Data protection and privacy policy

INTRODUCTION

This Company Privacy Policy (Data Protection) refers to our commitment to treat information of employees, customers and other parties with the utmost care and confidentiality.
With this policy, we ensure that we gather, store and handle data fairly, transparently and with respect towards individual rights.

POLICY

This policy refers to all parties whose data is made known to us.

This primarily includes:

  • Clients (who provide us with their own data)
  • End Users of services we provide on a contractual or non-contractual basis (whose data is forwarded to us)

This policy also applies to data we have regarding:

  • Employees
  • Other Contractors
  • Job Candidates
  • Suppliers

Employees of our company must follow this policy. Contractors, consultants, and any other external entity are also covered. Generally, our policy refers to anyone we collaborate with or acts on our behalf and to whom we may forward Data (such as names and addresses of Clients).

As part of our operations, we need to obtain and process information. This information includes any offline or online data that makes a person identifiable such as names, addresses, financial data etc. Our company is given this information in a transparent way and only with the full cooperation and knowledge of the concerned parties. Once this information is given to us, the following rules apply.

INFORMATION/DATA WE MAY HOLD (and reason):

  • Full Name
  • Address
  • Contact Number
  • Email Address
  • Type of Crime (if referred in relation to certain contractual services we provide)
  • Information regarding vulnerabilities, disabilities, circumstances which is relevant to the services we provide.

This information is necessary for us to provide our services and to keep a record of a works carried out. We need this for monitoring, analysis and reporting back to contracting authorities.

DATA PROTECTION LEGISLATION

Our Data Protection Policy and processes have been formulated in line with two main pieces of legislation:

  1. The EU General Data Protection regulation 2016 (also known as GDPR)
  2. The Data Protection Act 2018

WHO DO WE RECEIVE PERSONAL DATA FROM?

  1. From individuals themselves
  2. From family/friends or other known third party
  3. From one of the many contractual clients and their nominated/authorised agencies/bodies
    who refer into Secure Horizon to enable individuals to benefit from our service delivery.

HOW DO WE RECEIVE PERSONAL DATA?

On all contractual work we receive personal data primarily by secure mail (cjsm/egress/password protected files). We can also receive data via telephone.

The methodology/integrity of safe transfer of data is agreed upon between this company (data processor), contracting authorities and agencies/bodies involved in transferring data to us (data controllers).

WE WILL SHARE INFORMATION WITH THE FOLLOWING:

  • We may share personal Client’s personal data with other support bodies/agencies. We only do this with the Client’s consent.
  • We share data back with the contracting authority for reporting purposes.
  • We may have to share information if we are legally obliged to do so, for example where we have serious concerns about Client safety or that of a related person. In these cases, we would share the relevant information with safeguarding organisations (Social Services, the Police or any other Emergency Service) if they or anyone else is at risk of harm. We only share information when authorised by Management. We only share information where the law allows.

STORAGE OF DATA (Digital)

We are duty bound to store all data in a safe and secure manner.
Data is stored on our CRM. Our CRM provider has attained ISO-27001 standard.
Data is normally held for a period of six years unless stated otherwise by contracting authorities.

STORAGE OF DATA (Hard Copies)

This company does not record, compile, store or retain personal data in any hard copy format.

DATA WILL NOT BE:

  • Communicated informally.
  • Stored for more than a specified amount of time.
  • Distributed to any party other than the ones agreed upon by the data’s owner (exempting legitimate requests from law enforcement authorities or where Secure Horizon Management considers there to be a legitimate safety issue eg: safeguarding)

In addition to ways of handling the data the company has direct obligations towards people to
whom the data belongs.

CLIENTS RIGHTS RE INFORMATION WE HOLD

  • There are rights that individuals have which we are required by law to uphold such as the
    following: The right to be informed – how we will use personal information.
  • The right of access – how to access information we hold.
  • The right to rectification – request that information that is held is inaccurate or incomplete be rectified.
  • The right to erasure – requests that under special circumstance information held, may be
    removed or deleted if applicable.
  • The right to restrict processing – Block or suppress processing of information.
  • The right to data portability – Obtain and re-use information held about Client’s for their
    own purposes across different services if applicable.
  • The right to object to processing of information.
  • The right to withdraw consent where information is being processed based on that consent.
  • The right to lodge a complaint with the Information Commissioners Office.

DATA PROTECTION TRAINING

All Employees undergo both in-house and externally provided training. This forms part of the induction/on-boarding process for all recruits and takes place prior to any data access permissions. This training is appropriate for all members of staff.

External training is in the form of an online course including different modules and test (CPD certified; IIRSM approved).

This training enables staff to:

  • Understand the key terms used in data protection law.
  • Understand their responsibilities under the EU and UK GDPR and the Data Protection Act.
  • Have knowledge of the principles of data protection that all organisations must adhere to.
  • Understand the lawful grounds for processing personal information.
  • Understand how to obtain consent from data subjects.
  • Have an understanding of data subject rights, including access rights and the right to be forgotten.
  • Recognise the responsibilities of data controllers, data processors and data protection officers.
  • Understand how to ensure data security and report personal data breaches.
  • Be familiar with the consequences of non-compliance.

REFRESHER TRAINING

All training is diarised, and refresher training is carried out:

  • Every two years as a minimum
  • On an ad-hoc basis as necessary/relevant

NON-DISCLOSURE AGREEMENTS

All employees of Secure Horizon sign Non-Disclosure Agreements as a condition of being
offered employment. This also applies in the event of Secure Horizon using the services of any Sub-Contractor or any person acting in any way on the company’s behalf which may involve
access to data.

SOCIAL MEDIA

This company does not publish Client Data on social media.

Communications between Employees and Clients/Service-Users on social media is not permitted.

PHOTOS

Photos can be taken to show works progress (eg before and after photos/completions photos/parts verification photos).

These photos do not show individuals.

These photos are not published.

PROMOTIONS

This company periodically participates in promotional activities in relation to contractual works/launches/events. These promotional activities can include photographs/videos/news reports.

Involvement in these promotions only takes place with Management consent.

Employees must give their consent to be involved in these promotional activities.

Consent is needed from Clients/Service Users and before they or their homes/property are to be filmed/photographed/featured in any such promotions.

Signed consent is sought by either:

  • Media Outlet
  • Contracting Authority
  • Secure Horizon
  • Or other organiser of the promotion

DATA SECURITY BREACH PROCEDURES

In the event of data breach, the procedure is as follows:

Escalation – Any breach will immediately be brought to the attention of Management.

Investigation – What-Where-When-Who-Why-How. Investigation is carried out by Senior Management and involves those staff involved in the breach.

Report – Investigation will result in a Report. This will assess whether change of process is required or whether breach was due to process not being followed (human error).

Notification – Data Controller and persons affected by breach will be informed at the earliest opportunity. This will be done via email/telephone as appropriate. This will include details of breach and a timeframe for investigation.

Legal Compliance – This Company will comply with any legal or external investigation into the
breach.

Outcomes/Rectification/Next Steps – All concerned will be notified of investigation and rectification. Lessons learnt may result in change to process or staff re-training. If breach is found to be deliberate, staff member concerned will be subject to disciplinary procedures.

Adherence to this Policy
All principles described in this policy must be strictly followed.

Any breach of this policy and our data protection procedures will cause staff members to be subject to relevant disciplinary procedures.

Depending on severity, these procedures may include legal action.

Cyber Essentials
This company has Cyber Essentials accreditation. Accreditation relates to all devices and
server/s. Assessments are carried out and certification is renewed on an annual basis.

ICO
We are registered with the ICO (Information Commissioners Office)cReg Number: ZA156057

PRIVACY NOTICE

This company’s Privacy Notice is compliant with Data Protection Act 2018. It is renewed/reviewed and signed off on an annual basis by Company Director.

Our Privacy Notice is available to all parties upon request.