Data Protection Policy
Purpose
This document sets out CDR Training Ltd.’s policy on data protection. It provides an overview of data protection requirements. If you have any questions relating to this policy, please contact Nicola Edwards nicki@cdr-training.co.uk
Data Protection Principles
The legislation is underpinned by a set of six straightforward principles, which define how data can be legally processed.
These six principles are:
- Personal data shall be processed fairly, lawfully and transparently.
- Personal data shall be held only for one or more specified and lawful purposes and shall not be further processed in any manner incompatible with that purpose or purposes. There is an exemption for research data.
- Personal data shall be adequate, relevant and not excessive in relation to the purpose for which it is processed.
- Personal data shall be accurate and where necessary kept up to date.
- Personal data processed for any purpose shall not be kept for longer than is necessary for that purpose. There is an exemption for research data.
- Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of the data.
We promise to follow the following data protection principles:
- Processing is lawful, fair, transparent. Our Processing activities have lawful grounds. We always consider your rights before Processing Personal Data. We will provide information regarding Processing upon request.
- Processing is limited to the purpose. Our Processing activities fit the purpose for which Personal Data was gathered.
- Processing is done with minimal data. We only gather and Process the minimal amount of Personal Data required for any purpose.
- Processing is limited with a time period. We will not store personal data for longer than needed.
- We will do our best to ensure the accuracy of data.
- We will do our best to ensure the integrity and confidentiality of data.
Data Subject’s rights
The GDPR also sets out rights of data subjects relating to their personal data. These rights include:
- the right to access
- the right to rectification
- the right to erasure (in certain circumstances)
- the right to stop processing
- the right to portability (in certain circumstances)
- the right to object to marketing. and
- the right to have human intervention with regards to automated processing, including profiling
The Data Subject has the following rights:
- Right to information – meaning they have the right to know whether their Personal Data is being processed; what data is gathered, from where it is obtained and why and by whom it is processed.
- Right to access – meaning they have the right to access the data collected from/about them. This includes the right to request and obtain a copy of any Personal Data gathered about them.
- Right to rectification – meaning they have the right to request rectification or erasure of their Personal Data that is inaccurate or incomplete.
- Right to erasure – meaning in certain circumstances they can request for their Personal Data to be erased from CDR Training Ltd.’s records.
- Right to restrict processing – meaning where certain conditions apply, they have the right to restrict the Processing of their Personal Data.
- Right to object to processing – meaning in certain cases they have the right to object to Processing of their Personal Data, for example in the case of direct marketing.
- Right to object to automated Processing – meaning they have the right to object to automated Processing, including profiling; and not to be subject to a decision based solely on automated Processing. This right they can exercise whenever there is an outcome of the profiling that produces legal effects concerning or significantly affecting them.
- Right to data portability – they have the right to obtain their Personal Data in a machine-readable format or if it is feasible, as a direct transfer from one Processor to another.
- Right to lodge a complaint – in the event that we refuse their request under the Rights of Access, CDR Training Ltd will provide them with a reason as to why. If they are not satisfied with the way their request has been handled, please contact CDR Training Ltd.
- Right for the help of supervisory authority – meaning they have the right for the help of a supervisory authority and the right for other legal remedies such as claiming damages.
- Right to withdraw consent – they have the right withdraw any given consent for Processing of their Personal Data
Data we gather
Information provided by the data subject
This may be an e-mail address, name, telephone number, date of birth – mainly information that is necessary for delivering a service or to enhance customer experience with us.
Information automatically collected about the data subject
This includes information that is automatically stored by cookies and other session tools. This information is used to improve customer experience. Activities may be logged when looking at the contents of our website
Information from our partners
Information is gathered from our trusted partners with confirmation that they have legal grounds to share that information with us. This is either information provided to them directly that they have gathered about the data subject on other legal grounds.
Publicly available information
We might gather information about the data subject that is publicly available.
Data Sources (places we gather data)
- Phone
Data Comes From: Customer bookings & customer enquiries
Data Collected: name, contact number, business addresses (we do not share this data information)
How We Use the Data: to process customer bookings, to offer products and services relevant to the customer via email, text and phone.
Data Shared With: contact number & email address shared with Yell.com when sending a text message request for an online review - Email
Data Comes From: Customer bookings & customer enquiries
Data Collected: Names, Addresses, Emails, Contact Numbers, Booking Information
How We Use the Data: to process customer bookings, to offer products and services relevant to the customer via email, text and phone.
Data Shared With: contact number & email address shared with Yell.com when sending a text message request for an online review - Website
Data Comes From: We gather data on customers browsing habits, we take customers name, phone number, email when taking a booking, we also gather email addresses sent to us via customer enquiries on our website
Data Collected: Names, Addresses, Emails, Contact Numbers, Booking Information
How We Use the Data: to process customer bookings, to offer products and services relevant to the customer via email, text and phone.
Data Shared With: Google to monitor website traffic
- Training Inhouse Certification
Data Collected: Trainee names, date of birth, email addresses, telephone numbers, health declaration and passport style photograph (if operator ID cards are required by the client)
How We Use the Data: The information is entered onto a certificate database for issuing of certification and course report sheets and then stored in a locked filing cabinet at the office of CDR Training Ltd, as proof if required of accredited training records. We use the email addresses, contact numbers to request on line reviews from each trainee.
Data Is Shared With: Training data is shared with the customer/trainees’ employer - Training RTITB Certification
Data Collected: Trainee Names, date of birth, email addresses, telephone numbers, health declaration and passport style photograph (if operator ID cards are required by the client)
How We Use the Data: The information is entered onto the National Operators Registration Scheme for RTITB Accredited Training and then stored in a locked filing cabinet at the office of CDR Training Ltd, as proof if required of accredited training records. We use the email addresses, contact numbers to request on line reviews from each trainee.
Data Is Shared With: RTITB for accredited training documentation you see the RTITB privacy policy by clicking here
How we use Personal Data
We use Personal Data to:
- provide our service to our clients. This includes for example providing you with information on other products and services as requested; providing promotional items, communicating in relation to those products and services; communicating and interacting with the data subject and notifying them of changes to any services.
- enhance the customer experience;
- fulfil an obligation under law or contract;
We use Personal Data on legitimate grounds and/or with your Consent.
On the grounds of entering into a contract or fulfilling contractual obligations, we process Personal Data for the following purposes:
identification
- to provide a service or to send/offer a product;
- to communicate either for sales or invoicing;
On the ground of legitimate interest, we process Personal Data for the following purposes:
- to send personalised offers;
- to administer and analyse our client base (purchasing behaviour and history) to improve the quality, variety, and availability of products/ services offered/provided;
- to conduct questionnaires concerning client satisfaction;
If we have not been informed otherwise, we consider offering products/services that are similar or same to your purchasing history/browsing behaviour to be our legitimate interest.
With your consent we process Personal Data for the following purposes:
- to send newsletters and campaign offers;
- for other purposes we have asked your consent for;
Personal Data is processed in order to fulfil obligation rising from law and/or use Personal Data for options provided by law. We reserve the right to anonymise Personal Data gathered and to use any such data. We will use data outside the scope of this policy only when it is anonymised. We save billing information and other information gathered for as long as needed for accounting purposes or other obligations deriving from law, but not longer than 6 years.
We might process Personal Data for additional purposes that are not mentioned here but are compatible with the original purpose for which the data was gathered. To do this, we will ensure that:
- the link between purposes, context and nature of Personal Data is suitable for further processing;
- the further processing would not harm the data subject’s interests and there would be appropriate safeguard for processing.
We will inform data subjects of any further Processing and purposes.
Who else can access Personal Data
We do not share Personal Data with strangers. Personal Data is in some cases provided to RTITB to either make providing the accredited training services possible or to enhance customer experience.
We share your data with:
Our processing partners
RTITB – To store data to provide accredited certification and registration on their national database
Our business partners:
RTITB – To store data to provide accredited certification and registration on their national database
Connected third parties:
RTITB – To store data to provide accredited certification and registration on their national database
Google – Google Analytics Tracking Code that logs details about the visitor’s browser and computer.
Facebook – used to promote CDR Training Ltd and allow its customer to give feedback
Twitter – used to promote CDR Training Ltd and allow its customer to give feedback
LinkedIn – used to promote CDR Training Ltd and allow its customer to give feedback
indeed.co.uk – used to offer work opportunities to visitors of our website
We only work with processing partners who are able to ensure adequate level of protection of Personal Data. We disclose Personal Data to third parties or public officials when we are legally obliged to do so. We might disclose Personal Data to third parties if they have consented to it or if there are other legal grounds for it.
How we secure your data
We do our best to keep Personal Data safe. We use safe protocols for communication and transferring data (such as HTTPS). We use anonymising and pseudonymising where suitable. We monitor our systems for possible vulnerabilities and attacks.
Even though we try our best we cannot guarantee the security of information. However, we promise to notify suitable authorities of data breaches. We will also notify the data subject if there is a threat to your rights or interests. We will do everything we reasonably can to prevent security breaches and to assist authorities should any breaches occur.
Children
We do not intend to collect or knowingly collect information from children. We do not target children with our services.
Cookies and other technologies we use
We use cookies and/or similar technologies to analyse customer behaviour, administer the website, track users’ movements, and to collect information about users. This is done to personalise and enhance customer experience with us.
A cookie is a tiny text file stored on your computer. Cookies store information that is used to help make sites work. Only we can access the cookies created by our website, however users of our site can control cookies at the browser level. Choosing to disable cookies may hinder the use of certain functions.
We use cookies for the following purposes:
Functionality cookies – these cookies provide functionality that makes using our service more convenient and makes providing more personalised features possible. For example, they might remember name and e-mail addresses in comment forms
Analytics cookies – these cookies are used to track the use and performance of our website and services
Advertising cookies – these cookies are used to deliver advertisements that are relevant to the user and to their interests. In addition, they are used to limit the number of times an advertisement is seen. They are usually placed on the website by advertising networks with the website operator’s permission. These cookies remember that the users have visited a website and this information is shared with other organisations such as advertisers. Often targeting or advertising cookies will be linked to site functionality provided by the other organisation.
You can remove cookies stored in your computer via your browser settings.
Alternatively, you can control some 3rd party cookies by using a privacy enhancement platform such as optout.aboutads.info or youronlinechoices.com. For more information about cookies, visit allaboutcookies.org.
We use Google Analytics to measure traffic on our website. Google have their own Privacy Policy which can be review here. If you’d like to opt out of tracking by Google Analytics, visit the Google Analytics opt-out page.
In the Event Data Is Lost
When we are aware that data loss has been encountered Nicola Reid shall be in contact within 24 hours after the incident to advise that data has been lost, and the manner in which it was lost. CDR Training Ltd shall also ensure that following data loss it conducts a review of the systems that led to the loss.
Contact Information
If you have any questions regarding the Processing of Personal Data, rights regarding Personal Data or this Privacy Policy, contact Nicola Edwards at nicki@cdr-training.co.uk
Supervisory Authority
Email: casework@ico.org.uk
Phone: 0303 123 1113
