Aro Money Data Privacy & Protection
- Aro Money
- The kind of personal data we collect & what we do with it
- Where do we collect your data from
- Who do we share your data with
- Transfers within the EEA and outside the EEA
- Data Security
- Your data rights
- How to make a data related complaint
1. Aro Money
1.1 ‘We’ Aro Money Limited t/a ‘Aro Money’.
1.2 We act as an Apppointed Representative of Aro Finance Limited who are authorised by the Financial Conduct Authority
1.3 We operate from and are registered at: Dakota House, Concord Business Park, Simonsway Manchester M22 0RR.
1.4 We are registered with the Information Commissioners Office (‘ICO’) ZB359170 and regulated by them for the purposes of data protection.
1.5 Our mortgage services are in relation to advice relating to second charge mortgages also known as a “secured loan” or “homeowner loan”.
1.6 We act as a mortgage intermediary (broker) and not a lender. We are paid for loan completions and subsequently paid out to the customer only. Check out our scope of service for further information.
2. The kind of personal data we collect & what we do with it
2.1 In order to offer our services, we have to collect data from you, including personal and in some cases sensitive data also known as ‘special category’.
2.2 Set out below, are the kinds of data we collect, for what purpose it is collected and the lawful basis*:
Purpose | Data we process | Lawful basis | Retention of data |
To offer our services as set out in 1.5 and 1.6 above. | Full name; previous name; age; DOB; marital/ relationship status; residential address; dependents; employment status and employer; Financial information (where applicable) for you and any financial associates including bank statements; payment card details; current debts; financial commitments; savings; income & expenditure and in some instances health conditions. In addition we may also request and store copies of your credit reference check, driving licence, proof of address and residency or Passport, marriage certificate or where applicable, probate documentation. Status of property including valuation and land registry details. (‘mortgage application data’) | Performance of a contract Legal obligation explicit consent | 6 years from the date you provided your information. |
Marketing our own products and services by way of email and or SMS as well as provide you with alerts such as when we believe there is another suitable product you could apply for. | Email address and telephone number. | Soft opt in | On-going, unless withdrawn or no contact in the past 12 months. |
Marketing our partner, Cream | Name, email address, telephone number and loan details | Consent | 6 years |
Service communications | Email address, telephone number and where specified, address. | Performance of a contract. Legal obligation. | 6 years from the date you provided your information and where relevant. |
Call recordings | All calls and their contents to Aro Money will be recorded. | Regulatory and Legal requirements | 6 years from the date you provided your information. |
*Lawful basis: The UK Data Protection Act tells us we must have a lawful basis as to why we collect data and process it
3.Where do we collect your data from
3.1 Most of the personal information we collect and process is provided to us directly by you.
3.2 We will receive information from credit reference agencies and fraud prevention agencies, Aro Money also uses soft searches to work out whether you’re eligible for a product this includes checking any outstanding credit, defaulted payments or anything else relevant to the lending criteria and to ensure any product/s offered are suitable and affordable.
3.3 We may also receive personal information indirectly from third party firms you may have contacted directly and provided your consent to share your data with. For example, from a comparison site such as our sister company, Aro or another mortgage broker.
4. Who do we share your data with
Data Processors
4.1 Companies such as us, may use third parties to help them with things they are unable to do. These companies are referred to as data ‘Processors’. Processors can only do what the company (data Controller) has told them to do with the data, unless a legal exemption applies.
4.2 Listed below, are the names of the Processors we work with in the capacity set out above, along with some other important information we think you should know:
Name of third party Processor | What data we share | Why we share it | Lawful basis | Retention of data |
NIVO | Mortgage application data Written communications throughout the application journey Correspondence from the lender where we have made a personal recommendation and where you have consented to proceed. | For the purposes of fulfilling the secured loan. | Performance of a contract. Legal obligation | 6 years from the data collected. |
Blueshift Inc. | Mortgage application data | We use Blueshift as a database in which it both houses your customers marketing preferences including opt in and opt out as well as aiding with our internal marketing and servicing strategies. | Performance of a contract | 6 years or on-going where not opted out from marketing. |
Equifax | Mortgage application data | To undertake a soft credit check. | Legal obligation | 6 years |
Surveyor/s – Aro Money works with 2 different surveying companies. Details of which will be provided to you as and when applicable. | Full name; address and contact details. | To undertake a survey of the property in which the application is associated with. | Performance of a contract | 6 years |
Valuation company/ies – Aro Money works with 2 different valuation companies. Details of which will be provided to you as and when applicable. | Full valuation: Full name; address and contact details. Drive by valuation: Full Name and Address. | To undertake a valuation of the property in which the application is associated with. | Performance of a contract | 6 years |
(Where applicable, Courier) FieldConnect Limited | Full Name; address and contact details. | Upon the request of the customer, to collect mortgage related paperwork from the customers address in which it is returned to us in order to further facilitate the application. | Consent | 6 years |
Connex One | Mortgage application data Voice recordings | For the purposes of operating our Solutions Centre and Compliance purposes. | Legal obligation | 6 years |
Data Controllers
4.3 In addition to the Processors above; we also share information with third parties for other reasons, please see below. These are known as joint Controllers or simply, data’ Controllers’ and so process data jointly with us for the purposes of the services set out above, yet may also process your data for their own purposes. For example, the Police may request data from us, then further process it as part of a criminal investigation.
4.4 Listed below, are the names of the Controllers we work with in the capacity set out above, along with some other important information we think you should know:
Name of third party | What data we share | Why we share it | Lawful basis | Retention of data |
Those who make up the panel of mortgage lenders. Note, this is only applicable where Aro Money has provided advice and made a personal recommendation in which case, full disclosure of the lender/s will then be provided. | Mortgage application data Surveyor report Valuation report | To facilitate your request and subsequent application for a secured loan. | Performance of a contract. | 6 years or longer where retained for marketing purposes. |
Third parties performing roles in fraud prevention and credit reference agencies | Mortgage application data. | For product development purposes and to evaluate new products and services | Legitimate interest | 6 years |
Regulators: ICO; FCA; ASA | Any data concerned with any visitor to our site. This may include those who took out products via our platform or those who merely entered partial details then left the site. This further includes customers who received advice from us. | To comply with the legal requirements placed on us as a regulated company. | Legal obligation | NA |
Law enforcement: NCA; Police | The same as the above. | To assist with criminal investigations. | Legal obligation | NA |
Credit Reference Agencies: Equifax | Cookies served by Equifax are held on Aro’s website. Equifax is a consumer credit reporting agency. These cookies will be used to serve adverts to visitors based upon the websites they’ve been to previously. | To serve adverts based on previous history | Legitimate intertest | 5 years |
5.Transfers within the EEA and outside the EEA
5.1 Whilst the majority of the data we process is within the EEA, we do use Processors whose head offices are based outside the EEA including the USA. This means we are to take extra assurance prior to any data transfers.
5.2 Should you wish to review your safeguards please contact us on the details below.
6. Data Security
How we store your personal information
6.1 All information you provide to us is stored on our secure servers. We take all reasonable steps to maintain the security of your data, and we are ISO27001 certified.
6.2 Whilst we do our best to protect your personal data; we cannot guarantee the security of your data transmitted within our systems, any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access, loss or damage.
7. Your data rights
7.1 Under data protection law, you have rights including:
Your right to be informed – You have the right to know what we do with any data you provide us or that we collect from you or other sources.
Your right of access – You have the right to ask us for copies of your personal information.
Your right to rectification – You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances.
Your right to restriction of processing – You have the right to ask us to restrict the processing of your personal information in certain circumstances. You also have the right to object to the processing of your personal information in certain circumstances.
Your right to not be subject to automated decision-making – You have the right not to be subject to automated decision-making yet for some services this may mean we are unable to fulfil your objectives.
Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
7.2 You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
8.How to make a data related complaint
8.1 If you have any concerns about our use of your personal information, you can contact us using any of the following –
Phone: 0161 498 7739
Email: complaints@aro.co.uk
Post: Aro Complaints, Dakota House, Concord Business Park, Simonsway, Manchester M22 0RR
8.2 You can also complain to the ICO if you are unhappy with how we have used your data:
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO Website: www.ico.org.uk