1. About us

We are Castle Trust Group consisting of “Castle Trust Bank” and “Omni Capital Retail Finance (OCRF)”. This policy details the types of data we use, why we use it and how.  

1.1        “We”, “Us” and “Our” refers to Castle Trust Group which consists of:

  • Castle Trust Capital plc, company number 07454474, authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and the Prudential Regulation Authority.
  • Omni Capital Retail Finance Limited, company number 07232938, authorised and regulated by the Financial Conduct Authority.

1.2        Our registered office is 10 Norwich Street, London, EC4A 1BD.  Both firms are registered in England and Wales.

1.3        For the purposes of data privacy laws, we are a Data Controller in relation to the information that we collect and hold about you. This means that we are responsible for ensuring that your data is processed fairly and lawfully by us.

2. Introduction

2.1        This Privacy Policy applies to all current, former and prospective: directors, employees, workers, agents and contractors (including, for the avoidance of doubt, self-employed consultants) working with or for Castle Trust Group.  Throughout this policy we refer to employees.  In the context of this policy only the phrase “employee” should be taken to include directors, employees, workers, agents and contractors (including, for the avoidance of doubt, self-employed consultants) but does not imply nor should be assumed to imply or create any specific relationship between any person to whom this policy applies and Castle Trust Group.

2.2        This policy does not form part of any employee’s contract of employment and may be amended at any time.

2.3        There are strict rules governing the collection, retention, storage, use and disclosure of personal information.  Information protected by these laws includes not only personal data held on computer but also certain manual records that form part of a structured filing system.  If you are in any doubt about what you can or cannot disclose and to whom, do not disclose the personal information until you have sought further advice from your Manager or Castle Trust Group’s Data Protection Officer.  It is a criminal offence to knowingly or recklessly disclose personal data in breach of the laws and any such action could also result in significant fines for the Company, as well as irreparable damage to the Company’s reputation.  Accessing another employee’s personal records without authority is a disciplinary offence and may amount to potential gross misconduct.

3. Your rights and obligations

You have the right to be provided with clear, transparent and easily understandable information about how we use your information and your rights. This is why we’re providing you with the information in this policy. You might need a copy of the information we hold, or you may ask us to correct it or delete it amongst other things. This section explains your rights and what to do if you’re not happy.

3.1          Your rights in connection with personal information

Under certain circumstances, by law you have the right to:

  • Object to processing of your personal information where we are relying on a legitimate interest (or that of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object to being subject to automated decision processes and where we are processing your personal information for direct marketing purposes.
  • Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.

Where we have requested a reference in confidence from a referee and that reference has been given on terms that it is confidential and that the person giving it wishes that it should not to be disclosed to you, it is our policy that it would not normally be reasonable to disclose such a reference to you unless the consent of the person who gave the reference is first obtained. 

We reserve the right not to disclose to you any management forecasts or management planning documentation, including documents setting out the Company’s plans for your future development and progress.  We will also not disclose to you any information that contains personal data of any other person.

  • Request correction of your personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
  • Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see above).
  • Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
  • Request the transfer of your personal information to another party in a machine-readable, commonly used and structured format.

Where you have previously given us your permission to use your personal information, you may withdraw that permission. Where your permission is withdrawn, your previous consent will remain valid in respect of our use of your information prior to the date you withdrew it, or if any marketing material has been sent prior to you advising that you do not wish us to contact you again.

If you wish to exercise any of these rights then please contact the Data Protection Officer (see section 10).

Please note that in some cases, even when you make a request concerning your personal information, we may not be required, or may not be able, to honour it as this may result in us not being able to fulfil our legal and regulatory obligations or there is a minimum statutory period of time for which we have to keep your information. If this is the case, then we will let you know our reasons.

4. Information we collect

We collect the following kinds of information about you:

4.1        Information you provide to us

You provide us, or our agents, with certain information when you apply to work or become employed by Castle Trust. This includes:

  • Your name, address, date of birth, email address and telephone number;
  • Previous address details;
  • Bank account details;
  • Special categories of personal information such as gender; nationality; racial or ethnic origin; health related information or information relating to disabilities; age; religion or belief; sexual orientation;
  • In certain circumstances, utility bills, bank statements or copies of official identity records such as passports, driving licences or birth and marriage certificates; and
  • Details of criminal convictions.

4.2        Information obtained from credit reference agencies

We obtain a copy of your credit file from credit reference agencies TransUnion, Experian and Equifax. For detailed information on the information obtained and how it is used, see section 7.1.

4.3        Combining data

The information you give us may be combined with other information about you that is obtained from other sources. The combination is usually undertaken with a view to enhancing an existing database with more information. This will include:

  • The information you give us may be compared with data available elsewhere in the public domain such as social media profiles or electoral role information to verify your identity or validate the information you have provided (for example, professional networking sites for employment history).

4.4        Information provided from your use of our websites

We gather information about how often you and other users access our websites, the way in which you navigate around it, and how long you spend on particular pages.

4.5        Information from your devices when you use our websites

We gather information about the devices that you use to access our websites, such as the operating system, hardware, software versions, browser configuration, display size, browser configuration and connection information such as IP addresses.

We use cookies to recognise when you return to our site and to compile anonymous, aggregated statistics that allow us to understand how users use our site and to help us improve the structure of our website. We also use cookies to measure performance of our web server and, via a third party, allow you to leave comments on our blog pages. You can find more information about the types of cookies we use in our Cookie Policy.

4.6        Other information

We monitor or record your communications with us to meet our regulatory obligations and to improve our services.

We will provide you with the appropriate devices and systems to carry out your role.  In some circumstances, the technology installed on those devices may provide the option for you to authenticate your identification using biometric data.  Your biometric data is not stored or processed by Castle Trust.  However, in providing you with this technology, we will have carried out an appropriate security assessment to ensure your personal data is handled in accordance with data protection regulations.

If you provide us with information about another person, it is important you gain their consent and tell them what information you are providing and why, for example, details of your next of kin. If they do not want their information given to us, then you should not provide it. If they would like to know more, they can have a copy of this Privacy Policy or they can write to our Data Protection Officer using the contact details in section 10. 

5. How we use that information

We collect information about you for the following purposes:          

5.1          Verifying your identity

The information you provide will help us to verify your identity so that we know we are dealing with the correct person. We do this by checking the information you give us against external databases such as the electoral roll and your credit file.

5.2          Recruitment and employment

We will use the information that we hold about you in order to enter or look to enter into a contract of employment with you and to fulfil our obligations under such contract. This includes contacting you to communicate with you in connection with our services and to deal with any queries concerning the data that we hold.

5.3          Fraud prevention and other legitimate interests

We will use the information in order to detect or prevent fraud and to comply with our legal obligations (for example, to ensure that no-one has fraudulently used your details or to confirm you have only entered information about yourself). Information can be used to corroborate your details (including using third parties to undertake those checks on our behalf).

5.4          Automated decision making and decisions made based on profiling 

You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making unless we have a lawful basis for doing so and we have notified you of this fact.

 

5.5          Quality Assurance Activity

In customer facing roles where calls are recorded, voice data will be captured and processed so that quality assurance oversight activity can be undertaken.

6. Our basis for using your information

As your employer (or prospective employer) we hold a variety of information about you in our systems. This data includes but is not limited to your name and address, salary details, bank details, gender, nationality, health related information or information relating to disabilities, age, religion or belief, sexual orientation and details of criminal convictions.  This information will only be used in order that we can monitor our compliance with the law and best practice in areas such as recruitment, equal opportunity, pay and benefits, administration, performance appraisal and disciplinary matters.  If your personal information changes, you should let us know so that our records can be updated. 

In some circumstances, we may have to hold, and process, sensitive personal data about you.  This will be, for example:

  • Information about your physical or mental health in order to monitor sick leave and take decisions about your fitness for work; and
  • your racial or ethnic origin, or religious or similar beliefs, in order to monitor compliance with equal opportunities legislation. 

In addition, there may be situations where we process information relating to your criminal record.  This may include, for example, undertaking criminal records and/or DBS checks against potential employees and/or keeping on our files information relating to certain criminal convictions of employees whilst in our employment. 

In both of these circumstances the lawful basis for processing is slightly different.  When processing this ‘sensitive’ personal data, including criminal record information, we will rely upon the lawful bases of ‘Consent’ (only for information that you voluntarily provide to us), ‘Legal Obligations’ and ‘Vital Interests’.

7. Who we share information with
8. Keeping your data

We will keep your information only for as long as necessary depending on the purpose for which it was provided. Details of retention periods for different aspects of your personal information are available in our retention policy which is available from the Data Protection Officer.

No matter what kind of personal data we hold about you (whether sensitive or otherwise) we will only hold the minimum amount of data that we require to comply with our obligations and it will only be retained for as long as it is required to enable us to comply with our legal obligations.  After this time it will be permanently deleted. All data is retained in accordance with our data retention policy (called the “Data Backup and Retention Standard”), a copy of which is available on the firm’s common drive, or can be supplied upon request using the contact details in section 10.

9. Our security measures

We are aware of the importance of safeguarding the information under our control and endeavour to take all reasonable steps to protect it. All data collected through the website is stored on secure servers, and we have stringent security and confidentiality procedures covering the storage and disclosure of such information in accordance with the current data protection regulations.

We link to a wide variety of other sites. We are not responsible for the content or privacy policies of these sites, nor for the way in which information about their users is treated. In particular, unless expressly stated, we are not agents for these sites nor are we authorised to make representations on their behalf.

10. How to contact us
Scroll to Top