GDPR PRIVACY NOTICE – PUBLISHED 23/05/18
Team Rewards Limited, Crewe Hall, Weston Road, Crewe, Cheshire, CW1 6UY
Team Rewards Limited collects and processes personal information, or personal data, relating to its customers to manage the working relationship. Team Rewards Limited is committed to being transparent about how it handles your personal information, to protecting the privacy and security of your personal information and to meeting its data protection obligations under the General Data Protection Regulation (“GDPR”) and the Data Protection Act 2018. The purpose of this privacy notice is to make you aware of how and why we will collect and use your personal information.
This privacy notice applies to all current and former customers. It is non-contractual and does not form part of any contract, agreement, consultancy agreement or any other contract for services.
Team Rewards Limited is not required to appoint a data protection officer to oversee compliance with this privacy notice. If you have any questions about this privacy notice or about how we handle your personal information, please contact the Managing Director at the above Head Office address.
Data protection principles
Under the GDPR, there are six data protection principles that Team Rewards Limited must comply with. These provide that the personal information we hold about you must be:
- Processed lawfully, fairly and in a transparent manner. 2. Collected only for legitimate purposes that have been clearly explained to you and not further processed in a way that is incompatible with those purposes. 3. Adequate, relevant and limited to what is necessary in relation to those purposes. 4. Accurate and, where necessary, kept up to date. 5. Kept in a form which permits your identification for no longer than is necessary for those purposes. 6. Processed in a way that ensures appropriate security of the data.
Team Rewards Limited is responsible for, and must be able to demonstrate compliance with, these principles.
What types of personal information do we collect about you?
Personal information is any information about an individual from which that person can be directly or indirectly identified. It doesn’t include anonymised data, i.e. where all identifying particulars have been removed.
Team Rewards Limited collects, uses and processes a range of personal information about you. This includes:
- your contact details, including your name, telephone number and personal e-mail address
- History of sales made to you and payments made by you
How do we collect your personal information?
Team Rewards Limited may collect personal information about you in a variety of ways.
Whilst some of the personal information you provide to us is mandatory and/or is a statutory or contractual requirement, some of it you may be asked to provide to us on a voluntary basis. We will inform you whether you are required to provide certain personal information to us or if you have a choice in this.
Your personal information may be stored in different places, including in IT systems, as well as our e-mail system.
Why and how do we use your personal information?
We will only use your personal information when the law allows us to. These are known as the legal bases for processing. We will use your personal information in one or more of the following circumstances:
- where we need to comply with a legal obligation
- where it is necessary for our legitimate interests (or those of a third party), and your interests or your fundamental rights and freedoms do not override our interests.
The purposes for which we are processing, or will process, your personal information are to:
- enable us to maintain accurate and up-to-date customer records and contact details
- comply with statutory and/or regulatory requirements and obligations
- administer a contract we have entered into with you
- operate and maintain a record of performance management systems
- meet our obligations under health and safety laws
- ensure adherence to rules, policies and procedures
- enable us to establish, exercise or defend possible legal claims
Please note that we may process your personal information without your consent, in compliance with these rules, where this is required or permitted by law.
Why and how do we use your sensitive personal information?
We will only collect and use your sensitive personal information when the law allows us to.
Change of purpose
We will only use your personal information for the purposes for which we collected it. If we need to use your personal information for a purpose other than that for which it was collected, we will provide you, prior to that further processing, with information about the new purpose, we will explain the legal basis which allows us to process your personal information for the new purpose and we will provide you with any relevant further information. We may also issue a new privacy notice to you.
Who has access to your personal information?
Your personal information may be shared internally within the company, including with members of the accounts and finance department, your account manager and IT staff if access to your personal information is necessary for the performance of their roles.
Team Rewards Limited may also share your personal information with third-party service providers (and their designated agents), including:
- external IT services • service suppliers • professional advisers
We may share your personal information with third parties where it is necessary to administer any contract we have entered into with you, where we need to comply with a legal obligation, or where it is necessary for our legitimate interests (or those of a third party).
How does Team Rewards Limited protect your personal information?
Team Rewards Limited has put in place measures to protect the security of your personal information. It has internal policies, procedures and controls in place to try and prevent your personal information from being accidentally lost or destroyed, altered, disclosed or used or accessed in an unauthorised way. In addition, we limit access to your personal information to those employees, workers, agents, contractors and other third parties who have a business need to know in order to perform their job duties and responsibilities. You can obtain further information about these measures by writing to the Managing Director.
Where your personal information is shared with third-party service providers, we require all third parties to take appropriate technical and organisational security measures to protect your personal information and to treat it subject to a duty of confidentiality and in accordance with data protection law. We only allow them to process your personal information for specified purposes and in accordance with our written instructions and we do not allow them to use your personal information for their own purposes.
Team Rewards Limited also has in place procedures to deal with a suspected data security breach and we will notify the Information Commissioner’s Office (or any other applicable supervisory authority or regulator) and you of a suspected breach where we are legally required to do so.
For how long does Team Rewards Limited keep your personal information?
Team Rewards Limited will only retain your personal information for as long as is necessary to fulfil the purposes for which it was collected and processed.
Your rights in connection with your personal information
It is important that the personal information we hold about you is accurate and up to date. Please keep us informed if your personal information changes, e.g. you change your address, during your working relationship with Team Rewards Limited so that our records can be updated. Team Rewards Limited cannot be held responsible for any errors in your personal information in this regard unless you have notified Team Rewards Limited of the relevant change.
As a data subject, you have a number of statutory rights. Subject to certain conditions, and in certain circumstances, you have the right to:
- request access to your personal information – this is usually known as making a data subject access request and it enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it • request rectification of your personal information – this enables you to have any inaccurate or incomplete personal information we hold about you corrected • request the erasure of your personal information – this enables you to ask us to delete or remove your personal information where there’s no compelling reason for its continued processing, e.g. it’s no longer necessary in relation to the purpose for which it was originally collected • restrict the processing of your personal information – this enables you to ask us to suspend the processing of your personal information, e.g. if you contest its accuracy and so want us to verify its accuracy • object to the processing of your personal information – this enables you to ask us to stop processing your personal information where we are relying on the legitimate interests of the business as our legal basis for processing and there is something relating to your particular situation which makes you decide to object to processing on this ground • data portability – this gives you the right to request the transfer of your personal information to another party so that you can reuse it across different services for your own purposes.
If you wish to exercise any of these rights, please contact our Managing Director who will provide you with a Data Access Request Form. We may need to request specific information from you in order to verify your identity and check your right to access the personal information or to exercise any of your other rights. This is a security measure to ensure that your personal information is not disclosed to any person who has no right to receive it.
In the limited circumstances where you have provided your consent to the processing of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. This will not, however, affect the lawfulness of processing based on your consent before its withdrawal. If you wish to withdraw your consent, please contact our Managing Director. Once we have received notification that you have withdrawn your consent, we will no longer process your personal information for the purpose you originally agreed to, unless we have another legal basis for processing.
If you believe that Team Rewards Limited has not complied with your data protection rights, you have the right to make a complaint to the Information Commissioner’s Office (ICO) at any time.
Transferring personal information outside the European Economic Area
Team Rewards Limited will not transfer your personal information to countries outside the European Economic Area without your prior written consent.
Changes to this privacy notice
Team Rewards Limited reserves the right to update or amend this privacy notice at any time, including where Team Rewards Limited intends to further process your personal information for a purpose other than that for which the personal information was collected or where we intend to process new types of personal information. We will issue you with a new privacy notice when we make significant updates or amendments. We may also notify you about the processing of your personal information in other ways.
If you have any questions about this privacy notice or how we handle your personal information, please contact our Managing Director.