1 - Insight Solutions IT Services Ltd (Insight Solutions) gathers and processes your personal information in accordance with this privacy notice and in compliance with the relevant data protection Regulation and laws. This notice provides you with the necessary information regarding your rights and our obligations, and explains how, why and when we process your personal data.
2 - Insight Solutions registered office is at Droitwich Medical Centre, Ombersley Street, Droitwich Spa, Worcestershire, WR9 8RD and we are a company registered in England and Wales under company number 4621443. We are registered on the Information Commissioner's Office Register; registration number Z7799695, and act as the data controller when processing your data. Our designated Data Protection Champion is Lisa Seeley, who can be contacted at the office address and by calling 01527 577407. The name of our retained Data Protection Officer is Andrew Chilvers and he can be contacted via the same address and telephone number as detailed above.
Information that we collect
3 - Insight Solutions processes your personal information to meet our legal, statutory and contractual obligations and to provide you with our products and services. We will never collect any unnecessary personal data from you and do not process your information in any way, other than as specified in this notice.
4 - The personal data that we collect from you is: -
- Name and job title
- Organisation address
- Email address
- Telephone number – main organisation and direct dial/mobile if offered
- Clinical system
- The service/product you require
- Dietary requirements if attending a seminar
5 - We collect information in the below ways: -
- Online forms, website orders, emails, telephone, order forms via fax and external post
How we use your personal data (legal basis for processing)
6 - Insight Solutions takes your privacy very seriously and will never disclose, share or sell your data without your consent; unless required to do so by law. We only retain your data for as long as is necessary and for the purpose(s) specified in this notice. Where you have consented to us providing you with promotional offers and marketing, you are free to withdraw this consent at any time. The purposes and reasons for processing your personal data are detailed below: -
- We collect your personal data in the performance of a contract or to provide a service and to ensure that orders are completed and can be sent out to your preferred address
- We collect and store your personal data as part of our legal obligation for business accounting and tax purposes
- We will occasionally send you marketing information were we have assessed that it is beneficial to you as a customer and in our interests. Such information will be non-intrusive and is processed on the ground of legitimate interests
- We will only send our monthly newsletter out to customers who have requested to receive it and this will be processed on the ground of consent. Recipients can request to stop receiving this at any time by emailing email@example.com and withdrawing their consent
7 - You have the right to access any personal information we process about you and to request information about:
- What personal data we hold about you
- The purposes of the processing
- The categories of personal data concerned
- The recipients to whom the personal data has/will be disclosed
- How long we intend to store your personal data for
- If we did not collect the data directly from you, information about the source
8 - If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the information and we will strive to do so as quickly as possible; unless there is a valid reason for not doing so, at which point you will be notified.
9 - You also have the right to request erasure of your personal data or to restrict processing (where applicable) in accordance with the data protection laws; as well as to object to any direct marketing from us. Where applicable, you have the right to data portability of your information and the right to be informed about any automated decision-making we may use.
10 - If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the request; this is to ensure that your data is protected and kept secure.
Sharing and Disclosing Your Personal Information
12 - We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this notice or where there is a legal requirement. Insight Solutions uses third-parties to provide the below services and business functions; however, all processors acting on our behalf only process your data in accordance with instructions from us and comply fully with this privacy notice, the data protection laws and any other appropriate confidentiality and security measures.
- Joanne Hawes – Bookkeeping
- Howell Dunn – Accountants
- Fusemetrix – Hosted CRM system
- ShredPro – confidential waste disposal
12 - Insight Solutions takes your privacy seriously and takes every reasonable measure and precaution to protect and secure your personal data. We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place, including: -
- The website is served over SSL/TLS encryption (https) and has restricted access for the website admin system using a username and password combination
Transfers Outside the EU (if applicable)
13 - Personal data in the European Union is protected by the General Data Protection Regulation (GDPR) but some other countries may not necessarily have the same high standard of protection for your personal data. Isnight Solutions does not transfer or store any personal data outside the EU.
Consequences of Not Providing Your Data
14 - You are not obligated to provide your personal information to Insight Solutions, however, as this information is required for us to provide you with our services, we will not be able to offer some/all our services without it.
15 - As noted in the ‘How We Use Your Personal Data’ section of this notice, we occasionally process your personal information under the legitimate interests’ legal basis. Where this is the case, we have carried out a thorough Legitimate Interests’ Assessment (LIA) to ensure that we have weighed your interests and any risk posed to you against our own interests; ensuring that they are proportionate and appropriate.
16 - We use the legitimate interests’ legal basis for processing when we need to advise our customers about products or services that we feel are advantageous for them to be informed about.
How Long We Keep Your Data
17 - Insight Solutions only ever retains personal information for as long as is necessary and we have strict review and retention policies in place to meet these obligations. We are required under UK tax law to keep your basic personal data (name, address, contact details) for a minimum of 6 years after which time it will be destroyed.
18 - Where you have consented to us using your details for direct marketing, we will keep such data until you notify us otherwise and/or withdraw your consent.
Lodging A Complaint
19 - Insight Solutions only processes your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, you have the right to lodge a complaint by contacting firstname.lastname@example.org at our office address or by contacting our independent Data Protection Officer.
Data Protection Officer
c/o Insight Solutions IT Services Ltd Droitwich Medical Centre Ombersley Street