We are ASPIRE SALES, LETTINGS & PROPERTY MANAGEMENT LIMITED with registered number 10374795 and registered address 55 Church Lane Barnwell Oundle Northamptonshire United Kingdom PE8 5BG. Our Data Protection Lead can be contacted at firstname.lastname@example.org. We have produced this privacy notice in order to keep you informed of how we handle your personal data. All handling of your personal data is done in compliance with the General Data Protection Regulation (EU) 2016/679 ("Data Protection Legislation").
When reading this notice, it might be helpful to understand that your rights arising under Data Protection Legislation include:
Under Data Protection Legislation, there must be a ‘lawful basis’ for the use of personal data. The lawful bases are outlined in Article 6, Section 1 of the GDPR. They are sub-sections:
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together follows:
Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.
Contact Data includes billing address, delivery address, email address and telephone numbers.
Financial Data includes bank account and payment card details.
Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us.
Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
Usage Data includes information about how you use our website, products and services.
Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
|Reference||What catergories of information about you do we process?||Why are we processing your data?||Where did we get your personal data from?|
||Direct marketing to former, current and prospective clients. This processing is conducted lawfully on the basis of 'our legitimate interests'.||Directly obtained or by referral from existing clients/partners/suppliers.|
||To understand how you use our website, how you reached us and how long you spend on our website, in order to analyse our performance and improve our service. This processing is conducted lawfully on the basis of 'our legitimate interests'.||Directly obtained or indirectly obtained through a client's website (notice given at the point of collection).|
||To combat fraud, we share information of clients who instruct the payment issuer to cancel payments to us without first informing us of why and/or allowing us the opportunity to issue a refund with credit reference agencies. This processing is conducted lawfully on the basis of 'protection of your, or another's vital interests'.||Directly obtained or indirectly obtained through a client's website (notice given at the point of collection).|
||When you send us information about you by posting on a forum or blog, we will store this information in order to make it available for viewing on the website. You consent is obtained at the time of posting and via reference to this notice. This processing is conducted lawfully on the basis of 'your consent'.||Directly obtained or indirectly obtained through a client's website (notice given at the point of collection).|
|Online Payment Processing||
||We require certain information about you in order to instruct our payments processor to take payment from you and transfer it to us. To ensure security, we do not ever process your payment information and will transfer you to the payment service's website at the time of payment. None of our staff or contractors ever have access to this information. This processing is conducted lawfully on the basis of 'performance of a contract'.||Directly obtained.|
||To setup a direct debit between your bank and ours, we pass your details to our bank and keep a copy for our records. This activity is conducted under the Direct Debit Guarantee Scheme. This processing is conducted lawfully on the basis of 'performance of a contract'.||Directly obtained.|
||We might record calls for training and/or auditing purposes. We also collect Calling Line Identification information. This is used to help improve the efficiency and accountability of our customer services. This processing is conducted lawfully on the basis of 'our legitimate interests'.||Directly obtained.|
|Email and Web Contact||
||If you contact us through our website or by email, we will use the information you send in order to respond to your enquiry or complaint. This information will be kept in order to improve our service to you overall. This processing is conducted lawfully on the basis of 'our legitimate interests'.|
||If you make a purchase with us, we will add your contact information to our marketing list and send you information we think you might be interested in. This processing is conducted lawfully on the basis of 'our legitimate interests'.||Directly obtained.|
Cookies are small text files that are placed on your computer's hard drive through your web browser when you visit any web site. They are widely used to make web sites work, or work more efficiently, as well as to provide information to the owners of the site.
Like all other users of cookies, we may request the return of information from your computer when your browser requests a web page from our server. Cookies enable our web server to identify you to us, and to track your actions and the pages you visit while you use our website. The cookies we use may last for a single visit to our site (they are deleted from your computer when you close your browser), or may remain on your computer until you delete them or until a defined period of time has passed.
The information about you that we have collected for the performance of our contracts is required in order for us to successfully fulfil our obligations to you. If you choose not to provide the personal data requested, we will not be able to enter into a contract with you to provide the benefits we offer. If we are already processing your personal information under a contract, you must end our contractual relationship (as/where permitted) in order to exercise some of your rights.
We process some personal information as part of a contractual relationship with a Data Controller. Any requests to restrict this type of processing should be forwarded to the Data Controller; they will be responsible for discussing your concerns and making any decisions.
Legitimate interests are a flexible basis upon which the law permits the processing of an individual's personal data. To determine whether we have a legitimate interest in processing your data, we balance the needs and benefits to us against the risks and benefits for you of us processing your data. This balancing is performed as objectively as possible by our Data Protection Lead. You are able to object to our processing and we shall consider the extent to which this affects whether we have a legitimate interest. If you would like to find out more about our legitimate interests, please contact us via email@example.com.
ASPIRE SALES, LETTINGS & PROPERTY MANAGEMENT LIMITED holds different categories of personal data for different periods of time. Wherever possible, we will endeavour to minimise the amount of personal data that we hold.
ASPIRE SALES, LETTINGS & PROPERTY MANAGEMENT LIMITED passes your data to the third parties listed in the section 'Third Party Interests' below, for the purposes of providing our services to you, and for no other purpose.
ASPIRE SALES, LETTINGS & PROPERTY MANAGEMENT LIMITED uses overseas web and IT providers. Details of what data is sent where, and the safeguards in place, are included in the section 'Third Party Interests' below.
Our Data Processors
|Name of Third Party||Purposes for Carrying out Processing|
|D Curtis||Board supplier|
|Vebra CFP / Alto||Property Management Software|
|Moore Thompson||Accountant - provides client account audit|
|HMRC||HMRC - we deal with HMRC for our landlords overseas and UK landlords we also deal with HMRC for PAYEE, Tax and VAT|
|DPS||Deposit Protection Scheme - a deposit where we hold or tenants deposits|
|Alto||Software cloud back-up|
|BT Cloud||Cloud provider for phones|
|Carbonite||External software backup|
|123 Reg||Domain provider|
|Solicitors||Customer details to progress sales|
|Property Jungle||Customer leads|
|Landlords||Provide details on prospective tenants. Tenant details are shared for landlord information.|
|Maintenance Contractors||Carrying out day to day repairs on behalf of landlords & tenants|
|Rightmove||Provide Customer Leads|
|Zoopla||Provide Customer Leads|
In addition to sending us your complaints directly to firstname.lastname@example.org, you can send complaints to our supervisory authority. As ASPIRE SALES, LETTINGS & PROPERTY MANAGEMENT LIMITED predominantly handles the personal data of UK nationals, our supervisory authority is the Information Commissioner's Office. If you believe that we have failed in our compliance with data protection legislation, complaints to this authority can be made by visiting https://ico.org.uk/concerns/ .
The purpose of our relationship with our customers is to act as an Agent for the sale of property. As an Estate Agent we are obliged to register with HMRC and we have done so. Lettings agents who only carry out lettings work are not required to register.
We are required to assess the risks that criminals may exploit our business for money laundering and terrorist financing.
We therefore assess the risks to this particular business as very low.
The law requires us to check the identities of our customers, or the ‘beneficial owner’ of a property, for whom we are acting as Agent. Our Nominated Officer for managing this process is our Managing Director. All of our employees are required to be familiar with this policy.
We are required to confirm our customers name, their photograph on an official document which confirms their identity, their residential address and date of birth. We are obliged to record that we have seen these documents, but we are not obliged to make copies, so we do not. We take the view that holding unnecessary copies of our customers personal information puts both parties at risk, if the copies of these documents were mislaid or stolen, so we do not do it.
If we have doubts about a customers identity, we may decline to deal with them until we are sure. Any concerns should be reported to the Nominated Officer.
We ask to see a government issued document - a Passport, Drivers License along with utility bills, bank statements and other official documents. Other sources of customer information may include the electoral register and information held by credit reference agencies such as Experian and Equifax. We intrude on our customers privacy to the minimum necessary to comply with the law: An identity document with photograph and a linking document with address.
We are not document experts and although we are vigilant we cannot be expected to spot expert forgeries, especially those purportedly issued in other countries, but all staff are required to review, “Guidance on examining identity documents” published on the .gov website
We are obliged to check if our customers are Politically Exposed Persons. Domestic or foreign PEP’s are individuals who are or have been entrusted with prominent public functions, for example Heads of State or of government, senior politicians, senior government, judicial or military officials, senior executives of state owned corporations, important political party officials. A family member or close associate of any of the above. As we predominantly deal in domestic properties not of the highest value and there are very few such persons it is unlikely that we will ever interact. If we do the Nominated Officer will decide a course of action.
An estate agency business enters into a business relationship with both parties to the transaction - the property seller and the property buyer. The person who is not a customer, in the commercial sense, must be treated in the same way as a customer for the purposes of the Regulations, for example, the same obligations to apply an appropriate level of customer due diligence. So we will confirm the identity of purchasers when they make a formal offer which is accepted by our client.
Here are some of the questions to consider in deciding whether or not to submit a suspicious activity report when dealing with new transactions:
These are some of the questions to consider when deciding whether or not to submit a suspicious activity report in relation to regular and existing customers:
These are some of the questions to consider when deciding whether or not to submit a suspicious activity report in relation to the transactions carried out:
Report any suspicious activity to the Nominated Officer.
The personal data we are obliged to collect under these regulations 'is necessary in order to exercise a public function that is in the public interest', and keep it for a minimum of five years. This means that we cannot lawfully delete it, even if requested under GDPR legislation until that period has elapsed. During that time we may not use the data for any other purpose.
All staff are obliged to read this document and return a signed, dated copy acknowledging that they have read and understood it to the Nominated Officer who will keep it on file.
In the event of any suspicious activity the Nominated Officer is to be informed and they will decide whether to discontinue dealing with the client or make an SAR Suspicious Activity Report.
Identity details are recorded on our Sales Marketing Agreement and Formal Offer record and we keep a copy for a minimum of five years. We believe this policy and our record keeping makes us fully compliant with current legislation.
This policy is dated 1st January 2018, next review by 1st January 2019.