Legal
Privacy and Cookies Policy
This Privacy and Cookies Policy explains how SK Dream Properties Services Ltd (“we”, “us”, “the Firm”) collects and uses personal data when you visit our website, contact us, or engage us for our services. It is published in accordance with Articles 12, 13 and 14 of the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the Privacy and Electronic Communications Regulations 2003 (PECR), and the Data (Use and Access) Act 2025.
1. Who we are and how to contact us
SK Dream Properties Services Ltd is a UK-registered limited company providing property sourcing and portfolio-building services. We are an Estate Agency Business under section 1 of the Estate Agents Act 1979, supervised by His Majesty's Revenue and Customs (HMRC) for Anti-Money Laundering purposes. We are a member of the Property Redress Scheme (PRS), membership number PRS058864.
We are the data controller for the personal data described in this policy.
- Email: [email protected]
- Postal address: 106b West Way, Botley, Oxford OX2 9JU
- Money Laundering Reporting Officer (MLRO) / Data-protection contact: Stavros Stergiopoulos
2. Personal data we collect
We collect personal data in three main contexts:
2.1 When you visit our website
- Technical and device data automatically logged by our website host: your Internet Protocol (IP) address, browser type and version, operating system, the page you arrived from (referrer), the pages you visit on our site, the time and date of your visit, and the language settings of your browser.
- Cookie data as described in section 9 below.
2.2 When you contact us via the website, by email or by phone
- Identity and contact information you provide: your name, email address, telephone number, postal address, and any other details you choose to share in your enquiry.
- Enquiry content: what you wrote to us, your stated property requirements, budget, timeframe, and any other context.
2.3 When you become a client
The data we collect at engagement is described separately in our Privacy Notice and Acknowledgement(provided to you before the business relationship begins). It includes identity documents, proof of address, beneficial-ownership information for corporate clients, source-of-funds evidence, and sanctions / Politically Exposed Person (PEP) screening data. That additional processing is required by the Money Laundering Regulations 2017 (the “MLRs”) and applies on top of this Privacy and Cookies Policy.
3. How we collect your personal data
- Directly from you when you fill in a contact form, email us, telephone us, or instruct us as a client.
- Automatically via our website (technical/device data and cookies).
- From public registers (Companies House for corporate clients; the Land Registry where relevant; the Persons with Significant Control (PSC) register).
- From third-party screening providers we engage to perform sanctions, PEP and adverse-media checks on clients and counterparties.
4. Why we use your personal data — purposes and lawful basis
Under UK GDPR Article 6 each processing activity must have a lawful basis. The table below maps each purpose to the basis we rely on.
| Purpose | Lawful basis (UK GDPR Art 6) |
|---|---|
| Operating our website and ensuring it is secure | Legitimate interests (running our business; protecting against fraud and abuse) |
| Responding to enquiries you send us | Legitimate interests (responding to people who contact us); on becoming a client, performance of a contract with you |
| Sending you transactional emails (e.g. replies to your enquiries, updates on a property search you asked about) | Legitimate interests / performance of a contract |
| Sending you marketing communications you have consented to | Consent (UK GDPR Art 6(1)(a); PECR Reg 22 for electronic marketing) |
| Performing services for clients | Performance of a contract with you |
| Performing Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), sanctions and Politically Exposed Person (PEP) screening, and ongoing monitoring | Legal obligation under the MLRs |
| Making Suspicious Activity Reports (SARs) or Defence Against Money Laundering (DAML) requests to the National Crime Agency (NCA); reports to the Office of Financial Sanctions Implementation (OFSI); notifications to HMRC | Legal obligation (Proceeds of Crime Act 2002; Terrorism Act 2000; UK sanctions regulations) |
| Keeping records for the statutory AML retention period | Legal obligation (MLRs regulation 40) |
| Defending or pursuing legal claims | Legitimate interests (establishment, exercise or defence of legal claims) |
We do not use your personal data for automated decision-making with legal or similarly significant effects on you, and we do not sell your personal data to anyone.
5. Who we share your personal data with
We share your personal data only with parties who need it for the purposes set out in this policy:
- Our website host and IT service providers acting as our data processors under written agreements that meet UK GDPR Article 28.
- Sanctions, Politically Exposed Person (PEP) and adverse-media screening providers acting as our data processors.
- His Majesty's Revenue and Customs (HMRC) — our Anti-Money Laundering supervisor.
- The National Crime Agency (NCA) — where we make a Suspicious Activity Report or Defence Against Money Laundering request.
- The Office of Financial Sanctions Implementation (OFSI) — for any required sanctions report.
- The Foreign, Commonwealth & Development Office (FCDO) — by reference to the UK Sanctions List for screening purposes.
- The Property Redress Scheme (PRS) — if you make a complaint and refer it to PRS as the independent redress scheme.
- The Information Commissioner's Office (ICO) — only if required by law.
- Your professional advisers (solicitor, accountant) — where you have authorised us to share information with them.
- Law enforcement, courts and regulators — where required by law or court order.
We do not sell, rent or trade your personal data with anyone.
6. International transfers
We do not transfer your personal data outside the United Kingdom routinely. If a transfer outside the UK is necessary (for example, if a service provider hosts data in the European Economic Area or elsewhere), we rely on either an Adequacy Regulation made by the UK government or appropriate safeguards under UK GDPR Article 46 (such as the Standard Contractual Clauses, with a UK Addendum where required).
7. How long we keep your personal data
| Category | Retention |
|---|---|
| Website log data and analytics cookies | Up to 26 months, or per the lifespan stated for each cookie in section 9 |
| Enquiry data where you did not become a client | Up to 12 months from your last contact with us, unless you ask us to delete it sooner |
| Client data and AML records | Minimum 5 years from the end of the business relationship or the completion of the occasional transaction, in accordance with Money Laundering Regulations 2017, regulation 40. Where another law (for example tax law or limitation periods for litigation) requires longer, we retain for the longer period. |
| Marketing-consent records | For as long as you remain subscribed, plus 24 months after unsubscribe (to evidence that you previously consented) |
At the end of the retention period we delete or anonymise the data.
8. Your rights
Under the UK GDPR you have the right to:
- be informed about how we process your data (this policy);
- request access to your data (a subject access request);
- request correction of inaccurate data;
- request erasure of your data (“right to be forgotten”);
- request restriction of processing;
- object to processing based on legitimate interests or direct marketing (you can opt out of marketing at any time by clicking the unsubscribe link in any marketing email or by emailing us);
- data portability where the lawful basis is consent or contract performance;
- withdraw consent at any time where we are processing your data on the basis of consent (this does not affect the lawfulness of processing before withdrawal).
Important AML restrictions on these rights. In the AML context two statutory exemptions may limit our ability to fulfil your rights:
- Crime and taxation exemption — Data Protection Act 2018, Schedule 2, Part 1, paragraph 2. We may withhold or restrict information where doing so is required to prevent prejudice to the prevention, detection, investigation or prosecution of crime, or the assessment or collection of a tax or duty.
- Tipping off — Proceeds of Crime Act 2002, section 333A. We may not confirm or deny whether a Suspicious Activity Report has been made about you or any related person, even if you ask.
If we apply either exemption we will tell you we are doing so (where we are permitted to do so) and explain the reason in general terms.
To exercise your rights, please contact us using the details in section 1. We will respond within one month of receiving a valid request (extendable by a further two months if the request is complex). We may need to verify your identity before responding.
9. Cookies and similar technologies
A cookie is a small text file placed on your device when you visit a website. Cookies are governed in the United Kingdom by regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR) and by UK GDPR Article 7 where the cookie processes personal data.
9.1 Categories of cookies we use
| Category | Purpose | Legal basis | Default |
|---|---|---|---|
| Strictly necessary | Required for the website to function (e.g. session management, security, load balancing, remembering your cookie-consent choices) | Necessary for the service you requested — does not require consent under PECR Reg 6(4) | Always on |
| Performance / analytics | Help us understand how visitors use the site so we can improve it (e.g. which pages are most read; where visitors come from) | Your consent | Off until you accept |
| Functionality | Remember preferences you set (e.g. language) | Your consent | Off until you accept |
| Marketing / advertising | Used to measure the effectiveness of our marketing, or to show you relevant adverts on other websites | Your consent | Off until you accept |
9.2 Specific cookies in use
The specific cookies on our site, their providers, purposes and durations are listed in our cookie consent banner when you first visit the site (you can re-open the banner at any time via the link in the website footer). At the date of this policy:
- We use strictly necessary storage for security and to remember your cookie-consent choices.
- We use marketing / advertising cookies set by Google Ads to measure the effectiveness of our advertising. These are off until you accept — we operate Google Consent Mode so that no advertising cookie is set before you choose.
- We do not currently use third-party analytics or functionality cookies. If we add any in the future, the cookie banner will be updated and we will ask for your consent before they are set.
9.3 How to control cookies
- Via our cookie consent banner. When you first visit our site you will see a banner asking you which categories of cookies you accept. You can change your choices at any time by clicking in the footer.
- Via your browser. Most browsers let you block or delete cookies. Blocking cookies may affect your ability to use parts of our site.
- Via opt-out tools for specific advertising networks (e.g. Your Online Choices — www.youronlinechoices.com).
9.4 Do Not Track and global privacy signals
Where your browser sends a “Do Not Track” header or a Global Privacy Control (GPC) signal, we treat it as a signal to disable non-essential cookies.
10. Marketing communications (PECR)
If you ask us to keep you updated on new property opportunities, we will send you marketing communications by email only with your prior consent (in line with PECR regulation 22). You can withdraw consent at any time by clicking the unsubscribe link in any marketing email or by emailing us.
We do not make unsolicited marketing telephone calls or send unsolicited marketing texts. We do not share your marketing-consent data with third parties.
11. Children's data
Our services are not directed at people under the age of 18 and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Security
We protect your personal data using technical and organisational measures proportionate to the size of our business and the nature of the data — including access controls, secure email, encrypted storage where applicable, and the credential-handling practices set out in our internal AML Policy. We require our data processors to maintain equivalent measures under UK GDPR Article 28.
13. Changes to this policy
We may update this policy from time to time (for example, when our website features change, when we engage new service providers, or when the law changes). The “Effective date” at the top of this policy reflects the date of the most recent update. We will draw material changes to your attention where we hold a contact email for you.
14. How to make a complaint
If you have a concern about how we are handling your personal data, please contact the MLRO using the details in section 1. We will acknowledge within 5 working days and respond substantively within 28 days — see our Complaints Procedure for the full three-stage process.
You also have the right to complain to the Information Commissioner's Office (ICO) at any time, without contacting us first:
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post:Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Complaining to the ICO does not affect any other remedy available to you.
Document version 1.0; effective 2026-05-22. Owner: Money Laundering Reporting Officer (MLRO). This policy is published on the Firm's website and held on file. Retention: as long as the policy is in force; superseded versions retained for 5 years (MLRs reg 40).