Privacy Notice
Name: Orestone Controls Ltd
Address: Unit 2 & 3 Blandys Farm, Basingstoke, RG23 7ES
Phone Number: 0330 660 0265
E-mail: hello@orestone.uk
Webite: www.orestone.uk
The data we collect about you
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We may collect, use, store and transfer different kinds of personal data about you.
Identity Data: includes your first name first name, maiden name, last name, username or similar identifier, marital status, title, date of birth, gender, as well as employment history, educational or professional background, tax status, employee number, job title and function.
Contact Data: includes phone numbers, delivery address, billing address, residential address, and company details.
Transaction Data: includes your information about payments to and from you, details of products and services you have purchased from us.
Business Information including information provided during the contractual or client relationship between you or your organisation and us, or otherwise voluntarily provided by you or your organisation, as well as information available from public sources.
Technical Data: includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
Profile Data: includes your username and password when you create an account to access our online platform, purchases or orders made by you, your interests, preferences, feedback and survey responses.
Usage Data: includes information about how you use our website, Business Information including information provided during the contractual or client relationship between you or your organisation and us, or otherwise voluntarily provided by you or your organisation, as well as information available from public sources.
Marketing and Communications Data: includes your preferences in receiving marketing from us and our third parties and your communication preferences.
If you provide information to us about any person other than yourself, such as your employees, counterparties, your advisers or your suppliers, you must ensure that they understand how their information will be used, and that they have given their permission for you to disclose it to us and for you to allow us, and our outsourced service providers, to use it.
How we get the personal information and why we have it
Most of the personal information we process is provided to us directly by you for one of the following reasons:
when you or your organisation seek our products and services or use any of our online services;
when you correspond with us by phone, email or other electronic means, or in writing, or when you provide other information directly to us, including to our consultants and staff;
when you subscribe to our service or publications;
when you give us feedback or contact us.
We may also collect information about you indirectly, including:
from publicly accessible sources, e.g. Companies House or HM Land Registry;
from third parties with your consent, e.g. your bank or building society;
from cookies saved by our website in your browser
through our IT systems monitoring your interaction with us, e.g. automated monitoring of your interaction with our websites and other technical systems, such as our computer networks and connections, communications systems, email and instant messaging systems;
through our IT systems monitoring your conduct on our premises, e.g. reception logs, CCTV and access control systems; and
we also collect information of site manager’s such as contact details, working hours from our clients when providing a service at their premises.
How we use your personal data
Under the UK General Data Protection Regulation (UK GDPR), the lawful bases we rely on for processing this information are: Under data protection law, we can only use your personal information if we have a proper reason for doing so, for example:
A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests.
Generally, we do not rely on consent as a legal basis for processing your personal information although we will get your consent before sending third party direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting us.
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so. Please note that we may process your personal information without your knowledge or consent, in compliance with the rules set out in this section, where this is required or permitted by law.
We will use your personal information for the following purposes and on the following grounds:
On the basis of fulfilling our contract with you or entering into a contract with you on your request, in order to:
- register you as a new client and update our client records
- register you as a new supplier and update our supplier records
- process and deliver your order, including sending you updates and managing payments, fees and charges
- manage your subscriptions and user accounts
- deal with and respond to requests, enquiries and complaints
On the basis of our legal obligations, we process your personal information when it is necessary:
- for compliance with tax, accounting and other applicable law and obligations which we are subject to
- for managing your statutory rights; and
- for ensuring security of your personal data by preventing unauthorised access to it.
On the basis of our legitimate interest, we will use your personal information for:
allowing effective performance of our business by ensuring necessary internal administrative, commercial, and security processes (including in finance, controlling, business intelligence, legal & compliance, information security)
- collecting and recovering money you owed to us
- asking you to provide feedback, leave a review or take a survey
- sending you information about and enabling you to participate in events (including online events) organised by us (with or without another party), including seminars and training; leisure, sports and/or charity events; prize draws and competitions; and surveys, marketing campaigns, market analysis or other promotional activities
- communicating with you and keeping you up-to-date on the latest developments, announcements, and other information about our services and solutions (including briefings, newsletters and other information), events and initiatives;
- promoting (including by delivering advertisements) and making suggestions and recommendations to you (including by email or when you visit our website) about products and services that may be of interest to you, as well as to personalise content you see on our website, and measuring and analysing the effectiveness of the promotions and suggestions we serve you
- using statistical data analytics about your use of our website to improve the website, our services, marketing, customer relationships and experiences
- preventing unauthorised access and modifications to systems
- carrying out and dealing with security-related tasks, such as troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data
- allowing interoperability within our applications; and
- establishing, exercising and/or defending our legal rights.
Promotional Communications
- We may use your personal information to send you updates (by email, text message, telephone or post) about our products and services, including exclusive offers, promotions or information about new products and services.
- We have a legitimate interest in processing your personal information for promotional purposes (see above). This means we do not usually need your consent to send you promotional communications. However, where consent is needed, we will ask for this consent separately and clearly.
- We will not sell your personal information to or share it with other organisations for marketing purposes, except where we remain the controller of your personal information and share it with third parties who act as a data processor on our behalf and only process the personal information on our instructions and for the purposes set out above.
- You have the right to opt out of receiving promotional communications at any time by contacting us or using the ‘unsubscribe’ link in emails or ‘STOP’ number in texts.
- We may ask you to confirm or update your marketing preferences if you instruct us to provide further products and services in the future, or if there are changes in the law, regulation, or the structure of our business.
Who we share your personal information with
We routinely share personal information with service providers whom we use to help deliver our products and services to you, such as security providers, site contacts and contractors, payment service providers, warehouses and delivery companies. We only allow our service providers to handle your personal information if we are satisfied they take appropriate measures to protect your personal information. We also impose contractual obligations on service providers to ensure they can only use your personal information to provide services to us and to you.
We may also share personal information with:
- Logistic Providers. when a purchase is made, we may share your name, delivery address and email address with third parties in order to enable shipment of goods.
- credit reference agencies who may, for example, supply anti-fraud and credit-insight information to us
- legal and regulatory authorities. we may need to share your information with the Solicitors Regulation Authority or the Legal Ombudsman if we are providing legal services to you
- our professional advisers such as our lawyers or auditors when they need to give us their professional advice
- public authorities, agencies and other government bodies. We may disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations; and
- potential corporate buyer. We may also share some personal information in the case of transfer of some or all of our business, during re-structuring or change of ownership of the business. Usually, information will be anonymised but this may not always be possible. The recipient of the information will be bound by confidentiality obligations.
How long your personal information will be kept
We will keep your personal information while we are providing products and services to you. Thereafter, we will keep your personal information for as long as is necessary:
- to respond to any questions, complaints or claims made by you or on your behalf
- to show that we treated you fairly; and
- to keep records required by law.
We will not retain your personal information for longer than necessary for the purposes set out in this policy. Different retention periods apply for different types of personal information. By law we must keep basic information about our customers (including Identity, Contact, Financial and Payment Data and Business Information) for six years after they cease being customers. If you want to learn more about our specific retention periods for your personal information, please contact us.
Your rights
Under the applicable data protection laws, you have several rights, as set out below:
- Right to access your personal information. You may request confirmation that we hold personal information about you, as well as access to a copy of any such data.
- Right to rectification. You may ask us to correct any inaccurate information we hold about you.
- Right to erasure (or Right to be forgotten). You may, in certain circumstances, ask us to delete your personal information.
- Right to restriction. You may ask us to restrict the processing of your personal information if (i) you want us to establish the accuracy of the information, (ii) where our use of the information is unlawful but you do not want us to erase it, (iii) where you need us to hold the information even if we no longer require it as you need it to establish, exercise or defend legal claims, or (iv) you have objected to our use of your personal information but we need to verify whether we have overriding legitimate grounds to use it.
- Right to portability. You may request the receipt of the personal information that you have provided to us, in a structured, commonly used and machine-readable form, or its transfer to another organisation.
- Right to object. You may object to our processing of your personal information (i) at any time when your personal information is being processed for direct marketing, or (ii) where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
- Right not to be subject to automated individual decision making. You have the right not be subject to a decision based solely on automated processing (or profiling) that produces legal effects concerning you or similarly significantly affects you.
- Right to withdraw consent. Where our processing of your personal information is based on your consent, you may withdraw this consent at any time, although this will not affect the lawfulness of any prior processing where we relied on your consent.
- Right to make a complaint. You may make a complaint about our processing of your personal information by contacting us via the contact details set out in this privacy policy. While we hope that we would be able to address any issues you have in respect of this processing, you may also make a complaint to the UK’s data protection regulator (see below).
For further information on each of these rights, including the circumstances in which they apply, please contact us or see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals’ rights under the General Data Protection Regulation available via the following link: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/.
If you would like to exercise any of these rights, please contact us – hello@orestonecontrols.co.uk / 0330 660 0265 / Unit 2 & 3 Blandys Farm, Basingstoke, RG23 7ES if you wish to make a request.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Keeping your personal information secure
We have put in place appropriate security measures to prevent personal information from being accidentally lost, used or accessed unlawfully, altered or disclosed. We limit access to your personal information to those who have a genuine business need to access it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
How to complain
If you have any concerns about our use of your personal information, you can make a complaint to us at Data Protection Officer, Unit 2 & 3 Blandys Farm, Basingstoke, RG23 7ES.
You can also complain to the ICO if you are unhappy with how we have used your data. Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk