Christopher Anthony Financial Services
Website Privacy Policy
Last updated: 26 July 2026
Version: 1.0
1. Introduction
Christopher Anthony Financial Services Limited, trading as Christopher Anthony Financial Services (“we”, “us”, “our”), is committed to protecting and respecting your privacy. This policy explains how we collect, use, store and share your personal data when you visit our website at https://christopher-anthony.mortgage, when you enquire about mortgage, protection or related financial services, and when we act for you as a mortgage and protection adviser.
We are the “data controller” for the personal data described in this policy. This means we decide how and why your personal data is processed. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).
Our details
- Trading name: Christopher Anthony Financial Services
- Registered company name: Christopher Anthony Financial Services Limited
- Company registration number: 17157920, registered in England and Wales
- Registered office: 17 Doyle Gardens, Yateley, Hampshire, GU46 6XY
- Email: mortgages@christopher-anthony.co.uk
- Telephone: 01189 952 771 (direct) or 01256 961 002 (office)
- Website: https://christopher-anthony.mortgage
Regulatory status
Christopher Anthony Financial Services Limited is an Appointed Representative of Stonebridge Mortgage Solutions Ltd, which is authorised and regulated by the Financial Conduct Authority. We are entered on the Financial Services Register under firm reference number 1058362. You can check our entry, and that of our principal firm, at https://register.fca.org.uk.
Because we act as an Appointed Representative, Stonebridge Mortgage Solutions Ltd is responsible for the regulated business we carry out on its behalf. Stonebridge is a separate data controller in respect of the advice records, applications and compliance files it holds, and it processes your personal data in accordance with its own privacy notice, which is available on request or from the Stonebridge website.
If you have any questions about this policy or about how we handle your personal data, please contact us using the details above.
2. The personal data we collect
The information we collect depends on how you interact with us. We may collect and process the following categories of personal data.
2.1 Information you give us
- Identity data: title, full name, date of birth, nationality, marital status, dependants and identification documents such as a passport or driving licence.
- Contact data: home address, previous addresses, email address and telephone numbers.
- Financial data: income, employment details, bank account and payment card details, existing borrowing and credit commitments, outgoings, savings, assets, pensions and investments.
- Property data: details of properties you own, are buying, selling or remortgaging, including addresses, valuations and tenancy details.
- Enquiry data: the content of enquiry forms, callback requests, mortgage calculators, emails, letters, text messages and notes of our conversations with you.
- Marketing and communications data: your preferences for receiving marketing from us and your communication preferences.
2.2 Special category data
Where we advise on protection products such as life cover, critical illness cover or income protection, we may need to process information about your health, medical history and lifestyle. This is “special category” data and receives additional protection under data protection law. We will normally process it on the basis of your explicit consent, or where processing is necessary for reasons of substantial public interest in connection with an insurance contract. We may also process information about criminal convictions where a lender or insurer requires this as part of an application.
2.3 Information about other people
If you provide us with personal data about another person, for example a joint applicant, a dependant, a guarantor or a beneficiary, you confirm that you have their permission to do so and that you have made them aware of this privacy policy.
2.4 Information we collect automatically
When you visit our website, our servers and those of our hosting provider automatically record certain technical information in server log files. This may include:
- Your IP address and approximate location derived from it
- Browser type and version, operating system and device type
- The pages you visit, the date and time of your visit and time spent on each page
- Referring website addresses and outbound links clicked
- Error reports and diagnostic data
This information is used for security monitoring, fraud prevention, diagnosing technical problems and understanding how our website is used. Server logs are typically retained for a limited period by our hosting provider before being overwritten or deleted.
2.5 Information from third parties
- Credit reference agencies, such as Experian, Equifax and TransUnion
- Fraud prevention agencies, such as Cifas and National Hunter
- Lenders, insurers, product providers and their administrators
- Introducers and referral partners, such as estate agents, solicitors, accountants or existing clients who refer you to us
- Your employer or accountant, where we need to verify income
- Publicly available sources, including Companies House, HM Land Registry, the electoral roll and social media profiles that are open to the public
3. How we use your personal data and our lawful bases
Under the UK GDPR we must have a lawful basis for processing your personal data. The bases we rely on are set out below.
3.1 Performance of a contract
- Assessing your circumstances, needs and objectives and providing mortgage and protection advice
- Researching the market and recommending suitable products
- Submitting applications to lenders, insurers and providers on your behalf
- Liaising with lenders, insurers, solicitors, estate agents, surveyors and other parties involved in your transaction
- Administering your case through to completion and dealing with post-completion queries
3.2 Legal obligation
- Verifying your identity and carrying out anti-money laundering, sanctions and know your customer checks under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
- Meeting our obligations under the FCA Handbook, including record keeping, suitability reporting and Consumer Duty requirements
- Complying with tax, accounting and company law obligations
- Responding to lawful requests from regulators, law enforcement or the courts
- Handling complaints and cooperating with the Financial Ombudsman Service
3.3 Legitimate interests
We may process your data where it is necessary for our legitimate interests, or those of a third party, provided your interests and fundamental rights do not override those interests. Our legitimate interests include:
- Running, administering and improving our business and our website
- Keeping records of the advice we have given so that we can defend ourselves against future claims
- Preventing and detecting fraud and financial crime
- Contacting existing clients about reviews of their mortgage or protection arrangements, for example ahead of a fixed rate ending
- Sending business to business marketing where relevant and proportionate
- Analysing website usage to improve the content and layout of our site
You can ask us for further information about our legitimate interests assessments using the contact details in this policy.
3.4 Consent
- Sending you marketing emails, text messages or newsletters where consent is required
- Placing non-essential cookies and similar technologies on your device
- Processing special category data, such as health information, in connection with protection applications
Where we rely on consent, you can withdraw it at any time. Withdrawing consent will not affect the lawfulness of any processing carried out before you withdrew it, and it will not affect processing carried out under a different lawful basis. To withdraw consent, contact us using the details in this policy or use the unsubscribe link in any marketing email.
4. Marketing communications
We may send you information about our services by email, text, telephone or post where you have consented to this, or where you are an existing client and we are contacting you about similar services under the “soft opt-in” permitted by PECR.
Every marketing email we send includes an unsubscribe link. You can also opt out at any time by contacting us. If you opt out of marketing, we will still send you service communications relating to any mortgage, protection or other case we are handling for you.
We will not sell your personal data to third parties, and we will not share it with third parties for their own marketing purposes.
5. Who we share your personal data with
We may share your personal data with the following categories of recipient.
- Lenders, insurers, product providers and their administrators, in order to place and administer your applications
- Credit reference agencies, which may record our search and, where an application proceeds, details of the credit agreement. Searches may be recorded on your credit file and may be visible to other lenders
- Fraud prevention agencies, which may use your data to prevent fraud and money laundering and may share it with other organisations
- Solicitors, conveyancers, estate agents, surveyors, valuers and accountants involved in your transaction
- Stonebridge Mortgage Solutions Ltd, our principal firm, together with any mortgage club, compliance monitoring or file checking service it operates
- Professional advisers, including our own auditors, accountants, insurers and solicitors
- Regulators and authorities, including the Financial Conduct Authority, the Information Commissioner’s Office, HM Revenue and Customs, the Financial Ombudsman Service and law enforcement agencies
- Our service providers and sub-processors, as described below
Where we share data with an organisation that determines its own purposes for processing, such as a lender or insurer, that organisation will be a separate data controller and will handle your data in accordance with its own privacy notice.
6. Hosting providers and sub-processors
We use a number of third party service providers who process personal data on our behalf. These providers act as data processors, are bound by written contracts that meet the requirements of Article 28 of the UK GDPR, and may only process your data on our documented instructions.
Our current processors and sub-processors include:
- Website enquiry forms: Gravity Forms, which stores form entries within our website database and forwards them to us by email
- Website analytics: Google Analytics
- Hosting: Hostinger
We review our processors regularly and will update this policy when our arrangements change. You can request a current list of our processors at any time.
7. International transfers
We aim to keep your personal data within the United Kingdom or the European Economic Area wherever possible. Some of our service providers, however, are based outside the UK or process data using servers located outside the UK.
Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place. This will be one of the following:
- The country has been assessed by the UK government as providing an adequate level of protection under UK adequacy regulations
- The transfer is made under the UK International Data Transfer Agreement (IDTA), or the European Commission Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported where necessary by a transfer risk assessment
- Another safeguard recognised under Chapter V of the UK GDPR applies
You may request a copy of the safeguards we rely on by contacting us using the details in this policy.
8. Cookies and similar technologies
Our website uses cookies, which are small text files placed on your device. We use:
- Strictly necessary cookies, which are required for the website to function and cannot be switched off
- Analytics cookies, which help us understand how visitors use our site
- Functional cookies, which remember your preferences
- Marketing and advertising cookies, which may be set by third parties
Non-essential cookies are only set where you have given consent through our cookie banner. You can change or withdraw your cookie preferences at any time through the banner or by adjusting your browser settings. Blocking cookies may affect the functionality of parts of the website.
Social media pixels and tracking
Our website may include tracking technologies operated by social media and advertising platforms, such as the Meta (Facebook) pixel, the LinkedIn Insight Tag, Google Ads conversion tracking and similar tools. These allow us to measure the effectiveness of our advertising and to show relevant adverts to people who have visited our site.
These platforms may act as independent or joint controllers for the data they collect. Their processing is governed by their own privacy policies, which we encourage you to read. Where consent is required, these technologies are only activated after you have accepted the relevant cookie category.
9. How long we keep your personal data
We only keep your personal data for as long as is necessary for the purposes for which it was collected, including to satisfy legal, regulatory, accounting or reporting requirements.
- Mortgage and protection advice records: at least six years from the end of our relationship or the end of the product term, reflecting FCA record keeping expectations and the limitation period for potential claims
- Records relating to pensions, investments or long term protection contracts: indefinitely or until the product ends plus six years, where a longer period is appropriate to defend against claims
- Anti-money laundering and identity records: five years from the end of the business relationship or the completion of the transaction
- Financial and accounting records: six years from the end of the relevant financial year
- Enquiries that do not proceed: 24 months from your last contact with us, unless you ask us to delete them sooner
- Marketing consents and preferences: for as long as you remain subscribed, plus a record of your opt out so that we can honour it
- Website server logs and analytics data: typically up to 26 months, depending on the provider
At the end of the applicable retention period we will securely delete or anonymise your data.
10. How we keep your personal data secure
We have put in place appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration or disclosure. These include access controls, encryption in transit, secure password policies, multi factor authentication, staff training and confidentiality obligations, and regular review of our systems.
No transmission of information over the internet can be guaranteed to be completely secure. Any transmission is at your own risk, although we take reasonable steps to protect data once we receive it.
Data breaches
We have procedures in place to detect, investigate and report personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to your rights and freedoms, we will also inform you directly without undue delay.
11. Your rights
Under data protection law you have the following rights in relation to your personal data.
- The right to be informed about how your data is used, which this policy is intended to satisfy
- The right of access, allowing you to receive a copy of the personal data we hold about you
- The right to rectification of inaccurate or incomplete data
- The right to erasure, sometimes called the right to be forgotten, which applies in certain circumstances
- The right to restrict processing in certain circumstances
- The right to data portability, allowing you to obtain and reuse data you have provided to us in a structured, commonly used and machine readable format
- The right to object to processing based on our legitimate interests, and an absolute right to object to direct marketing
- Rights in relation to automated decision making and profiling
- The right to withdraw consent at any time where we rely on consent
Please note that some of these rights are qualified. In particular, where we are required by the FCA, anti-money laundering law or other legislation to retain records, we may not be able to delete your data on request.
To exercise any of your rights, please contact us using the details at the start of this policy. We will respond within one month. This period may be extended by up to two further months for complex requests, in which case we will let you know. There is normally no fee, although we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive. We may need to verify your identity before acting on a request.
12. Automated decision making
Some lenders, insurers and credit reference agencies use automated systems, including credit scoring and underwriting engines, to decide whether to accept an application. These decisions are made by those organisations rather than by us. Where an automated decision produces a legal or similarly significant effect on you, you have the right to ask the organisation concerned for human involvement, to express your point of view and to challenge the decision. We can help you identify the correct contact.
13. Third party links
Our website may contain links to third party websites, plug-ins and applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third party websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.
14. Children
Our services are not directed at children and we do not knowingly collect personal data from anyone under the age of 18, other than information about dependants provided by their parents or guardians in connection with a mortgage or protection application.
15. Changes to this policy
We keep this privacy policy under review and may update it from time to time. Any changes will be posted on this page with a revised “last updated” date. Where changes are significant, we will notify you directly where it is reasonable to do so.
16. Complaints
If you are unhappy with how we have handled your personal data, please contact us first so that we have the opportunity to put things right.
You also have the right to lodge a complaint with the Information Commissioner’s Office, the UK supervisory authority for data protection.
- Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Helpline: 0303 123 1113
- Website: www.ico.org.uk
Complaints about the financial advice or service we have provided, as opposed to data protection matters, are handled under our separate complaints procedure and may be referred to the Financial Ombudsman Service. Details are available on request.