How we gather personal data
By individuals filling in forms (either electronically or in paper format) or by corresponding with us by telephone, e-mail, in person or otherwise.
The purpose(s) of processing personal data
We use personal data for the following purposes:
- To maintain our accounts and records
- To inform individuals of news, events or activities
- To process & facilitate Members’ orders
Personal data held, where it came from and our lawful basis for processing
|SECTION||Personal data you might supply to us||How and why we process your personal data|
|MEMBER DATA –
|May include your name, trading title, address, e-mail address, telephone number, mobile number & financial information.
|We will process the data to maintain your account with us, to provide our services to you and to communicate with you.The reason we process the data is to ensure the proper administration of your account and our business and allow us as agent to process orders on your behalf, process invoices & credit notes, produce statements and collect funds.|
|SUPPLIER DATA –
|May include your name, business name, address, e-mail address, telephone number, mobile number & financial information.||We will process the data to maintain your account with us, to provide services to you and to communicate with you. The reason we process the data is to ensure the proper administration of your account and our business and allow us as agent to process orders, invoices & credit notes and pay funds.|
|Where you have subscribed to receive newsletters/emails we will process your data so that we can send such newsletters and email notifications to you. If you would prefer not to receive such communications, please contact firstname.lastname@example.org.||The legal basis for us processing this data is that you have consented to such processing.|
|COMMUNICATION DATA||If you communicate with us, we may process the information contained in your communication. This information may include your name and contact information, the content of your communication and any metadata our website generates where you communicate with us using the contact form available on our website.||We will process that information so we can correspond with you and keep records of such correspondence. The reason we are processing this data is to ensure the proper administration of our business (our legitimate interest).|
|REGULATORY DATA||We may process your data if we need to do so in order to comply with our legal and/or regulatory obligations, so that we can protect the vital interests of you/ another natural person||The reason we process such data is to protect the vital interests of you or another natural person.|
Sharing your personal data
Your personal data will be treated as strictly confidential and will be shared only with:
- In the case of Members – Group suppliers
- In the case of suppliers – Group Members
Or if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce any legal agreement we have with you; or to protect our rights or property, or the safety of us, our Members, or others. This may include exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
Where do we store your personal data
All information you provide to us is stored on our secure server/s. Unfortunately the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, and we will maintain appropriate technical and organisation measures to protect your personal data, we cannot guarantee the security of your data.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition we limit access to your personal data to those employees, agents and suppliers who have a business need to know. They will only process your personal data at our instruction and they are a subject to a duty of confidentiality.
We will notify and report any suspected personal data breach to you/the applicable regulator where we are legally required to do so.
Storage and deletion of personal data
- Any personal data that we process will be deleted from our systems once we have completed the purpose for which we were processing the personal data. In some cases, the purpose for which we are processing your personal data will last for a considerable period (for example, if you are a long-standing Member or supplier, we will need to store your data until our relationship with you comes to an end).
- We will determine the period for which we need to retain your data, acting reasonably, and taking into consideration a number of factors such as your relationship with us, your engagement with us, and the fulfilment of any outstanding orders.
- We may need to retain your personal data where this is necessary to comply with our legal or regulatory obligations, or to protect the vital interest of another natural person.
Your rights and your personal data
Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data:
- The right to request a copy of the personal data which we hold about you;
- The right to request that we correct any personal data if it is found to be inaccurate or out of date;
- The right to request your personal data is erased where it is no longer necessary to retain such data;
- The right to request that we provide you with your personal data and where possible, to transmit that data directly to another data controller, (known as the right to data portability), (where applicable i.e. where the processing is based on consent or is necessary for the performance of a contract with the data subject and where the data controller processes the data by automated means);
- The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;
- The right to object to the processing of personal data, (where applicable i.e. where processing is based on legitimate interests (or the performance of a task in the public interest/exercise of official authority); direct marketing and processing for the purposes of scientific/historical research and statistics).
Transfer of Data Abroad
We do not transfer personal data outside the EEA.
How to make a complaint
To exercise all relevant rights, queries or complaints please in the first instance contact our data representative, John Norton on 01865 390011.
If this does not resolve your complaint to your satisfaction, you have the right to lodge a complaint with the Information Commissioners Office on 03031231113 or via email https://ico.org.uk/global/contact-us/email/ or at the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, England.