Privacy policy
Who we are
This website, www.bricksfinance.co.uk, is operated by Bricks Finance Ltd (“we”, “us”, “our”), a company registered in England and Wales under company number 09298424, with registered address at Winslade Park, Manor Drive, Exeter EX5 1FY.
We are registered with the Information Commissioner’s Office (ICO) under registration number ZA151973.
If you have any questions about this policy or how we handle your personal data, you can contact us at:
Email: info@bricksfinance.co.uk
Post: Bricks Finance Ltd, Winslade Park, Manor Drive, Exeter EX5 1FY
We will always treat your personal details with the utmost care and will never sell them to other companies for marketing purposes. All information provided by you will be treated securely and confidentially.
Visitors to our websites
When someone visits our website we collect standard internet log information and details of visitor behaviour patterns. We do this to understand things such as the number of visitors to different parts of the site. Where this information does not identify anyone, we do not attempt to associate it with any personally identifying information.
If we collect personally identifiable information through our website, we will be upfront about this. We will make it clear when we collect personal information and explain what we intend to do with it, and we will identify our lawful basis for doing so (see “Our lawful basis for processing your data” below).
What information we collect about you
Depending on how you interact with us, we may collect:
Contact details — name, address, email, phone number
Identity information — date of birth, proof of ID, proof of address
Financial information — income, expenditure, existing borrowing, bank details, credit history
Communications — records of meetings, emails, messages, and telephone conversations with you
Application information — details you provide through proposal forms, fact finds, or online forms
Technical information — IP address, browser type, and website usage data (see “Use of cookies” below)
We collect this information during meetings, email, messages, and/or telephone conversations with you, and through the completion of proposal forms and fact finds.
Our lawful basis for processing your data
Under UK GDPR, we must have a valid lawful basis for using your personal data. Depending on the activity, we rely on one or more of the following:
Contract — where processing is necessary to provide services you’ve asked for, or to take steps towards entering into a contract with you
Legal obligation — where we’re required to verify your identity, prevent fraud, or meet regulatory requirements (e.g. FCA rules, anti-money-laundering law)
Legitimate interests — where processing is necessary for our legitimate business interests (e.g. improving our services), provided this doesn’t override your rights and interests
Consent — where we ask for your specific agreement (e.g. for certain marketing communications), which you can withdraw at any time
How your information will be used
We are required to verify the identity of all new clients and to keep information regarding our current clients updated. We, or our lawyers, will verify your name, address, and other personal information supplied by you against appropriate third-party databases.
In performing these checks, personal information provided by you may be disclosed to our lawyers and to registered Credit Reference Agencies (CRAs), which may keep a record of that information. CRAs may also use and share this information with other organisations for fraud prevention purposes and to check your identity. Full details of how CRAs use your data are set out in their own privacy notices; please contact us if you’d like these links or further information.
We will never sell your personal details to other companies for marketing purposes. If we ever wish to use your data for our own marketing communications, we will ask for your consent first (where required) and you can opt out at any time by contacting us.
How long we keep your information
We retain personal data only for as long as necessary for the purpose it was collected. As a general rule:
Client and transaction records: up to six years after the end of our professional relationship, in line with regulatory record-keeping requirements
Data held electronically for compliance, audit, or dispute-resolution purposes: may be retained longer where legally required
Website usage/log data: 12 months
Where we can, we anonymise or securely delete data once it is no longer needed.
Use of cookies
Cookies are small text files placed on your device by websites you visit. They’re widely used to make websites work, or work more efficiently, and to give site owners information about how the site is used.
Most web browsers also let you control cookies through browser settings. For more information on cookies generally, including how to see what’s been set on your device and how to manage or delete them, visit www.allaboutcookies.org.
Links to other websites
This privacy notice does not cover links within this site to other websites. We encourage you to read the privacy policies of any other websites you visit.
Data security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We limit access to your personal data to those employees, agents, contractors, and other third parties who have a genuine business need to know it. They will only process your personal data on our instructions and are subject to a duty of confidentiality.
We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator where we are legally required to do so. All information you provide to us is stored on secure servers.
Your rights
Under UK GDPR, you have the right to:
Access — request a copy of the personal information we hold about you
Rectification — ask us to correct information that is inaccurate or incomplete
Erasure — ask us to delete your personal data in certain circumstances
Restriction — ask us to limit how we use your data in certain circumstances
Object — object to our processing of your data, including for direct marketing
Data portability — request that we transfer your data to another organisation, in certain circumstances
Withdraw consent — where we rely on consent, withdraw it at any time
To exercise any of these rights, contact us using the details at the top of this policy. If you believe any information we hold is incorrect or incomplete, please let us know and we will amend it promptly.
How to complain
If you’re unhappy with how we’ve handled your personal data, please contact us first at info@bricksfinance.co.uk so we can try to resolve it. We aim to respond to complaints within 14 business days.
If you’re not satisfied with our response, or you’d prefer not to raise it with us directly, you have the right to complain to the Information Commissioner’s Office (ICO):
Website: ico.org.uk/make-a-complaint
Helpline: 0303 123 1113
Changes to this policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated “Last updated” date.