to support customers to understand the products and services offered and to provide support to customer throughout the lifecycle of the relationship.

Occasionally we may make you aware of products or services which are similar to those you currently hold with us that may be of interest to you. We will only do this if we consider this type of processing to be of a legitimate business interest or with your consent. You can request that we stop sending you these messages at any time without it affecting you receiving important information about your product or service.

If we have contacted you by post, this can be done by using the contact section on our website or by notifying our Data Protection Officer whose contact details are listed in the contact us section of this document.

If we have contacted you by email you can clink on the link to unsubscribe.

13. How long do we keep your personal information?

Your data is important to us and we take all reasonable steps to maintain it safely and securely and fully in accordance with the General Data Protection Regulation.
We will only retain your personal data for as long as necessary to fulfil the purpose we collected it for, including for the purpose of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period of personal data, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure of the data, the purpose for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

14. Use of Automated Processing and Automated Decision Making

Like many Financial Service providers, we use automated processing in our account opening and identification processes. This means we attempt to match your personal details to publicly available information through sources such as the Royal Mail or Credit Reference Agencies. If for any reason we are unable to complete our formalities using this process you will be informed how you many complete the process using manual methods.

As part of the processing of your personal data, decisions may be made by automated means. This means we may automatically decide that you pose a fraud or money laundering risk or if our processing reveals your behaviour to be consistent with that of known fraudsters or money launderers; or is inconsistent with your previous submissions; or you appear to have deliberately hidden your true identity.

Here are some examples of the types of automated decisions we make:

Pricing
We may decide what to charge for some products and services based on what we know.

Tailoring products and services
We may place you in groups with similar customers. These are called customer segments. We use these to study and learn about our customers’ needs, and to make decisions based on what we learn. This helps us to design products and services for different customer segments, and to manage our relationships with them.

Detecting fraud
We use your personal information to help decide if your personal or business accounts may be being used for fraud or money-laundering. We may detect that an account is being used in ways that fraudsters work. Or we may notice that an account is being used in a way that is unusual for you or your business. If we think there is a risk of fraud, we may stop activity on the accounts or refuse access to them.

Approving credit
We use a system to decide whether to lend money to you or your business, when you apply for credit such as a loan or credit card. This is called credit scoring. It uses past data to assess how you’re likely to act while paying back any money you borrow. This includes data about similar accounts you may have had before.

Credit scoring uses data from three sources
• Your application form
• Credit Reference Agencies
• Data we may already hold

It gives an overall assessment based on this. Banks and other lenders use this to help us make responsible lending decisions that are fair and informed. Credit scoring methods are tested regularly to make sure they are fair and unbiased.

15. Profiling

We use our customers’ data to understand how our web site is operating, to track how certain products are performing and to generate business strategy based on statistical analysis
For this we profile using data generated throughout your contact with us by our online applications and in strict accordance with our Cookie Policy.

Profiling is also relied upon in the processes used by Credit Reference Agencies where automated decisioning methods are used to check for Fraud or Money Laundering activity. You have rights in relation to auto decisioning so contact us if you want to learn more.

We also profile your data to help us identify opportunities for us to maximise the benefits to you of being a LFL customer, such as, for example, through the provision of special offers, unless you have told us that you do not want us to do this.

We can do this activity based on our legitimate interests (and they are listed in the What we do with your data section above) only where the profiling and other automated decision making does not have a legal or other significant effect on you. In all other cases, we can do this activity only where it is necessary for entering into or performing the relevant contract, is authorised by laws that apply to us, or is based on your explicit consent. In those cases, you have the right to obtain human intervention to contest the decision (see ‘rights in relation to automated decision making which has a legal effect or otherwise significantly affects you’ below). Profiling for direct marketing can mean there is a separate right to object (see ‘rights to object’ above). If you want to know more, please contact us using the details provided.

16. Your information rights

Here is a list of the rights that all individuals have under Data Protection laws. They do not apply in all circumstances. If you wish to exercise any of them, we will explain at that time if they are engaged or not. The right of data portability is only relevant from 25 May 2018.

• The right to be informed – we must be transparent with you about the processing that we do with your personal data. This is why we have a privacy policy. The information that you supply is determined by whether we collected your personal data directly from you or indirectly via someone else (such as a third party or another intermediary). Your right to be informed may be relevant if you consider it necessary to ask for more information about what we do with your personal data.

• The right to request access to the personal data held about you, to obtain confirmation that it is being processed, and to obtain certain prescribed information about how we process it. This may assist if you wish to find out what personal data, we do have about you to then determine if you can exercise other rights (those mentioned above and below).
You can exercise this right by writing to us or by emailing us. We will respond within one month.

• The right to object to processing of your personal data where it is based on legitimate interests, where it is processed for direct marketing (including profiling relevant to direct marketing) or where it is processed for the purposes of statistics. Your rights to object may be relevant if you wish to find out more about what legitimate interests we rely on (they are listed in our privacy policy) or about what profiling we do in relation to our direct marketing communications and activities (as mentioned in our privacy policy) for instance. There is an important difference between the right to object to profiling relevant to direct marketing in cases where that profiling activity does not have a legal effect on you or otherwise significantly affect you, and the separate right which exists under data protection laws in relation to profiling including automated decision making which has a legal effect or can otherwise significantly affect you (see below).

• The right to restrict processing of your personal data, for instance where you contest it as being inaccurate (until the accuracy is verified); where you have objected to the processing (where it was necessary for legitimate interests) and we are considering whether our organisation’s legitimate interests override your own; where you consider that the processing is unlawful (and where this is the case) and where you oppose erasure and request restriction instead; or where we no longer need the personal data for the purposes of the processing for which we were holding it but where you require us to continue to hold it for the establishment, exercise or defence of legal claims.

• The right to have your personal data erased (also known as the “right to be forgotten”). This enables an individual to request the deletion or removal of personal data where there is no compelling reason for its continued processing. This right is not absolute – it applies only in particular circumstances and where it does not apply any request for erasure will be rejected. It may be relevant where the personal data is no longer necessary in relation to the purpose for which it was originally collected/processed; if the processing is based on consent which you then withdraw; when you object to the processing and there is no overriding legitimate interest for continuing it; if the personal data is unlawfully processed; or if the personal data has to be erased to comply with a legal obligation. Requests for erasure may be refused in some circumstances such as where the personal data must be retained to comply with a legal obligation or to exercise or defend legal claims.

• The right to have your personal data corrected if it is inaccurate and to have incomplete personal data completed in certain circumstances. If we have disclosed the personal data in question to other organisations, we must inform them of the rectification where possible. Your rights in relation to rectification may be relevant if you consider that we are processing inaccurate or incomplete information about you.

• The right to data portability. This allows individuals to obtain and reuse their personal data for their own purposes across different services; to move, copy or transfer their personal data easily from one environment to another in a safe and secure way without hindrance to usability. This right can only be relevant where personal data is being processed based on a consent or for performance of a contract and is carried out by automated means. This right is different from the right of access (see above) and that the types of information you can obtain under the two separate rights may be different. You are not able to obtain through the data portability right all of the personal data that you can obtain through the right of access.

• Rights in relation to automated decision making which has a legal effect or otherwise significantly affects you. This right allows individuals in certain circumstances to access certain safeguards against the risk that a potentially damaging decision is taken solely without human intervention. This right is different from the more general right to object to profiling (see above) because that other right is not tied to a scenario where there is a legal effect on you or where the processing otherwise significant affects you. Data protection laws prohibit this particular type of automated decision making except where it is necessary for entering into or performing a contract; is authorised by law; or where you have explicitly consented to it. In those cases, you have the right to obtain human intervention and an explanation of the decision and you may be able to challenge that decision.

• You also have a right to complain. If you wish to complain about how we have treated your personal data, please contact Data Protection Officer using the contact information below. You may also refer your concern to the Information Commissioner’s Office (ICO) which regulates the processing of personal data in the UK. You can contact then at:

Information Commissioner
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 01625 545745
Email: casework@ico.org.uk
www.ico.org.uk

If you wish to exercise any of these rights against the Credit Reference Agencies, the Fraud Prevention Agencies, or a broker or other intermediary, who is a data controller in its own right, you need to contact them directly.

17. If you chose not to give personal information

We are unable to provide you with a product or service or to process your application without having personal data about you. Your personal data is required before you can enter into the relevant contract with us, or it is required during the life of that contract, or it is required by laws that apply to us.

If we already hold some of the personal data that we need – for instance if you are already a customer – we may not need to collect it again when you make your application. In all other cases we will need to collect it except as follows:

In cases where providing some personal data is optional, we will make this clear. For instance, we will say in application forms or on our website or via the broker or other intermediary if alternative (such as work) telephone number contact details can be left blank.

18. How and when you can withdraw your consent

Much of what we do with your personal data is not based on your consent and is instead based on other legal grounds. For processing that is based on your consent, you have the right to revoke that consent for future processing at any time. You can do this by contacting us using the contact details at the end of this document. The consequence might be that we cannot send you some marketing communications or that we cannot consider special categories of personal data such as about your health or if you are a vulnerable customer (but these outcomes will be relevant only in cases where we rely on your explicit consent for this).

We will tell the third party or other intermediary who introduced you to us that you have withdrawn your consent only if it is our data processor (this means an organisation that is processing personal data on our behalf) or if we are required to do when you exercise certain rights under data protection laws. If they are acting as a data controller in their own right, you should make sure to contact them directly to withdraw your consent for what they do with your personal data.

To comply with payment services regulations, we must share some of your personal data with other payment service providers in some circumstances such as when you ask us to share information about your account with them. Whilst those payment services regulations mention ‘consent’ for this, ‘consent’ in that context does not have the same meaning as ‘consent’ under data protection laws. The legal grounds which may be relevant to this are compliance with our legal obligations, performance of our contract with you, our legitimate interests, or a combination of these. Therefore, if you ask to revoke consent with respect to what we do with your personal data, we may still have to hold and use that personal data if we need to under the payment services regulations.

19.Transferring data abroad

We will only send your data outside of the European Economic Area (EEA) to
• Follow your instructions
• Comply with a legal duty
• On rare occasions, where this is required by suppliers who help run your accounts and services

Safeguards include contractual obligations imposed on the recipients of your personal data. Those obligations require the recipient to protect your personal data to the standard required in the European Economic Area. Safeguards also include requiring the recipient to subscribe to ‘international frameworks’ intended to enable secure data sharing and where the framework is the means of protection for the personal data.

We protect your data using a secure backup system some of which may be encrypted.

You should also note that whenever fraud prevention agencies transfer your personal data outside of the European Economic Area (EEA), they impose contractual obligations on the recipients of that data to protect your personal data to the standard required in the EEA. They may also require the recipient to subscribe to ‘international frameworks’ intended to enable secure data sharing

20. What you should do if your personal data changes

You should tell us without delay so that we can update our records. If you were introduced to us by a third party or another intermediary you should contact them separately.

21. Data anonymisation and the use of aggregated information

Your personal data may be converted into statistical or aggregated data which cannot be used to re-identify you. It may then be used to produce statistical research and reports. This aggregated data may be shared and used in all the ways described in this privacy policy.

22. Contact Us

You can contact our Data Protection officer at the following address:
Data Protection Officer
Lindsay Finance Limited
Offices 19-20,
22, Cyan Close
Nottingham
NG14 5JX

Email: compliance@lindsay.finance
Phone: 0115 931 4545