HomePrivacy Notice

The UK Adviser Ltd Privacy Notice

Last updated: 14 September 2026

Who we are

We are The UK Adviser Ltd and we can be contacted using the following details:

For the purposes of UK data protection law, The UK Adviser Ltd is the data controller for the personal data described in this notice unless we tell you otherwise.

  • Telephone Number: 03300881494
  • Address: Unit 1a, Link 665 Business centre, Todd Hall Road, Rossendale, BB4 5HU
  • Email address: compliance@ukadviser.co.uk
  • Data Protection Officer / contact: Maxim Cohen
  • ICO Registration Number: ZA286899

Our legal grounds for holding your data

The UK GDPR and Data Protection Act 2018 allow us to use personal data only where we have a lawful basis. The lawful basis depends on why we are using the information and may differ between activities.

We consider we have the following reasons (legal bases) to use your personal data:

  • Contract and steps before entering into a contract: we use personal data where it is necessary to take steps at your request before entering into a contract, to provide our services, or to perform a contract with you.
  • Legal obligation: we use personal data where necessary to comply with legal and regulatory requirements that apply to us, including financial crime, anti-money laundering, sanctions, regulatory reporting and record-keeping obligations.
  • Legitimate interests: we may use personal data where this is necessary for our legitimate business interests or those of a third party and those interests are not overridden by your rights, freedoms or interests. Examples include preventing and detecting fraud, protecting our systems and business, improving our services, administration, responsible lending, tracing and debt recovery, establishing or defending legal claims and, where permitted, direct marketing. We carry out the required balancing assessment where we rely on this basis.
  • Consent: where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before consent was withdrawn and does not prevent us continuing to use the information where another lawful basis applies.

When information is required: some personal data is needed so that we can assess or progress your application, provide our services, or meet legal and regulatory obligations. If you do not provide information that is required, we may be unable to assess or submit an application, arrange finance, provide a service, or comply with our legal obligations.

More information on how we use your personal data and for what purposes is set out below.

What data do we collect?

Data provided by you

  • Application and fact-find details: for example, your name, National Insurance number, contact details, date of birth, bank account details, income and expenditure, assets and liabilities, employment or business information, property and home-ownership details, borrowing requirements, source of funds, proof of identity and address, information about available equity or security and other information relevant to the finance or service requested.
  • When you talk to us: for example on the phone, or in person including call recordings and voice messages. We may monitor or record calls with you to check we have carried out your instructions, to resolve queries or disputes, to improve the quality of our service or for regulatory or fraud prevention purposes.
  • In writing: for example letters, emails, texts and other electronic communications.
  • Online: for example when you use our website or mobile app.
  • In financial reviews, for renewals and in any surveys etc.

Data we collect when you use our services

  • Transaction data: for example what sort of products you are selecting, the length of term, the types of asset you are looking at financing, business type and geographical location.
  • Payment data: for example, the amount, origin, frequency, history and method of your payments.
  • Usage, device and profile data: for example, IP address, device/browser information, account or profile information and how you use our website or online services. Where the law requires consent for cookies or similar technologies, we will obtain that consent before using non-essential technologies.
  • Register online or other communication methods for our services.
  • Voluntarily complete a customer survey or provide feedback on any of our message boards or via email.
  • Cookie and similar-technology data when you use or view our website. You can manage non-essential cookie choices through the controls made available on our website.

Data provided to and by third parties

  • Data from persons that introduce you to us: for example brokers, product suppliers, financial advisers, agents, finance providers or other third parties.
  • Data from credit reference agencies and business information providers, which may include Experian, Equifax, TransUnion and, where relevant, providers such as Creditsafe.
  • Data from fraud prevention agencies.
  • Publicly available information: for example, from the land registry, companies house, the electoral register, other information available online or in the media, including social media.
  • Data from your representatives where relevant: for example your legal and financial advisers such as lawyers and accountants.
  • Data from employers, accountants and other relevant third parties where appropriate and lawful. Health information will normally be obtained from you, or from another person with your knowledge or authority, unless the law permits otherwise.

*If information about your health or another vulnerability is relevant, we will only collect and use what is necessary for a defined purpose, for example to understand support needs, make reasonable adjustments, assess suitability where relevant, or meet legal and regulatory obligations. We will tell you why the information is needed and identify an appropriate lawful basis and special-category condition before processing it.

**We may ask you to provide, or authorise an independent qualified accountant to provide, information about your financial position, including gross and net worth, assets, liabilities and available collateral or security, where this is necessary to assess or progress your application or meet a legal or regulatory requirement.

Where we obtain personal data about you from someone other than you, we will provide the required privacy information within the applicable legal time limits (normally within one month, at the first communication with you, or before the first disclosure), unless an exemption applies or you already have the information.

Special Category Data

In the course of your interactions with The UK Adviser Ltd you may share information that is classified as 'Special Category Data'. This could include data about:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometric data used for the purpose of uniquely identifying a person
  • Health
  • Sex life
  • Sexual orientation

If we process special category data, we must have both an Article 6 lawful basis and an Article 9 condition. Depending on the circumstances, the Article 9 condition may include your explicit consent, the establishment, exercise or defence of legal claims, or a condition based on substantial public interest under the Data Protection Act 2018 (for example where relevant to preventing fraud, preventing or detecting unlawful acts, regulatory requirements or safeguarding). Where the law requires it, we will maintain an Appropriate Policy Document. We will not rely on explicit consent where it would not be valid or appropriate.

Criminal offence data

Where we process information about criminal convictions, offences, allegations or related security measures (for example for fraud prevention or financial-crime checks), we will do so only where authorised by UK law and with the safeguards required by the Data Protection Act 2018.

Why do we collect personal data?

The UK Adviser Ltd collects and uses personal data for the purposes described in this notice.

If we want to use your personal data for a new purpose that is not compatible with the purposes described in this notice, we will provide you with appropriate information before the new processing begins and, where consent is required, we will ask for it.

We and fraud prevention agencies may process personal data to verify identity and to detect, investigate and prevent fraud, money laundering and other crime. Depending on the activity, our lawful basis may be compliance with a legal obligation or our legitimate interests in protecting our customers and business and preventing crime. Fraud prevention agencies may also allow law-enforcement agencies to access information where legally permitted. Their retention periods are determined by their own legal obligations and policies and, in some circumstances, fraud-risk information may be retained for up to six years.

To process an application we may provide personal data to credit reference agencies (CRAs) and receive information from them about identity, credit history and financial circumstances. We may use this information to assess creditworthiness, affordability or product suitability, verify identity, prevent crime, manage an application or account, and where applicable trace or recover debts. A CRA search may leave a footprint on your credit file and information may be linked with joint applicants or financial associates where relevant. CRAs act under their own privacy information. We can tell you which CRA(s) were used and will provide or signpost you to the relevant CRA information notice where appropriate.

Credit Reference and Affordability Checks

To help us assess applications, prevent fraud, and meet our legal and regulatory obligations, we may obtain information about you from credit reference agencies (CRAs). We obtain this information via Creditsafe, which uses its data partner TransUnion to supply consumer credit and identity data.

  • Creditsafe Business Solutions Limited is authorised and regulated by the Financial Conduct Authority. FCA Firm Reference Number: 742313
  • TransUnion International UK Limited is authorised and regulated by the Financial Conduct Authority. FCA Firm Reference Number: 737740

The information we receive may include data relating to your identity, credit commitments, payment history, and public record information. This data is used solely for legitimate business purposes, including creditworthiness assessment, identity verification, and fraud prevention, in accordance with applicable data protection laws.

Further information about how Creditsafe and TransUnion process your personal data can be found in their respective privacy notices:

We may use service providers and selected business partners for research, analytics, quality assurance and customer-service purposes so that we can monitor and improve our services. Where another organisation processes data on our behalf, we require appropriate contractual and security protections. Where another organisation acts as an independent controller, it is responsible for its own compliance and privacy information.

We may also contact you about our products or services where direct-marketing rules allow us to do so. The separate Marketing section below explains the rules we apply and your right to opt out.

How will we use your data?

Our Company collects your data so that we can:

  • Process enquiries, applications and requests, provide advice or broking services, source products and communicate with lenders or product providers.
  • Verify identity, carry out anti-money laundering, sanctions, fraud-prevention and other financial-crime checks.
  • Assess creditworthiness, affordability, eligibility, suitability or product options where relevant to the service requested.
  • Administer our relationship with you, keep records, respond to queries and complaints and, where applicable, record or monitor communications.
  • Comply with legal and regulatory obligations, including FCA requirements, Consumer Duty monitoring, financial-crime obligations, audit and regulatory reporting.
  • Protect our business, customers, systems and services; prevent misuse; establish, exercise or defend legal rights; and undertake tracing or debt-recovery activity where relevant.
  • Analyse and improve our services, systems, customer experience and business performance.
  • Send service and regulatory communications and, where legally permitted, direct marketing.

Lawful Basis for Processing Data

Purpose / Processing ActivityLawful Basis for Processing
Enquiries, applications, product sourcing and arranging/providing servicesContract or steps at your request before contract; legitimate interests where appropriate.
Identity, AML, sanctions, fraud and financial-crime checksLegal obligation; legitimate interests where appropriate. Special-category/criminal-offence conditions apply where relevant.
Creditworthiness, affordability, eligibility and suitability assessmentsContract/pre-contract steps; legal or regulatory obligation; legitimate interests, depending on the activity.
Customer service, administration, communications and call recordingContract; legal obligation; legitimate interests.
Regulatory compliance, Consumer Duty monitoring, complaints, audit and reportingLegal obligation; legitimate interests where the activity is not required by law.
Tracing, debt recovery and legal claimsContract; legitimate interests; legal obligation. Legal-claims conditions may also apply to special category data.
Service improvement, research, analytics and website useLegitimate interests; consent where required for non-essential cookies or similar technologies.
Direct marketingConsent or legitimate interests, as applicable, and always subject to PECR. The electronic-mail soft opt-in is used only where its legal conditions are met.
Sharing with lenders, product providers, professional advisers and service providersThe lawful basis depends on the purpose of the sharing and will normally be contract/pre-contract steps, legal obligation or legitimate interests.
Special category and criminal offence dataAn Article 6 lawful basis plus the applicable Article 9 / Data Protection Act 2018 condition, or Article 10 / Data Protection Act 2018 authority, as relevant.

When Personal Data is shared

We may share personal data where necessary with lenders and product providers, brokers or introducers, professional advisers (including solicitors and accountants), valuation or property professionals, banks and payment providers, insurers, IT/cloud/CRM and communications providers, identity and verification providers, customer-service providers, tracing or debt-recovery providers, and other suppliers that support the services we provide. Recipients may act as processors on our behalf or as independent controllers in their own right.

We may also share personal data with credit reference agencies, fraud prevention agencies, law-enforcement bodies, regulators and other public authorities, the Financial Ombudsman Service or Financial Services Compensation Scheme where relevant, persons you authorise us to deal with, companies we introduce you to, and other recipients where disclosure is required or permitted by law. We only share information that is necessary for the relevant purpose.

Where your application relates to an asset, personal data may appear on documents such as the V5, service history, manufacturer records, insurance documents or receipts and may be shared where necessary with organisations involved in storing, transporting, insuring, valuing, advertising, selling, purchasing or hiring that asset.

If we sell, transfer, restructure or merge all or part of our business or assets, or acquire another business, we may share personal data with prospective or actual counterparties and professional advisers where necessary. We will use appropriate confidentiality and data-protection safeguards and will ensure any new controller uses the information lawfully.

International transfers of personal data

We transfer, or permit access to, some personal data outside the United Kingdom. This can occur where a lender, business partner or service provider (for example an IT, cloud, CRM, communications, analytics, verification or support provider) is located outside the UK or uses overseas systems or sub-processors. The countries involved depend on the providers used from time to time.

Where a transfer is a restricted transfer under the UK GDPR, we will ensure that an appropriate transfer mechanism is in place. This may include UK adequacy regulations; appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or approved Binding Corporate Rules; or, in limited circumstances, a specific legal exception. Where appropriate safeguards are used, we will complete the required transfer risk assessment/data protection test and apply any additional contractual, technical or organisational measures identified as necessary.

You may contact compliance@ukadviser.co.uk for further information about the countries to which your personal data is transferred and to request information about, or a copy of, the safeguards used for a particular restricted transfer.

How we protect your personal data

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure, access or destruction. These measures include access controls, supplier due diligence and contractual protections, staff controls and training, secure storage and transmission measures where appropriate, and retention and disposal controls. We review security measures in light of the nature of the information and the risks involved.

What are your data protection rights and choices?

Your rights depend on the circumstances and lawful basis used. They are not all absolute, but may include:

  • Right to be informed – the right to receive clear information about how we collect and use your personal data.
  • Right of access – the right to ask whether we process your personal data and to receive a copy of it together with supplementary information.
  • Right to rectification – the right to have inaccurate personal data corrected and incomplete data completed.
  • Right to erasure – the right to ask us to delete personal data in circumstances where the law requires or permits erasure.
  • Right to restriction – the right to ask us to restrict use of your personal data in certain circumstances.
  • Right to data portability – where applicable, the right to receive personal data you provided to us in a structured, commonly used and machine-readable format and to ask us to transmit it to another controller.
  • Right to object – you may object to processing based on legitimate interests in certain circumstances. You have an absolute right to object at any time to the use of your personal data for direct marketing, including related profiling.
  • Rights relating to significant solely automated decisions – where we make a decision based solely on automated processing which has legal or similarly significant effects on you, we will apply the safeguards required by law. These include providing information about the decision and enabling you to make representations, obtain human intervention and challenge the decision. Stricter rules apply where special category data is used.
  • Right to withdraw consent – where we rely on consent, you may withdraw it at any time as easily as you gave it.

If a right does not apply because of the lawful basis, an exemption or another legal requirement, we will explain this when we respond to your request.

We will respond to rights requests without undue delay and normally within one month. Where permitted by law, we may extend the period by up to a further two months if a request is complex or you have made a number of requests; if so, we will tell you within the first month. Rights requests are normally free of charge, although the law permits a reasonable fee or refusal in limited circumstances, for example where a request is manifestly unfounded or excessive. Contact compliance@ukadviser.co.uk to exercise your rights.

For further information about our use of personal data, international-transfer safeguards, security measures or your rights, email compliance@ukadviser.co.uk or call 03300 881494.

How long is your data kept?

We keep personal data only for as long as it is reasonably necessary for the purpose for which it was collected and to meet legal, regulatory, accounting, fraud-prevention, complaint-handling and limitation requirements. Retention periods vary according to the type of record, the product or service and the applicable legal or regulatory requirement. We take account of the duration of our relationship with you, FCA record-keeping rules, anti-money laundering requirements, the possibility of complaints or legal claims, and whether information is needed to demonstrate that we have treated customers fairly.

Customer due-diligence and transaction records that fall within the Money Laundering Regulations are generally retained for five years from the end of the business relationship or completion of the relevant transaction, subject to the specific rules and any lawful reason requiring longer retention. Other records may have shorter or longer periods. Where information is retained solely for research or statistical purposes, we will apply appropriate safeguards and use anonymised information where reasonably possible.

Credit reference agencies control their own retention periods. Credit account and default information is commonly retained on credit files for periods set by the CRA and applicable industry rules. You should refer to the relevant CRA privacy information for its current retention periods.

You may contact us if you would like further information about the retention period that applies to a particular category of personal data.

Marketing

We may send service, regulatory and customer-support communications where they are necessary to provide our services, meet legal or regulatory obligations or support customers throughout the relationship. These communications are not treated as direct marketing where their content and purpose are genuinely service or regulatory in nature, and you may continue to receive them even if you opt out of marketing.

For direct marketing, we comply with the UK GDPR, Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR). Depending on the communication and recipient, we may rely on consent or legitimate interests. For unsolicited marketing by email or text to individual subscribers, we will obtain consent unless the legal requirements of the products-and-services soft opt-in are met. We will not rely on the soft opt-in for contact details obtained from a third party.

Every electronic marketing message will provide a clear way to opt out. You can also opt out at any time by contacting compliance@ukadviser.co.uk. Withdrawing marketing consent or objecting to direct marketing will not affect service or regulatory communications that we still need to send.

We will not disclose your personal data to another organisation for that organisation's own electronic marketing unless we have a lawful basis and, where PECR requires it, your specific valid consent.

Changes to our privacy policy

We keep this Privacy Notice under regular review and will update it when our processing changes or when legal or regulatory requirements change. Where a change materially affects how we use your personal data, we will take appropriate steps to bring the change to your attention before the new processing begins. This Privacy Notice was last updated on 14 September 2026.

How to contact us

If you have any questions about this Privacy Notice, the personal data we hold about you, or you would like to exercise a data protection right or make a data protection complaint, please contact us.

  • Email us at: compliance@ukadviser.co.uk
  • Call us: 03300881494
  • Or write to us at: Unit 1a, Link 665 Business centre, Todd Hall Road, Rossendale, BB4 5HU

How to make a complaint and contact the appropriate authority

If you believe we have not handled your personal data in accordance with data protection law, you can make a data protection complaint to us by emailing compliance@ukadviser.co.uk, calling 03300 881494 or writing to the address above. We will facilitate your complaint, acknowledge receipt within 30 days, take appropriate steps to investigate it without undue delay, keep you informed as appropriate and tell you the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. The ICO can be contacted through its online complaint service, by telephone on 0303 123 1113, or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. The ICO will usually expect you to have raised the matter with us first.

Your Privacy Matters

The UK Adviser Group uses cookies to ensure our websites function correctly, improve your browsing experience and, with your consent, help us understand how our websites are used. You can accept all cookies, reject non-essential cookies or manage your preferences at any time. For more information, please read our Cookie Policy and Privacy Policy.