The Company (sometimes referred to as “We”) takes the security and privacy of your data seriously. We need to gather and use information or ‘data’ about you as part of our business and to manage our relationship with you. We intend to comply with our legal obligations under the Data Protection Act 2018 (the ‘2018 Act’) and the EU General Data Protection Regulation (‘GDPR’) in respect of data privacy and security. We have a duty to notify you of the information contained in this policy.
This policy applies to clients or prospective clients. If you fall into one of these categories then you are a ‘data subject’ for the purposes of this policy.
The Company has measures in place to protect the security of your data in accordance with our Data Security Policy. A copy of this can be obtained from Susan Brown, the Data Protection Officer.
The Company will hold data in accordance with our Data Retention Policy. A copy of this can be obtained from Susan Brown. We will only hold data for as long as necessary for the purposes for which we collected it.
The Company is a ‘data controller’ for the purposes of your personal data. This means that we determine the purpose and means of processing your personal data.
This policy explains how the Company will hold and process your information. It explains your rights as a data subject and your obligations when obtaining, handling, processing or storing personal data in the course of working for, or on behalf of, the Company.
This policy is intended to be fully compliant with the 2018 Act and GDPR. If any conflict arises between those laws and this policy, the Company intends to comply with the 2018 Act and GDPR.