Our legal basis for using your personal data
Our use of your personal data as outlined above is subject to different legal bases for processing, including where necessary for:
- the purposes of the performance of any contract we enter into with you or to take steps at your request prior to entering into a contract with you;
- our legitimate interests, for example in providing our services to an entity you work for, managing and monitoring our website operation, preventing fraud and for our business compliance purposes; and
- compliance with our legal and regulatory responsibilities.
If you do not agree to provide your personal data to us we may not be able to provide you with our services or process your application for employment. Where our use of your data is not necessary for one of the purposes outlined above we may use it in a particular way with your consent. Where we ask for your consent you are free to refuse our use of your personal data for those purposes and you may withdraw your consent at any time by contacting us using the details set out below. This shall not affect the lawfulness of any processing that was based on your consent before you withdrew it
Storage and transfer of your personal data
The personal information that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (EEA). It may also be processed by staff operating outside the EEA who work for us or one of our suppliers or in circumstances where you have requested us to provide a product or service with international considerations and/or parties related to your request are located overseas. Before we transfer your personal data outside the EEA we will take all steps reasonably necessary to ensure that any such transfer is made securely and that there is adequate protection in place in order to protect your personal data, as required by the Act and Chapter V of the GDPR. Please contact us if you wish to obtain more information regarding relevant safeguards. By submitting your personal information you agree to this transfer, storing or processing outside the EEA.
Retention of your personal data
We will retain your personal information for a minimum of six years and so long as is reasonably necessary for the purpose for which it was obtained and in accordance with our legal obligations and follow our data destruction policy and processes thereafter. Your personal data may be retained by use for more than six years for the purposes of satisfying any legal, accounting or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Your personal information is protected under data protection law and you have a number of rights (see below) which you can seek to exercise. Please contact us in writing or by email using the details shown under ‘Contact’ below if you wish to do so, or if you have any queries in relation to your rights. Please note these rights do not apply in all circumstances.
Right of access – subject to certain exceptions, you have the right of access to your personal data that we hold (commonly known as a “data subject access request”).
Right to rectify your personal information – if you discover that the information we hold about you is inaccurate or incomplete, you have the right to have this information rectified (i.e. corrected).
Right to be forgotten – you may ask us to delete information we hold about you in certain circumstances. This right is not absolute and it may not be possible for us to delete the information we hold about you, for example, if we have an ongoing contractual relationship or are required to retain information to comply with our legal obligations.
Right to restriction of processing – in some cases you may have the right to have the processing of your personal information restricted. For example, where you contest the accuracy of your personal information, its use may be restricted until the accuracy is verified.
Right to object to processing – you may object to the processing of your personal information (including profiling) when it is based upon our legitimate interests. You may also object to the processing of your personal information for the purposes of direct marketing and for the purposes of statistical analysis. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
Right to data portability – you have the right to receive, move, copy or transfer your personal information to another controller when we are processing your personal information based on consent or on a contract and the processing is carried out by automated means.
Right to withdraw consent – you have the right to withdraw your consent where we are relying on consent to process your personal data. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.