Why should you read this document?
During the course of dealing with us, we will ask you to provide us with detailed personal information relating to your existing circumstances, your financial situation and, in some cases, your health and family health history (Your Personal Data). This document is important as it allows us to explain to you what we will need to do with Your Personal Data, and the various rights you have in relation to Your Personal Data.
About this document
This privacy notice explains how Duncan Financial Services Ltd (“we“, “our“, “us“) collects, uses and shares your personal data, and your rights in relation to the personal data we hold. This privacy notice concerns our processing of personal data for past, prospective and present clients of Duncan Financial Services Ltd (“you“, “your“). Your Personal Data means any information that describes or relates to your personal circumstances.
Duncan Financial Services Ltd (a UK registered company, registered in England with company number 10331883) is the data controller of your personal data and is subject to the Data Protection Act 1998 (“DPA“) and the General Data Protection Regulation (the “GDPR“).
What do we mean by “Your Personal Data”?
Your Personal Data means any information that describes or relates to your personal circumstances. Your Personal Data may identify you directly, for example your name, address, date of birth, national insurance number. Your Personal Data may also identify you indirectly, for example, your employment situation, your physical and mental health history, or any other information that could be associated with your cultural or social identity.
In the context of providing you with assistance in relation to your Investment and/or Insurance requirements Your Personal Data may include:
- Title, name, date of birth, gender, nationality, civil/marital status, contact details, addresses and documents that are necessary to verify your identity
- Employment and remuneration information, (including salary/bonus schemes/overtime/sick pay/other benefits), employment history
- Bank account details, tax information, loans and credit commitments, personal credit history, sources of income and expenditure, family circumstances and details of dependents
- Health status and history, details of treatment and prognosis, medical reports (further details are provided below specifically with regard to the processing we may undertake in relation to this type of information)
- Any pre-existing investment and/or insurance products and the terms and conditions relating to these
The basis upon which our firm will deal with Your Personal Data
When we speak with you about your investment and/or insurance requirements we do so on the basis that both parties are entering a contract for the supply of services.
In order to perform that contract, and to arrange the products you require, we have the right to use Your Personal Data for the purposes detailed below.
Alternatively, either in the course of initial discussions with you or when the contract between us has come to an end for whatever reason, we have the right to use Your Personal Data provided it is in our legitimate business interest to do so and your rights are not affected. For example, we may need to respond to requests from mortgage lenders, insurance providers and our Compliance Service Provider relating to the advice we have given to you, or to make contact with you to seek feedback on the service you received.
On occasion, we will use Your Personal Data for contractual responsibilities we may owe our regulator, The Financial Conduct Authority, or for wider compliance with any legal or regulatory obligation to which we might be subject. In such circumstances, we would be processing Your Personal Data in order to meet a legal, compliance or other regulatory obligation to which we are subject.
The basis upon which we will process certain parts of Your Personal Data
Where you ask us to assist you with for example your insurance / ethical investments, in particular life insurance and insurance that may assist you in the event of an accident or illness, we will ask you information about your ethnic origin, your health and medical history (“sensitive personal data“). We will record and use Your Sensitive Personal Data in order to make enquiries of insurance / investment providers in relation to insurance products that may meet your needs and to provide you with advice/guidance regarding the suitability of any product that may be available to you.
If you have parental responsibility for children under the age of 13, it is also very likely that we will record information on our systems that relates to those children and potentially, to their Sensitive Personal Data.
The arrangement of certain types of insurance may involve disclosure by you to us of information relating to historic or current criminal convictions or offences (together “Criminal Disclosures”). This is relevant to insurance related activities such as underwriting, claims and fraud management.
We will use Sensitive Personal Data and any Criminal Disclosures in the same way as Your Personal Data generally, as set out in this Privacy Notice.
Information on Special Category Data and Criminal Disclosures must be capable of being exchanged freely between insurance intermediaries such as our Firm, and insurance providers, to enable customers to secure the important insurance protection that their needs require.
How do we collect Your Personal Data?
We will collect and record Your Personal Data from a variety of sources, but mainly directly from you. You will usually provide information during the course of our initial meetings or conversations with you to establish your circumstances and needs and preferences in relation to investment and insurance. You will provide information to us verbally and in writing, including email.
We may also obtain some information from third parties, for example, credit checks, information from your employer, and searches of information in the public domain such as the voters roll. If we use technology solutions to assist in the collection of Your Personal Data for example software that is able to verify your credit status. We will only do this if we have consent from you for us or our nominated processor to access your information in this manner. With regards to electronic ID checks we would not require your consent but will inform you of how such software operates and the purpose for which it is used.
What happens to Your Personal Data when it is disclosed to us?
In the course of handling Your Personal Data, we will:
- Record and store Your Personal Data in our paper files, mobile devices and on our computer systems (email, hard drives, and cloud facilities). This information can only be accessed by employees and consultants within our firm and only when it is necessary to provide our service to you and to perform any administration tasks associated with or incidental to that service.
- Submit Your Personal Data to Product Providers and/or Insurance Product providers, both in paper form and on-line via a secure portal. The provision of this information to a third party is essential in allowing us to progress any enquiry or application made on your behalf and to deal with any additional questions or administrative issues that lenders and providers may raise.
- Use Your Personal Data for the purposes of responding to any queries you may have in relation to any investment product or insurance policy you may take out, or to inform you of any developments in relation to those products and/or polices of which we might become aware.
Sharing Your Personal Data
From time to time Your Personal Data will be shared with:
- Investment providers / Insurance providers
- Third parties who we believe will be able to assist us with your enquiry or application, or who are able to support your needs as identified. These third parties will include but may not be limited to, our compliance advisers, product specialists, providers of legal services such as estate planners (in each case where we believe this to be required due to your particular circumstances).
In each case, Your Personal Data will only be shared for the purposes set out in this Customer Privacy Notice, i.e. to progress your investment and/or insurance enquiry and to provide you with our professional services.
Please note that this sharing of Your Personal Data does not entitle such third parties to send you marketing or promotional messages: it is shared to ensure we can adequately fulfil our responsibilities to you, and as otherwise set out in this Customer Privacy Notice.
We do not operate globally, and therefore your personal data will not be transmitted to and processed outside of the European Economic Area.
How we use your information and our basis for processing that information
We may process your personal data because it is necessary for the performance of a contract with you or in order to take steps at your request prior to entering into a contract. Under these circumstances, we use your personal data for the following:
- to interact with you for example when you express your interest in our services (for example, to answer enquiries about our services);
- to provide you with the services as set out in our Client Agreement or Terms of Business or any other contractual document (including, but not limited to, the provision of our services where applicable, the processing of your sensitive personal data, for example where your health and/or medical details are relevant to the calculation of annuities, pensions or other benefits);
- to deal with any concerns or feedback you may have;
- for any other purpose for which you provide us with your personal data.
We may also process your personal data because it is necessary for our or a third party’s (this is a person or organisation external to Duncan Financial Services Ltd) legitimate interests. Our “legitimate interests” include our commercial interests in operating our business in a client focused, efficient and sustainable manner, in accordance with all applicable legal and regulatory requirements. In this respect, we may use your personal data for the following:
- to monitor and evaluate the performance and effectiveness of our services, including by training our staff or monitoring their performance, and for the monitoring of communications, as set out in the section below.
- outsourcing selected ‘back office’ functions to third parties (for example, vendors of hosted software solutions or cloud storage providers) for the purposes of efficient, fast and secure access to information across the company
- to seek advice on our rights and obligations, such as where we require our own legal advice;
- as part of a reorganisation, sale or negotiations for sale of all or part of our business;
- to follow up with you after you request information to see if we can provide any further assistance and for more general marketing purposes, including in order to keep you informed (by letter, telephone, email and other electronic means) of services from us. If you do not wish to receive such information, please let us know now or at any time in the future, and your details will be removed from our mailing list(s).
Security and retention of Your Personal Data
Your privacy is important to us and we will keep Your Personal Data secure in accordance with our legal responsibilities. We will take reasonable steps to safeguard Your Personal Data against it being accessed unlawfully or maliciously by a third party.
We also expect you to take reasonable steps to safeguard your own privacy when transferring information to us, such as not sending confidential information over unprotected email, ensuring email attachments are password protected or encrypted and only using secure methods of postage when original documentation is being sent to us.
Your Personal Data will be retained by us either electronically or in paper format for a minimum of six years, or in instances whereby we have legal right to such information we will retain records indefinitely.
You have the following rights:
- to obtain access to, and copies of, the personal data that we hold about you;
- to require that we cease processing your personal data if the processing is causing you damage or distress;
- to require us not to send you marketing communications.
- to require us to correct the personal data we hold about you if it is incorrect;
- to require us to erase your personal data;
- to require us to restrict our data processing activities (and, where our processing is based on your consent, you may withdraw that consent, without affecting the lawfulness of our processing based on consent before its withdrawal);
- to receive from us the personal data we hold about you which you have provided to us, in a reasonable format specified by you, including for the purpose of you transmitting that personal data to another data controller;
- to require us to comply with your objection, to any of our particular processing activities where you feel this has a disproportionate impact on your rights.
Please note that the above rights are not absolute, and we may be entitled to refuse requests where exceptions apply.
If you have given your consent and you wish to withdraw it, please contact Gordon Duncan using the contact details set out below. Please note that where our processing of your personal data relies on your consent and where you then withdraw that consent, we may not be able to provide all or some aspects of our services to you and/or it may affect the provision of those services.
If you are not satisfied with how we are processing your personal data, you can raise a concern with the Information Commissioner. You can also find out more about your rights under data protection legislation from the Information Commissioner’s Office website available at: www.ico.org.uk, or by writing to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
- If you have any questions you would like to raise about how we process your Personal Data, you can contact Gordon Duncan by writing to our registered office: Duncan Financial Services Ltd, 35 Larcombe Road, Petersfield, Hampshire GU32 3LS, email at , or by telephone on 07881 020609.