Epure Privacy Policy

Revision – Date 24.05.18

Our company is required to comply with the ‘General Data Protection Regulations’ (GDPR) which have now come into force. To comply with GDPR Epure Design requires your ‘consent’ to process your personal data.

For the purposes of the Data Protection Act 1998 (the Act) and General Data Protection Regulation (GDPR), under Article 6 our lawful bases for processing your data are:

Lawful bases for processing Description Applicable
a) Consent To process data Yes
b) Contract – The process is necessary to enable us to carry out our duties as part of a contract or process required to take before entering into a contract The process is necessary to enable us to carry out our duties as part of a contract or process required to take before entering into a contract Yes
c) Legal Obligation – The process is necessary for us to comply with the law No
d) Vital interests – The process is necessary to protect someone’s life No
e) Public interests – The process is necessary to enable us to perform a task in the public interest No
f) Legitimate interests – The process is necessary for your legitimate interests or the legitimate interests of a third party unless there is good reason to protect the individual’s personal data which overrides those legitimate interests The process is necessary to enable us to maintain contact details of clients, design team members, third party suppliers, project contacts and marketing purposes. Data used for the purchasing of supplies, goods and services and for the legitimate running of the business Yes

For the purposes of Data Protection Epure Design Limited is the data controller which means that we decide how your personal data is processed and for what purpose. Our contact details are: Epure Design Ltd, Unit 11a, Greenway Farm, Bath Road, Wick, Bristol, BS30 5RL.
Tel: 01173 258 852. Email: info@epure-design.co.uk

OBTAINING YOUR PERSONAL DATA

You are under no statutory or contractual obligation to provide us with your personal data and should you choose not to provide your data this may have a considerable impact on the contract, payment of goods & services. Communication will be reduced and possible delays or prevention of payments.

WHY DO WE PROCESS YOUR PERSONAL DATA?

Your data is required to enable Epure Design to maintain contact & communication with you throughout the course of a potential or new project. We also require your information for the following reasons:

  1. Purchase of goods & services
  2. Accounts & finance records
  3. Marketing & advertising

SHARING YOUR DATA

Your data is only shared between directors, members of the project team and the finance department where necessary. Your data may be shared with third parties and consultants as part of the project contract and to enable us to undertake our professional duties under the contract.

AUTOMATED DECISION MAKING, INCLUDING PROFILING

Our organisation does not use any form of automated decision making or profiling.

TRANSFER OF DATA ABROAD

In no circumstances is your personal data transferred outside of the EEA unless specifically requested by the individual or if the client or main supplier is based outside the EEA then project team contact details may be shared with them for communication purposes only.

HOW LONG WILL WE RETAIN YOUR DATA?

We keep your personal data for no longer than reasonably necessary but may be for a period of 12 or 7 years beyond the end of the contract with you. Examples include; in case of any legal claims/complaints, accounting etc, for example for accounting purposes we must keep records for 6 years from the end of the last company financial year they relate to. For contracts under seal details need to be kept for 12 years for legal purposes.

WHAT ARE YOUR RIGHTS?

Under the new GDPR you have several rights which you can exercise under the Data protection law. These rights are briefly outlined below.

  1. Right to be informed
  2. Right of access
  3. Right of rectification
  4. Right to erasure
  5. Right to restrict processing
  6. Right to data portability
  7. Right to object
  8. Rights related to automated decision making including profiling

We strongly recommend that you also read the information available on ico.org.uk which will explain in more detail your rights and processes we need to adhere to.

All our employees are trained in how to deal with any requests you may make in relation to the above.

YOUR RIGHT TO WITHDRAW CONSENT

Most importantly you have the right to withdraw consent for us to process your data which you can do either by written or verbal communication. Once we receive your request we will record, review, and process the request. Certain elements of client’s financial information must be held for 7 years, but all personal and contact data will be deleted 12 months after the date when we stopped providing the services.

All requests will be processed within 30 days upon receipt of request unless an extension of time is required due to the complexity of the request or number of requests received from the individual. In which case an extension of 2 months will be required, and the individual notified of this within one month.

CHANGES TO THE INFORMATION?

We regularly review and where necessary update our privacy information. Should we need to use your personal data for a new purpose the privacy policy will be updated, and changes communicated to individuals prior to commencing the new process.

UNSURE? CONTACT US

We are committed to protecting and respecting your privacy and are happy to discuss this policy and what it means for you in more detail. Should you wish to contact us please Email: info@epure-design.co.uk Tel: 01173 258 852.