1.1 EliteScribe Limited (“EliteScribe”) collects, keeps and uses personal data or information about individuals for specific and lawful purposes. Individuals could include customers, current and former employees, temporary and agency workers, contractors, suppliers and other third parties.
1.2 We are committed to complying with our data protection obligations. We understand that your personal data is important to you, and we have a responsibility to you to ensure that the information we collect and use is done so proportionately, correctly and safely.
1.3 We also have an obligation to be concise, clear and transparent about how we obtain and use personal information relating to you and what we do with the information when it is no longer required. Being transparent with you and providing accessible information about how we use your information builds trust and demonstrates our commitment to the General Data Protection Regulations, hereafter referred to as “GDPR” (Regulation (EU) 2016/679).
2. OUR DETAILS
2.1 EliteScribe is registered as a Data Controller with the Information Commissioner’s Office (ICO). Our registration number is ZA754108.
2.2 Our Data Protection Contact is Ms J Stevens.
3. PURPOSE OF PROCESSING
3.1 We collect, hold and use personal data received by you to provide our services to you or to respond to your query. The amount and type of information we hold about you depends on the services we are providing for you. We will not ask you for any information which is not necessary for the particular service we are providing to you.
4.1 “Personal data” means any information relating to a person who can be identified, directly or indirectly, from that information. This could include your name, your identification number, location data, online identifier (such as IP address) or to one or more factors specific to the physical, physiological, mental, economic, cultural or social identity of that person.
4.2 Some of the services we provide may require us to process your “special categories of personal data”. These special categories of personal data are of a sensitive nature, and might include health data or financial data. The definition “special categories” of personal data has been extended to now include biometrics data (such as facial images) and genetic data (such as the analysis of a biological sample).
4.3 “Processing” means obtaining, recording, organising, storing, amending, retrieving, disclosing and/or destroying information, or using or doing anything with it.
4.4 “Data Subject” means the data subject to whom the personal data relates.
4.5 “GDPR” means the General Data Protection Regulation.
4.6 “ICO” means the Information Commissioners Office, the governing body for Data Protection in the UK.
5. CONDITIONS OF PROCESSING
5.1 When we process your personal data we will do so in accordance with the data protection principles. These principles are designed to protect you, and ensure that we:
5.1.1 Process your information lawfully, fairly and in a transparent manner;
5.1.2 Use your information for a specified, explicit and legitimate purpose and not further processed in a manner that is incompatible with that purpose;
5.1.3 Only obtain adequate, relevant and limited information to allow us to carry out the purpose for which it was obtained;
5.1.4 Ensure the information we hold about you is accurate and, where necessary, kept up to date;
5.1.5 Keep any information for no longer than necessary for the purposes for which it was collected; and
5.1.6 Process your information in a manner that ensures appropriate security of your personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
6. LAWFULNESS OF PROCESSING
6.1 Paragraph 5.1.1 above stipulates that the processing of personal data shall be undertaken ‘lawfully’. To show the processing is being undertaken lawfully, EliteScribe relies on your consent to the processing of your personal data for one or more specific purposes; (for example to respond to a query you have sent us, or because the processing is necessary for us to perform a contract with you (by providing our services to you). We may also process your personal data for the purposes of our legitimate interests. For example, to provide further, related, online or email information and ongoing news updates about services of interest to you.
7. PROCESSING “SPECIAL CATEGORIES” OF PERSONAL DATA
7.1 EliteScribe does not routinely process special category personal data. Where processing of special category personal data is undertaken, it is the responsibility of customers/clients to ensure that an appropriate legal basis exists before any processing of the special category personal data is undertaken.
8.1 Personal information (and special category personal data) should not be retained for any longer than necessary. The length of time over which data should be retained will depend upon the circumstances, including the reasons why the personal information was obtained. EliteScribe will keep the personal information for a period of as long as necessary to provide the services and products requested or required by law (for example 6 years for HMRC purposes).
9.1 EliteScribe will use appropriate technical and organisational measures to keep personal information secure, and in particular to protect against unauthorised or unlawful processing and against accidental loss, destruction or damage. These may include:
9.1.1 making sure that, where possible, personal information is pseudonymised or encrypted;
9.1.2 ensuring the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
9.1.3 ensuring that, in the event of a physical or technical incident, availability and access to personal information can be restored in a timely manner; and
9.1.4 a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
10. INTERNATIONAL TRANSFERS OF YOUR PERSONAL DATA
10.1 EliteScribe does not transfer personal data outside of the European Economic Area (EEA) unless requested and authorised by the customer/client.
11. STAFF ADMINISTRATION
11.1 EliteScribe will process personal information relating to its current and former staff and data subjects, (who have applied for permanent or temporary jobs at EliteScribe), for the purposes of managing their contract of employment, the work of EliteScribe, pay and/or pensions, discipline and other personnel matters.
12. INFORMATION SHARING
12.1 To ensure that we can provide you with the best possible service we may have to share your personal data between our internal teams or external partners. Our external partners, who we may share your personal data with on a contractual, consent and/or lawful basis are StayPrivate Ltd, Xero, bOnline Ltd, Ionos by 1&1, Seers Group Ltd, Hiscox and Giess Wallis Crisp LLP.
12.2 We may also share your information with third parties, other than those who either process information on our behalf or because of a legal requirement/entitlement, and it will only do so if necessary or where permitted under the GDPR.
13. YOUR RIGHTS
13.1 You have certain rights in relation to the personal information we hold about you. These rights are as follows:
13.1.2 Right of access – you have the right to request a copy of the information that we hold about you. (This right is similar to a subject access request).
13.1.3 Right of rectification – you have a right to correct data that we hold about you that is inaccurate or incomplete.
13.1.4 Right to erasure (right to be forgotten) – in certain circumstances you can ask for the data we hold about you to be erased from our records.
13.1.5 Right to restrict processing – where certain conditions apply to have a right to restrict the processing.
13.1.6 Right of data portability – in certain circumstances you have the right to have the data we hold about you transferred to another organisation.
13.1.7 Right to object – you may have the right to object to certain types of processing such as direct marketing, the performance of a legal task and scientific or historical research.
13.1.8 Right to object to automated processing, including profiling.
13.1.9 Right to withdraw consent – If the legal basis for our processing of your personal information is ‘consent’ then you have the right to withdraw that consent at any time.
14. HOW TO EXERCISE YOUR RIGHTS
14.1 You may exercise any of your rights in relation to your personal data by emailing us at email@example.com or writing to us at our registered address:
10-12 Mulberry Green
To avoid delay in dealing with your request please ensure that you confirm in your request which right you wish to exercise along with the reasons why.
14.2 The first copy will be provided free of charge, but additional copies may be subject to a reasonable fee.
14.3 We will respond to your request within 30 days, by either providing you with the information requested, requesting further information from you, or requesting further time to complete your request, if for example the request is substantial or we need to obtain information from various departments within EliteScribe.
14.4 EliteScribe can also refuse your request. In the event that EliteScribe refuses your request we will provide you with reasons why, as well as provide you with details of how you can challenge or appeal our decision. You will also be informed of your right to legally challenge our decision with the ICO.
15.1 Cookies are small text files that are placed on your computer, smartphone, tablet or smart TV’s when you access a website. They are widely used in order to make websites work, or work more efficiently, by allowing the website to recognise your device and store information about past actions or preferences. An example could be internet banking, where your device may recognise and populate certain previously entered login details previously entered.
15.3 There are two kinds of cookies:
15.3.1 session cookies – which are short-term and auto delete after a few minutes or when you close your browser; and
15.3.2 persistent cookies – set by the website and stored for a longer period of time, usually used to store commonly entered information on forms (such as your name, address, and telephone number). They also store information about your browsing habits across multiple sites, usually used to allow advertisers and social network site operators to target advertising at you.
15.4 EliteScribe uses Google Analytics and Ionos Analytics to analyse the use of our website and help us create a more useful and easy to use site. The data collected is completely anonymous and does not store any personal details. The information is used to analyse how visitors make use of our website and allows us to gather statistical information such as website activity, visitor numbers, popular pages and customer journey through the website.
15.6 You can find out more about cookies by visiting www.aboutcookies.org.
16. LINKS TO OTHER WEBSITES
17.2 EliteScribe encourages you to periodically visit EliteScribe’s website to review this notice and to be informed of how EliteScribe is protecting your information.
17.3 If you require general information about the Data Protection Act 2018 or GDPR then information is available on the Information Commissioner’s website.
18.1 If you wish to make a complaint about how EliteScribe is processing your personal data, then in the first instance please email us at firstname.lastname@example.org or by writing to our registered address:
10-12 Mulberry Green
18.2 If you are still dissatisfied with how EliteScribe have handled your complaint then you have the right to complain to the Information Commissioners Office (ICO). The ICO can be contacted as follows:
The Information Commissioner
Telephone: 08456 306060
Name: Ms J Stevens
Title: Data Protection Contact
Telephone: 0208 138 1026