Privacy Policy
Zuto Limited and its affiliates (collectively, “Zuto”, “we”, “us” or “our”) take your privacy and the security of your personal data seriously. This privacy policy is meant to help you understand what personal data we collect on you, how we use, share and protect such information and the rights and choices you have with regard to your personal data when you visit our website (www.zuto.com), when you communicate with us, or where you otherwise use our services.
For the purposes of European Union and United Kingdom (“UK”) data protection laws, and depending on how you interact with our services, the responsible entity (i.e., controller) of your personal data will be one of the following entities: Zuto Limited, Zuto Business Services Limited, Zuto Holdings Limited and Zuto Ancillary Services Limited.
If you have any questions or complaints, please contact us at datarequests@zuto.com.
We collect most of the personal data we process directly from you (for example, when you complete an application or contact us). We may collect some personal data from third parties, including price comparison websites, credit reference agencies, and fraud prevention agencies as part of our services.
Directly from you
We collect personal data from you when you provide it to us directly, for example when you:
- enquire about, apply for, and use our products and services;
- talk to us on the phone (we record our calls and we will tell you about this when we speak to you);
- send us an email or letter;
- use our website;
- communicate with us via social media;
- complete a customer survey; and/or
- make an enquiry or complaint.
Third parties making an application on your behalf
Third parties making an application on your behalf. If someone is making an application on your behalf (for example, someone who has a power of attorney), we will receive personal data on you from that person.
Lenders or other third parties you take out products with
If your application results in you borrowing from one of our panel of lenders, and/or taking out any other products, such as warranties, the lender or other provider will share certain information about you with us (including to let us know if you default on your payment obligations).
Credit reference agencies (CRAs)
CRAs hold personal data about individuals’ credit accounts (such as credit cards and loans) and publicly available information (for example, from the electoral roll). When you make an application, we receive information from the CRAs including your financial status and financial history. We also receive information like your address so that we can verify your identity.
If you want to know more about how we exchange data with CRAs, please see the section headed “Credit reference agencies” below
Regulatory bodies
We are regulated by the Financial Conduct Authority, the Financial Ombudsman Service and the Information Commissioner’s Office. If you make a complaint to any of these regulators, or otherwise speak to them about us, we may receive some of your personal data from them to enable us and them to manage your complaint or enquiry.
Each of these regulators has their own privacy notice on their website, which will tell you more about how they use and share personal data.
Price comparison websites
We will use the information you share with price comparison websites; where that data is passed to us for us to share with selected lenders to return a finance quote or eligibility check for you which you can choose whether to proceed with.
Lead generators
We work with lead generation partners who will pass us personal data about potential customers. If you have submitted your details to one of these partners, they will tell you if they are going to share your information with us.
Other third parties
We might also receive personal data from other third parties not mentioned above. This could include law enforcement and government authorities, if they make enquiries about you, or the Court if you are involved in legal proceedings with us.
When you make an application or otherwise engage with us, you voluntarily supply us with some of your personal data. This may include (but is not limited to) your contact information, employment details, financial information, identity information and marketing preferences. We also collect data that you voluntarily provide us with in communications that you have with us, data we collect automatically when you use our website, and data we receive from third parties. Sometimes we might also need to collect sensitive data about you.
Contact information
Contact details that we ask you for, or that you provide to us, including your name (and any previous names), date of birth, address, previous addresses from the last three years, email address and contact telephone number. This also includes any other contact details you may provide when interacting with our website, or when you contact us via email, social media, telephone or letter.
Application details
Information we ask you to provide as part of your application. This will be made clear in our application form, but could include details of your employment (including your employment status and employer), your financial details (including income, outgoings, and existing credit commitments) and information about your identity (including identity confirmation documents such as your passport).
Communications
When you communicate with us, including via email, social media, telephone, letter or when completing customer feedback or complaints, we collect the personal data you provide to us, this will include your name, contact information (such as email, address, telephone number) and the content of the communications.
Events or meetings
If you attend an event or meeting of ours, we may collect your personal data when you attend the event or meeting and exchange your details with us (for example, by providing your business card or contact details on arrival) and we may take photographs with your personal image.
Consent information
Permissions, consents, or preferences that you give us, for example how you want to be contacted and whether you want to receive marketing from us.
Sensitive information
Sometimes, we need to collect personal data that is more sensitive than usual, or you might provide this to us in communications. This could include:
- personal data that is classified as special categories of data, such as information about your health (for example, to assess vulnerability or accessibility); and
- information about criminal convictions or criminal offences you have committed, for example if you have previously been convicted of fraud.
This information will only be collected where there is a valid legal basis and will be handled with a high level of care, as required by law.
Third parties
As described in Section 3 above, we also receive information about you from third parties. This may include your credit information, payment and default information, and information from regulatory bodies or courts in connection with complaints or legal proceedings.
Automated information
We and our service providers may automatically log information about you, your computer or mobile device, and your interactions with our services and our communications, such as:
- the type of browser you use, access times, pages viewed, documents downloaded, your IP address, and the site you visited before navigating to our Services;
- the computer or mobile device you use to access our Services, including the hardware model, operating system and version, unique device identifiers, and mobile network information;
- your browsing actions and patterns; for example, your internet protocol address and other similar identifiers, browsing history, search history, information on your interaction with the website. We collect this personal information by using different technologies, including cookies and web beacons. Please see our cookies policy here.
- your city, state, zip or postal code, to personalise content provided to you, or to show you prices and promotions.
Other information
We may need to collect other information not specifically listed here, which we will use as described in this privacy policy or as otherwise disclosed at the time of collection.
We use your personal data for a variety of purposes described below. We process your personal data for these purposes in reliance on our legitimate business interests, in order to perform our contractual obligations to you or third parties with whom we have a contractual relationship (e.g. lenders or credit reference agencies), with your consent, and/or for compliance with our legal obligations. We indicate the specific processing grounds we rely on next to each purpose listed below.
What we use your personal data for:Application
To perform our contract with you or third parties with whom we have a contractual relationship (e.g. lenders or credit reference agencies), or when it is in our legitimate business interests to do so, we will use your personal data to consider and process your application for our products and/or services, to communicate with you by social media, email, telephone, text (SMS) message or other electronic means to discuss your application or provide you with updates, to share your personal data with our panel of lenders and other partners to generate a finance quotation and process your application or otherwise provide the relevant product or service to you, and to manage our ongoing relationship with you, including notifying you of changes to our services. Where it is in our legitimate interests to do so, which includes ensuring that applications are processed efficiently and accurately and matching customers to appropriate products and/or services, we will also carry out credit checks with CRAs, verify your identity using our KYC ID verification partner, and carry out validation checks to confirm that your details are valid and that the application is being made by a human, in order to reduce the risk of fraudulent applications.
Compliance and protection
We use your personal data to comply with our legal obligations and to defend us against legal claims or disputes where it is in our legitimate business interests to do so, including to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to court orders or requests from regulators and other government authorities;
- audit our internal processes for compliance with legal and contractual requirements and internal policies;
- enforce the terms and conditions that govern our products and services;
- prevent, identify, investigate, and deter fraudulent, harmful, unauthorised, unethical, or illegal activity, including cyberattacks, identity theft and other financial crime;
- protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims).
Improving our services and developing new products and services
Where it is in our legitimate interests to do so, including so that we can provide the best possible service to our customers and to ensure that we design products to meet our customers’ needs and objectives, we will use your personal data to undertake analysis of your credit information to identify and inform you of suitable credit products, to ensure that our content, services, and advertising are tailored to your needs and interests, to provide products and services that meet the needs and requirements of our customers, and to process feedback from customers including through complaints.
We use personal data to help us better understand how people use our services and how we can develop, analyse and improve them where it is in our legitimate interests to do so. This includes monitoring and analysing trends, usage, and activities in connection with our services. As part of these activities, we may create aggregated, de-identified or other anonymous data from personal data we collect. We may use this anonymous data and share it with third parties for our lawful business purposes, including to analyse and improve the services, and promote the services.
Sending marketing communications to you
We may use your personal data to send you marketing communications about our products and services, and those of our Zuto Partners. In certain instances, we may ask you for your explicit consent to market to you, but in other cases we may rely on our legitimate interests in promoting our business and our products and services. In each case you will be given the opportunity to opt-out in each marketing communication. Please see Section 12 for more information on how we use your personal data for marketing purposes.
Call recording
Where it is necessary to comply with the law, and where it is in our legitimate interests to protect and improve our business, train our staff, and ensure that complaints and disputes are dealt with in a timely and appropriate manner, we record calls and use recordings and transcripts to check your instructions to us, to analyse, assess and improve our services, for training and quality purposes, to investigate complaints you make, and as evidence in any dispute between you and us.
Key stroke recording
Where it is in our legitimate interests to improve our services and ensure that customers are able to complete their applications efficiently, we may use key stroke recording technology on our website. This technology records the information you fill in on our application form as you complete it. If you do not proceed to submit your application, we may contact you using the details you provided, to see if you would like to complete it.
Validation checks
Where it is necessary to comply with the law or where it is in our legitimate interests to prevent and detect fraud and protect our business from false applications, we may use a third-party supplier to carry out validation checks before you submit your application, to confirm that your details are valid and that it is a human making the application.
We may need to disclose your personal data to others to ensure we can efficiently provide the products, services, and information you request.
In particular, please note that when you make an application, we will share personal data you submit during the application process with our panel of lenders to process your application and generate a quote. Lenders may contact you directly and may share your personal data with fraud prevention agencies as part of assessing your application.
We also need to share your personal data with some of our suppliers, who act as processors on our behalf.
Our panel of lenders that provide services in connection with your application
We will share personal data to process your application for finance products/services and to generate a finance quotation. Our lenders may carry out additional credit reference searches. They may also share your personal data with fraud prevention agencies to prevent and detect fraud and help them make credit decisions.
As part of your application for credit, some lenders may use Open Banking solutions. If this is the case, your personal data will be shared with the relevant Open Banking provider. This will be made clear in the application process.
Alternative credit providers
If your application is declined by our panel of available lenders, and if you give us consent to do so, we may pass your personal data to another credit provider (such as a lender, broker, or price comparison sites) to allow them to consider your eligibility for alternative finance products. These providers may carry out additional credit reference searches.
Third party suppliers, who process your information on our behalf
We may share your personal data with the following types of third party organisations for the following reasons:
- Online advertising solutions - To allow us to show you relevant content about our finance products/services.
- Customer feedback tools, live chat services and marketing communications software- To ensure we get your feedback to help us improve our service to you, help us speak to each other and contact you more effectively.
- Communication platforms and cloud hosting platforms - To allow us to contact you and securely store your data.
- Social media sites - To show you relevant content about our finance products/services.
- Vehicle valuation tools, car dealerships and our delivery partners - To allow you to value your vehicle as part of the finance process and to facilitate selecting a vehicle as part of your application, including arranging test drives for your selected vehicle and enabling collection by or delivery of the vehicle to you. Our delivery partners may also contact you directly in relation to the delivery of your vehicle, to allow you to track the delivery or provide updates on any delays.
Credit reference agencies (CRAs)
In assessing your application for credit, we share personal data with CRAs to carry out credit checks, verify your identity, and to prevent fraud and money laundering.
Please see the section headed “Credit reference agencies” below for more information.
Know Your Client (KYC) ID verifier
We will share your personal data obtained through our application process with our KYC ID verification partner for the purposes of verifying your identity.
Providers of additional products
We may offer additional products and services, including warranty, either directly or on behalf of our partners, and your personal data may be passed to the providers of these additional products for the purposes of providing you with these products. You can control whether this happens when speaking to your car buying expert. These providers may carry out additional credit reference searches against you.
Please note that we or our warranty provider may contact you directly to discuss renewals of your warranty, if relevant.
Affiliates
We may share your personal data between and among our current and future parents, affiliates, subsidiaries, and other companies under common control and ownership for purposes consistent with this privacy policy.
Third party advertising providers
If you opt into marketing, we may share an encrypted version of your personal data with third party advertising providers (using a process called hashing), to allow us to target our advertising more accurately.
Law enforcement and government agencies
We share personal data with these agencies where we are required to do so by law or where information is required in connection with a crime or investigation.
Regulators
We share personal data where required to comply with our regulatory obligations, including communicating with our regulators and responding to complaints and enquiries from them.
Sale and transfer of business
We may share personal data as part of a proposed or completed corporate transaction, such as a merger, acquisition, reorganisation, financing, asset sale, or similar transaction, or in the event of bankruptcy or related proceedings. Any such disclosure would be subject to appropriate confidentiality protections.
Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with financing or other services). In this case, we may have to cancel such financing or service you have with us, but we will notify you if this is the case at the time.
Your personal data provided in line with the purposes detailed in this privacy policy will mainly be stored on servers based in the UK. Please note that we may transfer your personal data to our service providers in jurisdictions outside the UK, such as the United States and other jurisdictions. Please note that such jurisdictions may not provide the same protections as the data protection laws in your home country.
When we engage in cross-border data transfers, we will ensure that relevant safeguards are in place to afford adequate protection for personal information and we will comply with applicable data protection laws, in particular by relying on an EU Commission or UK government adequacy decision or on contractual protections for the transfer of personal information. For more information about how we transfer personal information internationally, please contact us.
We will only keep your information for as long as we reasonably need it.
In relation to personal data that we use for marketing purposes, we may process this personal data for the duration of your finance agreement plus two years. Alternatively, if you have not taken out a finance product, we may process this personal data for a period of up to three years following your application.
In relation to all other personal data, we will keep this for as long as necessary to manage our relationship with you and to comply with our regulatory and legal obligations.
You have certain rights over your personal data. These include rights to access a copy of your personal data, to ask us to erase your personal data and ask us to correct inaccurate personal data. You can ask to exercise these rights by contacting us at datarequests@zuto.com. There are some circumstances in which we do not need to comply with all or part of your request. If this is the case, we will explain this to you.
The rights you have, and what each of these means, are explained in the table below. If you ask to exercise one of these rights, we may ask you to verify your identity before we process your request. This is to avoid confidentiality breaches and make sure we do not disclose personal data to the wrong person.
Right to access personal data
You can ask us to send you a copy of the personal data we hold about you. We will carry out a reasonable search for personal data and send you the personal data that we locate within one month, or three months if your request is complex. We are allowed to withhold information in some circumstances (for example to protect other individuals’ privacy or in the event of a criminal investigation).
Right to correct inaccurate personal data
You can ask us to correct, clarify or amend your personal data if it is inaccurate, incomplete, or otherwise out of date.
Right of erasure
You can ask us to delete your personal data in certain circumstances, for example if we no longer need it or if we have collected it unlawfully. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Right to restrict use of your personal data
You can ask us to limit how we use your personal data in certain circumstances. For example, if you think your personal data is inaccurate but we disagree, you can ask us to stop using it to make decisions until we can verify if it is accurate or not.
Right to data portability
Where personal data is necessary for a contract, or where we collected it based on your consent, you can ask us to move, copy or transfer it to another provider.
Right to object
Where the use of personal data is necessary for our legitimate interests, you can ask us to stop using it for those purposes. We can continue to use it if we can show that we have a compelling, legitimate reason to do so.
Right to opt out of direct marketing
You can always ask us not to continue to send direct marketing to you. You can do this by clicking on the “unsubscribe” link in marketing emails or contacting us using the details above.
Right to withdraw consent
If we have asked you for your consent to use personal data in a particular way, you can withdraw that consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We use CRAs to help us carry out credit and identity checks when you apply for a product or service with us. This involves us sharing your personal data with CRAs and receiving personal data back from them. We use the personal data they send us to assess our credit risk and make sure what you’ve told us is true.
We share your personal data with CRAs to ask them to provide a credit scoring computation when you make an application. Credit scoring uses several factors to assess risks involved in any application. A score is given to each factor and a total score obtained. Where automatic credit scoring computations are used, acceptance or rejection of your application will not depend only on the results of the credit scoring process.
When we ask CRAs about you, they will note it on your credit file. This is called a credit search. Other organisations (including lenders or providers of goods or services) will see this credit search or previous footprint on any report prepared for their own purposes and prospective relationship with you. The CRAs have created a “Credit Reference Agency Information Notice” or “CRAIN” which includes more details about how the CRAs use and share your personal data, as well as their role as fraud prevention agencies. The CRAINs for each of the three main CRAs are available on their websites, which we have linked below:
- Experian: https://www.experian.co.uk/legal/crain/
- Equifax: https://www.equifax.co.uk/crain/
- Transunion: https://www.transunion.co.uk/legal/privacy-centre/pc-credit-reference
You can also find more information about how the CRAs use personal data, and your data protection rights with the CRAs, here: https://ico.org.uk/for-the-public/credit/
We may send you marketing communications about our products and services, and those of our Zuto Partners. In certain instances, we may ask you for your explicit consent to market to you, but in other cases we may rely on our legitimate interests in promoting our business and our products and services. In each case you will be given the opportunity to opt-out in each marketing communication. You can unsubscribe at any time. You should be aware that if you opt out of marketing, you may continue to receive communications from us about your own products. These are called “service messages” and are not marketing communications.
We may:
- contact you by mail, telephone, email, SMS, or other electronic messaging service with offers of products, services or information that may be of interest to you; and/or
- send you information about goods and services provided by our Zuto Partners (please see below for more information on our Zuto Partners).
Before we send you any marketing communications, we will make sure that either:
- you have given us your consent;
- you have given consent to the company that shared your personal data with us, allowing Zuto to contact you for marketing purposes; or
- if we have collected your information whilst selling, or negotiating to sell, our products or services, we have given you the opportunity to opt out of receiving marketing from us.
Our Zuto Partners include third parties who provide products which may be relevant and helpful for you:
- Insurance comparison providers - This allows you to compare insurance products so you can make an informed decision.
- Vehicle maintenance & roadside assistance providers - This enables you to review complementary products that you may wish to purchase after financing a new vehicle.
- Credit score companies – to help you keep up to date with your credit score and improve it going forward.
- Alternative finance providers – if our main panel of lenders are unable to help you, we may be able to offer you some other alternatives, or present you with other products you may also be interested in.
- Car selling providers – to help you consider your options if you have a vehicle you wish to sell or part exchange.
We do not share your personal data with Zuto Partners, but we may send you information about their products and services if you have consented.
If you do not wish to receive marketing information from us, please DO NOT tick the relevant boxes when submitting your personal data by application, or on one of our sign up forms. Alternatively, please contact us using the details below or simply unsubscribe from any email that is sent to you by Zuto (which will be located at the bottom of the email).
Like most organisations, we use cookies on our website. Please see our cookies policy here
The services are not intended for use by children under 18 years of age. If we learn that we have collected personal data through our services from a child under 18 without the consent of the child’s parent or guardian as required by law, we will delete it as soon as possible.
If you have any questions about this privacy notice or have a concern about how we have handled your personal information, we encourage you to contact us in the first instance so we can try to resolve it for you.
- Email: datarequests@zuto.com
- Telephone number: 01625 619944
- Post: Zuto, Winterton House, Winterton Way, Macclesfield. SK11 0LP.
We aim to acknowledge your complaint within 30 days and will keep you informed throughout the process.
For more details on how we handle complaints, please visit our complaints policy and procedure here.
You also have the right to lodge a complaint directly with the Information Commissioner’s Office (ICO) at www.ico.org.uk at any time.
We reserve the right, at our discretion to change, modify, add, or remove portions of this policy at any time so you are encouraged to review this policy from time to time.
Our services may contain links to websites and other online services operated by third parties. In addition, our content may be included on web pages or online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control third party websites or online services, and we are not responsible for their actions. Other websites and services follow different rules regarding the collection, use and disclosure of your personal data. We encourage you to read the privacy policies of the other websites and online services you use.
The privacy notice was last updated on 19 June 2026.