Who we are?
Thomas Bates and Son Limited is a Limited Company incorporated in England and Wales and is a ‘controller’ under the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
Whose data do we hold?
We may hold data about the following people;
- Suppliers and service providers
- Advisers, consultants and other professional experts,
- Complainants and enquirers
What data we will collect?
We will only collect information from you that is relevant to the matter that we are dealing with. In particular we may collect the following information from you which is defined as ‘personal data’:
- Personal details, such as name, address and email address
- Financial details
- Business activities of the person whose details we are processing
We may also collect information that is referred to as being in a ‘special category’. This could include:
- Racial or ethnic origin
- Religious beliefs or other beliefs of a similar nature
- Sexual orientation
Basis for processing
The basis on which we process your personal data is one or more of the following:
- It is necessary for the performance of our contract with you
- It is necessary for us to comply with a legal obligation
- It is in our legitimate interest to do so
- You have given us your consent (this can be withdrawn at any time by emailing firstname.lastname@example.org)
How will we use your data?
We may use your information for the following purposes:
- Maintaining accounts and records
- Promotion of our goods and services
Who will we share your data information with?
- Service providers based in the United Kingdom who provide IT and system administration services to us
- Solicitors who create leases for us
- Debt collection agencies if you do not pay our bills
How long will we keep your information for?
By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.
We may from time to time transfer your personal data to a country outside of the EEA. For example when we store personal data on a cloud server.
- We shall ensure that all the information that you provide to us is kept secure using appropriate technical and organisational measures
- In the event of a personal data breach we have in place procedures to ensure that the effects of such a breach are minimised and shall liaise with the Information Commissioner’s office (ICO) and with you as appropriate
- More information can be obtained by contacting email@example.com
What rights do you have?
You have the following rights under the GDPR;
- Request access to your personal data.
- Request correction of your personal data.
- Request erasure of your personal data.
- Object to processing of your personal data.
- Request restriction of processing your personal data.
- Request transfer of your personal data.
- Right to withdraw consent
Who you can complain to?
If you are unhappy about how we are using your information or how we have responded to your request then initially you should contact firstname.lastname@example.org
If your complaint remains unresolved then you can contact the ICO, details available at www.ico.org.uk