We are committed to ensuring that we manage your personal data professionally and in compliance with all applicable data protection laws. Part of this commitment is to ensure that there is transparency about how we process personal data. This policy includes an explanation of:
what data we are processing;
why we are processing it and what we do with it;
whether we will share it with anyone else;
whether we will transfer it outside of the United Kingdom;
how we keep your data safe; and your rights.
Our Company name is My Car And Finance
For any queries concerning your data please contact the Data Protection Appointed Director at 31 Park Grove Knaresborough HG5 9ET
[email protected] Tel:07426 819237
We are a Finance Broker
Your personal data
We process your personal data if we understand that you may be interested in purchasing our products or services.
What data do we hold about you and how have we obtained this?
We will obtain information about you when you enquire about our products or services. Typically, the information that we obtain will be: Name, Address, Date of Birth, Employment details, bank details and salary details. Email Address and telephone numbers.
If you have visited our website we may automatically collect some personal information including: details of your browser and operating system, the website from which you visit our website, the pages that you visit on our website, the date of your visit, and the Internet protocol (IP) address assigned to you by your internet service. We collect some of this information using cookies – please see Cookies in section 5 for further information. We may also collect any personal information which you allow to be shared that is part of your public profile on a third party social network.
Sometimes you will have sent your information directly to us, but you may have provided your information to our
supporting suppliers / dealers, Agents, Brokers and Appointed Representatives who, in turn, has provided the information to us.
How do we use your personal data and what is the applicable lawful basis?
Where you are an individual, sole trader or unlimited partnership and have consented, we:may provide you with marketing information about our products and services or the products and services of our selected partners or for events;
Where we are required to do so to perform our contract with you, we may process your information for providing a financial statement.
We may process your information to comply with legal obligations including assisting HMRC, the Police and the Driver and Vehicle Licensing Agency
Will we share your personal data with any third parties?
We may share your data with our third party partners and other finance houses.
We may disclose your information to our third-party service providers for the purposes of providing services to us or directly to you on our behalf e.g. advertising agencies or administrative service providers. When we use third party service providers, we only disclose to them any personal information that is necessary for them to provide their service and we have a contract in place that requires them to keep your information secure and not to use it other than in accordance with our specific instructions.
We may transfer your data to government or other official bodies for the purposes of complying with legal obligations, for enforcing our rights, or for the prevention or detection of a crime.
How long do we keep your data?
If you have expressed an interest in buying products from us or from our selected partners, we will retain your contact details and related information concerning your enquiry for 7 years from the date that we last had contact with you.
If you have purchased products from us or from our selected partners, we will keep the data relating to that purchase (e.g. order forms and invoices and related correspondence) for term of the agreement plus 7 years from the termination of the contract or the most recent financial transaction.
If you have requested that we do not send you marketing information we will always retain sufficient
information to ensure that we remember to comply with your request.
The periods stated in this section may be extended if we are required by law to keep your data for a longer period.
How do we use your personal data?
market research, training and to administer our websites;
the prevention of fraud or other criminal acts;
undertaking credit checks for finance;
enforcing our legal rights or to defend legal proceedings and for general administration purposes.
(where you have contacted us on behalf of a business or organisation excluding sole traders or unlimited partnerships) providing you with marketing information about our products and services or the products and services of our selected partners or for events.
Transferring your data outside of the United Kingdom (‘UK’)
The information that you send to us may be transferred to countries outside of the UK. By way of example, this may happen where any of our group companies are incorporated in a country outside of the UK or if any of our servers or those of our third-party service providers are from time to time located in a country outside of the UK. These countries may not have similar data protection laws to the UK.
If we transfer your information outside of the UK in this way, we will take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected. These measures include imposing contractual obligations on the recipient of your personal information or ensuring that the recipients are subscribed to ‘international frameworks’ that aim to ensure adequate protection. Please contact us if you would like more information about the protections that we put in place.
If you use our services whilst you are outside the UK, your information may be transferred outside the UK to provide you with those services.
We have adopted appropriate measures to protect the personal data we collect and use
having regard to the nature of the data stored and the risks to which the data is exposed to human action or the physical or natural environment. However, as effective as our security measures are, no security system is impenetrable. We cannot guarantee the security of our database.
The transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our website; any transmission is at your own risk. Once we have received your information, we will use procedures and security features to try to prevent unauthorised access
Links to other websites
Our website may contain links to and from other websites (e.g. social media sites such as Twitter, Flickr, YouTube and
Your right to access data
We always aim to be as open as we can and allow people access to their personal information. Where we hold your personal data, you can make a ‘subject access request’ to us and we will provide you with:
a description of it;
an explanation of why we are holding it;
information about who it could be disclosed to; and
a copy of the information in an intelligible form – unless an exception to the disclosure requirements is applicable.
If you would like to make a ‘subject access request’ please make it in writing to our contact email address noted
and mark it clearly as ‘Subject Access Request’.
If you agree, we will try to deal with your request informally, for example by providing you with the specific
information you need over the telephone.
Unless you agree a different time, we will complete your subject access request within one month.
Right to stop marketing messages
You always have the right to stop marketing messages. We will usually include an unsubscribe button in any marketing emails. If you do wish to unsubscribe, please just click the unsubscribe button and we will promptly action that request. Alternatively, you can update your marketing preferences by contacting us at any-time. Our contact details are shown On our contact page.
Right to be forgotten
If we hold personal data about you, but it is no longer necessary for the purposes that it was collected and cannot otherwise be justified – you have the right to request that we delete the data.
Right to restrict data
If we hold personal data about you and you believe it is inaccurate you have the right to request us to restrict the data until it is verified. You also have the right to request that the data is restricted where you have a right to it being deleted but would prefer that it is restricted.
You can ask us to send your personal information directly to another service provider, and we will do so if this is technically possible. We may not provide you with a copy of your personal information if this concerns other individuals or we have another lawful reason to withhold that information
Right to complain
You always have the right to complain to the personal data regulator, the ICO. You may also be entitled to seek compensation if there has been a breach of data protection laws.
This policy was last updated on 13 September 2019