C JEV LTD, trading as Bene Finance, is the controller of personal information collected directly through this website. In this notice, references to Bene Finance mean C JEV LTD trading under that name. This notice is effective from 27 August 2026 and should be read with the website terms.
1. Controller and contact
C JEV LTD is registered in England and Wales under company number 16089456. Email enquiries@benefinance.co.uk for privacy questions, rights requests or data-protection complaints, or write to Suite 15a Stone Cross Place, Stone Cross Lane North, Warrington, Lancashire, England, WA3 2SH.
Current direct online lead and named handoff
The current direct online service is only for a UK limited company borrowing wholly for its own business. It is not for LLPs, sole traders, partnerships, individuals, trustees, consumer, personal or mixed-purpose borrowing. For a direct lead, Bene collects the funding amount and purpose, the wholly-commercial-property confirmation where relevant, Companies House number, registered company name, the business contact's name, role, work email, telephone number and preferred contact method. Bene uses this basic information to record and deliver a lead; it does not collect an application or documents, assess creditworthiness or eligibility, compare or recommend finance, negotiate or decide.
The final affirmative button names Asset & General Finance Ltd (SC308532), the only current fixed referral route. It asks permission for that separate controller to receive the basic lead. Bene then sends an email confirmation; a lead is not passed to Asset & General until that confirmation is completed. Asset & General handles any finance discussion, fact find, recommendation and application; its funders decide whether to offer finance. The handoff and delivery can occur only when the service is available.
Asset & General may receive commission from a funder and may share part with C JEV LTD trading as Bene. The amount and calculation vary by funder and product. Asset & General provides further information, including the amount where required or requested, before proceeding. You may withdraw permission before handoff by emailing enquiries@benefinance.co.uk. C JEV LTD keeps the direct-lead, confirmation and delivery audit record for 90 days, unless a live complaint, rights request, legal duty or claim requires a limited longer retention.
2. Technical, confirmation and draft-route information
We process the limited technical, delivery and security information needed to operate the website, confirm control of the submitted email address, prevent misuse and maintain an audit record. This includes confirmation and delivery states, delivery-attempt count, delivery time, the message identifier returned by the email-delivery provider and keyed HMAC comparison values derived from the network address, email address, telephone number and company number. Raw network addresses are not stored in the website database or Bene application logs, and the confirmation token is stored only as a keyed hash.
Campaign labels, placement and landing path may record claimed attribution only; they do not prove that a lead is genuine or that any payment is due. The separately enabled manual-introduction and partner-application routes remain draft and subject to their own published boundaries, approval and release controls. Do not send bank statements, accounts, tax references, identity documents, personal credit information, health information or other special-category personal information through any Bene route.
3. Where the information comes from and what is required
Most information comes directly from the business contact completing the form. The registered company name, number, status and type are checked against the public Companies House register. A direct lead cannot proceed unless an active UK limited company is matched. Limited campaign labels may come from the link used to reach the site and record claimed attribution only.
Fields marked as required are needed to record a basic lead; without them, the form cannot be submitted. After the form is accepted, Bene sends the business contact a confirmation link that expires in 24 hours. The business contact must complete that confirmation before the named Asset & General handoff can occur when the service is available. A failed handoff delivery may be retried from the same stored lead, with no more than three total attempts. Receipt or email confirmation does not verify identity, authority, creditworthiness, eligibility or finance availability.
The separately enabled manual-introduction and partner-application routes remain draft. Their collection, confirmation and access boundaries are described in the applicable portal terms and notices; they do not alter the direct online lead scope.
4. Purposes and lawful bases
The purposes and lawful bases below describe the current direct enquiry and customer-completed broad-link routes. The manual-introduction wording is a draft and that route is not active. The partner application wording is a draft and self-registration is not active.
- Email confirmation and basic scope record: legitimate interests in checking that the business contact submitted the enquiry, confirming an active UK limited-company match and maintaining a proportionate record.
- Security, duplicate prevention and service audit: legitimate interests in protecting the website, its users and C JEV LTD from misuse, and demonstrating whether a submission was confirmed and delivered.
- Claimed affiliate attribution: legitimate interests in recording which approved campaign link led to a submitted enquiry and resolving attribution disputes. Attribution does not determine whether the enquiry is genuine.
- Rights requests, data-protection complaints and legal duties: legal obligation, together with legitimate interests where needed to establish, exercise or defend legal claims.
- Named Asset & General handoff: specific consent requested by the affirmative final button and completed email confirmation before any information is transferred.
- Optional website analytics: consent recorded through the website privacy controls. Analytics remains off unless selected.
- Optional Google Ads click attribution: consent recorded through the separate Advertising measurement control. It is used to remember which Google Ads click led to an enquiry and, only if the approved recipient later confirms that the applicant completed its full finance application, to measure that outcome against the click.
The enquiry form does not currently register anyone for email marketing. If marketing is introduced later, it will use separate, optional consent and a simple unsubscribe route.
5. Who may receive information
Resend acts as C JEV LTD's email-delivery provider for confirmation and delivery messages. Website hosting, security, database and business-email suppliers may also process information for C JEV LTD under their service and data-processing arrangements. Professional advisers, insurers, courts, regulators or public authorities may receive information where reasonably necessary or legally required. When the lookup is used, the company number is sent from the Bene Finance website server to the Companies House Public Data API; contact details and enquiry answers are not sent to Companies House.
For the current direct route, Asset & General Finance Ltd (SC308532) receives the basic lead only after the business contact uses the affirmative final button and completes the Bene email confirmation. Asset & General is a separate controller. It receives the company, contact, amount, purpose and wholly-commercial-property confirmation where relevant, then handles its own finance discussion, fact find, recommendation and application. Bene does not sell personal information or circulate direct-enquiry details to a public or general broker list.
The separately enabled portal and manual-introduction routes remain subject to their own draft boundaries. An approved portal user may see only its own bounded case information, not another partner's cases or finance, lender, rates, reasons, notes or commission information.
6. International processing
Some suppliers may process information outside the United Kingdom. Resend states that its primary processing operations are in the United States and that its data-processing addendum incorporates the UK Addendum for restricted UK transfers. Cloudflare's data-processing addendum also provides UK transfer safeguards where applicable. Google Analytics and Google Ads may process consented measurement information internationally under Google's data-protection terms. C JEV LTD records the providers and safeguards used for each service. You may ask for further information about those safeguards using the contact details above.
7. Retention
An unconfirmed direct enquiry is removed from the website database after seven days and is never sent through the Asset & General handoff. A used confirmation-token hash is cleared when confirmation succeeds. An expired hash is cleared when its expiry is detected or by the daily cleanup; the expired state may remain until the unconfirmed enquiry is removed. A confirmed enquiry and its administrative scope, confirmation and delivery record, including the Companies House profile fields, delivery status and Resend message identifier, are kept for 90 days from submission and then removed by a daily scheduled process. Security-counter HMAC records expire within seven days. A revoked affiliate-code control may be removed after 90 days only when the code has also been removed from the production allowlist. Resend's standard service retains email data for 30 days. After 90 days, Microsoft Exchange moves the delivered mailbox copy into its recoverable deletion state. It may remain recoverable only for Exchange's limited mailbox-recovery period before permanent removal. A specific confirmed record may be kept longer only where a live complaint, rights request, legal obligation or legal claim makes that necessary; any extension is limited and recorded under C JEV LTD's retention schedule.
For the draft manual and partner-application routes, an unconfirmed manual-introduction record is deleted after seven days and a confirmed manual-introduction record is deleted 90 days after confirmation. An unverified partner application expires after 24 hours and a verified application awaiting review expires after 30 days. Approved, rejected or expired application records retain the email HMAC, masked hint, company number and opaque identifiers for no longer than 90 days after the terminal decision, except while a user, credential, token, session, challenge or referral-case dependency still requires the linked record. The terminal application and its internal review-delivery record are then deleted together in dependency order. Used or expired authentication tokens are deleted within seven days after use or expiry. Password verification and recovery challenges, together with their temporary encrypted email-delivery copies, are deleted within seven days after the challenge expires, is used or is revoked. Revoked or expired sessions are deleted within 30 days. A revoked password verifier and the revoked-user HMAC, masked email hint and display name are deleted after 90 days when no token, session, challenge, live application or case dependency remains. Bounded partner audit records are deleted after 12 months. Aggregate counts remain non-identifying. These periods must be reviewed before activation.
Google Analytics user-level and event-level data is set to its shortest available retention period of two months, without resetting that period when a user returns. Analytics cookies are limited to 60 days and are not refreshed on later page views. This setting does not control aggregated reporting data.
8. Security
Measures include encrypted transport, server-side validation, Cloudflare Turnstile security checks, mandatory email confirmation, keyed HMAC comparison values, private rate limits, a fixed named delivery route, restricted delivery settings and scheduled database deletion. Access is limited to people who need it for the stated purposes. No internet service can promise absolute security, which is why the initial form deliberately avoids requesting sensitive financial or identity documents.
9. Cookies, local storage and measurement
The site stores a small privacy-choice record called bene-tracking-consent in the browser's local storage so it can remember the separate Analytics and Advertising measurement choices. The choice expires after six months and is then requested again. Either choice can be changed or withdrawn using Privacy settings in the footer. Rejecting optional cookies sets both categories to off.
The Google tag and optional storage remain blocked until at least one category is selected. Analytics events, page views and analytics storage remain blocked unless Analytics is selected. Advertising storage remains blocked unless Advertising measurement is selected. Google's ad_user_data consent signal is granted only while Advertising measurement is selected; it is denied when that choice is off, unknown, expired or withdrawn. Advertising personalisation remains denied for every choice.
The private portal uses one essential 12-hour partner session cookie named __Host-bene_partner_session. It is Secure, HttpOnly, SameSite Strict, limited to the site root and has no Domain attribute. It authenticates the named portal user; it is not advertising or analytics. Optional analytics and browser affiliate-attribution carry are suppressed on portal, authentication and referral-confirmation routes.
Only after analytics consent, the browser may store bene-seo-landing-context-v1 in session storage. It remembers one fixed SEO content category and its fixed query-free landing path in the current tab until the tab closes or analytics consent is rejected or becomes invalid. The only eligible paths are /dorset, /finance/commercial-mortgages, /tools/commercial-mortgage-calculator, /blog/preparing-to-buy-commercial-property, /blog/commercial-mortgage-deposit-guide and /blog/commercial-mortgage-valuation-guide.
Queries, referrers, UTM, campaign, source or affiliate labels, form answers and lead data are never stored in that record. The record is limited landing context, not source or campaign attribution, and it cannot accept an arbitrary path or extra field.
If accepted, Google Analytics records the current query-free page path and title and limited interaction events for calculator use, enquiry-route clicks, form-step progress, submission attempts or errors, and email-confirmation requests. It is not sent web-address query details, form answers, contact details, company details, funding amounts or funding purposes. Google states that IP addresses from UK and EU traffic are used for location information and discarded before being logged.
If Advertising measurement is selected, the consent-controlled Google Ads tag AW-18409650335 can collect the page URL and title, browser, device, network and ad-click information and can set or read advertising measurement cookies. A new non-duplicate enquiry accepted by the website sends one fixed Submit lead form conversion with a value of £1. This is measurement of the Bene enquiry only; it is not a confirmed handoff, completed finance application, approval, funding decision or fee trigger. We do not send form answers, contact details, company details or finance details through the website tag. The website explicitly supplies an empty user_data value before configuring the Ads destination and does not provide user data for Enhanced Conversions. Advertising personalisation remains off.
Google Ads click attribution may also retain one validated gclid, gbraid or wbraid click identifier with the consent version, query-free landing path and relevant timestamps. Its purpose is to connect a consented ad click to the later provider-confirmed completed-application outcome; an initial enquiry, email confirmation or lead handoff is not that outcome. Withdrawing the choice stops future processing and queued transmission, clears the retained click attribution and clears the browser record. It cannot retract a conversion already imported to Google before withdrawal.
The separate completed-application import sends only the ad click identifier, completed-application time, fixed conversion action and an opaque order ID. Google never receives the applicant's name, email address, telephone number, address, company details, application answers or finance details from this import.
Approved campaign links may carry limited referral labels in the web address. The fixed landing-context record does not copy or infer those labels, and no new SEO source or campaign attribution is inferred from the record. The neutral enquiry_confirmation_requested browser event records only a confirmation request for a non-duplicate submission. It is not evidence that the enquiry was confirmed, delivered to Asset & General, approved or funded. Private delivery evidence remains separate and authoritative.
Cloudflare Turnstile is used on the enquiry form and private portal to distinguish genuine users from automated abuse. It processes browser, device, network and interaction signals. The challenge token and, where available, the network address are validated through Cloudflare's Siteverify service. This security processing takes place independently of the optional analytics choice.
10. Administrative controls and automated decisions
Bene may check that a direct lead fits the stated online scope and has no unresolved duplicate, security or abuse concern. These are administrative controls only. Bene does not assess creditworthiness, eligibility or finance suitability, create a finance score, make a recommendation or decision, or make a decision with legal or similarly significant effect based solely on automated processing. Affiliate-code administration does not change that boundary.
The website does not calculate an affiliate payment, create a balance or invoice, collect bank details, initiate a transfer, notify a payment provider or record an enquiry as paid. Any permitted referral payment is handled separately outside the website under an approved commercial process.
11. Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction or transfer of your personal information. You have the right to object to processing based on legitimate interests and an absolute right to object to direct marketing. Where consent is used, you can withdraw it at any time as easily as it was given; withdrawal does not affect processing that was lawful beforehand.
Email enquiries@benefinance.co.uk or write to the registered office. We may need proportionate information to confirm identity before completing a request.
12. Data-protection complaints
Email enquiries@benefinance.co.uk with the subject “Data protection complaint”, or write to the registered office. C JEV LTD will acknowledge and investigate the complaint without undue delay and within applicable legal timescales, keep you informed where the investigation takes time and explain the outcome when the review is complete.
If you remain unhappy, you can complain to the Information Commissioner's Office.
13. Updates
This notice was last reviewed on 15 September 2026 for the current website processing. The manual-introduction wording and partner application wording above are drafts prepared on 26 August 2026. They are not active processing routes, legal approval or authority to activate either route. Each will be replaced with a reviewed effective version before its route can be enabled. The notice will also be reviewed before accepting any sole-trader personal data and before any material change to a recipient, supplier, purpose, lawful basis, retention schedule, international transfer, measurement setup or marketing activity. Material changes will be explained before the new processing begins.