Privacy Policy
- Supporting you with expert advice and top-quality products
- Working closely with you to understand your wants and needs, ensuring these align with your budget.
- Finding you the most suitable deal for now and in the future.
Please contact us for a no-obligation conversation with an adviser about the most suitable mortgage option for you.
Get In Touch
Customer Privacy Policy
Heron Financial Ltd is committed to protecting your privacy. This Privacy Policy forms part of our legal information and sets out how we protect data which identifies you. If you have any queries concerning your personal information, please contact us.
We are registered under the Data Protection Act 2018 and all information you supply will be treated in accordance with that Act. You can obtain further information about data protection laws by visiting the Information Commissioner’s website.
We receive and securely store information that you enter on our website, or give us in any other way, We use your contact details to communicate with you only about the product we are advising you on, except that we may, occasionally, communicate other information we believe to be of genuine interest to you. We may contact you by post, email or telephone for these purposes. If you do not want to receive such communications we provide an opt-out option in each communication, or you can contact us separately to opt out. Please note that there may be instances where it will be necessary for us to communicate with you for administrative or operational reasons relating to our service or the products you have acquired through us.
When you use this site we anonymously record the details of the pages you look at. This data is not personally identifiable; we use it to analyse the paths that customers take through our site. This helps us improve the service we provide. This information is used only by us and is not passed to any other party.
The personal information held by us is stored and processed by secure computers situated in the United Kingdom. We have internal security measures in place to protect our customer database and access to it is restricted. However, it remains your responsibility:
- to protect against unauthorised access to your log-in details;
- if you open more than one browser of the same type whilst using the website, to remember to close down all browser windows when you finish.
- if you share a computer with someone else, use someone else’s computer or use a computer provided at public Internet access facility you should delete the browsing history and log-off the computer at the end of your session so that any personal information stored temporarily in the computer’s memory is lost.
We reserve the right to communicate such personal information as we hold to third parties which seek the disclosure of it, only if we are requested to do so by law or by a regulatory authority.
Our site contains links to other sites. We are not responsible for the privacy practices, or the content of those websites. You should read the privacy policies of every website that collects data.
As the internet can be assessed worldwide, if you are visiting the site from outside the UK, your visit will necessarily result in the transfer of information across international borders. By visiting this site and communicating electronically with us you are consenting to these transfers.
We reserve the right to change, modify, add or remove provisions of this Privacy Policy. Any changes to this Policy will be shown here, and we recommend that you check this Policy again from time to time
How long is your personal data retained?
We only retain your personal data for as long as necessary. The table below outlines how long data is retained, and depends on the reason the personal data is used for:
Purpose of processing | Retention |
---|---|
Successful mortgage / protection applications | For the full mortgage or protection policy term plus a further 6 years, or for a period of 30 years for historical cases if the original term is not recorded |
Withdrawn, stalled, incomplete and failed mortgage/ protection applications | 2 years from the date the latest application was started, or 6 years from the application submitted date if application was submitted and subsequently rejected |
Client Portal accounts | 2 years from the date of last login if not proceeded to full application |
Affordability assessments for new build property | 2 years from Decision In Principle if affordability check does not proceed to a full mortgage application |
Enquiry data obtained from third parties that do not result in an application | 2 years from the date the lead was received from the Introducer |
After these retention periods if there is no other on-going client relationship your personal data will either be securely deleted or anonymised so that it can be used for statistical purposes but without any method of identifying you individually.
Your legal rights regarding your personal data
You have the right to:
Request access
Request access to your personal data. This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
Request correction
Request correction of the personal data. This enables you to have any incomplete or inaccurate data corrected, though we may need to verify the accuracy of the new data you provide to us.
Request erasure
Request erasure of your personal data. This enables you to ask us to delete personal data where there is no good reason for us continuing to process it. You can also to ask us to delete your personal data where you have successfully objected to the processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to delete the data for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Object to processing
Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
Request restriction of processing
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Request the transfer
Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Withdraw consent at any time
Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
Questions
If you have any questions or complaints relating to how we use your personal data, or if you wish to exercise any of your rights regarding your personal data, please contact the Information Security & Data Protection Manager by emailing data@heronfinancial.co.uk or by writing to us. We will respond to you as soon as is possible. The length of time will depend on the type and complexity of the request, but you will receive a response no later than one month from the initial request.
What if I am still not satisfied?
If you are not satisfied with how the Mortgage Advice Bureau has responded to your enquiry, you have the right to complain to the Information Commissioner’s Office (ICO), who is the regulator for data protection in the United Kingdom.
Data request and removal
You have the right to access, rectify, erase, restrict, challenge, object and migrate the data we hold on you. For more detailed information please read our Privacy Policy above. To find out what data we hold on you and to request to update or remove partially or wholly the data we hold on you (as long as it’s not data that we legally have to hold onto – as outlined in our Privacy Policy). If you want to get in contact with us about your data please either:
Email us: data@heronfinancial.co.uk
Write to us at: DPO, Heron Financial Ltd,
Moor Park Mansion, Rickmansworth, Hertfordshire WD3 1QN
We aim to respond to data enquiries promptly but at busy times may take up to 21 days to get back to you