Privacy Policy

Downland Estate Limited and its subsidiaries ("Downland", "we", "us", "our")

Effective date: 18 August 2026 Version: 1.0 Last reviewed: 18 August 2026


1. Introduction

Downland Estate Limited and its subsidiaries are committed to protecting the privacy and security of personal data. This policy explains how we collect, use, share, store and protect personal data, and sets out the rights available to individuals under the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 ("DPA 2018") and the Privacy and Electronic Communications Regulations 2003 ("PECR").

This policy applies to personal data we process through our website at downland.com, through our estate, land, hospitality, letting and commercial operations, and through our correspondence and dealings with enquirers, customers, guests, tenants, licensees, suppliers, contractors and job applicants.

Please read this policy alongside any specific privacy notice, booking terms, tenancy documentation or contractor terms we may provide on particular occasions, which supplement (and do not replace) this policy.

2. Who we are and who is responsible for your data

Downland Estate Limited is a company registered in England and Wales (company number 14717254), with its registered office at 16 Beaumont Street, Oxford, England, OX1 2NA.

In this policy, "Downland" means Downland Estate Limited together with its subsidiary undertakings from time to time. The Downland group operates a portfolio of land, estate, property, hospitality and related businesses through separate legal entities. Depending on the nature of your relationship with us:

  • the Downland group company with which you contract or correspond will normally be the controller of your personal data; and
  • Downland Estate Limited acts as the lead entity for group-wide data protection governance, and administers this policy, privacy enquiries and requests on behalf of the group.

If you are unsure which Downland entity holds your personal data, contact us using the details in section 3 and we will confirm.

3. How to contact us

For all data protection enquiries, including requests to exercise your rights, to withdraw consent, or to complain about our handling of personal data:

Email: info@downland.com Post: Data Protection, Downland Estate Limited, 16 Beaumont Street, Oxford, England, OX1 2NA Website: downland.com

We aim to acknowledge privacy enquiries within five working days and to respond substantively within one month, as required by the UK GDPR.

4. The personal data we collect

We collect and process the following categories of personal data. Not all categories will apply to every individual.

4.1 Identity and contact data

Name, title, employer or trading name, job title, postal address, email address, telephone and mobile numbers, and preferred method and language of contact.

4.2 Enquiry and correspondence data

The content of enquiries submitted via our website forms, email, telephone, post or in person; notes of meetings, calls and site visits; and our replies and internal records relating to your enquiry or relationship with us.

4.3 Marketing and communications preferences

Your consents, opt-ins and opt-outs, the topics you have asked to hear about, and records of the communications we have sent you and whether they were delivered or opened.

4.4 Hospitality, booking and visitor data

Where you book accommodation, an event, a venue, a pitch, a tour or another visitor experience with us: booking reference and dates, party details and number of guests, vehicle registration where required for parking or access, arrival and departure information, dietary requirements, accessibility requirements, special requests, feedback and reviews.

4.5 Tenant, licensee and land occupier data

Where you are, apply to be, or occupy under a tenant, licensee, grazing agreement, wayleave, easement, sporting right or other land arrangement: identity and contact data; proof of identity and right to rent where legally required; referencing, affordability and credit information; guarantor details; tenancy or licence documentation; rent, service charge and payment records; arrears and enforcement records; maintenance, repair and inspection records; meter readings and utility data; insurance details; correspondence about the property or land; and records of alleged breaches, disputes, notices and proceedings.

4.6 Supplier, contractor and professional adviser data

Company and individual contact details; trading and registration details; quotations, tenders and contracts; insurance certificates, qualifications, accreditations, competence and health and safety documentation (including risk assessments and method statements); site induction and attendance records; invoices, purchase orders and payment records; and performance and dispute records.

4.7 Recruitment and applicant data

CV and covering letter; employment and education history; qualifications and certifications; references; right to work documentation; interview notes and assessment outcomes; salary expectations; and where relevant to a role, driving licence and relevant criminal-records information where lawfully permitted.

4.8 Financial and transaction data

Bank account details, payment card data (processed by our payment providers, not stored in full by us), billing addresses, invoices, receipts, deposits, payments and refunds.

4.9 Technical and website usage data

IP address, approximate location derived from IP address, browser type and version, device type, operating system, time zone setting, referring URLs, pages viewed, time spent on pages, clicks and other website interaction data, and cookie identifiers. See section 9.

4.10 CCTV and estate security data

Images and footage captured by CCTV cameras at our sites and properties, together with the date, time and camera location. Cameras are used for the security of people and property, the prevention and detection of crime, and health and safety. Signage is displayed at monitored locations. Section 10 sets out further detail.

4.11 Special category and criminal offence data

We do not generally seek special category data. Where we do process it — for example health, dietary or accessibility information you provide for a booking or visit, health information relevant to workplace safety, or safeguarding and vulnerability information relating to an occupier — we do so only where a condition under Article 9 UK GDPR and Schedule 1 DPA 2018 applies, most commonly your explicit consent, the establishment of legal claims, or reasons of substantial public interest. Criminal offence data is processed only where necessary and permitted by Schedule 1 DPA 2018, for example in safeguarding, fraud prevention or specified roles.

4.12 Children's data

Our website and marketing communications are not directed at children. We do not knowingly collect personal data from children under 13 through the website. Where a child's data is provided as part of a hospitality booking or a tenancy, it is provided by, and processed on the basis of the arrangements with, a parent or guardian.

5. How we collect personal data

  • Directly from you — when you complete a website form, subscribe to updates, email or telephone us, meet us, make a booking, apply for a tenancy or licence, tender for or perform work, apply for a role, or otherwise correspond with us.
  • Automatically — through cookies and similar technologies when you use our website, and through CCTV when you visit a monitored site.
  • From third parties and public sources — including letting and estate agents, managing agents, referencing and credit reference agencies, guarantors, previous landlords and employers, recruitment agencies, professional advisers (legal, accountancy, tax, surveying, ecology and planning), booking platforms and payment providers, contractors and subcontractors, HM Land Registry, Companies House, local planning authorities, statutory bodies, and publicly available sources including websites and social media used for professional purposes.

6. Why we use personal data and our lawful bases

We only use personal data where the law allows. The table below sets out our principal purposes and lawful bases. More than one basis may apply to a given activity.

Purpose Data used Lawful basis
Responding to enquiries and providing information you request Identity, contact, enquiry data Legitimate interests (responding to and developing relationships with those who contact us); consent where you have subscribed
Administering bookings, stays, events and visits Identity, contact, booking, financial, health/accessibility where provided Performance of a contract; legitimate interests; consent for special category data
Managing tenancies, licences and land arrangements Identity, contact, tenant/occupier, financial data Performance of a contract; legal obligation; legitimate interests (protecting our property and rental income)
Referencing, affordability, right to rent and identity checks Identity, financial, referencing data Legal obligation; performance of a contract; legitimate interests (assessing suitability and reducing risk)
Procuring and managing suppliers and contractors, including health and safety and site access Supplier, contractor, financial data Performance of a contract; legal obligation; legitimate interests
Recruitment and selection Recruitment and applicant data Legitimate interests (assessing candidates); legal obligation; consent for retention on file
Sending infrequent updates about Downland, our projects, land, properties, hospitality offers and events Identity, contact, preference data Consent; or legitimate interests where you are an existing customer or contact and the communication relates to similar goods or services (the PECR "soft opt-in")
Internal administration, record keeping, management reporting and business planning All categories as relevant Legitimate interests (running our business efficiently)
Sharing data within the Downland group so the right entity can serve you and to avoid duplicated records Identity, contact, relationship data Legitimate interests (efficient group administration and consistent customer service)
Website operation, security, analytics and improvement Technical, usage data Legitimate interests (secure, functional website); consent for non-essential cookies
Security of people and property, and prevention and detection of crime CCTV, visitor, vehicle data Legitimate interests (protecting people, property, land and livestock); legal obligation for health and safety
Accounting, tax, audit, insurance, grant and regulatory compliance, including environmental and land-management schemes Identity, contact, financial, land data Legal obligation; legitimate interests
Establishing, exercising or defending legal claims, and handling complaints, disputes and insurance matters All categories as relevant Legal obligation; legitimate interests; establishment, exercise or defence of legal claims
Corporate transactions, restructuring, financing, refinancing and due diligence All categories as relevant Legitimate interests (managing and financing the group's structure and assets)

Where we rely on legitimate interests, we have carried out a balancing assessment to satisfy ourselves that our interests do not override your rights and freedoms. You may ask us for further information about any such assessment using the contact details in section 3.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7. Marketing communications

We aim to keep marketing communications infrequent, relevant and easy to stop.

  • We will send you updates about Downland and its projects, properties, hospitality and events only where you have asked to hear from us, or where you are an existing customer or contact and the communication relates to similar goods or services and you did not object when your details were collected.
  • Every marketing email contains a clear unsubscribe link. You can also opt out at any time by emailing info@downland.com.
  • We do not sell, rent or trade personal data, and we do not share personal data with third parties for their own marketing purposes.
  • Opting out of marketing does not stop service or transactional messages — for example booking confirmations, tenancy notices, invoices, safety notifications or legally required communications.
  • We keep a suppression record of individuals who have opted out, so that we can honour that preference. This is retained on the basis of our legal obligation to respect objections.

8. Internal use and sharing within the Downland group

Personal data collected by any Downland entity may be shared with, and used by, other companies in the Downland group where there is a legitimate business reason to do so, including:

  • routing an enquiry to the entity best placed to answer it;
  • maintaining a single, accurate group record of a contact, customer, tenant or supplier;
  • shared back-office administration, including finance, payments, procurement, records management, compliance and IT;
  • group-level management reporting, planning and risk management; and
  • ensuring consistent standards of service, health and safety, and legal compliance across the group.

Access within the group is restricted to those personnel and advisers who need it to perform their role. Marketing preferences are applied consistently across the group: if you unsubscribe, we will suppress your details across Downland group marketing, not only for the entity you contacted.

9. Cookies and website analytics

Our website uses cookies and similar technologies.

  • Strictly necessary cookies enable core functionality such as page navigation, security, load balancing and form submission. These are set on the basis of our legitimate interests and cannot be switched off.
  • Analytics and performance cookies help us understand how visitors use downland.com, which pages are of interest and where the site can be improved. These are set only with your consent.
  • Functional and preference cookies remember your settings, such as your cookie choices.

Where consent is required, we obtain it through the cookie banner presented when you first visit the site, and you can change your choices at any time via the cookie settings on the site or by clearing cookies in your browser. Most browsers also allow you to block or delete cookies, though this may affect how the site functions.

Analytics data is generally aggregated and does not identify individuals directly. Where analytics providers act on our behalf, they do so as processors under written terms; where a provider determines its own purposes, we identify it in our cookie information.

10. CCTV and estate security

  • CCTV is operated at certain Downland sites, buildings, yards and access points for the security of people and property, the protection of land, livestock, equipment and crops, the prevention and detection of crime, and health and safety.
  • Clear signage identifies areas subject to CCTV and provides contact details for enquiries.
  • Cameras are positioned to avoid capturing areas where there is a heightened expectation of privacy, so far as reasonably practicable. We do not use CCTV for routine monitoring of employees' performance, and we do not record audio unless a specific and documented need exists.
  • Footage is stored securely with restricted access, is retained normally for 30 days and then automatically overwritten, unless it is required for an ongoing investigation, insurance claim, legal proceedings or a request from law enforcement.
  • Footage may be disclosed to the police, insurers, our legal advisers and other bodies where lawfully required or necessary to protect people or property.
  • You may request access to footage of yourself under section 12. Please provide the date, time and location so we can locate it, and note that images of other individuals may be redacted.

11. Who else we share personal data with

We may share personal data with the following categories of recipient:

  • Service providers and processors — IT, hosting, cloud storage, email and CRM providers, website and analytics providers, payment processors, booking and reservation platforms, marketing email platforms, printing and mailing houses, and document management providers.
  • Professional advisers — solicitors, barristers, accountants, tax advisers, auditors, land agents, surveyors, valuers, architects, ecologists, planning consultants and insurance brokers.
  • Agents and intermediaries — letting, estate and managing agents, and recruitment agencies.
  • Referencing, credit and fraud prevention agencies — where we need to assess a tenancy, licence or credit application, or to prevent fraud.
  • Contractors and suppliers — where necessary to carry out works, repairs, maintenance, deliveries or services, including at a property you occupy or visit.
  • Utility providers, local authorities and statutory bodies — including HM Revenue & Customs, the Environment Agency, Natural England, the Rural Payments Agency, planning and licensing authorities, and grant-funding bodies, where required for compliance, scheme administration or statutory reporting.
  • Insurers, insurance brokers and loss adjusters.
  • Banks, lenders, funders and their advisers, including in connection with financing, refinancing and security.
  • Law enforcement, courts, tribunals and regulators, where we are legally required or permitted to disclose.
  • Prospective buyers, sellers, investors or joint-venture partners and their advisers, in connection with a corporate or property transaction, restructuring or due diligence exercise, normally under confidentiality obligations and, where practicable, using anonymised or redacted information.

We require all processors acting on our behalf to enter into written contracts that meet the requirements of Article 28 UK GDPR, to process personal data only on our instructions, to apply appropriate security measures, and to assist us with data subject requests and breach notification.

12. International transfers

We prefer to keep personal data within the United Kingdom or the European Economic Area. Some of our service providers, particularly cloud, email, CRM and analytics providers, may process personal data outside the UK.

Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place, being one of:

  • a transfer to a country covered by UK adequacy regulations;
  • the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or
  • another mechanism permitted under Chapter V UK GDPR.

You may request details of the safeguards applied to a specific transfer by contacting us at info@downland.com.

13. Data security

We maintain appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These include access controls and role-based permissions, multi-factor authentication, encryption in transit and, where appropriate, at rest, secure and reputable cloud hosting, regular software patching, backup and recovery arrangements, confidentiality obligations for staff and contractors, staff awareness of data protection responsibilities, secure disposal of paper and electronic records, and due diligence on suppliers.

We maintain procedures to deal with any suspected personal data breach and will notify the Information Commissioner's Office and affected individuals where we are legally required to do so.

No transmission of information over the internet can be guaranteed to be completely secure. Please do not send sensitive information to us by unencrypted email; contact us and we will arrange a secure method.

14. How long we keep personal data

We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax, insurance and reporting requirements, and to resolve disputes. Our usual retention periods are:

Record type Usual retention period
Website enquiries that do not lead to a relationship 24 months from last contact
Marketing subscriber records For the duration of the subscription, then 24 months from unsubscribe or last engagement; suppression records kept indefinitely
Hospitality and booking records 6 years from the end of the stay or event, for tax and claims purposes
Tenancy, licence and land agreement records 6 years from the end of the agreement; longer for records relating to land title, rights, easements, wayleaves and covenants, which may be kept permanently
Unsuccessful tenancy or licence applications 12 months from decision
Supplier and contractor records 6 years from the end of the engagement; health and safety and construction records for longer where required
Recruitment records for unsuccessful applicants 12 months from decision, or longer with consent for future opportunities
Accounting, tax and financial records 6 years from the end of the relevant accounting period, plus the current year
CCTV footage 30 days, unless required for an investigation, claim or legal proceedings
Website analytics data Generally up to 26 months in aggregated form
Insurance and legal claim records For the duration of the claim plus the applicable limitation period, normally 6 years, and longer for personal injury or latent-damage matters

Where retention periods differ for a specific relationship, we will tell you in the relevant notice or documentation. At the end of a retention period we securely delete, destroy or anonymise the data.

15. Your rights

Under the UK GDPR you have the right to:

  • be informed about how we use your personal data — the purpose of this policy;
  • access the personal data we hold about you, and receive a copy of it;
  • rectification of inaccurate or incomplete personal data;
  • erasure of your personal data where there is no good reason for us to continue processing it (the "right to be forgotten");
  • restrict processing in certain circumstances, for example while accuracy is being verified;
  • object to processing based on legitimate interests, and an absolute right to object to processing for direct marketing;
  • data portability — to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means;
  • withdraw consent at any time where we rely on consent; and
  • not be subject to solely automated decision-making that has legal or similarly significant effects. We do not currently carry out such decision-making; if that changes, we will update this policy and tell affected individuals.

To exercise any right, email info@downland.com or write to us at the postal address in section 3.

There is normally no charge. We may ask for proof of identity to make sure we do not disclose personal data to the wrong person. We will respond within one month, which may be extended by up to a further two months for complex or numerous requests — we will tell you if that applies. Some rights are qualified and may not apply in every case; if we cannot comply in whole or in part, we will explain why.

16. Complaints

If you are unhappy with how we have handled your personal data, please contact us first at info@downland.com so we can try to resolve matters.

You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 Website: ico.org.uk

Our website may contain links to third party websites, plug-ins and applications. Clicking a link or enabling a connection may allow third parties to collect or share data about you. We do not control those websites and are not responsible for their privacy practices.

18. Providing personal data to us

Where we need personal data to comply with a legal obligation or to perform a contract with you, and you do not provide it, we may not be able to perform the contract, progress your booking, application or tenancy, or engage you as a supplier. We will tell you at the time if this is the case.

19. Changes to this policy

We keep this policy under regular review and will publish any updated version on downland.com with a new effective date. Where changes are material, we will take reasonable steps to notify affected individuals, for example by email or a notice on the website. Please check this page periodically.

20. Governing law

This policy, and any dispute or claim arising out of or in connection with it or its subject matter, is governed by and construed in accordance with the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save that this does not restrict your ability to bring a claim or complaint under applicable data protection law in your country of residence or place of work.


Downland Estate Limited — registered in England and Wales, company number 14717254, registered office 16 Beaumont Street, Oxford, England, OX1 2NA. Contact: info@downland.com · downland.com