Privacy Policy

1. Policy Statement

This Privacy Policy explains how CrowdProperty Ltd (“CrowdProperty”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you use our peer-to-peer lending platform, visit our website, apply to borrow, invest through us, contact us, or work with us as a business contact or adviser.

  • We are the data controller for most personal data we use about investors, borrowers, website users, prospective customers and business contacts.
  • We use personal data to provide and administer accounts, assess borrower and project risk, meet financial crime and regulatory obligations, operate our platform, protect our systems, provide support and, where permitted, send marketing.
  • We only share personal data where necessary, such as with payment providers, investor administration providers, credit reference and fraud prevention agencies, professional advisers, regulators, HMRC, law enforcement and IT/cloud suppliers.
  • We may use AI and automated technologies to support operational tasks, but we do not use AI as the sole basis for decisions that have legal or similarly significant effects on you.
  • You have rights over your personal data, including rights to access, correct, delete, restrict or object to certain uses of it, and to complain to the Information Commissioner’s Office (ICO).

2. Who we are and how to contact us

CrowdProperty Ltd operates a peer-to-peer lending platform that connects investors with property developers seeking funding. We are regulated in the UK and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Contact point

Details

Data controller

CrowdProperty Ltd

Registered address

Crowd Property Ltd, Quadrant Court, 49 Calthorpe Road, Birmingham, B15 1TH

Privacy contact / Data Protection Officer

[email protected]

3. Scope

  • This policy applies to personal data we use about:
  • retail and institutional investors;
  • borrowers, including property developers and, where relevant, their directors, owners, guarantors, beneficial owners or connected parties;
  • website users and prospective customers;
  • business partners, introducers, professional advisers and supplier contacts.


4. Personal data collection and usage

Source

Examples of personal data

Information you give us

Name, date of birth, address, email address, telephone number, identity documents, bank details, source of funds information, income or financial information, account credentials, borrower application information, investment preferences and instructions.

Information created through your use of our platform

Account activity, investment activity, transaction history, payment and repayment records, communications with us, customer support records, login activity and platform interactions.

Information collected automatically

Device and technical data such as IP address, browser type, usage data, cookies and analytics data. For more information, please see our Cookie Notice or cookie settings where available.

Information from third parties

Credit reference agencies, fraud and anti-money laundering screening providers, public registers such as Companies House and HM Land Registry, professional advisers, introducers, payment providers and other parties involved in lending or borrowing activity.

5. How and why we use personal data

We only use personal data where we have a lawful basis under data protection law. The table below summarises the main purposes and lawful bases.

Purpose

Types of data used

Lawful basis

Create and manage your account

Identity, contact, account and credential data

Contract; legitimate interests

Facilitate lending and borrowing activity

Investment activity, borrower application data, financial information, transaction records and communications

Contract; legitimate interests

Process payments, repayments and investor returns

Bank details, payment records, transaction history and account information

Contract; legal obligation; legitimate interests

Carry out Know Your Customer (KYC), anti-money laundering (AML), fraud prevention and sanctions checks

Identity documents, date of birth, address, source of funds, screening results and public register information

Legal obligation; legitimate interests

Assess borrower creditworthiness, project risk and underwriting requirements

Borrower financial information, property/project information, credit reference data, Companies House and Land Registry information

Legitimate interests; legal obligation where applicable

Administer loans throughout their lifecycle

Borrower and investor account data, loan records, communications, repayment records and enforcement-related information where relevant

Contract; legitimate interests; legal obligation

Operate, secure and improve our platform

Device data, login data, usage data, security logs and support records

Legitimate interests; legal obligation where applicable

Provide customer support and respond to enquiries

Contact details, account information, communications and support records

Contract; legitimate interests

Meet regulatory, tax, audit, accounting and record-keeping requirements

Account, transaction, identity, financial, communications and compliance records

Legal obligation; legitimate interests

Send marketing and manage cookie preferences

Contact details, marketing preferences, cookie and analytics data

Consent where required; legitimate interests for certain business communications where permitted


Where we rely on legitimate interests, these may include operating and securing our platform, assessing borrower and project risk, preventing fraud, supporting customers, improving our services, managing our business and protecting our legal rights. We balance these interests against your rights and freedoms.

6. How our platform uses personal data

As a peer-to-peer lending platform, investors lend funds to borrowers through our electronic platform. We use personal data to assess borrower applications and project risk, make investment opportunities available, match and administer lending activity, process payments and repayments, and manage loans throughout their lifecycle.

This may involve controlled sharing of relevant information between investors, borrowers and other parties where necessary, lawful and proportionate. We apply appropriate safeguards and only share the information needed for the relevant purpose.

7. Who we share personal data with

We share personal data only where necessary and subject to appropriate safeguards. Recipients may include:

  • Goji – investor administration services, including IFISA, pension and wallet administration;
  • Modulr – payment services and regulated e-money infrastructure;
  • Lloyds Bank – banking services, including client and operational accounts;
  • credit reference agencies and fraud prevention agencies;
  • legal, audit, tax, compliance and other professional advisers;
  • IT, security, analytics, cloud hosting and platform service providers;
  • regulators, HMRC, courts, law enforcement agencies and other public authorities where required or permitted by law;
  • other parties involved in a loan, transaction, enforcement process, corporate restructuring or business transfer, where lawful and necessary.

Where suppliers process personal data for us, we put appropriate contracts in place requiring them to protect the data, use it only for agreed purposes, keep it confidential and apply suitable security measures.

8. International transfers

Some suppliers or systems may process or access personal data from outside the UK. Where this happens, we use appropriate safeguards required by data protection law. These may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or equivalent legal protections.

9. How we protect personal data

We use appropriate technical and organisational measures to protect personal data.

  • encryption of data in transit and at rest where appropriate;
  • role-based access controls and authentication;
  • security monitoring, logging and system controls;
  • staff training and confidentiality obligations;
  • supplier due diligence and contractual controls;
  • procedures to detect, investigate and report personal data breaches where required.


10. How long we keep personal data

We keep personal data only for as long as necessary for the purposes described in this notice, including to meet legal, regulatory, tax, accounting, audit, dispute management and operational requirements. Retention periods vary depending on the type of data and the nature of your relationship with us.

Data type

Typical retention approach

Investor and borrower account, transaction and loan records

Usually retained for the relationship and typically 5–7 years after the end of the relationship, or longer where required for legal, regulatory, tax, audit, dispute or enforcement purposes.

KYC, AML, fraud prevention and compliance records

Retained for periods required by financial crime, regulatory and record-keeping laws, typically 5–7 years after the relationship ends, unless a longer period is required.

Website analytics and cookie data

Kept in line with our cookie settings and analytics retention periods.

Marketing preferences

Kept while you receive marketing and for a reasonable period afterwards to maintain suppression records and respect opt-out choices.

Customer support and complaint records

Kept for the time needed to manage the query or complaint and meet regulatory, audit or legal requirements.

 

When personal data is no longer needed, we securely delete, anonymise or archive it in line with our retention and disposal processes. Physical records are securely destroyed where applicable.

11. AI and automated technologies

We may use AI and automated technologies to help our teams work more efficiently, for example by reviewing documents, extracting information, identifying fraud indicators or supporting risk analysis. These tools support human review and decision-making. We do not use AI as the sole basis for decisions that have legal or similarly significant effects on you.

Our safeguards include:

  • human oversight and review of AI-supported outputs where the output is used to support a decision or customer outcome;
  • not using AI as the sole basis for decisions that have legal or similarly significant effects on you;
  • data protection, security and supplier assessments before using AI tools;
  • using only the personal data that is necessary for the relevant purpose;
  • not using personal data to train AI models unless we have a lawful basis and appropriate safeguards;
  • contractual controls with AI and technology providers where they process personal data for us.

If we introduce automated decision-making that has a legal or similarly significant effect on you, we will provide the information required by data protection law, including details of the logic involved, the significance and likely consequences, and your rights.

12. Your rights

Depending on the circumstances, you may have the right to:

  • ask for access to your personal data;
  • ask us to correct inaccurate or incomplete personal data;
  • ask us to delete personal data in certain circumstances;
  • ask us to restrict how we use personal data;
  • object to certain uses of personal data, including some uses based on legitimate interests and direct marketing;
  • ask for data portability where the right applies;
  • withdraw consent where we rely on consent, such as for certain marketing or non-essential cookies;
  • not be subject to a decision based solely on automated processing where that decision has legal or similarly significant effects;
  • complain to the Information Commissioner’s Office (ICO).

To exercise your rights, contact [email protected]. We may need to verify your identity before responding. Some rights are not absolute and may be subject to legal or regulatory limits, for example where we need to keep records for financial crime, regulatory, tax, audit, legal claim or fraud prevention purposes.

We will usually respond to a request within one month. If a request is complex or we receive multiple requests, we may extend this period where permitted by law and will let you know.


13. Marketing and cookies

Where required, we will ask for your consent before sending marketing or placing non-essential cookies. You can withdraw consent or change your preferences at any time using the unsubscribe link in our emails, your account settings, cookie settings, or by contacting us. We may still send service or transactional messages that are necessary to administer your account or comply with legal obligations.

14. Complaints

If you have concerns about how we use your personal data, please contact us first at [email protected] so we can try to resolve the issue. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. You can contact the ICO at www.ico.org.uk or by calling 0303 123 1113.

15. Changes to this notice

We may update this Privacy Policy  from time to time. The latest version will be made available on our website or through the platform. If we make material changes, we will take appropriate steps to bring them to your attention.

16. Glossary of Terms

Term

Meaning

AI / Artificial Intelligence

Technology that can analyse information, identify patterns, generate outputs or support tasks that would normally require human judgement.

AML / Anti-Money Laundering

Checks and processes designed to prevent financial crime and money laundering.

Anonymised data

Information that can no longer identify an individual and cannot reasonably be linked back to them.

Automated decision-making

A decision made by technology without meaningful human involvement.

Borrower

A property developer, company director, owner or related party applying for or receiving funding through the platform.

Consent

A lawful basis used where someone has clearly agreed to a specific use of their personal data, such as certain marketing or non-essential cookies.

Cookies

Small files placed on a device to help a website work, remember preferences or collect analytics information.

Credit reference agency

An organisation that provides credit, identity, fraud prevention and financial history information.

Data controller

The organisation that decides why and how personal data is used.

Data processor

A supplier or service provider that uses personal data on CrowdProperty’s instructions.

Data Protection Act 2018

The UK law that supplements and applies the UK GDPR.

Data Protection Officer / DPO

The person or function customers can contact about privacy questions or rights requests.

Data subject

The individual whose personal data is being used.

ICO / Information Commissioner’s Office

The UK regulator for data protection and privacy rights.

IFISA

Innovative Finance Individual Savings Account, a tax-efficient investment account used for certain peer-to-peer lending investments.

Institutional investor

An organisation, fund or professional investor investing through the platform.

International transfer

Making personal data available to an organisation outside the UK.

Investor

A person or organisation that lends funds through the platform.

KYB / Know Your Business

Checks carried out on companies and business ownership/control for onboarding, risk and financial crime purposes.

KYC / Know Your Customer

Identity and verification checks used to confirm who a customer is and assess financial crime risk.

Lawful basis

A valid legal reason under UK data protection law for using personal data.

Legitimate interests

A lawful basis used where the company or another party has a genuine reason to use data, and this is not overridden by the individual’s rights and interests.

PEP / Politically Exposed Person

Someone who holds, or has held, a prominent public role, or is closely connected to someone who does; PEP checks are used for financial crime controls.

Personal data

Any information that identifies, or can be linked to, an individual, such as name, contact details, identity documents, account activity or payment details.

Platform

CrowdProperty’s online service used by investors and borrowers to manage lending, borrowing, payments and related activity.

Processor / sub-processor

A processor uses personal data for CrowdProperty; a sub-processor is another supplier used by that processor to help provide the service.

Profiling

Using personal data to evaluate or predict things about a person, such as risk, behaviour or preferences.

Retention period

How long personal data is kept before it is deleted, anonymised or archived.

Special category data

More sensitive personal data, such as health, racial or ethnic origin, biometric data, religion, trade union membership or sexual orientation.

UK GDPR

The UK General Data Protection Regulation, the main UK data protection law governing how personal data is used.

Underwriting

Assessing a borrower, property project and related risks before deciding whether and how to fund a loan.

Wallet

An account or facility used to hold and move investor funds on or in connection with the platform.


Download the CrowdProperty Privacy Policy.