How does HR First collect and process information about you and who is responsible for it?
HR First may collect and process information about you from several sources which are outlined here.
- When you enter your information on a contact form on our website. The data controller for this data is HR First.
- When you enter your information into a newsletter subscription form. The data controller for this data is HR First.
- When information is received through networking activity by a staff member of HR First with information about yourself or your company and where it is understood there is a legitimate interest in receiving services from HR First. The data controller for this information is HR First.
- When you or your company or employing company enters into a client agreement with HR First and provides information about you to HR First and HR First for the purposes of delivering or receiving services by HR First under a service agreement it is necessary to transfer data about you or your company or your employer to another service supplier in order to deliver the service. In this case, only information about you that is relevant to the delivery of these services should be shared by your employer with HR First. The data controller for this information is your company or employing company.
What sort of information about you is being collected and processed by HR First?
In line with the expectations of the Data Protection Act (2018) and the GDPR regulations, we only collect the necessary information that is required to allow us to promote and deliver our services fairly and effectively.
How can you find out what information HR First holds about you?
Under the Data Protection Act (2018) and European GDPR regulations, any person about whom organisations holds data (a ‘data subject’) is allowed to request a copy of that information. This is called a Subject Access Request (‘SAR’).
There is guidance for individuals who want to make a Subject Access Request on the website of the regulator, the Information Commissioners Office (‘ICO’) and it is strongly recommended that you review this guidance before submitting your request to avoid any delays. There is also information on this site about requirements for SARs for both the requesting and responding parties, and who SARs should be sent to.
If you wish to make a subject access request to HR First, these should be submitted via email to info@hrfirst.co.uk or by post to : HR First, HR First House,19 Downside Road, Winchester, Hants, SO22 5LT.
Why is HR First collecting and processing your information?
We collect and process information about you for several purposes depending on the context of the information and how it was collected:
- to analyse website usage so we can determine how we can make improvements and if you subscribe to our newsletter, to email you about other directly related products and services we think may be of interest to you based on our understanding of your legitimate interest.
- to personalise your repeat visits to our website. If you submit your information on a contact form with interest in accessing services provide by HR First.
- to survey contacts about activity directly related to our marketing activity, service delivery or directly related projects undertaken by HR First.
- to provide outsourced HR services to your company or employing company in line with client agreements made with the company.
If you provide your information to us through this website, we would consider this to mean you have a legitimate interest in our services, and that you are happy to be contacted in relation to those services, and that you are happy for us to share this with our relevant data sub-processors outlined below in order for our services to be delivered to you.
How long is your information kept, and can you make sure it is accurate?
HR First must retain some information for periods in line with regulatory or legislative requirements. If there is no regulatory or legal requirement to retain your information, then it will be kept until one of the following is true:
- You request for your data to be erased (see the section below) and this can be legally fulfilled.
- The data is known to be or is suspected to be invalid/inaccurate by HR First.
- The data is known to be or is suspected to be no longer appropriate for use for reasons of legitimate interest by HR First (as outlined above).
If you believe any information held by HR First is incorrect and wish to amend it, please contact us in writing. Please see the section at the end of this Privacy Notice about how to contact us by email or post.
Can you opt-out of marketing or request for your information to be erased?
HR First does not wish to undertake marketing activity to those who do not wish to receive it, and HR First will always comply with a request from you to opt-out of receiving marketing material. We will comply with a request from you for your information to be erased if it is appropriate to do so (a) in accordance with the Data Protection Act (2018) or the European GDPR requirements and (b) if there is no legitimate justification for retaining the information.
In some cases, we may not be able to agree, wholly or in part, to your request for your information to be erased if there is a legitimate requirement to keep it. An example of a legitimate requirement would be if you are an employee of a company using HR First for outsourced HR services, and you are involved in some way with an HR issue which is being dealt with by HR First. In such a case, there is a legitimate requirement to retain relevant information relating to that issue in order for your employer to be able to resolve the HR issue and any related legal matters. This may extend beyond the apparent resolution of the issue if there is a reasonable argument that the information may need to be revisited.
You can:
- Use the ‘opt-out’ or ‘unsubscribe’ link in any marketing communication from HR First if you do not wish to be contacted with any marketing communications.
- Request directly by email info@hrfirst.co.uk if you do not wish to be contacted with any marketing communications.
- Request by email to info@hrfirst.co.uk if you wish for your information to be erased (the right to be forgotten).
- Contest our determination of a legitimate requirement to retain your information on a case-by-case basis.
Who else is your information shared with?
HR First does transfer your information to third parties outside of HR First where required to do so to deliver a service.
In order to facilitate marketing and delivery of our services to those who have provided their information and who we believe have a legitimate interest in our business, we may share your information with specific ‘sub-processors’ with whom we have data-sharing agreements. We want to be clear and transparent with you about the sub-processors we use and what we have done to ensure that they take your data protection as seriously as we do.
HR First will share your information for marketing or service delivery purposes with the sub-processors below. This is only shared for the purpose of sending you marketing content or survey/research material relating to HR First’s own services, or if necessary to be able to deliver HR services to your company/employing company in line with our client agreements and related contracts.
These sub-processors are:
Mailchimp
Mailchimp is an online system which HR First uses to send out our newsletters, promotional materials and marketing-related communications to clients, prospective clients who have chosen to share their data with HR First.
Microsoft
We use Microsoft Office 365 to manage our emails and file storage, which may include some information that has been collected through our website or other sources relating to marketing and surveying activity. Microsoft have confirmed that they are DPA/GDPR compliant and have updated their terms and conditions to reflect this. Microsoft may transfer data outside of the EEA but will only do so in a manner which protects your data and meets the requirements of the GDPR and the Data Protection Act (2018).
We use Google Analytics and Google Tag Manager to monitor how you use the site to ensure that we can continue to provide you with the best possible experience online. Google may transfer data outside of the EEA but will only do so in a manner which protects your data and meets the requirements of the GDPR and the Data Protection Act (2018).
How is the data stored?
The information we collect is stored in secure cloud vaults that operate inside the EEA. All information is stored in an encrypted form. Information held by Microsoft on our behalf may be transferred outside of the EEA but only where there are appropriate protections in place and in line with GDPR guidance.
Cookies
Cookies are text files placed on your computer to collect standard internet log information and visitor behaviour information. This information is used to track visitor use of the website and to compile statistical reports on website activity. You can set your browser not to accept cookies using the following instructions, although in a few cases some of our website features may not function as a result. You can configure cookie settings in your browser’s settings.
Detailed step by step guidance on how to control and delete cookies is also available from www.aboutcookies.org.
Other websites
Our website contains links to other websites. This privacy policy only applies to this website so when you link to other websites you should read their own privacy policies.
Changes to our Privacy Notice
We keep our Privacy Notice under regular review and we will place any updates on this web page.
How to contact HR First
If you would like to contact HR First in relation to any matter covered in this Privacy Notice or with queries about our website or marketing/survey activity, please email info@hrfirst.co.uk or write to us at HR First, HR First House, 19 Downside Road, Winchester, Hants SO22 5LT.