1 About this Policy
2 About us
We are The GRC Network (Registration Number 12368991), registered at 268 Croyland Road, N9 7BG. For the purposes of data privacy legislation, we will be a ‘controller’.
3 Contacting us
By post: The GRC Network Ltd., 268 Croyland Road, London, N9 7BG
By email: firstname.lastname@example.org
4 Your rights
You have certain rights in relation to your personal data.
4.1 Your rights in connection with personal information
Under certain circumstances, by law you have the right to:
- Object to processing of your personal information where we are relying on a legitimate interest (or that of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
- Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are processing it lawfully.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see above).
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your personal information to another party in a machine-readable, commonly used and structured format.
If you want to exercise any of these rights then please contact us using the details at section 3. The various rights are not absolute and each is subject to certain exceptions or qualifications. For example, if you wish to withdraw your consent or object to processing, we may need to discuss with you whether our use of your data needs to continue for other lawful purposes, such as fulfilment of a legal or contractual requirement.
We will respond to your request within one month of receipt of your request. In some cases we may not be able to fulfil your request to exercise the right before this date, and may need to request more time. Where we cannot provide a full response to you for any reason, we will let you know about this in our initial reply to your request.
4.2 Your duty to inform us of changes
It is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during your working relationship with us.
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). In some cases, we may charge a reasonable fee if your request for access is clearly unfounded or excessive, or if you request multiple copies of the information. Alternatively, we may refuse to comply with the request in such circumstances.
4.4 What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
4.5 Right to complain
If you wish to request further information about any of the above rights, or if you are unhappy with how we have handled your information, please contact us on the contact details contained in section 3.
If you are not satisfied with our response to your complaint or believe our processing of your information does not comply with data protection law, you can make a complaint to the Information Commissioner’s Office: https://ico.org.uk/global/contact-us/ or 0303 123 1113.
5 Information we collect
5.1 Information you provide to us
This section details the information we collect about you in the course of your involvement with The GRC Network and otherwise in your interaction and correspondence with us and our representatives. We will collect:
- basic personal details which can include your name and address (and proof of name and address), email address, telephone number, any other contact details you supply
- records of all communications including electronic communications with our staff and meeting notes (see below for more details); and employment and education history (where you send us this information as part of a membership application process).
We can receive information about you from publicly available sources such as LinkedIn or your company websites.
5.2 Information from your use of our website
We collect information about your use of our website and the devices you use. We collect information on:
- how often you access our website;
- the way in which you navigate around it;
- how long you spend on particular pages;
- the operating system, hardware, software versions, browser configuration, display size, browser configuration of the devices you use; and
- connection information such as IP addresses.
6 How we use the information we collect
6.1 General uses of information
The information which we collect and what we use it for will depend on the nature of our relationship with you. We use your information:
- to provide you with services which you have requested and/or to fulfil our contractual obligations towards you;
- to fulfil our contractual obligations to third parties to whom you have provided your information;
- for our internal business administration and record-keeping purposes;
- to respond to your enquiries submitted through our website; and
- for legal and regulatory compliance purposes, including as necessary to respond to governmental, regulatory or law enforcement agency requests.
6.2 Information for marketing purposes
We use your information to identify services and events that we think may be of interest to you.
We will only send you marketing messages where you have consented to such contact, or in the case of services, where these are similar to those that we have already provided to you.
As a member of The GRC Network you have the right to ask us not to not send you marketing messages by post, telephone or e-mail or any combination of these at any time by resigning your membership. If you have a different relationship with us you have the right to ask us not to send you marketing messages by post, telephone or email or any combination of these at any time.
You can do this:
- by replying directly to the marketing message;
- at any time by contacting us (see section 3);
- use the unsubscribe button at the bottom of each email.
Periodically, we will remind you (possibly along with other communications) that you may unsubscribe if you no longer wish to receive communications from us. If you choose to unsubscribe, we will cease to send you such communications as mentioned above.
7 Our bases for collecting and using the information
- the use of personal data in this way is necessary for the performance of a contract with you for provision of our services or to take steps at your request prior to entering into such a contract;
- we have legal obligations that we have to discharge;
- the use of your personal data is necessary for our legitimate interests in ensuring the quality of the services we provide to you; collecting information for marketing purposes; communicating with you, and statistical analysis;
- you have consented to such use; and/or
- to establish, exercise or defend our legal rights for the purposes of legal proceedings.
If the provision of your personal information is a legal or contractual requirement or a requirement necessary to enter into a contract with us, and you choose not to provide it, we may not be able to perform some of the tasks we need to in order to provide certain services to you.
If you do choose to provide your consent you can withdraw it at any time by contacting us (see section 3).
8 Sharing your information
Where necessary, we disclose your personal data to third parties that are specifically engaged by us to provide services to us and/or you, in which case we will require those parties to keep that information confidential and secure and to use it solely for the purpose of providing the specified services to us and/or you.
9 Where we store your information
We transfer, use and/or store your personal information outside of the European Economic Area (“EEA”) and the laws of some of these destination countries may not offer the same standard of protection for personal information as countries within the EEA. It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers (for example, those who supply support services to us).
Transfers to our third party service providers are to enable them to use and store your personal information on our behalf. We will, however, put in place, where necessary, appropriate security procedures in order to protect your personal information.
10 Keeping your information
We will keep your information only for as long as necessary depending on the purpose for which it was provided. Details of retention periods for different aspects of your personal information are available in our retention policy which you can request by contacting us (see section 3).
When determining the relevant retention periods, we will take into account factors including:
- our relationship with you;
- legal obligations under applicable law to retain data for a certain period of time;
- statute of limitations under applicable law(s);
- (potential) disputes; and
- guidelines issued by relevant supervisory authorities.
We acknowledge that the information you provide may be confidential and will maintain the confidentiality of and protect your information in accordance with our normal procedures and all applicable laws. We employ appropriate technical and organisational security measures to help protect your personal data against loss and to guard against access by unauthorised persons. We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
In addition, those employees, agents, contractors and other third parties who process your personal data will only do so on our instructions and they will be subject to a duty of confidentiality.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data. Any transmission is at your own risk. Once we have received your information, we will use procedures and security features to try to prevent unauthorised access.
12 Links to other websites