This policy sets out the data-protection principles Cowiretech Limited applies when handling personal information in connection with website enquiries and business communications.
1. Data-protection principles
Personal information should be processed lawfully, fairly and transparently; collected for specified purposes; limited to what is necessary; kept accurate; retained no longer than necessary; and protected with appropriate security. The company should also be able to demonstrate reasonable accountability for its processing activities.
2. Lawful processing
Before personal information is used, the purpose and an appropriate lawful basis should be identified. Depending on the situation this may include contract-related processing, legitimate interests, legal obligations or consent.
3. Data minimisation and accuracy
Only information reasonably required for the relevant business purpose should be collected. Reasonable steps should be taken to correct or update inaccurate information where necessary.
4. Individual rights
Requests concerning access, rectification, erasure, restriction, objection, portability or automated decision-making should be recognised and handled in accordance with applicable UK data-protection law.
5. Subject access requests
Requests for a copy of personal information should be logged, assessed and handled within the applicable legal timescale. Identity may be checked where reasonable and proportionate. Relevant systems and correspondence should be searched while respecting information about other people and applicable exemptions.
6. Retention
Personal information should not be retained indefinitely without a business or legal reason. Retention should take account of the nature of the information, the purpose for which it is held and any relevant contractual, legal or dispute-related period.
7. Security and access
Access to personal information should be limited to people or service providers that reasonably need it. Appropriate account security, updates, backups and access controls should be used in proportion to the systems and information involved.
8. Processors and suppliers
Where another organisation processes personal information on Cowiretech's behalf, its role and safeguards should be considered and appropriate contractual arrangements used where required.
9. International transfers
If personal information is transferred outside the UK, the transfer should use an available lawful mechanism and any additional safeguards required by UK data-protection legislation.
10. Personal-data breaches
Suspected loss, unauthorised disclosure, access or alteration of personal information should be assessed promptly. The company should contain the incident where possible, document material decisions and make any required notification to the ICO or affected individuals where the legal threshold is met.
11. Privacy by design
New website features, systems and processes should consider data minimisation, security, transparency and retention from the outset rather than treating privacy as an afterthought.
12. Contact
Questions about this policy or requests concerning personal information can be sent to info@cowiretech.co.uk.