Privacy Notice

Date of publication: February 2026

Riverton Home Finance (”Riverton”) takes the privacy of personal data very seriously. As required under the UK General Data Protection Regulation (UK GDPR), we have provided a privacy notice which set out how personal data is processed and protected, and individuals’ rights surrounding this data.

Who needs to read this privacy notice?

You should read this privacy notice if you use or are involved with our mortgage lending services.

About us and our relationship with you

Riverton Home Finance Limited is authorised and regulated by the Financial Conduct Authority. Firm reference number 1023724 and ICO registration reference ZB953628. Riverton Home Finance Limited is registered in England and Wales with company number 11877651. Registered Office: The Post Building, 100 Museum Street, London WC1A 1PB.


This privacy notice applies to all situations where we process personal data about any individual in connection with our mortgage lending services.


Riverton Home Finance Limited provides regulated mortgage lending services in England, Wales and Scotland. In order to provide these services, we process personal information about you throughout your relationship with us. If you are an applicant, your personal data is likely to be provided to us by your adviser in the first instance, but it may also be collected directly from you and other available sources. Prior to and throughout the application process and after the loan has been granted, we may also be required to process personal data relating to a joint applicant of the loan, or another related third party. If you are an adviser, or intermediary, we are likely to collect your personal data directly from you or your broker firm as required for onboarding or over the course of a mortgage application. 


We are a controller under data protection laws. This privacy notice explains how we use and look after your personal data. This privacy notice also tells you about your privacy rights and how the law protects you.


About this privacy notice

This privacy notice contains information about:

•    The personal data that we process as a controller.
•    Where the personal data has been obtained.
•    The reasons why we process your personal data and the lawful basis we use to do so.
•    The security measures that we have in place to keep your personal data secure.
•    The length of time we store your personal data for.
•    The organisations, or categories of organisation, with whom we might share your personal data.
•    International transfers of your personal data.
•    The rights you have under data protection laws in relation to our processing of your personal data.


The meaning of words which are shown in bold underlined text are explained in the Glossary. Throughout this notice any reference to "we" or "us" refers to Riverton Home Finance Limited.


Please note that we may change this privacy notice from time to time. The latest version of our privacy notice can be found on our website: www.rivertonhomefinance.co.uk/privacy-notice

 

What personal data do we process?

The categories of personal data we process include the following:

1. Personal data which includes:

  • identity: name, date of birth, gender, National Insurance number
  • contact: address, address history telephone number, email address
  • family information: marital status, details of dependents and other occupants
  • nationality, residency status and citizenship information
  • financial information: income and expenditure, savings, borrowings, debts, transactional history, information from credit reference agencies and fraud prevention agencies, financial distress reports, source of deposit
  • employment record
  • occupier status: e.g. whether you are currently a tenant or owner-occupier

 

2.  Mortgage information: Personal data relating to details of your mortgage and property. Personal data in this category may include:

  • property value
  • loan amount
  • joint/single loan
  • cash advance
  • loan to value ratio
  • Additional information - if you are in breach of the terms of your mortgage, we may obtain more information about the reason for the breach from other third parties in order to help determine what action to take.

 

3.    Sensitive personal data: We may also collect sensitive personal data about you to the extent that this is necessary and relevant to the provision of our products and services (for example, where we need to carry out our legal obligations, such as detecting fraud and financial crime, where it is needed in the public interest, such as making our products and services more accessible for those who require additional support or for our customers economic well-being, or in limited circumstances with your explicit written consent (which you can withdraw at any time)).  The processing of sensitive personal data may also extend to:

  • religious beliefs
  • political opinions
  • racial or ethnic origin information
  • biometric data
  • information concerning health
  • trade union membership

 

We may also, in line with relevant laws and regulations, process information that you provide to us about criminal convictions as part of your application.

The reasons why and lawful bases relied on to process your personal data

The table below provides details of the purpose and the lawful bases upon which we process personal data.

Types of personal data Why do we need it Lawful bases for processing
  • Identity information
  • Contact information
  • Family information
  • Nationality, residency and citizenship information
  • Financial information
  • Employment information
  • Occupier status
  • Mortgage information
  • Sensitive personal data
To provide you with our mortgage lending services and operate our busConiness. We process personal data to onboard you, correspond with you and/or to manage your account, and discuss accounts you are supporting, effectively. We also process personal data to operate our mortgages business and manage the risks aligned to our loans. This includes the potential processing of personal data in connection with the sale or potential sale of our interest in the loans to other parties and managing mortgage term breaches. Performance of a contract (the mortgage agreement) with you. Necessary for our legitimate interests (to manage customer accounts and the onboarding process, operate our business effectively and efficiently, manage the risks associated with our business, and provide a high standard of service). Substantial public interest – to allow us to support individuals with a disability or medical condition (sensitive personal data) which impacts the account or service with us.
  • Identity information
  • Contact information
  • Family information
  • Nationality, residency and citizenship information
  • Financial information
  • Employment information
  • Occupier status
To verify your identity and to assess creditworthiness. We process personal data to carry out due diligence in relation to your application. For example, we need to verify your identity and check your credit history with Credit Reference Agencies to assess your creditworthiness. We also use your personal data to assess your affordability and suitability for our products where appropriate, and for security assessments. Performance of a contract with you. Necessary for our legitimate interests (to ensure products are suited to your needs, to make fair, informed decisions).
  • Identity information
  • Contact information
  • Family information
  • Nationality, residency and citizenship information
  • Financial information
  • Employment information
  • Occupier status
  • Mortgage information
  • Sensitive personal data
For the prevention of financial crime. We process personal data to meet our obligations in relation to anti-money laundering and the prevention of financial crime. Performance of a contract with you. Legal obligation Necessary for our legitimate interests (to detect, prevent and investigate financial crime, including fraud and money laundering) Substantial public interest – preventing fraud and detecting unlawful acts (for sensitive personal data and criminal convictions)
  • Identity information
  • Contact information
  • Sensitive personal data
  • Mortgage information
To communicate with you, and relevant third parties. We process personal data to correspond with you regarding your mortgage application or a mortgage application you are supporting, and to ensure we are providing adequate support to you in the management of your mortgage account prior to and throughout the application process and after the loan has been granted. Performance of a contract with you. Legal obligation. Necessary for our legitimate interests (to manage your account and provide a high standard of service). Substantial public interest – Such as providing support for individuals with a disability or medical condition (for sensitive personal data), for example providing our documents in accessible formats such as braille or large print.
  • Identity information
  • Contact information
  • Sensitive personal data
To improve our service. Where we have telephone calls with you, we may record these for training, auditing and monitoring purposes and to review and improve our services. We may also send you a customer satisfaction and/or feedback survey. Performance of a contract with you. Necessary for our legitimate interests (to manage customer accounts and provide a high standard of service). Substantial public interest – Support for individuals with a disability or medical condition (for sensitive personal data) such as using scenarios relating to customers with disabilities or medical conditions to train our staff or audit customer experiences.
  • Identity information
  • Contact information
  • Financial information
  • Employment information
To meet our legal and regulatory obligations. We process personal data to meet our obligations under the law, regulations, and guidelines issued by the Information Commissioner's Office (ICO), General Data Protection Regulation (UK GDPR), Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA).
Legal obligation.
 
  • Identity information
  • Contact information
  • Family information
  • Nationality, residency and citizenship information
  • Financial information
  • Employment information
  • Occupier status
  • Mortgage information
When purchasing or selling a mortgage portfolio. We process personal data to:
  • Complete due diligence checks.
  • Establish that you, your property and your circumstances meet our criteria to enable us to provide the mortgage amount to you.
  • Establish that we can fulfil our obligations under our mortgage agreement with you.
  • Establish that we can collect amounts due under the mortgage.
Necessary for our legitimate interests (to operate our business effectively and efficiently, manage the risks associated with our business, and meet our legal and contractual obligations. This includes selling interests in the loans to other parties.)
  • Identity information
  • Contact information
  • Financial information
  • Occupier status
  • Mortgage information
When servicing a mortgage portfolio.
We process personal data to:
  • Ensure mortgage investments are properly funded and priced.
  • Verify that the mortgage charge has been correctly registered against the property at the land registry.
  • Undertake flood, geographical or environmental risk assessments of the properties securing the mortgage loans in which we have an economic interest.
  • Ensure we can operate our business and sell our loans to other loan providers like us.
  • Ensure that we operate our business responsibly and cease lending if there are material breaches relating to the mortgage portfolio or if the portfolio in aggregate is not sustainable and gathering increased risks.
 
Necessary for our legitimate interests (to operate our business effectively and efficiently, manage the risks associated with our business, and meet our legal and contractual obligations. This includes selling interests in the loans to other parties.)
  • Identity information
  • Contact information
  • Mortgage information
To tell you about our products and services.
We process personal data to tell you about products and services that may interest you.
Consent (we may ask for your consent in order to provide you with information about our products and services)
How do we keep your personal data secure?

Our commitment to corporate security is demonstrated through the implementation of policies, controls and procedures, which are externally certified and audited to the international information security standard, ISO 27001:2013.

 

Our security policies, controls and procedures are regularly reviewed and updated so that we maintain good practices across our business to keep your information safe. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

 

We have contractual arrangements in place with all of our service providers who process personal data in accordance with data protection laws. We regularly check that our service providers are complying with their contractual commitments. This includes assessing and reporting on our service providers' information security controls to check their compliance using questionnaires and/or on-site audits.

How long do we store your personal data?

We will only keep your personal data for so long as we reasonably required and, in any event, only for as long as our internal rules and polices allow us in order to fulfil our business or legal and regulatory obligations. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

Who has access to your personal data?

We share personal data with a variety of other companies to operate our business. However, we only share the personal data where necessary to help us satisfy one or more of the reasons for processing set out above.

We have detailed the types of companies with whom we currently share personal data below:

 

 1. Tracing agencies

We use these companies in order to check whether you are alive and whether your current address is your place of residence.

 

 2. Property related service providers

We engage a number of companies to provide services relevant to the mortgages we provide, including property valuation companies, auditors and due diligence providers.

 

3. Credit reference and fraud prevention agencies

We may use credit reference agencies to verify your identity and check your credit history. Fraud prevention agencies may also be used to prevent fraud and money-laundering and to verify your identity. If fraud is detected, you could be refused certain services, finance, or employment. Further details of how your information may be used by these fraud prevention agencies, and your data protection rights, can be found here.

 

 4. Other service providers to our business

Other companies who process personal data on our behalf include and those service providers who provide day-to- day operational business services such as emails, IT infrastructure and software, archiving, document scanning and copying, document destruction and printing.

 

5. Existing mortgage providers

We may share your personal data with lenders in the course of your mortgage application.

 

6. Group entities

We will sometimes need to share personal data with entities within the Rothesay group of companies for administrative purposes and as part of our internal financing arrangements.

 

 7. Other loan providers or third parties like us

If we decide to sell our interests in certain of our loans to another provider or third party, we will give your personal data to the actual or proposed purchaser of the economic interest in your mortgage.

 

8. Professional advisers

We sometimes have to share personal data with our professional advisers (including accountants and lawyers) where it is required for the purposes of their advice.

 

9. Regulators, law enforcement and auditors

We will share personal data when requested by regulators, law enforcement agencies or other third parties to comply obligations imposed on us by laws and regulations.

International transfers

Where personal data is transferred to and processed in a country outside of the UK or the EEA (as applicable), we take steps to provide appropriate safeguards to protect your personal data, including by entering into approved standard contractual clauses obliging recipients to protect your personal data and only transferring personal data to the extent that an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data is ensured in compliance with data protection laws.

If you want further information on the specific mechanisms used by us when transferring your personal data outside of the UK or EEA, please contact us using the details contained in the part of this privacy notice headed Contact details.

Your rights

Under certain circumstances, you have the following rights under data protection law:

  • The right of access to personal data relating to you. This is commonly known as a ‘subject access request’ and enables you to receive a copy of the personal data we hold about you.
  • The right to correct any mistakes in your personal data. However, please note that we may need to verify the accuracy of the new data you provide to us.
  • The right to require us to delete your personal data in certain circumstances. For example, where there is no good reason for us to continue to process it or where we may have processed your information unlawfully. However please note that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • The right to restrict our processing of your personal data. This means you can ask us to suspend the processing of your personal data in one of the following scenarios:
  1. If you want us to establish the data's accuracy;
  2. Where our use of the data is unlawful but you do not want us to erase it;
  3. Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
  4. You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  • The right to object to us processing your personal data, including for marketing purposes. Where we are relying on a legitimate interest as the legal basis for that particular use of your data. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object.
  • Right to data portability of your personal data. You have the right to ask that we transfer personal information you gave us to another organisation or to you, in certain circumstances.
  • Right to withdraw your consent at any time if we rely on your consent as the legal basis for processing your personal data.

How to exercise your rights

If you wish to exercise any of your rights, please contact us using the details contained in the part of this privacy notice headed Contact details.

Contact details

How to contact us regarding this privacy notice

To contact us you can;

 

Email us: dpo@rivertonhf.co.uk 

 

Write to us: Data Protection, Riverton Home Finance, The Post Building, 100 Museum Street, London WC1A 1PB.

 

If you live within the European Union, you can also contact our European representative. Their details are as follows:

How to make a complaint

If you have a problem or concern relating to the ways we process your personal data or the contents of this privacy notice, please contact us in the first instance.

 

We hope that we will be able to address the problem or concern to your satisfaction. However, you also have the right to make a complaint to the Information Commissioner's Office.

 

 The process for making a complaint to the Information Commissioner's Office is available here: https://ico.org.uk/ make-a-complaint/.

Their contact details are as follows:

  • Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Phone: 0303 123 1113
  • Website: ico.org
Glossary
Controller

The entity which determines the purposes for which, and the manner in which, any personal data is processed.

Data protection laws

Any law relating to the use of Personal Data, as applicable to the Parties, including:

In the United Kingdom

  • The General Data Protection Regulation (EU) 2016/679 (GDPR) including as adopted by the United Kingdom as a result of its exit from the European Union (“UK GDPR”) and the Data Protection Act 2018, and/or any corresponding or equivalent national laws and regulation in the United Kingdom and/or any other applicable jurisdiction; and/or
  • The Privacy and Electronic Communications (EC Directive) Regulations 2003, and any laws or regulations implementing Directive 2002/58/EC (e-Privacy Directive) and/or any corresponding or equivalent national laws and regulation

In member states of the European Union (EU) and/or the EEA

  • The GDPR and the e-Privacy Directive, and all relevant EU and EEA member state laws or regulations giving effect to or corresponding with any of them

Also including any judicial or administrative interpretation of any of the above.

Mortgage information

Personal data relating to details of a homeowner’s mortgage and property.

Personal Data

Any information relating to a living identifiable individual, including:

  • Information such as names, addresses, telephone numbers, email addresses, photographs, voice recordings and financial information
  • Expressions of opinion and indications of intentions about individuals (and their own expressions of opinion/intentions)
  • Information which on its own does not identify someone but which would identify them if put together with other information which we have or are likely to have in the future.
Processing, processed or process

This covers almost anything a company or individual can do with personal data, including:

  • Obtaining, recording, retrieving, consulting or holding it
  • Organising, adapting or updating it
  • Disclosing, sharing or otherwise making it available
  • Cleansing, blocking, erasing or destroying it.
Sensitive personal data

Any information relating to any of the following:

  • Racial or ethnic origin
  • Political opinions
  • Religious beliefs or beliefs of a similar nature
  • Trade union membership
  • Physical or mental health
  • Sexual life or orientation
  • Genetic data or biometric data for the purpose of uniquely identifying an individual
  • Personal data relating to criminal convictions