Privacy Policy

Last updated: September 2026

1. Introduction and purpose

This Privacy Notice explains how Bolton Business Finance Ltd, trading as Medical Business Finance (“we”, “us”, “our”, “the Broker”), collects, uses, stores, shares and protects your personal data when you engage with us as a client, prospective client, introducer, or visitor to this website.

We are committed to protecting your privacy and handling your personal data in a transparent, fair and lawful manner in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and the Code of Practice and Minimum Standards of the National Association of Commercial Finance Brokers (NACFB).

This Notice forms part of our Terms of Business and is provided to you separately or alongside any Confirmation of Instructions Letter. By providing personal data to us, or by signing our Terms of Business, you acknowledge that you have read and understood this Notice.

Important: Bolton Business Finance Ltd is not authorised or regulated by the Financial Conduct Authority. We provide non-regulated commercial finance broking services only: business loans, invoice finance, asset finance, merchant cash advances, trade finance, commercial mortgages, unregulated bridging loans, property development finance and non-regulated buy-to-let mortgages. We work with an unrestricted number of lenders and act solely as an introducer.

2. Who we are (data controller)

  • Data controller: Bolton Business Finance Ltd, trading as Medical Business Finance
  • Company number: 12495909, registered in England and Wales
  • Registered office: Westgate House, 1 Westgate Avenue, Bolton, Greater Manchester, BL1 4RF
  • ICO registration: ZA712923, verifiable at ico.org.uk
  • NACFB membership: full member. Verifiable at nacfb.org
  • Data protection contact: Marcus Wright, Information Officer
  • Telephone: 0161 546 9128
  • Email: sales@bolton-finance.co.uk

3. We do not collect patient data

This deserves stating plainly at the outset, because we work exclusively with healthcare businesses.

We never require, request or process patient-identifiable information. Assessing a practice for funding needs financial and business information: accounts, contract income, occupancy, prescription volumes, patient list numbers. It does not need anything about individual patients or residents, and we will not accept such data if it is sent to us in error.

If you are preparing documents for a funding application, redact anything patient-identifiable before sending it. If you inadvertently send us information of that kind, tell us and we will delete it and confirm we have done so.

4. What personal data we collect

Identity and contact data. Full name, title, previous names, date of birth, nationality, marital status, dependants; home address (current and previous where less than three years), residential status, email address, telephone numbers; National Insurance number where required for identity verification or credit searches.

Financial and credit data. Employment or self-employment status, job title, income; residential property value, outstanding mortgage, arrears, CCJs, bankruptcy or insolvency history; business turnover, accounts, management figures, bank statements (usually three to six months), existing borrowing, liabilities and assets; details of adverse credit and tax arrears.

Practice and professional data. Professional registration details where relevant to the application, for example GMC, GDC, GPhC, RCVS or HCPC registration; regulatory registration and inspection standing with the CQC, Care Inspectorate, Healthcare Improvement Scotland, Care Inspectorate Wales, Healthcare Inspectorate Wales or the RQIA; partnership structure and share; clinical team composition.

Business and trading data. Company name and number, trading name, start date, VAT registration, trading address, ownership structure, directors and shareholders of 25% or more, PSC information; NHS or HSC contract details; notional rent position; occupancy and fee rates; prescription volumes; patient or client list size; card payment providers and average monthly card sales.

Property and transaction data. Property address, value, purchase price, existing lending, loan amount and term required, property type, rental income and tenants; EPC rating, planned works and development costs, gross development value, source of deposit, exit strategy, portfolio details; security offered, including personal guarantees.

Special category data. We do not routinely collect special category data such as health, racial or ethnic origin, or political opinions. Where such data is genuinely required, for example health information relevant to keyman insurance or capacity, we will process it only with your explicit written consent and for a specific purpose.

Technical and website data. IP address, browser type, device information, cookies and similar technologies; information you provide via website contact and enquiry forms.

5. How we collect your data

  • Directly from you, by telephone, email, fact-find and application forms, website forms, or in meetings
  • From third-party introducers, accountants, solicitors, practice agents or other professional advisers who refer you to us, with your knowledge or consent
  • From publicly available sources such as Companies House, Land Registry, regulator registers and inspection reports, and credit reference agencies via lenders
  • From lenders and ancillary service providers (solicitors, valuers, surveyors) during the application and underwriting process
  • Via cookies and analytics when you visit this website

6. Lawful bases for processing

Under Article 6 of the UK GDPR we rely on the following:

  1. Performance of a contract. Processing necessary to take steps at your request before entering into a contract, and to perform our credit broking services under it.
  2. Legitimate interests. To introduce you to suitable lenders, administer our business, prevent fraud, improve our services, and send relevant commercial communications where we have a soft opt-in or a legitimate interest not overridden by your rights. You may object at any time.
  3. Legal obligation. To comply with anti-money laundering, counter-terrorist financing, fraud prevention, tax and other statutory requirements.
  4. Consent. Where we process special category data, or send electronic marketing where a soft opt-in is not available. You may withdraw consent at any time.

7. How we use your personal data

  • To assess your funding requirements and prepare a lending proposal
  • To source finance offers from an unrestricted panel of lenders and introduce you to them
  • To complete our fact-find, application form, confirmation of instructions letter and commission disclosure
  • To coordinate valuations, legals, insurance and other ancillary services
  • To manage the relationship through to completion, and for aftercare and renewal
  • To comply with our legal and regulatory obligations, including the NACFB Code
  • To prevent and detect fraud, money laundering and other crime
  • To send service-related communications and, where permitted, marketing
  • To maintain records for audit, complaints handling and professional indemnity purposes

8. Who we share your data with

  • Lenders and funders on our panel. Details available on request. Different lenders pay different commission models.
  • Ancillary service providers: solicitors, valuers, surveyors, insurance brokers and accountants engaged in connection with your application
  • Credit reference and fraud prevention agencies, via lenders, for identity verification, credit scoring and fraud prevention
  • Professional advisers and regulators: our accountants, solicitors, professional indemnity insurers, the NACFB, the ICO, HMRC, courts and law enforcement where required by law
  • Introducers, where you were referred to us or we refer you. Commission arrangements are disclosed.
  • Business transfer, in the event of a sale, merger or reorganisation of our business

Service providers who process data for us. We use a small number of technology providers who process personal data on our behalf and on our instructions, under written data processing terms. The main ones are:

  • HubSpot, which provides our customer relationship management system and the enquiry form on this website. Information you submit through the form is stored in HubSpot.
  • Automattic, which hosts this website through WordPress.com and provides related services including Jetpack site statistics and the cookie consent banner.

Transfers outside the UK. Some of these providers are based in, or use infrastructure in, the European Economic Area or the United States. Where personal data is transferred outside the UK, we rely on a lawful transfer mechanism: UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified under it), or the International Data Transfer Addendum to the European Commission’s standard contractual clauses. You can ask us for more information about the safeguards that apply.

We do not sell your personal data.

We approach lenders deliberately and selectively. We do not circulate your details across a wide panel to generate commission.

9. How long we keep your data

  • Client files and application records: duration of the relationship plus six years
  • Enquiry data where no engagement follows: up to 12 to 24 months, or sooner if you object
  • Fraud prevention records: up to six years
  • Website analytics and cookies: as described in section 14 below, usually 12 to 24 months

10. Your rights under UK GDPR

  • Right to be informed: this Notice provides the required information
  • Right of access: a copy of the personal data we hold about you
  • Right to rectification: correction of inaccurate or incomplete data
  • Right to erasure: deletion in certain circumstances
  • Right to restrict processing
  • Right to data portability
  • Right to object: including to direct marketing, which is absolute
  • Rights relating to automated decision-making: we do not make solely automated decisions producing legal or similarly significant effects

To exercise any of these rights, contact Marcus Wright using the details in section 2. We will respond within one month, extendable in complex cases. We may need to verify your identity. There is usually no fee, though we may charge a reasonable fee or refuse unfounded or excessive requests.

11. Marketing

We may contact you about products and services we believe may interest you, including refinance opportunities and portfolio reviews. For existing clients and enquirers we rely on legitimate interests or the soft opt-in under PECR.

You can opt out at any time by clicking unsubscribe in any marketing email, emailing us with “Unsubscribe” in the subject line, or calling us. Service-related communications about your application are not marketing and will continue.

12. Data security

We take appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These include secure IT systems, access controls, encrypted communications where appropriate, and secure storage. We operate a largely paperless office and maintain professional indemnity insurance.

13. Use of artificial intelligence

We use artificial intelligence tools to help with drafting and administrative work, such as preparing website content, correspondence, summaries of documents and first drafts of lending proposals and other paperwork.

  • A person reviews everything. Nothing produced with the help of an AI tool is sent to you or to a lender without being checked by a member of our team.
  • AI makes no decisions about you. Decisions about your enquiry, your application and which lenders to approach are made by people, not by AI.
  • Your data is not used to train AI models. We only use AI tools whose terms do not allow client data to be used to train their models, and we apply the same confidentiality and security standards to them as to our other systems.

If you would prefer that AI tools are not used on your file, tell us and we will respect that.

14. Cookies

This website uses cookies and similar technologies to make the site work, to understand how it is used, and to support our enquiry form. Cookies are set by WordPress.com and Jetpack (Automattic), including for site statistics, and by HubSpot where you use the enquiry form.

When you first visit, a cookie banner lets you accept or decline non-essential cookies. You can also control cookies through your browser settings. Essential cookies required for the site to function cannot be disabled. Most analytics cookies expire within 12 to 24 months.

15. Complaints

If you are unhappy with how we have handled your personal data, contact Marcus Wright in the first instance using the details in section 2.

You also have the right to lodge a complaint with the Information Commissioner’s Office: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone 0303 123 1113. Website ico.org.uk/make-a-complaint.

As a NACFB member we also follow the NACFB complaints and mediation procedures. See our complaints policy.

16. Changes to this notice

We may update this Notice to reflect changes in law, our practices or our services. The latest version will always be available here. Material changes will be notified to existing clients where appropriate.

17. Contact

Marcus Wright, Information Officer and Director, Bolton Business Finance Ltd trading as Medical Business Finance, Westgate House, 1 Westgate Avenue, Bolton, Greater Manchester, BL1 4RF.

Telephone 0161 546 9128. Email sales@bolton-finance.co.uk

This Privacy Notice should be read in conjunction with our Terms of Business and any Confirmation of Instructions Letter.