- H & E Smith Ltd are committed to the protection of the private data you provide us with and we store from you and respect your rights under the General Data Protection Regulation.
The origin of our data
- We only gather information from customers for schedule and financial purposes either when an order is placed or for the purposes of generating an invoice for products provided.
- When someone visits www.hesmith.co.uk we use a third party service, Google Analytics, to collect standard internet log information and details of visitor behaviour patterns. We do this to find out things such as the number of visitors to the various parts of the site. This information is only processed in a way which does not identify anyone. We do not make, and do not allow Google to make, any attempt to find out the identities of those visiting our website.
The processing of your data
- Your data will be used by us for transaction data and may be used for the financial records and will be kept for 6 years (such as VAT invoices).
- Your data will be used by us for correspondence data (H & E Smith Ltd may contact you by telephone or e-mail to provide you with updates on the products or services you have requested or to send you a written quote. The legal grounds for processing of the correspondence data is the legitimate interest we have to perform a service, requested by you from us.
Sharing your details
- H & E Smith Ltd does not share your private data with any other third party other than the necessary amount of data for purposes of completing orders to suppliers and delivery companies.
How we store your data
This section sets out the ways in which H & E Smith Ltd store your private data and for how long.
- We store our correspondence/schedule data for the maximum term requested by HMRC for the legitimate purpose of keeping a record of the products and services we provide to you.
- Your private data may also be stored electronically on our UK based servers. Our computers are password protected and have up to date anti-virus software installed. They can only be accessed internally by our staff members.
- Your private data may be printed and secured in our own filing system. Paperwork is stored in an secure area that is monitored an alarm system.
Deleting your data
This section explains how we destroy/delete your data once is no longer required.
- Once your private data is no longer needed/relevant H & E Smith Ltd will permanently delete the electronic files we hold.
- Once your private data is no longer needed/relevant H & E Smith Ltd will destroy the documents.
Breaches of data
- H & E Smith Ltd has standard procedures to protect your details against data breaches such as passwords for electronic files, that are systematically changed, security alarms and secure filing cabinets for used for the storage of physical documents.
- We back-up your data by creating an electronic copy of each document that is stored securely on our UK based server, that is protected by password and up to date anti-virus program.
- H & E Smith Ltd understands the legal requirement placed upon us to report a data breach to ICO (Information Commissioner’s Office) within 72 hours from the event. We also commit to inform each person that has been affected by the data breach.
- H & E Smith Ltd will notify you of any significant changes to this policy.
Your rights (GDPR rights of the natural person)
This section explains the rights you have as a data subject in respect to your personal information.
- You have the right to be informed about why, how and on what basis your information is processed.
- You have the right to have data corrected if the data we hold is inaccurate or incomplete.
- You have the right to obtain confirmation that your information is being processed and to gain access to your data as well as certain other information by making a “subject access request” to us. Your “subject access request” will be answered within 7 days.
- You have the right to restrict the processing of your personal information where the veracity of the information is contested, or the processing is deemed unlawful (but you do not want the data to be erased), or where the employer no longer needs the personal information, but you require the data to establish, exercise or defend a legal claim.
- You have the right to restrict the processing of personal information temporarily where you do not believe it is accurate (and while the employer is verifying whether it is accurate), or where you have objected to the processing (and the employer is reviewing whether the organisation’s legitimate grounds override your interests).
- You have the right to have data erased if it is no longer needed for the purpose for which it was originally processed/collected, or if there are no remaining legitimate grounds for the processing (the right to be forgotten).
If you wish to exercise any of the rights in the above paragraphs, please contact the Data Protection Officer via firstname.lastname@example.org
H & E Smith Ltd details
H&E Smith Ltd, Britannic Works,, Stoke-on-Trent, ST1 2ER
You can contact us:
a) by post to the address of our registered office
c) by e-mail to email@example.com
c) by telephone 01782 281617