Privacy Policy

Mortgage Advice Bureau Limited. Registered Office: Capital House, Pride Place, Derby DE24 8QR. Registered in England Number: 3368205

Mortgage Advice Bureau (Derby) Limited. Registered Office: Capital House, Pride Place, Derby DE24 8QR. Registered in England Number: 6003803

Both companies known together in this document as "Mortgage Advice Bureau", "we" and "us".

As the controller of your data, Mortgage Advice Bureau comply with Data Protection laws in the United Kingdom and the EU General Data Protection Regulation (GDPR). This Privacy Policy details how Mortgage Advice Bureau processes your personal data.

The personal data we collect about you

Personal data collected, used, stored and transferred by us may include:

  • Identity Data including forenames, last name, maiden name, date of birth, gender, marital status, and username or similar identifier
  • Contact Data including home address, email address and telephone numbers
  • Financial Data including bank statements, payment card details, savings, debts such as loans and credit cards, income & expenditure, employer & pension benefits, and other assets
  • Special Category Data specifically medical history
  • Transaction Data including payments made for products and services you have purchased from us
  • Technical Data including internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices used to access the Mortgage Advice Bureau website
  • Profile and Usage Data including purchases made by you, feedback and survey responses, and how you use our website, products and services
  • Marketing and Communications Data including your preferences in receiving marketing from us and our business partners and your communication preferences

How do we collect your personal data?

Personal data is collected by us using the following methods:

  • Direct interactions with an adviser in person, by post, phone (including call recordings and voicemail), email, videoconferencing or otherwise when sourcing and applying for mortgage or protection products.
  • Automated technologies or technical interactions with our website, via the customer portal, by using the web enquiry form or the Find A Mortgage function.
  • Third parties or publicly available sources such as estate agents (with your consent), new home builders (legitimate interest to assess affordability), enquiries on third-party mortgage sourcing websites, and your financial information from your bank via credit bureau providers and Open Banking with your consent.

How do we use your personal data?

Purpose / ActivityType(s) of dataLawful basis for processing
To initially engage with you via a website, estate agent, new home builder, the home buying app or in person to discuss your requirements, and any on-going communications until you are ready to proceedIdentity; ContactConsent
To source products, provide indicative quotes, and process & deliver your application for a mortgage or protection product as part of the advice processIdentity; Contact; Financial; Transaction; Marketing & Comms; Special CategoryPerformance of a contract with you. Special Category data – Explicit Consent (medical information for protection policies).
To comply with FCA rules including record keeping, consumer duty, vulnerable customers, and to meet Anti Money Laundering legislationIdentity; Contact; Financial; Transaction; Special CategoryTo comply with a legal obligation. Special Category – Substantial Public Interest.
To create and maintain access to the My Mortgage Account portal and the Home Owner / Home Buyer appsIdentity; Contact; Profile & Usage; Marketing & CommsPerformance of a contract with you
To manage our client relationship with you including re-engagement when existing products near expiryIdentity; Contact; Profile & Usage; Marketing & CommsNecessary for our legitimate interests
To perform customer service and satisfaction surveys for recently completed transactionsIdentity; ContactConsent
To respond to case enquiries and input to & defend against complaintsIdentity; Contact; Profile & Usage; Transaction; Marketing & Comms; Special CategoryNecessary for our legitimate interests. Special Category – Legal Claims & Judicial Acts.
To perform an affordability check for a property on behalf of an Estate Agent or New Home BuilderIdentity; Contact; FinancialNecessary for our legitimate interests
To record appointments to perform checks on the quality of advice our advisers provideIdentity; Contact; Special CategoryConsent. Special Category – Explicit Consent.
To administer and protect our business and our websiteIdentity; Contact; TechnicalNecessary for our legitimate interests
To deliver relevant website content and advertisements and measure their effectivenessIdentity; Contact; Profile & Usage; TechnicalNecessary for our legitimate interests
To use cookies, data analytics and other systems to improve our website, products/services and marketingIdentity; Technical; Profile & UsageConsent / Explicit Consent
To generate reports on business activity for performance and capacity planningIdentity; Contact; Financial; TransactionNecessary for our legitimate interests
To perform internal audits by third party auditors across the organisationIdentity; Contact; FinancialTo comply with a legal obligation
To use systems including AI and automated decision making to support our services (document validation, affordability and product sourcing)Identity; Contact; FinancialPerformance of a contract with you

We only use your personal data for the purposes stated above, unless we reasonably consider that we need to use it for another reason and it is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so.

Changes to our Privacy Notice

We keep our Privacy Notice under regular review. This Privacy Notice was last updated on 17th March 2025. Historic versions can be obtained by contacting us.

Use of AI and Automated Decision Making

We use AI and automated decision-making systems to assist the adviser to assess your affordability and source suitable products as part of the contract to provide advice. Any results obtained from these automated decision making systems are subject to review by the adviser, i.e. product sourcing is not solely reliant on the automated decisions. This processing is performed under UK GDPR Article 22(2)(a). We also use AI for identity verification to meet our legal requirement in terms of anti money laundering. This processing is performed under UK GDPR Article 22(2)(b). We use AI to assess and support our Complaints Team when investigating and responding to complaints.

Marketing communications

You will also have the choice to opt-in to receiving other related marketing information and related products and services. You can opt-out of receiving these types of communications at any time by contacting your adviser, by emailing data.protection@mab.org.uk or by clicking on the relevant link in email communications you receive from us. Your personal information will not be passed to any third-party organisation for marketing purposes.

Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We also limit access to your personal data to only those Mortgage Advice Bureau staff, appointed representatives, advisers, business partners and suppliers who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required.

Cookies

When using our website, you can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.

Website third-party links

Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.

Sharing of personal data outside of the United Kingdom

Some external suppliers are based overseas so their processing of your personal data will involve a transfer of data outside of the UK. In such cases data is transferred under conditions to provide protection to personal data equivalent to UK Data Protection standards, including the use of standard contractual clauses.

Who we disclose personal data to

Type of recipientReason
Within the Mortgage Advice Bureau networkTo share your personal data with our network and with specialist product providers so suitably qualified advisers can source relevant products or re-engage with existing clients, and to obtain input from specialist trainers to improve advice quality.
Lenders and protection product suppliersTo source and submit applications, conclude the mortgage / protection contract, support ongoing servicing, quality checks, and ensure full disclosure to lenders and providers.
Financial InstitutionsTo source your bank account information via Open Banking with your consent.
External suppliersSpecialist IT system providers, payment processing, service & advice quality checking, feedback, and non-affiliated professional, legal or accounting advisers.
Housing Associations / Registered ProvidersTo confirm your identity / proof of deposit, provide application progress updates, and provide a copy of the mortgage offer to support your application.
Solicitors / ConveyancersTo update the firm of solicitors / conveyancers with whom you are interacting about the progress of your application and confirm your identity / proof of deposit.
Estate agents / new home buildersTo update them about the results of affordability checks and progress of your application.
ID verification & Licensed Credit AgenciesTo confirm your identity for Anti Money Laundering, perform a credit assessment, obtain a Lender's Decision In Principle, and as part of a full application.
RegulatorsTo fulfil our legal obligations as a regulated profession (e.g. FCA), comply with Anti Money Laundering legislation, and co-operate with law enforcement, legal proceedings or regulatory authorities.
OthersThird parties to whom we may choose to sell, transfer, or merge parts of our business. New owners may use your personal data in the same way as set out in this privacy notice.

How long is your personal data retained?

Purpose of processingRetention
Successful mortgage / protection applicationsFor the full mortgage or protection policy term (or for Lifetime mortgages, the duration of the mortgage) plus a further 6 years, or 30 years for historical cases if the original term is not recorded.
Withdrawn, stalled, incomplete and failed applications2 years from the date the latest application was started, or 6 years from the application submitted date if subsequently rejected or from creation date if advice has been provided but not pursued.
My Mortgage Account portal accounts2 years from date of last login if not proceeded to full application.
Affordability checks2 years from Decision In Principle if the check does not proceed to a full mortgage application.
Enquiry data obtained from third parties that do not result in an application2 years from the date the lead was received from the Introducer.
Mortgage Advice Bureau App data7 years from date of last login.
Video recordings of appointments used for quality checking of adviceUp to 1 month after the appointment date.

After these retention periods, if there is no other on-going client relationship your personal data will either be securely deleted or anonymised so that it can be used for statistical purposes but without any method of identifying you individually.

Your legal rights regarding your personal data

  • Request access to your personal data to receive a copy and check we are lawfully processing it.
  • Request correction of incomplete or inaccurate data.
  • Request erasure where there is no good reason for us continuing to process it (some legal exceptions apply).
  • Object to processing where we rely on a legitimate interest, or for direct marketing purposes.
  • Request restriction of processing in certain circumstances.
  • Request the transfer of your personal data to you or a chosen third party in a structured, commonly used, machine-readable format.
  • Withdraw consent at any time where we are relying on consent (without affecting prior lawful processing).

Questions

If you have any questions or complaints relating to how we use your personal data, or wish to exercise any of your rights, please contact Data.Protection@mab.org.uk or write to us. We will respond no later than one month from the initial request.

What if I am still not satisfied?

If you are not satisfied with how we have responded, you have the right to complain to the Information Commissioner's Office (ICO), the regulator for data protection in the UK.