Crest Nicholson Holdings plc is committed to protecting the privacy and security of your personal data. This privacy notice (Notice) describes how we collect and use personal data in accordance with the UK General Data Protection Regulation (UK GDPR).
This Notice is provided in a layered format so you can click through to specific areas as required. Alternatively, you can download a copy of the Notice here.
We reserve the right to update this Notice at any time and we will make the revised Notice publicly available. We may also notify you in other ways from time to time about the processing of your personal data.
This notice was last updated on 1 September 2025.
This notice covers the following topics:
what personal data we collect about you
how we collect personal data
why we process personal data
the transfer of any personal data outside the UK and/or the EEA
when we may disclose your personal data
protecting your personal data
your rights in connection with the personal data we collect
how long we hold your personal data for
how we update or change this notice
how you can contact us
We issue other privacy notices, policies and terms (alongside this Notice) which relate to specific situations – please refer to the following notices where applicable:
Employee Privacy Notice – copies supplied to employees on joining or on request
Contents
Business and general correspondents
Website visitors
Customers (direct and indirect)
Visitors to our buildings or properties
Social media followers
Job applicants
Suppliers and subcontractors
Shareholders
1. SCOPE
This Notice is given by Crest Nicholson Holdings plc on behalf of itself, its subsidiaries and its joint venture companies (collectively referred to as Crest Nicholson, we, us, our in this Notice). We act as a data controller for the personal data we collect during the course of our engagement with you. We are registered as a data controller with the Information Commissioner's Office under number: ZA433197.
Crest Nicholson Holdings plc is a public limited company registered in England and Wales and listed on the London Stock Exchange. Our company number is 06800600 and our registered office is at 500 Dashwood Lang Road, Bourne Business Park, Addlestone, Surrey KT15 2HJ, United Kingdom which is also our main trading address.
2. AUDIENCE
This Notice relates to the range of data processing activities undertaken by Crest Nicholson. To help you navigate this Notice we have extracted the key information applicable to you depending on the nature of your relationship with us. Please click on the below tabs to access the relevant summary. Full details of our processing are set out in the rest of the Notice.
We may collect your personal data if you contact Crest Nicholson by email, post, telephone or otherwise in connection with any business or general matter, in order to maintain a general business relationship with you.
The information we collect
We will only collect the information you provide to us directly, such as your name and contact details or other details you might provide when corresponding with us.
Who we share the information with
Depending on the correspondence we have with you, we may share your information with businesses that provide us with services necessary in relation to what you have requested.
Please see section 8 below for additional circumstances where we may disclose your data.
Legal basis for processing
We have a legitimate interest to process your personal data in order to maintain normal business operations and to fulfil the request you have made through your correspondence with us.
How long we keep information for
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
As a visitor to our websites, www.crestnicholson.com and corporate.crestnicholson.com and any associated sub-domains, we will collect information related to you as required for our websites to operate, as well as giving you the opportunity to request brochures, make enquiries about our new homes, book appointments and subscribe for newsletters, press releases or other alerts.
The information we collect
News alerts and webcasts
If you chose to sign up for press releases, RNS emails, or other news alerts from our website, or to participate in investor webcasts, we will collect and store your name, email address and choice of news and information services. We use this information to provide the service you requested.
You are able to unsubscribe from the news and information service at any time and/or opt out of receiving communications by clicking the unsubscribe link in any email you are sent from us.
New home enquiries
If you make an enquiry about a new home, request a brochure and/or book a viewing appointment, we will collect your name, address, contact numbers and email address, and information about the nature of your enquiry. We may ask you about the type of property that you are interested in purchasing, such as number of bedrooms, location, price range, transport link requirements and details of your current property status, including if you are a first-time buyer and whether you are selling a property and are in a chain.
Technical information
We use cookies on our website to gather and record on our servers certain information about all users who visit the website, including without limitation, IP address, time zone setting and location, interaction with our website browser type and version, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website. We may also receive technical data about you from analytics providers such as Google (for example, standard internet log information and details of visitor behaviour patterns). We do this to find out such things as the number of visitors to the various parts of the site. This information is only processed in a way that does not directly identify anyone. We do not make, and do not allow Google to make, any attempt to find out the identities of those visiting our website.
At any time, you can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For further information on this, please see our Cookie Policy.
The information we collect about your use of the website will be used to report on visitor numbers, administer and protect our business and websites (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data), to improve our websites, services and consumer experiences.
We also collect, use and share aggregated data such as statistical or demographic data (Aggregated Data) for limited purposes. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
Who we share the information with
We share the information we collect with our website providers to the extent necessary for them to perform their services to us.
If you sign up for our alert service that delivers the latest regulatory news directly to your mailbox we will share your information with our data processor for these services, The Design Portfolio Marketing Services Limited, with a registered address of Sierra Quebec Bravo, 4th Floor, 77 Marsh Wall, London E14 9SH.
If you sign up to participate in an investor webcast we will share your information with our data processor for these services, Investis Digital Limited, with a registered address of 5th Floor, The Counting House, 53 Tooley Street, London SE1 2QN.
Third-party links
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and we are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
Please note that Crest Nicholson does not warrant, represent, endorse or hold responsibility over any external sites that may be linked to and from this site.
Please see section 8 below for additional circumstances where we may disclose your data.
Legal basis for processing
Where you have agreed to provide us with your data in relation to new home enquiries and/or email alerts and/or webcasts, then you have consented to us processing that information.
We have a legitimate interest in administering, protecting and improving our website. We also have a legitimate interest to process your personal data for the purpose of providing you with the information you request when accessing and interacting with our website.
Our use of cookies is subject to consent – please see our Cookie Policy.
Direct marketing
Where you agree (or where otherwise permitted by law), we will send you information about new property developments and or services which may be of interest to you, according to your preferred methods of communication. Even after you agree and ask us to send you information, you can always unsubscribe/withdraw your consent at any time and we’ll stop sending you marketing materials. Just use the ‘unsubscribe' link at the bottom of marketing emails or inform one of our sales staff. To stop receiving SMS marketing you can text STOP to the number which sent you the latest message.
How long we keep information for
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Information you provide when requesting sales and marketing information about developments and properties will be kept for up to five years after the last inbound contact we have from you, as some developments can take a number of years to plan, market and complete. Please see section 10 of this Notice to learn how you can manage marketing communications.
If you unsubscribe from the email alerts and/or webcast access, we will not retain the data you submitted when you subscribed for the service and will cease sending you news and information.
If you decide to buy a Crest Nicholson home directly from us, we will collect personal data directly from you when you:
visit our website and/or submit online forms
visit one of our sales and marketing suites
call us, email us or contact us via social media
complete questionnaires
make a complaint
enter into any transaction with us or request information in relation to entering into a transaction
We may also indirectly obtain personal data from third parties when you:
visit a third-party property site (for example Rightmove or Zoopla) or an estate agent and request information about one of our homes
engage with other property companies that we have arrangements with, for example registered providers and social landlords
engage with solicitors, financial advisors, insurers, surveyors, and estate agents involved in your search for, and purchase of, a new home from us
liaise with the NHBC, contractors and suppliers about your new home
If you own a Crest Nicholson home which is subject to remediation, we may collect personal data from you and other third parties associated with carrying out the works.
The information we collect
We will collect information such as proof of identity and financial status in order to help you purchase and secure your new home. We will also obtain details of any mortgage, part exchange property and your extras and choices made in relation to the home you wish to purchase, along with details of advisors appointed by you in relation to any purchase, for example mortgage brokers, solicitors, financial advisors and surveyors.
We may record or track telephone calls made to some of our sales and customer services teams for training, monitoring and quality purposes. If you visit one of our sales offices or show homes, see also section D below.
If you are a joint purchaser and give us personal data about another person, you must ensure you tell them, and please ask them to read this Notice. Please also note that when you purchase a property jointly, we may share your personal data with the other purchaser.
Who we share the information with
Your information may be shared with and processed by:
our own employees, agents and auditors
third-party data processors who provide support services to us and who will process your personal information on our behalf. Such third parties may include cloud services providers (such as hosting and email management), other IT service providers as well as marketing companies that we use to distribute materials on our behalf
independent financial advisors, estate agents and solicitors that you choose to help you with your new home search and purchase
recipients involved when you take out a mortgage including those backed by an insurance policy or product, covered by a Government Indemnity or other scheme, including credit reference agencies
recipients involved when you purchase your home through a shared ownership or other support scheme
warranty organisations such as NHBC
those supplying, and those providing warranty or support services for items in your home such as appliances, technology or other special features
after sales support providers and contractors and tradesmen who help investigate and/or carry out repairs to your new home
agencies or providers who help us understand your experience with us, and your opinion of our Company
parties that we have a legal obligation to disclose information to, for example regulators and law enforcement agencies
Processing for credit referencing purposes
We may undertake searches of credit reference agencies (CRAs) to verify your identity when you apply to reserve a new home. We do this by submitting your personal data to them. We need to undertake such searches in accordance with anti-money laundering laws. This is not a credit check but details of the search may appear on your credit file.
If you apply, or have a shared equity loan with us in order to process your application and manage your account, we will perform credit and identity checks on you with one or more CRAs.
To do this, we will supply your personal data to CRAs and they will give us information about you. This will include information from your credit application and about your financial situation and financial history. CRAs will supply to us both public (including the electoral register) and shared credit, financial situation and financial history information and fraud prevention information. We will use this information to assess your creditworthiness and suitability, verify the accuracy of the data you have provided to us, prevent criminal activity, fraud and money laundering, manage your account and trace and recover debts from you.
We will continue to exchange information about you with CRAs while you have a relationship with us. If you borrow and do not repay in full and on time, CRAs will record the outstanding debt. This information may be supplied to other organisations by CRAs. When CRAs receive a search they will place a search footprint on your credit file that may be seen by other lenders.
Find out more about CRAs and the ways in which they use and share personal data in this Credit Reference Agency Information Notice.
Legal basis for processing
Where you have agreed to provide us with your data in relation to purchasing a new home, then you have consented to us processing that information.
In most cases we will process your personal data because it is necessary for the performance of a contract with you (or to take steps to entering into a contract with you) i.e. the purchase of a new home and the provision of customer services after legal completion.
We may also process your personal data where it is necessary to comply with our legal obligations or for the purposes of our legitimate interests. If we are marketing to you we will only do so with your consent, or where otherwise permitted by law.
Direct marketing
Where you agree (or where otherwise permitted by law), we will send you information about new property developments and or services which may be of interest to you, according to your preferred methods of communication. Even after you agree and ask us to send you information, you can always unsubscribe/withdraw your consent at any time and we will stop sending you marketing materials. Just use the ‘unsubscribe' link at the bottom of marketing emails or inform one of our sales staff. To stop receiving SMS marketing you can text STOP to the number that sent you the most recent message.
Please see section 8 below for additional circumstances where we may disclose your data.
How long we keep information for
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Information you provide when requesting sales and marketing information about developments and properties will be kept for up to five years after the last inbound contact we have from you, as some developments can take a number of years to plan, market and complete. Please see section 10 of this Notice to learn how you can manage marketing communications.
We keep the purchase record and associated records for customer services purposes for 15 years from the legal completion date.
Anti-money laundering regulations require us to keep evidence of identity checks and details of the relevant business transaction for five years.
If you start a home purchase process and do not complete it, your information will be retained for five years after your last communication to Crest Nicholson.
We may keep your data for longer if we cannot delete it for legal and/or regulatory reasons.
We store and use your information for the purposes of managing and operating our buildings and within our reporting and marketing materials.
The information we collect
If you are visiting any of our regional offices (see addresses on our Contact Us page), or a sales office at one of our development sites, we may collect personal data where necessary for security, administration and safety purposes – this may include collecting personal and contact details, as well as dietary, health or accident information. Further, we have a guest Wi-Fi network for visitors to access; however, no personal data is collected by us in relation to this.
At some developments we operate CCTV for the purposes of detecting and preventing crime and general estate management. We may also receive information from law enforcement agencies if criminal activity is alleged or suspected in the publicly accessible areas of our portfolio. Our CCTV feeds provide a 24/7 live feed, which is retained for a period of 30 days after which it is automatically overwritten, unless we are aware of a particular incident, where the footage may be kept for longer to share with law enforcement agencies (see section 8 for further information on why we might share your personal data).
We may also take photographs or videos within a property or public space, in which case we may capture the image of visitors. If you have any concerns or do not wish to be photographed, you should raise this with a member of our team. Where specific or close up images of individuals are taken (for example, for use on our social media or website), your consent will be sought.
We may also collect aggregated footfall and visitation data across our developments. No personal data is collected through this.
Who we share the information with
We share the information we collect with the following third parties:
our suppliers to the extent necessary to perform their services to us
where access control information or fire evacuation information is required to be shared with an occupier
where the information relates to health and safety incidents, security events or any matter giving rise to an insurance claim or relevant to our insurance coverage, our lawyers, insurance brokers and other professional advisors
when requested to do so by relevant authorities such as the police, in the event of criminal conduct
Please see section 8 below for additional circumstances where we may disclose your data.
Legal basis for processing
We have a legitimate interest in wishing to interact with you in order to manage and operate our buildings effectively and ensure that these are safe and secure. The processing we undertake is limited and concentrates on the use of the building.
In the case of photography, the processing we undertake will either be on the basis that we have a legitimate interest in undertaking the processing or that your consent has been obtained.
In some instances, for example for health and safety purposes, we are required by law to hold certain records to comply with this obligation.
How long we keep information for
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
We have active social media accounts that are used to answer enquiries received from followers, reshare photos tagged to our account and to promote our developments. Please refer to our social media terms for more information.
The information we collect
By contacting or interacting with us through our social media accounts, you share with us your details on your social media account, which can include your social media username/handle, public profile, public posts, and any personal information included as part of your enquiry such as your name, email address, place of work and job title.
Who we share the information with
We only share the information we collect with our suppliers to the extent necessary for them to perform their services to us. In this instance the main suppliers will be our marketing agents.
Please see section 8 below for additional circumstances where we may disclose your data.
Legal basis for processing
When you contact us through our social media channels, we have a legitimate interest in responding to your query.
How long we keep information for
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
We collect and process personal data about you to consider your application for a vacancy. This includes:
to assess your suitability for any vacancy you apply for
to make offers of employment and provide contracts if you are successful in your application
to meet legal obligations (such as payroll, tax, benefits)
to determine that you are eligible to live and work in the UK
to monitor compliance with anti-discrimination legislation and our policies
to consider you for alternative vacancies
to help us improve our recruitment practices
If you are unable to provide us with sufficient personal data, we may be unable to assess your suitability for the job applied for or to communicate with you. As your application progresses, we may need to ask you for more personal data. We will let you know what the consequences will be if we are unable to obtain and process personal data about you.
The information we collect
CVs may be submitted to us through recruitment agencies, in job applications either via our own external website or third-party advertisements, via third-party job boards, sent to our general enquiries inbox, or to individuals within our organisation. If a CV is submitted to any Crest Nicholson email address other than that of an HR specialist, it will be passed to our HR department, and the individual who received it will be required to delete it from their email.
Throughout the recruitment process information collected may include:
biographical information about you – such as your name, address, date of birth, gender, nationality, marital status, details of family members, preferred languages
your contact details – telephone numbers, email address, postal address
employment history – your CV or résumé, application form details, records of education, qualifications, skills and training
information to identify you – National Insurance or other identification number, your visa, passport or permission to work documentation
sensitive personal information – health details (including any disabilities that affect your ability to perform your work and that we need to assess and help us consider your workplace needs)
suitability for employment – interview notes, references, proof of professional qualifications, the results of criminal records (we will ask for your consent to do this at the reference/pre-employment stage if it is required)
equal opportunities and anti-discrimination – we may ask you to provide details of your ethnic origin via our Equal Opportunities Form and whether you have been long-term unemployed. You do not have to supply this information. We process it strictly for the purposes of providing equality of opportunity for all, and for monitoring compliance with anti-discrimination legislation
Who we share the information with
We may share your information with third parties used to process personal data on our behalf such as IT hosting or recruitment software companies. We have contracts, policies and procedures in place to ensure these companies safeguard personal data entrusted to them, and to only use it under our instructions and for the purposes outlined in this Notice.
If we elect to contact your referees and/or previous employers directly, we will share information with them to the extent necessary to confirm the details provided in your CV.
Please see section 8 below for additional circumstances where we may disclose your data.
Legal basis for processing
Where you have agreed to provide us with your data in relation to a job application, then you have consented to us processing that information.
We will process personal data in the CVs we receive, either directly from you or through a recruitment agency, on the basis of our legitimate interest in recruiting suitable candidates for our roles or where the processing is necessary to perform a contract or to take steps at your request, before entering a contract.
If you provide us with any information about reasonable adjustments you require under the Equality Act 2010 the lawful basis we rely on for processing this information is to comply with our legal obligations under the Act.
We request that CVs do not contain special category data (such as medical information) – to the extent that you voluntarily provide such information, any processing by us will be incidental and we will rely on the fact we have obligations in employment and the safeguarding of your fundamental rights. In other limited circumstances we may ask for your specific consent.
How long we keep information for
If you are successful in your job application, we will collect further details from you in line with your employment with Crest Nicholson, and a separate Privacy Notice will be communicated to you.
If your application is not successful, we will keep your personal data for up to three years after the recruitment process has ended. We do this so we can consider you for other suitable vacancies that might become available. You can ask us to erase this data at any time if that is your preference – see section 10 of this Notice.
If you send us your personal data on an unsolicited basis, for example, submitting a CV that is not connected to a specific role for which we are recruiting, we will retain your personal data for 12 months.
The information we collect
When you are engaged with Crest Nicholson as a supplier or subcontractor, we collect relevant information about you through our engagement with you in order to enter into a contract with you or your organisation for the provision of goods or services. This data may include:
contact details for your business and your team, so that we liaise with the correct people
bank account details, Unique Tax References and/or company registration number
evidence of competency relevant to any works/services being discussed and undertaken
site induction and other training records, including details pertaining to health and safety incidents and references, should we wish to follow them up
your National Insurance details as required to comply with HMRC rules
We will also take minutes during meetings over the course of our relationship, which may include names, job titles and contact details.
All visitors and workers on our sites will be required to sign in and out each day. Some locations may use CCTV (see part D above) and a form of biometric/fingerprint access for safety and security purposes.
Who we share the information with
We only share the information we collect with our suppliers, contractors and professional advisors to the extent necessary for them to perform their services to us.
Please see section 8 below for additional circumstances where we may disclose your data.
Legal basis for processing
Where you have agreed to provide us with your data in relation to acting as a supplier to Crest Nicholson, then you have consented to us processing that information.
In most cases we will process your information because it is necessary for the performance or award of a contract with you. We will also process your information where it is necessary to comply with our legal obligations.
We have a legitimate interest in processing this data from you in order for us to undertake necessary due diligence and to ensure that the invoice details match your account details. The data that we collect from you may also be used to ensure we comply with legal requirements.
How long we keep information for
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Documents including contracts, designs, drawings and specifications relating to developments, buildings or schemes built after June 2002 will be retained for 17 years. Documents relating to developments, buildings or schemes built before June 2022 will be retained for 32 years.
We collect and process your personal data as a shareholder so we can manage your shareholding in Crest Nicholson Holdings plc to comply with our statutory and regulatory obligations and keep your record on the share register up to date; to make shareholder communications and shareholder meeting materials available to you; to pay you dividends; to allow you to exercise your rights as a shareholder including the right to vote, and to respond to any correspondence you send us.
The information we collect
As a shareholder of Crest Nicholson Holdings plc, we may collect your name, registered address, bank sort code and account number, email address, number of shares, date of death, corporate action election options, identification numbers, phone number, communication method preference and voting instructions.
It is important to ensure that the personal information we hold about you is accurate and up to date, and you should let us know if anything changes, for example if you move home or change your phone number or email address. You may be able to update some of the personal information we hold about you through the MUFG share portal at cn.signalshares.com. Alternatively, you can contact our Registrar, MUFG Corporate Markets (UK) Ltd at the address below or by phone on 0371 664 0300.
Who we share the information with
We will share your information with our data processor for these services, our Registrar MUFG Corporate Markets (UK) Ltd, with a registered address at Central Square, 29 Wellington Street, Leeds LS1 4DL.
We may also share your information with any other professional advisors and third-party service providers as required in order to communicate with shareholders (such as printing and mailing services). These providers process your personal information in accordance with our instructions and subject to data processing agreements in accordance with applicable data protection law.
In compliance with our legal obligations (such as s.811 Companies Act 2006), we may share your data with those who request a copy of the register of members of Crest Nicholson Holdings plc.
Please see section 8 below for additional circumstances where we may disclose your data.
Legal basis for processing
We are under a statutory obligation to process your personal details on our share register. Other than this, we process your information on the basis of our legitimate interest.
Your information may also be aggregated to conduct data analytics studies to review and better understand shareholder purchase, retention and attrition rates for our legitimate interest in order to improve as a company.
How long we keep information for
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Generally, where there is no legal requirement to retain it for longer, we will retain your data for a period of 12 years after you cease to hold shares.
3. WHAT KIND OF PERSONAL DATA WE COLLECT ABOUT YOU
The types of personal data which we collect about you will vary according to the nature of your relationship with us. Please see the relevant section at part 2 of this Notice. We may also process other categories of personal data from time to time, as specifically notified or as may reasonably be anticipated as part of the operation of our business and the management of our property portfolio.
Under the UK GDPR certain types of information are considered to be more sensitive and so in need of more protection. These 'special categories of personal data' are information about your race, ethnic origin, political opinions, religion, trade union membership, genetics, biometrics (where used for ID purposes), health, sex life, or sexual orientation, and may also include information relating to criminal convictions and allegations. Where you provide us with this information, we are required to establish an additional lawful basis for holding this information, which will usually be your explicit consent or our compliance with a legal or regulatory obligation.
We may process such information in the following circumstances:
as a visitor to our premises, we may process health-related information such as dietary requirements and accident details
in very rare instances we will process special categories of personal data in order to prevent or detect unlawful acts in connection with publicly accessible areas of our developments (e.g. fraud or antisocial behaviour), which in some circumstances will involve disclosures to the police or other regulatory/legal authorities.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during the course of your relationship with us.
4. HOW WE COLLECT YOUR PERSONAL DATA
The way in which we collect your personal data will vary according to the nature of your relationship with us. Please see the relevant section at part 2 of this Notice. We may also collect personal data from other sources from time to time, as specifically notified or as may reasonably be anticipated as part of the operation of our business and the management of our property portfolio.
5. WHY WE PROCESS PERSONAL DATA
The personal data we collect and process will vary according to the nature of your relationship with us. Whenever we process your personal data we do so on the basis of a lawful condition of processing. The applicable legal basis will vary according to the nature of your relationship with us. Please see the relevant section at part 2 of this Notice.
We may also process personal data for the following purposes:
internal business and regulatory requirements
exercising and/or defending our legal rights
we may also process personal data for other purposes from time to time, as specifically notified or as may reasonably be anticipated as part of the operation of our business
In addition, we may also undertake processing: where necessary for compliance with a legal obligation to which Crest Nicholson is subject (for example, undertaking mandatory background checks or to comply with court orders); where you provide your consent to the processing of your personal data for certain specific purposes, including where based on additional information made available at the time consent is provided; where we need to protect the vital interests for you or someone else, or where it is necessary to do so in the public interest; and in other circumstances where necessary for our legitimate interests (or those of a third party).
Where we process your personal data as necessary for our legitimate interests (or those of a third party), we do so only provided it is carried out in a way that is proportionate and respects your privacy rights.
The special categories of personal data that may be processed by Crest Nicholson are set out in section 3 of this Notice. Where we process special categories of data it will be justified by a condition set out above and also by one of the following additional conditions:
based on your explicit consent
in accordance with paragraph 10 of Schedule 1 of the UK’s Data Protection Act 2018 – for example where we seek to prevent or detect unlawful acts (e.g. fraud or antisocial behaviour)
where necessary to protect the vital interests for you or someone else where you are physically or legally incapable of giving consent (for example in exceptional emergency situations, such as a medical emergency), or where it is necessary to do in the public interest
the processing is otherwise permitted by law, such as in relation to legal claims
We will only use your personal data for the purpose for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
6. RETAINING YOUR PERSONAL DATA
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements including applicable statutory limitation periods. Please see the relevant section at part 2 of this Notice.
In some circumstances we may anonymise your personal data so that it can no longer be associated with you, in which case we may use such information without further notice to you.
7. YOUR PERSONAL DATA AND THE EEA
In limited circumstances, your personal data may be accessed, transferred, and/or stored outside the UK or the European Economic Area (EEA) in which data protection laws may be of a lower standard than in the EEA. For example, some of our third-party data processors have servers located in South Africa, India and the United States. Regardless of location we will impose the same data protection safeguards that we deploy inside the EEA.
If you are located outside the UK or the EEA your personal data will be exported back out to the jurisdiction that it originated from or from where you are located (for example when we reply to your emails or we write to you).
8. WHEN WE MAY DISCLOSE YOUR PERSONAL DATA
The ways in which we disclose your personal data will vary according to the nature of your relationship with us. Please see the relevant section at part 2 of this Notice. In addition, we may also disclose your personal data to the following recipients:
to service providers to whom we outsource certain functions of our business. For example, we have service providers such marketing agencies who provide marketing support or IT service providers who provide/support IT applications or systems, which means that your personal data will be hosted on their servers, but under our control and direction. We require all our service providers to respect the confidentiality and security of personal data
to a prospective buyer in the event of a sale, merger or restructuring of any part of our business
to a prospective buyer and their advisors in the event of a sale, merger or restructuring of any part of our business
to any company within the Crest Nicholson group of companies and our joint venture companies)
to any regulatory agency or enforcement body (e.g. the police or intelligence services) or court where we reasonably believe that we are required to do so by applicable law or regulation or by any court order or at their request where it is legal to do so
When we share your personal data with other parties we will ensure contracts are in place that impose strict data sharing requirements.
9. PROTECTING YOUR PERSONAL DATA
We have put in place technical and organisational measures to protect the security of your information. Third parties will only process your personal data on our instructions and where they have agreed to treat the information confidentially and to keep it secure.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
10. YOUR RIGHTS AND CHOICES OVER YOUR PERSONAL DATA
UK GDPR gives you a number of rights over your personal data such as a right to be informed and to access your information, a right to object to direct marketing and certain other processing, a right to rectify inaccurate information, and a right to erase information to name but a few. The rights available to you depend on our reason for processing your information and may include those set out below.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with the request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Right to know and right to access
You can ask us if we are holding and using personal data relating to you and, if we are, for a copy of the personal data we hold about you.
Right to rectify
You can ask us to rectify inaccuracies in your personal data. You can also ask us to complete personal data considered incomplete or to record a supplementary statement.
Right to erasure
In some circumstances, you can ask us to erase personal data we hold about you.
Right to restrict processing
In some circumstances you have the right to ask us to ‘restrict’ (block or suppress) the processing of your personal data.
Right to object
Based on your particular situation, you can object to the processing of your personal data, that is:
based on our legitimate business interests (including profiling)
done for research and statistical purposes
You also have the right to object to the use of your personal data for direct marketing purposes (including profiling).
Right to withdraw consent
When we rely on your consent to process your personal data – such as for marketing communications – you have the right to withdraw your consent at any time. We’ll always strive to make it easy for you to withdraw consent, and if you find this isn’t the case, then just email us using the information in section 11 of this Notice, and we will endeavour to resolve your concerns as quickly as possible.
Right to lodge a complaint with the UK regulator
UK GDPR is overseen by the Office of the Information Commissioner (the ICO). If you are dissatisfied with how we handle your personal data under UK data protection law, or how we respond to your rights, you can lodge a complaint with the ICO. See www.ico.org.uk for more information.
We would ask that you give us the opportunity to resolve your complaint before contacting the ICO. Our complaints procedure is available at https://www.crestnicholson.com/buying-with-us/complaints-procedure.
11. CONTACT US
You can contact us at any time about how we use your personal data or to exercise any of your rights set out above, or to notify us of any changes to the personal data that you have provided to us.
You can contact us by post or email us:
The Company Secretary, Crest Nicholson, 500 Dashwood Lang Road, Bourne Business Park, Addlestone, Surrey KT15 2HJ
privacy@crestnicholson.com (please remember email is not a secure way of communicating personal data)
The Company Secretary at Crest Nicholson will be the primary contact point for the other Crest Nicholson Group companies.