
Privacy Notice – Quantum Financial Solutions
​
Compliant with UK GDPR & Data Protection Act 2018 (England & Wales)
Last Updated: 21.11.25
​
Quantum Financial Solutions (“we”, “us”, “our”) is committed to safeguarding your personal data and complying fully with the laws of England and Wales, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
​
This Privacy Notice explains how we collect, use, store and protect your personal information when providing commercial finance brokerage services.
​
1. Who We Are
Quantum Financial Solutions is a commercial finance brokerage registered and operating in England and Wales.
For the purposes of data protection legislation, we act as a Data Controller when determining how your data is handled, and as a Data Processor in certain administrative functions.
Contact Details:
Quantum Financial Solutions
20 Wenlock Road, London, United Kingdom, N1 7GU
luke@quantumlodgesystems.co.uk
02922 949606
If you have any questions regarding this notice or your data rights, please contact us using the details above.
2. The Personal Data We Collect
We may collect and process the following categories of information:
Personal Information
-
Full name
-
Contact details (address, phone number, email)
-
Date of birth
-
Identification documents (where legally required)
Business Information
-
Company name and structure
-
Business address and contact details
-
Financial statements and accounts
-
Credit history or credit reference information
-
Details regarding funding requirements
Compliance Information
-
Anti-money laundering (AML) verification
-
Know Your Customer (KYC) details
-
Fraud prevention data
Technical Data
-
IP address
-
Website usage analytics
-
Cookies (subject to your consent)
We do not intentionally collect special category data unless required by law and only with your explicit consent.
3. How We Use Your Data
We use your data to:
-
Assess funding eligibility and requirements
-
Prepare, submit and manage finance applications
-
Introduce you to appropriate lenders and financial institutions
-
Conduct AML and fraud-prevention checks as required by law
-
Maintain accurate business records
-
Communicate with you about your enquiry or application
-
Improve our services and website
-
Fulfil our legal and regulatory obligations under English law
4. Lawful Basis for Processing (UK GDPR)
We process your personal data using the following lawful bases:
-
Contractual Necessity – to provide the services you request
-
Legitimate Interests – for internal administration, risk management and business operations
-
Legal Obligation – including AML, fraud prevention, regulatory reporting and record-keeping
-
Consent – where you explicitly agree (e.g., marketing communications)
5. Sharing Your Data
We may share your information with:
-
Commercial lenders and financial product providers
-
Credit reference agencies
-
Fraud prevention and verification partners
-
Our accountants, legal advisers, and professional service providers
-
Technology, CRM, and data storage partners
-
Regulatory authorities where required (e.g., HMRC, law enforcement)
We never sell your data to third parties.
All third parties are required to comply with UK GDPR when handling your information.
6. International Transfers
If your data is transferred outside the UK, we ensure that:
-
An adequacy decision is in place; or
-
Standard Contractual Clauses (SCCs) are used; or
-
Other UK-approved safeguards apply
We ensure all transfers comply with UK law.
7. Data Security
We use appropriate technical and organisational measures to protect your data, including:
-
Encrypted systems and secure servers
-
Access controls and authentication
-
Staff training in data protection
-
Regular monitoring and auditing
8. Data Retention (England & Wales Requirements)
We retain your data only as long as necessary to fulfil the purposes outlined.
Typical retention periods:
-
Finance applications & business records: 6 years (to comply with HMRC and legal requirements)
-
AML and compliance documentation: 5 years from the end of the business relationship (as required under UK law)
-
Marketing data: until you withdraw consent
Data is securely deleted once no longer required.
9. Your Rights Under UK GDPR
You have the right to:
-
Request access to your personal data
-
Request correction of inaccurate information
-
Request erasure (in certain circumstances)
-
Restrict or object to processing
-
Request data portability
-
Withdraw consent at any time (for consent-based processing)
-
Lodge a complaint with the Information Commissioner’s Office (ICO)
To exercise your rights, please contact us.
ICO Contact Information (England & Wales)
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
www.ico.org.uk
10. Marketing Communications
We will only send marketing communications if you have opted in.
You can withdraw consent at any time by:
-
Clicking ‘unsubscribe’ in any email
-
Contacting us directly
11. Updates to This Notice
We may update this Privacy Notice to comply with changes in UK law or business practices.
The latest version will always be available on our website or upon request.
