RQ Capital Ltd (“we”) are committed to protecting and respecting your privacy.
This Privacy Statement explains how RQ Capital Limited collects, uses, stores, shares and protects personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018. Please read this statement carefully to understand how we process personal data and the rights available to individuals.
Last updated: 7 August 2026
For the purposes of UK data protection law, the data controller is RQ Capital Limited, Bawdeswell Hall, Bawdeswell, Dereham, Norfolk, NR20 4SA.
Data Protection Officer: John Tindall, RQ Capital Limited. Email: mail@rqcapital.co.uk.
1.1 We may collect and process the following data about you:
1.1.1 information that you provide to us through our website, forms, loan applications, enquiries, correspondence, meetings or dealings with us;
1.1.2 if you contact us by letter, email, telephone or other means, we may keep a record of that correspondence and related communications;
1.1.3 we may keep records of telephone calls or call notes for training, monitoring, compliance, dispute resolution and record-keeping purposes;
1.1.4 we may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them;
1.1.5 details of loan applications, lending transactions, property information, security arrangements, guarantees, indemnities, repayments and account administration; and
1.1.6 details of your visits to our site including traffic data, location data, weblogs, IP address, device information, browser type and other technical information about the resources you access and use.
1.2 The personal data we process may include identity data, contact data, financial data, credit and affordability data, compliance data, communications data, technical data and information relating to borrowers, directors, shareholders, guarantors, beneficial owners and other relevant individuals.
1.3 We may obtain personal data directly from you and from third parties, including brokers, introducers, solicitors, valuers, professional advisers, Companies House, HM Land Registry, credit reference agencies, fraud prevention agencies, compliance screening providers and publicly available sources.
2.1 We may collect information about your computer or device, including your IP address, operating system and browser type, for system administration, website security, analytics and service improvement. This information may be statistical data about browsing actions and patterns and may not identify any individual by itself.
2.2 For the same reason, we may obtain information about your general Internet usage by using a cookie file which is stored on the hard drive of your computer. Cookies contain information that is transferred to your computer’s hard drive. They help us to improve our site and to deliver a better and more personalised service. They enable us:
2.2.1 to estimate our audience size and usage pattern;
2.2.2 to store information about your preferences, and so allow us to customise our site according to your individual interests;
2.2.3 to speed up your searches; and
2.2.4 to recognise you when you return to our site.
2.3 You may refuse to accept cookies by activating the setting on your browser which allows you to refuse the setting of cookies. However, if you select this setting you may be unable to access certain parts of our site. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log on to our site.
3.1 We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, disclosure, alteration or destruction.
3.2 Where we use service providers to store or process personal data, we require them to protect that data and process it only in accordance with our instructions and applicable data protection law.
3.3 Transmission of information over the internet is not completely secure. Where you send personal data to us electronically, transmission is at your own risk until received by us.
4.1 We use information held about you in the following ways:
4.1.1 to ensure that content from our site is presented in the most effective manner for you and for your computer;
4.1.2 to provide you with information, products or services that you request from us, to respond to enquiries, and to send relevant service or marketing communications where permitted by law;
4.1.3 to carry out our obligations arising from any contracts entered into between you and us;
4.1.4 to allow you to participate in interactive features of our service, when you choose to do so;
4.1.5 to notify you about changes to our service.
4.1.6 to assess, underwrite and administer loan applications and lending facilities;
4.1.7 to carry out identity verification, anti-money laundering checks, sanctions screening, politically exposed person screening, source of funds/source of wealth checks, fraud prevention checks and other compliance checks;
4.1.8 to obtain and review credit reference, affordability and public record information for borrowers, directors, shareholders, guarantors and other relevant individuals;
4.1.9 to manage contracts, accounts, security documentation, repayments, communications, disputes and customer relationships;
4.1.10 to comply with legal, regulatory, accounting, tax, audit and record-keeping obligations; and
4.1.11 to operate, secure and improve our website, business systems and services.
4.2 We process personal data under one or more lawful bases, including performance of a contract, compliance with legal obligations, our legitimate interests, and consent where required.
4.3 Our legitimate interests include assessing lending risk, preventing fraud, complying with responsible business practices, protecting our business, managing customer relationships, maintaining records and keeping our systems secure.
4.4 If you are an existing customer, we may contact you by electronic means with information about services similar to those previously provided or discussed with you, where permitted by applicable electronic marketing rules. You may opt out of marketing communications at any time.
5.1 We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in UK Companies Act 2006.
5.2 We may disclose your personal information to third parties:
5.2.1 in the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets; or
5.2.2 if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, regulatory requirement, court order or request from a public authority; to enforce or apply our agreements; or to protect our rights, property, safety, customers or others. This includes exchanging information with other companies and organisations for identity verification, anti-money laundering, fraud prevention, credit risk reduction and responsible lending purposes.
5.3 We may also share personal data with credit reference agencies, fraud prevention agencies, Creditsafe, TransUnion, solicitors, valuers, surveyors, auditors, accountants, insurers, brokers, introducers, funders, security trustees, IT providers, compliance providers and other service providers supporting our business operations.
5.4 We only share personal data where we have a lawful basis to do so and where sharing is necessary for the relevant purpose.
6.1 You have the right to ask us not to process your personal data for direct marketing purposes. You can exercise this right by contacting us using the contact details set out at the top of this Privacy Statement.
6.2 Where we send marketing communications, we will do so in accordance with applicable electronic marketing rules. You may opt out of marketing communications at any time.
6.2 Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
7.1 Under UK GDPR, you may have the right to access your personal data, correct inaccurate data, request deletion, restrict processing, object to processing, request data portability and withdraw consent where processing is based on consent.
7.2 These rights are subject to legal exemptions and restrictions. We will not usually charge a fee for responding to a data subject rights request, although we may charge a reasonable fee or refuse a request where permitted by law, for example if a request is manifestly unfounded or excessive.
8.1 We may update this Privacy Statement from time to time. Any changes will be posted on this page and, where appropriate, notified to you by email or other suitable means.
8.2 The “Last updated” date at the top of this Privacy Statement shows when it was most recently reviewed.
9.1 Questions, comments and requests regarding this Privacy Statement should be addressed to: John Tindall, Data Protection Officer, RQ Capital Limited, Bawdeswell Hall, Bawdeswell, Dereham, Norfolk, NR20 4SA. Email: mail@rqcapital.co.uk.
10.1 To help us assess applications, prevent fraud, and meet our legal and regulatory obligations, we may obtain information about you from credit reference agencies (“CRAs”).
10.2 We obtain this information via Creditsafe, which uses its data partner TransUnion to supply consumer credit and identity data.
10.3 Creditsafe Business Solutions Limited is authorised and regulated by the Financial Conduct Authority. FCA Firm Reference Number: 742313.
10.4 TransUnion International UK Limited is authorised and regulated by the Financial Conduct Authority. FCA Firm Reference Number: 805757.
10.5 The information we receive may include data relating to your identity, credit commitments, payment history, fraud prevention information and public record information. This data is used solely for legitimate business purposes, including creditworthiness assessment, affordability assessment, identity verification, anti-money laundering compliance and fraud prevention, in accordance with applicable data protection laws.
10.6 Further information about how Creditsafe and TransUnion process personal data can be found in their respective privacy notices:
Creditsafe Privacy / Transparency Notice: https://www.creditsafe.com/gb/en/legal/transparency-notice-customer-supplier.html
TransUnion CRAIN (Credit Reference Agency Information Notice): https://www.transunion.co.uk/legal/privacy-centre/pc-credit-reference
TransUnion Bureau Privacy Notice: https://www.transunion.co.uk/legal/privacy-centre/pc-bureau
11.1 We may transfer personal data to recipients or service providers located outside the United Kingdom and/or European Economic Area where necessary for our business operations.
11.2 Where such transfers take place, we ensure appropriate safeguards are in place to protect personal data in accordance with applicable data protection laws. These safeguards may include the use of approved international data transfer agreements, standard contractual clauses, or transfers to countries recognised as providing an adequate level of data protection.
12.1 We keep personal data only for as long as necessary for the purposes for which it was collected and to meet legal, regulatory, tax, accounting, audit and record-keeping obligations.
12.2 Data used for credit reference, affordability, AML/KYC, fraud prevention and lending assessment purposes is retained only for as long as required for those purposes and then securely deleted, anonymised or archived in accordance with our retention practices.
12.3 Where a specific legal or regulatory retention period applies, we will retain the relevant records for that period.
13.1 The provision of certain personal data is primarily contractual and, in some circumstances, required to meet legal and regulatory obligations.
13.2 Personal data is required to enter into and perform contracts, assess lending applications, administer accounts, verify identity, prevent fraud, comply with AML/KYC obligations and meet applicable legal, regulatory, accounting and tax obligations.
13.3 If you choose not to provide personal data that we require, we may be unable to enter into a contract with you, assess or administer a loan application, conduct necessary verification or compliance checks, or provide our services. As a result, our services may be delayed, restricted or declined.
14.1 We may use automated systems and tools to support certain business processes, such as risk assessment, fraud prevention, affordability checks, identity verification, creditworthiness assessment and record management.
14.2 These tools may analyse personal data using predefined criteria or rules to generate indicators, alerts, scores or recommendations. At present, we do not make decisions that have a legal or similarly significant effect on individuals based solely on automated processing. Any approval, rejection, restriction or other significant decision is subject to meaningful human review and approval.
14.3 We may in the future use automated decision-making or profiling where permitted by law and where appropriate safeguards are in place. Where we make a decision based solely on automated processing that has a legal or similarly significant effect on an individual, we will provide relevant information about the processing and applicable rights, including the right to request human intervention, express a point of view and challenge the decision.
15.1 If you are unhappy with how we process your personal data, please contact us first so that we can try to resolve your concern.
15.2 You also have the right to complain to the UK Information Commissioner’s Office (“ICO”) or another relevant data protection authority if you are dissatisfied with how we manage your personal data.
15.3 Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Website: https://ico.org.uk