The purpose of this document is to communicate our position and the application of controls in respect of lawful processing and retention of personal data held by Advanté.
Advanté are committed to safeguarding the privacy of the personal data we hold. This policy applies where we are acting as a data controller with respect to the personal data of our customers – should the data not be considered business contact, suppliers, employees and interested parties, and where we determine the purposes and means of the processing of any personal data associated with those subjects.
These can include customers, suppliers, business contacts, employees and other people the organisation has a relationship with or may need to contact.
Why this Policy exists
- Complies with the obligations and responsibilities of the GDPR and follows good practice
- Protects the rights of staff, customers and our interested parties
- Is open about how we store and process individual’s data
- Protects ourselves from the risk of data breach or unauthorised access to the data we hold
The Data Protection Act 2018 (DPA)
The DPA describes how organisations – including Advanté – can collect, handle and store personal information.
These rules apply regardless of whether data is stored electronically, in hard copy or on other materials or types of media.
To comply with the law, personal information must be collected freely, used fairly, stored safely and not disclosed unlawfully.
What we collect – Customer and Commercial Information
Through the purposes and nature of our business and provision of services to our customers we may collect the following information:
- Name and job title
- Contact information including work email address
- Demographic information such as postcode, preferences and interests
- Other information relevant to customer surveys and/or offers
What we do with the information we gather
We require this information to understand your needs, provide you with our services and ensure the compliance of the plant and transport services we deliver to you. In particular we hold this information for:
- Internal Customer Relationship Management (CRM) purposes
- To maintain communication and service regarding the equipment you have on hire from us
- To plan and organize the delivery/collection of equipment you have on hire or specialist transport services you have ordered
- To periodically contact you regarding our products and services, industry information, H&S guidance and offers we think you may find of interest using either the email address or telephone number provided
- From time to time we may also use your contact information to contact you for market research purposes. We may contact you by phone or email
Advanté are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure your information is stored electronically within our internal IT network and protected by industry best practice encryption and firewall technology.
Advanté have undertaken suitable Data Protection Impact Assessment (DPIA) audits on our supply chain and hold relevant due diligence information relating to their ability to provide and maintain protection over the services we consume from them. This includes the use and selection of our primary information technology partners and bespoke hosted solutions consumed by Advanté for the management of the data we hold.
We have established controls within this policy for the prevention of misuse or unauthorised access and processing of the data we hold by those not authorised to access, download, copy or use data held by Advanté.
We periodically review the security provisions and controls provided by our supply chain and have Incident Management and Breach Procedures to use in the event of issues.
Controlling Customer and Commercial personal information
You may choose to restrict the collection or use of your personal information however if the need to hold such data is ‘necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract’ then we have lawful obligation to hold such data.
Should you feel that the data held is not subject to the above provision you may:
- Request details of personal information that we hold about you under the GDPR. We are obliged to provide this information within a 30-day period of receiving your request. If you please contact us at our registered office – Advanté, 10/11 Argent Court, Sylvan Way, Southfields Business Park, Basildon, SS15 6TH and address your communication to the ‘Data Controller’
- Request under the right to be forgotten that we remove your personal data. Such actions must be compliant with the provisions for lawful processing as stated above
Should you wish to remove consent for us to hold data collected for this purpose please advise us in writing.
What we collect – Internal HR related personal data
Through the purposes and nature of our employment of staff and engagement with directly employed contractors we may collect the following information:
- Name, address and personal contact details including phone and email address
- Date of birth
- Valid information to verify your identity including copies of photographic ID such as copies of your passport or driving license
- Valid information to verify your right to work in the UK and wider European Economic Union until such time as this no longer applies
- Details relating to your driving license and driving history – specific consent is obtained for this to enable the DVLA to provide up to date license details
- Health information that may be relevant to your job role and ability to undertake it – Advanté subscribe to the Safety Critical Worker scheme operated by Constructing Better Health (CBH) – INDUSTRY STANDARDS FOR WORKPLACE HEALTH IN UK CONSTRUCTION
- Vocational qualifications and competence evidence that supports your ability to undertake assigned tasks
- In Case of Emergency (ICE) contact details
- References – prior to the commencement of employment
- Tax and National Insurance details
- Bank details for remuneration purposes
- DBS checking should your job function require such validation
- Performance appraisal information for the completion of your duties whilst in the employment of Advanté
Advanté do not actively seek to obtain or process sensitive data about our staff other than that collected as part of our monitoring of the Occupational Health of our Safety Critical Workers.
Any such sensitive data outside of this source will only be obtained as a result of your performance reviews, disclosures to the business or due to issues arising with your employment.
Such information, if collected will only be retained by the business if it relates to ongoing disciplinary or litigation obligations and shall be deleted upon end of employment in order to protect your right to a private life as defined under Section 8 of the Human Rights Act.
Third Party Processing
Advanté have 3rd party relationships with authorised permissions to process and store internal personal data. These are with organisations that assist and support Advanté in the management of our services, financial affairs, pensions, HR guidance and the provision of company vehicles.
Advanté have undertaken DPIA of our supply chain and have entered into GDPR compliant supplier relationships with all such parties to protect our personal data holdings. We hold on file suitable due diligence information to verify and validate the provision of data protection by our 3rd party processors and subject certain suppliers to our internal controls to assist in maintaining a compliant supply chain.
Advanté do undertake or permit the international transfer of data outside of the UK or European Economic Union.
Personal Data Inventory
Our HR Process contains a Personal Data Inventory mechanism that enables us to:
- Map the data we hold for internal HR purposes
- Ensure its suitability and accuracy
- State our retention obligations
- Identify the sources from which the data will be obtained
- State the storage mechanisms used to retain such data and protect it from unauthorised access or disclosure
Unauthorised Access or Misuse of Advanté held data
Unauthorised access use or processing of data held by Advanté including CRM content, internal Personal Data or data covered under Intellectual Property Rights (IPR) is an offence and will be pursued accordingly in the event of a breach.
Any individuals who are found to be in breach of the confidentiality obligations within their contract will face disciplinary actions including gross misconduct if unauthorised processing of data is established.
Advanté takes very seriously the rights of individuals in relation to their personal data. As such Advanté uses a standalone consent form to ensure that we do not rely on the imbalance of an employment contract to obtain your personal data.
This Policy allows you to freely consent to the collection of data that relates to your employment with Advanté and states clearly and specifically what:
- Personal data we need to collect
- How it will be processed
- How it will be managed
- What will be retained post-employment and for how long and;
- The mechanisms for its secure disposal to prevent retention
Managing Director – Advanté Limited