Privacy Policy

This privacy notice tells you want to expect us to do with your personal information.

If you wish to raise a question or issue in relation to your personal information, please contact us at hello@lorrainehr.co.uk.

What information we collect and use, and why

We collect or use the following information to provide and improve products and services for clients: Names and contact details; Addresses; Occupation; Transaction data (including details about payments to and from you and details of products and services you have purchased); and Usage data (including information about how you interact with and use our website, products and services).

We collect or use the following information for the operation of client accounts: Names and contact details; Addresses; Occupation; and Purchase or account history.

We collect or use the following information for information updates or marketing purposes: Names and contact details; Addresses; Occupation; and Purchase or account history.

We collect or use the following information for dealing with queries, complaints or claims: Names and contact details; Addresses; Payment details; Account information; Purchase or service history; and Client accounts and records.
 

Lawful bases and data protection rights

Under UK data protection law, we must have a "lawful basis" for collecting and using your personal information. Which lawful basis we rely upon may affect your data protection rights, which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO's website.

  • You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with.
  • You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete.
  • You have the right to ask us to delete your personal information.
  • You have the right to ask us to limit how we can use your personal information.
  • You have the right to object to the processing of your personal data.
  • You have the right to ask that we transfer the personal information you gave us to another organisation or to you.
  • When we use consent as our lawful basis, you have the right to withdraw your consent at any time.
     

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of the privacy policy. The provision of certain personal data is or may be a contractual requirement, or a requirement necessary to enter into a contract. Also, the provision of certain personal data may be a statutory requirement. The consequences of not providing the personal data are that the commercial contract may not be able to function and certain legal responsibilities may be impossible to meet. In certain circumstances, it may be that the commercial contract cannot function and so is brought to an end. 

Our lawful bases for the collection and use of your data 

Our lawful bases for collecting or using personal information for the operation of client accounts including the provision and update of products and services are:

  • Consent - We have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Contract - We have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply, except the right to object.
  • Legal - We have to collect certain information in order to comply with our legal obligations.
  • Legitimate interests - We collect or use your information because it benefits you, our organisation or someone else, without causing undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. The legitimate interests are our ability to keep clients informed of our products and services and provide products and services to clients.

Our lawful bases for collecting or using personal information for information or marketing purposes are:

  • Consent - We have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Legitimate interests - We collect or use your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. The legitimate interests are our ability to keep clients informed of our products and services.

Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:

  • Consent - We have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Contract - We have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.


Where we get personal information from

The nature of the personal data may be received from a number of sources, but primarily from you or your organisation.

How long we keep information

We keep certain relevant personal data for a period of 6.5 years from the end of the tax year following the services provided, in part due to the need to keep records for certain legal reasons. 

In relation to personal data retained for marketing purposes, we retain that data until such time as you request to be removed from any marketing list. Only limited data is retained for such purposes. You can request to unsubscribe from marketing emails at any time.

The nature of our work means that we receive client information, including their employee personal data. This personal data is stored securely within our computer, email and filing systems. It is our policy to process or hold the personal data of employees of our clients only at the request of our clients and for no longer than is needed to fulfil an immediate need, process or project. Once the work, process or project has been completed, the information will be deleted or destroyed.

Acting as a Processor and not a Controller 

There may be circumstances where we act as a data processor only and in such cases will only process data on the instructions of the client's Data Controller. It may be, in such circumstances, we process, in addition to the categories of personal data listed in this policy, special categories data and data relating to employment. In such circumstances, all relevant safeguards will apply to such data and processing, and such data will only be used for the purposes it is collected for.

How to complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.

If you remain unhappy with how we've used your data after raising a complaint with us, you can contact the ICO by writing to The Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF or by calling their helpline number 0303 123 1113.

 

Last updated: September 2024

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.