Legal and Regulatory Notice
This Privacy Notice (“Notice”) explains how we use (“Process”) your personal information (including personal information that you provide to us about other persons) (together, “Personal Information”). It also explains your privacy rights and how you can exercise them.
We are responsible for and are the ‘Data Controller’ for the Personal Information we collect about you (including through the www.complianceondemand.co.uk website). We are registered as a Data Controller with the Information Commissioners Office under number ZA474581. The type of Information we collect and how we Process it will vary depending on the relationship we have with you (e.g. whether you are a client, a supplier or someone else). Please note in particular that:
We will publish updates to this Privacy Notice on this website, with relevant changes highlighted as appropriate. Where we hold or Process your Personal Data, we will also take appropriate measures to inform you of any amendments which have a material impact on you and your ability to exercise your privacy rights.
If you have any questions regarding our processing of your Personal Information or would like to exercise your privacy rights, please email: philip.olmer@complianceondemand.co.uk
How We Collect Your Personal Information
We collect Personal Information to provide our services, for legal and regulatory purposes and to manage our business and relationships. For further details, please see the ‘Use of your Personal Information’ section of this Notice below.
You will voluntarily provide most of your Personal Information directly to us. We will also obtain Personal Information from other sources or persons. Sometimes the provision of your Personal Information to us by third parties will be unsolicited and/or provided in confidence (for example, reports made to us by regulators and other persons) and we will be unable to notify you of this. In all cases we shall take such necessary steps to ensure that Personal Information is obtained and used in a fair and lawful way.
The Types of Personal Information That We Collect
The categories of Personal Information we collect will vary, depending on our specific relationship with you and the context.
We will not be able to further our relationship with you (for example, to provide you with regulatory services if you are a client or engage you if you are a potential supplier) without certain Personal Information. We will inform you at the relevant time if this is the case.
We will in most cases need to collect your work details (such as your name, job title, work address, office email and telephone number).
Use of Google Fonts Web API
Our website utilises Google Fonts API to provide a unified and visually pleasing textual experience for our users. Google Fonts is a service offered by Google LLC (“Google”) that allows websites to utilise high-quality fonts.
By using Google Fonts, some information may be transferred to Google servers, which may be located in other countries. This section outlines how Google collects and uses data in relation to the Google Fonts Web API.
Data Collection by Google
When you visit a page on our website that uses Google Fonts, your web browser automatically sends a request to Google’s servers. This request may include the following information:
This data is primarily used by Google to serve the font files to your browser and to improve the overall service quality.
Google may also use this data for the purposes of analytics and to enhance user experience. The data is processed in accordance with Google’s Privacy Policy, which you can review for further details: Google’s Privacy Policy.
If you are concerned about the data collection practices associated with Google Fonts, you may choose to disable the Google Fonts service through browser settings or use browser extensions designed to block such features. However, doing so may affect the appearance and functionality of our website.
Sensitive Information
In certain very limited circumstances we will need to collect more sensitive Personal Information, such as (unless applicable local law prevents this) diversity and health data, and details of offences, regulatory action and related proceedings (“Sensitive Information”). Such information may be collected from you or, in those jurisdictions where it is permitted under applicable local law, from third parties.
This will typically be more relevant: (a) where necessary to enable us provide you with our regulatory services; or (b) as part of our due diligence on third parties (including clients and related persons, and suppliers) – please see the relationship-specific sections of this Notice for further information.
Sensitive Information may also be inadvertently disclosed to us (for example, if you provide us with your dietary requirements for the purpose of a business meal – which may give an indication your religion or health. Providing the name of your spouse or partner to us may also reveal your sexual orientation).
We will only request Sensitive Information where absolutely necessary and we are legally allowed to and will put in place enhanced safeguards to protect such Sensitive Information.
Use of Your Personal Information
Our Processing of your Personal Information will include obtaining, recording or holding the data, or carrying out any operation or set of operations on the data including organising, copying, analysing, amending, retrieving, using, systemising, storing, disclosing, transferring, retaining, archiving, anonymising, erasing or destroying it by automated or non-automated means.
The GDPR require us to communicate to you the purposes for which we Process your Personal Information (the “Permitted Purposes”), together with the corresponding ‘Legal Basis’. These are summarised in the tables below. As the GDPR requirements are still relatively new, the way we have grouped the Permitted Purposes and Legal Basis may change as more regulatory guidance and market practice develops.
Further details on: (a) security and business continuity arrangements; (b) client due diligence, pre-hire checks and supplier vetting; and (c) equal opportunities monitoring and reporting, can be found in ‘The types of Personal Information that we collect’ section above. For further information about marketing, cookies and profiling, please see the ‘Marketing, cookies and profiling’ section.
General Permitted Purposes
We Process Your Personal Information for one or more of the following general Permitted Purposes. Where the Processing involves Sensitive Information, see also the second table under the heading ‘Sensitive Information’.
Sensitive Information
Where we are legally permitted to do so and one of the general Permitted Purposes apply, we will Process Sensitive Information for one or more of the following additional Permitted Purposes:
Marketing, Cookies and Profiling
We generally rely on our legitimate interests to Process your Personal Information for marketing purposes. We will inform you in advance of sending you marketing or if a related entity will send you marketing material (unless this is reasonably obvious in the circumstances – for example, when you provide us with your business card during a formal meeting).
Cookies
We may use cookies (small text files placed on your device) and similar technologies on our website and marketing emails to:
Please note that some of the cookies on our website may be third party cookies (e.g. Google advertising cookies) which we do not control. Please view the relevant website for details of their privacy policy.
If you are concerned about cookies, most web browsers (Safari, Internet Explorer, Chrome etc) now recognize when a cookie is offered and allow you to opt-out of receiving it. You can also delete all cookies that are already on your browser. If you choose to do this, you may have to manually adjust some preferences every time you visit our websites and some services and functionalities may not work.
For more information about cookies and how to disable and/or delete them, please visit www.allaboutcookies.org
Profiling
Where you are known to us and have been added to our contacts database, we will: (a) use your marketing and content preferences, and other Personal Information you provide to us (including details of your attendance at, or interest in, events) in an identifiable format to build a profile for you; and (b) supplement this profile with information about how you use our website, review our content and interact with us. We use this profile to try and ensure that you only receive material and information from us that you are likely to find of interest.
Changing your marketing preferences
You can change your preferences for receiving marketing emails, regulatory updates and other information from us by emailing us at philip.olmer@complianceondemand.co.uk
You also have the right to ask us not to process your Personal Information for marketing purposes – and can exercise the right at any time by sending us an email as above.
Where Is Your Personal Information Stored and Who Will It Be Shared?
Electronic information is stored by us on our Apple iMac desk top and Apple MacBook notebook hardware which are all password protected and information is stored in the Apple iCloud. All Microsoft Word, Excel and PowerPoint electronic information is encrypted and automatically uploaded and synchronised via the Microsoft One Drive system to Microsoft servers.
We will also at times need to share some of your Personal Information with select third parties, such as:
(collectively, “Select Third Parties”)
We do not disclose (or sell) your Personal Information to any other third parties.
This Processing will involve the transfer (sometimes via cloud computing) of some of your Personal Information to other countries whose privacy laws may not be as comprehensive to those where you are based. Where third party and/or cross-border transfers take place, we will put enhanced confidentiality and information security safeguards in place to ensure the lawfulness of the transfer, and protect your Personal Information. For further details, please see the Security of your Personal Information and data breaches section of this Notice below.
Security of Your Personal Information and Data Breaches
We operate technical, non-technical and procedural controls to safeguard your Personal Information (including protection against unauthorised or unlawful Processing and against accidental loss, destruction or damage). In particular:
We will keep these arrangements under regular review, taking into account security and compliance best practices, current risks, threats, vulnerabilities, mitigating controls, technology, and changes in applicable legal requirements.
However, the transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Information, we cannot guarantee the security of your Information transmitted to our websites – and any such transmission is at your own risk. Our website may also, from time to time, contain links to third party websites – which are outside of our control and are not covered by this Notice. If you access other websites using the links provided, please check their privacy policy before submitting any Personal Information to them.
Data Breaches
If a data breach (leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, your Personal Information) occurs which is likely to result in a high risk of adversely affecting your rights and freedoms, we will inform you of this without undue delay. Where legally permitted, any such notifications will be made either via email, post or telephone.
How long we keep Your Information
We will only keep your Personal Information in an accessible form which can identify you for as long as we need to for the Permitted Purposes. As retention periods can vary significantly depending on the Permitted Purpose and the relevant jurisdictions concerned, it is not possible for us to commit to an overall retention period for all of your Personal Information held by us. For example, we are under legal obligations to keep certain records for specific periods which will usually extend after the end of a contractual relationship (including minimum statutory retention periods in respect of client due diligence documents – which vary from jurisdiction to jurisdiction).
As a result, we use certain categories and criteria to determine how long we keep certain of your Personal Information, and these are set out below. Where your Personal Information is used for more than one Permitted Purpose (and/or in more than one jurisdiction), there will be overlapping retention periods in respect of that Information. In such cases, we will retain your Information for the longer of those overlapping retention periods. We will also transfer paper files into, and store them in, electronic format where appropriate.
Where we no longer require your Personal Information, we will take steps to delete or anonymise it. There will be circumstances where certain Information cannot be permanently deleted or anonymised, for example because it is stored in our back-ups for business continuity purposes.
In such cases, we will take appropriate steps to minimise (and pseduonymose where technically practicable) the Personal Information that we hold, and to ensure that it is: (a) not used in connection with any decision involving you; (b) not shared with anyone, except where we are legally required to do so (e.g. following a court order); (c) kept secure and virtually inaccessible; and (d) permanently deleted if, or when, this becomes technically possible.
Your Rights
The following privacy rights apply under the EU GDPR. Although applicable data protection legislation in relevant jurisdictions afford similar rights, there may be circumstances where some of these rights do not apply under or are modified by, local law. Further information can be sought from our privacy contacts. In the event of any inconsistency, the applicable local legislation will prevail.
Questions about how we handle your information?
Email philip.olmer@complianceondemand.co.uk or call +44 20 3963 9966.
