Privacy Policy

The General Data Protection Regulation or GDPR became law and replaces the previous 1995 data protection directive. Previous UK law was based upon this directive.

What is GDPR?

Significant and wide-reaching in scope, the new GDPR law brings a 21st century approach to data protection. It expands the rights of individuals to control how their personal data is collected and processed, and places a range of new obligations on organisations to be more accountable for data protection.

Morita Estates (‘we’ or ‘us’ or ‘our’) are committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have always had a robust and effective data protection program in place which complies with existing law and abides by the data protection principles. However, we recognise the requirement and importance of updating and expanding this program to meet the demands of the GDPR and the UK’s Data Protection Bill.

Morita Estates are dedicated to safeguarding the personal information under our remit and to developing a data protection regime that is effective, fit for purpose and demonstrates an understanding of, and appreciation for the new Regulation. Our preparation plans for the GDPR have been summarised in this statement and includes the development and implementation of new data protection roles, policies, procedures, controls and measures to ensure maximum and ongoing compliance.

We know that your privacy is very important to you. We make it our business for it to be as important to us, thats why we have designated a Data Protection Officer (DPO), who is taking full responsibility for all matters relating to data protection and GDPR compliance. The DPO will ensure that we are accountable and transparent to the supervisory authorities, including the creation and maintenance of “Records of processing activities” as per Article 30 of the GDPR.

How we are preparing for the GDPR

Morita Estates already have a consistent level of data protection and security across our companies, however are now fully compliant with the GDPR since the 25th May 2018. 

Our compliance includes the following:

- Information Audit - carrying out a company-wide information audit to identify and assess what personal information we hold, where it comes from, how and why it is processed and if and to whom it is disclosed.

- Policies & Procedures - The revision and implementing of new data protection policies and procedures to meet the requirements and standards of the GDPR and any relevant data protection laws, including:

- Data Protection – our main policy and procedure document for data protection has been overhauled to meet the standards and requirements of the GDPR. Accountability and governance measures are in place to ensure that we understand and adequately disseminate and evidence our obligations and responsibilities; with a dedicated focus on privacy by design and the rights of individuals.

- Data Retention & Erasure – we have updated our retention policy and schedule to ensure that we meet the ‘data minimisation’ and ‘storage limitation’ principles and that personal information is stored, archived and destroyed compliantly and ethically. We have dedicated erasure procedures in place to meet the new ‘Right to Erasure’obligation and are aware of when this and other data subject’s rights apply; along withany exemptions, response timeframes and notification responsibilities.

- Data Breaches – our breach procedures ensure that we have safeguards and measures in place to identify, assess, investigate and report any personal data breach at the earliest possibility. Our procedures are robust and have been disseminated to all employees, who are aware of the reporting lines and steps to follow.

- International Data Transfers & Third-Party Disclosures – where Morita Estates stores or transfers personal information outside the EU, we have robust procedures and safeguarding measures in place to secure, encrypt and maintain the integrity of the data. Our procedures include a continual review of the countries with sufficient adequacy decisions, as well as provisions for binding corporate rules; standard data protection clauses or approved codes of conduct for those countries without. We carry out strict due diligence checks with all recipients of personal data to assess and verify that they have appropriate safeguards in place to protect the information, ensure enforceable data subject rights and have effective legal remedies for data subjects where applicable.

- Subject Access Request (SAR) – we have revised our SAR procedures to accommodate the revised 1-month timeframe for providing the requested information and for making this provision free of charge. Our new procedures detail how to verify the data subject, what steps to take for processing an access request, what exemptions apply and a suite of response templates to ensure that communications with data subjects are compliant, consistent and adequate.

- Legal Basis for Processing - we are reviewing all processing activities to identify the legal basis for processing and ensuring that each basis is appropriate for the activity it relates to. Where applicable, we are also maintaining records of our processing activities, ensuring that our obligations under Article 30 of the GDPR are met.

- Privacy Notice/Policy – we are revising our Privacy Notice(s) to comply with the GDPR, ensuring that all individuals whose personal information we process have been informed of why we need it, how it is used, what their rights are, who the information is disclosed to and what safeguarding measures are in place to protect their information.

- Obtaining Consent - we are revising our consent mechanisms for obtaining personal data, ensuring that individuals understand what they are providing, why and how we use it and giving clear, defined ways to consent to us processing their information. We have developed stringent processes for recording consent, making sure that we can evidence an affirmative opt-in, along with time and date records; and an easy to see and access way to withdraw consent at any time.

- Direct Marketing - we are revising the wording and processes for direct marketing, including clear opt-in mechanisms for marketing subscriptions; a clear notice and method for opting out and providing unsubscribe features on all subsequent marketing materials.

- Processor Agreements – where we use any third-party to process personal information on our behalf (i.e. Payroll, Recruitment, Hosting etc), we have drafted compliant Processor Agreements and due diligence procedures for ensuring that they (as well as we), meet and understand their/our GDPR obligations. These measures include initial and ongoing reviews of the service provided, the necessity of the processing activity, the technical and organisational measures in place and compliance with the GDPR.

- Special Categories Data - where we obtain and process any special category information, we do so in complete compliance with the Article 9 requirements and have high-level encryptions and protections on all such data. Special category data is only processed where necessary and is only processed where we have first identified the appropriate Article 9(2) basis or the Data Protection Bill Schedule 1 condition. Where we rely on consent for processing, this is explicit and is verified by a signature, with the right to modify or remove consent being clearly signposted.

​Data Subject Rights

In addition to the policies and procedures mentioned above that ensure individuals can enforce their data protection rights, we provide easy to access information via our website of an individual’s rightto access any personal information that Morita Estates processes about them and to request information about: -

- What personal data we hold about them

- The purposes of the processing

- The categories of personal data concerned

- The recipients to whom the personal data has/will be disclosed

- How long we intend to store your personal data for

- If we did not collect the data directly from them, information about the source

- The right to have incomplete or inaccurate data about them corrected or completed and the process for requesting this

- The right to request erasure of personal data (where applicable) or to restrict processing in accordance with data protection laws, as well as to object to any direct marketing from us and to be informed about any automated decision-making that we use

- The right to lodge a complaint or seek judicial remedy and who to contact in such instance

Who we are:

Morita Estates Ltd is a limited company registered in England and Wales, with company number 9257105. Morita Estates is also part of the Morita Group. 

Our registered office address is: 12 Lexham Gardens, Kensington, London W8 5JE

T: 020 8785 6060

F: 020 8785 6060

E: info@moritaestates.com

Morita Estates is registered with the ICO (Information Commissioners Office) under registration number A8302001. 

Morita Estates Key Privacy Principles:

Here at Morita Estates, we have strict compliance with the Data Protection Act 2018 and the General Data Protection Regulations which underlies all of our privacy practices. We also have a set of guiding principles which govern how we use the personal information that we collect about you.

These principles are:

  • We aim to continuously improve our website, communications, products and services for you. We use personal information about you to help us do this

  • We give you control over the personal information we hold about you, including who is allowed to see it and how it is used

  • We won’t use your personal information to contact you for direct marketing purposes unless you specifically allow us to by giving your consent

  • We take all reasonable care to safeguard your personal information through security policies and secure business processes

Why we collect personal information about you?

We collect personal information about you for the following reasons:

To provide you with products and services. Each product and service has different information requirements. Therefore the personal information we need, and what it is needed for, can differ. For full details please ask us for our terms and conditions for each product or service.

To enhance or improve your user experience with us. When you indicate your marketing preferences, we may use this information to personalise the website or our communications with you to better meet your needs.

To provide you with information about products and services that we, believe will be of interest to you. We will only do this with your consent. If you have registered online to use the website or applied online for a product or service, you can change your mind and remove or add your consent at any time by emailing us.

To keep your personal information secure. To minimise the risk of unauthorised access to your personal information, we use some of your personal information to authenticate your identity when using the website.

We collect personal information from you in a number of ways:

  • Directly from you. Sometimes we’ll ask you for personal information about you, for example in our registration form, when you communicate with our Customer Services team, or when you buy any product or subscribe for any service.

  • From what you do on our website. This can show us which products or services you use most and least. We will use this information to personalise the website to better meet your needs and, where you have given us your consent, to provide you with information about our products and services that we believe will be of interest to you.

  • From third parties. We may ask third parties for personal information about you, for example when we authorisation for a payment you make using a credit or debit card or to complete a credit check.

Who will see your personal information?

The personal information we collect about you will be used within Morita Estates. Exactly who sees your personal information depends on the context in which you provided it and whether or not you have given any marketing preferences. You can change your mind about your marketing preferences at any time by emailing us.

Sometimes we’ll share your personal information with third parties outside the Morita Estates. We may do this for the following reasons:

  • To provide you with a product or service. Some of our products and services are provided in conjunction with our partner companies, and we’ll need to share your personal information with them to provide you with the products or services. We make it clear in the terms and conditions for each service whether personal information will be shared with such third parties or not

  • To assist us or our partner companies in providing products or services to you. To enable third parties to provide us or our partner companies with such assistance, we may need to share your personal information with them. When we do so, these companies are required to act in accordance with our or our partner companies’ instructions and they must keep your personal information secure

  • To provide you with information about other products, services and promotions. If you have given your consent, we may share some of your personal information with our partner companies so that they can provide you with information about other products, services and promotions that may be of interest to you

  • To protect Morita Estates Ltd. We may share your personal information with third parties when we believe it is necessary to protect our or another person’s rights, property, or safety. This includes exchanging personal information with third parties to protect against fraud and reduce payment risks

  • To provide personal information collected during the application process to credit reference agencies. This personal information may be recorded by them. We may give details of your account and how you manage it to them. If you do not pay us in full and on time credit reference agencies may record the outstanding debt. This personal information may be supplied to other organisations by credit reference agencies to perform similar checks and to trace your whereabouts and recover debts that you owe. Records remain on file with the credit reference agencies for 6 years after they are closed, whether settled by you or defaulted

  • If you give us false or inaccurate information and we suspect or identify fraud we will record this and may also pass this information to fraud prevention agencies and other organisations involved in crime and fraud prevention

  • To comply with applicable laws, regulations and codes of practice or in response to a valid request from a competent authority

We will only deal with third parties that we trust to treat our customers’ personal information with the same stringent controls that we apply ourselves.

Your personal information may be processed outside the European Economic Area (EEA) where privacy laws may not provide protection to the same level as in the UK, but before any such processing takes place we will take steps to ensure that your personal information will be adequately protected as required by the Data Protection Act.

How long do we keep your personal information?

How long we keep your personal information depends on the context in which you provided it and the marketing preferences you have expressed.

In particular:

  • We will keep any personal information we or our partner companies need to provide you with any product you buy or service you subscribe to for the period during which we or our partner companies provide that product or service to you

  • We may keep your contact details for as long as we have your consent to send you marketing information and/or pass your contact details to third parties

  • We may keep records of any transactions you enter with us or our partner companies for up to six years. This is so that we can respond to any complaints or disputes that arise in that period

  • We will keep other personal information about you if it is necessary for us to do so to comply with the law

We aim to give you control over the personal information we hold about you. If you have registered on our website or applied online for certain products or services, you can see certain personal information you have provided to us through the website by accessing your Personal Portal. You will need to log in to your account in order to do this. You can also use this page to update this personal information, correct any inaccurate information and change the marketing preferences you have given us. Alternatively, you can contact us and we will make the necessary changes.

You can request details of all the personal information we hold about you by contacting our Customer Services Team on 020 8785 6060. You can also write to us at Morita Estates Ltd, Unit 3, Ashlone Wharf, Embankment, Putney, London SW15 1LB

Marketing Preferences:

If you have given your consent, we at the Morita Estates may provide you with information about other products, services and promotions that we believe will be of interest to you. You can change your mind and remove or add your consent by contacting us. 

The marketing preferences you give will not prevent you from receiving information about the benefits and features of specific products or services we already supply you through.

When you select your marketing preferences, these preferences will only apply to the personal information stored about you on the database appropriate for that particular product or service or the database used to manage registrations on our website. If you have provided personal information to us through another channel, or have purchased other products or subscribed for other services, the use of that personal information may not be affected by the marketing preferences you select.

Keeping your information secure:

Here at Morita Estates, we take the security of your personal information seriously.

We’ve implemented technology and security policies, rules and measures to protect the personal information we have under our control, both on and offline, from improper access, use, alteration, destruction and loss.

Here are some of the ways we protect your personal information:

  • If you provide personal information to us online the transmission of that information to us is protected by a secure encryption. Encryption is the process through which sensitive information is scrambled before it is transmitted so that it remains private even if it is intercepted.

  • Offline, your personal information is kept securely in our databases and offices, or, where relevant, by our partner companies who store our extra data.

We will take all reasonable steps to protect your personal information, but data can never be guaranteed as 100% secure. Please note that we will not be liable for any breach of security unless we have been negligent.

As you would expect of us, we will take all reasonable measures to ensure that the personal information you provide through our website is held and managed securely. However, there is a lot that you can do to help keep your personal information safe – not just on our website, but whenever you provide personal information online.

Links to other sites:

Our website includes links to other sites through marketing and online adverts. We make every effort to provide links to high quality, reputable sites but we’re not responsible for their privacy practices, website content or the services they offer. If you find a link which does not appear to be working, please contact us.

Your communication with us

Your communications with us (including by telephone or email) may be monitored and/or recorded for training, quality control and compliance purposes to ensure that we continuously improve our customer service standards.

Changes to our Privacy Policy

We may change our Privacy Policy from time to time. Any changes will be published on our website. Below is the date of which our Privacy Policy was created. If we amend our Privacy Policy, a new date will appear below.

If you have any questions about GDPR or would like us to remove your data then please contact our Data Protection Officer at: privacy@moritaestates.com  

Privacy Policy Updated February 2024