1. Who we are
Refresh Mortgage Network Limited (company number 11614569, registered office 207 Knutsford Road, Grappenhall, Warrington, Cheshire WA4 2QL) is the data controller for personal data collected through this website and in the course of applications to join the network, introducer registrations and enquiries. For anything about your personal data, email contact@refreshnetwork.co.uk or write to the registered office. This policy is governed by the UK GDPR and the Data Protection Act 2018.
2. Who this policy covers
Brokers, advisers and firm principals who enquire about or apply to join the network; individuals at firms we carry out due diligence on (directors, advisers, shareholders); introducers; and visitors to this website. If you become a member, the Appointed Representative Agreement and the privacy notices issued to your clients also apply; this policy does not cover the personal data of your clients, which is governed by those documents.
3. What we collect and where it comes from
- From you: name, firm, role, contact details, region, number of advisers, your current network or authorisation status, approximate annual commission, your enquiry, your answers about experience, qualifications and CAS status, and anything you send us. If you apply to join: identity documents, employment and regulatory history for the last six years, qualifications, financial information about your firm, and bank details for payments.
- From public and regulatory sources, when you apply: Companies House, the FCA Register and Directory, sanctions and politically-exposed-person lists, and the register of disqualified directors.
- From third parties, when you apply: credit reference agencies (a soft or hard search, as we tell you at the time), the Disclosure and Barring Service (basic or standard checks, as the role requires), regulatory references from your previous principals and employers, and professional-indemnity insurers.
- Automatically: basic technical data about your visit (IP address, browser, pages viewed) and, only if you accept it in the cookie banner, a single analytics cookie. Calculator inputs are not stored unless you submit them in a form.
4. Why we use it and our lawful bases
- Answering your enquiry and arranging a call — to take steps at your request before entering a contract, and our legitimate interest in responding to business enquiries.
- Assessing an application to join the network — to take steps before entering the Appointed Representative Agreement; to comply with our legal and regulatory obligations as an FCA-authorised principal (fitness-and-propriety assessment, regulatory references, financial-crime checks, appointment notifications); and our legitimate interest in protecting the network and its members' clients.
- Criminal-records (DBS) data — processed only where the FCA regime requires us to assess fitness and propriety, under Schedule 1 to the Data Protection Act 2018 (regulatory requirements relating to unlawful acts and dishonesty), in accordance with our appropriate policy document. Results are used only for the decision and are not retained beyond the record of the outcome.
- Running the introducer scheme — to perform the Introducer Terms with you and to meet tax and accounting obligations.
- Business marketing — our legitimate interest in telling intermediaries about the network. Where the law requires consent (for example email marketing to sole traders and partnerships) we ask for it. You can opt out at any time using the link in any email or by contacting us.
- Running and securing this website — our legitimate interests in operating, improving and protecting the site; analytics cookies only with your consent.
- Legal claims and regulatory requests — our legitimate interests and legal obligations.
5. Automated decision-making
Our systems assemble and check application information and flag issues. Decisions on applications, and on any adverse finding, are taken by a named individual in our compliance function, not solely by automated means. You can ask for any decision to be explained and reviewed.
6. Who we share it with
- The Financial Conduct Authority (appointment notifications and regulatory reporting) and other regulators or law-enforcement bodies where required.
- Credit reference, identity-verification, sanctions-screening and DBS providers, for the checks described above.
- Your previous principals and employers, when we request regulatory references; and future principals, when they request references about you after you leave.
- Our professional-indemnity insurers and brokers, lenders, mortgage clubs and product providers, to the extent needed to appoint you, open agencies and underwrite the network.
- Our funding partner, only if you choose to use Refresh Advance, and only case-level information needed to operate it.
- Suppliers who process data on our behalf under contract: cloud hosting and database services, email services, document and AI tooling used to assemble and check files, and professional advisers.
We do not sell personal data.
7. Where it is kept
Our systems are hosted on secure cloud infrastructure. Where a supplier processes personal data outside the United Kingdom, we rely on UK adequacy regulations or the UK International Data Transfer Agreement (or Addendum) to protect it.
8. How long we keep it
- Enquiries that do not lead to an application: 24 months from last contact.
- Unsuccessful applications: 12 months from the decision, then deleted, except where a longer period is needed to meet regulatory expectations on repeat applications.
- Members and their advisers: for the duration of membership and six years after it ends, to meet FCA record-keeping and regulatory-reference obligations (references cover six years).
- Introducers: for the duration of the arrangement and six years after the last payment, for tax purposes.
- Website analytics data: 26 months.
9. Your rights
You can ask us to: give you a copy of your personal data; correct it; delete it; restrict how we use it; provide it to you or another organisation in a portable format; and stop processing based on legitimate interests, including direct marketing, which we will always stop on request. You can also object to automated decision-making. To exercise any right, email contact@refreshnetwork.co.uk. We respond within one month. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
10. Security
We use access controls, encryption in transit and at rest, audit logging and supplier due diligence to protect personal data. No transmission over the internet is completely secure; if you suspect an email or call claiming to be from us is not genuine, check with us using the contact details on this site before acting on it, and never make a payment on the strength of an email alone.
11. Changes
We will publish any changes to this policy on this page and, where they are significant, tell applicants, members and introducers directly.