Staff Privacy Policy


This Privacy Policy applied to staff for Data Protection GDPR purposes.

How your personal information is used by Spicerhaart and the Spicerhaart family of companies…

Your information will be held electronically by Spicerhaart Group Services Limited, which is a processor of information for our trading names such as haart, Felicity J Lord, Chewton Rose, Haybrook, Darlows, Butters John Bee, Brian Holt, Just Mortgages, Spicerhaart Corporate Sales, ChainFree.com, Mustbesold.com and Valunation which are trading brands owned by the Spicerhaart Group.

Further information on our group of companies can be found at www.spicerhaart.co.uk

1. Introduction

This Privacy Policy forms part of Spicerhaart Group Services Limited (“Spicerhaart”) obligation to be open and fair with all individuals whose personal data we process and to provide details around how we process such personal data and what we do with it.

Spicerhaart is committed to safeguarding the privacy of personal data and complying with the European General Data Protection Regulation (2016/679) and the UK Data Protection Bill 2017, and any future changes in data protection legislation with which Spicerhaart will be required to comply.

During recruitment and employment with Spicerhaart we process your personal data such as name, address, contact details, email address and passport amongst other things.  Processing of this data implies collecting, storing, using or disclosing your personal data.

If You consent to be notified of, or receive other benefits or services from Spicerhaart, or use any of our websites, You may be provided with further privacy notices which may be contained in a separate policy or within any terms and conditions.  These additional privacy notices shall supplement this Privacy Policy.

This Privacy Policy relates to the processing of personal data by Spicerhaart and any of its subsidiaries and high street brands.  Unless otherwise stated, all references to “we” or “our” shall imply all Spicerhaart lines of business that process personal data.

None of the lists or examples provided in this Privacy Policy is intended to be exhaustive or fully representative of every individual.

2. Scope

The scope of this Privacy Policy covers client personal data in respect of the following:

 

 

  •      Ways we use your Personal Data
  •       Sharing Personal Data
  •   Definitions of Personal Data types
  •    International Data Transfers
  •      Collecting Personal Data
  •      Data Subject Rights
  •     Using Personal Data
  •     Updates / Amendments
  •     Fraud Protection Agencies (FPAs)
  •      Third Party Websites
  •    Disclosing Personal Data
  •      Consents (“Opt-in”)
  •    Retaining Personal Data
  •      Withdrawal of Consent (“Opt-out”)
  •    Securing Personal Data
  •      Our Details

 

3. Ways we use your Personal Data

We’ll process your personal data:

  1. as necessary to perform and fulfil our contract with You:
  1. as necessary to comply with legal obligation, e.g.:
  1. as necessary for our own legitimate interests, or those or other persons and organisations, e.g.:
  1. based on your consent, e.g.:

You are free at any time to change your mind and withdraw your consent. The consequence might be that we can’t do certain things for You.

4. Definitions of Personal Data types

We use various kinds of personal information, and group them together like this.

Type of Personal Information

Description

Contact

Where You live and how to contact You.

Consent

Any permissions, consent or preferences that You give Us, including how You would like Us to contact You.

Financial

Your financial position, status, remuneration details, any pension arrangements and history.

Contractual

Details about the benefits and services we provide to You, such as an employment contract.

Behavioural

Details about how You use our benefits and services including performance reviews and performance management information.

Communications

What we learn about You from conversations, emails and letters between Us.

Social Relationships

Your Family, friends and other relationships including nominated next of kin.

Open Data and Public Records

Details about You that are in public records such as the Electoral Register and information about You that is openly available on the internet.

Usage Data

Other data about how You use the benefits and services.

Documentary

Data

Details about You that are stored in documents in different formats, including copies. This could include things like your photographs, birth certificate or utility bill.

Socio-

demographic

This includes details about your work or profession, nationality, education and where You fit into general social or income groups.

National Identifier

A number or code given to You by a government to identify who You are, such as a National Insurance number, Driving License or Passport Number.

5.  Collecting Personal Data

We may collect and store the following kinds of personal data:

i. Information that You provided to Us when applying through our website, during visits to branch offices, in emails or over the phone.

ii. Information contained in or relating to any communication that You send to Us through our website, email, in writing, using Live Chat or over the phone.

iii. Information that You provide to Us when using any benefits we provide, or that is generated during the use of those benefits.

iv. Information that You provide as part of electronically signing agreements with Us.

v. Information that You provide in performing anti-money laundering, financial and credit checks as well as for fraud and crime prevention and detection purposes.

vi. Information related to the security and access of our systems and applications.

vii. Information to help Us comply with our legal and regulatory obligations, including reporting to and being audited by regulators and external auditors.

viii. Information to help Us comply with court orders and to exercise and defend our legal rights.

ix. Any other personal information that may be sent to Us and which we use for legitimate business purposes.

x. Information shared as part of our competitions or promotions.

Before You disclose to Us the personal information of another person, You must obtain that person's consent to both the disclosure and the processing of that personal information in accordance with this Privacy Policy.

Data from third parties we work with:

  •     Companies that introduce You to Us (recruitment for example)
  •      HMRC
  •     Public information sources such as Companies House
  •     Social networks

We may need to collect personal information by law, or under the terms of a contract we have with You.  If You choose not to give Us this personal information, it may delay or prevent Us from meeting our obligations.  It may also mean that we cannot employ you for the services needed.

Any data collection that is optional would be made clear at the point of collection.

6. Using Personal Data

We may use your personal information to:

i. Enable your use of any services that we may provide through our websites or third-party websites.

ii. Supply You with our benefits and services.

iii. To send You payslips, P60’s, P45’s and other employment related documentation as required.

iv. Send You benefit communications.

v. Deal with enquiries and complaints.

vi. Perform identity checking, credit rating, employment referencing and unspent criminal convictions checks.

vii. Use tracing services to obtain onward contact details and collect any unpaid debts for any default by You.

viii. Ensure appropriate access to systems and applications.

ix. Comply with our legal and regulatory obligations.

7. Fraud Prevention Agencies (FPAs)

We may need to confirm your identity before we provide benefits or services to You or your business.  Once You have become a customer of ours, we will also share your personal information as needed to help detect fraud and money-laundering risks.  We use Fraud Prevention Agencies to help Us with this.

Both we and fraud prevention agencies can only use your personal information if we have a proper reason to do so. It must be needed for either of Us to obey the law, or for a ‘legitimate interest’.

8.  Disclosing Personal Data

We only disclose your personal data in the ways set out in this Privacy Policy or subject to any agreements in place between Us.  The following circumstances may apply:

i. Across our different lines of business and brands, as part of a need to know or as part of improving our existing benefits and services or as part of providing new employee benefits.

ii. To third parties[1] who process personal data on our behalf.

iii. To third parties1 who process personal data on their own behalf but provide Us, or You, with a service on behalf of Us.

iv. To third parties1 with whom information is shared for identity checking, credit rating, employment referencing and unspent criminal convictions checking purposes.

v. To any regulator, external auditor or applicable body or court where we are required to do so by law or regulation or as part of any investigation.

vi. To any central or local government department and other statutory or public bodies, such as HMRC.

vii. If the law or a public authority says we must share the personal data;

viii. If we need to share personal data in order to establish, exercise or defend our legal rights (this includes providing personal data to others for the purposes of preventing fraud or reducing credit risk);

ix. To any other successors in title to our business(es);

We do not sell, rent or trade any of your personal data.

We will not, without your consent, disclose or supply your personal data to any third party for the purpose of their or any other third party's direct marketing.

9. Retaining Personal Data

The following criteria are used to determine data retention periods for your personal data (whether or not You become a customer):

10. Securing Personal Data

Where Spicerhaart acts as the controller of personal data, it will ensure that necessary and adequate safeguards (e.g. encryption) are in place to prevent unauthorised access, loss, misuse or alteration of your personal data.

Where data is stored electronically we store all personal information on secure servers with relevant access and firewall controls.

Where data is stored on paper or forms all personal data is locked away when not in use, and disposed of securely after use either using document shredders or third-party disposal organisations who have been contracted to dispose of documents appropriately.

Any personal data sent to Us, either in writing or email, may be insecure in transit and we cannot guarantee its delivery.

Where You use a Password to access any service provided by Spicerhaart this must be kept confidential and not disclosed to anyone else.  Spicerhaart does not ask You for your password.

11. Sharing Personal Data

To provide the services to You we may share the personal data that You supply with several third parties:

i. Experian Limited who are used to undertake identity checking, credit rating, employment referencing and unspent criminal convictions checking.

ii. Docusign Inc who are used to undertake the electronic digital signing of agreements.

iii. Shergroup Limited who are used to undertake client tracing and debt collection activities where Spicerhaart is recovering unpaid debts where You have defaulted on an agreement and Spicerhaart is owed money.

iv. BACS Payment Schemes Limited provide banking systems for the payment of remuneration.

v. ClassMarker Pty Limited who provide test result services and records.

vi. Competent Adviser Ltd who provide test result services and records.

vii. iCIMS, Inc who provide recruitment and employee application software services.

viii. NEST Corporation who provide Workplace Pension products.

ix. Standard Life Aberdeen plc who provide employee pension products.

x. Clayden Financial Planning Limited who provide pension management services.

xi. Punter Southall Health and Protection Limited who provide consultancy services for health insurance.

xii. Aviva Plc who provide health insurance services.

xiii. Unum Limited who provide life insurance services.

xiv. Skillsarena Corporate Limited who provide recruitment testing services.

xv. Kaizen Software Solutions, LLC who provide training records management solutions.

xvi. FMG Support Limited who provide vehicle tracking and telematics services.

To protect your data Spicerhaart agree contractual arrangements with these third-party data processors to ensure that your personal data is protected in compliance with this Privacy Policy and the data protection legislation that Spicerhaart is required to comply with.

Unless otherwise defined under section 12 all personal data shared with third parties is stored and processed in the UK or EU.

12. International Data Transfers

Personal data that we collect, is predominantly stored and processed in the UK, but for specific services may be transferred, stored, processed outside of the EU (designated under GDPR as “Third Countries”).

As part of providing our services to You under an agency agreement we will use third party data processors from Third Countries as outlined below:

i. Docusign Inc which is based in the USA.

ii. Shergroup Limited whose services are based in India.

iii. ClassMarker Pty Limited who are based in Australia and operate services from the USA.

iv. iCIMS, Inc which is based in the USA.

v. Kaizen Software Solutions, LLC, which is based in the USA.

Spicerhaart has agreed contractual agreements with these third-party data processors to safeguard your personal data as required by GDPR when transfers are undertaken to Third Countries.  If You wish to know more about the safeguards that are in place, please contact Spicerhaart as outlined in Section 20.

You expressly consent to the transfers of personal data described in this section for the purposes stated.

13.  Log Files and Statistics

Spicerhaart may use IP addresses, URLs of requested resources, timestamps and HTTP user agents to administer the system, analyse trends and gather broad demographic information for aggregate use.

In addition to this we may use third party services to monitor your use of our website, including Google Analytics, a web analytics service provided by Google, Inc ('Google'). This information allows Us to track how many visitors we have, how often they visit and where they originated from.  It also gives the ability to gather which terms were used when searching for properties.

14.Data Subject Rights

Your rights are as follows (noting that these rights don’t apply in all circumstances):

You have the right to complain to the Information Commissioner’s Office.  It has enforcement powers and can investigate compliance with data protection law: www.ico.org.uk

For more details on all the above You can contact our DPO using the details in Section 20.

15.Updates / Amendments

To remain compliant with any legal and regulatory obligations, or as part of our evolving business practices, we may update this Privacy Policy from time to time by publishing a new version.

16. Third Party Websites

We are not responsible for the practices employed by Third Party Websites linked to or from our Website nor the information or content contained therein.  Often links to other websites are provided solely as reference points to information on topics that may be useful to the users of our Website.  Please remember that when You use a link to go from our Website to a Third-Party Website, our Privacy Policy will no longer apply. Your browsing and interaction on any other Website, including Third Party Websites, which have a link on our Website, are subject to that Website's own Privacy Policy.

17. Consents (“Opt-in”)

Your personal data is provided for the purpose of recruitment and employment as agreed under the terms of an Agreement or Contract we have agreed between You and Us.

However, Spicerhaart would like to support You throughout the employment cycle by offering You additional relevant and related benefits, and keep You informed about all Spicerhaart services (marketing) which You can elect to, or decline from, receiving.

18. Withdrawal of Consent (“Opt-out”)

You have the right, at any time, to ask Us not to process your personal data for marketing purposes and any additional services that You have consented to receive.

You can opt-out of receiving any of these services and communications simply by clicking the unsubscribe link on any emails You receive, or contacting your branch or head office.

Please note it can take up to one calendar month for a request to be fulfilled for general Spicerhaart communications because of pre-planned or ongoing activity.

19. Data Protection Registration

We are registered as a data controller with the UK Information Commissioner's Office and our data protection registration number is Z151642X.

20. Our Details

Spicerhaart is registered in England and Wales under company number 06679992.  Its registered office is at Colwyn House, Sheepen Place, Colchester, Essex, CO3 3LD.  You can contact Us as follows:

Email:                                    DPO@spicerhaart.co.uk

Web:                                     https://www.spicerhaart.co.uk/contact-Us/enquiry-form/

Telephone:                         +44 (0) 1206 765599  (Head Office)

In writing:                            Data Protection Officer

Spicerhaart Group

Colwyn House

Sheepen Place

Colchester

Essex, CO3 3LD

21.0     Revision History

Revision 1.0, 02/05/2018 SL (V0418)

 

[1] The third parties we share data with are listed in Section 11