Privacy Policy:
Privacy Policy
Last updated: 22 June 2026
1. Who we are
This website is operated by AMCO HOUSING (MCR) LTD ("we", "us", "our"), the data controller responsible for your personal data.
Registered / trading address: 67 Windsor Road, Prestwich, Manchester, England, M25 0DB
Telephone: 0161 773 3978
General contact: info@amcocommercial.co.uk
Data Protection Officer: Philip Corn — philip@amcomanagement.com
Privacy complaints: enquires@amcomanagement.com (or use the complaints form at the bottom of this page)
2. Categories of personal data we process
We may collect and process the following categories of personal data:
Identity data — name, date of birth, title, username or other identifiers.
Contact data — postal address, email address, telephone number.
Account and access data — user IDs, login details, access permissions, authentication information.
Professional or employment data — job title, employer name, business contact details.
Financial and transactional data — payment details, billing information, transaction records.
Technical and usage data — IP address, device information, browser type, operating system, access logs, usage activity.
Security and audit data — system logs, monitoring records, access records, incident-related information.
Communications data — correspondence, emails, and records of interactions with us.
Compliance and risk data — records required for regulatory, audit, or due diligence purposes.
3. Where we get your personal data
We may collect personal data about you from:
you directly;
employers or clients when you apply for a tenancy or are considered for an opportunity;
referees, where relevant and permitted;
publicly available sources (for example professional networking sites, business websites, and public records);
credit reference agencies (CRAs) where required for consumer credit, identity, or affordability checks;
third party service providers used to support tenant vetting, screening, and compliance processes.
4. Credit reference and affordability checks
To help us assess applications, prevent fraud, and meet our legal and regulatory obligations, we may obtain information about you from credit reference agencies (CRAs).
We obtain this information via Creditsafe, which uses its data partner TransUnion to supply consumer credit and identity data.
Creditsafe Business Solutions Limited is authorised and regulated by the Financial Conduct Authority — FCA Firm Reference Number 742313.
TransUnion International UK Limited is authorised and regulated by the Financial Conduct Authority — FCA Firm Reference Number 737740.
The information we receive may include data relating to your identity, credit commitments, payment history, and public record information. This data is used solely for legitimate business purposes, including creditworthiness assessment, identity verification, and fraud prevention, in accordance with applicable data protection laws.
Further information about how Creditsafe and TransUnion process your personal data can be found in their respective privacy notices:
Creditsafe Transparency Notice: https://www.creditsafe.com/gb/en/legal/transparency-notice-customers-and-suppliers.html
TransUnion CRAIN (Credit Reference Agency Information Notice): https://www.transunion.co.uk/legal/privacy-centre/pc-credit-reference
TransUnion Bureau Privacy Notice: https://www.transunion.co.uk/legal/privacy-centre/pc-bureau
5. How we use your data (lawful bases)
We process your personal data on one or more of the following lawful bases:
Contract — to enter into and perform a tenancy agreement or service contract with you.
Legal obligation — to comply with anti-money-laundering, right-to-rent, accounting, tax, and other regulatory duties.
Legitimate interests — to vet prospective tenants, prevent fraud, manage our property portfolio, and run our business.
Consent — where required, for example for marketing communications, which you can withdraw at any time.
6. International data transfers
We may transfer personal data to recipients or service providers located outside the UK and/or the European Economic Area (EEA).
Where such transfers take place, we ensure appropriate safeguards are in place to protect personal data in accordance with applicable data protection laws. These safeguards may include the use of approved standard contractual clauses, international data transfer agreements, or transfers to countries that have been recognised as providing an adequate level of data protection.
7. How long we keep your data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, regulatory, or reporting requirements. Tenancy and financial records are typically retained for at least seven years after the end of the relationship in line with HMRC and AML obligations.
8. Your rights
Under UK GDPR you have the following rights:
Right of access — to request a copy of the personal data we hold about you and information about how it is used.
Right to rectification — to request that inaccurate or incomplete personal data is corrected.
Right to erasure ("right to be forgotten") — to request that we delete your personal data where there is no lawful reason for us to continue processing it.
Right to restrict processing — to request that we limit how we use your personal data in certain circumstances.
Right to data portability — to receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transfer it to another organisation where technically feasible.
Right to object — to object to the processing of your personal data where we rely on legitimate interests, or where data is used for direct marketing.
To exercise any of these rights, contact our DPO at philip@amcomanagement.com.
9. Provision of personal data — statutory or contractual?
The provision of certain personal data is primarily contractual and, in some circumstances, required to meet legal and regulatory obligations. Personal data is required to:
enter into and perform contracts with customers, suppliers, or business partners;
process applications, manage accounts, and deliver services;
verify identity and prevent fraud;
comply with applicable legal, regulatory, accounting, and tax obligations.
Consequences of not providing personal data. If you choose not to provide the personal data we request:
we may be unable to enter into a contract with you;
we may be unable to grant a tenancy, supply goods, or provide services;
we may be unable to conduct necessary verification, compliance, or fraud prevention checks;
as a result, our services may be delayed, restricted, or declined.
Where personal data is requested for optional purposes, such as marketing communications, providing this data is not mandatory and you may withdraw your consent at any time without affecting your ability to receive services from us.
10. Non-automated decision making and profiling
We may use automated systems and tools to support certain business processes, such as risk assessment, fraud prevention, affordability checks, identity verification, or record management.
These tools may analyse personal data using predefined criteria or rules to generate indicators, scores, or recommendations. However, we do not make decisions that have a legal or similarly significant effect on individuals based solely on automated processing. Any such decisions are subject to meaningful human review.
The use of these tools may influence the speed or level of review applied to an application or request, but individuals will not be subject to automatic rejection or adverse decisions without human involvement.
11. Cookies
Our site uses cookies. For details of the cookies we set and how to manage them, see our Cookies Policy.
12. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
13. Complaints
You have the right to complain about how we handle your personal data. Under the Data (Use and Access) Act 2025, you may make a complaint either:
directly to us — by using the complaints form below, or by emailing enquires@amcomanagement.com; or
to the Information Commissioner's Office (ICO) — the UK supervisory authority for data protection. Details at https://ico.org.uk/make-a-complaint/ or by calling 0303 123 1113.
We will acknowledge your complaint within one month and respond as soon as reasonably practicable. We may ask you to verify your identity (for example by uploading a copy of photo ID) before we respond, in line with ICO guidance.
[The online complaints form supplied by it'seeze will appear below this section once the complaints email address is configured in the Privacy Policy component settings.]
14. Changes to this policy
We may update this policy from time to time. Any changes will be posted on this page with a revised "Last updated" date.