Privacy Notice
This document demonstrates our commitment to protecting the privacy and security of personal information we collect and keep. The statement contains information regarding how we collect and use personal data or personal information about you in accordance with the General Data Protection Regulation (GDPR) and all other data protection legislation currently in force.
In accordance with that legislation, when are committed to;
EP:IC Consultants Ltd is a “data controller”. This means that we are responsible for determining the purpose and means of processing personal data relating to our employees, contactors and research / involvement participants.
“Personal data”, or “personal information”, means any information relating to an identified, or identifiable individual in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
There are “special categories” of sensitive personal data, meaning data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, physical or mental health conditions, sex life or sexual orientation, genetic data, and biometric data which require a higher level of protection.
This privacy notice (also called a data protection compliance statement) applies to current and former employees, workers and contractors, as well as those who have provided their views for research or engagement purposes.
Details of the information we hold.
The list below identifies the kind of data that we will hold about employees and / or contractors:
The following list identifies the kind of data that that we will process and which falls within the scope of “special categories” of more sensitive personal information:
The list below identifies the kind of data that we will hold following participation in research / engagement activities. Since all engagement activities are different, this list will not be true for everyone:
How we collect personal data
Employee and contractors’ personal information is obtained through the application and recruitment process, this may be directly from candidates, via an employment agency or a third party who undertakes background checks (such as the Disclosure and Barring service, with your consent). Further information will be collected directly from the employee through self-completion forms at the start of the employment period. Other details may be collected directly from you in the form of official documentation such as your driving licence, passport or other right to work evidence. Personal data is kept in personnel files or within our HR and IT systems.
Engagement participants’ personal information is obtained through electronic, written or verbal correspondence, or through meetings in person.
Processing infromation
We will only use personal information in accordance with the law. At least one of the following will apply when we process personal data:
Sharing data
Your data will be shared with colleagues within the Company where it is necessary for them to undertake their duties. This includes, for example, those involved in analysis of engagement data will need to see this data, and the HR team will need to see employee data.
The list below identifies which activities are carried out by third parties on our behalf:
If data is shared, we expect third parties to adhere and comply with the GDPR and protect any data we share. We do not permit any third parties to process personal data for their own reasons. Where they process your data it is for a specific purpose according to our instructions.
Data security
Retention
We will keep your data only for as long as it is required to meet our evaluation / involvement purposes and our legal obligations, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements).
When we have no ongoing legitimate business need to keep or use your personal information, we will either delete or anonymise it.
Storage
As part of our commitment to protecting the security of any data we process, we have the appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process.
However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. In cases of a breach, or suspected breach, of data security you will be informed, as will any appropriate regulator, in accordance with our legal obligations.
Your rights
We commit to ensure that any data we process is correct and up to date. It is your obligation to make us aware of any changes to your personal information.
Everyone who provides us with data has the following rights, where applicable.
Where you have provided consent to our use of your data, you also have the unrestricted right to withdraw that consent at any time. Withdrawing your consent means that we will stop processing the data that you had previously given us consent to use. There will be no consequences for withdrawing your consent. However, in some cases, we may continue to use the data where so permitted by having a legitimate reason for doing so.
If you wish to exercise any of the rights explained above, please contact Donna at donna@epicconsultants.co.uk
Questions or complaints
Should you have any questions regarding this statement, please contact Donna at donna@epicconsultants.co.uk
If you have any concerns about our use of your personal information, you can make
a complaint to us using the details given at the top of this Notice.
You can also complain to the Information Commissioner’s Office if you are unhappy
with how we have used your data;
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk
Website created by Golden Fish Designs.