- Purpose and Scope of this Privacy Policy
- Uniplumo collect, use, share and hold certain Personal Data about current, past and prospective, consumers, customers, suppliers, business contacts, employees and other people in course of its business activities. Personal Data must be Processed in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679) and other applicable national and European privacy legislation and regulations (together the “Data Protection Law”).
- The Company recognises the need to treat Personal Data in an appropriate and lawful manner and is committed to complying with its obligations in this regard. This Privacy Policy explains how the Company use Personal Data.
- This Privacy Policy applies to all entities within the Uniplumo Group and all individuals who work for, with or on behalf of any Uniplumo business.
- The Company use the words Personal Data to describe information that about an individual, and from which they are identifiable. Other key data protection terms are defined in Schedule 1.
- This Privacy Policy describes how the Company use Personal Data that the Company collect as part of its business activities. This includes Personal Data obtained from a variety of sources, including:
- telephone calls, emails and other communications;
- service providers and other third parties;
- the Uniplumo website (the “Site”); and
- social media applications.
- In this Privacy Policy, the Company refer to the Site and social media applications collectively as “Online Tools”.
- Personal Data may be provided to the Company by the individual directly or by a third party.
- This Privacy Policy may be supplemented by other privacy notices tailored to the Company’s specific relationships with the individual.
- Personal Data the Company Process
- The Personal Data the Company hold about employees and other individuals may differ depending on the relationship, including the type of communications between the Company and the individual and the services the Company provides.
- The Personal Data the Company collect generally falls within one of three categories – Personal Data about
- Employees;
- Business Contacts;
- Customers.
- The Company endeavours to keep the Personal Data it Processes accurate and up to date. Furthermore Personal Data is stored in as few places, with as few copies, as is reasonably possible. The Company’s relevant staff are trained to not create any unnecessary additional copies of Personal Data.
- Personal Data the Company may hold and process is further described in Schedule 2.
- How the Company use Personal Data
- The Company use Personal Data to carry out its business activities. The purposes for which the Company use an individual’s Personal Data may differ based on the relationship, including the type of communications between the Company and the individual and the services the Company provides.
- The main purposes include using Personal Data to:
- facilitate general business purposes, including payroll activities, HR records, performance management, making business travel arrangements;
- facilitate communication with an employee and their nominated contacts in an emergency and protecting the health and safety of staff and others;
- provide products and services;
- communicate with employees and other individuals;
- improve the quality of products and services, provide training and maintain information security (for example, for this purpose the Company may record or monitor phone calls);
- carry out research and analysis, including analysis of the Company’s customer base and other individuals whose Personal Data the Company collect;
- provide marketing information in accordance with preferences the individual have told the Company about (marketing information may be about products and services offered by third party partners subject to the individual’s preferences);
- personalise the individual’s experience when using Online Tools or visit third party websites by presenting information and advertisements tailored to the individual, and facilitate sharing on social media;
- manage the Company’s business operations and IT infrastructure, in line with its internal policies and procedures, including those relating to finance and accounting, billing and collections, IT systems operation, data and the website hosting, data analytics, business continuity, records management, document and print management, and auditing;
- manage complaints, feedback and queries, and handle requests for data access or correction, or the exercise of other rights relating to Personal Data;
- comply with applicable laws and regulatory obligations (including laws and regulations outside the individual’s country of residence), for example, laws and regulations relating to anti-money laundering, sanctions and anti-terrorism; comply with legal process and court orders; and respond to requests from public and government authorities (including those outside the individual’s country of residence); and
- establish and defend legal rights to protect the Company’s business operations, and those of its business partners.
- Automated decisions using Personal Data
- The Company may use automated decision making tools (i.e. where a person is not involved in the decision). The Company typically use these tools when making straightforward decisions about an individual. Where this is the case the Company may provide the individual with more information at the time to aid in understanding of what is involved.
- Responsibility for Personal Data
- The Company is responsible for looking after Personal Data in accordance with this Privacy Policy, internal standards and procedures, and the requirements of data protection law.
- When the Company provide Personal Data to third parties, the third parties will be selected carefully and required to use appropriate measures to protect the confidentiality and security of the Personal Data. In such circumstances, the Company will disclose requested Personal Data to the extent permitted by, and in accordance with, applicable Data Protection Law. Those third parties will assume certain responsibilities under data protection law for looking after the Personal Data that they receive from the Company.
- Sharing of Personal Data
- In connection with the purposes described above, the Company may need to share Personal Data with third parties (this may involve third parties disclosing Personal Data to the Company and the Company disclosing Personal Data to them).
- The types of third parties with which the Company may share Personal Data are further described in Schedule 4.
- In certain circumstances, Data Protection Law allows Personal Data to be disclosed to law enforcement agencies without the consent of the Data Subject. In such circumstances, the Company will disclose requested Personal Data to the extent permitted by, and in accordance with, applicable Data Protection Law. Prior to any such disclosure of Personal Data the Company will ensure the request is legitimate and in accordance with Data Protection Law, seeking assistance from Group Legal Counsel where necessary.
- International Transfers of Personal Data
- For the purposes set out in this Privacy Policy the Company may transfer Personal Data to parties located in other countries (including the USA and other countries that have data protection regimes which are different to those in the country where the individual is based, including countries which have not been found by the European Commission to provide adequate protection for Personal Data).
- The Company may transfer information internationally to its service providers, business partners, and government or public authorities.
- When making these transfers, the Company will take steps to ensure that the Personal Data is adequately protected and transferred in accordance with the requirements of Data Protection Law.
- This may involve the use of data transfer agreements in the form approved by the European Commission or another mechanism recognised by data protection law as ensuring an adequate level of protection for Personal Data transferred outside the EEA (for example, the standard contractual clauses).
- For further information about these transfers and to request details of the safeguards in place, please contact the Company using the details in Schedule 8.
- Security of Personal Data
- The Company uses appropriate technical, physical, legal and organisational measures, which comply with data protection laws to keep Personal Data secure.
- As most of the Personal Data the Company holds is stored electronically the Company has implemented appropriate IT security measures to ensure this Personal Data is kept secure. For example, the Company may use anti-virus protection systems, firewalls, and data encryption technologies. The Company have procedures in place at their premises to keep any hard copy records physically secure. The Company also train its staff regularly on data protection and information security.
- When the Company provides Personal Data to a third party (including its service providers) or engages a third party to collect Personal Data on its behalf, the third party will be selected carefully and required to use appropriate security measures to protect the confidentiality and security of Personal Data. For example Personal Data is encrypted / password protected where appropriate.
- Unfortunately, no data transmission over the Internet or electronic data storage system can be guaranteed to be 100% secure. If an individual has reason to believe that their interaction with the Company is no longer secure (for example, if they feel that the security of any Personal Data sent to the Company has been compromised), they should immediately notify the Company.
- The manner in which Personal Data is kept secure is further described in the Company’s security policy, a copy of which can be obtained from the contact details in Schedule 8.
- Legal Justifications for Processing of Personal Data
- To comply with Data Protection Law, the Company need to describe the legal justification it relies on for using Personal Data for its purposes.
- While the law provides several legal justifications, the table in Schedule 5 describes the main legal justifications that apply to the purposes for using Personal Data.
- In order to obtain Personal Data from an individual to comply with applicable legal requirements, and certain Personal Data may be needed to enable the Company to fulfil the terms of its contract with an individual, or in preparation of entering into a contract with an individual. The Company may inform the individual of this at the time that the Company obtain the Personal Data. In these circumstances, if the individual does not provide the relevant Personal Data to the Company, the Company may not be able to provide its products or services to the individual. To obtain more information, please contact the Company using the details set out in Schedule 8.
- Where the Company rely on its legitimate business interests or the legitimate interests of a third party to justify the purposes for using Personal Data, its legitimate interests are:
- pursuit of its commercial activities and objectives, or those of a third party (for example, by carrying out direct marketing);
- compliance with applicable legal and regulatory obligations, and any guidelines, standards and codes of conduct (for example, by carrying out background checks or otherwise preventing, detecting or investigating fraud or money laundering);
- improvement and development of business operations and service offering, or those of a third party;
- protection of the business, shareholders, employees and customers, or those of a third party (for example, ensuring IT network and information security, enforcing claims, including debt collection); and
- analysing competition in the market for the Company’s services (for example, by carrying out research, including market research).
- The Company may need to collect, use and disclose Personal Data in connection with matters of important public interest, for instance when complying with its obligations under anti-money laundering and terrorist financing laws and regulations, and other laws and regulations aimed at preventing financial crime. In these cases, the legal justification for the use of Personal Data is that the use is necessary for matters of public interest. Additional justifications may also apply depending on the circumstances.
- For Processing of more Sensitive Personal Data the Company will rely on either:
- consent; or
- that use of Sensitive Personal Data is necessary for the establishment, exercise or defence of legal claims, or whenever courts are acting in their judicial capacity (for example, when a court issues a court order requiring the Processing of Personal Data).
- Processing of Personal Data relating to criminal convictions and offences is subject to the requirements of applicable law.
- Monitoring
- The Company may record telephone calls with employees so that the Company can:
- improve the standard of service that the Company provide by providing employees with feedback and training, where applicable;
- address queries, concerns or complaints;
- prevent, detect and investigate crime, including fraud and money laundering, and analyse and manage other commercial risks; and
- comply with the Company’s legal and regulatory obligations.
- In addition, the Company monitor electronic communications between the Company and employees (for example, emails) to protect the employees, the business and IT infrastructure, and third parties including by:
- identifying and dealing with inappropriate communications; and
- looking for and removing any viruses, or other malware, and resolving any other information security issues.
- The use of CCTV involves Processing of Personal Data.
- The Company may record telephone calls with employees so that the Company can:
- Retention of Personal Data
- The Company will keep Personal Data for as long as is necessary for the purposes for which the Company collects it. This mean the Company will retain Personal Data for so long as the Company has a relationship with the individual to whom the Personal Data relates. Once this relationship comes to an end the Company will retain such Personal Data for a period of time that allows it to: (a) comply with legal record retention requirements; (b) defend or bring legal claims; (c) maintain records for business analyses and audit; and (d) address complaints and other issues regarding its business.
- Where the Company holds Personal Data to comply with a legal or regulatory obligation, the Company will keep the information for at least as long as is required to comply with that obligation. In some cases a retention period will apply once the initial purpose has ceased e.g. payroll files are required to be kept for current year plus 6 years.
- Where the Company holds Personal Data in order to provide a product or service, the Company will keep the information for at least as long as the Company provides the product or service, and for a number of years thereafter. The number of years varies depending on the nature of the product or service provided.
- The Company endeavours to ensure that Personal Data will only be kept which is relevant and not excessive to achieve the purposes for which it is being held. Personal Data will be deleted once that purpose is achieved or it is no longer required as set out
- For further information about the period of time for which the Company retains Personal Data, please contact the Company using the details in Schedule 8.
- Personal Data Rights
- Schedule 7 sets out a summary of the data protection rights available to individuals in the EEA in connection with their Personal Data. These rights may only apply in certain circumstances and are subject to certain legal exemptions.
- To exercise any of these rights, please contact the Company using the details set out in Schedule 8.
- Who to contact about Personal Data
- For any questions or concerns about the way the Company uses Personal Data, please contact the Company at the email address in Schedule 8.
- Review and Revision
- The Company review this Privacy Policy regularly and reserve the right to make changes at any time to take account of changes in the business, legal requirements, and the manner in which the Company process Personal Data. This Privacy Policy was last updated on the date indicated on page 1. The Company may review this policy and make changes from time to time.
- SCHEDULE 1 – Definition of key data protection terms
- “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
- “Data Controller” means the entity that controls Personal Data, by deciding why and how such Personal Data is Processed.
- “Data Processor” means the party that Processes Personal Data on behalf of the Data Controller (for example, a payroll service provider).
- “European Economic Area” or “EEA” means Austria, Belgium, Bulgaria, Croatia, Republic of Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, the UK, Iceland, Liechtenstein, and Norway.
- “Personal Data” is any information relating to a living individual which allows the identification of that individual. Personal Data can include:
- a name, an identification number;
- details about an individual’s location; or
- any other information that is specific to that individual.
- “Processing” includes collecting, using, recording, organising, altering, disclosing, destroying or holding Personal Data in any way. Processing can be done either manually or by using automated systems such as information technology systems and “Process” and “Processing” shall be interpreted accordingly.
- “Profiling” is the automated Processing of Personal Data for the purpose of assessing certain aspects relating to an individual so as to analyse or predict the individual’s performance, decisions or behaviour.
- “Sensitive Personal Data” are types of Personal Data that reveal any of the following information relating to an individual: racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership. Special Categories of Personal Data also include the Processing of genetic data, biometric data (for example, fingerprints or facial images), health data, data concerning sex life or sexual orientation and any Personal Data relating to criminal convictions or offences.
- SCHEDULE 2 – Types of Personal Data
Type of Personal Data Examples Contact information Name, address, email and telephone number. General information Gender, marital and family status, date and place of birth, physical characteristics, expression of wishes form. Education and prior employment Educational background, employer details and employment history, skills and experience, professional licences, memberships and affiliations. Government Social security number, passport number, tax number, driver’s licence number, or other government issued identification number. Financial information Payment card number (credit /debit card), bank account number, other financial account number and account details, other financial information. Information enabling us to provide products and services Status as company officer or director, or partner, or other ownership or management interest in an organisation. Marketing preferences, marketing activities and customer feedback Marketing preferences or responses to customer satisfaction surveys. Online activity information The Company may receive Personal Data about an individual when they use Online Tools; this may include social media account identifiers, IP address and other online identifiers (to the extent that they are Personal Data), and other Personal Data that an individual may provide to the Company online. Supplemental information from other sources The Company and its service providers may supplement the Personal Data the Company collects with information obtained from other sources (for example, publicly available information from online social media services and other information resources, third party commercial information sources, and information from its business partners).