Privacy Policy
JC Mortgages Limited
Go to:
1. About us
JC Mortgages Limited, referred to in this Data Protection Statement as “JC Mortgages”, “we”, “us” or “our”, provides mortgage and insurance intermediary services in Ireland.
Our contact details are:
JC Mortgages Limited
24 Millrace Road Apartments
Phoenix Park Racecourse
Castleknock
Dublin 15
Ireland
Telephone: 01 810 2032
Email: info@jcmortgages.ie
Website: www.jcmortgages.ie
JC Mortgages Limited is regulated by the Central Bank of Ireland.
For the purposes of applicable data protection law, JC Mortgages Limited is the data controller of personal data that we collect and use in connection with our mortgage and insurance intermediary services, our website and the operation of our business.
2. Contact details
If you have any questions about this Data Protection Statement, wish to exercise a data protection right or have concerns about how we use your personal data, please contact:
Data Privacy Contact
JC Mortgages Limited
24 Millrace Road Apartments
Phoenix Park Racecourse
Castleknock
Dublin 15
Ireland
Telephone: 01 810 2032
Email: info@jcmortgages.ie
Person responsible for data protection matters
The person currently responsible for dealing with data protection matters within JC Mortgages is:
Name/role: John Coleman, Owner
Email: john@jcmortgages.ie
Postal address: 24 Millrace Road Apartments, Phoenix Park Racecourse, Castleknock, Dublin 15, Ireland.
3. Purpose of this Data Protection Statement
This Data Protection Statement explains how JC Mortgages collects, obtains, uses, stores, discloses, transfers and otherwise processes personal data.
For the purposes of this statement:
“Personal data” means any information relating to an identified or identifiable living individual. A person may be identifiable directly or indirectly, including by reference to a name, identification number, online identifier, location information or factors relating to that person’s physical, economic, social or other identity.
This statement is intended to provide the information required under applicable data protection law, including the General Data Protection Regulation and the Irish Data Protection Act 2018.
It explains:
- what personal data we process;
- where we obtain it;
- why we process it;
- the legal bases on which we rely;
- who we may disclose it to;
- whether it may be transferred outside the European Economic Area;
- how long we retain it;
- the rights available to individuals; and
- how to contact us or make a complaint.
4. Who this data protection statement applied to
This Data Protection Statement applies to personal data relating to:
- prospective customers and people who make an enquiry;
- current customers;
- former customers;
- joint applicants; guarantors and beneficial owners, where relevant
- dependants and household members, where relevant to an application;
- people whose income, assets, liabilities or other circumstances are relevant to an
- complainants;
- website users;
- Any other individual whose personal data is provided to us in connection with our services
In this statement, these individuals may be referred to collectively as “you”.
Information about other people
Where you provide us with personal data about another person, you should:
- ensure that you are authorised or otherwise permitted to provide the information;
- tell the person that you are providing their information to us;
- direct the person to this Data Protection Statement; and
- provide any additional notice required in the circumstances.
Providing information about another person does not remove our responsibility to provide that person with appropriate transparency information where required by law.
5. Sources of personal data
We may obtain personal data directly from you or from other sources.
5.1 Information provided directly by you
We may collect personal data when you:
- contact us by telephone, email, post, website form or another communication channel;
- attend a meeting or consultation;
- complete a fact-find, application or proposal form;
- create or use an online mortgage application;
- upload documentation to an online portal;
- request mortgage or insurance advice;
- apply for a mortgage, insurance policy or other product;
- communicate with our employees or contractors;
- make a complaint;
- exercise a data protection right;
- subscribe to marketing;
- use our website; or
6. Categories of personal data
The personal data we process will depend on the service requested and your circumstances.
6.1 Identity data
Identity data may include:
- name;
- title;
- date of birth;
- signature;
- nationality;
- marital or civil status;
- gender, where relevant and lawfully required;
- PPS number, where required;
- passport details;
- driving-licence details;
- national identity documentation
6.2 Contact data
Contact data may include:
- home address;
- previous addresses;
- correspondence address;
- email address;
- telephone number; and
- communication preferences.
6.3 Personal, family and household data
This may include:
- marital or relationship status;
- number and age of dependants;
- residency status;
- citizenship or right-to-reside information;
6.4 Employment and professional data
This may include:
- employer name and address;
- occupation and job title;
- employment status;
- employment history;
- salary and remuneration;
- bonuses, commission and allowances;
- employment contracts;
- salary certificates;
- payslips;
- business ownership
6.5 Financial and economic data
Financial data may include:
- income;
- expenditure;
- bank statements;
- savings;
- investments;
- assets;
- property ownership;
- liabilities;
- personal loans;
- pension contributions;
- source of wealth
7. Our legal bases for processing personal data
We will only process personal data where we have a lawful basis.
Depending on the processing activity, we may rely on one or more of the following grounds.
7.1 Contract and steps before entering a contract
We process your Personal Data where necessary to perform our obligations under a contract with you, or to take steps at your request prior to entering into a contract (such as assisting you to secure a mortgage loan offer or suitability assessment from a product provider).
7.2 Legal obligation
We will need to process your Personal Data to comply with a legal obligation, for example the provision of mortgage advice, anti-money laundering checks, sanctions screening, record keeping, responding to the Central Bank of Ireland, Revenue, and other statutory bodies.
7.3 Legitimate interests
We may need to process your Personal Data to pursue our legitimate business interests, for example for administrative purposes, to provide information to you, to expand our business opportunities, to operate, evaluate, maintain, develop and improve our website and services or to maintain their security and protect intellectual property rights.
We will not process your Personal Data on a legitimate interest basis where the impact of the processing on your interests or fundamental rights and freedoms outweigh our legitimate interests.
You may object to any processing we undertake on this basis. If you do not want us to process your Personal Data on the basis of our legitimate interests, contact us at info@jcmortgages.ie and we will review our processing activities
7.4 Consent
For certain processing activities we may rely on your consent.
Where we are unable to collect consent for a particular processing activity, we will only process the Personal Data if we have another lawful basis for doing sYou may withdraw your consent at any time by contacting us. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.
7.6 Vital interests
In exceptional circumstances, we may process personal data where necessary to protect your vital interests or the vital interests of another person.
This basis would generally only be used in an emergency where another legal basis is unavailable.
8. Our processing activities
We only use your personal data where we have a lawful basis to do so.
| Purpose | Examples | Legal Basis |
|---|---|---|
| To respond to your enquiry and take steps before entering a contract | Discussing your requirements, collecting fact find information, obtaining quotes, assessing eligibility | Performance of a contract or taking steps at your request before entering into a contract |
| To provide mortgage or insurance intermediary services | Advising, recommending products, arranging applications, liaising with lenders or insurers, administering your file | Performance of a contract or taking steps at your request before entering into a contract |
| To comply with legal and regulatory obligations | Anti-money laundering checks, sanctions screening, record keeping, responding to the Central Bank of Ireland, Revenue, An Garda Síochána or other statutory bodies | Compliance with a legal obligation |
| To manage and protect our business | File administration, service oversight, systems security, fraud prevention, staff training, legal claims, complaint handling, internal governance | Legitimate interests |
| To send direct marketing | Updates about services or products that may be relevant to you | Your consent, where required by law |
| To operate and improve our website and digital services | Website security, analytics, troubleshooting and performance monitoring | [Consent and/or legitimate interests — amend to reflect actual cookie and analytics practice] |
9. Special category personal data
In some cases, particularly where you ask us to arrange protection or life assurance products, we may process special category data, including health information.
Special category personal data is personal data that receives additional protection under data protection law.
We will only process this information where it is necessary and lawful, and where an additional condition for processing under data protection law applies.
This may include:
- your explicit consent, where required
- compliance with legal obligations
- the establishment, exercise or defence of legal claims
- another condition permitted by applicable data protection law
Where we collect or pass health information to an insurer or product provider, that insurer or provider may act as a separate controller of that data for underwriting and policy administration purposes. You should also read the privacy notice of the relevant insurer or product provider.
We ask that you only provide sensitive personal data where it is necessary for the product or service requested.
It includes information concerning:
- health;
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- genetic data;
We will only process health information where:
- it is necessary for the service requested;
- there is an Article 6 lawful basis;
- an additional Article 9 condition applies; and
- appropriate safeguards are in place.
Depending on the circumstances, the additional condition may include:
- your explicit consent;
- the establishment, exercise or defence of legal claims; or
- another condition permitted under applicable law.
Where possible, health information should be provided directly to the insurer through the insurer’s approved process.
An insurer or assurance company receiving health information will generally act as a separate data controller for underwriting, policy administration, claims and related purposes. You should review the privacy notice of the relevant provider.
9.2 Criminal-offence data
We will only process information relating to criminal convictions or offences where authorised by law and where appropriate safeguards apply.
9.3 Data minimisation
You should only provide special category or other highly sensitive information where it is relevant and necessary for the service requested.
10. Disclosure of personal data
In certain circumstances, where necessary and lawful, we may disclose Personal Data to third parties as follows:
- mortgage lenders and other credit providers
- insurers, assurance companies and other product providers
- service providers that support our business, such as IT, cloud storage, CRM, email, document management, hosting, print/post and backup providers
- identity verification, anti-money laundering, sanctions, fraud prevention and compliance support providers
- accountants, solicitors, auditors and other professional advisers
- employers, accountants or solicitors involved in your application, where relevant
- introducers or referrers, where this is lawful and necessary
regulators, ombudsmen, law enforcement agencies, courts and statutory bodies, including the Central Bank of Ireland, the Financial Services and Pensions Ombudsman, Revenue and An Garda Síochána, where required or permitted by law
11. Security measures
We will take all steps reasonably necessary to ensure that all Personal Data is treated securely in accordance with this Data Protection Statement and the relevant law, including the GDPR.
In particular, we have put in place appropriate technical and organisational procedures to safeguard and secure the Personal Data we process.
We monitor for and do everything we can to prevent security breaches of the Personal Data that we process.
Once we have received your Personal Data, we will use strict procedures and security features for the purpose of preventing unauthorised access and ensuring that only those who need to have access to your Personal Data can access it.
12. Transfers outside the European Economic Area
Some personal data may be accessed, supported or processed outside the European Economic Area.
Based on our current operations, this may include access or processing involving:
- IT or support personnel in India;
- a freelance contractor in the Philippines;
- team members working from Brazil; and
- international service providers, including Microsoft, monday.com and Paperform.
The location of data processing may change where a service provider changes its infrastructure, subprocessors or support arrangements.
Where we rely on the Standard Contractual Clauses under Article 46.2 of the GDPR adopted by the EU Commission, we will also assess whether the laws and practices of the destination country may affect the effectiveness of the safeguard and whether supplementary measures are required.
You may contact us for further information about:
- the countries to which personal data is transferred;
- the categories of overseas recipients;
- the transfer mechanism relied upon; and
- how to obtain a copy of or information about the relevant safeguards.
Commercially sensitive or security-related information may be redacted where appropriate.
13. Cookies and similar technologies
Cookies are small text files placed on your computer or mobile device by websites that you visit, and they help us improve the products and services that we offer you. They are used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site. Cookies may allow a website to remember your activity over a period of time. Cookies are optional and you do not have to accept them.
Further information on the cookies we use on the website and the purpose behind their respective uses are set out in our Cookie Policy.
14. Third-party websites and platforms
Our website may contain links to third-party websites, services or platforms, including:
- mortgage lenders;
- insurers;
- product providers;
- online application platforms;
- social-media platforms; and
These organisations may collect and process personal data as separate controllers.
This Data Protection Statement does not govern the independent processing activities of third parties. You should review the privacy notice and cookie information of the relevant third party before providing personal data or using its services.
15. Retention of personal data
Our general retention approach is set out below.
15.1 Regulated customer and transaction records
Where we provide, arrange or advise on a regulated financial service, relevant records will generally be retained for six years after:
- the end of the customer relationship or the last service provided;
- completion of the relevant transaction;
- discontinuance of the application; or
A longer period may apply where:
- required by law or regulation;
- directed by a regulator;
- a complaint or legal claim is ongoing or reasonably anticipated;
- the record relates to a continuing product or relationship; or
- another lawful reason requires continued retention.
15.2 Prospective customers and unsuccessful applications
Where you make an enquiry or request a service but do not become a customer, we will generally retain the relevant information for up to 12 months after the last meaningful contact or discontinuance of the enquiry or application.
A different period may apply where:
- you have requested follow-up contact;
- you have consented to a longer period;
- regulatory requirements apply;
- the records are required for a complaint or legal claim; or
- another lawful basis supports the retention.
15.3 Anti-money laundering records
Customer due-diligence, identity-verification and transaction records will be retained for the period required under applicable anti-money laundering legislation.
Records may be retained for a longer period where permitted or required by law or where a competent authority directs that they be retained.
15.4 Complaints and disputes
Complaint and dispute records will be retained for as long as necessary to:
- investigate and resolve the matter;
- comply with regulatory requirements;
- respond to an ombudsman or regulator; and
- establish, exercise or defend legal claims.
15.5 Marketing records
Marketing information will generally be retained until:
- you withdraw consent;
- you object to direct marketing;
- the information is no longer accurate or relevant; or
- we determine that there has been no meaningful engagement for an appropriate period.
We may retain a minimal suppression record after an opt-out to ensure that further marketing is not sent contrary to your wishes.
15.6 Website and analytics information
Website logs, analytics data and cookie information will be retained according to:
- the purpose of the relevant technology;
- the configuration of the service;
- the cookie duration shown in our Cookie Policy; and
- security and legal requirements.
15.8 Secure deletion and anonymisation
At the end of the applicable retention period, personal data will be:
- securely deleted;
- securely destroyed; or
- irreversibly anonymised,
unless continued retention is required or permitted by law.
16. Your data protection rights
Your rights depend on the circumstances and the legal basis on which we process your information. A right may be subject to restrictions or exemptions under applicable law.
16.1 Right of access
You may request:
- confirmation as to whether we process your personal data;
- a copy of your personal data; and
- information about how it is processed.
The first copy will generally be provided free of charge. A reasonable fee may be charged for additional copies or where a request is manifestly unfounded or excessive, where permitted by law.
We may withhold or redact information where disclosure would adversely affect the rights and freedoms of another person or where another lawful restriction applies.
16.2 Right to rectification
You may ask us to correct inaccurate personal data or complete incomplete personal data.
We may need to verify the corrected information before changing our records.
16.3 Right to erasure
You may ask us to erase personal data in certain circumstances, including where:
- it is no longer necessary for the purpose for which it was collected;
- you withdraw consent and no other lawful basis applies;
- you successfully object to processing;
- the information has been unlawfully processed; or
- erasure is required by law.
The right to erasure does not apply in all circumstances. We may retain information where necessary:
- to comply with a legal obligation;
- for the establishment, exercise or defence of legal claims;
- for regulatory record-keeping;
- for public-interest purposes recognised by law; or
- where another lawful exemption applies.
16.4 Right to restriction
You may ask us to restrict processing where:
- you contest the accuracy of the personal data;
- the processing is unlawful and you prefer restriction to erasure;
- we no longer need the information but you require it for a legal claim; or
- you have objected to processing and the objection is being considered.
Restricted personal data will generally only be stored unless:
- you consent to another use;
- it is required for a legal claim;
- it is required to protect another person’s rights; or
- an important public-interest reason applies.
16.5 Right to data portability
Where processing is:
- based on consent or contract; and
- carried out by automated means,
you may have the right to receive personal data you provided to us in a structured, commonly used and machine-readable format.
You may also request that it be transmitted directly to another controller where technically feasible.
This right does not apply to all personal data and must not adversely affect the rights and freedoms of another person.
16.6 Right to object to legitimate-interest processing
You may object to processing based on legitimate interests.
We will stop the processing unless:
- we demonstrate compelling legitimate grounds that override your interests, rights and freedoms; or
- the processing is necessary for the establishment, exercise or defence of legal claims.
16.7 Right to object to direct marketing
You may object to direct marketing at any time.
Where you object, we will stop using your personal data for direct-marketing purposes.
16.8 Right to withdraw consent
Where we rely on consent, you may withdraw it at any time.
Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Withdrawal of consent may mean that we cannot continue a particular optional service or activity. We will explain the consequences where relevant.
16.9 Rights relating to automated decision-making
You may have the right not to be subject to a decision based solely on automated processing, including profiling, where the decision produces legal effects or similarly significantly affects you.
Further information is provided in section 18.
16.10 Exercising your rights
To exercise a right, contact:
Email: info@jcmortgages.ie
Telephone: 01 810 2032
Post: JC Mortgages Limited, 24 Millrace Road Apartments, Phoenix Park Racecourse, Castleknock, Dublin 15, Ireland
Please identify:
- the right you wish to exercise;
- the personal data or processing activity concerned; and
- any information that will help us locate the relevant records.
16.11 Identity verification
We may ask for information reasonably necessary to confirm your identity.
This is intended to ensure that personal data is not disclosed to or altered at the request of an unauthorised person.
We will not request more identity information than is reasonably necessary.
16.12 Response period
We will generally respond without undue delay and within one month of receiving a valid request.
The period may be extended by up to two further months where permitted by law, taking account of the complexity and number of requests. We will tell you if an extension is required and explain the reason.
16.13 Refusal or fee
Where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may:
- charge a reasonable fee; or
- refuse to act on the request,
where permitted by law.
If we refuse a request, we will explain the reason and inform you of your right to complain to the Data Protection Commission and seek a judicial remedy.
16.14 Complaint
If you have a concern about how we use your personal data, please contact us first and we will try to resolve it.
You also have the right to make a complaint to the Data Protection Commission.
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28
Ireland
Website: www.dataprotection.ie
Direct marketing
We will only send direct marketing where it is lawful to do so.
Depending on the circumstances, we may rely on:
- your consent; or
- another basis permitted by applicable electronic-marketing and data protection law.
You may stop direct marketing by:
- using an unsubscribe link in an electronic communication;
- replying to the communication;
- emailing info@jcmortgages.ie; or
contacting us by telephone or post.
18. Automated decision making and profiling
We do not usually make decisions about you solely by automated means where those decisions produce legal effects or similarly significant effects.
However, lenders, insurers and other product providers may use automated systems when assessing applications, pricing, underwriting, fraud risk or eligibility. Where relevant, those providers will explain that processing in their own privacy notices.
19. Amendments to this data protection statement
We may amend this Data Protection Statement from time to time to reflect changes in:
- our services;
- our processing activities;
- our systems;
- our suppliers;
- our organisational structure;
- applicable law;
- regulatory requirements; or
- guidance from a supervisory authority.
The current version will be published on our website.
We will post any changes on the Website and when doing so will change the effective date at the top of this Data Protection Statement.
In some cases, we may provide you with additional notice of changes to this Data Protection Statement, such as via email. We will always provide you with any notice in advance of the changes taking effect where we consider the changes to be material.
