MarketOffer – Privacy Policy
Last updated: 21 September 2026
1. About this policy
This policy explains how Real Marketplace Ltd, trading as MarketOffer ("we", "our" or "us"), collects and uses personal data, and what rights you have in relation to it. It covers our website, marketoffer.co.uk, and the personal data we handle in the course of our business.
This policy is provided for information. It is not a contract and does not form part of our Web Terms or any agreement between us. Where you are asked to confirm that you have read it, that is an acknowledgement — not consent to processing. We identify the lawful basis for each purpose in section 3.
We are the controller of the personal data described in this policy. Our registered office is The Offices, 53 King Street, Manchester, England, M2 4LQ (company number 14456959), and we are registered with the Information Commissioner's Office under number ZB438983.
How to contact us: email support@marketoffer.co.uk with any question about this policy, to exercise your rights, or to complain about how we handle your personal data.
2. Personal data we process
2.1 Who this policy covers
- Landlords, property owners and developers, including prospective clients we identify before any contact with us
- Letting agents, estate agents, sourcers, introducers and other partners
- Supported living and social housing providers ("accommodation providers"), and the people who act for them
- Contractors, suppliers and consultants
- People connected to any of the above, such as directors, persons with significant control, joint owners and professional advisers
- Job and contractor applicants
- Visitors to our website
2.2 What we process
Depending on your relationship with us, this may include:
- Name, postal address, email address, telephone number, and business or professional profile information — whether you give it to us or we obtain it from the sources in section 2.4;
- Job title, employer, business affiliations and company information;
- Property details, and your role in relation to a property (for example owner, introducer or accommodation provider);
- Bank details and payment information, agreements and related documentation, and partner fee details;
- Identity verification and anti-money-laundering information, including identity documents, proof of address, evidence of ownership or interest, and source of funds or source of wealth information;
- Commercial credit information about accommodation providers and, where it appears in those reports, about their directors and officers;
- Correspondence with us, notes of calls and meetings, and records of what has been discussed or agreed;
- Website and device information — see section 6.
2.3 Special category and criminal offence data
Some of our identity and anti-money-laundering checks involve data that needs additional protection. We carry these checks out through a compliance platform, and the biometric element is performed by a specialist identity verification provider on its behalf.
Biometric data. We will send you a link to complete an identity check. You may be asked to take a photograph of yourself so that it can be compared with your identity document, and to confirm that you are live and present when you do so. Where that comparison is used to identify you, it involves special category biometric data under Article 9 of the UK GDPR. The comparison is carried out only where you give explicit consent as part of the verification process. If you would rather not complete a check involving a photograph, or you withdraw your consent, tell us and we will verify your identity by a suitable non-biometric method instead.
Politically exposed person screening. This identifies whether someone holds, or has held, a prominent public function. That status does not by itself reveal political opinions. A screening result may nevertheless contain or reveal political opinions, and where it does we treat that element as special category data under Article 9.
Criminal offence and related data. Sanctions screening, adverse media checks, enhanced due diligence and fraud screening may return information about alleged or actual criminal offences. This is not special category data, but it is subject to additional conditions under Article 10 of the UK GDPR.
To the extent that the politically exposed person, sanctions, adverse media and fraud screening described above processes special category or criminal offence data, we rely on the substantial public interest condition for the prevention or detection of unlawful acts, in order to meet our anti-money-laundering and sanctions obligations. The underlying identity checks and the records we keep of them are dealt with in section 3.2.
We do not otherwise seek special category data, and you should not send it to us unless we have asked for it.
2.4 Where we get personal data from
- From you directly, through forms, email, calls and meetings;
- From your colleagues, representatives or professional advisers;
- From letting agents, estate agents, sourcers or introducers who put a landlord or property forward;
- From public registers and public sources, including HM Land Registry, Companies House, the FCA Register and publicly available business and professional information;
- From property data platforms, which draw principally on those public registers, and from business contact data providers;
- From credit reference agencies, fraud prevention agencies, identity verification providers and sanctions and politically exposed person watchlists;
- From accommodation providers, about the people who act for them.
We use the sources in paragraphs 4 and 5 to identify who owns a property and who to contact about it, and we may combine information from them to work out the right point of contact. We can tell you which categories of source we used in your case if you ask.
Where we verify your identity through a credit reference agency, this records an identity search on your credit file. It is not a credit application and does not affect your credit score.
Where we obtain your personal data from a source other than you — for example from a commercial credit report, or from an agent who introduces you — we will provide this policy, or a link to it, at the earliest of: when we first contact you; within one month of obtaining the data; or no later than when we first disclose the data to another recipient.
3. Why we process personal data, and our lawful bases
3.1 To enter into or perform a contract with you
Where you are personally a party to a contract with us, or have asked us to take steps before entering into one. This applies, for example, to an individual landlord, a sole trader introducer, or a self-employed contractor.
If you deal with us on behalf of a company or other organisation, you are not personally a party to that contract. We process your personal data in that situation under our legitimate interests (section 3.3).
3.2 To comply with legal obligations
- Customer due diligence, identity verification and record-keeping under the Money Laundering Regulations;
- Sanctions screening;
- Tax, accounting and company law obligations;
- Responding to lawful requests from regulators, courts and law enforcement.
Financial sanctions obligations apply to us regardless of the value of a letting, so we screen against sanctions lists in every case. Where we carry out identity, ownership or screening checks more widely than the money laundering regime requires — for example on a letting below the statutory threshold — we rely on our legitimate interests rather than legal obligation.
3.3 For our legitimate interests
- Administering and keeping records of our business;
- Identifying property owners and the people who act for them, and contacting them about our services;
- Introducing landlords to accommodation providers and progressing potential leases;
- Carrying out point-in-time onboarding and commercial risk checks on accommodation providers, including commercial credit checks, which is what "MarketOffer Checked" status refers to;
- Communicating with individuals who act for organisations we deal with;
- Managing relationships with agents, sourcers, introducers and partners;
- Collecting rent and administering lease-related matters on behalf of landlord clients;
- Coordinating inspections, compliance and contractor attendance where a landlord has asked us to;
- Protecting and asserting legal rights, managing business risk, and obtaining professional advice and insurance;
- Keeping our website and systems secure, and reviewing and improving our services.
Before relying on legitimate interests we consider whether the same result could reasonably be achieved another way, whether the processing might cause you harm, and whether you would expect it. You can object to processing based on legitimate interests — see section 8.
3.4 With your consent
We rely on explicit consent for the biometric processing described in section 2.3, and on consent for optional marketing communications and for non-essential cookies and similar technologies (section 6). You can withdraw consent at any time.
Withdrawing consent will not affect the services we provide to you, or any processing already carried out lawfully. It does not require us to delete the outcome of an identity check, or anti-money-laundering records that we are required or otherwise permitted to keep under a separate lawful basis.
3.5 Whether you have to provide personal data
Some information is necessary for us to enter into or perform a contract, or is required by law — identity and anti-money-laundering information is the main example. If you do not provide it, we may be unable to accept you as a client, act in relation to a property, or continue an engagement. You are not required to use the biometric verification method, however — a suitable non-biometric method is available. Marketing and cookie choices are always optional and have no effect on the service you receive.
4. Keeping personal data secure
We use appropriate technical and organisational measures to protect personal data, and we use or disclose it only as described in this policy or as permitted by law. Access is limited to those who need it. No system can be guaranteed completely secure; where a personal data breach occurs we will notify the Information Commissioner's Office, and you, where the law requires it.
5. Who we share personal data with
We share personal data with the following categories of recipient:
- Accommodation providers, landlords and property owners, where necessary in connection with a proposed or actual lease;
- Agents, sourcers or introducers involved in a particular property or landlord relationship;
- Service providers and other organisations supporting our operations, including rent collection, customer relationship management, identity verification and anti-money-laundering screening, commercial credit reference agencies, electronic signature, cloud hosting and storage, email and communications, software and automated tools including artificial intelligence tools, and IT support;
- Contractors and virtual assistants working under our instructions;
- Professional advisers, including lawyers, accountants and insurers;
- Regulators, redress schemes, law enforcement agencies and courts, where required or permitted by law;
- A purchaser or successor, if we sell or reorganise our business.
We do not sell personal data. If you would like to know the specific providers we use within any of these categories, ask us and we will tell you.
Where we share personal data with a landlord client, each of us acts as an independent controller in respect of our own use of that data. We are not joint controllers, and neither of us acts as the other's processor.
6. Cookies, analytics and website data
Cookies are small files placed on your device by your browser. We group ours as follows:
- Essential — needed for the website to work, and for security. These are set without consent because the site cannot function without them.
- Analytics — help us understand how the website is used, in aggregate.
- Functional — support features such as live chat.
- Marketing and remarketing — allow us to show you our advertising on other websites, and to measure how our advertising performs.
Only essential cookies are set without your consent. Analytics, functional and marketing cookies are set only if you consent through our cookie banner, and you can change or withdraw your choices at any time using our cookie preferences tool. That tool shows what is actually in use, together with the purposes, durations and any third parties involved, and it is the authoritative source for that detail.
Where marketing or remarketing technologies are in use with your consent, the relevant advertising platform may receive information about your visit to our website.
Separately, our servers record requests made by your browser, including your IP address, device type and browser software. We use this for security and to assess in aggregate how the website performs. It is not our policy to use this information to identify you personally.
7. How long we keep personal data
- Customer due diligence and anti-money-laundering records — where the Money Laundering Regulations apply, five years from the end of the business relationship or the completion of an occasional transaction, as those Regulations require, then deleted unless a recognised exception applies. Where we carry out identity, ownership or screening checks outside that statutory regime, we keep those records, as a matter of our own policy rather than because those Regulations require it, for five years from completion of the check or, if a business relationship begins, from the end of that relationship;
- Client, property and transaction records — normally six years from the end of the relationship, reflecting limitation periods and tax record-keeping;
- Unsuccessful job or contractor applications — six months, unless you agree to us keeping your details longer for future opportunities, in which case we will tell you for how long;
- Employees and engaged contractors — relevant records for up to six years after the relationship ends;
- Prospective client and marketing records — business contact details we have identified but not yet engaged with are reviewed periodically and deleted when no longer of interest, and in any event within two years of collection unless a relationship has begun. If you ask us to stop contacting you, or unsubscribe, we keep a minimal record so that we do not contact you again;
- Identity check records — we keep the report we receive, which may include a photograph you submitted, as part of the record described in paragraph 1 above. We do not keep the biometric template created for the comparison; within the verification service it is retained only for as long as necessary to complete the identity comparison and related verification or security checks, after which it is deleted;
- Website and cookie data — for the periods shown in our cookie preferences tool.
We may keep information for longer where we are required to by law, or where it is needed to bring or defend a legal claim. Where we are contractually required to delete or return shared personal data earlier, we will do so unless retention is required by law.
8. Your rights
You have the right to:
- Be informed about how we use your personal data — this policy does that;
- Access the personal data we hold about you, and receive a copy;
- Rectification of personal data that is inaccurate or incomplete;
- Erasure of personal data where there is no good reason for us to continue holding it;
- Restriction of our processing in certain circumstances;
- Object to processing based on our legitimate interests;
- Object to direct marketing at any time — this right is absolute, and we will always stop;
- Data portability, where processing is based on consent or contract and carried out by automated means;
- Withdraw consent at any time, where we rely on it;
- Complain — see section 9.
Most of these rights are not absolute and may not apply in every case; where we cannot do what you have asked, we will explain why. There is normally no charge. We will respond within one month, and will tell you if we need up to a further two months because a request is complex or you have made a number of requests. We may need to verify your identity first, to make sure we do not disclose your data to someone else.
To exercise any right, email support@marketoffer.co.uk.
9. Complaints about how we handle personal data
If you are unhappy with how we have handled your personal data, please tell us — email support@marketoffer.co.uk, though you may raise a complaint with us in any way you choose.
We will acknowledge your complaint within 30 days of receiving it, carry out an investigation that is reasonable and proportionate to what you have raised, keep you informed of progress, and tell you the outcome without undue delay.
You also have the right to complain to the Information Commissioner's Office at any time, at ico.org.uk, or to seek a remedy through the courts. Raising a complaint with us first does not affect that right.
Complaints about our services generally, rather than about personal data, are handled under our Complaints Procedure.
10. Automated processing and automated decision-making
Some of the software we use to carry out the activities described in this policy includes automated features, including artificial intelligence, which assist with tasks such as drafting, summarising, organising information and searching our records. These tools support decisions made by our people; they do not replace them.
We do not make decisions about you using automated means alone where those decisions have legal or similarly significant effects on you.
11. International transfers of personal data
Some of our service providers and contractors are based outside the United Kingdom, including in the Philippines and the United States. This means your personal data may be transferred to and processed in countries that do not have the same data protection laws as the UK.
We only transfer personal data internationally where it is necessary to support our business operations — for example hosting and cloud services, communications and support tools, customer relationship management and analytics platforms, software and automated tools including artificial intelligence tools, and international contractors and virtual assistants.
Where we make a restricted transfer, we rely on one of the following:
- UK adequacy regulations, where the destination country is covered by one;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- for providers in the United States, the UK Extension to the EU–US Data Privacy Framework, where the provider is certified under it;
- another safeguard permitted by UK data protection law.
We apply additional contractual, organisational and technical measures where appropriate. If you would like further information about the safeguards that apply, email support@marketoffer.co.uk.
12. Changes to this policy
We may update this policy from time to time. The version that applies is the one published on this page, and the date at the top shows when it last changed. Where a change is material, we will take reasonable steps to bring it to your attention. Earlier versions are available on request.
13. Establishment and applicable law
We are established in England and we comply with applicable UK data protection law. We engage international suppliers and contractors, and process personal data in connection with those relationships as described in section 11.
Nothing in this policy limits any right you have under data protection law, or your right to complain to the Information Commissioner's Office or to bring proceedings before a court.