Revision – Date 24.05.18
Our company is required to comply with the ‘General Data Protection Regulations’ (GDPR) which have now come into force. To comply with GDPR Epure Design requires your ‘consent’ to process your personal data.
For the purposes of the Data Protection Act 1998 (the Act) and General Data Protection Regulation (GDPR), under Article 6 our lawful bases for processing your data are:
Lawful bases for processing | Description | Applicable |
a) Consent | To process data | Yes |
b) Contract – The process is necessary to enable us to carry out our duties as part of a contract or process required to take before entering into a contract | The process is necessary to enable us to carry out our duties as part of a contract or process required to take before entering into a contract | Yes |
c) Legal Obligation – The process is necessary for us to comply with the law | No | |
d) Vital interests – The process is necessary to protect someone’s life | No | |
e) Public interests – The process is necessary to enable us to perform a task in the public interest | No | |
f) Legitimate interests – The process is necessary for your legitimate interests or the legitimate interests of a third party unless there is good reason to protect the individual’s personal data which overrides those legitimate interests | The process is necessary to enable us to maintain contact details of clients, design team members, third party suppliers, project contacts and marketing purposes. Data used for the purchasing of supplies, goods and services and for the legitimate running of the business | Yes |
For the purposes of Data Protection Epure Design Limited is the data controller which means that we decide how your personal data is processed and for what purpose. Our contact details are: Epure Design Ltd, Unit 11a, Greenway Farm, Bath Road, Wick, Bristol, BS30 5RL.
Tel: 01173 258 852. Email: info@e-pure.local
You are under no statutory or contractual obligation to provide us with your personal data and should you choose not to provide your data this may have a considerable impact on the contract, payment of goods & services. Communication will be reduced and possible delays or prevention of payments.
Your data is required to enable Epure Design to maintain contact & communication with you throughout the course of a potential or new project. We also require your information for the following reasons:
Your data is only shared between directors, members of the project team and the finance department where necessary. Your data may be shared with third parties and consultants as part of the project contract and to enable us to undertake our professional duties under the contract.
Our organisation does not use any form of automated decision making or profiling.
In no circumstances is your personal data transferred outside of the EEA unless specifically requested by the individual or if the client or main supplier is based outside the EEA then project team contact details may be shared with them for communication purposes only.
We keep your personal data for no longer than reasonably necessary but may be for a period of 12 or 7 years beyond the end of the contract with you. Examples include; in case of any legal claims/complaints, accounting etc, for example for accounting purposes we must keep records for 6 years from the end of the last company financial year they relate to. For contracts under seal details need to be kept for 12 years for legal purposes.
Under the new GDPR you have several rights which you can exercise under the Data protection law. These rights are briefly outlined below.
We strongly recommend that you also read the information available on ico.org.uk which will explain in more detail your rights and processes we need to adhere to.
All our employees are trained in how to deal with any requests you may make in relation to the above.
Most importantly you have the right to withdraw consent for us to process your data which you can do either by written or verbal communication. Once we receive your request we will record, review, and process the request. Certain elements of client’s financial information must be held for 7 years, but all personal and contact data will be deleted 12 months after the date when we stopped providing the services.
All requests will be processed within 30 days upon receipt of request unless an extension of time is required due to the complexity of the request or number of requests received from the individual. In which case an extension of 2 months will be required, and the individual notified of this within one month.
We regularly review and where necessary update our privacy information. Should we need to use your personal data for a new purpose the privacy policy will be updated, and changes communicated to individuals prior to commencing the new process.
We are committed to protecting and respecting your privacy and are happy to discuss this policy and what it means for you in more detail. Should you wish to contact us please Email: info@e-pure.local Tel: 01173 258 852.
Careers
Terms & conditions
CDM Regulations
Privacy Policy
Copyright © Épure Design