4.1 Purposes for which we will use your personal data
We have set out below a description of the ways we plan to use your personal data,
the purposes for this usage and which of the legal grounds we rely on to do so.
We have also identified what our Legitimate Interests are where appropriate.
Note that we may process your personal data for more than one legal ground depending
on the specific purpose for which we are using your data. If you had a
loan product or are supporting our customers
(e.g. powers of attorney) then the reasons we process your personal data are set out separately below.
Purposes and Legal Grounds
-
We may process your information to:
-
Understand how you use products, services, processes and related
customer experiences provided by us and other organisations;
-
Inform the way that we manage our products, services, processes and platforms;
-
Develop, test and change our products, services, processes and platforms;
-
Invite you to provide customer feedback through surveys and forums to help us understand and improve the effectiveness of our products, services, processes and platforms;
-
Monitor usage and performance of our products, services, processes and platforms;
perform analysis (e.g. statistical, market, product analysis), reporting,
forecasting and accounting;
-
Tell you about our products, services, events and
activities that may be of interest to you;
-
Understand how you interact with our marketing; develop,
test or change our marketing activities;
-
Communicate with our third parties to help them understand, improve and fulfil
on marketing activities (including supporting behavioural advertising techniques
e.g. use of cookie data);
-
Promote our products and services.
When processing your information for these purposes, we are relying on our
Legitimate Interest to help us understand, develop, improve and market our
products and services.
-
We may process your information to:
-
Allow you to begin using or register for our products or services;
-
Check your eligibility for our credit products; process your
application and/or set up an account for you;
-
Uphold our lending criteria by performing creditworthiness,
affordability and other checks including, but not limited to,
fraud checks, anti-money laundering checks, vulnerability assessments, identity checks;
-
Report activities to credit reference agencies (CRAs), fraud prevention agencies (FPAs)
and/or crime prevention agencies in line with our legal, regulatory or business requirements;
-
Communicate with you to provide updates following a credit application or eligibility check;
-
Communicate with you to provide updates and information while you are using,
registering or continuing to use one of our products or services;
-
Communicate with you for design or research purposes or to ask you about our
current or potential products, services, processes and customer experiences;
-
Provide targeted communications via social media platforms (for example Facebook), by sending to them a hashed version of your personal information (which may be your email address, phone number and/or first name and surname) to provide you with information in relation to our current service availability and other relevant service and support information.
When processing your information for these purposes, we rely on our Legitimate Interest
to allow you to access our products and services. In addition, in relation to some of
the purposes, it is necessary for us to process your information for the Performance
of the Contract between us.
-
We may process your information to:
-
Enable you to access and use our online services and functionality;
-
Understand how you use and navigate our online services;
-
Tailor online experiences or develop and/or change these services;
-
Service and fulfil on your products and services (e.g. processing
transactions, managing account information and settings);
-
Provide you with other suitable products, services or relevant information where we (or our partners) think you may be interested;
-
Manage potential Payment Protection Insurance (PPI) related activities on your
accounts including activities relating to the potential miss-sell of PPI;
-
Keep our records up to date including updating preferences and making changes to your account;
-
Manage requests from you where you are exercising your data privacy rights;
-
Assess your personal circumstances while you are using our products and services and,
potentially, taking actions on your account based on these circumstances
(e.g. making changes to your account where you appear to be in financial difficulty);
-
Communicate with you for any purpose relating to the servicing of your account;
-
Manage your accounts, products or services effectively (e.g. applying
credit limit increases and decreases, updating your product terms);
- Develop, improve or change the products and services that you are using;
- Offer you additional products, services and promotions;
- Assess, collect or recover outstanding debts from you;
-
Transfer ownership of your account to a third party. This may include
activities we carry out with third parties including the assessment,
pricing and handover of the debt;
-
Inform strategies around how we collect, recover or sell outstanding debts.
This may involve sharing data with third parties to help inform this strategy
including which third parties we work with;
-
Monitor usage and performance of our products, services, processes and platforms;
perform analysis (e.g. statistical, market, product analysis), reporting,
forecasting and accounting.
When processing your information for these purposes, we rely on our
Legitimate Interest to fulfil on our products and services. In addition,
in relation to some of the purposes, it is necessary for us to process your
information for the Performance of the Contract between us.
-
We may process your information to:
-
Perform checks to prevent, detect, investigate and report fraud,
crime and/or terrorist activity;
-
Carry out our obligations required by relevant laws and regulations including anti-money laundering (AML) checks, Her Majesty's Treasury (HM Treasury) and Office of Foreign Assets Control (OFAC) sanctions list checks, Politically Exposed Persons (PEP's) assessments and Transaction/Account monitoring and restriction;
-
Protect the security and resilience of our networks/applications
and respond to technical and security incidents;
-
Devise defence strategies (e.g. in relation to fraud, crime, terrorist
or cyber-attack risks) and develop, test or change our defences.
-
Review and take appropriate action relating to threatening and abusive behaviour of customers to our agents whilst performing their day to day role.
-
To ensure we are able to offer our services in a secure manner by authenticating our customers and reducing the risk of fraud.
When processing your information for these purposes, we rely on our
Legitimate Interest to manage risk, security and crime prevention.
In addition, in relation to some of the purposes, we may process your
information to comply with a Legal Obligation.
-
We may process your information to:
-
Improve, test, investigate and remediate any issues with our internal processes and practices;
-
Maintain your data and ensure the data that we hold about you is accurate and up to date.
When processing your information for these purposes, we rely on our
Legitimate Interest to manage and improve our business processes.
-
We may process your information to:
-
Cooperate with (and respond to) requests from courts, regulators, law
enforcement bodies and other institutions (e.g. fraud prevention agencies);
-
Appropriately handle and process complaints or disputes
– this may include contacting relevant parties;
- Exercise our rights in relation to complaints, disputes or litigation;
-
Manage policy affairs, public relations issues, media
enquiries or customer interactions with the media;
- Manage complaints with third parties;
- Manage disputes and charge backs;
- Manage litigation against third parties;
-
Enable us to provide legal and/or regulatory
advice in line with our business activities;
-
Share your online account information with regulated third parties,
known as Account Information Service Providers (AISPs) where you
have asked them to access this information.
When processing your information for these purposes, we rely on our
Legitimate Interest to satisfy our industry, regulatory and legal
requirements and exercise our rights. In addition, in relation to
some of the purposes, we may process your information to comply with
a Legal Obligation or it may be necessary to assist in relation to a
task performed in the Public Interest.
We may use third parties for any of the purposes listed above.
Loan customers and those supporting our customers
If you had a loan product or are supporting one of our customers (e.g. powers of attorney)
then we only process your data for the specific purposes set out below:
Purposes and Legal Grounds
-
We may process your information to:
-
Manage potential Loan Protection Insurance (LPI) related activities
including activities relating to the potential miss-sell of LPI;
-
Communicate with you for any purpose relating to
the servicing of your products and services;
- Manage requests from you where you are exercising your data privacy rights.
Where we process your information for these purposes, we rely on our
Legitimate Interest to fulfil on our products and services.
In addition, in relation to some of the purposes, it is necessary for
us to process your information for the Performance of the Contract between us.
-
We may process your information to:
-
Appropriately handle and process complaints or disputes – this may
include contacting relevant third parties to assist in their handling;
- Exercise our rights in relation to complaints, disputes or litigation.
Where we process your information for these purposes, we rely on our
Legitimate Interest to satisfy our industry, regulatory and legal
requirements and exercising our rights. In addition, in relation to
some of the purposes, we may process your information to comply with a Legal Obligation.
We may use third parties for any of the purposes listed above.
Purposes and Legal Grounds
-
We may process your information to:
- Communicate with you for any purpose relating to the servicing of the account;
- Manage any rewards, offers or promotions;
- Manage requests from you where you are exercising your data privacy rights.
Where we process your information for these purposes, we rely
on our Legitimate Interest to fulfil on our products and services.
-
We may process your information to:
-
Perform checks to prevent, detect, investigate and
report fraud, crime and/or terrorist activity;
-
Carry out our obligations required by relevant laws and regulation
including anti-money laundering (AML) checks, Her Majesty's Treasury
(HM Treasury) and Office of Foreign Assets Control (OFAC) sanctions list checks, Politically Exposed Persons (PEP's) assessments and Transaction/Account monitoring and restriction.
Where we process your information for these purposes, we rely on our
Legitimate Interest to manage risk, security and crime prevention.
In addition, in relation to some of the purposes, we may do so to comply with a Legal Obligation.
-
We may process your information to:
-
Improve; test, investigate and remediate any
issues with our internal processes and practices;
-
Maintain your data and ensure the data that we hold about you is accurate and up to date.
Where we process your information for these purposes, we rely on our
Legitimate Interest to manage and improve our business processes.
-
We may process your information to:
- Assess your personal circumstances in order to support you with the right outcome;
-
Appropriately handle and process complaints or disputes – this may
include contacting relevant third parties to assist in their handling;
- Exercise our rights in relation to complaints, disputes or litigation;
-
Manage policy affairs, public relations issues,
media enquiries or customer interactions with media;
- Enable us to provide legal/regulatory advice in line with our business activities;
-
Cooperate with (and respond to) requests from other institutions, regulators,
law enforcement bodies and other agencies (e.g. fraud prevention agencies).
Where we process your information for these purposes, we rely on our
Legitimate Interest to satisfy our industry, regulatory and legal
requirements and exercise our rights. In addition, we may process your
information to comply with a Legal Obligation.
We may use third parties for any of the purposes listed above.
Special Categories of Personal Data
Health data
When we receive information concerning your health from you or someone else we may process it to provide a more appropriate service and/or protect your best interests as follows:
-
Processing personal data relating to your health enables us or someone else to better protect
you against potential harm, such as:
- Taking out credit that is not appropriate;
- Falling behind on debt repayments;
- Falling prey to fraud or financial abuse; or
- Otherwise not being able to protect your economic well-being.
- To ensure that we are able to send communications to you in an appropriate format or make other reasonable adjustments due to a condition.
-
So that we can try and prevent fraud and/or where there may be suspicions of terrorist financing or money laundering;
We may also process your health data to establish, exercise or defend a legal claim.
Where we process this information we will usually do so on the basis of a Substantial Public Interest
which has been set out in legislation, to perform or exercise obligations or rights which are imposed or
conferred by law on us in connection with social protection or to exercise, establish or defend a legal
claim.
If you do not want us to process information concerning your health, you may object to this processing
as set out in Your legal rights. We will consider your request appropriately. If we stop processing your
health data, we may still include a marker on your account to ensure that we are able to continue to
protect your best interests.
Biometric Data
To ensure we are able to offer our services in a secure manner by authenticating our customers and reducing the risk of fraud, we process information about operations and behaviour performed on the device such as mouse movements and key strokes (Device Operations). In some circumstances this information is known as Biometric Data - where it is used to uniquely identify you.
Where we process this information we do so on the basis of a Substantial Public Interest which has been set out in legislation.
If you do not want us to process information you may object to this processing as set out in Your Legal Rights. We will consider your request appropriately. If we stop processing this information, we will still need to protect the security of your account. We will do this in alternative ways available to us but this might change the overall standard of security that we can apply. You also might not be able to access your account and/or carry out transactions as quickly or easily.
We use third parties to fulfil this purpose on our behalf. The third parties do not process this data as Biometric Data but only as Device Operations. They will:
- Use the Device Operations data to help us to understand whether you are the person using your device;
- Maintain the confidentiality and security of the information, including maintaining technical and physical safeguards that are designed to (a) protect the security and integrity of the information while it is within their systems and (b) guard against the accidental or unauthorised access, use, alteration or disclosure of information within their systems;
- Only retain the data for as long as is necessary to fulfil this purpose and delete once it is no longer needed for this purpose.
They will not:
- Share the information with any third parties.
- Use the information to append to other information to build profiles.
- Use the information to provide services to you.
4.2 Marketing
We strive to provide you with choices regarding certain personal
data uses, particularly around marketing and advertising.
You will receive marketing communications from us if you have requested information
from us or provided us with your details when you applied or registered for one of
our products or services and, in each case, you have not opted out of receiving
that marketing. However,
you can ask us to stop sending you direct marketing at any time. When you ask us to stop, please note that this may not take effect immediately, since it takes time for the change to be processed in our systems.
If you ask us to stop sending you marketing messages, you will still receive
communications pertaining to the servicing or fulfilment of your account,
product, service or relationship with us (such as statements for your credit product,
communications about your outstanding debts or relevant updates about the products
or services that you are already using).
We may share information that we collect about you with third parties and we may also use third parties to conduct marketing activities on our behalf. In some cases, we do this to identify groups of similar audiences to target for advertising purposes. If you do not want us to share your personal information with third parties for this purpose, you can tell us not to.
4.3 Cookies and Online Marketing
For more information about the cookies we use for online marketing purposes, please see our Cookie and Online Marketing Policy.
Online advertising through pixels
We use targeting and advertising pixels on our website for various reasons, including to ensure you do not see advertisements that are not relevant or identify groups of similar audiences to target for advertising purposes.
We collect information about you using these pixels such as email addresses, names and telephone numbers and share this with our marketing partners such as Facebook and Google. These can also monitor your online behaviour and identify website usage.
In some cases, we may also take your information to evaluate personal aspects about you. This is called profiling. We use data that you provide along with internal and third-party data to place you into groups with similar types of people.
If you have allowed us to use pixels for targeting and advertising, this information will be collected and sent through pixels to our marketing partners. For more information or to alter your cookie settings, please visit our Cookie and Online Marketing policy.
Facebook is a joint controller with us when we process information we collect about you from your actions online or through the Facebook pixel on our website. This Joint Controller relationship is subject to Facebook's Controller Addendum. Facebook is the independent Data Controller once it is in receipt of that data. You can find more information about Facebook’s processing at
https://www.facebook.com/policy.php opens in a new tab
. To learn more about this type of processing please see our Cookie and Online Marketing Policy.
Data shared in other ways
We share information that we collect about you such as email addresses and telephone numbers with our third party partners such as Facebook, Google, Microsoft and Yahoo. We do this so that we can identify groups of similar audiences to target for advertising purposes, or ensure you do not see advertisements that are not relevant. We call these groups 'custom audiences'.
Yahoo
You can find more information about how Yahoo uses data that it receives here:
https://legal.yahoo.com/us/en/yahoo/privacy/index.html opens in a new tab
Microsoft
You can find more information about how Microsoft uses data that it receives here:
https://privacy.microsoft.com/en-gb/privacystatement opens in a new tab
Google
You can find more information about how Google uses data that it receives here:
https://policies.google.com/technologies/partner-sites opens in a new tab
Facebook Custom Audience
When we use this feature, we "hash" your data locally before we pass it to Facebook. This is a process which turns your data into letters and numbers so that it is protected.
Facebook will:
- Use the hashed data for matching purposes; and
- Maintain the confidentiality and security of the hashed data and the collection of Facebook User IDs that comprise the customer audience created from the hashed data, including maintaining technical and physical safeguards that are designed to (a) protect the security and integrity of data while it is within Facebook's systems and (b) guard against the accidental or unauthorised access, use, alteration or disclosure of data within Facebook's systems.
Facebook will not:
- Share the hashed data with third parties or other advertisers and will delete the hashed data promptly after the match process is complete;
- Give access to or information about the custom audience(s) to third parties or other advertisers;
- Use custom audience(s) to append to the information it has about its users or build interest-based profiles;
- Use custom audience(s) to provide services to you.
For further details in relation to Facebook Custom Audience, please visit
https://www.facebook.com/legal/terms/customaudience opens in a new tab
.
When processing your information for these purposes, we are relying on our Legitimate Interest to help us understand, develop, improve and market our products and services.
If you do not want us to share your personal information with third parties for this purpose, you can tell us not to. If you opt out after your data has been shared with the platform, your data will be removed from the custom audience.
4.4 Change of purpose
We will only use your personal data for the purposes for which we collected it,
unless we reasonably consider that we need to use it for another reason and that
reason is compatible with the original purpose. If we need to use your personal
data for an unrelated purpose, we will notify you and we will explain the legal
ground which allows us to do so.
Please note that we may process your personal data without your knowledge or consent,
in compliance with the above rules, where this is required or permitted by law.