We respect your privacy and understand that privacy is important to you and that you care about how information about you is used, so this privacy notice sets out details about what data we collect and how we use it. It also explains how we’ll store and handle that data, and how we keep it safe.
We are Bright Blue Day Limited, a UK Limited Company number 4535919. Our Registered Office is at Parkway House, 26 Avenue Road, Bournemouth BH2 5SL.
In order to provide our services, we need to use and keep personal data about our customers and certain third parties. We are required to provide information about how we will use personal data, the safeguards to ensure that the personal data will not be used or shared inappropriately and an individual’s rights in respect of their personal data. An organisation that holds personal data and decides how it should be used is a controller. We will be a controller because we have to decide how to use the data to provide our services to our customers.
We have appointed a Data Protection Manager to oversee compliance with data protection. The Data Protection Manager is Stefan Brynard. Any enquiries about the personal data that we hold should be addressed to the Data Protection [Officer/Manager], Parkway House, 26 Avenue Road, Bournemouth BH2 5SL, by telephone at 01202 669090 or by email stefan.brynard@brightblueday.com.
The collection, use, sharing and storage of personal data are all termed “processing”.
There must be a legal basis for any processing, which we have set out below.
THE PURPOSE OF THE PROCESSING | THE LEGAL BASIS FOR THE PROCESSING |
If you are a customer, we will require personal data, particularly contact information, in order to discuss the services that you require and to provide the services. We will also need your personal data to carry out the administration of your account with us. The provision of our services may include communication with you, invoicing and for contractual purposes. | The data is necessary to perform the contract for services between us or to take steps prior to entering the contract. |
Where you contact us by email your email will be stored on Google servers and will only be accessible to our employees and our IT support partners. All emails are subject to virus scanning and junk mail filtering. | The data is necessary to perform the contract for services between us or to take steps prior to entering the contract. |
We will store the files or a copy of the files relating to a customer’s matter. | It is in our legitimate interests to retain files or a copy of files in order to deal with any queries that may arise after the services have been provided. |
Personal data may be collected on our CCTV system if you visit our offices and recorded in our visitor book at reception. If we occupy offices that have a centralised room booking system, your name may be recorded in that system. | It is in our legitimate interests to maintain the security of our premises. |
We may use your name, address, email address and telephone numbers for marketing purposes. | It is in our customer’s legitimate interests that the personal data of other parties or third parties to our customer’s services be processed. |
We may need to use data to comply with audit and statutory regulations. | The processing is necessary for compliance with a legal obligation to which we are subject.
|
We hold applicant information for recruitment vacancies. This may include address, personal email and personal telephone number, National Insurance number, previous employment details and next-of-kin details. | The data is necessary to consider the application for employment prior to making any offer of employment. You consent to us having the data. |
If you are directly engaged in employment with us, we may need personal data to: | |
| The various lawful bases upon which we will rely to process these situations are: Where it is necessary for the performance of a contract with you or in order to take steps prior to entering into a contract. Where there is a legal obligation which we have to comply with. Where is it necessary for our legitimate interests or the legitimate interests of us or a third party and your interests and fundamental rights do not override those interests. Where it is necessary to protect your vital interests (or someone else’s interests). Where it is necessary for reasons of substantial public interest. Where you have provided us with consent. |
Employee data is occasionally provided by third parties (for example from tax authorities or where we have received a reference as part of a recruitment process). Data is stored in both local and third-party cloud-based systems. | The data is necessary to consider the application for employment prior to making any offer of employment. You consent to us having the data. |
We may be acting as a processor and processing your data on behalf of another business/organisation. | We process the data on the instruction of the controller. |
We may need to provide personal data to other people in order to provide our services to our customers. The recipients of such data may include:
Where appropriate, with experts, we will enter into a Data Sharing Agreement with them to ensure that the data is protected.
We may use other external service providers for IT, fileshare and communication services. We use external service providers to take card payments. All our external service providers are required to take appropriate security measures to protect your data.
In most cases, there will be no need to transfer your personal data to a country outside the UK.
If there is a need to transfer your personal data outside the UK, we will ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
If there are no appropriate safeguards in place, we may transfer data outside the UK where the transfer is necessary for:
Customer data (which might include third party data) will be kept until the completion of the provision of the services for which it was collected. Once the services have been fully provided, we will keep our files and that data for as long as is necessary to fulfil the purposes of satisfying any legal, accounting or regulatory requirements and, where necessary, as long as is required for us to assert or defend legal claims. Customer data is stored both locally and on cloud-based systems and in most instances will be retained by us for a period of 6 years following the cessation of trade with a customer.
Recruitment applications will be retained for seven months by our HR Team.
Other personal data collected for recruitment purposes is stored both locally and on cloud-based systems and is retained for no longer than for 12 months from receipt.
CCTV images are kept for 30 days, at which point they are overwritten unless there has been a security incident in which case the images will be kept until such time as the incident has been investigated and any necessary action has been taken.
Visitor information in our visitor book is kept for a 2-year period.
Personal data will be kept on HubSpot for a period of 12 months unless you withdraw your consent earlier.
We will keep any data that we hold for marketing purposes whilst we have your consent to do so.
Where we have acted as a processor we return the data to the controller upon completion of their instructions.
If we ask for your consent to use your personal data for marketing purposes, you have the right to withdraw your consent at any time. The form of consent and a subsequent marketing communication will tell you how to withdraw your consent. In addition, you can withdraw consent by email to hello@brightblueday.com.
The withdrawal of consent will not affect our provision of our services in any way.
Under certain circumstances, you have the right to:
If you want to review, verify, correct or request erasure of your personal information, object to the processing of your personal data, or request that we transfer a copy of your personal information to another party, please contact us by writing to Data Protection Manager, Parkway House, 26 Avenue Road, Bournemouth BH2 5SL or by email to stefan.brynard@brightblueday.com.
Prior to actioning your request, we may ask you to validate your identity and we will only carry out any request by you when we are satisfied that we have validated your identity appropriately.
If you are dissatisfied with the way in which we have dealt with your personal data, you have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues.
Telephone number: 0303 123 1113.
Website address:Â https://ico/org.uk