The Data Protection Act 2018 (DPA 2018) sets out the data protection framework in the UK and
incorporates the Regulation (EU) 2016/679 (General Data Protection Regulation, 'GDPR') into the
national law. Its purpose is to protect the 'rights and freedoms' of natural persons (living
individuals), and to ensure that personal data is not processed without their knowledge, and,
wherever possible, that it is processed with their consent.
Personal information includes any information that identifies you personally, such as your name, address, email address, internet protocol address or telephone number.
Under the DPA 2018 and the GDPR, Mortgage Brain is defined as the Data Processor and therefore has a legal duty to protect any information we collect and process from you as customers.
We use appropriate technologies to safeguard your details and keep to strict security standards to prevent unauthorised access to it.
We recognise that your privacy is very important and so we want you to be confident with the way Mortgage Brain and any of its Partners, Associates & 3rd Parties handle your personal information.
We have outlined below how Mortgage Brain collects, uses, discloses, and protects this information.
The lawful bases for processing are set out in Article 6 of the GDPR. At least one of these must apply whenever you process personal data:
All our data we collect is based on Legitimate Interest & forms part of a contract with our customers where they are
Our business architecture, accounting and systems infrastructure and compliance organisation means that all personal data is processed on common, group-wide platforms. We have processes in place to make sure that only those people in our organisation who need to access your data can do so. A number of data elements are collected for multiple purposes, as the table below shows. Some data may be shared with third parties, this will be shown in your contract with Mortgage Brain.
When we process on the lawful basis of legitimate interest, we apply the following test to determine whether it is appropriate:
The purpose test - is there a legitimate interest behind the processing?
Necessity test - is the processing necessary for that purpose?
Balancing test - is the legitimate interest overridden, or not, by the individual's interests, rights or freedoms?
We collect personal data from you for one or more of the following purposes:
Below table shows our Business areas, what data we collect and where it is stored...
|Mortgage Brain Systems/Areas||Data Collected||Data Stored|
|The Key||Applicants- Name, date of birth, marital status, sex, nationality, Address and contact data, Employment details including National Insurance number and salary, Loans, credit cards and monthly outgoings, Adverse credit data, Previous name, Previous addresses, Previous employers, New property details, New property details, Bank details including account number and sort code, Contact details for Estate Agent, Solicitor, Landlord, current mortgage lender, Accountant, Doctor, health information, convictions||Navisite & Claranet|
|Mortgage Brain Classic||Applicants- Name, date of birth, marital status, sex, nationality, Address and contact data, Employment details including National Insurance number and salary, Loans, credit cards and monthly outgoings, Adverse credit data, Previous name, Previous addresses, Previous employers, New property details, New property details, Bank details including account number and sort code, Contact details for Estate Agent, Solicitor, Landlord, current mortgage lender, Accountant, Doctor, health information, convictions||Customer own desktop|
|Sourcing Brain||Applicants- Name, date of birth, marital status, sex, nationality, Address and contact data, Employment details including National Insurance number and salary, Loans, credit cards and monthly outgoings, Adverse credit data, Previous name, Previous addresses, Previous employers, New property details, New property details, Bank details including account number and sort code, Contact details for Estate Agent, Solicitor, Landlord, current mortgage lender, Accountant, Doctor, health information, convictions||Navisite & Claranet|
|MTE & User Registration Database (URD)||First Name, Surname, Date of birth, address, email address, FCA Number, Telephone number||Navisite ELP Server, Navisite test server, Claranet|
|Submissions Brain & User Registration Database (URD)||First Name, Surname, Date of birth, address, email address, FCA Number, Telephone number||Claranet|
|Web Brain (websites)||First Name, Surname, company, emails, postcode, phone numbers||Navisite, Eshot Servers|
|Mailchimp||Name, company, emails, postcode, phone numbers.||The Rocket Science Group LLC server in United States (covers EU & Privacy Shield Framework)|
|Affordability Brain||Applicant Data: Postcode, DOB, incomes, expenses, credit, debit values. Financial information credit/debit card numbers, FCA number, Name, email, phone number, device information, actions throughout the site and we monitor your sessions using our A-Hub Website including your searches, pages visited and information collected (automatically collected); company related information, associated Network/Club partnerships, compliance authority stance (AR/DA); IP Addresses||UK Fast, AWS, Google Server Suite|
|Criteria Brain||Customer: First name, last name, telephone, office telephone, email, company fca no, company name, network/club identification, office postcode, office address||UK Fast, AWS, Google Server Suite|
|Conveyancing Brain||First name, Surname, Email, Telephone number, Company, FCA Number, Authorised type, Network/Corporate, Address, Postcode, Type of business||IFA Conveyancing|
|AE3 Media||Name, company name, address, postcode, contact details-telephone, mobile, email. Bank details, firmographic information, details of newsletter subscriptions and event engagement (register, declined, no show, attended)||AE3 Media server Holborn, Pathfinder Server, Ivent Server, CSV Database|
|Your Mortgage Finder||Property price/value, Sale price, Loan amount, Loan purpose, Term, Mortgage length, Outstanding mortgage, Mortgage type, Mortgage payment, Payment type, Existing lender, First name, Surname, Email, Telephone number, House number, Postcode, Property (type, construction/residency), Country, Age, Employment, Salary, Adverse credit, Sale tenure, Purchase tenure||Mortgage Brain web server, London & Country Mortgages, Fluent Money, Blacks Solicitors LLP|
|Loans Brain||Loan amount, Loan purpose, Term, Mortgage type, Income, Property value, Mortgage amount, DOB, Employment status, Time in employment, Adverse credit history. Broker: Name, Company, Telephone, Email, FCA. Client: Name, Address, Telephone number, Email||Mortgage Brain web server, Fluent Money|
|Administration Systems||Name, address, contact details, bank details, emails, FCA numbers, customer information related to query||Croydon Internal Server|
Should you have any queries on the above please email GDPR@mortgagebrain.co.uk.
The security of your personal information is of the utmost importance and Mortgage Brain is committed to protecting the personal data we process. We maintain administrative, technical and physical safeguards designed to protect against accidental, unlawful or unauthorised destruction, loss, alteration, access, disclosure or use. We use SSL encryption on a number of our websites from which we transfer certain personal information. We take measures to destroy or permanently de-identify personal information if required by law or the personal information is no longer required for the purpose for which we collected it. In addition, access to personal data is restricted only to those who have a legitimate business need and data processed by third parties is only done so under strict instruction from Mortgage Brain, as per the terms of their contract. Procedures are in place to ensure breaches, or suspected breaches, are dealt with in a timely and secure manner and applicable notification applied within the required timeframes.
We do not, however, have any control over what happens between your device and the boundary of our information infrastructure. You should be aware of the many information security risks that exist and take appropriate steps to safeguard your own information. We accept no liability in respect of breaches that occur beyond our sphere of control.
As a data subject whose personal information we hold, you have certain rights. If you wish to exercise any of these rights, please email GDPR@mortgagebrain.co.uk or use the information supplied in the Contact Us section below. To process your request, we will ask you to provide two valid forms of identification for verification purposes. Your rights are as follows:
You may request a copy of the personal data we hold about you free of charge. Once we have verified your identity and, if relevant, the authority of any third-party requestor, we will provide access to the personal data we hold about you as well as the following information:
If there are exceptional circumstances that mean we can refuse to provide the information, we will explain them. If requests are frivolous or vexatious, we reserve the right to refuse them. If answering requests is likely to require additional time or occasions unreasonable expense (which you may have to meet), we will inform you.
When you believe we hold inaccurate or incomplete personal information about you, you may exercise your right to correct or complete this data. This may be used with the right to restrict processing to make sure that incorrect/incomplete information is not processed until it is corrected.
Where no overriding legal basis or legitimate reason continues to exist for processing personal data, you may request that we delete the personal data. This includes personal data that may have been unlawfully processed. We will take all reasonable steps to ensure erasure.
You may ask us to stop processing your personal data. We will still hold the data but will not process it any further. This right is an alternative to the right to erasure. If one of the following conditions applies you may exercise the right to restrict processing:
You may request your set of personal data be transferred to another controller or processor, provided in a commonly used and machine-readable format. This right is only available if the original processing was on the basis of consent, the processing is by automated means and if the processing is based on the fulfilment of a contractual obligation.
You have the right to object to our processing of your data where…Processing is based on legitimate interest;
Alternatively, you can contact us using the following postal address or telephone numbers:
Mortgage Brain Limited
6 The Courtyard,
Telephone: 01527 557201
Should you wish to discuss a complaint, please feel free to contact us using the details provided above. All complaints will be treated in a confidential manner.
Should you feel unsatisfied with our handling of your data, or about any complaint that you have made to us about our handling of your data, you are entitled to escalate your complaint to a supervisory authority within the European Union. For the UK, this is the ICO (Information Commissioner's Office), which is also our lead supervisory authority. Its contact information can be found at www.ico.org.uk/global/contact-us/
Last updated 01 September 2021