HAYHURST CONSULTANCY Privacy Notice
BACKGROUND:
Simon Hayhurst, trading as Hayhurst Consultancy of 29 Everard Avenue, Bromley, Kent, BR2 7LR, understands that your privacy is important to you and that you care about how your personal data is used. I respect and value the privacy of all of my clients and research participants and will only collect and use personal data in ways that are described here, and in a way that is consistent with my obligations and your rights under the law.
- Information About Me
Simon Hayhurst, a sole trader, trading as Hayhurst Consultancy of 29 Everard Avenue, Bromley, Kent, BR2 7LR
Email address:[email protected].
Telephone number: 07395 409062
Postal address: 29 Everard Avenue, Bromley, BR2 7LR
2. What Does This Notice Cover?
This Privacy Information explains how I use your personal data: how it is collected, how it is held, and how it is processed. It also explains your rights under the law relating to your personal data.
3. What Is Personal Data?
Personal data is defined by the UK GDPR and the Data Protection Act 2018 (collectively, “the Data Protection Legislation”) as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’.
Personal data is, in simpler terms, any information about you that enables you to be identified. Personal data covers obvious information such as your name and contact details, but it also covers less obvious information such as identification numbers, electronic location data, and other online identifiers.
The personal data that I use is set out in Part 5, below.
4. What Are My Rights?
Under the Data Protection Legislation, you have the following rights, which I will always work to uphold:
- The right to be informed about my collection and use of your personal data. This Privacy Notice should tell you everything you need to know, but you can always contact me to find out more or to ask any questions using the details in Part 11.
- The right to access the personal data I hold about you. Part 10 will tell you how to do this.
- The right to have your personal data rectified if any of your personal data held by me is inaccurate or incomplete. Please contact me using the details in Part 11 to find out more.
- The right to be forgotten, i.e. the right to ask me to delete or otherwise dispose of any of your personal data that I hold. Please contact me using the details in Part 11 to find out more.
- The right to restrict (i.e. prevent) the processing of your personal data.
- The right to object to me using your personal data for a particular purpose or purposes.
- The right to withdraw consent. This means that, if I am relying on your consent as the legal basis for using your personal data, you are free to withdraw that consent at any time.
- The right to data portability. This means that, if you have provided personal data to me directly, I am using it with your consent or for the performance of a contract, and that data is processed using automated means, you can ask me for a copy of that personal data to re-use with another service or business in many cases.
- Rights relating to automated decision-making and profiling.
For more information about my use of your personal data or exercising your rights as outlined above, please contact me using the details provided in Part 11.
It is important that your personal data is kept accurate and up-to-date. If any of the personal data I hold about you changes, please keep me informed as long as I have that data.
Further information about your rights can also be obtained from the Information Commissioner’s Office or your local Citizens Advice Bureau.
If you have any cause for complaint about my use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office. I would welcome the opportunity to resolve your concerns myself, however, so please contact me first, using the details in Part 11.
Data Collected | How I Collect the Data |
Identity Information including first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender. | I may collect the data when you: enquire/engage my services; subscribe to my services or newsletters; request marketing to be sent to you; participate in my surveys or research; or provide me with feedback. |
Contact information including billing address, delivery address, email address and telephone numbers. | I may collect the data when you: enquire/engage my services; subscribe to my services or newsletters; request marketing to be sent to you; participate in my surveys or research; or provide me with feedback. |
Business information including business name, job title, profession etc. | I may collect the data when you: enquire/engage my services; subscribe to my services or newsletters; request marketing to be sent to you; participate in my surveys or research; or provide me with feedback. |
Payment information including bank account, payment card details and in relation to respondents, their income, investments, bank accounts, pension and insurance. | I may collect the data when you: enquire/engage my services; subscribe to my services or newsletters; request marketing to be sent to you; participate in my surveys or research; or provide me with feedback. |
Profile information including your username and password, services purchased, your interests, preferences, feedback and survey responses. | I may collect the data when you: enquire/engage my services; subscribe to my services or newsletters; request marketing to be sent to you; participate in my surveys or research; or provide me with feedback. |
Data from third parties including contact information, profile information | I may collect the data when you: enquire/engage my services; subscribe to my services or newsletters; request marketing to be sent to you; participate in my surveys or research; or provide me with feedback. |
Special Data including data about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data (where used for ID purposes). | I may collect the data when you: enquire/engage my services; subscribe to my services or newsletters; request marketing to be sent to you; participate in my surveys or research; or provide me with feedback. |
Technical Data including internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website. | I may collect the data when you: enquire/engage my services; subscribe to my services or newsletters; request marketing to be sent to you; participate in my surveys or research; or provide me with feedback. |
Third parties or publicly available sources. | I may receive personal data about you from various third parties and public sources as set out below: Technical Data from analytics providers. Identity and Contact Data from publicly available sources such as Companies House and the Electoral Register based inside the EU. |
5. What Personal Data Do You Collect and How?
I may collect and hold some or all of the personal and non-personal data set out in the table below, using the methods also set out in the table. I do not collect any personal data relating to criminal convictions and/or offences.
6. How Do You Use My Personal Data?
Under the Data Protection Legislation, I must always have a lawful basis for using personal data.
I will only use your personal data when the law allows me to. Most commonly, I will use your personal data in the following circumstances:
- Where I need to perform the contract I am about to enter into or have entered into with you or my client or to take steps at your or my client’s request before entering into such a contract.
- Where it is necessary for my legitimate interests (or those of a third party) in conducting and managing my business to enable me to provide a good service and a secure experience. I make sure I consider and balance any potential impact on you (both positive and negative) and your rights before I process your personal data for my legitimate interests. I do not use your personal data for activities where my interests are overridden by the impact on you (unless I have your consent or are otherwise required or permitted to by law).
- Where I need to comply with a legal or regulatory obligation and processing your personal data is necessary for compliance with a legal or regulatory obligation that I am subject to.
- Where I have obtained your consent to use your personal data. I may also ask for your explicit consent to use special categories of your personal data. You have the right to withdraw consent to marketing and/or to participate in my surveys or research at any time by contacting me at [email protected]
What I Do | What Data I Use | My Lawful Basis |
Administering my business | (a) Identity (b) Contact (c) Technical | (a) Necessary for my legitimate interests (including running my business, provision of administration and IT services; IT security; to prevent fraud and in the context of a business reorganisation or group restructuring exercise (b) Necessary to comply with a legal obligation |
Supplying my services to you | (a) Identity (b) Contact (c) Financial (d) Transactional (e) Marketing and communications | (a) Performance of any contract I enter into with you or for taking steps at your request with a view to entering into a contract (b) Necessary for my legitimate interests (including to recover debts to me) |
Managing payments for my services | (a) Identity (b) Contact (c) Financial (d) Transactional (e) Marketing and communications | (a) Performance of any contract I enter into with you or for taking steps at your request with a view to entering into a contract (b) Necessary for my legitimate interests (including to recover debts due to me) |
Personalising and tailoring myservices for you | (a) Technical (b) Usage | Necessary for my legitimate interests (to customise my proposition; analyse types of clients for my services; to keep my website updated, to develop my business) |
Communicating with you. | (a) Identity (b) Contact (c) Technical (d) Usage (e) Profile | Necessary for my legitimate interests (to develop my services) |
To use data analytics to improve my website, services, marketing, client relationships and experiences | (a) Technical (b) Usage | Necessary for my legitimate interests (to develop my services, improve my website and attract clients to my business) |
To enable you to participate in my surveys or research | (a) Identity (b) Contact (c) Special Data (d) Profile (e) Usage (f) Marketing & Communications | (a) Performance of any contract I may enter into with you or my client; or for taking steps at your or my client’s request with a view to entering into a contract (b) Necessary for my legitimate business interests (to study how clients use my services, to develop those services and grow my business) (c) I have obtained your consent to use your personal data. |
With your permission and/or where permitted by law, I may also use your personal data for marketing purposes, which may include contacting you by email ortelephoneortext messageorpost with information, news, and offers on myservices. You will not be sent any unlawful marketing or spam. I will always work to fully protect your rights and comply with my obligations under the Data Protection Legislation and the Privacy and Electronic Communications (EC Directive) Regulations 2003, and you will always have the opportunity to opt-out.Iwill always obtain your express opt-in consent before sharing your personal data with third parties for marketing purposes and you will be able to opt-out at any time.
I will only use your personal data for the purpose(s) for which it was originally collected unless I reasonably believe that another purpose is compatible with that or those original purpose(s) and need to use your personal data for that purpose. If I do use your personal data in this way and you wish me to explain how the new purpose is compatible with the original, please contact me using the details in Part 11.
If I need to use your personal data for a purpose that is unrelated to, or incompatible with, the purpose(s) for which it was originally collected, I will inform you and explain the legal basis which allows me to do so.
In some circumstances, where permitted or required by law, I may process your personal data without your knowledge or consent. This will only be done within the bounds of the Data Protection Legislation and your legal rights.
7. How Long Will You Keep My Personal Data?
I will not keep your personal data for any longer than is necessary in light of the reason(s) for which it was collected
I will only retain your personal data for as long as necessary to fulfil the purposes it was collected for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, I consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which I process your personal data and whether I can achieve those purposes through other means, and the applicable legal requirements.
Personal identifiable information collected in relation to respondents will in most cases, be kept for no longer than twelve months from the expiry of the project, but in some cases it may be necessary to keep it for a maximum of twenty four months, unless I tell you otherwise at the time of participating. Non-identifiable data may be kept for longer.
Where I am required to keep basic information about my clients by law (including Contact, Identity, Financial and Transaction Data), I shall retain such personal data for six years after they cease being clients for tax purposes.
In some circumstances you can ask me to delete your data: see below for further information.
In some circumstances I may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case I may use this information indefinitely without further notice to you.
8. How and Where Do You Store or Transfer My Personal Data?
Some of my external third parties are based outside the European Economic Area (“EEA”) so their processing of your personal data will involve a transfer of data outside the EEA.
Whenever I transfer your personal data out of the EEA, I ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- I will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries.
- Where I use certain service providers, I may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.
- Where I use providers based in the US, I may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US. For further details, see European Commission: EU-US Privacy Shield.
- I can ensure that appropriate safeguards are in place to ensure an adequate level of protection with respect to the privacy rights of individuals as required by Article 46 of the General Data Protection Regulation ((EU) 2016/679) or the transfer otherwise complies with the applicable data protection legislation.
Please contact me via [email protected] for further information on the specific mechanism used by me when transferring your personal data out of the EEA.
The security of your personal data is essential to me, and to protect your data, I take a number of important measures, including the following:
- limiting access to your personal data to those employees, agents, contractors, and other third parties with a legitimate need to know and ensuring that they are subject to duties of confidentiality;
- procedures for dealing with data breaches (the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, your personal data) including notifying you and/or the Information Commissioner’s Office where I am legally required to do so;
9. Do You Share My Personal Data?
I may have to share your personal data with the parties set out below for the purposes set out above.
External third parties
You agree that I have the right to share your personal information with the recipients referred to below for the purposes set out in the table above (under the heading ‘How do you use my personal data’).
Recipient | Activity Carried Out |
Banks and payment provider services | Processing of payments in the performance of my contract with you |
Banks and payment provider services Business partners, suppliers or subcontractors such as data processors, translators, consultants, writers, research service providers | Performance of any contract I enter into with you or my client or for the taking of steps at your or my client’s request |
Credit reference agencies | Analytics and search engine providers Assessing your credit score which may be a condition of my entering in to a contract with you, for fraud prevention, and / or to pursue debtors which is necessary for my legitimate interests |
Analytics and search engine providers | Improvement and optimisation of my service which is necessary: (a) for my legitimate interests (for running my business, provision of administration and IT services, IT security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise and understand how clients use my services (b) to comply with a legal obligation |
Professional advisers such as insurers, accountants, lawyers, business advisors, pension advisors and financial advisors | Supporting my investigations necessary for: (a) any contract I enter into with you or taking steps at your request with a view to entering into a contract (b) to comply with a legal obligation (c) my legitimate interests (for running my business, provision of administration and IT services) |
Analytics and search engine providers Software development companies and web designers | My legitimate interests (for running my business, provision of administration and IT services). |
If any of your personal data is shared with a third party, as described above, I will take steps to ensure that your personal data is handled safely, securely, and in accordance with your rights, my obligations, and the third party’s obligations under the law, as described above in Part 8.
If I sell, transfer, or merge parts of my business or assets, your personal data may be transferred to a third party. Any new owner of my business may continue to use your personal data in the same way(s) that I have used it, as specified in this Privacy Policy.
In some limited circumstances, I may be legally required to share certain personal data, which might include yours, if I am involved in legal proceedings or complying with legal obligations, a court order, or the instructions of a government authority.
10. How Can I Access My Personal Data?
If you want to know what personal data I have about you, you can ask me for details of that personal data and for a copy of it (where any such personal data is held). This is known as a “subject access request”.
All subject access requests should be made in writing and sent to the email or postal addresses shown in Part 11.
There is not normally any charge for a subject access request. If your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests) a fee may be charged to cover my administrative costs in responding.
I will respond to your subject access request within less than one month of receiving it. Normally, I aim to provide a complete response, including a copy of your personal data within that time. In some cases, however, particularly if your request is more complex, more time may be required up to a maximum of three months from the date I receive your request. You will be kept fully informed of my progress.
11. How Do I Contact You?
To contact me about anything to do with your personal data and data protection, including to make a subject access request, please use the following details [(for the attention of Simon Hayhurst
Email address: [email protected].
Telephone number: 07395 409062
Postal Address: 29 Everard Avenue, Bromley, BR2 7LR.
12. Changes to this Privacy Notice
I may change this Privacy Notice from time to time. This may be necessary, for example, if the law changes, or if I change my business in a way that affects personal data protection.
Any changes will be made available at www.hayhurstconsultancy.co.uk.
This Privacy Notice was last updated on 23 April 2021.