The Health & Safety Dept is part of a company called H&S Dept Ltd. The Health & Safety Dept operates as a franchise, which means that Health & Safety Dept offices around the UK are individual registered companies operating under licence to use The Health & Safety Dept brand and resources. We refer to this as the ‘Health & Safety Dept Network’.
This Privacy Notice explains how information collected and processed by The Health & Safety Dept network as a franchise of independently operated businesses collects and processes your information.
How does The Health & Safety Dept collect and process information about you and who is responsible for it?
The Health & Safety Dept may collect and process information about you from several sources which are outlined here.
- When you enter your information on a contact form on our website. The data controller for this data is H&S Dept Ltd.
- When you enter your information into a newsletter subscription form. The data controller for this data is H&S Dept Ltd.
- When information is received through networking activity by a staff member of any business in The Health & Safety Dept Network with information about yourself or your company and where it is understood there is a legitimate interest in receiving Health & Safety services from The Health & Safety Dept. The data controller for this information is whichever business within The Health & Safety Dept Network you provided the information to, and H&S Dept Ltd is a sub-processor.
- When your company or employing company enters into a client agreement with a business in The Health & Safety Dept Network and provides information about you to that Health & Safety Dept business for the purposes of receiving Health & Safety services. In this case, only information about you that is relevant to the delivery of these services should be shared by your employer with The Health & Safety Dept. The data controller for this information is your company or employing company. The business within The Health & Safety Dept Network you provided the information to, and H&S Dept Ltd, are sub-processors.
What sort of information about you is being collected and processed by The Health & Safety Dept?
In line with the expectations of the Data Protection Act (2018) and the GDPR regulations, we only collect necessary information that is required to allow us to promote and deliver our services fairly and effectively.
How can you find out what information The Health & Safety Dept holds about you?
Under the Data Protection Act (2018) and European GDPR regulations, any person about whom organisations hold data (a ‘data subject’) is allowed to request a copy of that information. This is called a Subject Access Request (‘SAR’).
There is guidance for individuals who want to make a Subject Access Request on the website of the regulator, the Information Commissioners Office (‘ICO’) (https://ico.org.uk) and it is strongly recommended that you review this guidance before submitting your request to avoid any delays. There is also information on this site about requirements for SARs for both the requesting and responding parties, and who SARs should be sent to.
If you wish to make a subject access request to The Health & Safety Dept, these should be submitted to the Head of Operations by email to email@example.com, or by post to:
The Head of Operations
The Health & Safety Dept
3 Brook Office Park
Bristol BS16 7FL
Why is The Health & Safety Dept collecting and processing your information?
We collect and process information about you for several purposes depending on the context of the information and how it was collected:
- to analyse website usage so we can determine how we can make improvements and if you subscribe to our newsletter, to email you about other directly related products and services we think may be of interest to you based on our understanding of your legitimate interest.
- to personalise your repeat visits to our website. If you submit your information on a contact form with interest in accessing Health & Safety Services through The Health & Safety Dept, we will pass on your information to a franchise business operating under license from H&S Dept Ltd that is located closest to you or can appropriately service you, so that they may offer you their products and services.
- to survey contacts about activity directly related to Health & Safety Dept marketing activity, service delivery or directly related projects undertaken by the H&S Dept Ltd.
- to provide outsourced Health & Safety services to your company or employing company in line with client agreements made with the company.
If you provide your information to us through this website, we would consider this to mean you have a legitimate interest in our services, and that you are happy to be contacted in relation to those services, and that you are happy for us to share this with our relevant data sub-processors outlined below in order for our services to be delivered to you.
How long is your information kept, and can you make sure it is accurate?
The Health & Safety Dept must retain some information for periods in line with regulatory or legislative requirements. If there is no regulatory or legal requirement to retain your information, then it will be kept until one of the following is true:
- You request for your data to be erased (see section below) and this can be legally fulfilled.
- The data is known to be or is suspected to be invalid/inaccurate by The Health & Safety Dept.
- The data is known to be or is suspected to be no longer appropriate for use for reasons of legitimate interest by The Health & Safety Dept (as outlined above).
If you believe any information held by The Health & Safety Dept is incorrect and wish to amend it, please contact us in writing. Please see the section at the end of this Privacy Notice about how to contact us by email or post.
Can you opt-out of marketing or request for your information to be erased?
The Health & Safety Dept does not wish to undertake marketing activity towards those who do not wish to receive it, and we will always comply with a request from you to either opt-out of marketing. We will comply with a request from you for your information to be erased if it is appropriate to do so (a) in accordance with the Data Protection Act (2018) or the European GDPR requirements and (b) if there is no legitimate justification for retaining the information.
In some cases, we may not be able to agree, wholly or in part, to your request for your information to be erased if there is a legitimate requirement to keep it. An example of a legitimate requirement would be if you are an employee of a company using The Health & Safety Dept for outsourced Health & Safety services, and you are involved in some way with an Health & Safety issue which is being dealt with by business within The Health & Safety Dept Network. In such a case, there is a legitimate requirement to retain relevant information relating to that issue in order for your employer to be able to resolve the Health & Safety issue and any related legal challenges. This may extend beyond the apparent resolution of the issue if there is a reasonable argument that the information may need to be revisited.
- Use the ‘opt-out’ or ‘unsubscribe’ link in any marketing communication from Health & Safety Dept if you do not wish to be contacted with any marketing communications.
- Request directly by email to firstname.lastname@example.org if you do not wish to be contacted with any marketing communications.
- Request by email to email@example.com if you wish for your information to be erased (the right to be forgotten).
- Contest our determination of a legitimate requirement to retain your information on a case-by-case basis. In the first instance, we ask that you contact the relevant Health & Safety Dept office to obtain an explanation of that determination.
Who else is your information shared with?
The Health & Safety Dept does pass your information to third parties outside of The Health & Safety Dept Network, other than to specific data sub-processors necessary for us to market and provide our services.
In order to facilitate marketing and delivery of our services to those who have provided their information and who we believe have a legitimate interest in our business, we may share your information with specific ‘sub-processors’ with whom we have data sharing agreements. We want to be clear and transparent with you about the sub-processors we use and what we have done to ensure that they take your data protection as seriously as we do.
Health & Safety Dept businesses operating under licence from H&S Dept Ltd.
If you fill in your details on a contact form with interest in accessing Health & Safety Services through The Health & Safety Dept, we shall pass on your personal information to a franchise business operating under license from H&S Dept Ltd that is located closest to you or can appropriately service you, so that they may offer you their products and services.
Other than the data sub-processors below, or the franchise businesses operating under licence from H&S Dept Ltd mentioned above, The Health & Safety Dept will not share or sell your information with other companies.
H&S Dept Ltd will share your information for marketing or service delivery purposes with the sub-processors below. This is only shared for the purpose of sending you Health & Safety Dept marketing content or Health & Safety Dept survey/research material relating to The Health & Safety Dept’s own services, or if necessary to be able to deliver Health & Safety services to your company/employing company in line with our client agreements and related contracts.
These sub-processors are:
Astonish Email Ltd
Astonish Email Ltd provides our Astonish marketing online platform. This is an online system which The Health & Safety Dept uses to send out our newsletters, promotional materials and marketing-related communications to clients, prospective clients who have chosen to share their data with H&S Dept Ltd or one of the franchise businesses trading under licence from H&S Dept Ltd, or contacts in businesses who have provided their information to us for whom we understand there to be a legitimate interest in our survey activity.
We use Microsoft Office 365 to manage our emails and file storage, which may include some information that has been collected through our website or other sources relating to marketing and surveying activity. Microsoft have confirmed that they are DPA/GDPR compliant and have updated their terms and conditions to reflect this. Microsoft may transfer data outside of the EEA but will only do so in a manner which protects your data and meets the requirements of the GDPR and the Data Protection Act (2018).
Workbuzz Ltd are a surveying company with whom we may share your data in the interest of undertaking customer surveys about Health & Safety Dept services. We have a Data Sharing Agreement in place with Workbuzz which governs the transfer of data to them and ensures that this is DPA/GDPR compliant.
SugarCRM / Sugabyte Ltd
We use a CRM system called SugarCRM which is hosted by a company called SugarCRM based in California and is administered in the UK by a distributor called SugaByte Ltd. On this system, we may store and process information about you collected through our website or marketing activities. All of this data is stored on secure servers based in Germany. We have a Data Sharing Agreement in place with SugaByte which governs the transfer of this data and ensures that it is GDPR/DPA compliant. SugaByte, in turn, have such an agreement in place with SugarCRM.
Additional sub-processors using your data via companies that operate under franchise licence from H&S Dept Ltd.
As well as the sub-processors above, data provided by your company about you or your employees to franchise businesses that operate under licence from H&S Dept Ltd may be shared with other sub-processors in the interest of delivering those services. Detail of those sub-processors will for part of the client agreement between your company/employing company and that Health & Safety Dept licensee business, and you can contact that Health & Safety Dept licensee business directly for more detail.
Each of the sub-processors listed above may change and be updated at any time, but our commitment to the security of your data remains. Any new providers will be subject to the same vetting and selection process and will be governed by the same or similar terms and conditions.
Under these agreements, data may be transferred outside of the EEA but only where your rights and the rights of the data subject are protected and where that transfer is compliant with the requirements of the DPA and GDPR.
How is the data stored?
The information we collect is stored in secure cloud vaults that operate inside the EEA. This includes SugarCRM, Microsoft, Google & Act-On. All information is stored in an encrypted form. Information held by Microsoft on our behalf may be transferred outside of the EEA but only where there are appropriate protections in place and in line with GDPR guidance.
Cookies are text files placed on your computer to collect standard internet log information and visitor behaviour information. This information is used to track visitor use of the website and to compile statistical reports on website activity. You can set your browser not to accept cookies using the following instructions, although in a few cases some of our website features may not function as a result. You can configure cookie settings in your browser’s settings.
Detailed step by step guidance on how to control and delete cookies is also available from www.aboutcookies.org.
Changes to our Privacy Notice
We keep our Privacy Notice under regular review and we will place any updates on this web page.
How to contact the Health & Safety Dept
If you would like to contact The Health & Safety Dept in relation to any matter covered in this Privacy Notice or with queries about our website or marketing/survey activity, please email firstname.lastname@example.org or write to us at The Health & Safety Dept, First Floor, 3 Brook Office Park, Emersons Green, Bristol, BS16 7FL.
Looking for expert health & Safety support?
We can help you focus on your business by taking care of all your health & safety needs.
Let us know how we can help or ask about our free initial H&S review.
Sensible Safety Solutions
Subscribe to our newsletter
Office Address: First Floor, 3 Brook Office Park, Emerson’s Green, Bristol, BS16 7FL | VAT Number: 900674738 | Registration Number: 06316590
Copyright © 2007 – 2019 The H&S Dept Ltd. H&S DEPT is a registered trademark belonging to The H&S Dept Limited.