Table of contents
- 1. Introduction
- 2. Information we may collect
- 3. How we use your data
- 4. Applicable to all users
- 5. Applicable to renters
- 6. Applicable to landlords / Build-2-Rent (Institutional Landlords)
- 7. Applicable to letting agents/ Build-2-Rent (Institutional Landlords)
- 8. Applicable to Guarantors
- 9. Applicable to Referees
- 10. Marketing
1. Introduction
InsureStreet Limited (trading as Canopy) is the data controller. We are registered with the ICO and our registration number is: ZA207155
Protecting your data, privacy and personal information is very important to InsureStreet Limited (trading as Canopy) (“Canopy”, “us”, “our” or “we”). It is vitally important to us that our customers feel secure when using the Services.
This policy (together with our terms of use at https://www.canopy.rent/terms-of-service and any other documents referred to in it), sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by Canopy. Please read this privacy policy carefully to understand the types of information we collect from you, how we use that information, the circumstances under which we will share it with third parties, and your rights in relation to the personal data you provide to us.
When visiting Canopy’s website at https://www.canopy.rent (our “Website”), using our application:
“Canopy” (our “App”) or using any of the services offered via the Website or the App (the “Services”), you will be asked to indicate your acknowledgment of, and where applicable your consent to, the practices described in this policy.
Our Website contains links to third party websites. If you follow a link to any of those third party websites, please note that they have their own privacy policies and that we do not accept any liability for their policies or processing of your personal information. Please check these policies before you submit any personal information to such third-party websites.
2. Information we may collect
We may collect and process the following data about you:
By continuing to use our Platform, you are agreeing to our use of cookies. Please refer to our Cookie Policy for further information: https://www.canopy.rent/legal/cookie-policy
Information that you provide to us. You will be asked to provide us with your information when you:
- fill in forms on our Website or App, or correspond with us by phone, email or otherwise;
- register to use our Services, subscribe to our newsletter, promotional emails or other marketing materials;
- use the Services;
- report a problem with our Services; or
- complete any surveys we ask you to fill in that we use for research purposes (although you do not have to respond to these if you do not want to).
The information you will be asked to provide to us for these purposes will include your name, address, previous addresses (up to three years), date of birth, nationality, e-mail address, gross income, pay slips, references from landlords, phone number, national insurance number, passport number, credit records, personal description and photograph, payment details and banking and open banking information (which includes, but is not limited to, the name, account ID, type, time stamp and amount transacted of your bank transactions), or further information required to verify your identity, rent affordability assessment, provide access to financial and non-financial products including tracking your rental payments. We may also request move-to and move-from addresses, moving dates, tenancy details, council tax status, and other data required for the provision of those services (including data relating to other occupants or household members).
Information we collect about you. With regard to each of your visits to our Website or our App we may automatically collect the following information;
- device-specific information, such as your hardware model, operating system version, unique device identifiers, and mobile network information;
- technical information about your computer, including where available, your IP address, operating system and browser type, for system administration and analytical purposes;
- details of your visits to our Website and App, including the full Uniform Resource Locators (URL) clickstream to, through and from our Website and App (including date and time), length of visits to certain pages, and page interaction information (such as scrolling, clicks, and mouse-overs); and
- information showing us from which app store you downloaded our App.
Information we receive from other sources. When using our Services, we will be in contact with third parties who may provide us with certain information about you in order to enable your use of the Services.
If when using our Services you input any personal data of a third party, you must have obtained clear consent from the individuals prior to sharing their data and provide them with a copy of this Privacy Policy.
For the avoidance of any doubt, any reference in this privacy policy to your data shall include data about other individuals that you have provided us with.
3. How we use your DATA
Use of personal information under UK and EU data protection laws must be justified under one of a number of legal “bases” and we are required to set out the ground in respect of each use of your personal data in this policy. These are the principal grounds that justify our use of your information:
- Consent: where you have consented to our use of your information (you are providing explicit, informed, freely given consent, in relation to any such use and may withdraw your consent in the circumstance detailed below by notifying us);
- Contract performance: where your information is necessary to enter into or perform our contract with you;
- Legal obligation: where we need to use your information to comply with our legal obligations;
- Legitimate interests: where we use your information to achieve a legitimate interest and our reasons for using it outweigh any prejudice to your data protection rights; and
- Legal claims: where your information if necessary for us to defend, prosecute or make a claim against you or a third party.
We use information held about you (and information about others that you have provided us with) in the following ways:
4. Applicable to all users
Type of information collected: Email address, name.
- Use of information: To provide you with access to our Website, App and any other information which you request from us, and to use our Services.
- Justification: Contract performance.
Type of information collected: Email address, name.
- Use of information: For marketing products and services that we believe will be of interest to you.
- Justification: Legitimate interest (for marketing our own similar products and services and any re-engagement campaigns). Consent (for marketing unrelated products or services or products or services of third parties).
Type of information collected: Email address.
- Use of information: To notify you about changes to our Services.
- Justification: Legitimate interests (to update our Services from time to time).
5. Applicable to renters
Type of information collected: Email address, name, date of birth, current address and previous addresses.
- Use of information: To provide you with access to our Website, App and any other information which you request from us, and to use our Services.
- Justification: Contract performance.
Type of information collected: Information from linked accounts such as social networking sites.
- Use of information: To administer our Services and identify more appropriate products and services that we may be of interest to you.
- Justification: Consent.
Type of information collected: Identity confirmation, right to reside in the UK, date of birth, current and previous addresses, gross income, pay slips, credit records, payment details, banking and open banking information, education history employment history, legal and regulatory warnings issued against you, and your appearance on any global watch lists.
- Use of information: To provide you with the Services, specifically our RentPassport™ (which is your digital renter identity and rental history, which you can share with Landlords) based on the information you provide to us. This includes using an artificially defined algorithm. The same information will be used to identify a range of personalised insurance non-insurance based services which are tailored to you.
- Justification: Legitimate interests; consent (in respect of open banking information); contract performance (to the extent required to provide the services e.g. to track rental payments or Renter income verification as required by Landlords / Agents before a rental contract between Agent / Landlord and Renter can be executed)
Type of information collected: Email address, name.
- Use of information: To provide you with the Services, specifically Right to Rent identity verification (provided by IDnow GmbH, whose registered office is at Auenstraße 100, 80469, Munich, Germany).
- Justification: consent, legal obligation.
- Types of information collected: Identity document (including UK / EU / International Passport, UK Drivers License, UK/EU Residence Card, UK Immigration document), biometric data, mobile number and any supplementary information submitted to prove right to rent in the UK..
- Use of information: For marketing products and services that we believe will be of interest to you.
- Justification: Legitimate interest (for marketing our own similar products and services and any re-engagement campaigns). Consent (for marketing unrelated products or services or products or services of third parties).
Type of information collected: Move-to and move-from addresses, tenancy details, council tax status.
- Use of information: To provide you with the Services, including CanopyBills and CanopyCover as described in our terms and conditions, we will need to provide relevant personal data to Just Move In, The Bunch, HomeBox and LegalforLandlords as contracting parties for this service. As per the contract entered into between renters and Canopy, Just Move In, The Bunch, HomeBox and LegalforLandlords will also store and be a controller of such personal data. This will be limited to the data required to fulfil the contract, such as name and contact details.
- Justification: Consent, contract performance, legitimate interest (for the purpose of fulfilling the contract for Home Setup Services/CanopyCover by Just Move In/HomeBox/The Bunch/LegalforLandlords)
Type of information collected: Email address, name, payment details and bank account information
- Use of information: To administer our Services including payment processing services such as Stripe and for internal operations, including research, data analysis and data statistics, and to create derived, anonymised and aggregated data to improve our Services.
- Justification: Contract performance (in respect of payment processing); Legitimate interests (to administer and improve our Services)
Type of information collected: Email address
- Use of information: To notify you about changes to our Services.
- Justification: Legitimate interests (to update our Services from time to time).
6. Applicable to landlords / Build-2-Rent (Institutional Landlords)
Type of information collected: Email address, name
- Use of information: To provide you with access to our Website, App (including having a Canopy Account) and any other information which you request from us, and to use our Services.
- Justification: Contract performance
Type of information collected: Email address, name
- Use of information: For marketing products and services that we believe will be of interest to you.
- Justification: Legitimate interest (for marketing our own similar products and services and any re-engagement campaigns). Consent (for marketing unrelated products or services or products or services of third parties).
Type of information collected: Email address, name, payment details and bank account information
- Use of information: To administer our Services including Renter Screening services, payment processing services such as Stripe and for internal operations, including research, data analysis and data statistics, and to create derived, anonymised and aggregated data to improve our Services.
- Justification: Contract performance (in respect of Renter screening, payment processing); Legitimate interests (to administer and improve our Services)
Type of information collected: Email address, name.
- Use of information: For marketing products and services that we believe will be of interest to you.
- Justification: Legitimate interest (for marketing our own similar products and services and any re-engagement campaigns). Consent (for marketing unrelated products or services or products or services of third parties).
Type of information collected: Email address
- Use of information: To notify you about changes to our Services.
- Justification: Legitimate interests (to update our Services from time to time).
7. Applicable to letting agents/ Build-2-Rent (Institutional Landlords)
Type of information collected: Email address, name.
- Use of information: To provide you with access to our Website, App (including having a Canopy Account) and any other information which you request from us, and to use our Services.
- Justification: Contract performance
Type of information collected: Email address, name.
- Use of information: For marketing products and services that we believe will be of interest to you.
- Justification: Legitimate interest (for marketing our own similar products and services and any re-engagement campaigns). Consent (for marketing unrelated products or services or products or services of third parties).
Type of information collected: Email address, name, payment details and bank account information
- Use of information: To administer our Services including Renter Screening services, payment processing services such as Stripe and for internal operations, including research, data analysis and data statistics, and to create derived, anonymised and aggregated data to improve our Services.
- Justification: Contract performance (in respect of Renter Screening, payment processing); Legitimate interests (to administer and improve our Services)
Type of information collected: Email address.
- Use of information: To notify you about changes to our Services.
- Justification: Legitimate interests (to update our Services from time to time)
We will not sell your personal data (or any other data you provide us with) to third-parties, however, we reserve the right to share any data, which has been anonymised and/or aggregated. You acknowledge and accept that we own all right, title and interest in and to any derived data or aggregated and/or anonymised data collected or created by us.
8. Applicable to Guarantors
Type of information collected: Email address, name, date of birth, current address and previous addresses.
- Use of information: To provide you with access to our Website, App and any other information which you request from us, and to use our Services.
- Justification: Contract performance
Type of information collected: Information from linked accounts such as social networking sites.
- Use of information: To administer our Services and identify more appropriate products and services that we may be of interest to you.
- Justification: Consent
Type of information collected: Identity confirmation, right to reside in the UK, date of birth, current and previous addresses, gross income, pay slips, credit records, payment details, banking and open banking information, education history employment history, legal and regulatory warnings issued against you, and your appearance on any global watch lists
- Use of information: To provide you with the Services, specifically our RentPassport™ (which is a digital renter identity and rental history, which renters can share with Landlords) based on the information you provide to us. This includes using an artificially defined algorithm
- Justification: Legitimate interests; consent (in respect of open banking information); contract performance (to the extent required to provide the services e.g income verification as required by Landlords / Agents before a rental contract between Agent / Landlord and Renter can be executed)
Type of information collected: Email address, name, Identity document (including UK / EU / International Passport, UK Drivers License, UK/EU Residence Card, UK Immigration document), biometric data, mobile number and any supplementary information submitted to prove right to rent in the UK.
- Use of information: To provide you with the Services, specifically Right to Rent identity verification (provided by IDnow GmbH, whose registered office is at Auenstraße 100, 80469, Munich, Germany).
- Justification: Consent, legal obligation.
Type of information collected: Email address, name, payment details and bank account information
. Use of information: To administer our Services including payment processing services such as Stripe and for internal operations, including research, data analysis and data statistics, and to create derived, anonymised and aggregated data to improve our Services.
. Justification: Contract performance (in respect of payment processing); Legitimate interests (to administer and improve our Services)
Type of information collected: Email address.
. Use of information: To notify you about changes to our Services.
. Justification: Legitimate interests (to update our Services from time to time).
Guarantor information will only be used for the purpose for which it was collected and will not be used for any additional purposes, such as marketing.
9. Applicable to REFEREES
Type of information collected: Email address, name, telephone number, job title, employment details.
- Use of information: To administer our Services including Renter Screening services.
- Justification: Consent, Legitimate Interest (In order to conduct necessary background checks)
Referee information will only be used for the purpose for which it was collected and will not be used for any additional purposes, such as marketing.
10. Marketing
We may use information for marketing products and services to you in the following ways:
- Newsletters and marketing emails relating to our own similar services and products. Where required by law, we will ask for your consent at the time we collect your data to conduct any of these types of marketing. We may rely on Legitimate Interest to market similar products or services that we believe may be beneficial or of interest. You will be able to unsubscribe at anytime.
Justification: Legitimate interest (to market our products and services - you have the right to unsubscribe at any time) - To send you details about unrelated services or products or special offers and discounts which are being provided by our selected business partners. Where required by law, we will ask your consent at the time we collect your data to conduct any of these types of marketing.
Justification: Consent (which can be withdrawn at any time)
We will provide an option to unsubscribe or opt-out of further communication on any electronic marketing communication sent to you or you may opt out by contacting us.
11. Where we store your personal information
The personal data that we collect from you (including email addresses that form part of our prospective marketing database) is processed in the European Economic Area (“EEA”) and stored on Amazon Web Services (Europe) Cloud Servers.
We shall transfer your data subject only to your consent except for transfers to and from: (i) any country with a valid adequacy decision from the European Commission; or (ii) any organisation which ensures an adequate level of protection in accordance with applicable data protection laws.
Your data may be processed outside of the EEA for the purposes provided in this policy. Where such countries do not have equivalent safeguarding measures in place, we will, where possible, do so with your consent. Alternatively we will transfer using appropriate safeguarding measures, such as Standard Contractual Clauses and in accordance with applicable data protection legislation.
A full list of our third party sub-processors and details of their privacy policies can be found here: https://www.canopy.rent/legal/sub-processor
Your passwords are stored on Canopy’s servers in encrypted form. We do not disclose your account details. It is your responsibility to keep your password secure. Unfortunately, the transmission of information via the internet is not completely secure. Although Canopy will do its best to protect your personal data, we cannot guarantee the security of your data transmitted to our Website, any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent any unauthorised access.
Please contact us if you would like further details on the specific safeguards applied to the export of your personal information outside EEA.
12. Disclosure of your information
We may also disclose your personal information to third parties in the following circumstances:
- We may disclose your personal information to our service providers and business partners, including payments processors, database tool providers and insurance providers (to assist us in performing any contract we enter into with them or you, including providing the Website and the Services it enables), analytics providers, (to assist us in the improvement and optimisation of the Website) and/or a member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.
We share your personal information with Experian Limited of Sir John Peace Building, Experian Way, NG2 Business Park, Nottingham, NG80 1ZZ, with company number 653331 (“Experian”) Equifax Limited of 1 Angel Court, London, EC2R 7HJ, with company number 2425920 (“Equifax”), TransUnion International UK Limited of One Park Lane, Leeds, West Yorkshire, LS3 1EP (“TransUnion”), as well as with additional Credit Reference Agencies (“CRA’s”), which we may choose to partner with from time to time, in order to process rental data through a Rental Exchange Database Tool (the “Tool”). Use of the Tool will enable us to work with you as a Renter more closely to manage your existing tenancy agreement. We will only share your open banking information if you permit us to do so.
We also share your personal information with third party payment processor Stripe which manages payment of rent, splitting bills between tenants and facilitates a pay-as-you-go service for Renters. Further information in relation to Stripe can be found in our terms of service.
Justification: Contract performance, legitimate interest, consent(to allow our Service providers to provide the necessary services). - If we sell or buy any business or assets, we may disclose your personal information to the prospective seller or buyer of such business or assets.
Justification: Legitimate interest (to sell our business or assets); and where required by applicable law, consent (for sensitive personal data). - If Canopy or substantially all of its assets are acquired by a third party, personal information about our customers will be one of the transferred assets.
Justification: Legitimate interest (to sell our business or assets); and where required by applicable law, consent (for sensitive personal data). - If we are under a duty to disclose or share your personal data in order to comply with any legal obligation or to protect the rights, property, or safety of Canopy, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection.
Justification: Legal obligation, vital interest. - Fraud Prevention and other checks. We and other organisations may also access and use your personal information to conduct credit checks and checks to prevent fraud. If false or accurate information is provided and fraud is identified or suspected, details may be passed to fraud prevent agencies.
Justification: Legitimate interest (to assist with the prevention of fraud and to assess your risk profile). - As a Renter we will share your following personal information with Letting Agents and Landlords: name, email address, previous and current addresses (up to three years), nationality, TrustScore™ and RentPassport™ information.
As a Landlord we will share your following personal information with Renters and Letting Agents: name, email address, bank account information for payments.
As a Letting Agent, Build-2-Rent Operator we will share your following personal information with Renters and Landlords: name, email address, bank account information for payments.
Justification: Consent - As part of our Services, we offer Renters with regulated account information services as an agent of Plaid Financial Ltd., an authorised payment institution regulated by the Financial Conduct Authority under the Payment Services Regulations 2017 (Firm Registration Number: 804718) for the provision of payment services, including account information services (“Plaid”). Plaid provides us with a portal through which Renters can authorise Plaid to share Renter’s information with us. Once we receive such information, we shall process such personal data in accordance with this privacy policy. We are not responsible for, and take no liability for, the acts and omissions of Plaid. Plaid’s privacy policy shall apply to their processing https://plaid.com/legal/#privacy-statement.
Justification: Consent
13. How long we retain your personal data
We will hold the above information for as long as is necessary in order to provide you with the Services, this is usually 12 months or otherwise as is required by law or any relevant regulatory body. We may be required to hold identity documents or financial data for longer, in order to comply with legal obligations.
Once your account is terminated or deactivated, we shall delete the personal data relating to your account within 72 hrs. If your account is inactive for 2 years, we may contact you to assess whether you want to continue to use the Services. Some personal data may need to be retained for longer than this to ensure Canopy can comply with applicable laws and internal compliance procedures, including retaining your email address for marketing communication suppression if you have opted not to receive any further marketing.
If information is used for two purposes, we will retain it until the purpose with the latest period expires but we will stop using it for the purpose with a shorter period when that period expires.
We restrict access to your personal information to those persons who need to use it for the relevant purpose(s). Our retention periods are based on business needs and your information that is no longer needed is either irreversibly anonymised (and the anonymised information may be retained) or securely destroyed.
14. Your rights
Under the General Data Protection Regulation (EU) 2017/676, you have various rights in relation to your personal data. All of these rights can be exercised by contacting us at [email protected].
You have the following rights in relation to your personal data:
Right to Rectification:
We will use reasonable endeavours to ensure that your personal information is accurate. In order to assist us with this, you should notify us of any changes to the personal information that you have provided to us by sending us a request to rectify your personal data where you believe the personal data we have is inaccurate or incomplete.
Right to erasure / ‘Right to be forgotten’:
Asking us to delete all of your personal data will result in Canopy deleting your personal data without undue delay (unless there is a legitimate and legal reason why Canopy is unable to delete certain of your personal data, in which case we will inform you of this in writing).
Right to restriction of processing:
You have the right to ask us to stop processing your personal data at any time.
Right to data portability:
You have the right to request that Canopy provides you with a copy of all of your personal data and to transmit your personal data to another data controller in a structured, commonly used and machine-readable format, where it is technically feasible for us to do so.
Right to complain:
You have the right to lodge a complaint to a supervisory authority such as the Information Commissioner’s Office in the UK (see www.ico.org.uk). Although we encourage our customers to engage with us in the event they have any concerns or complaints.
Right to object to discussions based solely on automated processing:
You have the right to not be subject to a decision based solely on automated processing which produces legal effects concerning your or similarly significant effects and to obtain human intervention, to express your point of view or contest the decision.
Canopy will not ordinarily charge you in respect of any requests we receive to exercise any of your rights detailed above; however, if you make excessive, repetitive or manifestly unfounded requests, we may charge you an administration fee in order to process such requests or refuse to act on such requests. Where we are required to provide a copy of the personal data undergoing processing this will be free of charge; however, any further copies requested may be subject to reasonable fees based on administrative costs.
Asking us to stop processing your personal data or deleting your personal data will likely mean that you are no longer able to use Canopy’s Services, or at least those aspects of the Services which require the processing of the types of personal data you have asked us to delete, which may result in you no longer being able to use the Services.
Where you request Canopy to rectify or erase your personal data or restrict any processing of such personal data, Canopy may notify third parties to whom such personal data has been disclosed of such request. However, such third party may have the right to retain and continue to process such personal data in its own right, for example payment processing or insurance companies.
15. Sharing of information with Credit Referencing AGENCIES
Not only will we be able to work with you more closely to manage your existing tenancy agreement, your track record as a tenant will enable the CRA's to use the information supplied to them to assist other landlords and organisations to:
- assess and manage any new tenancy agreements you may enter into;
- assess your financial standing to provide you with suitable products and services;
- manage any accounts that you may already hold, for example reviewing suitable products or adjusting your product in light of your current circumstances;
- contact you in relation to any accounts you may have and recovering debts that you may owe;
- verifying your identity, age and address, to help other organisations make decisions about the services they offer;
- help to prevent crime, fraud and money laundering;
- screen marketing offers to make sure they are appropriate to your circumstances;
- for the CRA's to undertake statistical analysis, analytics and profiling,
- and for the CRA's to conduct system and product testing and database processing activities, such as data loading, data matching and data linkage.
By signing up to Canopy, you acknowledge that information regarding your rental payments and track record as a tenant will be shared with Experian, Equifax and TransUnion, which will add this information to the credit reference data it holds about you and use it as a controller, in accordance with their privacy notices (a copy of which can be found by following the links below).
If you would like to see more information on these, and to understand how the credit reference agencies each use and share rental data as bureau data (including the legitimate interests each pursues) this information is provided in the following links: www.experian.co.uk/crain or www.equifax.co.uk/crain or https://www.transunion.co.uk/legal/privacy-centre (Credit Reference Agency Information Notice (CRAIN)), (Credit Reference Agency Information Notice (CRAIN)). (For a paper copy, please get in touch with us or with the relevant CRA using the contact details in this letter).
We and the CRA's will ensure that your information is treated in accordance with UK data protection law, so you can have peace of mind that it will be kept secure and confidential and your information will not be used for prospect marketing purposes.
If you would like advice on how to improve your credit history you can access independent and impartial advice from www.moneyadviceservice.org.uk (you can get a copy of your Statutory Credit Report by visiting www.experian.co.uk/consumer/statutory-report).
16. Changes to this policy
Any changes we make to our privacy policy in the future will be posted on this page, and where appropriate, notified to you by email or notifications via the App. We therefore encourage you to review it from time to time to stay informed of how we are processing your information.
17. Contact
Questions, comments and requests regarding this privacy policy are welcome and should be addressed to [email protected].
For the purpose of the relevant data protection legislation, the data controller is InsureStreet Limited (trading as Canopy) (company no. 10287920) with registered address at One Suffolk Way, Sevenoaks, Kent, England, TN13 1YL
You can contact our Data Protection Officer to discuss this Privacy Policy or if you have any questions relating to the processing of your personal data: [email protected]
18. Cookies
Canopy uses cookies to distinguish you from other users. This helps us provide you with a good experience when you use our Website, and also allows us to improve our Services. Please note that it is possible to disable cookies being stored on your computer by changing your browser settings. However, our Website may not perform properly or some features may not be available to you if you disable cookies.
For detailed information on the cookies we use and the purposes for which we use them see our Cookie policy at https://www.canopy.rent/cookie-policy.