Privacy
Policy
Last updated 7 September 2026
Introduction
This Privacy Notice ("Notice") explains how Cavis Marketing Limited ("Cavis", "Pocket Claim", "Data Breach Advisors", "we", "our", or "us") collects, processes, and protects personal data in the course of providing our services and conducting business operations. It also outlines the rights and choices available to you regarding your personal data.
We are committed to handling personal data lawfully, fairly and transparently in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Please read this policy carefully to understand how and why we process your data.
We provide lead generation, customer acquisition, and referral services in relation to both regulated and unregulated claims and compensation matters. This includes FCA-regulated claims management activities relating to personal injury, financial services and products, housing disrepair and employment-related claims, together with unregulated matters such as flight delay claims, data breach claims and other consumer compensation opportunities. We do not provide legal advice and are not a law firm. Where appropriate, eligible individuals may be referred to an independent professional representative or law firm.
Company Information
Cavis Marketing Limited is a company registered in England & Wales. Company Registration Number: 16437994, with its registered office at Cavis Marketing Limited, C/O Brabners LLP, 100 Barbirolli Square, Manchester, M2 3AB, United Kingdom.
Cavis Marketing Limited is an independent Data Controller of Personal Data and registered with the Information Commissioner's Office (ICO) under registration number ZB897675.
Email address: privacy@cavis.co.uk
What Personal Data We Collect
We may collect and process the following categories of Personal Data:
| Category | Examples |
|---|---|
| Identity | Information that identifies the person making the enquiry, the claimant or a representative, including title, full name, and date of birth. |
| Contact | Telephone number, email address, residential address, postcode and communication preferences used to administer an enquiry or contact the relevant person. |
| Claim | Information relating to a potential claim, complaint, compensation opportunity or redress matter, and compensation claim including details of the circumstances giving rise to the claim, employment information, membership information, account ownership information, information about the treatment or care concerned; the relevant healthcare provider; where the treatment occurred; whether the matter involved surgery, another procedure, or a delayed, missed or incorrect diagnosis; relevant dates; when the claimant became aware of possible harm; the claimant’s age at the relevant time; previous legal representation; the harm or outcome described; and the outcome and reason for our initial screening decision. |
| Health | Information about health, including but not limited to, additional needs and requirements, service adaptation, and support needs, physical or mental health, medical treatment, diagnoses, injuries, symptoms, deterioration, additional treatment, recovery, disability and other health outcomes relevant to the potential claim. |
| Vulnerability and Support Needs | Information relating to customer vulnerability, accessibility requirements, communication preferences, financial hardship, mental or physical health conditions, capacity considerations, safeguarding concerns, or other circumstances requiring additional support or reasonable adjustments. We limit this information to what is reasonably necessary to communicate effectively, make an appropriate adjustment, check understanding, provide requested support or administer the potential claim. |
| Marketing | Information about your marketing preferences and interactions, including but not limited to, consent records, opt-in status, opt-out status, and marketing/communication preferences. |
| Correspondence | Information contained in communications with you, including but not limited to, emails, letters, SMS messages, WhatsApp messages, live chat records, call recordings, complaint communications, and notes of conversations, records of eligibility questions, answers, verification checks, referral explanations, referral decisions, callback arrangements and attempted or completed transfers to a law firm. We record and retain telephone calls and other communications where required for regulatory compliance, quality assurance, customer protection, complaint handling, evidential purposes, staff training, fraud prevention, and the establishment, exercise or defence of legal claims. |
| Representatives and Authority | The representative’s identity and contact details, their relationship to the claimant, whether the claimant knows about and agrees to the enquiry, the scope of the authority given, and information about stated or evidenced authority. This may include parental responsibility, a power of attorney, Court of Protection deputyship or other court appointment, or status as an executor, administrator or prospective personal representative. |
| Referral and Service Records | The law firm proposed for referral; the categories of information explained to the customer; the customer’s referral and live-transfer decisions; the privacy information provided; transfer attempts and outcomes; callback arrangements; rejection or closure reasons; and, where applicable, limited referral-status information received from the law firm. |
| Technical | Information collected when you use our websites or systems, including but not limited to, device type, browser, session data, operating system, and interaction data via cookies and analytics tools. |
| Complaints | Information relating to complaints or feedback you submit, including but not limited to, complaint details, investigation records, complaint outcomes, complaint correspondence. |
| Data Protection | Information relating to data protection rights requests and regulatory compliance, including but not limited to, data protection rights requests, request records and responses, and ICO correspondence. |
How We Collect Personal Data
We may collect Personal Data about you:
Directly
We may receive your personal information from you when:
- You complete an online web form.
- You contact us using online chat.
- You contact us by telephone.
- You contact us by email.
- You contact us by post.
- Automatically by cookies or analytics technologies when using our websites.
Indirectly
We may obtain personal information about you from:
| Source | Personal Data |
|---|---|
| Big on Media Limited (Website) | We may obtain personal data about you from Big On Media Limited (trading as Join The Claim). This may include your full name, contact information, marketing contact channel choice(s), and marketing consent record. This may occur when you submit your personal data on their website for our marketing purposes, and only with your consent. They may also provide us with your updated marketing preferences, including where you have withdrawn consent for us to send you direct marketing communications. |
| Rev-X Limited (Website) | We may obtain personal data about you from Rev-X Limited. This may include your full name, contact information, marketing contact channel choice(s), and marketing consent record. This may occur when you submit your personal data on their website for our marketing purposes, and only with your consent. They may also provide us with your updated marketing preferences, including where you have withdrawn consent for us to send you direct marketing communications. |
| KP Law Limited (Website) | We may obtain personal data about you from KP Law Limited. This may include your full name, contact information, marketing contact channel choice(s), and marketing consent record. This may occur when you submit your personal data on their website for our marketing purposes, and only with your consent. They may also provide us with your updated marketing preferences, including where you have withdrawn consent for us to send you direct marketing communications. |
| Review Platforms | We may obtain personal data about you from online review platforms, including full names, feedback, and role/appointments. |
| Claimants and Representatives | If one person contacts us for another person, we may receive identity, contact, relationship, authority, claim, health and support information from the person making the enquiry. We may also obtain confirmation or further information directly from the claimant. |
| Panel Law Firms | A panel law firm may provide limited information about whether it received the referral, attempted contact, completed its independent assessment or is able to assist, together with information reasonably required to administer, reconcile and audit the referral relationship. |
Where we obtain personal data from publicly available sources, we will provide this Privacy Notice at the first point of contact or within one month of obtaining the data, unless an exemption under Article 14(5) UK GDPR applies.
Information About Other People
If you provide information about another living person, you should only do so where you are authorised or otherwise entitled to make the enquiry. We may contact that person, request evidence of your authority or ask the proposed law firm to verify it. Stating that you act for someone does not automatically authorise us to disclose their information to you or allow you to exercise their data protection rights.
Adults Represented by Another Person
Where an enquiry concerns another living adult, we may ask whether that person knows about and agrees to the enquiry and whether they can speak with us directly. If they cannot participate, we may record the representative’s stated authority and ask for proportionate supporting evidence. Formal authority may need to be verified by the law firm before the matter can proceed. Stating that a person is a representative does not automatically authorise us to disclose the claimant’s information to them.
Children
A medical negligence enquiry may concern a child. We limit collection to information reasonably required for the initial eligibility check and take the child’s interests and data protection rights into account. We may ask the person making the enquiry about parental responsibility or other authority. The law firm independently decides who may act in any resulting legal claim and may request supporting evidence. Where appropriate, we will provide privacy information in a form the child can understand.
Purposes and Lawful Basis of Processing
Under the UK GDPR, we must identify a lawful basis for each purpose of processing. We rely primarily on consent and legitimate interests, and where necessary on legal obligation.
Where we process special category data, including health information, we must also identify a separate condition under Article 9 UK GDPR. A customer’s operational decision to authorise a particular referral is separate from consent used as a lawful basis under the UK GDPR and separate from consent to receive direct marketing.
We have set out the purposes and Lawful Bases, including any additional Conditions for processing personal data, as follows:
| Purpose | Description | Lawful Basis |
|---|---|---|
| Claims Management | To contact you after having submitted your personal information to request a callback about a potential claim. These communications relate to the specific enquiry about our service and are not direct marketing. | Legitimate interest – Article 6(1)(f) UK GDPR as it is necessary to respond to the individual’s request for services in relation to potential claims. Establishment, Exercise or Defence of Legal Claims – Article 9(2)(f) UK GDPR as an additional condition for processing where Special Category Health Data relates to a claim. |
| Claims Management | To identify if you have a potential claim offered by a third-party independent SRA-regulated law firm based on eligibility criteria. | Legitimate interest – Article 6(1)(f) UK GDPR as it necessary to assess whether prospective claimants satisfy the eligibility criteria for legal claims, ensure that only appropriate and potentially meritorious claims are progressed, facilitate access to independent legal representation, operate an effective and proportionate claims assessment process, prevent unsuitable or fraudulent claims from being referred, and manage legal, regulatory and commercial risk. Establishment, Exercise or Defence of Legal Claims – Article 9(2)(f) UK GDPR as an additional condition for processing where Special Category Health Data relates to a claim. |
| Representatives and Authority | To record and verify a claimant’s authority for another person to communicate with us; receive information from that representative; and, where the claimant has expressly agreed, disclose relevant personal and health information to the representative for the purpose of administering the potential claim. | Consent – Article 6(1)(a) UK GDPR. Establishment, Exercise or Defence of Legal Claims – Article 9(2)(f) UK GDPR as an additional condition for processing where Special Category Health Data relates to a claim. |
| Claims Management | To share your information with an appropriate independent SRA-regulated law firm to progress a claim offered by that law firm. This may occur digitally, involve a live telephone transfer or a secure referral for the law firm to contact the customer. | Legitimate interest – Article 6(1)(f) UK GDPR as it necessary to facilitate the referral of, and requested by, eligible potential claimants to an appropriate independent SRA-regulated law firm, enable the law firm to assess, accept and progress legal claims, ensure the efficient administration of the claims referral process, maintain continuity of the customer's claim journey, and manage legal, regulatory and commercial risk. Establishment, Exercise or Defence of Legal Claims – Article 9(2)(f) UK GDPR as an additional condition for processing where Special Category Health Data relates to a claim. |
| Claims Management | To retain information submitted as part of a partially completed application or claim enquiry and to contact individuals who have not completed the process in order to provide reminders, request further information, assist with completion of the application process, and determine whether they remain interested in pursuing a potential claim. | Legitimate Interests – Article 6(1)(f) UK GDPR as it is necessary to retain partially completed application and enquiry information for a reasonable period to enable potential claimants to complete the claims assessment process, ensure applications are not unintentionally abandoned, verify and obtain any outstanding information required to assess eligibility, maintain continuity of the customer journey, improve administrative efficiency, avoid unnecessary duplication of applications, and manage legal, regulatory and commercial risk. Establishment, Exercise or Defence of Legal Claims – Article 9(2)(f) UK GDPR as an additional condition for processing where Special Category Health Data relates to a claim. |
| Contact Verification | To verify and validate the legitimacy and accuracy of data subjects' mobile telephone numbers and email addresses in order to prevent fraud, detect duplicate submissions across application channels, improve data quality and ensure reliable communication throughout the claims assessment process. | Legitimate interest – Article 6(1)(f) UK GDPR as it necessary to verify the accuracy and legitimacy of contact information, prevent fraud, misuse of the service and duplicate submissions, maintain the integrity and quality of customer records, ensure communications are delivered to the correct individual, facilitate the efficient assessment and progression of potential claims, and manage legal, regulatory and commercial risk. |
| Marketing | To promote the firm's products, services, claims opportunities, events and other commercial activities by sending direct marketing communications to prospective and existing customers through electronic mail, telephone, SMS, post and other permitted communication channels, and to administer marketing preferences and opt-out requests. | Consent – Article 6(1)(a) UK GDPR. Explicit Consent - Article 9(2)(a) - where special category health data is concerned). |
| Marketing | To record, maintain and manage direct marketing preferences, consents, suppression lists, unsubscribe requests and other communication preferences to ensure compliance with applicable data protection and electronic marketing legislation. | Legal Obligation – Article 6(1)(c) UK GDPR to comply with the Privacy and Electronic Communications Regulations (PECR) and UK GDPR suppression requirements. |
| Claim Updates and Notifications | To provide updates specifically requested by data subjects about a specific potential claim the data subjects have expressed and registered an interest in, including any next steps that may be available to data subjects in relation to that specific claim. | Consent – Article 6(1)(a) UK GDPR. Explicit Consent - Article 9(2)(a) - where special category health data is concerned). |
| Managing and progressing enquiries about potential claims | We use your personal information to record and assess an enquiry that you have submitted about a potential claim. This includes confirming receipt of information, requesting information needed to complete our assessment, communicating with you about the progress or closure of your enquiry, and checking eligibility for a potential claim. | Legitimate interest – Article 6(1)(f) UK GDPR as the processing is necessary for our legitimate interests in responding to and administering an enquiry about a potential claim that you have actively submitted, including obtaining the information needed to complete our assessment of that enquiry. Establishment, Exercise or Defence of Legal Claims – Article 9(2)(f) UK GDPR as an additional condition for processing where Special Category Health Data relates to a claim. |
| Call Recording and Communication Monitoring | To record, monitor, retain and review telephone calls and other customer communications for regulatory compliance, quality assurance, staff training, complaint handling, fraud prevention, evidential purposes, safeguarding vulnerable customers, and the establishment, exercise or defence of legal claims. | Legal Obligation – Article 6(1)(c) UK GDPR where recording is required to comply with FCA regulatory obligations. Legitimate Interests – Article 6(1)(f) UK GDPR as it is necessary to monitor and improve service quality, ensure employee compliance with legal and regulatory obligations, protect customers and the business from fraud and misconduct, investigate complaints, evidence customer interactions, safeguard vulnerable customers where appropriate, support staff training and quality assurance, and establish, exercise or defend legal claims. Substantial Public Interest – Article 9(2)(g) UK GDPR together with Schedule 1 Data Protection Act 2018 where special category data relating to vulnerability or health is incidentally processed for safeguarding and regulatory compliance purposes. Establishment, Exercise or Defence of Legal Claims – Article 9(2)(f) UK GDPR where relevant to complaints or legal claims. |
| Compliance Monitoring and Quality Assurance | To monitor, review and assess telephone calls and other customer communications for quality assurance, employee supervision, regulatory compliance, competence assessment, customer outcomes, coaching, performance management, complaint prevention and continuous service improvement. | Legal Obligation - Article 6(1)(c) UK GDPR including monitoring compliance with FCA rules and demonstrating effective systems and controls. Legitimate Interests – Article 6(1)(f) UK GDPR as it is necessary to assess whether prospective claimants satisfy the eligibility criteria for legal claims, ensure that only appropriate and potentially meritorious claims are progressed, facilitate access to independent legal representation, operate an effective and proportionate claims assessment process, prevent unsuitable or fraudulent claims from being referred, and manage legal, regulatory and commercial risk. Establishment, Exercise or Defence of Legal Claims – Article 9(2)(f) UK GDPR. |
| Vulnerable Customer Support and Reasonable Adjustments | To collect and record identified customer vulnerability and reasonable adjustment information to support customer's needs and requirements. | Consent – Article 6(1)(a) UK GDPR. Explicit Consent – Article 9(2)(a) UK GDPR. |
| Vulnerable Customer Support and Reasonable Adjustments | To share vulnerability and/or health information with the law firm responsible for assisting with the vulnerable customers claim to better support that customer's needs and requirements. | Consent – Article 6(1)(a) UK GDPR. Explicit Consent – Article 9(2)(a) UK GDPR where you expressly consent to us sharing health or vulnerability information with a law firm, professional representative or other claims-related service. |
| Complaints | To receive, record, investigate, manage and resolve complaints in accordance with legal, regulatory and contractual obligations, including communicating with complainants and determining appropriate outcomes and remedial actions. | Legitimate Interests – Article (6)(1)(f) UK GDPR as it is necessary to investigate and resolve complaints, maintaining accurate records, improving our services, and protecting our legal and regulatory position. This processing is necessary to respond appropriately to concerns raised and to ensure fair and accountable handling of complaints. |
| Complaints | To maintain records of complaints, complaint investigations, outcomes and supporting evidence to demonstrate compliance with legal and regulatory obligations where applicable, support governance and oversight, identify trends, improve products and services, and establish, exercise or defend legal claims. | Legal Obligation - Article 6(1)(c) UK GDPR where the complaint falls within the scope of applicable regulatory complaint handling requirements. Legitimate Interests - Article 6(1)(f) UK GDPR as it is necessary to maintain accurate records of complaints and complaint outcomes, demonstrate consistent complaint handling, identify systemic issues and service improvements, monitor complaint trends, protect the firm's legal and commercial interests, evidence decisions made, support internal governance and oversight, and establish, exercise or defend legal claims. Establishment, Exercise or Defence of Legal Claims – Article 9(2)(f) UK GDPR. |
| Data Protection | To receive, identify, record, assess, manage and respond to data subject rights requests in accordance with the UK GDPR, the Data Protection Act 2018 and other applicable data protection legislation. | Legal Obligation – Article 6(1)(c) UK GDPR to comply with the UK GDPR. |
| Data Protection | To maintain records of data subject rights requests, responses and supporting evidence to demonstrate compliance with data protection legislation, support governance and accountability, and establish, exercise or defend legal claims. | Legal Obligation – Article 6(1)(c) UK GDPR to comply with the UK GDPR. |
| Reviews | To invite customers to provide reviews and feedback regarding the services they have received, collect and publish customer reviews through Reviews.io, monitor customer satisfaction, improve service quality and respond to customer feedback. | Legitimate Interests – Article (6)(1)(f) UK GDPR as it is necessary to obtain independent customer feedback, measure customer satisfaction, improve the quality of products and services, identify areas for operational improvement, monitor customer outcomes, respond to customer concerns, demonstrate transparency through independent customer reviews and protect the firm's commercial reputation. |
Disclosure of Personal Data
We may share personal data with:
- Trusted independent SRA-regulated law firms, legal representatives, claims service providers and other professional representatives involved in assessing eligibility for, advising upon, or progressing a potential claim or compensation matter.
- Where special category data relating to health or vulnerability is shared, we will do so only where a lawful basis and additional condition under UK GDPR applies, including explicit consent where required.
- Internal staff requiring access for service delivery, all of whom have received data protection training.
- Professional advisors (e.g., legal, financial, insurance consultants).
- Third-party IT, marketing, and cloud service providers are necessary to provide our services.
- Any entity involved in a sale or restructuring of our business.
International Transfers
Some data may be processed outside the UK or EEA, such as when using cloud services. We will always ensure such transfers comply with UK and EU data protection laws using appropriate safeguards.
Automated Decision-Making
We do not make decisions about you based solely on automated processing that has legal or similarly significant effects. If we ever implement such technologies, we will do so only where permitted by law or based on your explicit consent, and with appropriate safeguards, including the right to obtain human review.
Data Security
We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, alteration, or disclosure. These include encryption, access controls, secure servers, staff training, and contractual data-processing safeguards with our suppliers. We review our security arrangements regularly to ensure they remain effective and proportionate to the nature, scope, context, and purposes of our processing. In the event of a personal data breach, we have procedures in place to identify, investigate, and notify the Information Commissioner's Office and affected individuals where legally required.
Data Storage & Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or to meet legal, regulatory, or operational requirements. Where it is not possible to specify an exact retention period, we determine the appropriate duration by considering factors such as: the nature and sensitivity of the personal data; the potential risk of harm from unauthorised use or disclosure; the purposes for which we process the data; whether those purposes can be achieved through other means; our contractual and legal obligations; and applicable limitation periods for potential claims or regulatory investigations.
For specific retention periods, please contact us at privacy@cavis.co.uk.
Your Data Subject Rights
Under the UK GDPR, you have the following Data Subject Rights; however, not all Rights are absolute and, in some cases, shall not apply.
- The right to be informed about how your personal data is used.
- The right of access to your personal data.
- The right to rectification of inaccurate or incomplete personal data.
- The right to erasure ("right to be forgotten") in certain circumstances.
- The right to restrict processing.
- The right to data portability.
- The right to object to the processing (including for direct marketing or processing based on legitimate interests).
- Rights in relation to automated decision-making and profiling.
To exercise your rights, or if you have any concerns about how we process your personal data, please contact us at privacy@cavis.co.uk.
Your Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of any processing carried out before withdrawal.
Your Right to Withdraw Consent for Direct Marketing
To withdraw consent for direct marketing purposes, please contact privacy@cavis.co.uk. Alternatively, you can withdraw consent at any time by using the unsubscribe mechanisms included within direct marketing communications received by SMS, WhatsApp, or email.
Data Subject Rights Conditions
| Data Subject Right | Conditions |
|---|---|
| Right of Access | The Right to Access can be restricted where disclosure would adversely affect the rights of others, involve disproportionate effort, or fall within specific exemptions under the Data Protection Act 2018. The Right to Access can also be refused if it is manifestly unfounded or excessive. |
| Right to Rectification | The Right to Rectification shall not apply if the data is accurate, if an exemption applies or if the request is manifestly unfounded or excessive. |
| Right to Erasure | Generally, the Right to Erasure shall apply if the personal data is no longer necessary for the purpose(s) which it was originally collected or processed for, where the lawful basis for processing is consent and the individual has withdrawn their consent, if the lawful basis for processing is legitimate interests and the individual has objected to the processing provided there is no overriding legitimate interest to continue the processing, where the personal data is processed for direct marketing purposes and the individual has objected to that processing, where the personal data has been processed unlawfully, or where erasure is necessary to comply with a legal obligation. It shall not apply where the processing is necessary for the establishment, exercise or defence of legal claims, to comply with a legal obligation. The request can also be refused if it is manifestly unfounded or excessive, or a specific exemption applies. |
| Right to Restrict Processing | The Right to Restrict Processing shall generally apply if the individual contests the accuracy of their personal data and we are verifying the accuracy of that data, where personal data has been processed unlawfully and the individual opposed erasure in favour of a request to restrict that data, where we no longer need the personal data but the individual needs us to retain it to establish, exercise or defend a legal claim, or the individual has objected to the processing and we are considering whether our legitimate grounds override those of the individual. It shall not apply if an exemption applies or if the request is manifestly unfounded or excessive. |
| Right to Data Portability | The Right to Data Portability shall apply if it concerns information that an individual has provided to the Controller and only if the lawful basis for processing is consent or for the performance of a contract. It may also apply if the processing is carried out by automated means. It shall not apply if an exemption applies or if the request is manifestly unfounded or excessive. |
| Right to Object | You have an absolute right to object to your personal data being used for direct marketing and in some cases where we process the personal data is processed if the lawful basis for that processing is legitimate interests. In other circumstances, the Right to Object shall not apply where we can demonstrate compelling legitimate grounds that override the individual's interests, rights and freedoms, or for legal claims. |
| Rights Related to Automated Decision-making and Profiling | Rights Related to Automated Decision-making and Profiling may still lawfully occur if an exception applies and suitable safeguards are in place. |
Complaints
You have the right to complain to us if you believe we have not handled personal data in accordance with data protection law. You may also complain to the Information Commissioner’s Office at any time, although the ICO recommends giving us an opportunity to address the matter first.
You can make a complaint about the handling of your or other people’s personal information, usually in the following circumstances:
- We have not properly responded to your request for your personal information.
- We have not kept your information secure.
- We hold inaccurate information about you.
- We have disclosed information about you.
- We keep information about you for longer than necessary.
- We have collected information for one reason and are using it for something else.
- We have not upheld any of your data protection rights.
If you wish to make a data protection complaint, please use the contact information below. We will acknowledge the complaint within 30 days, take appropriate steps to investigate it, keep you informed and communicate the outcome without unnecessary or unjustifiable delay.
- Registered Office Address: Cavis Marketing Limited, C/O Brabners LLP, 100 Barbirolli Square, Manchester, United Kingdom, M2 3AB.
- Email Address: privacy@cavis.co.uk
Complaints to the Information Commissioner's Office (ICO)
If you remain dissatisfied with our response, or if you prefer to contact the regulator directly, you may complain to the Information Commissioner's Office (ICO):
- Postal Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Phone: 0303 123 1113
- Online: https://ico.org.uk/make-a-complaint/personal-information-complaint/
- Website: www.ico.org.uk
Cookies
Our website uses cookies and similar technologies to ensure it functions correctly, to analyse usage, and to deliver relevant content and advertising. We use Cookiebot to manage cookie consent and compliance with the UK GDPR and the Privacy and Electronic Communications Regulations (PECR).
Strictly necessary cookies operate on the basis of our legitimate interests in providing a secure and functional website. All other cookies, including those used for statistics and marketing, are deployed only with your consent.
You can review, adjust, or withdraw your consent for non-essential cookies at any time via the Cookiebot banner or by selecting “Cookie Settings” in the website footer.
Updates to this Policy
We may update this privacy policy from time to time. We will publish any changes on our website and, where appropriate, notify you by other means. The date at the top of this page indicates when it was last revised.
Revision History
- V1.0 June 2026: Created.
- V1.1 June 2026: Updated Privacy Notice to include processing of incomplete applications and claim enquiries, including reminder and follow-up communications.
- V1.2 July 2026: Updated 'How We Collect Personal Data' and 'Purposes and Lawful Basis for Processing Personal Data'.
- V1.3 September 2026: Updated sections: 'What Personal Data We Collect', 'How We Collect Personal Data', added new 'Purposes' and the 'Lawful Bases' for Processing, 'Complaints'.