v1_1, last updated 23 August 2022
THIS PRIVACY POLICY APPLIES TO ANY PERSONAL DATA YOU PROVIDE US OR WE COLLECT ABOUT YOU, FOR EXAMPLE IF YOU ACCESS THE WEBSITE AT BAUGHCOMPLIANCE.COM OR ANY OTHER WEBSITE OR ONLINE PRESENCE OWNED, OPERATED OR PROVIDED BY ROBERT BAUGH COMPLIANCE LLP, INCORPORATED IN ENGLAND, # OC442628, REGISTERED OFFICE 120 CHATHAM ROAD, LONDON SW11 6HH (‘WEBSITE’ AND ‘BAUGH COMPLIANCE’, ‘US’, ‘WE’ RESPECTIVELY) OR USE ANY OF OUR PRODUCTS OR SERVICES (‘SERVICES’). WE DO NOT MARKET TO OR ENTER INTO CONTRACTS WITH CHILDREN NOR WE DO COLLECT PERSONAL DATA FROM ANY PERSON UNDER 18 YEARS OF AGE. PLEASE DO NOT ACCESS OR USE THE WEBSITE OR SERVICES IF YOU ARE UNDER 18 YEARS OF AGE.
This Policy sets out what personal data we might collect, how we process and protect that data, the lawful grounds for that processing, and your related rights. We always seek to comply with the data protection laws applicable to our processing of personal data. For example, the EU General Data Protection Regulation 2016/679 (‘EU GDPR’) may apply and, as a UK company, the UK Data Protection Act 2018, the UK e-Privacy Regulations (‘PECR’), and the UK-adopted version of the EU GDPR (‘UK GDPR’) apply directly to all our processing.
We use ‘GDPR’ to refer to either the EU or UK version as they’re almost identical. The GDPR is the world-standard for data protection laws, inspiring legal developments around the world.
‘Personal data’ is a defined term in EU and UK law. Essentially ‘personal data’ means any information relating to an identified or identifiable natural person, namely one who can be identified, directly or indirectly from that information alone or in conjunction with other information.
In most cases, the lawful ground (or legal basis) for our processing will be that the processing is necessary: (i) for our legitimate interests in carrying out our business, including to secure, manage, grow and improve our Services, provided those interests are not outweighed by your rights and interests (‘Legitimate Interests’), (ii) to perform a contract with you (‘Contract’), or (iii) to comply with our legal obligations (‘Legal Obligation’). Where processing is based on your consent (‘Consent’), we will identify the processing purposes and provide you with relevant information to make the processing fair and transparent when we ask for your consent.
As data protection law and practice are constantly developing, we’ll need to update this policy from time to time, which we’ll do by posting a new policy on the Website that takes effect from the date stated. It is your responsibility to return to the Website from time to time and check for changes.
We collect or are provided personal data in the normal course of business. For example:
In GDPR’s terms, we are the ‘controller’ of Account, Marketing, Website and Recruitment Data as we determine the purposes (the ‘why’) and the essential means (the ‘how’) of the collection and processing. We are the ‘processor’ of Customer Data as our client remains the ‘controller’ of Customer Data and we only process Customer Data to fulfil our contract with our client and on their instructions.
When you provide us with personal data about yourself or another person, for example a colleague or a contact, you are confirming to us that you either have their consent or are otherwise authorised to provide us with that information and that any personal data you give us is accurate and up-to-date.
Provision of personal data to us is never a requirement, however if you do not provide us with the personal data necessary for us to carry out an action at your request or under a contract with or relating to you, for example to respond to your query or provide Services to you, we may not be able to respond to your query or provide Services to you.
Given the nature of our business, we do not ask for ‘special categories of personal data’ such as information about your health, political opinions, racial origins or sexual life, or personal data relating to criminal convictions and offences – and we would ask you not to send any to us.
However, if at any time you choose to transmit such personal data over our Website or as part of our provision of the Services for any reason, or you provide us such personal data to us as part of Recruitment Data, you must have full authority to do so and you agree that it will be dealt with according to this Privacy Policy, including possible transfer to our offices or the third parties, inside or outside the UK or EEA, as described in this policy.
We use personal data in the normal course of our business, including to provide, secure, manage and improve our Services and to meet any binding contractual or legal obligations. This includes:
Where we carry out electronic direct marketing – including phone calls, automated phone calls, emails, SMS and IM – we will comply with the relevant, applicable laws.
We will not share, sell or rent your personal data to third parties so they can market their services to you. Nor do we accept advertising from third parties on the Website. We may share personal data in the following limited circumstances.
In limited situations, your personal data may be collected by or shared with third parties, who will act as separate or joint controllers, for example if we provide social media links such as buttons to like or share content through social media organisations such as LinkedIn or Twitter, those organisations will be joint controllers with us for the collection of the personal data. We will then be separate controllers for any processing of your personal data after collection. Lawful basis: Legitimate Interests or Contract.
We may be obliged to disclose your personal data to comply with a law, order or request of a court, government authority, other competent legal or regulatory authority or any applicable code of practice or guideline. Lawful basis: Legal Obligation.
If we enter negotiations with a third party for the sale or purchase of all or part of our business, we will only disclose personal data to that third party to the extent it relates to that business and only under conditions of confidentiality requiring the third party to be bound by the privacy policy that applies to that data. Lawful basis: Legitimate Interests.
In each case, we have written contracts in place incorporating relevant wording to safeguard that personal data and comply with applicable laws, and we will only share such data as is necessary for the purpose in question. Our starting position is always to keep personal data within the UK or European Economic Area (‘EEA’) where the UK GDPR or EU GDPR applies respectively. However, in order to carry out the above purposes, we may use third parties and their facilities outside the UK or EEA. In all such cases we will ensure that appropriate security measures are in place to protect your personal data and a valid legal basis for the transfer applies.
Our Website does not use cookies or similar technologies. Please review our Cookie Policy which is part of (and incorporated into) this Privacy Policy for more information, including on how to refuse or selectively accept cookies and/or similar technologies.
As a default position, we will only retain personal data for any statutory retention period, then a reasonable period (if any) necessary for the above purposes. This is subject, for example, to any valid opt-out or withdrawal of consent where processing is based on consent, or other valid exercise of your data subject rights.
We take appropriate technical and organisational measures to protect your personal data and keep those measures under review. However, we can only be responsible for systems that we control.
We may create anonymised data from personal data, and any anonymisation would be carried out in accordance with applicable law. Anonymisation may, for example, be achieved by aggregating data to the point that no individual can be identified such as aggregating website use statistics to see which web content is working well and which could be improved. Anonymised data does not allow for the identification of any individual person and, as it is no longer personal data, neither data protection laws nor this Privacy Policy would apply to such data.
If you access the services of another provider through our websites or services, for example through a link on the Website, your use of those services is entirely at your risk and governed by the terms and privacy policy of that third party provider. If we resell a service delivered or provided by a third party (‘Third Party Service’), including any software that is delivered or owned by a third party (‘Third Party Software’), it is that third party’s separate privacy policy that will apply to your personal data and your use of the Third Party Service and Third Party Software. Your use of a Third Party Service is not covered by this Privacy Policy. Please therefore review the privacy policy for any Third Party Service and Third Party Software before using it.
Under the UK and EU GDPRs, you have the following rights (some of which may be subject to conditions set out in the relevant GDPR):
You have the right, at any time, to object to the processing of your personal data for direct marketing.
The Website and Services do not use technologies that respond to ‘Do-Not-Track’ signals communicated by your internet browser.
If you’ve any question you can always contact us at the address above or by email to privacy@baughcompliance.com. You have the right, at all times, to notify a complaint to the regulator. Our supervisory authority, or regulator for data protection, is the UK ICO. We always welcome the opportunity to discuss and resolve any complaint with you first.