Privacy Notice
1. General
EQUA DESIGN LTD (“we” or “us”) takes the privacy of your information very seriously. Our Privacy Notice is designed to inform you, the user of our services, about our practices regarding the collection, use and disclosure of personal information which may be provided to us in person, over the phone, via our websites, associated apps and other platforms, or collected through other means.
This notice applies to personal data provided by our customers and their families, or our potential customers. In this notice, “you” refers to any individual whose personal data we hold or process (other than our staff).
In this notice, references to the “Site” are references to our website.
This notice is governed by the UK General Data Protection Regulation (UK GDPR).
2. The Basis on Which We Process Personal Data
Personal data we hold about you will be processed because:
- The processing is necessary for the pursuit of a “legitimate interest”. A legitimate interest in this context means a valid interest we have, or a third party has, in processing your data which is not overridden by your interests in data privacy and security;
- You have consented to the processing for the specific purposes described in this notice;
- The processing is necessary for us to comply with our obligations under a contract between you and us.
3. Personal Data We Process, Purpose and Legal Basis
We have explained below the personal data we may process and in each case the reason we process that data and the legal basis we are relying on:
Set Up Information
Information you provide when setting up an account with us.
We process this information based on our legitimate interest in obtaining the necessary information to provide our services.
Account Information
Information you provide relating to your account with us.
We process this information to monitor and administer your account based on our contract with you.
Services Information
Information relating to call-outs or orders you have placed with us, including products and services ordered.
We process this information to provide our services to you based on our contract with you.
Payment Information
Information provided relating to payment.
Please note that credit or debit card information may be supplied directly to a third-party payment processor.
Communication Information
A record and details of any correspondence or communication between you and us or relating to any complaint submitted to us.
Technical Information
Details of your visits to the Site, the resources and pages that you access and any searches you make.
Marketing Information
Information we may hold about you for marketing purposes.
We will not collect any sensitive personal data without your prior consent. By sensitive personal data, we mean data which falls within certain ‘special categories’ as defined under the UK GDPR.
4. Cookies and IP Address
A cookie is a piece of data stored locally on your computer and contains information about your activities on the Internet. The information in a cookie does not contain any personally identifiable information you submit to our Site.
On our Site, we use cookies to track users’ progress, allowing us to make improvements based on usage data. We also use cookies if you log in to one of our online services to enable you to remain logged in.
Once you close your browser, our access to the cookie terminates. You have the ability to accept or decline cookies.
We are required to obtain your consent to use cookies. We will obtain this consent through a notification banner when you first visit the Site.
An Internet Protocol (IP) address is a number assigned to your computer by your Internet Service Provider (ISP). We may use your IP address to diagnose problems with our server and administer the Site.
5. Data Retention
Our current data retention policy is to delete or destroy the personal data we hold about you in accordance with the following:
- Records relevant for tax purposes: 8 years from the end of the tax year to which the records relate.
- Personal data processed in relation to a contract: 7 years from either the end of the contract or the date you last used our services.
- Personal data held on marketing or business development records: 3 years from the last date on which you have interacted with us.
6. Sharing Your Information
We do not disclose any personal data you provide to any third parties other than:
- Payment information may be processed by our payment partners;
- We may provide information such as your name, location and relevant property details to our independent contractors who are engaged to deliver services to you;
- We may host personal data with third-party hosting providers;
- Certain third-party suppliers, including IT technical support providers, may have access to personal data;
- Where we are under a duty to disclose or share your personal data in order to comply with any legal obligation;
- In order to enforce any terms and conditions or agreements for our services;
- If we transfer part or all of our business to a third party;
- To protect our rights, property and safety, or the rights, property and safety of our users or other third parties.
7. Email and Other Communications
If you have placed an order for services with us, we may from time to time contact you about similar goods or services.
We may also contact you with information about our services if you have expressly consented to receive such communications.
You can opt out of receiving marketing communications from us at any time.
8. Security
We take all reasonable steps to ensure that appropriate technical and organisational measures are carried out in order to safeguard the information we collect from you. These measures include:
- Protecting our servers with firewalls;
- Locating our data processing storage facilities in secure locations;
- Encrypting all data stored on our servers;
- Ensuring that all communication with our servers is encrypted through Secure Sockets Layer (SSL);
- Regularly backing up and encrypting all data we hold.
9. Your Privacy Rights
Under the UK GDPR, you have the following rights:
- The right to be informed;
- The right of access (Subject Access Request – SAR);
- The right to correction;
- The right to erasure;
- The right to restrict processing;
- The right to data portability;
- The right to object (including to direct marketing);
- The right to withdraw consent at any time where consent is relied upon.
10. Data Breaches
If personal data we hold about you is subject to a breach or unauthorised disclosure or access, we will report this to the Information Commissioner’s Office (ICO) where legally required.
If a breach is likely to result in a risk to your rights and freedoms, we will notify you as soon as possible.
11. Contact
All requests or notifications in respect of your privacy rights must be sent to:
EQUA DESIGN LTD
Email: support@equadesign.co.uk
Phone: 020 8839 0080