Last updated: 13 February 2019
Open Access Finance Limited, trading as OnStep (“OnStep”) respects your right to privacy. This Privacy Notice explains who we are, how we collect, share and use personal information about you, and how you can exercise your privacy rights.
If you have any questions or concerns about our use of your personal information, then please contact us using the contact details provided at the bottom of this Privacy Notice. We recommend that you read this Privacy Notice in full to ensure you are fully informed.
OnStep is a peer to peer lending platform, operating in the UK. For more information about OnStep, please see the About Us section of our Website.
The personal information that we may collect about you broadly falls into the following categories:
Certain parts of our Website may ask you to provide personal information voluntarily: for example, we may ask you to provide your contact details in order to register an account with us and/or to submit enquiries to us. We may also ask you to provide us with your name, date of birth, residential address and banking details, so we can perform identity and fraud prevention checks on you. If you apply for an OnStep home we will also use the information to perform landlord credit checks on you, which will not leave a credit footprint. The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information.
When you visit our Website, we may collect certain information automatically from your device. For countries in the European Economic Area, this information may be considered personal information under applicable data protection laws.
Specifically, the information we collect automatically may include information like your IP address, device type, unique device identification numbers, browser-type, broad geographic location (e.g. country or city-level location) and other technical information. We may also collect information about how your device has interacted with our Website, including the pages accessed and links clicked.
Collecting this information enables us to better understand the visitors who come to our Website, where they come from, and what content on our Website is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our Website to our visitors.
Some of this information may be collected using cookies and similar tracking technology, as explained further under the heading “Cookies and similar tracking technology” below.
In order to process your application for an OnStep home, we will perform credit and identity checks on you with one or more credit reference agencies (“CRAs”). To do this, we will supply your personal information to the CRAs and they will supply to us publicly available credit and fraud prevention information. This will not include any credit information shared by other financial institutions.
We will use this information to:
We will not exchange any information about you with the CRAs apart from the initial search we perform, and such a search will not place a search footprint on your credit file that may be seen by other lenders.
If you are making a joint application, or tell us that you have a spouse or financial associate, we will perform searches on both of you. So you should make sure you discuss this with them, and share with them this information, before lodging the application.
The identities of the CRAs, their role also as fraud prevention agencies, the data they hold, the ways in which they use and share personal information, data retention periods and your data protection rights with the CRAs are explained in more detail at Transunion CRAIN.
Additionally, we may disclose your personal information to the following categories of recipients:
Our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.
However, we will normally collect personal information from you only (i) where we need the personal information to perform a contract with you, (ii) where the processing is in our legitimate interests and not overridden by your rights, or (iii) where we have your consent to do so. In some cases, we may also have a legal obligation to collect and process personal information about you (for example to report a potential fraud to the National Crime Agency).
If we ask you to provide personal information to comply with a legal requirement or to perform a contact with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information). For example, to participate in our platform as a lender, you will need to provide us with relevant personal information so we can carry out identity and fraud prevention checks, manage and administer your account, make or receive payments and contact you in relation to your account and respond to your queries. If you do not wish to provide us with this information, you will not be able to proceed with your application to borrow or lend on our platform.
If we collect and use your personal information in reliance on our legitimate interests (or those of any third-party), this interest will normally be to operate our platform and communicating with you as necessary to provide our services to you and for our legitimate commercial interest, for instance improving our platform, undertaking marketing or for the purposes of detecting or preventing illegal activities. We may have other legitimate interests and if appropriate we will make clear to you at the relevant time what those legitimate interests are.
If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided here under Contact Us.
We use appropriate technical and organisational measures to protect the personal information that we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal information. Specific measures we use include serving our website and all forms with personal data over a secure encrypted connection and storing the personal data in a PostgreSQL database with restricted access rights on a need-to-know basis.
Your personal information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country.
Specifically, some of the third-party service providers and partners we use, operate around the world. This means that when we collect your personal information we may process it in any of these countries.
However, we have taken appropriate safeguards to require that your personal information will remain protected in accordance with this Privacy Notice. OnStep only appoints third-party service providers who provide us with sufficient guarantees that they will comply with relevant data protection laws.
We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements).
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
You have the following data protection rights:
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
We may update this Privacy Notice from time to time in response to changing legal, technical or business developments. When we update our Privacy Notice, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes if and where this is required by applicable data protection laws.
You can see when this Privacy Notice was last updated by checking the “last updated” date displayed at the top of this Privacy Notice.
If you have any questions or concerns about our use of your personal information, please contact us using the following details: firstname.lastname@example.org.
The data controller of your personal information is Open Access Finance Limited.