PEXA – UK Privacy Policy

Page updated: Feb 2024
Version: 3.0

 

It is important that you read and retain this Privacy Policy, together with any related Privacy Notice in connection with our collection or processing of Personal Data about you, so that you are aware of how and why we are using such information and what your rights are under the UK Data Protection Legislation.

What is the purpose of this document?

Digital Completion UK Limited (“PEXA”) is part of PEXA Group Limited (ASX: PXA) (“PEXA Group”). In this Privacy Policy we refer to PEXA as “we“, “us“, or “our“. In some circumstances we operate as a Data Controller and in others as a Data Processor. When we operate as a Data Controller, we are responsible for deciding how we collect, hold, use, and share personal information about you. When we operate as a Data Processor, the Data Controller is responsible for deciding how we collect, hold, use, and share personal information about you.

PEXA is a Data Controller for the Personal Data of individuals we interact directly with at Lenders, Law Firms and other prospective or existing business partners (“Customer Personal Data“), and a Data Processor for the customers / clients of these business partners.

This UK Privacy Policy makes you aware of how and why your Personal Data will be used, and how long it will usually be retained for. It provides you with certain information that must be provided under the UK General Data Protection Regulation (“UK GDPR”).

Data Protection Principles

We will comply with data protection law and principles so, your data will be:

  • used lawfully, fairly and in a transparent way;
  • collected only for valid purposes that we have clearly explained to you, and not used in any way that is incompatible with those purposes;
  • relevant to the purposes we have told you about and limited only to those purposes;
  • accurate and kept up to date;
  • kept only as long as necessary for the purposes we have told you about; and,
  • kept securely.

Data Controller

We respect your privacy and will only use information for specified and lawful purposes under current UK Data Protection Legislation.

By using our Services, Websites and Platforms, or when you provide information when registering for Events that we host, you consent to the collection, use and sharing of your data as described in this Privacy Policy.

Our Services, Websites and Platforms, are not intended for children and we do not knowingly collect personal information relating to children.

We have appointed a Data Protection Officer (“DPO”) who is responsible for overseeing queries in relation to this Privacy Policy. If you have any queries, including those relating to a request to exercise your rights, please contact the DPO using the contact details below.

Data Controller: Digital Completion UK Ltd (Trading name PEXA). ICO Registration reference: ZB100560.

Address: First Floor, 85 Great Portland Street, London, W1W 7LT.

Data Protection Officer: Mr Matt Ellis, uk.dpo@pexa.com.au.

What is Personal Data

Personal Data is defined by the UK GDPR and the Data Protection Act 2018 (collectively, “UK Data Protection Legislation“) as any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.

Put simply, Personal Data is any information about a Data Subject that enables them to be identified. Personal Data covers information such as a Data Subject’s name and contact details, but it also covers identification numbers, electronic location data, and other identifiers.

Definitions

Automated Decision-Making (“ADM”) means when a decision is made which is based solely on Automated Processing (including profiling) which produces legal effects or significantly affects an individual. The UK GDPR prohibits Automated Decision-Making (unless certain conditions are met) but not Automated Processing.

Consent means agreement which must be freely given, specific, informed and be an unambiguous indication of the Data Subject’s wishes by which they, by a statement or by a clear positive action, signify agreement to the Processing of Personal Data relating to them.

Data Controller means the person or organisation that determines when, why and how to process Personal Data. They are responsible for establishing practices and policies in line with the UK GDPR.

Data Processor means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Controller. Processors act on behalf of the relevant Data Controller and under their authority.

Data Subject means an individual, identified or identifiable natural person about whom we hold Personal Data. Data Subjects may be nationals or residents of any country and may have legal rights regarding their Personal Data.

Data Privacy Manager (“DPM”) means the Company Data Protection Officer or such other person appointed by the Company who is responsible for data protection compliance.

UK GDPR means the General Data Protection Regulation ((EU) 2016/679) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 as modified by Schedule 1 to the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419). Personal Data is subject to the legal safeguards specified in the UK GDPR. The UK GPDR is supplemented by, and must be read in conjunction with, the Data Protection Act 2018 (“DPA 2018”). The DPA 2018 sets out separate data protection rules for law enforcement authorities, extends data protection to some other areas such as national security and defence, and sets out the Information Commissioner’s functions and powers.

Personal Data means any information relating to an identified or identifiable natural person (Data Subject).

Personal Data Breach means any act or omission that compromises the security, confidentiality, integrity or availability of Personal Data or the physical, technical, administrative or organisational safeguards that we or our third-party service providers put in place to protect it. The accidental or unlawful destruction, loss, or unauthorised access, disclosure or acquisition, of Personal Data is a Personal Data Breach.

Process or Processing means operation or set of operations which is performed on Personal Data or on sets of Personal Data whether or not by automated means, such as collection, recording, organisation, structuring, storage, alteration, retrieval, consultation, use, disclosure, dissemination, restriction, erasure or destruction.

The Data We Collect

We collect Personal Data ourselves only when we have a valid legal basis to do so. We may rely on your consent or that the Processing is necessary to fulfil our contractual arrangements. We also collect Personal Data from you either directly or indirectly, when using our Services, Websites or when our Platforms are accessed. We may also receive Personal Data from various third parties and from publicly available sources such as Companies House in the United Kingdom. Through the use of our Services, we may also collect Data Subject information, including but not limited to:

  • name, job title / details, contact details (e.g. personal or business address, personal or corporate email, telephone number(s), etc.), username and password;
  • date of birth;
  • photo ID;
  • occupation information;
  • borrower(s) and associated property information;
  • financial, banking or other payment information;
  • ‘PEXA Pay’ payee / beneficiary information;
  • information necessary to process and analyse documents such as title deeds for lodgement purposes, enable payment transactions, or other information required to deliver our core Services;
  • technical information as a result of configuring the Services, including IP addresses, geographic location, browser-type, device- type, operating system, date and time stamp; and,
  • other information including the interactions you may have with customer support.

End-user Data

You may provide us with ‘end-user Personal Data’ (“Consumer Personal Data”), including through your use of our Services. Where this is the case, you represent and warrant that you have received consent from the end-user to obtain and share the Consumer Personal Data with us as a Data Processor. For the remainder of this Privacy Policy, “data” and “Personal Data” refer to both Customer Personal Data and Consumer Personal Data.

How We Use Data

We use data for a variety of purposes, such as:

  • delivering our Services;
  • processing transactions necessary for property completion;
  • optimising customer experience;
  • providing customer support for our Services;
  • security and fraud prevention;
  • analytical purposes;
  • performance of our contractual arrangements; and,
  • complying with applicable laws or legislation.

You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making.

We will only retain Personal Data for so long as to fulfil the purposes for which it was collected as described in this Privacy Policy. Where we are acting as the Data Processor, this will be in line with our contract with the Data Controller. Where we are acting as the Data Controller, we will carefully consider retention periods and work to retain Personal Data for the shortest possible period under existing law or best practice. After this period, we will securely destroy your personal information in accordance with our data retention schedule.

Legitimate Interest

Our legitimate interests include record-keeping, administrative purposes and operating, maintaining, and improving our Website or Platform experience, and developing new service offerings. Additionally, one of our legitimate interests is to prevent fraud and money laundering, by completing identity verification where applicable.

By agreeing to use our Services, you agree that we are permitted to collect, use, share and store anonymised (or pseudonymised) and aggregated data for analytics, metrics, reporting and other legitimate business purposes.

Cookies and Other Technologies

Our Websites or Platforms may use Cookies and Other Technologies to help us safely authenticate users, understand visitor / user behaviour, for security and fraud prevention purposes, and/or to inform us about which parts of the Website visitors go to.

Cookies are text files containing small amounts of information that are transferred to and stored on your device when you visit one of our Websites. Cookies are then sent back to us on each subsequent visit, or to another Website that recognises that Cookie. Cookies are useful because they allow us to recognise a user’s device and to remember a user’s actions and preferences over a period of time and improve your experience the next time you visit. We consider the information collected from Cookies as non-Personal Data; however, IP addresses or similar identifiers are considered as Personal Data. Disabling certain cookies may impact the functionality of our Websites or Platforms.

Information is collected and used by us in accordance with the Cookies Policy and this Privacy Policy.

Location

When you use our Platforms, we may receive technical data about the device used to access the Platform, including device ID, operating system, browser type, IP address, and location (collectively, “Device Data“). Device Data may be used as part of our technical and organisational security measures which are used to identify the device and log and authenticate users accessing our Websites or Platforms. Device Data may be shared, along with information about any fraudulent transactions using the device with our Sub-Contractors. They may compare and add the Device Data, and any fraud-related data, to a database to identify and block access to our Websites or Platforms by devices that have performed questionable or fraudulent activity.

Data Transfers

In compliance with applicable laws, we may use, process, transfer, and share your data. We may combine this data with other information collected from publicly available information, including third-party sources.

By using our Services, Websites or Platforms or by providing Personal Data to us, you acknowledge and agree that Personal Data may be sent to and processed in countries outside your country of residence. Some of these countries may not have data protection laws that provide an equivalent level of data protection as the laws in the UK; however, we take all appropriate steps to ensure Personal Data is handled in accordance with applicable UK Data Protection Legislation. Personal Data relating to Data Subjects in the UK is governed by the UK International Data Transfer (Addendum), Art. 46 GDPR. These contractual clauses ensure appropriate data protection safeguards can be used as a ground for data transfers to third countries.

We may share data, including Personal Data, with Sub-Contractors to deliver our Services, Websites or Platform. These Sub-Contractors include business partners, completion and delivery services, analytics providers, IT specialists and product developers. Sub-Contractors are contractually bound to use and process Personal Data we share for the permitted purposes only, as well as use adequate technical and operational measures to protect Personal Data from unauthorised access and use. Permitted purposes may include providing payment processing, verifying, and authenticating identity, sanctions screening, document scanning, processing, and storage. Sub-Contractors may be located outside of the United Kingdom.

Lawful Basis

Most commonly your information is collected and processed for the performance of a contract. We will only process your Personal Data where it is necessary to support the legitimate interests of our business or with those we may have shared your information, except where these are overridden by your interests or fundamental rights and freedoms which require the protection of Personal Data.

We will obtain consent from customers / clients to process information in this way. You have the right to withdraw your consent at any time. Once consent has been refused or withdrawn, we will no longer process your Personal Data.

We may share data, including Personal Data to:

  • comply with applicable laws, court orders, or governmental agencies;
  • protect the security or integrity of our customers and our Databases, Services, Websites or Platforms; or,
  • prevent legal liability.

We may also share or exchange Personal Data with tax authorities and law enforcement for the purpose of fraud protection or money laundering prevention.

Your Rights

Under UK Data Protection Legislation, you have the following rights, which we will always work to uphold. These include rights to:

(a) withdraw Consent to Processing at any time;

(b) receive certain information about the Data Controller’s Processing activities;

(c) request access to your Personal Data that we hold;

(d) prevent our use of your Personal Data for direct marketing purposes;

(e) ask us to erase Personal Data if it is no longer necessary for the purposes for which it was collected or processed or to rectify inaccurate data or to complete missing data;

(f) restrict Processing in specific circumstances;

(g) challenge Processing which has been justified on the basis of our legitimate interests or in the public interest;

(h) request a copy of an agreement under which Personal Data is transferred outside of the UK;

(i) object to decisions based solely on Automated Processing, including profiling (ADM);

(j) prevent Processing that is likely to cause damage or distress to the Data Subject or anyone else;

(k) be notified of a Personal Data Breach which is likely to result in high risk to your rights and freedoms;

(l) make a complaint to the supervisory authority; and,

(m) in limited circumstances, receive or ask for their Personal Data to be transferred to a third party in a structured, commonly used, and machine-readable format.

Change of purpose

We will only use your Personal Data for the purposes for which it was collected. Any changes in the processing of your Personal Data for another purpose will be communicated with you and we will also explain the legal basis which allows us to do so.

Protecting Your Data

The Company processes Personal Data in a way that ensures its security, by using appropriate technical and organisational security measures. This is to protect against unauthorised or unlawful Processing and protection against accidental loss, destruction, or damage. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need-to-know. They are only permitted to process your personal information on our instructions, and they are subject to a duty of confidentiality. They must also comply with their obligations under applicable data protection legislation. Details of these measures may be obtained by contacting the from our Data Protection Officer at uk.dpo@pexa.com.au.

We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so. This will be done in line with our Data Protection Policy.

Withdrawing Consent

You can withdraw your consent at any time. If you wish to do so or have any questions, please contact our Data Protection Officer at uk.dpo@pexa.com.au.

Please note that if you do withdraw your consent, we may not be able to provide our Services to you. We will let you know in writing if this is the case.

You can also contact the ICO for more information about your rights of access, or if you are unhappy about how we have handled your information:

Post 

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF;  

Telephone

0303 123 1113 (local rate); or,

Fax

01625 524 510.

Changes to this Privacy Policy

We reserve the right to update this Privacy Policy at any time, and we will provide you with a new Privacy Policy when we make any substantial updates. We may also notify you in other ways from time to time about processing of your personal information. These changes will be posted on our website.

PEXA is the trading name of Digital Completion UK Limited.
Registered Office: 85 Great Portland Street, First Floor, London W1W 7LT.
Registered in England and Wales. Company No. 12830944.
VAT Registration Number: GB 455 8225 75

Our website uses cookies to make your browsing experience better. By using our site you agree to our use of cookies. Learn more.