Privacy Policy
Last updated: March 2026
1. Who We Are
This Privacy Policy applies to Mortgage Magick Limited trading as Mortgage Magic™ (“Mortgage Magic”, “we”, “us”, or “our”). We are a company registered in England and Wales.
Company Name: Mortgage Magick Limited t/a Mortgage Magic™
Company Number: 12179889 (England & Wales)
Registered Office: Ground Floor, Rainham House, Manor Way, Rainham, RM13 8RH
FCA Reference: 966949
Appointed Representative of: Ever North Limited (FCA No: 800196)
Data Privacy Contact: privacy@mortgage-magic.co.uk
Mortgage Magic is registered with the Information Commissioner's Office (ICO) as a data controller. This policy explains how we collect, use, store, and protect your personal data when you use our platform, visit our website, or interact with us in any way.
2. What Data We Collect
2.1 Information You Provide
- Full name, email address, telephone number, and company name
- Professional credentials, FCA reference numbers, and regulatory details
- Account login credentials (securely hashed)
- Case and client data entered into the platform in the course of your professional activities
- Payment and billing information (processed securely — we do not store card details)
- Communications with us via email, telephone, or in-platform messaging
2.2 Data Collected Automatically
- Usage data including pages visited, features used, session duration, and device information
- IP address and approximate location data
- Analytics data via Google Tag Manager (GTM ID: GTM-KNQQ28HH) and Facebook Pixel (ID: 581365441550882)
- Cookies as described in Section 9 of this policy
2.3 Credit Data (Platform Users)
Where you use the Mortgage Magic platform to access credit data for your clients, we integrate with TransUnion and Experian. Credit data is only accessed with the explicit, informed consent of the data subject (your client). All credit data access is logged and audited.
3. How We Use Your Data
- To provide, maintain, and improve the Mortgage Magic platform and services
- To comply with FCA regulatory requirements and obligations as an appointed representative of Ever North Limited
- To communicate with you about your account, platform updates, and service changes
- To process payments for subscriptions and usage charges
- To conduct identity verification and KYC/AML checks where required
- To send service-related communications and (where you have opted in) marketing communications
- To improve platform features through aggregated, anonymised analytics
- To investigate and respond to complaints, support requests, or compliance queries
4. Legal Basis for Processing
We process your personal data on the following legal bases under UK GDPR:
Contract Performance
Processing necessary to provide the platform services you have subscribed to.
Legal Obligation
Processing required to comply with FCA regulations, anti-money laundering obligations, and other applicable laws.
Legitimate Interests
Processing for platform improvement, fraud prevention, and business operations where these interests are not overridden by your rights.
Consent
Where we rely on consent (e.g., marketing communications, analytics cookies), you may withdraw consent at any time.
5. Data Sharing
We do not sell your personal data. We may share data with the following third parties in the course of providing our services:
- Ever North Limited (FCA 800196): As our principal firm, Ever North has access to compliance-relevant data for regulatory oversight purposes.
- TransUnion and Experian: For credit data services, accessed only with explicit client consent.
- UK cloud infrastructure: Our cloud infrastructure provider. All data remains within UK data centres.
- Payment processors: For secure billing and subscription management.
- Identity verification providers: For E-ID and KYC/AML checks.
- Law enforcement or regulators: Where required by law or legitimate regulatory request.
6. Data Storage & Security
All personal data is stored on UK cloud infrastructure within UK data centres. We do not transfer personal data outside the United Kingdom or European Economic Area without appropriate safeguards.
We employ industry-standard security measures including AES-256 encryption at rest and in transit, role-based access controls, multi-factor authentication options, regular penetration testing, and third-party security audits.
All processing is carried out in compliance with UK GDPR and the Data Protection Act 2018.
7. Data Retention
We retain personal data for as long as necessary to provide our services and comply with legal and regulatory obligations. Specifically:
- Client and case data related to regulated mortgage activity is retained for a minimum of 7 years as required by FCA regulations.
- Marketing contact data is retained until you withdraw consent or request deletion.
- Account data is retained for the duration of your subscription and for a reasonable period thereafter for compliance and dispute resolution purposes.
8. Your Rights
Under UK GDPR you have the following rights regarding your personal data:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your data where there is no legitimate reason to retain it.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Restriction
Request restriction of processing in certain circumstances.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
To exercise any of these rights, please contact us at privacy@mortgage-magic.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the ICO at ico.org.uk.
9. Cookies
We use the following types of cookies on our website:
Essential Cookies
Required for the platform to function. These cannot be disabled. They include session management, security tokens, and authentication cookies.
Analytics Cookies (Google Tag Manager)
We use Google Tag Manager (GTM-KNQQ28HH) to manage analytics tags and measure website performance. You may opt out via your browser settings or our cookie consent tool.
Marketing Cookies (Facebook Pixel)
We use Facebook Pixel (ID: 581365441550882) to measure advertising effectiveness. You may opt out via your Facebook settings or our cookie consent tool.
10. Contact Us
For all data protection enquiries, to exercise your rights, or to raise a concern about how we handle your data, please contact our Data Protection team:
Email: privacy@mortgage-magic.co.uk
Post: Mortgage Magick Limited, Ground Floor, Rainham House, Manor Way, Rainham, RM13 8RH
We reserve the right to update this Privacy Policy from time to time. Material changes will be communicated to registered users. The date of the most recent revision is shown at the top of this page.