At BBT Group Ltd we are committed to protecting and respecting your privacy. We are the data controller and will process your personal data in accordance with the Data Protection Act 2018, Regulation (EU) 2016/679 (the “GDPR”) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended from time to time as well as and any national laws which relate to the processing of personal data (“data protection legislation”).
Please read the following carefully to understand our views and practices regarding Your Data and how we will treat it.
- This policy applies to information we collect about:
- Visitors to our website
VISITORS TO OUR WEBSITE
We may collect and process personal data about you in the following circumstances:
when you complete the online contact forms on our website (“Site”) providing us with your name, address, email address and contact number;
whenever you provide information to us when reporting a problem with our Site, making a complaint, making an enquiry or contacting us for any other reason. If you contact us, we may keep a record of that correspondence;
when you visit our Site we will retain details such as traffic data, location data, weblogs and other communication data, and the resources that you access (see section 2.2.2 on Cookies below); and
whenever you disclose your information to us, or we collect information from you in any other way, through our Site.
We may also collect data in the following ways:
We may collect information about your device, including where available your Internet Protocol address, for reasons of fraud protection. We may also collect information about your device’s operating system and browser type, for system administration and to report aggregate information to our advertisers. This is statistical data about our users’ browsing actions and patterns, and does not identify any individual.
BBT Group Ltd is the Operator and Copyright Holder respectively of our Site. BBT Group Ltd uses technology to collect information about the use of the Site in order to improve your experience when you browse the Site.
Analytical/Performance Cookies – These Cookies collect information in an anonymous form about how visitors use our Site. They allow us to recognise and count the number of visitors and to see how visitors move around the site when they are using it.
You should note that by deleting or blocking Cookies, the Site may not function correctly and you may not be able to access certain areas. The Site uses Google Analytics, a web analytics service provided by Google, Inc. Goggle Analytics sets a number of Cookies (default is 4) in order to evaluate your use of the Site and compile reports for us on activity on the site.
Google stores the information collected by the Cookie on servers in the United States. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on behalf of Google. Google will not associate your IP address with any other data held by Google.
Google Inc are members of the US Safe Harbour Scheme. This scheme allows the transfer of data from within the EEA to countries that are outside of the EEA without having to enter into a specific data transfer agreement. Companies that sign up to the scheme are deemed to provide adequate protection for personal data transmitted from Europe. The Google Inc registration is at http://safeharbor.export.gov/companyinfo.aspx?id=10543
We may use your personal data for our legitimate interests in order to:
provide you with information, or services that you requested from us;
respond to an enquiry submitted via our online contact forms;
allow you to participate in interactive features of our Site, when you choose to do so;
ensure that content from our Site are presented in the most effective manner for you and for your device;
improve our Site and services;
process and deal with any complaints or enquiries made by you; and
contact you for marketing purposes where you have signed up for these (see section 5 for further details).
Our Site may, from time to time, contain links to and from the website of third parties. Please note that if you follow a link to any of these websites, such websites will apply different terms to the collection and privacy of your personal data and we do not accept any responsibility or liability for these policies. Please check before you submit your information to these websites.
We will collect details such as name, address, email address, contact number, date of birth, national insurance number and financial information in order to provide services to clients. We may also receive details of credit checks undertaken where you have supplied these to us.
We will share client personal information with our employees to manage our relationship with you and we will retain Client personal data for 80 years.
We will use your personal data provided to comply with our contractual obligations arising from the agreements we enter into with our Clients and share the data with financial institutions who can assist in the provision of financial services to Clients including professional compliance, accountancy or legal services as well as product providers, lenders, banks, insurers, fund managers, platform providers and third party para-planners. Where third parties are involved in processing your data we’ll have a contract in place with them to ensure that the nature and purpose of the processing is clear, that they are subject to a duty of confidence in processing your data and that they’ll only act in accordance with our written instructions.
Where it’s necessary for your personal data to be forwarded to a third party we’ll use appropriate security measures to protect your personal data in transit such a secure file share systems to ensure the security of data during transfer.
To fulfil our obligations in respect of prevention of money-laundering and other financial crime we may send your details to third party agencies for identity verification purposes.
We will use Client personal data for our legitimate interests including:
with your consent, marketing our other products and services by mail, email, phone and text; and
with your consent, obtaining your sensitive personal data from third parties including your health, ethnic origin, or criminal prosecutions from third parties such as employers and credit reference agencies, fraud prevention agencies and other similar organisations.
We may use Client personal data to provide you with details about our services, products, business updates and events which we think may be of interest. We will only send you marketing correspondence where you have given us your consent to do so.
You have the right to opt-out of receiving the information detailed in section 5.1 at any time. To opt-out of receiving such information you can:
tick the relevant box situated in the form on which we collect your information;
clicking the unsubscribe button contained in any such communication received; or
email us at email@example.com or call 01924 231400 providing us with your name and contact details. It may take up to 7 days for this to take place.
Where you have subscribed to receive marketing correspondence from us we will keep your personal data for 80 years from when you subscribed to receiving marketing information from us or until you unsubscribe from receiving such correspondence from us (whichever is earlier).
LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA
In accordance with data protection legislation we are required to notify you of the legal basis upon which we process your personal data. We process your personal data for the following reasons:
for performance of a contract we enter into with you;
where necessary for compliance with a legal obligation we are subject to; and
for our legitimate interests (as described within this policy).
We will also process your personal data including personal sensitive data where we have obtained your explicit consent.
DISCLOSURE OF YOUR DATA to third parties
In addition to the third parties mentioned previously in this policy, we may disclose your personal data to third parties for the following legitimate business purposes:
staff members in order to facilitate the provision of services to you;
IT software providers that host our website and store data on our behalf;
Service providers who provide us with software solutions and platforms in order to carry out our business and provide services (including, without limitation, open banking services) and
to a prospective buyer of some or all of our business or assets, in which case personal data including Your Data will also be one of the transferred assets. The recipient of the information will be bound by confidentiality obligations.
We only allow our service providers to handle your personal information if we are satisfied they take appropriate measures to protect your personal information. We also impose contractual obligations on service providers to ensure they can only use your personal information to provide services to us and to you. We may also share personal information with external auditors, eg in relation to ISO accreditation and the audit of our accounts.
We may disclose your personal data to the police, regulatory bodies, legal advisors or similar third parties where we are under a legal duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our agreements; or to protect our rights, property, or safety of our Clients, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
We will not sell or distribute your personal data to other organisations without your approval.
CROSS-BORDER DATA TRANSFERS
We share your personal data with external third parties in order to provide our services to you. Some of these third parties may transfer personal data outside the United Kingdom. We require such third parties to ensure that such transfers take place in accordance with data protection legislations.
Whenever we transfer your personal data out of the United Kingdome, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
* We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission;
* Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe;
* Where we use providers based in the US, we may transfer data to them if they are registered as being part of the Privacy Shield which requires them to provide similar protection to personal data shared between Europe and the US.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the United Kingdom.
Information you provide to us is shared on our secure servers. We have implemented appropriate physical, technical and organisational measures designed to secure your information against accidental loss and unauthorised access, use, alteration or disclosure. In addition, we limit access to personal data to those employees, agents, contractors and other third parties that have a legitimate business need for such access. We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security where we are legally required to do so.
Where we have given you (or where you have chosen) a password which enables you to access certain parts of our Site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your information transmitted to our Site; any transmission is at your own risk. If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
ACCESS TO, UPDATING, DELETING AND RESTRICTING USE OF YOUR DATA
It is important that the personal data we hold about you is accurate and current. Please keep us informed if the personal data we hold about you changes.
Data protection legislation gives you certain rights in relation to your personal data. You have the right to object to the processing of your personal data in certain circumstances and to withdraw your consent to the processing of your personal data where this has been provided.
You can also ask us to undertake the following:
update or amend your personal data if you feel this is inaccurate;
remove your personal data from our database entirely;
send you copies of your personal data in a commonly used format and transfer your information to another entity where you have supplied this to us, and we process this electronically with your consent or where necessary for the performance of a contract;
restrict the use of your personal data; and
provide you with access to information held about you and for this to be provided in an intelligible form.
We may request specific information from you to help us confirm your identity. Data protection legislation may allow or require us to refuse to provide you with access to some or all the personal data that we hold about you or to comply with any requests made in accordance with your rights referred to above. If we cannot provide you with access to your personal data, or process any other request we receive, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
Please send any requests relating to the above to our Privacy Officer at firstname.lastname@example.org specifying your name and the action you would like us to undertake.
RIGHT TO WITHDRAW CONSENT
Where you have provided your consent to the collection, processing and transfer of your personal data, you may withdraw that consent at any time. This will not affect the lawfulness of data processing based on consent before it is withdrawn. To withdraw your consent please contact us at email@example.com
BBT Group Ltd
2 Benton Office Park
This is in addition to your right to contact the Information Commissioners Office, if you are unsatisfied with our response to any issues you raise, at https://ico.org.uk/global/contact-us/
Information Commissioner’s Office
0303 123 1113 (local rate)
Last updated: 28 September 2020