We take your privacy seriously and we ask that you read this privacy notice carefully as it contains important information on who we are, how and why we collect, store, use and share personal data, your rights in relation to your personal data and on how to contact us and supervisory authorities in the event you have a complaint.
Italicised words in this privacy notice have the meaning set out in the Glossary of Terms at the end of this document.
Oak Tree Mortgages collects, uses and is responsible for certain personal data about you. When we do so we are required to comply with data protection regulation and we are responsible as a data controller of that personal data for the purposes of those laws.
When we mention "Oak Tree”, "we", "us" or "our" we are referring to Oak Tree Mortgages.
About Oak Tree Mortgages and how you can contact us
Oak Tree Mortgages is a Partnership between Andrew Rawlings and Calvin Oram whose principal office is at;
372 Stratford Road, Shirley, Solihull B90 4AQ
Oak Tree Mortgages is authorised and regulated by the Financial Conduct Authority. Oak Tree Mortgages Financial Services Register number is 302247.
Oak Tree Mortgages is registered with the Information Commissioner (registration number Z7476970).
You can contact us at the address above or;
By Telephone: 0121 733 8833 or
Our core business is acting as a mortgage broker. We also routinely offer our mortgage customers life assurance, buildings and contents insurance and other general insurance products.
The personal data we collect and use
We want to give all our customers the best standard of service we can and are serious about protecting your personal information. Please read on to find out what information we’ll need from you, how we use your personal information to make our products and services as effective as possible and how we look after it.
Information we collect directly
Mortgage Customers +
When you apply for a mortgage through us we will collect your direct debit details to pass on to your lender. If the products you select involve a cost, such as a valuation fee, we will ask for your payment information.
Mortgage lenders are data controllers in their own right and have their own privacy notices. However, because lenders may automatically profile your information against their lending criteria and against Credit Reference Agencies as soon as your information is forwarded to them and this may affect your credit score, we will always bring this to your attention as part of the process so that you are forewarned. We will also make you aware in advance when lenders are likely to debit any funds from your accounts.
Insurance Customers +
Vulnerable Customers +
Updating Your Details +
However, if you’ve opened an account or policy with another organisation that we introduced you to, you will need to contact them separately to update your information.
Telephone calls +
Marketing and Market Research +
We may contact you to conduct market research. We occasionally run promotions, competitions and prize draws but if we ask you for your contact details we will ensure these are not used for marketing unless you are happy to consent to that separately.
Money Laundering and preventing and detecting unlawful acts +
We are also required to disclose personal data where required to do so by law or by the order of a court.
We have discretion to disclose personal data where this is necessary for protecting the public against dishonesty.
Cookies on our website, analytics and contacting us via our website +
We use personal data for analytical purposes to understand trends and how the business works but the reports we produce do not identify individuals.
Where you send a message to us using a contact form on our website, your IP address is collected in order to help prevent fraud and impersonation and to ensure we are only dealing with clients within the United Kingdom.
Social Media +
Training and Testing +
Information collected from other sources
Information that we collect indirectly +
The personal data we obtain from other sources may include the following:
- From lenders and product providers:
- Details of your current mortgage or insurance arrangements.
- From identification and verification checking agencies:
- Details to help verify your identity to assist with anti-money laundering and fraud prevention.
- Checking your name, date of birth, place of birth and current address against the UK Treasury Sanctions List.
If you are referred to us by an Estate Agent we will be provided with your name and contact details, details of the property you are buying or selling as well as further comments regarding the potential purchase or sale.
We may also disclose information where permitted by law in connection with the resolution and pursuit of legal rights and disputes or complaints.
Automated Decision Making +
How we use your personal data
The law says we must have a legal basis for processing personal data. There are six standard data processing grounds or conditions for processing personal data Where we process what is called ‘special category data’ (information about health, genetic or biometric data etc) we must additionally have a special category condition or ground for processing your personal data.
We rely on the following conditions for the activities indicated.
|Rationale/Reason for Processing||Lawful Basis for Processing||Third party recipients linked to that activity|
||Legitimate Interest||Lenders/product providers|
||Legitimate Interest||Conveyancers/Solicitors, Mortgage Lenders|
||Content||Quality Solicitors Davisons, Eric Bowes & Co Solicitors, Sesame Bankhall Valuation Services Limited, MovinLegal, Conveyancing Alliance Limited|
|If you no longer wish us to share your data with any of these organisations, you may withdraw your consent at any time.
The above sets of organisation are each data controllers in their own right and will have their own Privacy Notices that will tell you about how your personal data will be used by them.
||Legitimate Interest||Amazon Web Services (AWS) and Dropbox; external suppliers of data storage and data hosting services to retain records on our behalf.|
||Public Interests & Substantial Public Interest Tasks|
||Performance of a contract|
Special category data
Certain types of personal data are considered more sensitive and so are subject to additional levels of protection under data protection legislation. These are known as ‘special categories of data’ and include data concerning your health, racial or ethnic origin, genetic data and sexual orientation. Data relating to criminal convictions or offences is also subject to additional levels of protection.
We may process:
- health information and lifestyle information when providing intermediary services in relation to a protection insurance product; and
- criminal conviction or offence information when providing intermediary services in relation to a general insurance product
In addition to the lawful basis for processing this information set out in the above table, we will be processing it either (i) for the purpose of advising on, arranging or administering an insurance contract or (ii) for the establishment, exercise or defence of legal claims.
In the course of our activities relating to the prevention, detection and investigation of financial crime, we may process criminal conviction or offence information. Where we do so, in addition to the lawful basis for processing this information set out in the above table, we will be processing it for the purpose of compliance with regulatory requirements relating to unlawful acts and dishonesty.
We may use personal data we hold about you to help us identify, tailor and provide you with details of products and services from us that may be of interest to you. We will only do so where we have obtained your consent and then will do so in accordance with any marketing preferences you have provided to us.
In addition, where you provided your consent, we may provide you with details of products and services of third parties where they may be of interest to you.
You can opt out of receiving marketing at any time. If you wish to amend your marketing preferences please contact us:
By phone: 0121 733 8833
By Post: 372 Stratford Road, Shirley, Solihull B90 4AQ
Whether information has to be provided by you, and if so why
We will tell you if providing some personal data is optional, including if we ask for your consent to process it. In all other cases you must provide your personal data in order for us to provide you with intermediary services.
How long your personal data will be kept
To ensure that we are able to meet our legal, regulatory and customer obligations, Oak Tree Mortgages will retain client information for the following time periods:
- If you become a client of a lender/insurer as a result of the advice we provide to you, we will keep a full record of your interactions with us for your lifetime plus a reasonable period to enable us to meet our regulatory obligations to evidence we gave suitable advice and to enable us to answer any complaints that may arise as a result of our advice. In practice this means that we will keep your records for no longer than 100 years after you last transact with us
- If, as a result of our advice, you make an application to a lender/insurer but do not ultimately become a client of that institution, we will keep a full record of your interactions with us for 6-years to meet our obligations under UK Money Laundering regulations.
- If we provide you with advice on a financial product, but you do not engage our services to make an application to a lender/insurer, we will keep a full record of your interactions with us for 3-years, to enable us to meet our regulatory record keeping obligations regarding evidencing suitability of our advice.
- If we collect personal information from you, but are unable to provide you with suitable advice, then we will keep a full record of your interactions with us for 1-year to facilitate an easier interaction between us if you re-engage our services within this period.
- If you request we contact you in relation to our service by providing us with your name and a contact method (e.g. phone, email) through an enquiry form or by email (either on our own, or a 3rd party website) we will use our best endeavours to contact you as soon as possible. If we are unable to make contact with you, we will retain this information for a period of 7-days in order to try and establish contact with you.
Transfer of your information out of the EEA
We may transfer your personal data to the following which are located outside the European Economic Area (EEA) as follows:
- The United States of America in order to store and access your Mortgage Factfind with Dropbox International Unlimited Company which allows us to access your form from any of our offices.
- British Columbia, Canada in order to use email services provided by Hush Communications Canada Inc
The European Commission have decided that Canada and the US (limited to the Privacy Shield Framework) have an adequate level of protection for personal data.
You have legal rights under data protection regulation in relation to your personal data. These are set out under the below headings:
- To access personal data
- To correct / erase personal data
- To restrict how we use personal data
- To object to how we use personal data
- To ask us to transfer personal data to another organisation
- To object to automated decisions
- To understand how we protect information transferred outside Europe
- To find out more about how we use personal data
We may ask you for proof of identity when making a request to exercise any of these rights. We do this to ensure we only disclose information or change your details where we know we are dealing with the right individual.
We will not ask for a fee, unless we think your request is unfounded, repetitive or excessive. Where a fee is necessary, we will inform you before proceeding with your request.
We aim to respond to all valid requests within one month. It may however take us longer if the request is particularly complicated or you have made several requests. We will always let you know if we think a response will take longer than one month. To speed up our response, we may ask you to provide more detail about what you want to receive or are concerned about.
We may not always be able to fully address your request, for example if it would impact the duty of confidentiality we owe to others, or if we are otherwise legally entitled to deal with the request in a different way.
To access personal data
You can ask us to confirm whether or not we have and are using your personal data. You can also ask to get a copy of your personal data from us and for information on how we process it.
To rectify / erase personal data
You can ask that we rectify any information about you which is incorrect. We will be happy to rectify such information but would need to verify the accuracy of the information first.
You can ask that we erase your personal data if you think we no longer need to use it for the purpose we collected it from you.
You can also ask that we erase your personal data if you have either withdrawn your consent to us using your information (if we originally asked for your consent to use your information), or exercised your right to object to further legitimate use of your information, or where we have used it unlawfully or where we are subject to a legal obligation to erase your personal data.
We may not always be able to comply with your request, for example where we need to keep using your personal data in order to comply with our legal obligation or where we need to use your personal data to establish, exercise or defend legal claims.
To restrict our use of personal data
You can ask that we restrict our use of your personal data in certain circumstances, for example
- where you think the information is inaccurate and we need to verify it;
- where our use of your personal data is not lawful but you do not want us to erase it;
- where the information is no longer required for the purposes for which it was collected but we need it to establish, exercise or defend legal claims; or
- where you have objected to our use of your personal data but we still need to verify if we have overriding grounds to use it.
We can continue to use your personal data following a request for restriction where we have your consent to use it; or we need to use it to establish, exercise or defend legal claims, or we need to use it to protect the rights of another individual or a company.
To object to use of personal data
You can object to any use of your personal data which we have justified on the basis of our legitimate interest, if you believe your fundamental rights and freedoms to data protection outweigh our legitimate interest in using the information. If you raise an objection, we may continue to use the personal data if we can demonstrate that we have compelling legitimate interests to use the information.
To request a transfer of personal data
You can ask us to provide your personal data to you in a structured, commonly used, machine-readable format, or you can ask to have it transferred directly to another data controller (e.g. another company).
You may only exercise this right where we use your personal data in order to perform a contract with you, or where we asked for your consent to use your personal data. This right does not apply to any personal data which we hold or process outside automated means.
To contest decisions based on automatic decision making
If we made a decision about you based solely by automated means (i.e. with no human intervention), and the decision made by us produces a legal effect concerning you, or significantly affects you, you may have the right to contest that decision, express your point of view and ask for a human review. These rights do not apply where we are authorised by law to make such decisions and have adopted suitable safeguards in our decision making processes to protect your rights and freedoms.
To obtain a copy of our safety measures for transfers outside of Europe
You can ask for a copy of, or reference to, the safeguards we have put in place when your personal data is transferred outside of the European Economic Area. We are not required to share details of these safeguards where sharing such details would affect our commercial position, or create a security risk.
You can contact us for more information
If you are not satisfied with the level of information provided in this privacy notice, you can ask us about what personal data we have about you, what we use your information for, who we disclose your information to, whether we transfer it abroad, how we protect it, how long we keep it for, what rights you have, how you can make a complaint, where we got your data from and whether we have carried out any automated decision making using your personal data.
If you would like to exercise any of the above rights, please:
- let us have enough information to identify you, e.g. name, address, date of birth;
- let us have proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill); and
- let us know the information to which your request relates.
Keeping your personal data secure
We have appropriate security measures in place to prevent personal data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Our supervisory authority
If you are not happy with the way we are handling your information, you have a right to lodge a complaint with the Information Commissioners Office. It has enforcement powers and can investigate compliance with data protection regulation (www.ico.org.uk).
We ask that you please attempt to resolve any issues with us before the ICO.
How to contact us
Please contact our Data Privacy Manager if you have any questions about this privacy notice or the information we hold about you.