PLEASE READ THIS NOTICE CAREFULLY.
It explains what data we collect, how we use your personal information and your legal rights relating to your personal information
We are The Improvement Service, a company limited by guarantee and registered in Scotland (Company No. SC287978) and operating from iHub, Quarrywood Court, Livingston, EH54 6AX. We are committed to protecting and respecting your privacy.
Please note that any reference to Data Protection Law we make in this document includes the Data Protection Act 1998 and all associated legislation. For the avoidance of doubt this also includes, from implementation, the General Data Protection Regulation (“Data Protection Law”), which is due to become effective in the UK on 25th May 2018.
We are required by law to treat your personal information legally and fairly. We must also give you the means to correct it if it is wrong, allow you to object to our processing it and, in some instances, delete it from our systems if you ask us to do so.
WE ARE YOUR DATA CONTROLLER
For the purposes of Data Protection Law, we are the Data Controller in relation to the processing of your personal data.
We collect and process data about you in different ways, depending on the service you are using. We collect data through the following services:
Please refer to the relevant section below.
Personal data you give us when you contact us:
If you want to contact us you can do so using a form on our website. To allow us to contact you and keep you up to date with your request you must give us a valid email address.
You can also contact us directly by email at firstname.lastname@example.org
We will store your personal information securely on our server and use it to follow up on any requests or to contact you for more information.
Our legal basis for processing your information is that we have a legitimate interest to communicate effectively with our partners and customers to ensure that we meet our business objectives and project commitments.
Personal data you give us when you subscribe to one or more of our newsletters:
We offer a number of newsletters on a range of topics. We use the Mailchimp service for this and we will subscribe you to a mailing list using that service.
When we send you a newsletter, we also gather statistics around email opening and clicks to help us monitor and improve our newsletters. You can find out more about this in Mailchimp’s privacy notice at https://mailchimp.com/legal/privacy/.
Our legal basis for processing your personal data is that you consent to provide us with your information so that we can send you information that relates to your subscription and preferences.
Personal data you give us when you complete one of our surveys:
Our legal basis for processing your personal data is that you consent to provide us with the information so that we can process survey responses and analyse the results.
Personal data we collect about you when you participate in our Associates Framework:
We operate an Associates Framework that allows us to match work and project requirements specified by our partners to appropriately qualified staff on the framework.
Our legal basis for processing your personal data if you are part of the Associates Framework is to enable the performance of a contract between you and one of our partners or to take steps at the request of one of our partners prior to setting up a contract with you.
We use Google Analytics to collect standard internet log information and information about how you use the site. The information we collect is:
Our legal basis for processing your personal data in this way is that we have a legitimate interest to understand how people are using our website so that we can improve the content and services we offer.
Personal data we collect about you when you register for an event:
Our legal basis for processing your personal data is that you consent to provide us with the information so that we can process your registration for attendance at an event.
We use personal data held about you in the following ways:
We will not sell your information or disclose it for direct marketing purposes.
We will disclose the personal data we process about you to the following third parties for the purposes indicated in the table below:
|Name, email address, IP address||The Mailchimp email service||To send you personalised newsletters periodically|
|Name, email address, IP address||The SmartSurvey service||To allow you to participate in our surveys|
|Name, email address, address, job title, organisation, phone number and dietary requirements||Eventbrite||To register you for one of our events|
|Name, company name, email address, phone number, information relating to your educational qualifications and work experience||Our partners within the Associates Framework||To allow our partners within the Associates Framework to assess your suitability in terms of their work requirements and to contact you and contract with you if they wish|
|IP address||Google Analytics||To analyse our website visitors, where they have come from and what content they find most useful|
|IP address||Google reCAPTCHA||To protect our web forms from spam|
We use the Knowledge Hub as a collaboration tool to make the Associates Framework Data available to partners. Data is shared through a private group that is strictly controlled and accessed only on a business need-to-know basis.
Disclosure to other parties
In addition, we may disclose your personal data to third parties:
- protect the rights, property or safety of our users or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection.
Personal data you provide to us is stored on computer equipment in the UK with the following exceptions:
We use the Mailchimp service to send you periodic newsletters and this means that some of your data is transferred to servers in the USA.
The Mailchimp service is covered by both the EU-US and Swiss-US Privacy Shield regimes and is used by many EU and worldwide businesses. As such, in our opinion, it poses a minimal threat to your privacy rights and freedoms.
We have also completed a Data Processor Agreement addendum with Mailchimp that specifically covers customers located in the EU.
You can read more about Mailchimp’s privacy measures at: https://mailchimp.com/legal/privacy/
We use Eventbrite to handle registrations for events. This means that some of your data is transferred to the US.
Eventbrite has certified its compliance with the EU-US Privacy Shield regarding collection, use and retention of customer data. As such, in our opinion, it poses a minimal threat to your privacy rights and freedoms.
We use the Google Analytics and Google reCAPTCHA services. This means that some of your data is transferred to servers outside the European Union/EEA. More information about these services is included below.
The following table shows what personal information we hold and how long it is held for.
|Personal Data||How long we hold it|
|Newsletter||Retained for as long as you subscribe; deleted immediately when you unsubscribe|
|Contact form data||Retained for the period it takes us to respond to your query satisfactorily or after one calendar year|
|Associates Framework data||Retained for as long as the Associates Framework contract is operational; retained for 7 years for audit purposes|
|Website analytics logs||26 months|
|Event registrations||2 years for event registration information; 7 years for billing information which is retained for audit purposes|
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your personal data in transit; any transmission is at your own risk. Once we have received your personal data, we will use strict procedures and security features as outlined above to try to prevent unauthorised access to your personal data.
You have the following rights:
Please be aware that we are legally obliged to verify your identity using reasonable means before you can exercise your rights.
If you sign up for our newsletters, we will send an e-mail to the registered e-mail address in which you will be asked to confirm your newsletter subscription (Double-Opt-In). When you accept, your IP Address and the date and time of your acceptance will be saved. We will only share your personal information with technical services that are needed to deliver your newsletter. You are free to unsubscribe to our newsletter service whenever you want by clicking on the unsubscribe button in the newsletter or by sending an e-mail to email@example.com.
Our website may, from time to time, contain links to and from the websites of third parties. If you follow a link to any of these websites, please note that these websites and any services that may be accessible through them have their own privacy notices and that we do not accept any responsibility or liability for these notices or for any personal data that may be collected through these websites or services, such as contact and location data. Please check these notices before you submit any personal data to these websites or use these services.
Our website may use Social Media plugins (plugins) for Twitter and Youtube. If you call up one of our website pages which has a plugin of this kind, your browser sets up a direct link to the Twitter or Youtube servers. The content of the plugin is passed by the provider directly to your browser and integrated by it into the website. This means that we have no influence over the data that Twitter and Youtube obtain with the help of this plugin.
We therefore inform you that through the plugin, the provider obtains information about you, even if you do not own a profile with the provider or are not logged in at the time. This information, including your IP address, will be passed from your browser directly to the provider and stored on its servers. The server location may be outside the European Union/EEA.
You can prevent the storage of cookies by disabling them in your browser. You can find out how to do this by visiting http://www.allaboutcookies.org
Please note that if you disable cookies, some of the functionality on our website may not be available to you or may not work as expected.
In addition, you may prevent the collection of analytics data by Google by downloading an add-on for your browser by visiting https://tools.google.com/dlpage/gaoptout?hl=en-GB
Once you install the add-on, an opt-out cookie will be set which prevents the future collection of your data when visiting our website.
Our website uses Google reCAPTCHA, a service provided by Google that helps protect our website from spam by using analysis techniques that can identify if a user is human rather than a machine.
Your entry in the reCAPTCHA field will be sent to Google in the USA and processed by Google for this purpose. The reCAPTCHA application will also send your IP address and other data to Google to enable it to provide the reCAPTCHA service. By using reCAPTCHA, you agree to Google processing your data for this purpose. The IP address provided as part of Google reCAPTCHA will not be merged with other Google data.
Any changes we may make to our privacy notice in the future will be posted on our website and, where appropriate, notified to you when you next visit. The new terms may be displayed on-screen and you may be required to read and accept them to continue your use of our services.
Questions, comments and requests regarding this privacy notice are welcomed and should be addressed by email to firstname.lastname@example.org or in writing to our main office address above.
Last Updated 18/05/2018