Ayrshire Chimney Services Ltd.
PLEASE READ THIS POLICY CAREFULLY. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE ADVISED NOT TO USE THE WEBSITE
This policy was last updated: 21st May 2020
Ayrshire Chimney Services Ltd herein known as Ayrshire Chimneys may change this policy from time to time by updating this page. On each visit to the website you should refer to this page to ensure that you are aware of and accept any changes.
Ayrshire Chimneys recognises the trust you place in us when you share personal information with us. We are committed to being open, honest and transparent with our use of personal data.
By providing us with your data, you warrant that you are over 18 years of age.
Ayrshire Chimney Services Ltd (Ayrshire Chimneys) is a company registered in Scotland under Company Registration Number SC443105. Our registered office address is at Ayrshire Chimney Services Ltd Roodlea, Coylton, Ayr, KA6 6EP.
Where we manage personal data, we identify as a Data Controller and recognise and act on our obligations under applicable data protection law. For any issues relating to data protection the person responsible is Jim McNish. You can contact him in relation to data protection matters by email to email@example.com
What personal data do we collect?
Personal information is any information relating to an identified or identifiable individual. It does not include data where the identity has been removed (anonymous data). We may collect, use, store and transfer different kinds of personal information about you when we engage with you. This will include:
Identity Data – title, first name, last name, job title, company name or similar identifier. If you interact with us through social media, this may include your social media user name;
Contact Data – billing address, delivery address, email address and telephone numbers;
Transaction Data – details about services you have purchased from us or we have purchased from you.
How do we collect personal data?
We use different methods to collect data from and about you, through:
Our Contact Us/Enquiry Form
The Enquiry Form on our website is used to collect your name, address, company name, email and phone number as well as your message, so that we can respond to your communications and provide details of our services and deal with general company enquiries. Data is held on the grounds of being legitimate to our business interests.
Subscriptions to our Newsletters
We will retain the information you provide to us if you subscribe to our newsletters via the website. This includes details of your name and email. Data is process on the lawful basis of your consent which may be withdrawn at any time (see Rights of Data Subject below).
Calls to us may be recorded and any data relating to the call may be retained by us. The data will be held on the basis of being for our legitimate business needs or in order to fulfil our contractual obligations if you are a client of ours.
Other direct interactions
You may give us your data by filling in forms or by corresponding with us face-to-face, by post, or through social media. This includes personal data you provide when you: sign up to receive our free consultation; make enquiries or request information be sent to you; order our services; ask for information to be sent to you; engage with us on social media; enter a competition, promotion or survey; contact us direct; or leave comments or reviews on our services.
We use social media to engage with users and link to our Facebook, Instagram, LinkedIn, Pinterest and Twitter pages. We do not keep any specific data that identifies you as an individual user but hold details of our followers on these platforms. You should refer to the Privacy Policies of these channels to understand how they treat your data in relation to linking to our site.
We may ask you for a testimonial in relation to our services that may be used on our website or social media. Your personal details other than your name and town are not published.
Visits to our website
When you visit our website we do not attempt to identify you as an individual user and we will not collect personal information about you unless you specifically provide this to us.
Special categories of data
We do not generally collect any special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
We do not market this website at those under 18 years old. Consistent with the GDPR we will never knowingly request personally identifiable information from anyone under the age of 16 years old.
Information we get from other sources
From time to time, we may need to obtain information from third parties about you. This will only apply where it is necessary to provide our services and as permitted by law.
We may receive personal data relating to: your identity and contact data from data partners; and data from any third parties who are permitted by law or have your permission to share your personal data with us, such as via social media or review sites.
How do we use your data?
UK data protection law requires us to have a “legal basis” for processing personal data. The legal basis we rely on are:
Performance of a contract we are about to enter into or have entered into with you;
Compliance with a legal or regulatory obligation;
Carrying out activities that are legitimate to our business interests;
However, generally, we shall not rely on consent as a legal basis for processing your personal data other than where the law requires it. Where our legal basis is consent, you have the right to withdraw consent any time.
We may use the information we collect from you as outlined in this table:
What we use your information for The legal basis for doing so
To provide, manage and personalise our services to you
– Where necessary to carry out our agreement or to take steps to enter into an agreement with you
– Where the law requires this
– It is in our legitimate interests to make sure that our customer accounts are well-managed, so that our customers are provided with a high standard of service, and to protect our business interests and the interests of our customers.
To administer and improve the website – It is in our legitimate interests to develop and improve our products and services, so that we can continue to provide products and services that our customers want to use, and to make sure we continue to be competitive.
To personalise the content and user experience of the website – It is in our legitimate interests to develop and improve our systems and provide our customers with a high standard of service.
To allow us to respond to communications – Where necessary to carry out our agreement or to take steps to enter into an agreement with you
To send email notifications which have been specifically requested – It is in our legitimate interests to give you information about our products and services that you may be interested in
To send marketing communications, where expressly agreed; – In the case of electronic marketing we have your permission to do so.
To provide third parties with statistical information about our users – It is in our legitimate interests to better understand how our customers use our products and what changes we could make to improve them
To ask for feedback or testimonials – It is in our legitimate interests to better understand how our customers use our products and what changes we could make to improve them
To deal with enquiries and complaints made by or about you relating to the website – It is in our legitimate interests to make sure that our customer accounts are well-managed, so that our customers are provided with a high standard of service
To recover debt and exercise other rights we have under any agreement with you, as well as to protect ourselves against harm to our rights and interests in property
– Where necessary to carry out our agreement or to take steps to enter into an agreement with you
– Where the law requires this
– It is in our legitimate interests to make sure that our business is run prudently and we can recover the debts owed to us, as well as making sure our assets are protected.
Users contacting this website and/or its owners do so at their own discretion and provide any such personal data requested at their own risk. Your personal information is kept private and stored securely until a time it is no longer required or has no use.
Our legitimate interests
When we use our legitimate interests as the legal basis for processing your personal information, we will consider and balance any potential impact on you and your rights before we process your personal data. We will only then proceed where we believe our interests are not overridden by the impact on you. Our legitimate interests include the management of our business operations.
We may use Data Processors who act on our instruction in relation to the management of your data and they must adhere to all data protection laws and regulations. We will ensure that any Data Processors used only operate on our written instructions and comply with their obligations under the GDPR. You will be informed of any other Data Controllers who have access to your data and who may determine processing activities separately to us, or as a Joint Data Controller.
We may carry out direct marketing by email, phone, text or post.
You have the option not to give consent and to withdraw consent at any time from marketing communications. You may withdraw your consent for us to contact you by email to firstname.lastname@example.org. We may continue to contact you if there is another lawful basis to do so.
Non-personally identifiable information may be provided to other third parties for marketing, advertising or other uses.
Social media platforms
Communication, engagement and actions taken through external social media platforms that this website and its owners participate on are subject to our terms and conditions as well as the privacy policies held with each social media platform respectively.
Users are advised to use social media platforms wisely and communicate and/or engage with them with due care and caution in regard to their own privacy and personal details. This website nor its owners will not ask for personal or sensitive information through social media platforms and encourage users wishing to discuss sensitive details to contact them through primary communication channels such as by telephone or email.
Ayrshire Chimneys uses social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised that before using such social sharing buttons, that they do so at their own discretion, and should consider that the social media platform may track and save requests to share a web page, through the users’ social media platform account.
This website does not process customer payments for our services. Payments handled on our premises or via other means shall comply with the standard procedures and requirements as laid down by law to ensure that personal data is kept secure. Details or payment processes and terms are contained in our terms and conditions.
We keep your personal information in accordance with our Data Retention Policy which reflects our needs to provide services to you as contracted and also as required to meet legal, statutory and regulatory obligations. The need to hold information is regularly reviewed and data will be disposed of when no longer required.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, personal data is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such system and are required to keep the information confidential.
We take appropriate steps to ensure a safe processing of personal data, however, we cannot guarantee the security of data transmitted through our website or by email. Any transmission is at your own risk.
Rights of Data Subjects
Ayrshire Chimneys recognises a data subjects rights and will uphold these in accordance with data protection laws. You are entitled to see the information held about you and you may ask us about any of the following:
Subject access requests
Data subjects (i.e. individuals) have the right to access personal data that is held by submitting a subject access request (SAR) to Ayrshire Chimneys. We will endeavour to respond quickly to any such requests, which legally require us to respond within one month of receiving the request and necessary information. A subject access request can be made by emailing email@example.com
Right to rectification
Data subjects have the right to request that we amend or change personal data that is inaccurate or incorrect.
Right to erasure
Data subjects have the right to ask us to delete personal information from our systems without giving any reason and at any time. We will act on any such request without delay.
Right to restrict processing
Data subjects have the right to rectification or erasure of personal data in the following circumstances:
Personal data is not accurate;
The processing of data is unlawful – data subjects may request that processing is restricted;
Data is required to exercise legal rights or defend legal claims;
Data is unlawful but there may be lawful grounds for processing, which override this right.
Right to data portability
Data subjects have the right to obtain and request the transfer of their data to different service providers.
Right to object
Data subjects have the right to object to the processing of data at any time based on their particular situation. This includes objecting to profiling unless it is in the ‘public interest’ or exercised lawfully by an official authority. We will only process data under lawful grounds.
Right not to be subject to decisions based on automated processing
We do not use any automated processing that results in any automated decision based on a data subject’s personal information.
Using your rights
If you wish to invoke any of these rights, you should contact the person responsible for data protection by email to firstname.lastname@example.org
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We will report any unlawful breach of data as required by the GDPR within 72 hours of the breach occurring, if it is considered that there is an actual, or possibility, that data within our control including the control of our data processors, has been compromised. If the breach is classified as ‘high risk’ we will notify all data subjects concerned using an appropriate means of communication. We will report any relevant breaches to the ICO, see below.
Questions and queries
If you have any concerns about how we handle your data, please get in touch by email to email@example.com
If you want to raise a concern about the use of your data, you can contact us by email to firstname.lastname@example.org. Alternatively, you can formally raise a concern or complaint to the Information Commissioner’s Office (ICO) directly on 0303 123 1113, or see the options for reporting issues on https://ico.org.uk/concerns/
Copyright © 2020 Ayrshire Chimney Services Ltd.