LAST UPDATED JULY 2019
We take Privacy seriously and fully endorse and adhere to the Principles of the EU GDPR. This Privacy Notice includes information about how we collect, use and disclose your personal data, and your rights in relation to the personal data we hold.
To help you further understand this policy, here are some terms used herein and in the data protection industry:
This is information that relates to and identifies living individuals, i.e. their personal information.
These are the living individuals to whom the personal data relates.
This covers a wide range of operations on personal information, this includes its collection, use, disclosure and disposal.
Data controllers are clients who supply us with their personal data (i.e. mailing lists) directly, or are the clients we gather personal data on behalf of. We only become the data controllers if we are using any personal data for our own purposes or it is the personal data of our staff. For example we are the Data Controllers of our own Mailing List.
These are individuals who are not employed by a data controller but who process personal data on behalf of and in accordance with the instructions of a data controller; in effect they could be referred to as subcontractors. We are the data processors for any personal data supplied by, or gathered on behalf of our clients.
2. WHO IS COLLECTING THE DATA?
We handle personal data exclusively to provide services to our clients and also for our own marketing purposes.
In certain circumstances, we may use third parties to collect and supply data. Any third party company used for this purpose will have been vetted by us to be fully GDPR compliant.
3. HOW DO WE COLLECT YOUR DATA?
We collect your personal data in a number of ways, for example:
during a meeting;
from information about you provided to us by your company;
from information about you provided to us by an independent referral;
when you communicate with us by telephone, email or other forms of electronic communication;
from publicly available sources.
4. WHAT DATA IS BEING COLLECTED?
For our day-to-day operations, we collect names, email addresses, postal addresses and/or telephone numbers, as appropriate. All data collected is the minimum required to successfully carry out specific operational needs. This data is kept as accurate and up-to-date as possible.
5. WHERE IS THE DATA STORED?
We store all personal data in a Client Database, on our dedicated and secure UK server with Data Souvereignity Guarantee, meaning no data is transferred outside the UK.
6. WHAT IS THE LEGAL BASIS FOR PROCESSING THE DATA?
We will only process data if it is necessary for the legitimate interests to the data subject unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests. We use opt-in procedures for collecting your personal data, and opt-out services are clearly shown and available at all times.
The purposes for which personal data is collected include:
(a) responding to any enquiries you have made;
(b) Sending you materials and/or information you have requested;
(c) Performing our obligations in relation to any agreement you have with us;
(d) Conducting contests, competitions or promotions;
(e) Enabling you to submit contributions to us and/or to the Website;
(f) To customise and improve the content on the website or any other websites which are part of NM Direct and/or to improve our products and services to respond to your current and future needs and interests;
(g) Contacting you if we change our products or services or terms or if we need to give you notice of such changes;
(h) for the purpose of marketing our other products and services to you unless you opt-out from receiving our News & Special Offers;
(i) For accounting purposes and internal administration and analysis;
(j) For the prevention of fraud; and
(k) For any purpose required by law or regulation.
7. WILL THE DATA BE SHARED WITH ANY THIRD PARTIES?
We do not share, sell, rent or distribute personal data to or with third parties unless the transfer of such information to third parties is strictly necessary for providing a service you have commissioned and will not disclose personal information to third parties for their own marketing purposes unless you have consented to this.
8. HOW WILL THE DATA BE USED?
The personal data is used solely for providing a service to our customers.
9. HOW LONG WILL THE DATA BE STORED FOR?
Your personal data remains in our client database and mailing lists until you request erasure or/and opt-out of our Mailing list.
10. WHAT ARE YOUR INDIVIDUAL RIGHTS?
You, as the data subject, have full rights under Chapter 3, Articles 12 to 23 of the General Data Protection Regulation (GDPR) which specifically deal with rights of the data subject.
Therefore, you have several rights in relation to how Apex Organisation uses your information. They are:
Right to be informed
You have a right to receive clear and easy to understand information on what personal information we have, why and who we share it with.
Right of access
You have the right of access to your personal information. If you wish to receive a copy of the personal information we hold on you, you may make a Data Subject Access Request (DSAR) by emailing Lida@nmdirect.co.uk
Right to request that your personal information be rectified
If your personal information is inaccurate or incomplete, you can request that it is corrected.
Right to be forgotten (request erasure)
You can ask for your information to be deleted or removed if there is not a compelling reason for us to continue to have it, for example, if you are an existing client and we need this information to contact you.
Right to restrict processing
You can ask that we block or suppress the processing of your personal information for certain reasons. This means that we are still permitted to keep your information – but only to ensure we don’t use it in the future for those reasons you have restricted.
Right to data portability
You can ask for a copy of your personal information for your own purposes to use across different services.
11. COOKIES AND IP ADDRESSES
11.1 In addition to asking you to submit personal information, we may collect information about you automatically when you visit the Website. This information is not normally personally identifiable. Such information includes general information about your computer settings, your connection to the internet (i.e. your Internet Service Provider), your IP address (this is the number assigned to your computer by a web server when you are on the internet), your geographical location, your operating system, your browsing patterns, the pages you visit and documents downloaded. We analyse such information in the aggregate and will not use it for the purpose of identifying you (except that we may use such information to identify a visitor if we consider that there are or may be safety or security issues or to comply with relevant laws and regulations).
11.2 We may collect this information through the use of software technology called “cookies”. Cookies are small bits of information which are sent to your computer’s hard drive when you first visit the Website, and which allow us to identify your computer the next time you visit the Website. We may use the information collected in this way to (i) identify what technologies and internet services are being used by our visitors and (ii) track usage of the Website so that we can adapt the Website to ensure that it better suits your needs and interests.
11.3 Up to date Internet browsers give you the option to reject, accept, or erase cookies stored on your computer or be notified before a cookie is stored on your computer. If you install or update your browser after May 2018 you will be given clear options on managing your cookies.
13. HOW CAN YOU RAISE A COMPLAINT?
If you think your personal data has been misused, please contact us by emailing Lida@nmdirect.co.uk with details. After an investigation, you will be notified of the results, including if no evidence of a security breach or misuse is discovered.
You always retain the right under Chapter 3, Article 17 of the GDPR to have any personal data held by NM Direct erased.
14. CONTACT DETAILS
For further information on any of the subjects covered in this document, please contact Lida Vasilakaki via email Lida@nmdirect.co.uk