This privacy policy sets out how H2 Projects uses and protects any information that you give H2 Projects when you use this website.
H2 Projects is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement.
H2 Projects may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes. This policy is effective from: December 2018.
About This Privacy Policy
This Privacy Policy applies when you visit our website www.h2-projects.com (our website). It also applies where we are in contact with you as a customer, supplier, and subcontractor whether in your capacity as an individual or as director, shareholder, partner, employee or other representative of a company or other organisation.
Data Protection Principles
We adhere to the following principles when processing your personal data:
1. Lawfulness, fairness and transparency – data must be processed lawfully, fairly and in a transparent manner.
2. Purpose limitation – data must be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
3. Data minimisation – data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
4. Accuracy – data must be accurate and, where necessary, kept up to date.
5. Storage limitation – data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
6. Integrity and confidentiality – data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage by using appropriate technical or organisational measures.
Information We Collect
Information you provide us
You may choose to provide us with personal data when you are introduced to us, when we meet you in person, or when we are in contact by phone, email, via our website or otherwise.
The categories of personal data you provide can include the following:
- first and last name;
- job title and company name;
- email address;
- phone number;
- postal address;
- self-employed subcontractor data includes one or more of the following; national insurance number, tax reference numbers (UTR / VAT), passport, driving license, right to work, birth certificate;
- marketing and communications data includes your preferences in receiving marketing from us and your communication preferences
- Information we collect from third parties
We collect most of this information from you directly. However, we also collect information about you:
- from publicly accessible sources, e.g. Companies House, HMRC;
- from third party sources of information, e.g. customer due diligence providers;
- which you have made public on websites associated with you or your company or on social media platforms such as LinkedIn;
- from a third party, e.g. a person who has introduced you to us or other professionals (such as accountants) you may engage;
- Information we collect online
We collect, store and use information about your visits to our website and about your computer, tablet, mobile or other device through which you access our website. This includes the following:
- technical information, including the Internet protocol (IP) address, browser type, internet service provider, device identifier, your login information, time zone setting, browser plug-in types and versions, operating system and platform, and geographical location;
- information about your visits and use of the Site, including the full Uniform Resource Locators (URL), clickstream to, through and from our Site, pages you viewed and searched for, page response times, length of visits to certain pages, referral source/exit pages, page interaction information (such as scrolling, clicks and mouse-overs), and website navigation and search terms used;
Sensitive personal data
We do not generally seek to collect sensitive (or special categories of) personal data. Sensitive personal data is defined by data protection laws to include personal data revealing a person’s racial or ethnic origin, religious or philosophical beliefs, or data concerning health. If we do collect sensitive personal data, we will ask for your explicit consent to our proposed use of that information at the time of collection.
Children
Our website is not intended for or directed at children under the age of 16 years and we do not knowingly collect data relating to children under this age.
How We Use Your Information
HOW WE USE YOUR INFORMATION
The purpose for which we use and process your information (excluding sensitive personal data) and the legal basis on which we carry out each type of processing is explained below.
(Purpose for which we will process the information)
To provide you with information and services that you request from us.
(Legal basis for the processing)
It is in our legitimate interests to respond to your queries and provide any information requested in order to generate and develop business. To ensure we offer a good and responsive service, we consider this use to be proportionate and will not be prejudicial or detrimental to you.
(Purpose for which we will process the information)
To send you alerts, newsletters, bulletins, announcements, and other communications
(Legal basis for the processing)
It is in our legitimate interests to market our services. We consider this use to be proportionate and will not be prejudicial or detrimental to you.
You can always opt-out of receiving direct marketing-related email communications or text messages by following the unsubscribe link.
(Purpose for which we will process the information)
To invite you to seminars, events, or other functions we believe may be of interest to you.
(Legal basis for the processing)
It is in our legitimate interests to market our services. We consider this use to be proportionate and will not be prejudicial or detrimental to you.
You can always opt-out of receiving direct marketing-related email communications or text messages by following the unsubscribe link.
(Purpose for which we will process the information)
To enforce the terms and conditions and any contracts entered into with you.
(Legal basis for the processing)
It is in our legitimate interests to enforce our terms and conditions of service. We consider this use to be necessary for our legitimate interests and proportionate.
(Purpose for which we will process the information)
To send you information regarding changes to our policies, other terms and conditions and other administrative information.
(Legal basis for the processing)
It is in our legitimate interests to ensure that any changes to our policies and other terms are communicated to you. We consider this use to be necessary for our legitimate interests and will not be prejudicial or detrimental to you.
(Purpose for which we will process the information)
• To administer our website including troubleshooting, data analysis, testing, research, statistical and survey purposes;
• To improve our website to ensure that consent is presented in the most effective manner for you and your computer, mobile device or other item of hardware through which you access our website; and
• To keep our website safe and secure.
(Legal basis for the processing)
For all these categories, it is in our legitimate interests to continually monitor and improve our services and your experience of our website and to ensure network security. We consider this use to be necessary for our legitimate interests and will not be prejudicial or detrimental to you.
Where we rely on legitimate interests as a lawful basis, we will carry out a balancing test to ensure that your interests, rights and freedoms do not override our legitimate interests. If you want further information on the balancing test we have carried out, you can request this from our Privacy Manager.
If you do not wish to provide us with your personal data and processing such information is necessary for the performance of a contract with you, we may not be able to perform our obligations under the contract between us.
Email Marketing
For email marketing to an individual subscriber (that is, a non-corporate email address) with whom we have not previously engaged as a customer, supplier, or subcontractor, we need your consent to send you unsolicited email marketing.
Where you provide consent, you can withdraw your consent at any time, but without affecting the lawfulness of processing based on consent before its withdrawal.
You have the right to opt out of receiving email marketing communications from us at any time by:
• contacting our Privacy Manager using the contact details set out above; or
• using the “unsubscribe” link in emails.
Who We Share Your Personal Data With
You may choose to restrict the collection or use of your personal information in the following ways:
We do not share your personal data with third parties except as provided in this Privacy Policy.
We share your information with the following third parties:
• suppliers providing marketing services to us, or with whom we are conducting joint marketing exercises;
• with our third-party data processors and service providers who assist with the running of our website and our office services including our IT support services and data storage/back up services.
Our third-party processors and service providers are subject to security and confidentiality obligations and are only permitted to process your personal data for specified purposes and in accordance with our instructions.
International Transfers
We do not transfer your personal data outside the UK or the European Economic Area (EEA).
Security of Your Personal Data
We use industry standard physical and procedural security measures to protect information from the point of collection to the point of destruction. This includes encryption, firewalls, access controls, policies and other procedures to protect information from unauthorised access.
Where data processing is carried out on our behalf by a third party, we take steps to ensure that appropriate security measures are in place to prevent unauthorised disclosure of personal data.
How Long We Keep Your Personal Data
Your personal data will not be kept for longer than is necessary for the purposes for which it was collected and processed and for the purposes of satisfying any legal, accounting, or reporting requirements.
The criteria we use for retaining different types of personal data, includes the following:
• General queries – when you make an enquiry or contact us by email or telephone, we will retain your information for as long as necessary to respond to your queries. After this period, we will not hold your personal data for longer than one year if we have not had any active subsequent contact with you;
• Direct marketing – where we hold your personal data on our database for direct marketing purposes, we will retain your information for no longer than two years if we have not had any active subsequent contact with you.
• Legal and regulatory requirements – we may need to retain personal data for up 12 years after we cease providing services and products to you where necessary to comply with our legal obligations, resolve disputes or enforce our terms and conditions.
Your Rights
Access to and Updating Your Personal Data
You have the right to access information which we hold about you. If you so request, we shall provide you with a copy of your personal data which we are processing (“data subject access request”). We may refuse to comply with a subject access request if the request is manifestly unfounded or excessive or repetitive in nature.
You may also have the right to receive personal data which you have provided to us in a structured and commonly used format so that it can be transferred to another data controller (“data portability”). The right to data portability only applies where your personal data is processed by us with your consent or for the performance of a contract and when processing is carried out by automated means.
We want to make sure that your personal data is accurate and up to date. You have the right to have inaccurate personal data rectified or completed if it is incomplete. You can update your details or change your privacy preferences by contacting us as provided in “Contacting Us” above. We may refuse to comply with a request for rectification if the request is manifestly unfounded or excessive or repetitive.
Right to Object
Direct marketing
You have the right to object at any time to our processing of your personal data for direct marketing purposes.
Where we process your information based on our legitimate interests
You also have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data which is based on our legitimate interests. Where you object on this ground, we shall no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.
Your Other Rights
You also have the following rights under data protection laws to request that we rectify your personal data which is inaccurate or incomplete.
In certain circumstances, you have the right to:
• request the erasure of your personal data erasure (“right to be forgotten”);
• restrict the processing of your personal data to processing in certain circumstances.
Please note that the above rights are not absolute and we may be entitled to refuse requests, wholly or partly, where exceptions under the applicable law apply. We may refuse a request for erasure, for example, where the processing is necessary to comply with a legal obligation or necessary for the establishment, exercise or defence of legal claims. We may refuse to comply with a request for restriction if the request is manifestly unfounded or excessive or repetitive in nature.
Exercising Your Rights
You can exercise any of your rights as described in this Privacy Policy and under data protection laws by contacting us as provided in “Contacting Us” above.
Save as described in this Privacy Policy or provided under data protection laws, there is no charge for the exercise of your legal rights. However, if your requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may either: (a) charge a reasonable fee taking into account the administrative costs of providing the information or taking the action requested; or (b) refuse to act on the request.
Where we have reasonable doubts concerning the identity of the person making the request, we may request additional information necessary to confirm your identity such as a copy of your passport or driving license.
Links
Our website may, from time to time, contain links to and from third-party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
Contacting Us
We are not required to appoint a formal data protection officer under data protection laws. However, we have appointed a Privacy Manager who you can contact about any queries you may have in relation to this Privacy Policy. Our Privacy Manager is Catherine Ferguson.
If you have any questions about our privacy policy or your information, or to exercise any of your rights as described in this privacy policy or under data protection laws, you can contact us:
By email via our contact form.
Complaints
If you have any questions or complaints regarding our Privacy Policy or practices, please contact us as provided in “Contacting Us” above.
You have the right to make a complaint at any time with our supervisory authority, the ICO who can be contacted at https://ico.org.uk or telephone on 0303 123 1113.
Changes to Our Privacy Policy
From time to time, we may change this Privacy Policy. The current version of this Policy will always be available from us on our website. We will post a prominent notice on our website to notify you of any significant changes to this Policy or update you by other appropriate means.
Updated and effective as of 25th May 2018.
Cookie Policy
Cookies
When you visit our website, we use cookies, which are small pieces of information that allow us to maintain your connection to our website. This website may use cookies for detecting what kind of device you have in order to present content in the best way, for a language switch and/or for other purposes. These cookies do not collect or store any personally identifiable information. You can refuse the use of cookies.
Google Analytics
This website uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”). Google Analytics uses cookies (text files placed on your computer) to help the website operators analyse how users use the site. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by Google. By using this website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.
How to Refuse The Use of Cookies
You may refuse the use of cookies by selecting the appropriate settings in your browser. However, if you do this you may lose some useful functionality such as personalisation and “keep me signed in” and “remember me” features.