How do you keep my information secure and confidential?

Short answer: your data is protected by design

We secure and use your information solely to match your UK business with relevant finance providers, and we never sell your data. We apply strong technical, organisational, and contractual safeguards aligned to UK GDPR and the Data Protection Act 2018, including encryption in transit and at rest, strict access controls, and vetted partners. You remain in control at every step, and you can request access, correction, or deletion of your data at any time.

Plain‑English summary of our approach

Best Business Loans is an independent introducer, not a lender or broker, and our platform is built to keep your information safe throughout the matching process. We collect only what we need, store it securely, and share it solely with carefully selected lenders or brokers who are relevant to your enquiry. We keep your data only as long as necessary to provide our services and meet legal obligations, then we delete or anonymise it.

What we do and what we don’t do

  • We do use TLS encryption, access logging, multi‑factor authentication, and least‑privilege permissions.
  • We do conduct due diligence on providers and put data‑processing terms in place before sharing.
  • We don’t make lending decisions, offer financial advice, or sell your data to third parties.

Not a lender, not advice, free to enquire

We introduce you to finance providers; we do not provide credit ourselves, and nothing on our site constitutes financial advice. Submitting a Quick Quote or Eligibility Check is free and without obligation, and it does not guarantee an offer, approval, or a particular rate. Providers will set their own terms and may run credit and fraud checks in line with their regulatory duties.

How we secure your information end‑to‑end

Security is embedded into our process from the moment you submit your Quick Quote. We protect your data in transit and at rest, and we restrict who can access it on a strict need‑to‑know basis. We regularly review our controls to keep pace with evolving threats and best practice.

Encryption and infrastructure

  • Transport‑layer security: All data moving between your browser and our platform is protected with current TLS encryption (HTTPS).
  • Encryption at rest: We encrypt stored application data using industry‑standard algorithms to reduce exposure risk.
  • Secure hosting: We use reputable UK/EU cloud providers with robust physical and network security controls and continuous monitoring.
  • Segregation: Production systems are logically separated, limiting lateral movement and unauthorised access.

Access controls and monitoring

  • Least‑privilege access: Team members only see the minimal data necessary to support your request.
  • Multi‑factor authentication: Administrative systems require MFA and strong password policies.
  • Audit trails: Access to sensitive areas is logged and reviewed to detect unusual activity.
  • Vendor oversight: We assess critical suppliers for security posture and contractual data‑protection commitments.

Data retention and deletion

We keep your information only for as long as needed to progress your enquiry, meet legal and reporting obligations, and resolve enquiries or disputes. When data is no longer required, we delete or anonymise it according to documented retention schedules. You may request deletion sooner, subject to any lawful grounds that require us to retain limited records.

How we use, share and store your data

Your details help us understand your business, the finance you’re seeking, and the providers most likely to help. We only collect information that is relevant to matching and onboarding and we avoid unnecessary fields. Where optional information would improve matching accuracy, we tell you why and let you choose.

What we collect and why

  • Business profile: Legal name, trading name, sector, location, company number, and trading history to determine eligibility.
  • Funding needs: Purpose, amount, and timescales to prioritise appropriate finance types and providers.
  • Contact details: Name, role, email, and phone so we can respond and coordinate introductions.
  • Financial context (optional): Turnover, asset base, or invoice values to refine matching where helpful.

When we share data — and with whom

We may share your information with a small number of relevant UK lenders or brokers so they can assess your eligibility and contact you. Before sharing, we confirm that a provider is appropriate for your sector, finance type, and likely criteria. Each provider we introduce will handle your data under their own privacy policy and regulatory duties.

International transfers and location

We aim to store and process personal data in the UK or EEA. If a transfer outside the UK/EEA is necessary, we will use appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses. We assess destination risks and ensure providers meet equivalent standards of protection.

We work with established UK sectors, including hospitality venues. If you operate a pub and are exploring options, our sector guidance on pubs business loans outlines typical considerations for your industry and funding use cases.

Your privacy rights and how to exercise them

You have clear rights over your information under UK GDPR. We have a straightforward process for requests and aim to resolve them quickly and transparently. We do not charge for routine requests, and we will always explain if we need to verify your identity or require additional details.

Your UK GDPR rights

  • Access: Ask for a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete information.
  • Erasure: Request deletion where we no longer have a lawful reason to keep it.
  • Restriction: Limit how we use your data in certain circumstances.
  • Portability: Receive your data in a structured, commonly used format.
  • Objection: Object to processing based on legitimate interests or direct marketing.

How to make a request

Email hello@bestbusinessloans.ai with your name, business name, and the right you wish to exercise. We will acknowledge your request and respond within one month, or explain if an extension is required due to complexity. If we have introduced you to a provider, we may guide you to contact them as well because they are a separate data controller for their processing.

Complaints and oversight

If you are unhappy with how we have handled your data, please contact us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office (ICO) in the UK if you remain dissatisfied. We continually review our privacy and security measures to learn from feedback and maintain best practice.

Transparency, compliance and next steps

We aim to make our communications clear, fair, and not misleading, consistent with the spirit of the FCA’s financial promotion rules and UK advertising standards. We are not authorised by the FCA and do not give regulated advice; we act solely as an independent introducer to commercial finance providers. Any funding offer, APR, or facility limit is set by the provider and depends on your circumstances, eligibility, and the provider’s underwriting.

Clear, fair and not misleading

  • No guaranteed outcomes: Eligibility checks and Decisions in Principle are subject to provider assessment.
  • Balanced information: We explain benefits and limitations to support informed decisions.
  • Provider transparency: You will receive key terms and costs directly from the lender or broker before you proceed.
  • Credit checks: Providers may run soft or hard searches; hard searches can impact your credit file.

Practical tips to protect your own privacy

  • Submit information through our secure Quick Quote form rather than by email where possible.
  • Share only the details requested; avoid sending passwords, full bank logins, or sensitive documents unprompted.
  • Verify provider identities before sending further information and use their official channels.
  • Review each provider’s privacy notice and keep copies of agreements for your records.

Start your secure Quick Quote

It takes a couple of minutes to outline your funding needs and business profile, and our AI matching will do the heavy lifting. You will be connected only to relevant lenders or brokers who are active in your sector and finance type. Begin your secure, no‑obligation enquiry now to check eligibility and explore your best‑fit options.

FAQs about security and confidentiality

Do you sell my data?

No. We never sell your data. We only share it with selected lenders or brokers who are relevant to your enquiry.

Will you run a credit check?

We do not run credit checks. Any checks are carried out by the providers we introduce you to, under their own policies and legal obligations.

What legal basis do you rely on?

We process your data primarily to take steps at your request prior to introducing you to potential finance providers and on legitimate interests to operate and improve our service. Where required, we seek consent for specific uses such as marketing preferences.

How long do you keep my information?

We retain your data only as long as necessary for matching, introductions, and lawful obligations. After that, we delete or anonymise it in line with our retention schedules.

How can I contact you about privacy?

Email hello@bestbusinessloans.ai and include “Privacy” in the subject line. We will respond promptly and help with any requests or concerns.


About Best Business Loans

BestBusinessLoans.ai helps established UK businesses compare and connect with relevant commercial finance providers using AI‑assisted matching. We do not supply loans or provide financial advice; we introduce you to lenders or brokers who may be able to help, and you decide what to do next. Updated October 2025.

Share your love