Privacy Policy

Learn how Buy to Let protects and processes your personal data in compliance with the UK GDPR and the Data Protection Act 2018.

01. Introduction

At Buy to Let, we take the privacy and security of your personal data seriously. This Privacy Policy outlines how we collect, store, process, and protect your information when you visit our website, submit inquiries, or use our premium property financing advisory services.

We operate as a data controller for the information you share with us. We ensure that your data is handled strictly in accordance with UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other relevant UK financial and data privacy laws.

02. Information We Collect

We may collect, use, and process different types of personal data about you to fulfill your inquiries and structure appropriate property financing recommendations, including:

  • Identity Data: Full name, title, and business entity details.
  • Contact Data: Telephone number, email address, and home or office address.
  • Financial & Portfolio Data: Estimated property values, targets for Loan to Value (LTV), portfolio details (such as current number of holdings, SPV structures, and rental yields), income details, and borrowing requirements.
  • Technical & Usage Data: Internet Protocol (IP) address, browser details, page interaction data, and session activity collected through cookies and website analytics.

03. How We Use Your Data

We process your personal information only to support our operations and provide exceptional wealth financing partners and advisory services. Specifically, we use your data to:

  • Respond to your initial finance inquiries and callback requests.
  • Assess your eligibility for specialist buy-to-let, bridging, HMO, or residential mortgages.
  • Match your borrowing profiles with our network of 90+ lenders, commercial funds, private banks, and boutique institutions.
  • Coordinate legal documentation pipelines with solicitors, underwriters, and appraisers.
  • Maintain high regulatory compliance under our Financial Conduct Authority (FCA) standard frameworks.
  • Improve our website's user interface, performance, and client-centric execution.

05. Sharing Your Information

We do not sell or rent your personal information. To secure the premium rates and bespoke financial structures you request, we may share your data with:

  • Mortgage Lenders & Private Banks: Selected off-market boutique funds, private lenders, and institutions to secure Agreements in Principle and formal mortgage offers.
  • Solicitors & Underwriters: Directly coordinated legal counselors and internal credit analysts to accelerate time-to-exchange.
  • Regulatory & Legal Authorities: The Financial Conduct Authority (FCA), anti-fraud networks, or law enforcement agencies where legally mandated.
  • Technology Partners: Regulated CRM, secure hosting, and communication platforms (such as menetalk chat, CRM tools, or lead intake processors) operating under strict data processor contracts.

06. Data Security

To prevent unauthorized access, alteration, disclosure, or loss of your personal information, we implement advanced technical and organizational security controls, including:

  • SSL/TLS encryption for all data in transit across our website and forms.
  • Restricted access control so that only authorized personnel can view sensitive financial records.
  • Secure database environments and continuous performance monitoring.
  • Regular security training for our staff and strict verification procedures for anyone requesting account access.

07. Data Retention

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, compliance, or regulatory reporting requirements.

For mortgage applications and advisory clients, UK financial regulators require us to keep client records for specified periods (typically six years following the end of the customer relationship) to maintain regulatory compliance.

08. Your Legal Rights

Under UK data protection laws, you possess the following rights in relation to your personal data:

  • Right of Access: Request a copy of the personal information we hold about you.
  • Right to Rectification: Request correction of any inaccurate or incomplete personal records.
  • Right to Erasure (Right to be Forgotten): Request deletion of your data when there is no compelling regulatory or legal reason for us to continue processing it.
  • Right to Restrict or Object to Processing: Limit how we process your personal data under certain conditions.
  • Right to Data Portability: Request transmission of your personal data to another service provider in a structured, machine-readable format.

To exercise any of these rights, please contact our data compliance desk using the details in Section 9. We aim to respond to all valid requests within one calendar month.

09. Contact Us

If you have any questions about this Privacy Policy, our data practices, or wish to submit a data rights request, please reach out to us: