Request a callback

Request a callback

Leave us a few brief details and we’ll be in touch to discuss your requirements within 24hrs.
This field is for validation purposes and should be left unchanged.

1. Introduction & Data Controller

Hammond Rock Ltd
Company No. 16069176
Address: 7 Clarendon Drive, Wymbush, Milton Keynes, MK8 8ED
Email: contact@hammondrock.co.uk
Telephone: 01908 972445

Hammond Rock Ltd is the data controller of the personal data you provide to us, meaning we decide how and why your personal data is processed.

If you have any questions about this policy, or our data practices, or wish to exercise your rights, you may contact us at the details above.

2. What Personal Data We Collect

We may collect, use, store and transfer different kinds of personal data about you, including:

  • Identity Data: name, title, date of birth, gender.
  • Contact Data: postal address, email address, telephone numbers.
  • Financial Data: bank account, payment card details, credit history, income, other financial information relevant to credit applications.
  • Transaction Data: details of products or services you acquire from us or lenders, and other similar information.
  • Technical / Usage Data: IP address, device identifiers, browser type and version, time zone, pages visited on our website, errors.
  • Marketing & Communications Data: your preferences in receiving marketing from us, your communication preferences.
  • Other Data: as required by law (e.g. identity checks, anti–money laundering documentation) or as needed for the finance application process.

We collect personal data:

  • Directly from you (for example, when you fill out forms, communicate with us, apply for finance).
  • From third parties (e.g. credit reference agencies, lenders, public sources).
  • Automatically, via our website (e.g. technical data, usage data).

3. Purposes & Legal Bases for Processing

We will use your personal data for the following purposes, on the legal bases set out:

Purpose 
To provide Broker Services (i.e. sourcing, quoting, applying for finance)

Legal Basis 
Performance of a contract / steps prior to contract

Additional Notes
We need your data to assess, submit proposals, and facilitate finance applications

Purpose 
To communicate with you, respond to inquiries, provide information

Legal Basis
Legitimate interests / your consent

Additional Notes
We want to maintain communication and provide updates

Purpose 
For due diligence, identity verification, credit checks, anti–money laundering checks

Legal Basis
Legal obligation / legitimate interests

Additional Notes
To comply with legal and regulatory requirements

Purpose 
To send you marketing (if you have consented)

Legal Basis
Consent

Additional Notes
You can withdraw consent at any time

Purpose 
To maintain records, audit, compliance, risk management

Legal Basis
Legitimate interests / legal obligations

Additional Notes
For our business and regulatory obligations

We do not process special category (sensitive) data (for example, health, race, religion) unless explicitly and lawfully required and you have given consent or another lawful basis applies. If we do, we will notify you at the point of collection.

4. Sharing Your Personal Data

We may share your personal data with:

  • Lenders and finance providers to whom we submit proposals.
  • Credit reference agencies and fraud prevention agencies for credit checks and due diligence.
  • Service providers and processors who support us (e.g. IT, hosting, CRM, compliance services).
  • Regulatory, law enforcement or government bodies if required by law or in connection with investigations or regulatory requests.
  • Our professional advisors (e.g. auditors, legal advisors) where needed.

Where we share your data with third parties, we require them to respect the security of your personal data and to comply with data protection law. We do not allow them to use your data for their own purposes.

If any data is transferred outside the UK Economic Area (UK-EEA), we will ensure appropriate safeguards (e.g. standard contractual clauses or other approved mechanisms) are in place.

5. Data Retention

We will retain your personal data for as long as is necessary for the purposes for which it was collected, or to comply with legal, regulatory, accounting, or reporting requirements.

Retention periods may vary depending on the type of data and purpose. For example:

  • Application / finance records: typically retained for [e.g. 7 years]
  • Marketing consent records: until you withdraw consent
  • Correspondence and complaints: [e.g. 6 years]

After the retention period ends, your data will be securely destroyed or anonymised.

6. Your Rights

Under UK GDPR and the Data Protection Act 2018, you have various rights concerning your personal data:

  • Right of access – you may request a copy of your personal data.
  • Right to rectification – you may request correction of inaccurate or incomplete data.
  • Right to erasure (right to be forgotten) – in certain circumstances you may request that we delete your data.
  • Right to restriction of processing – you may request we limit how we process your data in certain cases.
  • Right to data portability – you may ask to receive your data in a structured, commonly used, machine-readable format or have it transferred to another controller.
  • Right to object – to processing based on legitimate interests or direct marketing (you may withdraw consent for marketing at any time).
  • Rights in relation to automated decision-making and profiling – where applicable, you may ask that significant decisions not be taken solely by automated means.
  • Right to withdraw consent – if any processing was based on consent, you can withdraw it at any time (this will not affect processing done before withdrawal).
  • Right to lodge a complaint – you have the right to complain to the Information Commissioner’s Office (ICO).

If you wish to exercise any of these rights, please contact us (see contact details above). We will respond within the timeframes required by law (normally one month, extendable in certain cases).

7. Security & Safeguards

We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, alteration or destruction. These measures include:

  • Encryption, secure servers, access controls.
  • Regular security testing, audits, staff training.
  • Restricting access to personal data on a “need to know” basis.
  • Ensuring our service providers and processors follow strict security standards.

Despite our efforts, no security system is completely foolproof. If a personal data breach occurs which is likely to result in a risk to your rights, we will notify you and the ICO as required by law.

8. Cookies & Tracking Technologies

Our website may use cookies, web beacons, analytics tools, and similar technologies to collect Technical / Usage Data (e.g. IP addresses, browser type, pages visited).

We use these tools for:

  • Functionality of the site
  • Performance monitoring and analytics
  • Improving user experience
  • Marketing and advertising (if consented)

You should see a cookie banner or preferences tool when first visiting. You may control or disable cookies via your browser or our cookie consent settings. Note that disabling certain cookies may affect site functionality.

9. Changes to This Policy

We may update this Privacy Policy from time to time (e.g. as practices change or legislation updates). When we do, we will post the revised version on our website and indicate a new “last updated” date.

If changes are material, we may notify you (e.g. via email) if we have your contact details.

10. Third-Party Links

Our website may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party sites. We encourage you to read the privacy policies of those third parties before providing personal data.

11. Contact & Complaints

If you have any questions, requests, or complaints concerning this policy or how we handle your personal data, contact us at:

Hammond Rock Ltd
7 Clarendon Drive, Wymbush, Milton Keynes, MK8 8ED
Email: contact@hammondrock.co.uk
Telephone: 01908 972445

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Website: https://ico.org.uk

Telephone: 0303 123 1113