1. Policy Statement
This Privacy Policy explains how CrowdProperty Ltd (“CrowdProperty”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you use our peer-to-peer lending platform, visit our website, apply to borrow, invest through us, contact us, or work with us as a business contact or adviser.
- We are the data controller for most personal data we use about investors, borrowers, website users, prospective customers and business contacts.
- We use personal data to provide and administer accounts, assess borrower and project risk, meet financial crime and regulatory obligations, operate our platform, protect our systems, provide support and, where permitted, send marketing.
- We only share personal data where necessary, such as with payment providers, investor administration providers, credit reference and fraud prevention agencies, professional advisers, regulators, HMRC, law enforcement and IT/cloud suppliers.
- We may use AI and automated technologies to support operational tasks, but we do not use AI as the sole basis for decisions that have legal or similarly significant effects on you.
- You have rights over your personal data, including rights to access, correct, delete, restrict or object to certain uses of it, and to complain to the Information Commissioner’s Office (ICO).
2. Who we are and how to contact us
CrowdProperty Ltd operates a peer-to-peer lending platform that connects investors with property developers seeking funding. We are regulated in the UK and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
|
Contact point |
Details |
|
Data controller |
CrowdProperty Ltd |
|
Registered address |
Crowd Property Ltd, Quadrant Court, 49 Calthorpe Road, Birmingham, B15 1TH |
|
Privacy contact / Data Protection Officer |
3. Scope
- This policy applies to personal data we use about:
- retail and institutional investors;
- borrowers, including property developers and, where relevant, their directors, owners, guarantors, beneficial owners or connected parties;
- website users and prospective customers;
- business partners, introducers, professional advisers and supplier contacts.
4. Personal data collection and usage
|
Source |
Examples of personal data |
|
Information you give us |
Name, date of birth, address, email address, telephone number, identity documents, bank details, source of funds information, income or financial information, account credentials, borrower application information, investment preferences and instructions. |
|
Information created through your use of our platform |
Account activity, investment activity, transaction history, payment and repayment records, communications with us, customer support records, login activity and platform interactions. |
|
Information collected automatically |
Device and technical data such as IP address, browser type, usage data, cookies and analytics data. For more information, please see our Cookie Notice or cookie settings where available. |
|
Information from third parties |
Credit reference agencies, fraud and anti-money laundering screening providers, public registers such as Companies House and HM Land Registry, professional advisers, introducers, payment providers and other parties involved in lending or borrowing activity. |
5. How and why we use personal data
We only use personal data where we have a lawful basis under data protection law. The table below summarises the main purposes and lawful bases.
|
Purpose |
Types of data used |
Lawful basis |
|
Create and manage your account |
Identity, contact, account and credential data |
Contract; legitimate interests |
|
Facilitate lending and borrowing activity |
Investment activity, borrower application data, financial information, transaction records and communications |
Contract; legitimate interests |
|
Process payments, repayments and investor returns |
Bank details, payment records, transaction history and account information |
Contract; legal obligation; legitimate interests |
|
Carry out Know Your Customer (KYC), anti-money laundering (AML), fraud prevention and sanctions checks |
Identity documents, date of birth, address, source of funds, screening results and public register information |
Legal obligation; legitimate interests |
|
Assess borrower creditworthiness, project risk and underwriting requirements |
Borrower financial information, property/project information, credit reference data, Companies House and Land Registry information |
Legitimate interests; legal obligation where applicable |
|
Administer loans throughout their lifecycle |
Borrower and investor account data, loan records, communications, repayment records and enforcement-related information where relevant |
Contract; legitimate interests; legal obligation |
|
Operate, secure and improve our platform |
Device data, login data, usage data, security logs and support records |
Legitimate interests; legal obligation where applicable |
|
Provide customer support and respond to enquiries |
Contact details, account information, communications and support records |
Contract; legitimate interests |
|
Meet regulatory, tax, audit, accounting and record-keeping requirements |
Account, transaction, identity, financial, communications and compliance records |
Legal obligation; legitimate interests |
|
Send marketing and manage cookie preferences |
Contact details, marketing preferences, cookie and analytics data |
Consent where required; legitimate interests for certain business communications where permitted |
Where we rely on legitimate interests, these may include operating and securing our platform, assessing borrower and project risk, preventing fraud, supporting customers, improving our services, managing our business and protecting our legal rights. We balance these interests against your rights and freedoms.
6. How our platform uses personal data
As a peer-to-peer lending platform, investors lend funds to borrowers through our electronic platform. We use personal data to assess borrower applications and project risk, make investment opportunities available, match and administer lending activity, process payments and repayments, and manage loans throughout their lifecycle.
This may involve controlled sharing of relevant information between investors, borrowers and other parties where necessary, lawful and proportionate. We apply appropriate safeguards and only share the information needed for the relevant purpose.
7. Who we share personal data with
We share personal data only where necessary and subject to appropriate safeguards. Recipients may include:
- Goji – investor administration services, including IFISA, pension and wallet administration;
- Modulr – payment services and regulated e-money infrastructure;
- Lloyds Bank – banking services, including client and operational accounts;
- credit reference agencies and fraud prevention agencies;
- legal, audit, tax, compliance and other professional advisers;
- IT, security, analytics, cloud hosting and platform service providers;
- regulators, HMRC, courts, law enforcement agencies and other public authorities where required or permitted by law;
- other parties involved in a loan, transaction, enforcement process, corporate restructuring or business transfer, where lawful and necessary.
Where suppliers process personal data for us, we put appropriate contracts in place requiring them to protect the data, use it only for agreed purposes, keep it confidential and apply suitable security measures.
8. International transfers
Some suppliers or systems may process or access personal data from outside the UK. Where this happens, we use appropriate safeguards required by data protection law. These may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or equivalent legal protections.
9. How we protect personal data
We use appropriate technical and organisational measures to protect personal data.
- encryption of data in transit and at rest where appropriate;
- role-based access controls and authentication;
- security monitoring, logging and system controls;
- staff training and confidentiality obligations;
- supplier due diligence and contractual controls;
- procedures to detect, investigate and report personal data breaches where required.
10. How long we keep personal data
We keep personal data only for as long as necessary for the purposes described in this notice, including to meet legal, regulatory, tax, accounting, audit, dispute management and operational requirements. Retention periods vary depending on the type of data and the nature of your relationship with us.
|
Data type |
Typical retention approach |
|
Investor and borrower account, transaction and loan records |
Usually retained for the relationship and typically 5–7 years after the end of the relationship, or longer where required for legal, regulatory, tax, audit, dispute or enforcement purposes. |
|
KYC, AML, fraud prevention and compliance records |
Retained for periods required by financial crime, regulatory and record-keeping laws, typically 5–7 years after the relationship ends, unless a longer period is required. |
|
Website analytics and cookie data |
Kept in line with our cookie settings and analytics retention periods. |
|
Marketing preferences |
Kept while you receive marketing and for a reasonable period afterwards to maintain suppression records and respect opt-out choices. |
|
Customer support and complaint records |
Kept for the time needed to manage the query or complaint and meet regulatory, audit or legal requirements. |
When personal data is no longer needed, we securely delete, anonymise or archive it in line with our retention and disposal processes. Physical records are securely destroyed where applicable.
11. AI and automated technologies
We may use AI and automated technologies to help our teams work more efficiently, for example by reviewing documents, extracting information, identifying fraud indicators or supporting risk analysis. These tools support human review and decision-making. We do not use AI as the sole basis for decisions that have legal or similarly significant effects on you.
Our safeguards include:
- human oversight and review of AI-supported outputs where the output is used to support a decision or customer outcome;
- not using AI as the sole basis for decisions that have legal or similarly significant effects on you;
- data protection, security and supplier assessments before using AI tools;
- using only the personal data that is necessary for the relevant purpose;
- not using personal data to train AI models unless we have a lawful basis and appropriate safeguards;
- contractual controls with AI and technology providers where they process personal data for us.
If we introduce automated decision-making that has a legal or similarly significant effect on you, we will provide the information required by data protection law, including details of the logic involved, the significance and likely consequences, and your rights.
12. Your rights
Depending on the circumstances, you may have the right to:
- ask for access to your personal data;
- ask us to correct inaccurate or incomplete personal data;
- ask us to delete personal data in certain circumstances;
- ask us to restrict how we use personal data;
- object to certain uses of personal data, including some uses based on legitimate interests and direct marketing;
- ask for data portability where the right applies;
- withdraw consent where we rely on consent, such as for certain marketing or non-essential cookies;
- not be subject to a decision based solely on automated processing where that decision has legal or similarly significant effects;
- complain to the Information Commissioner’s Office (ICO).
To exercise your rights, contact [email protected]. We may need to verify your identity before responding. Some rights are not absolute and may be subject to legal or regulatory limits, for example where we need to keep records for financial crime, regulatory, tax, audit, legal claim or fraud prevention purposes.
We will usually respond to a request within one month. If a request is complex or we receive multiple requests, we may extend this period where permitted by law and will let you know.
13. Marketing and cookies
Where required, we will ask for your consent before sending marketing or placing non-essential cookies. You can withdraw consent or change your preferences at any time using the unsubscribe link in our emails, your account settings, cookie settings, or by contacting us. We may still send service or transactional messages that are necessary to administer your account or comply with legal obligations.
14. Complaints
If you have concerns about how we use your personal data, please contact us first at [email protected] so we can try to resolve the issue. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. You can contact the ICO at www.ico.org.uk or by calling 0303 123 1113.
15. Changes to this notice
We may update this Privacy Policy from time to time. The latest version will be made available on our website or through the platform. If we make material changes, we will take appropriate steps to bring them to your attention.
16. Glossary of Terms
|
Term |
Meaning |
|
AI / Artificial Intelligence |
Technology that can analyse information, identify patterns, generate outputs or support tasks that would normally require human judgement. |
|
AML / Anti-Money Laundering |
Checks and processes designed to prevent financial crime and money laundering. |
|
Anonymised data |
Information that can no longer identify an individual and cannot reasonably be linked back to them. |
|
Automated decision-making |
A decision made by technology without meaningful human involvement. |
|
Borrower |
A property developer, company director, owner or related party applying for or receiving funding through the platform. |
|
Consent |
A lawful basis used where someone has clearly agreed to a specific use of their personal data, such as certain marketing or non-essential cookies. |
|
Cookies |
Small files placed on a device to help a website work, remember preferences or collect analytics information. |
|
Credit reference agency |
An organisation that provides credit, identity, fraud prevention and financial history information. |
|
Data controller |
The organisation that decides why and how personal data is used. |
|
Data processor |
A supplier or service provider that uses personal data on CrowdProperty’s instructions. |
|
Data Protection Act 2018 |
The UK law that supplements and applies the UK GDPR. |
|
Data Protection Officer / DPO |
The person or function customers can contact about privacy questions or rights requests. |
|
Data subject |
The individual whose personal data is being used. |
|
ICO / Information Commissioner’s Office |
The UK regulator for data protection and privacy rights. |
|
IFISA |
Innovative Finance Individual Savings Account, a tax-efficient investment account used for certain peer-to-peer lending investments. |
|
Institutional investor |
An organisation, fund or professional investor investing through the platform. |
|
International transfer |
Making personal data available to an organisation outside the UK. |
|
Investor |
A person or organisation that lends funds through the platform. |
|
KYB / Know Your Business |
Checks carried out on companies and business ownership/control for onboarding, risk and financial crime purposes. |
|
KYC / Know Your Customer |
Identity and verification checks used to confirm who a customer is and assess financial crime risk. |
|
Lawful basis |
A valid legal reason under UK data protection law for using personal data. |
|
Legitimate interests |
A lawful basis used where the company or another party has a genuine reason to use data, and this is not overridden by the individual’s rights and interests. |
|
PEP / Politically Exposed Person |
Someone who holds, or has held, a prominent public role, or is closely connected to someone who does; PEP checks are used for financial crime controls. |
|
Personal data |
Any information that identifies, or can be linked to, an individual, such as name, contact details, identity documents, account activity or payment details. |
|
Platform |
CrowdProperty’s online service used by investors and borrowers to manage lending, borrowing, payments and related activity. |
|
Processor / sub-processor |
A processor uses personal data for CrowdProperty; a sub-processor is another supplier used by that processor to help provide the service. |
|
Profiling |
Using personal data to evaluate or predict things about a person, such as risk, behaviour or preferences. |
|
Retention period |
How long personal data is kept before it is deleted, anonymised or archived. |
|
Special category data |
More sensitive personal data, such as health, racial or ethnic origin, biometric data, religion, trade union membership or sexual orientation. |
|
UK GDPR |
The UK General Data Protection Regulation, the main UK data protection law governing how personal data is used. |
|
Underwriting |
Assessing a borrower, property project and related risks before deciding whether and how to fund a loan. |
|
Wallet |
An account or facility used to hold and move investor funds on or in connection with the platform. |
Download the CrowdProperty Privacy Policy.