Who We Are
Ian Smith Group (‘ISG’ ‘we’ or ‘us’ or ‘our’) gather and process your personal information in accordance with this privacy notice and in compliance with the relevant data protection Regulation and laws. This notice provides you with the necessary information regarding your rights and our obligations, and explains how, why and when we process your personal data.
Ian Smith Groups registered office is at 205 Great Bridge Street, West Bromwich, B70 0DJ and we are a company registered in England and Wales under company number 1421681. We are registered on the Information Commissioner’s Office Register; registration number Z5566870 and act as the data controller when processing your data. Our designated Data Protection Lead is Jonathan Harrod, who can be contacted at firstname.lastname@example.org
Information That We Collect
ISG processes your personal information to meet our legal, statutory and contractual obligations and to provide you with our products and services. We will never collect any unnecessary personal data from you and do not process your information in any way, other than as specified in this notice.
The personal data that we collect from is: –
- Business Email Address, business phone number,
We collect information in the below ways: –
Data freely given by you or your business
Online identifiers, such as: your IP address, cookie information, traffic data, location data, weblogs, page functionality tracking and other communication data.
How We Use Your Personal Data (Legal Basis for Processing)
ISG takes your privacy very seriously and will never disclose, share or sell your data without your consent; unless required to do so by law. We only retain your data for as long as is necessary and for the purpose(s) specified in this notice. Where we use your data to send you offers and marketing that we believe to be of legitimate interest to you, you are free to ‘opt out’ of these at any time. The purposes and reasons for processing your personal data are detailed below: –
- We collect your personal data in the performance of a contract or to provide a service and to ensure that orders are completed and can be sent out to your preferred address
- We collect and store your personal data as part of our legal obligation for business accounting and tax purposes
- We will occasionally send you marketing information where we have assessed that it is beneficial to you as a customer and in our interests. Such information will be non-intrusive and is processed on the grounds of legitimate interests
You have the right to access any personal information that ISG processes about you and to request information about: –
- What personal data we hold about you
- The purposes of the processing
- The categories of personal data concerned
- The recipients to whom the personal data has/will be disclosed
- How long we intend to store your personal data for
- If we did not collect the data directly from you, information about the source
If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the information and we will strive to do so as quickly as possible; unless there is a valid reason for not doing so, at which point you will be notified.
You also have the right to request erasure of your personal data or to restrict processing (where applicable) in accordance with the data protection laws; as well as to object to any direct marketing from us. Where applicable, you have the right to data portability of your information and the right to be informed about any automated decision-making we may use.
If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the request; this is to ensure that your data is protected and kept secure.
Sharing and Disclosing Your Personal Information
We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this notice or where there is a legal requirement ISG uses third parties to provide the below services and business functions; however, all processors acting on our behalf only process your data in accordance with instructions from us and comply fully with this privacy notice, the data protection laws and any other appropriate confidentiality and security measures.
TNT, Fedex, DPD, TRAX(APC), UK Mail, RDM Distribution
Office Friendly, Mail Chimp
ISG takes your privacy seriously and takes every reasonable measure and precaution to protect and secure your personal data. We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place,
We protect ourselves electronically via gateway firewall in order to prevent unauthorised access via the WAN address. Each site is connected via a VPN to a secure firewall located in a remote Newbury datacentre. Ian Smith’s data is separated from that of other clients using vLANS.
Our end users connect to their environment using a Microsoft terminal server. Access is restricted to the three offices which are located in West Bromwich, Norwich and Stoke. Any remotehome users can only connect via a secure SSL VPN tunnel which is managed through their bunker virtual firewall and which utilises individual active directory credentials as an extra layer of security. All endpoints are installed with anti-virus protection and any automated alerts generated by the system are received, managed and resolved via the CIS helpdesk and Sophos control portal.
We have recently introduced group policies which force an automatic log off of end users after a certain period of inactivity. Users are also periodically made to change their access credentials. Users have been prevented from copying and pasting data from the terminal server connection to their local machine.
Consequences of Not Providing Your Data
You are not obligated to provide your personal information to ISG however, as this information is required for to provide you with our services/deliver your products/legitimate interests, we will not be able to offer some/all our services without it.
As noted in the ‘How We Use Your Personal Data’ section of this notice, we occasionally process your personal information under the legitimate interests’ legal basis. Where this is the case, we have carried out a thorough Legitimate Interests’ Assessment (LIA) to ensure that we have weighed your interests and any risk posed to you against our own interests; ensuring that they are proportionate and appropriate, we use legitimate interest for the following reasons:
Invoicing and Billing – we need your details to accurately record payments that you make to us and to send you Invoices and Statements relating to your purchases or your business account.
Deliver Services & Goods – we need your details to enable us to accurately deliver the goods, services and any contractual obligations we have with you.
Marketing Subject – If we have identified you as a potential / existing customer with legitimate interest in our products or services we may market them to you. All our marketing is well thought out and must pass our thorough in house ‘considered marketing’ process before we contact you. In the event that you are not interested in our goods or services we will always give you the option to and respect your wish to ‘opt out’.
Responding to an Enquiry –If you have contacted us we will use you data to respond to your enquiry.
How Long We Keep Your Data (retention periods)
ISG only ever retains personal information for as long as is necessary and we have strict review and retention policies in place to meet these obligations. We will only retain your data as below:
Invoicing and Billing – UK Tax law dictates we hold your details for 7 years from the last time we invoice you.
Deliver Services & Goods – If you engage in our goods and services we will invoice you for them so we will retain the necessary data for 7 years after the last time we invoice you.
Marketing Subject – If you ‘opt out’ of our marketing we will remove your details immediately. If you engage with us we will hold that data for 3 months after the last engagement. Should you go on to purchase goods or services from us the Invoicing and Billing terms will apply.
Responding to an Enquiry – We will delete you details 3 months after the response, unless we engage further or you purchase services or goods from us in which case the above periods apply.
Lodging A Complaint
ISG only processes your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, you have the right to lodge a complaint with our company Data Lead or the supervisory authority (relevant contact information below).
Ian Smith Group
205 Great Bridge Street
Information Commissioner’s Office (ICO)
Tel: 0303 123 1113