Cookies | Privacy Policies

We ask that you read this website privacy policy carefully as it contains important information on who we are, how and why we collect, store, use and share personal information, your rights in relation to your personal information and on how to contact us and supervisory authorities in the event you have a complaint. This website privacy policy is divided into the following sections:

WHO ARE WE

This website is operated by Pure Utility Solutions Limited. We are facilities Services Company, and for more information see: https://www.dpgfss.co.uk/about-us/
We collect, use and are responsible for certain personal information about you. When we do so we are regulated under the General Data Protection Regulation which applies across the European Union (including in the United Kingdom) and we are responsible as ‘controller’ of that personal information for the purposes of those laws.

OUR WEBSITE

This privacy policy relates to your use of our website: https://www.dpgfss.co.uk/ only.
Throughout our website we may link to other websites owned and operated by certain trusted third parties to make additional products and services available to you. These other third party websites may also gather information about you in accordance with their own separate privacy policies. For privacy information relating to these other third party websites, please consult their privacy policies as appropriate.

OUR COLLECTION AND USE OF YOUR PERSONAL INFORMATION

We collect personal information about you when you access our website, register with us, contact us, send us feedback, purchase products or services via our website, post material to our website and compete customer surveys or participate in competitions via our website.

We collect this personal information from you either directly, such as when you register with us, contact us or purchase products or services via our website] or indirectly, such as your browsing activity while on our website (see ‘Cookies’ below).

We also collect personal information about you from other sources as follows:

  • Credit agencies such as Credit Safe
  • Government Agencies, such as Companies House

The personal information we collect about you depends on the particular activities carried out through our website. Such information includes:

  • Your name, address and contact details
  • Vat and Company Registration Numbers
  • Credit Rating
  • Details of any feedback you give us by phone, email, post or via social media
  • information about the services we provide to you
  • your account details, such as username, login details

We use this personal information to:

  • Create and manage your account with us
  • Verify your identity
  • Provide goods and services to you
  • Customise our website and its content to your particular preferences
  • Notify you of any changes to our website or to our services that may affect you
  • Improve our services
  • Debt management

This website is not intended for use by children under the age of 13 and we do not knowingly collect or use personal information relating to children.

OUR LEGAL BASIS FOR PROCESSING YOUR PERSONAL INFORMATION

When we use your personal information we are required to have a legal basis for doing so. There are various different legal bases upon which we may rely, depending on what personal information we process and why.

The legal bases we may rely on include:

  • Consent: where you have given us clear consent for us to process your personal information for a specific purpose
  • Contract: where our use of your personal information is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
  • Legal obligation: where our use of your personal information is necessary for us to comply with the law (not including contractual obligations)
  • Public task: where our use of your personal information is necessary for us to perform a task in the public interest or for our official functions, and the task or function has a clear basis in law
  • Legitimate interests: where our use of your personal information is necessary for our
  • legitimate interests or the legitimate interests of a third party (unless there is a good reason to protect your personal information which overrides our legitimate interests)

Further information—the personal information we collect, when and how we use it

For further details on when we collect personal information, what we collect as well as how we use it, please read the following sections:

When information is collected
When you register with us

What information we ask for
Contact details: your name, telephone number and email address

How and why we use your information

We ask for this:
— to subscribe to our newsletter in our online form
— to communicate with you about the latest information

We rely on legitimate interests as the lawful basis for collecting and using your personal information.

Who we share your personal information with:

We routinely share your name and delivery address details with our third party suppliers. For a list of our third party suppliers’) see our Approved Suppliers list available on request.

This data sharing enables them to provide services on our behalf.

We will share personal information with law enforcement or other authorities if required by applicable law.

We will not share your personal information with any other third party.

Whether information has to be provided by you, and if so why

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.”

COOKIES AND SIMILAR TECHNOLOGIES

A cookie is a small text file which is placed onto your device (eg computer, smartphone or other electronic device) when you use our website. We use cookies [and other similar tracking technologies such as [insert details, eg web beacons, action tags, single-pixel gifs]] on our website. These help us recognise you and your device and store some information about your preferences or past actions.

For further information on cookies generally visit www.aboutcookies.org or www.allaboutcookies.org.

 

Marketing

We would like to send you information about our other products and services, competitions and special offers which may be of interest to you. Where we have your consent or it is in our legitimate interests to do so, we may do this by post, email, telephone, text message (SMS) or automated call.

We will only ask whether you would like us to send you marketing messages when you tick the relevant boxes when you complete our online contact form for the first time. Click here to see what this form looks like.

If you have previously agreed to being contacted in this way, you can unsubscribe at any time by:

— contacting us at: helpdesk@dpgfss.com

— using the ‘unsubscribe’ link in emails or ‘STOP’ number in texts

It may take up to 30 days for this to take place:

For more information on your rights in relation to marketing, see ‘Your rights’ below.

ROLES AND RESPONSIBILITIES

Data Controller

The Company’s Data Controller is Yvonne Donnelly, Director. Her direct contact details are: 01355 708387. Email address: yvonne.donnelly@dpgfss.com

The role

The Data Controller is the key decision maker in respect of why and how personal data is used and handled. The Data Controller will ensure that, both in the planning and implementation phases of processing activities, data protection principles and appropriate safeguards are addressed and implemented and that records of processing activity are kept. Our Data Controller will ensure that a Privacy Impact Assessment (PIA) is carried out when necessary.

Overview of responsibilities

  • To be ultimately accountable for the Company’s compliance with the six principles (see section ‘Principles’).
  • To be able to demonstrate compliance with the six principles and therefore the proper handling and processing of all personal data. This will include information about the various data protection management resources that have been put into place and take the primary responsibility for the internal data protection framework.
  • To implement appropriate technical and organisational measures to ensure processing is performed in accordance with data protection laws. These measures will take into account the nature, scope, context and purposes of the data processing and the risks to the rights and freedoms of individuals.
  • To adopt measures to protect against any high levels of risk identified by a Privacy Impact Assessment, such as; discrimination, identity theft or significant legal, social or economic disadvantage.
  • To implement internal data protection policies; assign protection responsibilities and to ensure adequate training on data protection is provided and carried out by all staff.
  • To determine how data subjects may exercise their rights.

Data Processor

The role

This role processes personal data on behalf of and further to documented instruction given by the Controller.

Overview of responsibilities:

  • To take all measures required to ensure their own compliance with data protection legislation regarding security.
  • To make available all information necessary to demonstrate compliance with data protection legislation and to permit an audit should the Controller wish to further ensure compliance.
  • To assist the controller in compliance with its obligations under data protection legislation regarding;

– security of processing
– assist in meeting any rights exercised by a data subject e.g. subject access request
– notification of a personal data breach to the supervisory authority
– communication of a personal data breach to the data subject
– any necessary Data Protection Impact Assessments
– consultation with the supervisory authority about any processing that should be identified as being ‘high risk’

  • To ensure that on instruction from the Controller, any personal data held on behalf of a client for whom we act as a processor, is deleted and returned to that client, unless we are prohibited by data protection legislation.
  • To immediately inform the Controller if it believes any instruction given by the Controller would be in breach of data protection legislation.

Any processors are not permitted to appoint another processor without prior written agreement from the Company. Equally when we act as a processor we will not appoint another processor without written agreement of the Controller we act on behalf of.

YOUR RIGHTS

Under the General Data Protection Regulation you have a number of important rights free of charge. In summary, those include rights to:

  • Fair processing of information and transparency over how we use your use personal information
  • Access to your personal information and to certain other supplementary information that this Privacy Notice is already designed to address
  • Require us to correct any mistakes in your information which we hold
  • Require the erasure of personal information concerning you in certain situations
  • Receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
  • Object at any time to processing of personal information concerning you for direct marketing
  • Object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
  • Object in certain other situations to our continued processing of your personal information
  • Otherwise restrict our processing of your personal information in certain circumstances

 

For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals rights under the General Data Protection Regulation.

If you would like to exercise any of those rights, please:

  • email, call or write to us
  • let us have enough information to identify you; e.g. account name, user name
  • let us have proof of your identity and address (a copy of a recent invoice or emailed communication.
  • let us know the information to which your request relates, including any account or reference numbers, if you have them

 

Keeping your personal information secure

We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

 

If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org Get Safe Online is supported by HM Government and leading businesses.

HOW TO COMPLAIN

We hope that we can resolve any query or concern you raise about our use of your information.

The General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at www.ico.org.uk/concerns or telephone: [0303 123 1113].

SUBJECT ACCESS REQUESTS

Making a request

If you wish to make a subject access request to verify the lawfulness and accuracy of the personal data we hold about you, then you are encouraged to put your request in writing (letter or e-mail) and submit it to Yvonne Donnelly, Director.

Your request should be specific about the nature and the type of data you require.

Every attempt will be made to comply with your request in a timely manner and without undue delay.

Upon receipt of the information you are encouraged to check the accuracy of the information and to advise the Company of any updates that may need to be made.

A fee will not be charged for an access request, except where a request is deemed to be ‘manifestly excessive’ or you have already been provided with the information.

Receiving a request

If you receive a request, you should pass it to Yvonne Donnelly, Director immediately.

Requests must be acknowledged upon receipt.

Requests must be complied with in a timely manner and without undue delay. If it is anticipated that compliance with a request is not going to be immediate then the Controller should be notified and informed of the legitimate reasons for this. The information requested must be provided within one month of receipt of the request.

If an extension to the time line is absolutely necessary under exceptional circumstances, then any extension must be agreed by the data subject and signed off by the Controller within one month of the request. If an extension is agreed, then the information must be provided within a maximum of three months from the receipt of the request.

If a request is received electronically (eg via e-mail) then the request must be responded to electronically.
The data must be provided in a common format (eg a paper file, a pdf document etc.).

Only personal data pertaining to the individual who made the request should be released.

If there is any doubt over the identity of the individual making the access request, then reasonable steps must be taken to verify their identity, before complying with the request.

When the personal data is provided, the individual must be informed of the right to lodge a complaint with the relevant supervisory authority and the existence of the right to objection, rectification, erasure and restriction of the data.

The data subject may be directed to the relevant privacy/fair processing notice which will provide advice on the conditions for processing.

GENERAL GUIDANCE FOR EMPLOYEES

We recognise that there are different areas in the organisation where members of staff may be responsible for processing personal data in different ways. We also recognise that responsibilities and nuances in processing are likely to vary across specialisms and levels of seniority.

The Company will provide guidance to staff when processing personal data specific to their job. This information shall include:

  • A description of the limitations which surround how personal data can be used.
  • The steps that must be followed to ensure that personal data is maintained accurately.
  • A comprehensive discussion of security obligations, including all reasonable steps that should be taken as a minimum to prevent unauthorised access or loss.
  • Confirmation of whether the transfer of personal data shall be permitted. Transfer of personal data is prohibited unless specific legitimate grounds have been established.
  • Specific information regarding the way in which personal data should be handled when it is destroyed or deleted.

General responsibilities of management

All members of the senior management are responsible for championing and enforcing this policy to all other staff within the Company, whenever appropriate.

Particular roles within senior management are responsible for assessing the business risk arising as a result of processing personal data. These roles include directors of the Company.

Those members of senior management identified above are required to work with the Company to develop procedures and controls to identify and address risks appropriately.

Responsibility will be allocated to individual roles for determining risk-based technical, physical and administrative safeguards including safeguards for equipment, facilities and locations where personal data is stored; establishing procedures and requirements for collecting, transporting, processing, storing, transferring (where appropriate) and destroying personal data. These considerations must also be given when dealing with any third parties who may be authorised or obligated to process personal data on behalf of the Company.

Non-compliance

This policy along with associated documents, seeks to guide and instruct all member of staff on how they ensure compliance with data protection laws to which the Company is subject.

If a member of staff should fail to comply with applicable data protection laws, they may subject the Company and themselves as individuals to civil and criminal penalties. This is likely to jeopardise the reputation of the Company and as a result may impact on the operational and performance capabilities of the business.

As the ramifications of non-compliance are potentially severe, any failure to comply with this policy or reasonable instruction given in connection with the protection and security of personal data, may result in disciplinary action. Serious, deliberate or negligent transgressions may be regarded as gross misconduct and if substantiated, may result in summary dismissal (without notice).

Third parties, contractors and self-employed persons

If any self-employed person, contractor or third party is found to be failing to meet obligations with applicable data protection laws then notice may be served on the contract for service.

Serious, deliberate or negligent transgressions may permit the Company to terminate the contract for service with immediate effect. In this event, all reasonable steps will be taken to recover and protect the personal data concerned and the relevant supervisory authority will be notified. Where the rights and freedoms of data subjects are likely to be at risk, the data subjects will be notified without delay.

HOW TO CONTACT US

Please contact us if you have any questions about this privacy notice or the information we hold about you.

Any queries or comments about this policy, or any concerns that the policy has not been followed, should be addressed to Yvonne Donnelly, Director.

If you wish to contact us please send an email to: helpdesk@dpgfss.com or call 01355 708387

If you would like this website privacy policy in another format (for example: audio, large print, braille) please contact us (see ‘How to contact us’ above)

Contact Us Today
We are here for you 24/7.

Our network of highly experienced engineers are available in your local area 365 days a year 24/7