CONTENTS
1. SCOPE
All data subjects whose personal data is collected, in line with the requirements of the GDPR.
2. RESPONSIBILITIES
2.1 The management team is responsible for ensuring that this notice is made available to data subjects prior to HAS Compliance collecting/processing their personal data
2.2 All Employees/Staff of HAS Compliance (hereafter HASC) who interact with data subjects are responsible for ensuring that this notice is drawn to the data subject’s attention and their consent to the processing of their data is secured.
3. PRIVACY NOTICE
3.1 Who are we?
HASC is a Health & Safety Consultancy specialising in the Automotive Repair Industry.
Our management team and data protection representatives can be contacted directly here:
3.2 The personal data we would like to collect from/process on you is:
Personal data type:
Source (where HASC obtained the personal data from if it has not been collected directly from you, the data subject. Note if the personal data has been accessed from publicly accessible sources)
Name
Address
Telephone Number
Age
Payment Information
Location
People whom purchases have been dispatched to
Content of reviews
Emails to us
Phone conversations with us
Information and documents regarding identity
Credit information history
Login email addresses and passwords
Purchase and content use history which we sometimes aggregate with similar information from other customers to create features such as best sellers
The full uniform resource locators (URL) click stream to through and from our website (including time and date)
Products and content you viewed or searched for, page response times, length of visit for web pages, page interaction information (such as scrolling, clicks and mouse overs)
Phone numbers used to call us
Information from other sources including; updated delivery and address information from our carriers or other third parties
Carriers or third parties
3.3 Our legal basis for processing personal data:
Processing is necessary for HASC to meet contractual obligations or to take steps to enter into a contract e.g. provide a quote or complete an order.
Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. This includes direct marketing, fraud prevention, internal administration and market research.
3.4 For what purposes does HASC process your personal information?
We process your personal information to operate, provide and improve the services that we offer to our customers. These purposes include:
3.5 How will HASC protect your information?
All information held is on a secure server. The secure server software (SSL) encrypts all information you input before it is sent to us. Here at our premises the information is also held in secure form and is not accessible to anyone outside of HASC staff. This provides many security features.
Authentication: This assures your browser that your data is being sent to the correct computer server, and that the server is secure.
Encryption: This encodes the data, so that it cannot be read anywhere other than the secure server.
Data integrity: This checks the data being transferred to ensure it has not been altered. Communication between the merchant’s site server and real credit occurs via the internet using the simple commerce messaging protocol (SCMP). SCMP uses DES and public key cryptography to provide privacy, message authentication, no-repudiation and integrity. SCMP messages are digitally signed and converted to ASCII format (“armoured”) from transmission over a Hyper Text Transfer Protocol (HTTP) connection, enabling messages to pass though firewalls and proxy servers
Furthermore, as required by the UK Data Protection Act, we follow strict security procedures in the storage and disclosure of information which you have given us, to prevent unauthorised access.
It is important for you to protect against unauthorised access to your password and your computers. Be sure to sign off when you finish using a shared computer.
3.6 Consent
By consenting to this privacy notice you are giving us permission to process your personal data specifically for the purposes identified.
Consent is required for HASC to process both types of personal data, but it must be explicitly given. Where we are asking you for sensitive personal data we will always tell you why and how the information will be used.
You may withdraw consent at any time by contacting tk@hascompliance.uk
3.7 Disclosure
HASC will not pass on your personal data to third parties without first obtaining your consent.
3.8 Retention Period
HASC will process personal data and will keep your personal information to enable your continued use of HASC for as long as it is required in order to fulfil the relevant purposes described in this privacy notice, as may be required by law such as for tax and accounting purposes, or as otherwise communicated to you. For example we retain your transaction history so that you can review past purchases (and repeat orders if required) and what addresses you have orders shipped to and to improve the relevancy of products.
3.9 Your rights as a data subject
At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:
All of the above requests will be forwarded on should there be a third party involved (as stated in 3.7 above) in the processing of your personal data.
3.10 Complaints
In the event that you wish to make a complaint about how your personal data is being processed by HASC (or third parties as described in 3.7 above), or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and HASC’s data protection representatives management team.
The details for each of these contacts are:
GDPR Owner Contact Details
Contact Name
Theresa Knowles
Email tk@hascompliance.uk
4. ONLINE PRIVACY STATEMENT
Personal data
Under the EU’s General Data Protection Regulation (GDPR) personal data is defined as:
“any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.
Why does HASC need to collect and store personal data?
In order for us to provide you with a service or product we need to collect personal data. In any event, we are committed to ensuring that the information we collect and use is appropriate for this purpose, and does not constitute an invasion of your privacy.
In terms of being contacted for marketing purposes HASC would contact you for additional consent.
Will HASC share my personal data with anyone else?
We may pass your personal data on to third-party service providers contracted to HASC in the course of dealing with you. Any third parties that we may share your data with are obliged to keep your details securely, and to use them only to fulfil the service they provide you on our behalf. When they no longer need your data to fulfil this service, they will dispose of the details in line with HASC’s procedures. If we wish to pass your sensitive personal data onto a third party we will only do so once we have obtained your consent, unless we are legally required to do otherwise.
How will HASC use the personal data it collects about me?
HASC will process (collect, store and use) the information you provide in a manner compatible with the EU’s General Data Protection Regulation (GDPR). We will endeavour to keep your information accurate and up to date, and not keep it for longer than is necessary. HASC is required to retain information in accordance with the law, such as information needed for income tax and audit purposes. How long certain kinds of personal data should be kept may also be governed by specific business-sector requirements and agreed practices. Personal data may be held in addition to these periods depending on individual business needs.
Under what circumstances will HASC contact me?
Our aim is not to be intrusive, and we undertake not to ask irrelevant or unnecessary questions. Moreover, the information you provide will be subject to rigorous measures and procedures to minimise the risk of unauthorised access or disclosure.
Can I find out the personal data that the organisation holds about me?
HASC at your request, can confirm what information we hold about you and how it is processed. If HASC does hold personal data about you, you can request the following information:
What forms of ID will I need to provide in order to access this?
HASC accepts the following forms of ID when information on your personal data is requested: Passport, driving licence or birth certificate.
Contact details of the management team / GDPR Owner:
Management team / GDPR Owner contact details
Contact Name
Theresa Knowles
Email tk@hascompliance.uk
Document Owner and Approval
The management team & GDPR Owner is the owner of this document and is responsible for ensuring that this record is reviewed in line with the review requirements of the GDPR.
Change History Record
Issue 1
Description of Change Initial Issue
Approval Theresa Knowles
Date of Issue April 2024
©Copyright. All rights reserved.
We need your consent to load the translations
We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.