We at Surrey Power, Richmonds & Groundmech are committed to protecting your privacy and ensuring the personal information you have entrusted to us is processed in accordance with the Data Protection Act 1998 and the Electronic Communications Regulations 2003. These laws are being updated in May 2018 to strengthen your rights and give you control over the personal information that organisations hold about you.
Information We Collect
We collect your personal information in the following ways:
When you give it to us directly
You may provide us with your personal information described in the following ways:
o In person, by email, phone or through the post
o Contacting us through our websites
o Through Social Media
o Signing up to receive our email promotions
o Responding to product promotions
o Making a purchase through our websites
o Applying for a job
When you give it to us indirectly
Your information might be shared with us through independent third party interactions. These third parties will only provide us with your information if you have given your permission for it to be shared with us.
We routinely work with trusted partners and suppliers who work with us on our behalf, such as when you order through our websites and your payment details are handled securely by our Payment Service Provider, Barclays Merchant Services and PayPal.
When you engage with our social media accounts we may also obtain your personal information, such as through Facebook, Twitter, LinkedIn, depending on your settings or the privacy notices of these platforms and messaging services. You can change your settings by referring to their privacy notices for details on how to do this.
When you visit our websites and social media
When you visit our websites, we gather general information about how to use them, as well as information about the type of device you are using to access them (e.g. phone, tablet or PC). This data helps us to create a better online experience for you, to make it easier to find what you are looking for or fix things if they are difficult to use.
When your information is available publicly
To help us tailor the way we communicate with you about our activities and to make communications more relevant to you we may gather publicly available information about you. This area of activity is not something Surrey Power, Richmonds & Groundmech typically does though we may do so in the future. This could be your interests or postcode based demographics, for instance so that we gain a better understanding of you and can help reduce unnecessary communications to you and be more cost-effective in our marketing.
We gather this information from social media platforms such as Facebook, LinkedIn or Twitter. This information is only accessible based on the permissions you give these services and you will be able to change those permissions at any time by reviewing your privacy settings on those platforms.
How we use your Personal Information
We collect relevant personal information depending on the interaction you have with us. Personal information is anything that can be used to identify you as an individual. It can include your name, email address, postal address, telephone numbers, and credit/debit card details. The legal basis for processing your personal information is legitimate interest which means that we have respectfully considered the need to process your personal data and your rights as an individual when carrying out these data processes and we believe our contact with you is linked to legitimate business purposes, which may include some or all of the following:
o To process and fulfil any services, orders or enquiries you place with us through our websites or by telephone
o To keep a record of your relationship with us and for administrative purposes (such as our accounting and consent record-keeping to ensure we know when you prefer not to be contacted)
o Where the processing enables us to enhance, modify, personalise or otherwise improve our services / communications for the benefit of our customers
o To identify and prevent fraud
o To enhance the security of our network and information systems
o To better understand how people interact with our websites and improve their browsing experience by personalising the websites
o To send marketing information to you which we think may be of interest to you by post, email, SMS or other means
o To determine the effectiveness of promotional campaigns and advertising
o To administer employment applications
How we store your Information and Keep It Safe
At Surrey Power, Richmonds & Groundmech we take data protection very seriously. We make it a priority to ensure that we have the right level of controls, interventions and processes in place to ensure we keep your personal information safe. However, the nature of the data transfer – especially online – is never fully secure, so we cannot guarantee the complete security and protection of it when it is outside of our control. Be assured that once we have your personal information, we do all we can to ensure that we have the systems and processes in place to safeguard it including using encryption when needed.
Personal data you provide to us is stored on our secured servers within the EEA and also in the USA. The laws in the USA differ from those countries in the EEA; however, any third party referred to above outside of the EEA has agreed to abide by European levels of data protection in respect of the transfer, processing and storage of any personal data. By providing your data to us, you agree to this transfer and storage.
Only authorised staff have access to your personal information, and only if essential. They are trained to understand the policies, processes and protocols for keeping your information safe.
We have robust internal procedures for storing, protecting and deleting any paperwork relating to our customer orders and contacts.
At times we may share links to other websites and use social media platforms such as Facebook, LinkedIn and Twitter. We are not responsible for these sites – refer to their own privacy policies to learn more.
Credit and Debit Card Payment Information
When you order from us online or over the phone, Surrey Power, Richmonds and Groundmech ensure that this is done securely and in accordance with the Payment Card Industry Data Security Standard (PCI DSS). All credit or debit card details are entered directly to Global Payments, Barclaycard Merchant Services or PayPal, the numbers are not recorded or stored in any of our systems on completion of your transaction. Remember; do not send an email with any credit or debit card details.
If you have any questions about the security of your personal information you can contact us at firstname.lastname@example.org
In the event of a data breach, we shall ensure that our obligations under applicable data protection laws are compiled with where necessary.
How long we keep your data
Surrey Power, Richmonds & Groundmech will only keep your personal information for as long as it is required and in accordance with statutory requirements. For example HMRC requires that we keep a record of your name and address for seven years from the date of your last transaction. When there is a legitimate interest for us as the Data Controller to retain your personal information such as inform or communicate with you as a customer, we shall retain the personal information for this purpose only. Where the information is no longer required, we will ensure that it is disposed of in a secure manner. If you have indicated that you do not wish to hear from us in the future, we will keep the minimum information necessary to ensure we avoid contacting you any further. If we have not heard from you for a period of 5 years, your personal data will be removed from our systems.
Who we share your information with
We reserve the right to use or disclose your personal information if required by law or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process.
Sharing your information with Trusted Third Parties
We may share your personal information with trusted partners and third parties which it is necessary to provide products and services you have requested from us (such as courier services to deliver goods you have ordered) or where they are contracted to develop or maintain our services (such as website providers). We monitor information security compliance and require all partners or third party providers to process your personal information only on our instructions and in accordance with applicable data protection and privacy laws.
How to Access Correct or Delete Your Personal Information
Surrey Power, Richmonds & Groundmech acknowledges that you have the right to access your personal information and we are responsible for correcting, deleting or updating information that we have collected. Upon request Surrey Power, Richmonds & Groundmech will provide you with information about whether we hold any of your personal information. If your contact details change, or you believe the information we hold about you is out of date or inaccurate, please get in touch to update us in the following ways:
Surrey Power, Richmonds & Groundmech
Technology House, Church Road, Shottermill, Haslemere, Surrey, GU27 1NU
We will respond to your request within a reasonable timeframe and notify you of the action we have taken. Actions will be carried out within a month, and the likelihood is it will be much sooner.
Your Marketing Preferences
Email marketing is only sent to you if you have subscribed to our email subscription list. We send email communications to customers infrequently so as not to overwhelm you with emails. You may unsubscribe from our marketing communications at any time by clicking on the ‘unsubscribe’ link located on the bottom of our emails, or by sending us email us at email@example.com.
Postal marketing may be included with any orders you place with us including the latest special offers on products unless you have told us you would prefer not to receive this information by post.
Telephone and SMS marketing – we do not specifically carry out telephone or SMS marketing activities though we may call to update you on an order you have placed with us and if we do we may notify you of relevant offers on our products and services.
Surrey Power, Richmonds & Groundmech is committed to respecting your choice to receive marketing information. You can update your permissions and contact preferences at any time by calling our friendly team on 01428 658487 or email firstname.lastname@example.org.
Changes to this Policy and Contacting Us About this Policy
If you have any questions about this policy or our treatment of the information you provide us, please write to us by mail to Data Protection Officer, Surrey Power, Richmonds & Groundmech, Technology House, Church Road, Shottermill, Haslemere, Surrey, GU27 1NU or contact us by telephone 01428 658487 or email email@example.com
You also have the right to lodge a complaint with the Information Commissioner’s Office about how we manage your data.
You can contact them in the following ways:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wimslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113