Privacy Policy
Brunel Associates is committed to protecting and respecting your privacy.
This policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
For the purpose of UK data protection law, the data controller is Brunel Associates. The data protection officer is Tariq Khan, Tariq@brunelassociates.co.uk
Information we collect from you
We will collect and process the following data about you:
· Information you give us. This is information about you that you give us by filling in forms on our website (our site) or by corresponding with us by phone, e-mail or otherwise.
· Information we collect about you. With regard to each of your visits to our site we may automatically collect the following information:
· technical information, including the Internet protocol (IP) address used to connect your computer to the Internet; and
· information about your visit.
Contact details of the Data Protection Officer (DPO)
Tariq Khan, Tariq@brunelassociates.co.uk
Legal Basis for Processing Personal Data
Personal data is processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Depending on the activity, we rely on the following lawful bases:
· Performance of a contract – where processing is necessary to deliver services or meet contractual obligations, including obligations involving TransUnion.
· Legal obligation – where processing is required to comply with applicable laws, regulatory requirements, or statutory obligations.
· Legitimate interests – where processing is necessary for legitimate business purposes such as system security, fraud prevention, risk management, audit, and compliance, and where such interests do not override the rights and freedoms of individuals.
· Consent – where required by law, and where individuals have been provided with a clear choice and the ability to withdraw consent at any time.
Where legitimate interests are relied upon, appropriate assessments are conducted to ensure that the rights and freedoms of data subjects are protected.
Credit Reference and Affordability Checks
To help us assess applications, prevent fraud, and meet our legal and regulatory obligations, we may obtain information about you from credit reference agencies (CRAs).
We obtain this information via Creditsafe, which uses its data partner TransUnion to supply consumer credit and identity data.
- Creditsafe Business Solutions Limited is authorised and regulated by the Financial Conduct Authority
FCA Firm Reference Number: 742313 - TransUnion International UK Limited is authorised and regulated by the Financial Conduct Authority
FCA Firm Reference Number: 737740
The information we receive may include data relating to your identity, credit commitments, payment history, and public record information. This data is used solely for legitimate business purposes, including creditworthiness assessment, identity verification, and fraud prevention, in accordance with applicable data protection laws.
Further information about how Creditsafe and TransUnion process your personal data can be found in their respective privacy notices:
- Creditsafe Privacy / Transparency Notice:
Transparency Notice | Customers & Suppliers - TransUnion Bureau Privacy Notice:
https://www.transunion.co.uk/legal/privacy-centre/pc-bureau
Legitimate interests pursued by the controller
Our legitimate interests include operating our business, fulfilling contractual obligations, ensuring system and data security, preventing fraud, supporting audit and compliance activities, and protecting TransUnion data. These interests are balanced against the rights and freedoms of individuals, with appropriate safeguards in place.
The data retention period
We keep personal data only for as long as necessary for its purpose and to meet legal or regulatory obligations. Data used for credit reference or affordability checks is retained only for as long as required and then securely deleted.
Under UK data protection law, you have the following rights in relation to your personal data:
Right to rectification – You have the right to request that inaccurate or incomplete personal data is corrected.
You have the right to tell us not to use your personal information for marketing purposes. You can exercise this right by unsubscribing using the link in any of the marketing emails we send you.
UK data protection law also gives you the right to access your personal information, to object to the use of your personal information for certain purposes, and the right to erase, restrict or receive a machine-readable copy of your personal information. You can exercise any of these rights by contacting us at the address above.
We will comply with the law in responding to your requests. That means that there may be some legal reasons why we cannot comply with all requests.
Provision of Personal Data
The provision of certain personal data is primarily contractual and, in some circumstances, required to meet legal and regulatory obligations.
Personal data is required to:
- enter into and perform contracts with customers, suppliers, or business partners.
- process orders, manage accounts, and deliver goods and services.
- verify identity and prevent fraud; and
- comply with applicable legal, regulatory, accounting, and tax obligations.
What are the consequences of not providing personal data?
If you choose not to provide the personal data, we request:
- we may be unable to enter into a contract with you.
- we may be unable to fulfil orders, supply goods, or provide services.
- we may be unable to conduct necessary verification, compliance, or fraud prevention checks; and
- as a result, our services may be delayed, restricted, or declined.
Where personal data is requested for optional purposes, such as marketing communications, providing this data is not mandatory, and you may withdraw your consent at any time without affecting your ability to receive goods or services from us.
Automated Decision Making
Automated Decision Making and Profiling
In some circumstances, we may conduct automated decision making or profiling using personal data. This involves the use of automated systems to evaluate certain information about an individual, such as risk factors, affordability indicators, or fraud signals, based on predefined rules or algorithms.
Where automated decision making is used, it may result in decisions such as the approval, restriction, or rejection of an application or service.
Individuals have the right to request human intervention, to express their point of view, and to challenge decisions made solely by automated means. Further information about automated decision making and how to exercise these rights can be obtained by contacting us using the details provided in this Privacy Policy.
Cookies
Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site. For detailed information on the cookies we use and the purposes for which we use them see our cookie policy.
Changes to our privacy policy
Any changes we make to our privacy policy in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our privacy policy.
Contacting us
If you have any questions about this privacy policy or the way we handle your personal information, please contact us at the address in the ‘contact us’ section of this website.
We hope that we will be able to answer any questions or concerns that you have. You have the right at any time to raise your concern with the Information Commissioner’s Office at: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
This Privacy Policy Is Made On The 7th Day of August 2026.

