Privacy Policy
Last updated: —
VM Property Sourcing Ltd ("we", "us", "our") is a property deal sourcing business registered in England and Wales (Company No. 17304521), with its registered office at 65a Horwood Close, Cardiff, CF24 2LW. We are registered with the Information Commissioner's Office (ICO Reference: C1968586) as a data controller.
This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it. It applies to anyone who contacts us, uses our website, or engages us for property sourcing services.
Who we are and how to contact us
Data controller: VM Property Sourcing Ltd
Contact: Videet Mardania, Director
Email: videet@vmpropertysourcing.co.uk or enquiries@vmpropertysourcing.co.uk
Registered address: 65a Horwood Close, Cardiff, CF24 2LW
As a sole director with no employees, Videet Mardania is personally responsible for how your data is handled, including as the business's Money Laundering Reporting Officer (see below).
What personal data we collect
The data we collect depends on how you interact with us:
General enquiries
- Name and contact details (email, phone number)
- The content of any message, enquiry, or property details you share with us via our website, email, phone or WhatsApp
Vendors, landlords, buyers and investors
Where we act for you in a sourcing transaction, and in line with our obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, we collect and verify:
- Full name, date of birth and residential address
- Copies of identity documents (such as a passport or driving licence) and proof of address
- For corporate clients: company name, registration number, registered office, and details of directors and beneficial owners
- Property and transaction details relevant to the deal
This due diligence is completed before we market a property (for vendors) and no later than the point an offer is accepted (for buyers/investors), as set out in our AML Policies and Procedures.
How we use your data and our legal basis for doing so
- To respond to your enquiry and take the steps you ask of us before entering into an agreement — necessary for pre-contractual steps and our legitimate interest in running the business.
- To provide our services (sourcing) once instructed — necessary for the performance of a contract with you.
- To carry out customer due diligence and ongoing monitoring as required by the Money Laundering Regulations 2017, the Proceeds of Crime Act 2002 and the Terrorism Act 2000 — necessary to comply with a legal obligation.
- To detect and report suspicious activity, including submitting Suspicious Activity Reports to the National Crime Agency where required — necessary to comply with a legal obligation.
- To keep records for regulatory, tax and insurance purposes — necessary to comply with a legal obligation and our legitimate interest in maintaining an accurate compliance file.
We do not use your data for automated decision-making, and we do not sell your data to third parties.
Who we share your data with
- Regulators and authorities — HMRC (as our AML supervisor), the National Crime Agency, and other bodies where we are legally required to share information, including as part of a Suspicious Activity Report.
- Co-sourcing partners — where a deal is co-sourced under a written co-sourcing agreement, limited information may be shared with the partner strictly as needed to progress that transaction, under confidentiality.
- Service providers who process data on our behalf, such as our email providers and website host, under arrangements that require them to keep your data secure and only use it as we instruct.
- Professional advisers such as solicitors involved in a transaction, where relevant to completing that transaction.
We do not disclose the identity of confidential sourcing sources or introducers where doing so would breach an existing confidentiality obligation, except where required by law.
International data transfers
We use third-party providers to run our email and website:
- Zoho Mail (business email) — hosted on Zoho's EU data centre. Your data stays within the EU and no international transfer takes place.
- Resend (transactional email) and Netlify (website hosting) — both are US-based providers. Where personal data is transferred to them outside the UK, this is safeguarded by Standard Contractual Clauses approved for use under UK data protection law, and, in Resend's case, its certification under the EU-US Data Privacy Framework (including the UK Extension).
How long we keep your data
Where we have carried out customer due diligence as part of a sourcing transaction, we keep those records for at least 5 years after the end of the business relationship or the transaction, and no longer than 10 years, in line with our AML Policies and Procedures.
For general enquiries that do not proceed to a transaction or instruction, we keep your data for up to 12 months from your last contact with us, after which it is deleted or anonymised, unless we are legally required to keep it for longer.
Records are stored securely, including in encrypted cloud storage, and are retrievable promptly if required for regulatory inspection.
Cookies and website analytics
This website does not currently use analytics, advertising or tracking cookies. If that changes in future, we will update this policy and, where required, ask for your consent before any non-essential cookies are set.
Your rights
Under UK data protection law, you have the right to:
- Ask us what personal data we hold about you and receive a copy of it
- Ask us to correct inaccurate or incomplete data
- Ask us to delete your data, or restrict how we use it
- Object to us processing your data in certain circumstances
- Ask us to transfer your data to another organisation, where technically feasible
Please note that where we are required by anti-money laundering law to retain your data for a set period, we may not be able to delete it before that period ends, even if you ask us to.
To exercise any of these rights, contact us at videet@vmpropertysourcing.co.uk. You also have the right to complain to the Information Commissioner's Office at ico.org.uk if you believe we have not handled your data properly.
Keeping your data secure
We take reasonable technical and organisational steps to protect your personal data against unauthorised access, loss or misuse, including secure storage and limiting access to those who need it to carry out our work.
Changes to this policy
We may update this policy from time to time, for example if our services, providers, or legal obligations change. The date at the top of this page shows when it was last updated.
VM Property Sourcing Ltd is registered with Companies House (No. 17304521) and the Information Commissioner's Office (ICO Ref: C1968586), is a member of the Property Redress Scheme (Membership No. PRS059603), and is registered with HMRC for Anti-Money Laundering supervision (Registration No. XBML00000222524).