Privacy Policy
Last updated: 12 July 2026
1. Who we are
Quantum Brick Ltd (“Quantum Brick”, “we”, “us”) is a property sourcing and deal packaging business registered in England and Wales, company number 16810775, with its registered office at Flat 1, 5 Kingston Road, London, United Kingdom, SW19 1JX.
We are the data controller for the personal data described in this policy. You can contact us about anything in this policy at ADD: contact email or by post at the registered office above.
We are registered with the Information Commissioner's Office (ICO) under registration number ICO registration pending — XXXXX.
2. The personal data we collect
| When | What we collect |
|---|---|
| You join the investor network | Name, email address, investment focus, indicative budget, and your consent preferences. |
| You send an enquiry via our contact form | Name, email address and/or phone number, whether you are contacting us as an investor, vendor, JV partner, developer or agent, and the content of your message. |
| You correspond with us | The contents of emails, calls and meetings, and notes we make of them. |
| You proceed with a sourced deal | Identity documents, proof of address, and proof and source of funds, as required by UK anti‑money‑laundering law; transaction details; and details needed to prepare our written terms. |
| You visit this website | We do not set analytics or advertising cookies. Our hosting provider records standard server logs (IP address, browser type, pages requested) for security and delivery of the site. |
3. Why we use your data, and our lawful bases
- Responding to enquiries and providing our services — performance of a contract, or steps taken at your request before entering a contract (UK GDPR Article 6(1)(b)), and our legitimate interests in running our business (Article 6(1)(f)).
- Sending curated deal alerts — your consent (Article 6(1)(a)). You can withdraw consent at any time; every alert contains an unsubscribe link, and you can also email us.
- Anti‑money‑laundering and identity checks — compliance with our legal obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (Article 6(1)(c)).
- Keeping business records, defending legal claims, preventing fraud — our legitimate interests and, where applicable, legal obligation.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects, and we never sell your data.
4. Who we share your data with
- Service providers who help us operate: our website host (Netlify), our form-processing provider (which forwards form submissions to our mailbox), and our email provider (Google). Each acts under contractual terms limiting what they may do with your data.
- Professional advisers — solicitors, accountants, insurers and compliance consultants, where necessary.
- Identity-verification and AML-screening providers, where you proceed with a transaction.
- Counterparties to a transaction (for example a vendor's solicitor), only to the extent needed to progress a deal you have chosen to pursue.
- Authorities — HMRC, the National Crime Agency, law enforcement or regulators, where the law requires or permits.
5. International transfers
Some of our service providers (including our website host and email provider) may process data outside the United Kingdom, including in the United States. Where they do, we rely on safeguards recognised under UK GDPR, such as the UK Extension to the EU–US Data Privacy Framework or the ICO's International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
6. How long we keep your data
- Enquiries that do not lead to a transaction — up to 2 years from our last contact.
- Deal-alert subscriptions — until you unsubscribe or 2 years of inactivity, whichever is sooner.
- Transaction and AML records — at least 5 years after the end of the business relationship, as required by the 2017 Money Laundering Regulations.
- Accounting records — at least 6 years, as required by company and tax law.
7. Your rights
Under UK GDPR you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to our processing, including objecting at any time to direct marketing;
- data portability in certain circumstances; and
- withdraw consent at any time, where consent is our lawful basis.
To exercise any of these rights, contact us using the details in section 1. We will respond within one month. We may need to verify your identity first.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113, although we would welcome the chance to resolve your concern first.
8. Cookies
This website does not set analytics, advertising or other non-essential cookies. Fonts are loaded from Google Fonts, which involves your browser requesting font files from Google's servers; Google may log those requests as described in its own privacy policy.
9. Security
We use appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS) to this website, access controls on our mailboxes and systems, and secure storage of transaction records. No system is completely secure, but we take reasonable steps to protect your data against loss, misuse and unauthorised access.
10. Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last revised. Material changes will be highlighted on this page.