GRT Mortgage & Protection

Privacy policy

Last updated: 2026-10-05

Who we are

This privacy policy explains how GRT Mortgage & Protection Limited, trading as GRT Mortgage & Protection, a limited company registered in Scotland (company number SC891551) with registered office at 20 Aboyne Gardens, Kirkcaldy, Scotland, KY2 5SG ("we", "us") collects and uses personal data when you visit https://grtmortgageprotection.co.uk or contact us. We are the data controller for that personal data.

Email: greg@grtmortgageprotection.co.uk · Phone: 07808 713723

GRT Mortgage & Protection Limited is an Appointed Representative of The Right Mortgage Ltd, which is authorised and regulated by the Financial Conduct Authority. FCA No. 1063667.

The personal data we collect

We collect:

  • Contact form: your name, email address, phone number and the message you send.
  • Technical data: the IP address, browser type and pages visited that our hosting provider records in routine server logs.
  • Cookies: see our cookie policy for exactly what is set and when.

How and why we use personal data

UK data-protection law requires a lawful basis for every use:

What we use it forWhat dataLawful basis (UK GDPR Article 6)
Answering your enquiryIdentity, contact and message dataTaking steps at your request before a contract, and our legitimate interest in responding to people who contact us
Understanding how the site is usedUsage and technical dataYour consent, given through the cookie banner
Keeping the site and our records secureTechnical and correspondence dataOur legitimate interest in running the business safely
Meeting legal obligations (tax, accounting, disputes)Order, invoice and correspondence recordsLegal obligation

Analytics

We use Google Analytics 4 to understand how the site is used. It runs only after you consent through the cookie banner, and you can withdraw that consent at any time. See our cookie policy.

Form security

Our forms use Turnstile, from Cloudflare, Inc., to check that a form is sent by a person. When you use a form, it reads your IP address and signals from your browser and device. We use it to stop automated abuse of our forms. That is part of keeping the site secure, so its lawful basis is our legitimate interest in running the business safely.

Turnstile relies on the security exemption in the Privacy and Electronic Communications Regulations (PECR Schedule A1 paragraph 4(2)), so it needs no cookie consent.

Cloudflare acts for us when it secures the form. It also acts for itself, as a controller, when it uses what it reads to improve its bot detection; its Turnstile privacy notice, at www.cloudflare.com/turnstile-privacy-policy, covers that use.

Who we share personal data with

We use carefully chosen service providers who process personal data on our instructions under contract:

ProviderWhat they do for usWhere they process data
LaingLogicwebsite hosting and enquiry-form deliveryUnited Kingdom
Resendtransactional email delivery for enquiry notificationsUnited States
Googlewebsite analytics (Google Analytics 4), set only after consentUnited States
Cloudflare, Inc. (Turnstile)checks that a form is sent by a person (see Form security above)United States

We may also share personal data with our professional advisers, and with authorities where the law requires it. We do not sell your personal data.

Transfers outside the UK

Some of our providers process data outside the UK. When that happens we make sure a lawful safeguard is in place: a UK adequacy decision covering the destination, or the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.

How long we keep personal data

We keep personal data only as long as we need it:

  • Enquiry correspondence: kept while we deal with your enquiry and for a reasonable period afterwards, then deleted.
  • Records we must keep for tax and accounting: generally six years, as the law requires.
  • Everything else: only as long as needed for the purpose we collected it for, then deleted or anonymised.

Your rights

Under UK data-protection law you have the right to:

  • access the personal data we hold about you
  • have inaccurate data corrected
  • have your data erased in many circumstances
  • restrict or object to how we use it (including objecting to direct marketing, which we always honour)
  • receive the data you gave us in a portable format
  • withdraw any consent you have given, at any time

To exercise any of these, email greg@grtmortgageprotection.co.uk. We will respond within one month and will not charge a fee unless the law allows one. We may need to confirm your identity first.

If you are unhappy with how we handle your personal data, please complain to us first at greg@grtmortgageprotection.co.uk. We will acknowledge your complaint within 30 days and deal with it without undue delay, as UK law requires. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, helpline 0303 123 1113.

Automated decision-making

We do not make any decision about you based solely on automated processing that would have a legal or similarly significant effect on you.

Changes to this policy

We may update this policy from time to time; the date at the top shows when it last changed. Significant changes will be highlighted on the site.