DATA PRIVACY STATEMENT
Context and overview
- Policy Prepared by: Bluestone Sales & Distribution Ltd
- Policy became operational: May 2018
Bluestone Sales & Distribution Ltd needs to gather and use certain information about individuals.
These can include customers, suppliers, business contacts, employees and other people the organisation has a relationship with or may need to contact.
This policy describes how this personal data must be collected, handled and stored to meet the company’s data protection standards and to comply with the law.
Customers are entitled to request a copy of their electronic data held by Bluestone Sales & Distribution at any time.
Why this policy exists
- Complies with data protection law and follows good practice
- Protects the rights of staff, customers and partners
- Is open about how it stores and processes individuals’ data
- Protects itself from the risks of a data breach
Data protection law
The Data Protection Act 1998 describes how organisations including Bluestone Sales & Distribution Ltd must collect, handle and store personal information.
These rules apply regardless of whether data is stored electronically, on paper or on other materials.
To comply with the law, personal information must be collected and used fairly, stored safely and not disclosed unlawfully.
The Data Protection Act is underpinned by eight important principles. These say that personal data must:
- Be processed fairly and lawfully
- Be obtained only for specific, lawful purposes
- Be adequate, relevant and not excessive
- Be accurate and kept up to date
- Not be held for any longer than necessary
- Processed in accordance with the rights of data subjects
- Be protected in appropriate ways
- Not be transferred outside the European Economic Area (EEA), unless that country or territory also ensures an adequate level of protection
People, risks and responsibilities
This policy applies to:
- The head office of Bluestone Sales & Distribution Ltd
- All staff and volunteers of Bluestone Sales & Distribution Ltd
- All contractors, suppliers and other people working on behalf of Bluestone Sales & Distribution Ltd
It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the Data Protection Act 1998. This can include:
- Names of individuals
- Postal addresses
- Email addresses
- Telephone numbers
- Plus any other information relating to individuals
Data protection risks
This policy helps to protect Bluestone Sales & Distribution Ltd from some very real data security risks, including:
- Breaches of confidentiality – for instance, information being given out inappropriately.
- Failing to offer choice – for instance, all individuals should be free to choose how the company uses data relating to them.
- Reputational damage – for instance, the company could suffer if hackers successfully gained access to sensitive data.
Everyone who works for or with Bluestone Sales & Distribution Ltd has some responsibility for ensuring date is collected, stored and handled appropriately.
Each team that handles personal data must ensure that it is handled and processed in line with this policy and data protection principles.
However, these people have key areas of responsibility:
- The board of directors is ultimately responsible for ensuring that Bluestone Sales & Distribution Ltd meets its legal obligations.
- The data protection office is responsible for:
- Keeping the board updated about data protection responsibilities, risks and issues.
- Reviewing all data protection procedures and related policies, in line with an agreed schedule.
- Arranging data protection training and advice for the people covered by this policy.
- Handling data protection questions from staff and anyone else covered by this policy.
- Dealing with requests from individuals to see the data Bluestone Sales & Distribution Ltd holds about them (also called ‘subject access requests’).
- Checking and approving any contracts or agreements with third parties that may handle the company’s sensitive data.
- Ensuring all systems, services and equipment used for storing data meet acceptable security standards.
- Performing regular checks and scans to ensure security hardware and software is functioning properly.
- Evaluating any third-party services the company is considering using to store or process data. For instance, cloud computing services.
- Approving any data protection statements attached to communications such as emails and letters.
- Addressing any data protection queries from journalists or media outlets like newspapers
- Where necessary, working other staff to ensure marketing initiative abide by data protection principles.
Data protection principles
Under GDPR, all personal data obtained and held by us must be processed according to a set of core principles. In accordance with these principles, we will ensure that:
- Processing will be fair, lawful and transparent
- Data be collected for specific, explicit and legitimate purposes
- Data collected will be adequate, relevant and limited to what is necessary for the purposes of processing
- Data will be kept accurate and up to date. Data which is found to be inaccurate will be rectified or erased without delay
- Data is not kept for longer than I necessary for its given purpose
- Data will be processed in a manner that ensures appropriate security of personal data including protection against unauthorised or unlawful processing, accidental loss, destruction or damage by using appropriate technical or organisation measures
- We will comply with the relevant GDPR procedures for international transferring of personal data
Types of Data Held
The following Customer Data is recorded and stored by Bluestone Sales & Distribution Ltd:
- Customer name and address
- Customer email address
- Customer phone number
All of the above information is required for our processing activities and customer data is kept electronically on secured and managed IT Systems.
Disclosure to third parties
Where we engage third parties to process data on our behalf, we will ensure, via a data processing agreement with the third party, that the third party takes such measures in order to maintain the Company’s commitment to protecting data. Bluestone Sales & Distribution Ltd does not transfer personal data to any recipients outside of the EEA.
Bluestone Sales & Distribution Ltd has trained all staff on how to collect, manage and protect customer data. Protecting customer data is not just a legal requirement but imperative to protect our customer’s business.
In order to protect the personal data of relevant individuals, which it holds or to which it has access, we have designated employees with specific responsibilities for the processing and controlling of data. We have also appointed employees with responsibility for reviewing and auditing our data protection systems.
All queries relating to data privacy should be addressed to: Data Controller, Bluestone Sales & Distribution Ltd, 26 Oaktree Business Park, Trim, Co Meath, Ireland