This Policy has been approved and authorised by:
NAME: James Gorey
POSITION: Managing Director
LAST REVIEW DATE: 20 August 2026
James Gorey Ltd
Company Registration Number: 12029084
Registered Office: 13 Stirling Close, Sidcup, DA14 6RP
ICO Registration Reference: ZA594123
Carr Gorey Ltd
Company Registration Number: 15825263
Registered Office: 13 Stirling Close, Sidcup, DA14 6RP
ICO Registration Reference: ZB779588
Paul Fryer Estate Agents Ltd
Company Registration Number: 12691876
Registered Office: 27 Tyeshurst Close, Abbey Wood, London, SE2 0DZ
ICO Registration Reference: ZA773330
James Gorey Estate Agents is a trading brand used by separate legal entities operating within the James Gorey Estate Agents network.
James Gorey Ltd and Carr Gorey Ltd operate as separate and independent estate and letting agency businesses.
James Gorey Ltd may also license independently owned franchise businesses to trade using the James Gorey Estate Agents brand. Paul Fryer Estate Agents Ltd is currently an independent Franchisee of James Gorey Ltd.
Additional Franchisees may join the network in the future. Where this occurs, the relevant legal entity will be identified in appropriate branch information, terms of business or other communications.
Each legal entity remains responsible for complying with applicable data protection law in relation to processing for which it acts as a Data Controller.
James Gorey Estate Agents is a trading brand used by a network of separate legal businesses.
The network currently includes James Gorey Ltd, Carr Gorey Ltd and Paul Fryer Estate Agents Ltd.
James Gorey Ltd and Carr Gorey Ltd each independently operate estate agency and letting agency businesses. Where you enter into terms of business directly with either company, that company will ordinarily act as the Data Controller for personal information it processes in connection with the services it provides to you.
James Gorey Ltd may also grant independently owned businesses a licence to use the James Gorey Estate Agents brand under a franchise agreement. Such businesses remain separate legal entities and are referred to in this Policy as “Franchisees”.
The fact that businesses use the same trading name, website, CRM, telephone systems, email infrastructure, property portals, marketing infrastructure or other shared services does not by itself mean that they are the same legal entity or that they are jointly responsible for all personal information.
James Gorey Ltd, Carr Gorey Ltd and authorised Franchisees may use shared or interconnected business systems, including CRM software, telecommunications systems, email infrastructure, property portals, website and enquiry systems, marketing systems and other network technology.
As a result, authorised personnel of one network business may, depending upon their role, system permissions and the particular service being provided, have technical access to or visibility of personal information originally collected by or primarily controlled by another network business.
The existence of shared systems or technical visibility does not mean that every network business becomes the Data Controller of all information held within those systems.
The data protection role of each business depends upon the particular processing activity, the purpose for which the information is being processed and which business determines why and how that processing takes place.
Access to personal information held within shared systems must only take place where there is an appropriate business, contractual, legal, regulatory, technical or administrative reason and where an appropriate lawful basis applies.
This may include:
a) receiving, responding to or routing enquiries;
b) allocating network leads;
c) administering referrals between network businesses;
d) providing shared administrative, technical or operational support;
e) providing authorised services on behalf of another network business;
f) maintaining, supporting or securing shared systems;
g) dealing with complaints or Data Subject rights requests;
h) complying with legal or regulatory obligations;
i) administering the James Gorey Estate Agents network;
j) maintaining service continuity;
k) dealing with property transactions involving more than one network business; or
l) another lawful purpose connected with the services being provided.
Where one network business accesses or processes personal information solely on the documented instructions of another network business, it may act as a Data Processor for that processing.
Where two businesses process the same personal information for their own separate purposes, each may act as an independent Data Controller for its own processing.
Where two or more businesses jointly determine the purposes and essential means of a particular processing activity, they may act as Joint Data Controllers.
The fact that an authorised user is technically able to view a record does not give that individual or their business unrestricted authority to access, use, copy, disclose or otherwise process the information.
Personnel must only access or use personal information where reasonably necessary for their authorised duties or another documented lawful purpose.
Where James Gorey Ltd contracts directly with a seller, landlord or other client and determines why and how the relevant personal information is processed, James Gorey Ltd acts as the Data Controller.
Where Carr Gorey Ltd contracts directly with a seller, landlord or other client and determines why and how the relevant personal information is processed, Carr Gorey Ltd acts as the Data Controller.
The two businesses remain separate Data Controllers for their own independent estate and letting agency activities notwithstanding their use of the same Brand, systems or infrastructure.
Where a Franchisee enters into a sales agency agreement directly with a seller in the Franchisee’s own corporate name, that Franchisee acts as an independent Data Controller for the seller, buyer, applicant, transaction, Anti-Money Laundering, complaints, accounting and regulatory personal information relating to that Sales Transaction.
Where James Gorey Ltd provides shared CRM, IT, telecommunications, storage or associated technical services to a Franchisee and processes the Franchisee’s Sales Transaction personal information solely on the Franchisee’s documented instructions, James Gorey Ltd acts as a Data Processor for that particular processing.
James Gorey Ltd may separately act as an independent Data Controller where it processes Sales Transaction information for its own separate purposes, including brand management, network administration, lead allocation, referral accounting, legal, compliance or regulatory purposes.
Where a Franchisee introduces a prospective landlord, property or letting opportunity to James Gorey Ltd, James Gorey Ltd decides whether to accept the proposed instruction.
Once James Gorey Ltd accepts the instruction and enters into letting agency or property management terms directly with the landlord, James Gorey Ltd acts as the Data Controller for personal information processed in connection with landlord onboarding, identity and verification procedures, tenant and applicant administration, referencing, compliance, tenancy administration, rent collection, property management and related letting services.
Where a Franchisee carries out authorised marketing, viewings, communications or preliminary negotiations solely on the documented instructions of James Gorey Ltd, the Franchisee may act as a Data Processor on behalf of James Gorey Ltd for that processing.
A Franchisee may separately act as an independent Data Controller for personal information which it needs to process for its own accounting, taxation, insurance, complaint handling, legal claims or independent regulatory obligations.
Before a website, telephone, marketing or other network enquiry has been allocated to a particular network business, two or more businesses may in some circumstances jointly determine why and how that information is processed.
Where this happens, the relevant businesses may act as Joint Data Controllers.
Joint Controller processing may include shared network enquiry capture, jointly controlled lead-routing arrangements, central telephone handling, jointly determined network marketing campaigns or another activity where the relevant businesses jointly determine the purposes and essential means of processing.
James Gorey Ltd will normally act as the primary contact point for individuals in relation to shared network or Joint Controller processing involving James Gorey Ltd.
This does not affect your right to exercise your data protection rights against any Data Controller responsible for the processing.
Once an enquiry has been allocated and a particular business independently determines how and why it will process your information, that business will ordinarily act as an independent Data Controller for its subsequent processing.
Personal information will only be shared between businesses within the James Gorey Estate Agents network where there is an appropriate lawful basis and where sharing is necessary and proportionate for a specified purpose.
The use of shared or interconnected systems may mean that authorised users within another network business have technical access to certain information. However, the existence of that technical access does not itself authorise that business or its personnel to access or use the information for an unrelated purpose.
We may also share personal information with trusted business partners, professional advisers, referral partners, suppliers, contractors and other service providers where reasonably necessary to provide our services, facilitate a property transaction, comply with a legal or regulatory obligation, protect legitimate interests or where you have requested or agreed to a referral.
Such recipients may include solicitors, licensed conveyancers, mortgage advisers, surveyors, valuers, referencing providers, identity verification providers, fraud-prevention and financial-crime service providers, contractors, maintenance providers, utility providers, insurers, deposit protection providers, payment providers and other estate or letting agents.
Only information reasonably necessary for the relevant purpose will be disclosed.
This Policy explains how personal information is collected, used, shared, stored and protected across the James Gorey Estate Agents network.
This Policy is provided for transparency. Simply using our website or services does not mean that you consent to every type of processing described within it.
Where consent is required as the lawful basis for a particular activity, that consent will be requested separately.
This Policy also sets out data protection procedures and standards which must be followed, where applicable, by our employees, Franchisees, agents, contractors, service providers and other persons processing personal information on behalf of, or through the systems of, a business within the James Gorey Estate Agents network.
Each person must comply with the requirements applicable to their role and the Data Controller or Data Processor on whose behalf they are acting.
For questions, rights requests, data protection complaints or marketing preferences, contact:
Email: info@jamesgorey.com
Post: James Gorey Estate Agents, 1 Maidstone Road, Sidcup, DA14 5RH
Where appropriate, a centrally received request will be routed to the Data Controller responsible for the relevant processing.
For the purposes of this Policy:
Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025 insofar as applicable to or amending UK data protection and privacy law, Privacy and Electronic Communications Regulations 2003 and other applicable UK data protection and privacy legislation.
Customers / Data Subjects means individuals whose personal information is processed, including sellers, prospective sellers, buyers, prospective buyers, landlords, prospective landlords, tenants, prospective tenants, applicants, guarantors, occupiers, representatives and other individuals with whom we interact.
Data Controller means the person or legal entity which, alone or jointly with others, determines the purposes and essential means of processing personal information.
Data Processor means a person or legal entity which processes personal information on behalf of and on the instructions of a Data Controller.
Franchisee means an independently owned business authorised by James Gorey Ltd to use the James Gorey Estate Agents brand under a franchise agreement.
ICO means the Information Commissioner’s Office.
Joint Data Controllers means two or more Data Controllers which jointly determine the purposes and essential means of a particular processing activity.
James Gorey Estate Agents means the trading brand used by separate businesses operating within the James Gorey Estate Agents network. James Gorey Estate Agents is not itself a separate incorporated legal entity.
Personal Data / Personal Information means information relating to an identified or identifiable living individual.
Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal information.
Relevant Controller / We / Us / Our means the legal entity acting as Data Controller for the particular processing activity being described. Depending upon the circumstances, this may be James Gorey Ltd, Carr Gorey Ltd, Paul Fryer Estate Agents Ltd or another Franchisee which joins the network in the future.
UK GDPR means the United Kingdom General Data Protection Regulation as it applies in UK law and as amended from time to time.
We will comply with the principles of Applicable Data Protection Law.
Personal information must be:
a) processed lawfully, fairly and transparently;
b) collected for specified, explicit and legitimate purposes and not further processed incompatibly with those purposes;
c) adequate, relevant and limited to what is necessary;
d) accurate and, where necessary, kept up to date;
e) kept in identifiable form for no longer than is necessary, subject to lawful retention requirements; and
f) processed in a manner which provides appropriate security, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage.
Each Data Controller is responsible for demonstrating compliance with these principles for its own processing.
Personal information will only be processed where an appropriate lawful basis applies.
Depending upon the circumstances, processing may take place because:
a) the Data Subject has given valid consent for one or more specific purposes;
b) processing is necessary to enter into or perform a contract with the Data Subject;
c) processing is necessary to comply with a legal obligation;
d) processing is necessary to protect the vital interests of the Data Subject or another person;
e) processing is necessary for a task carried out in the public interest or in the exercise of official authority, where applicable; or
f) processing is necessary for legitimate interests pursued by the Relevant Controller or a third party, except where those interests are overridden by the Data Subject’s interests, rights or freedoms.
Where special category personal information or criminal offence information is processed, an additional lawful condition will be identified where required.
Where processing is based upon consent, consent may be withdrawn at any time.
Withdrawal does not affect processing which was lawful before consent was withdrawn.
Personal information may be collected directly from Data Subjects or received from third parties.
Third-party sources and service providers may include:
Rightmove;
Zoopla and other ZPG services;
Rex;
NetanAgent;
GetAgent;
Blinc;
PayProp;
other property portals;
website and lead-generation providers;
identity verification and Anti-Money Laundering providers;
financial sanctions screening providers;
referencing providers;
payment and client money platforms;
deposit protection providers;
utility providers;
insurers and rent protection providers;
contractors;
solicitors and conveyancers;
mortgage brokers;
surveyors;
local authorities;
government departments;
regulatory and law-enforcement authorities;
other estate or letting agents;
businesses within the James Gorey Estate Agents network; and
other organisations where obtaining, using or sharing information is lawful and necessary.
The organisations used may change from time to time.
Personal information may be processed for purposes including:
a) responding to enquiries;
b) allocating enquiries within the network;
c) administering referrals;
d) arranging valuations and appointments;
e) establishing client relationships;
f) marketing properties for sale or rent;
g) creating photographs, floorplans, videos and particulars;
h) publishing property advertisements;
i) arranging and conducting viewings;
j) communicating with relevant parties;
k) receiving, assessing and communicating offers or applications;
l) negotiating property transactions;
m) progressing sales;
n) administering seller, landlord, buyer, tenant or applicant relationships;
o) referencing;
p) identity verification, Anti-Money Laundering, source of funds, source of wealth, beneficial ownership and financial sanctions checks;
q) Right to Rent checks where applicable;
r) tenancy documentation and administration;
s) collecting and administering rent and permitted payments;
t) deposit administration;
u) property management;
v) repairs and maintenance;
w) operating client accounts and client money systems;
x) insurance or rent protection arrangements;
y) accounting, taxation and invoicing;
z) complaints and legal claims;
aa) detecting and preventing fraud and financial crime;
bb) legal and regulatory compliance;
cc) cooperating with competent authorities;
dd) operating shared CRM, IT, telephony, email and website infrastructure;
ee) information security;
ff) administering the James Gorey Estate Agents network;
gg) improving our services;
hh) direct marketing where permitted; and
ii) another compatible and lawful purpose.
To assist authorised personnel in reviewing documents and information provided during sales, lettings, referencing, compliance and transaction processes, we may use secure business software incorporating artificial intelligence and automated workflows.
This may include information contained in proof of funds, bank statements, affordability information, identity and verification information, property or transaction documentation and other documents supplied in connection with our services.
AI-assisted tools may be used to:
a) identify and summarise relevant information;
b) assist personnel in reviewing financial or transaction documents;
c) identify apparent inconsistencies, missing information or matters requiring further review;
d) assist with fraud, financial-crime and compliance reviews;
e) classify, organise or extract information from documents; and
f) automate administrative workflows.
Platforms currently used may include Gemini within our Google Workspace business environment and automation or AI services provided through Zapier. Services used may change from time to time.
Personal information processed through these services remains subject to appropriate contractual, technical and organisational safeguards and Applicable Data Protection Law.
Google states that customer data in Google Workspace, including prompts, is not used to train or improve its generative AI models without the customer’s permission or instruction.
Zapier treats Customer Content processed through its services as customer-controlled information for which Zapier acts as a processor. Zapier states that Enterprise customers are automatically excluded from use of Customer Content for model training and improvement, while other customers may opt out. Zapier also states that its AI subprocessors are prohibited from using Customer Content for their own model training.
Accordingly, we will configure and use these services in accordance with the data protection, security and model-training controls applicable to the relevant account and service.
AI-assisted systems are intended to support authorised personnel and do not replace appropriate human judgement.
Outputs, summaries, classifications or flags which may influence a decision concerning an individual will be subject to appropriate human review.
Human review must be meaningful. The reviewer must be able to consider the relevant information, challenge an AI-generated output where appropriate and reach their own decision rather than simply accepting the automated output.
We do not use AI systems to make solely automated decisions which produce legal or similarly significant effects on individuals unless that processing is permitted by Applicable Data Protection Law and the required safeguards, rights and transparency measures have been implemented.
Where AI-assisted processing is undertaken by a service provider on behalf of a Data Controller, that provider will be treated as a Data Processor or sub-processor where appropriate.
The ICO distinguishes genuine decision-support from solely automated decision-making and stresses that human oversight must be meaningful rather than a simple rubber stamp.
We only collect and process personal information which is adequate, relevant and limited to what is reasonably necessary for the relevant service, legal requirement or specified purpose.
The fact that additional information may technically be visible within a shared system does not authorise a person or business to access or use it.
Reasonable steps will be taken to ensure that personal information is accurate when collected and remains accurate where necessary.
Where information is inaccurate or materially out of date, appropriate steps will be taken to correct, update or, where appropriate, delete it without undue delay.
Data Subjects are encouraged to notify the Relevant Controller where information changes.
Personal information will not be retained for longer than is reasonably necessary for the purpose for which it was collected or subsequently lawfully processed.
Different categories of information may have different retention periods.
Factors considered may include:
a) legal and regulatory retention obligations;
b) Anti-Money Laundering requirements;
c) accounting and taxation;
d) tenancy and property management requirements;
e) contractual obligations;
f) legal limitation periods;
g) insurance;
h) Property Redress Scheme or professional obligations;
i) establishment, exercise or defence of legal claims;
j) the nature and sensitivity of the information; and
k) other lawful requirements.
Information which is no longer required will be securely deleted, destroyed or anonymised as appropriate.
Each Relevant Controller will implement appropriate technical and organisational measures designed to protect personal information against unauthorised or unlawful processing and accidental loss, destruction, alteration or disclosure.
Businesses using shared systems will take reasonable steps to ensure access is limited according to business need, duties, system permissions and applicable data protection responsibilities.
Each Data Controller will maintain appropriate records and evidence necessary to demonstrate compliance.
This may include records concerning:
a) controllers, Joint Controllers and processors;
b) processing purposes;
c) lawful bases;
d) Data Subject categories;
e) categories of personal information;
f) recipients;
g) sharing arrangements;
h) retention periods;
i) international transfers;
j) security;
k) Data Protection Impact Assessments;
l) breaches;
m) rights requests;
n) complaints;
o) processor agreements;
p) Joint Controller arrangements; and
q) other relevant compliance information.
A Data Protection Impact Assessment will be completed where required by Applicable Data Protection Law and may also be undertaken voluntarily for processing presenting material privacy risks.
An assessment may consider:
a) nature, scope, context and purposes;
b) lawful basis;
c) legitimate interests;
d) necessity and proportionality;
e) categories of information;
f) risks to individuals;
g) security and confidentiality risks;
h) risk-reduction measures; and
i) safeguards.
Each independent Data Controller is responsible for assessments concerning its own processing.
Joint Controllers will cooperate where appropriate.
Depending upon the processing involved and applicable legal restrictions or exemptions, Data Subjects may have rights including:
a) the right to be informed;
b) the right of access;
c) rectification;
d) erasure;
e) restriction;
f) data portability;
g) objection;
h) rights and safeguards relating to automated decision-making and profiling, including appropriate safeguards where a significant decision is based solely on automated processing;
i) withdrawal of consent where processing is based upon consent; and
j) the right to make a data protection complaint.
Not every right applies to every processing activity.
Requests should be made to the Data Controller responsible for the relevant processing.
Requests sent to info@jamesgorey.com will be routed appropriately where necessary.
Where required, the Relevant Controller will provide appropriate information concerning:
a) the identity and contact details of the Data Controller;
b) any relevant Joint Controller;
c) processing purposes;
d) lawful bases;
e) legitimate interests;
f) categories of personal information where information is obtained indirectly;
g) the source of indirectly obtained information where required;
h) recipients or categories of recipients;
i) international transfers and safeguards;
j) retention periods or criteria;
k) legal rights;
l) withdrawal of consent;
m) data protection complaints;
n) the right to complain to the ICO;
o) whether provision of information is statutory or contractual and consequences of not supplying it; and
p) relevant automated decision-making information where required.
Where information is collected directly from a Data Subject, privacy information will normally be provided at collection.
Where personal information is obtained from another source, the Relevant Controller will provide the required privacy information within a reasonable period and no later than one month after obtaining the information unless an exemption applies.
Where the information is used to communicate with the Data Subject, the information will be provided no later than the first communication.
Where the information is to be disclosed to another recipient, the information will be provided no later than the first disclosure.
The applicable one-month maximum period continues to apply.
A Data Subject may make a Subject Access Request at any time.
Requests may be verbal or written.
Requests received at info@jamesgorey.com will be routed to the appropriate Data Controller where necessary.
Where a request relates solely to an independent Sales Transaction undertaken by a Franchisee, that Franchisee will ordinarily respond.
Where it relates to services contracted directly with James Gorey Ltd, James Gorey Ltd will ordinarily respond.
Where it relates to services contracted directly with Carr Gorey Ltd, Carr Gorey Ltd will ordinarily respond.
Where it relates to Joint Controller processing, the relevant controllers will cooperate and James Gorey Ltd will normally coordinate the response where appropriate.
A request will be dealt with without undue delay and normally within one month of the applicable commencement date.
Where permitted by law, the response period may be extended by up to a further two months where necessary because the request is complex or the individual has made a number of requests.
The requester will be notified of an extension and the reasons for it within the initial month.
No fee will normally be charged.
Where permitted by law, a reasonable fee may be charged or a request refused where it is manifestly unfounded or excessive.
A reasonable fee may also be charged for additional copies where permitted.
Reasonable identification or authority information may be requested where necessary.
Reasonable and proportionate searches will be undertaken.
These timeframes reflect the ICO's current SAR guidance.
Data Subjects may request correction of inaccurate personal information and completion of incomplete information.
Requests will normally be dealt with within one month and may be extended by up to a further two months where legally permitted.
Where information requiring correction has previously been disclosed to another recipient, that recipient will be notified where required unless impossible or involving disproportionate effort.
Data Subjects may have a right to request erasure where:
a) information is no longer necessary;
b) consent is withdrawn and no other basis applies;
c) a successful objection is made;
d) information has been processed unlawfully; or
e) erasure is required by law.
The right is not absolute.
Information may be retained where necessary to comply with legal or regulatory obligations, establish, exercise or defend legal claims or where another lawful ground applies.
Requests will normally be dealt with within one month and may be extended where legally permitted.
Data Subjects may have a right to request restriction of processing.
Where processing is restricted, information may continue to be stored but will not normally be further processed except:
a) with consent;
b) for legal claims;
c) to protect another person’s rights;
d) for important public-interest reasons; or
e) where another lawful exception applies.
Relevant recipients will be informed of restrictions where required.
Where the applicable legal conditions are satisfied, a Data Subject may request personal information they provided in a structured, commonly used and machine-readable format.
The right generally applies where processing is based on consent or contract and carried out by automated means.
Where technically feasible and requested, information may be transmitted directly to another Data Controller.
Appropriate electronic formats may include CSV, spreadsheet, PDF or another suitable format depending upon the information concerned.
Requests will normally be dealt with within one month and may be extended where legally permitted.
Data Subjects may have the right to object to processing based on legitimate interests or certain other lawful bases.
Where a valid objection is made, processing will stop unless the Relevant Controller can demonstrate compelling legitimate grounds which override the Data Subject’s interests, rights and freedoms or processing is required for legal claims.
Data Subjects have an absolute right to object to processing for direct marketing.
Where an objection is made, relevant direct-marketing processing will stop.
Electronic marketing will only be undertaken where permitted by data protection law and PECR.
Where consent is required, consent will be obtained.
Where legally permitted, the business which obtained contact information may rely upon the existing-customer soft opt-in for its own similar products or services where all relevant conditions are satisfied.
An appropriate opportunity to opt out will be provided when required.
James Gorey Ltd, Carr Gorey Ltd and Franchisees are separate legal businesses.
A marketing consent or soft opt-in held by one independent business does not automatically authorise another network business to send its own electronic marketing merely because:
a) both use the James Gorey Estate Agents Brand;
b) they share a CRM;
c) information is technically visible to both; or
d) they have another commercial relationship.
Each sender remains responsible for having an appropriate basis to send its marketing.
The categories below describe information which may be processed across the James Gorey Estate Agents network.
Not every business receives or processes every category.
We may process:
a) name;
b) address;
c) telephone numbers;
d) email;
e) property ownership information;
f) property interests;
g) enquiry history;
h) preferences; and
i) marketing preferences.
We may process:
a) name;
b) address;
c) telephone;
d) email;
e) current property position;
f) purchase or rental budget;
g) financial position;
h) property preferences;
i) viewing history;
j) offers and applications;
k) mortgage or funding position;
l) chain position;
m) evidence of funds;
n) identification and verification;
o) source of funds;
p) source of wealth;
q) financial sanctions information; and
r) other transaction information reasonably required.
We may process:
a) name;
b) address;
c) telephone;
d) email;
e) valuation information;
f) property information;
g) photographs, floorplans and videos;
h) keys, alarm codes and security information;
i) title and ownership information;
j) offers and transaction information;
k) solicitor or conveyancer details;
l) identification and verification;
m) beneficial ownership information;
n) source of funds or wealth where required;
o) sanctions information;
p) communications;
q) complaints; and
r) other necessary information.
We may process:
a) name;
b) address;
c) telephone;
d) email;
e) rental valuation;
f) property information;
g) photographs, floorplans and videos;
h) keys and security information;
i) identification;
j) proof of address;
k) ownership or authority-to-let information;
l) beneficial or corporate ownership;
m) bank and payment details;
n) sanctions information;
o) insurance;
p) tax-related information;
q) tenancy and management records;
r) communications and complaints; and
s) other necessary information.
We may process:
a) name;
b) current and previous addresses;
c) telephone;
d) email;
e) date of birth;
f) application information;
g) employment;
h) income;
i) references;
j) affordability information;
k) guarantor information;
l) identification and verification;
m) Right to Rent information;
n) tenancy information;
o) payment and rent records;
p) deposit information;
q) inspection information;
r) maintenance records;
s) communications;
t) complaints; and
u) other information necessary to establish or administer a tenancy.
Where legally required or reasonably necessary, we may process:
a) name;
b) date of birth;
c) residential address;
d) address history;
e) photographic identification;
f) proof of address;
g) beneficial ownership information;
h) company, partnership or trust information;
i) persons acting for another person;
j) sanctions information;
k) politically exposed person information;
l) source of funds;
m) source of wealth;
n) purchase funding;
o) risk assessments;
p) verification results;
q) transaction information; and
r) other required compliance information.
Where statutory AML obligations apply, the relevant regulated business remains independently responsible for those obligations.
Technical access by another network business does not transfer that statutory responsibility.
Where applicable, we may process:
a) name;
b) date of birth;
c) nationality;
d) photographic identification;
e) immigration or Right to Rent documents;
f) Home Office checking information; and
g) follow-up check records.
Authorised staff, agents, photographers or other personnel may create photographs, floorplans, videos and other marketing material.
These may be published on websites, property portals, social media, printed marketing and other appropriate channels.
Property marketing may identify the property address or location where reasonably necessary.
Reasonable steps will be taken not to publish unnecessary personal information.
When a buyer or tenant requests a viewing, information reasonably necessary to arrange and administer the viewing may be shared with the seller, landlord, occupier or person conducting the viewing.
Only reasonably necessary information will be disclosed.
Where an offer or application is made, the seller or landlord may receive the prospective buyer’s or tenant’s name and relevant information concerning their position, including funding, chain, mortgage, affordability or proposed tenancy where reasonably necessary to consider the offer.
Each Data Controller and Data Processor within the network is required to maintain appropriate technical and organisational measures.
Measures may include:
a) individual user accounts;
b) secure passwords;
c) multi-factor authentication;
d) encryption;
e) secure cloud services;
f) firewalls and endpoint security;
g) anti-virus and anti-malware;
h) secure networks;
i) role-based access controls;
j) updates and patching;
k) backups;
l) device security;
m) secure deletion;
n) secure physical destruction;
o) removable-media controls;
p) mobile-device controls;
q) confidentiality obligations;
r) training;
s) access reviews;
t) secure disclosure methods;
u) incident-management procedures; and
v) monitoring and administration controls.
James Gorey Ltd, Carr Gorey Ltd and Franchisees may use shared CRM, telephony, email, website, portal and other systems.
Technical visibility of a record does not constitute unrestricted authority to access or use it.
Users must only access personal information where reasonably necessary for authorised duties or another documented lawful purpose.
Users must not browse, access, export, copy, modify or use information belonging to another network business simply because system permissions technically make it visible.
Appropriate permissions, confidentiality requirements, monitoring and access controls will be used to reduce unnecessary or unauthorised access.
Employees, Franchisees, agents, contractors and other authorised persons must comply with appropriate security requirements.
In particular:
a) sensitive information must be communicated using an appropriately secure method, including encryption where appropriate;
b) information being disposed of must be securely deleted or destroyed;
c) hardcopies requiring destruction should be shredded or confidentially destroyed;
d) electronic information should be securely deleted when no longer required;
e) personal information should only be transmitted using appropriately secure systems and networks;
f) facsimile transmission should not be used unless specifically authorised after considering the security risk;
g) physical documents must be transported using an appropriately secure method;
h) personal information must not be shared informally;
i) hardcopy records and removable media must be appropriately secured;
j) information must not be left unattended or visible to unauthorised persons;
k) computers and devices must be locked when unattended;
l) information should only be stored on authorised systems and devices;
m) personal devices must not be used for business personal information unless appropriately authorised and secured;
n) electronic information must be protected by appropriate password, encryption and security controls;
o) authentication credentials must not knowingly be shared;
p) multi-factor authentication must be used where required;
q) forgotten passwords must be reset through approved procedures rather than disclosed;
r) business information must be backed up using approved systems; and
s) backups must be appropriately secured.
Third-party processors must provide appropriate protections and written contractual protections where required.
Where personal information is transferred outside the UK, an appropriate lawful transfer mechanism or safeguard will be used where required.
Each Relevant Controller will take reasonable organisational measures including:
a) ensuring personnel understand their responsibilities;
b) maintaining appropriate policies;
c) providing this Policy where relevant;
d) restricting access according to need;
e) training;
f) additional training for sensitive or regulated information;
g) appropriate supervision;
h) reviewing collection and processing practices;
i) reviewing permissions;
j) processor agreements;
k) data-sharing and Joint Controller arrangements;
l) reviewing roles where systems are shared;
m) procedures for individual rights;
n) complaints procedures;
o) breach procedures;
p) security reviews;
q) supplier reviews;
r) retention and deletion procedures; and
s) appropriate compliance records.
Each independent Data Controller remains responsible for the compliance of its own personnel and processing.
Any suspected or actual Personal Data Breach must be reported immediately through the relevant business’s internal reporting process.
Reports may also be sent to:
Where appropriate, the report will be routed to the responsible Data Controller.
Where a breach concerns independent controller processing, that controller is responsible for assessing it and determining notification requirements.
Where it concerns Joint Controller processing, the controllers will cooperate and James Gorey Ltd will normally coordinate where it acts as primary contact.
Where a Franchisee acts as processor for James Gorey Ltd, the Franchisee must notify James Gorey Ltd without undue delay after becoming aware of a relevant breach.
Where James Gorey Ltd acts as processor for a Franchisee’s independent Sales Transaction information, James Gorey Ltd must notify that Franchisee without undue delay.
Where a breach is likely to result in a risk to individuals’ rights and freedoms, the Relevant Controller will notify the ICO without undue delay and, where required, within 72 hours of awareness.
Where it is likely to result in a high risk, affected individuals will also be informed without undue delay where required.
Breach records may include:
a) nature of the breach;
b) categories and approximate number of individuals;
c) categories and approximate number of records;
d) likely consequences;
e) containment measures;
f) mitigation;
g) remedial action; and
h) contact details.
You have the right to complain if you believe your personal information has not been handled in accordance with Applicable Data Protection Law.
A complaint may concern:
a) collection;
b) use;
c) sharing;
d) shared-system access;
e) retention;
f) accuracy;
g) security;
h) marketing;
i) a Personal Data Breach;
j) handling of a rights request; or
k) another data-protection matter.
Complaints may be made by any reasonable communication method.
To ensure correct routing, complaints may be submitted centrally to:
Email: info@jamesgorey.com
Post: James Gorey Estate Agents, 1 Maidstone Road, Sidcup, DA14 5RH
Please provide sufficient information to identify you and explain the concern.
You do not need to use legal terminology.
A centrally received complaint will be routed to the responsible Data Controller.
Complaints concerning a Franchisee’s independent Sales Transaction will ordinarily be investigated by that Franchisee.
Complaints concerning services contracted with James Gorey Ltd will ordinarily be dealt with by James Gorey Ltd.
Complaints concerning services contracted with Carr Gorey Ltd will ordinarily be dealt with by Carr Gorey Ltd.
Joint Controller complaints will be handled cooperatively, with James Gorey Ltd normally coordinating where appropriate.
A data protection complaint will be acknowledged within 30 days of receipt.
Where it can be investigated and concluded within that period, acknowledgement and final outcome may be provided together.
The Relevant Controller will take appropriate steps to investigate without undue delay.
Relevant evidence and information will be considered and the complainant will be kept appropriately informed.
The outcome will be communicated without unjustifiable or excessive delay and will explain the conclusion and, where appropriate, action taken or proposed.
You have the right to complain to the Information Commissioner’s Office.
The ICO recommends giving the organisation concerned an opportunity to investigate and resolve the issue first, but you do not have to exhaust our internal process before contacting the ICO.
The new statutory complaints duty requiring a clear complaints process, acknowledgement within 30 days, investigation and an outcome came into force in June 2026.
We may amend this Policy where:
a) services change;
b) systems or suppliers change;
c) the network structure changes;
d) a Franchisee joins or leaves;
e) Data Controller or Processor roles change;
f) legislation or guidance changes;
g) commercial arrangements change; or
h) another update is appropriate.
The latest version will be published at jamesgorey.com.
Where a material change affects existing processing, additional notice will be provided where legally required.
Our website uses cookies and may use other technologies which store information on, or access information from, a user’s device.
These may include cookies, pixels, scripts, tags and similar storage or access technologies.
Some technologies are necessary for operation, security or functionality.
Others may be used for analytics, preferences, functionality, advertising or marketing.
These may be used for:
a) security;
b) maintaining sessions;
c) remembering privacy choices;
d) operating forms;
e) preventing fraud or misuse; and
f) providing another function strictly necessary for a service requested by the user.
Where legally permitted, consent will not be requested for strictly necessary technologies.
These may be used to understand:
a) visitor numbers;
b) pages visited;
c) navigation;
d) website performance;
e) errors; and
f) how the website can be improved.
Where a technology is used solely for qualifying statistical purposes and all conditions of the statutory exception are satisfied, it may be used without prior consent.
Where that exception is relied upon, clear information and a simple, free means of objecting will be provided as required.
Where the exception does not apply, consent will be obtained where required.
These may be used to remember preferences or adapt how the website appears or functions.
Where the relevant statutory exception applies and all conditions are satisfied, these may be used without consent.
Where required, a simple and free means of objecting will be provided.
Otherwise, consent will be obtained where required.
Marketing, targeting or advertising technologies may record information concerning visits, pages, links and interactions.
This may be used to:
a) make advertising more relevant;
b) measure advertising performance;
c) understand campaign effectiveness; or
d) support other advertising activities.
Where consent is required, these technologies will not be activated until consent has been obtained.
Third parties supplying advertising, social media, video, analytics or related services may use cookies or similar technologies where enabled.
These providers may include organisations such as:
Meta / Facebook;
Instagram;
Google;
YouTube; and
other advertising, analytics or website providers used from time to time.
Where a cookie preference or consent tool is provided, you may use it to accept, reject or change preferences.
Consent may be withdrawn at any time as easily as it was given.
Where the statistical or appearance exception is relied upon and an objection facility is legally required, a simple and free means of objecting will be provided.
Browser settings may also be used to block or delete cookies, although this may affect website functionality.
We will maintain appropriate information concerning technologies used, including provider, purpose, category and duration where required.
The technologies used may change from time to time.
The ICO's current guidance confirms there are five PECR exceptions, including the newer statistical-purpose and appearance exceptions. Those two exceptions require clear information and a simple free means of objecting, and they do not extend to online advertising or profiling.
For data protection enquiries, rights requests, marketing preferences or data protection complaints:
Email: info@jamesgorey.com
Post: James Gorey Estate Agents, 1 Maidstone Road, Sidcup, DA14 5RH
Where the matter relates to an independent network business, the enquiry will be passed to the appropriate Data Controller.