Privacy policy

July 2024

This privacy policy aims to give information on how Inform Holdings Ltd collects, stores, uses and shares personal data.  It also explains subjects’ rights in relation to their personal data and how to contact us or supervisory authorities in the event of a complaint.

When we process personal data of UK residents, we are subject to the UK General Data Protection Regulation, the Data Protection Act (2018) and the Privacy and Electronic Communications Regulation.

This privacy policy supplements other notices and privacy policies and is not intended to override them. Any questions about this policy can be sent to us at:

Inform Holdings Ltd
Unit 613
6th Floor
125 Deansgate
Manchester
M3 2BY

Tel: 0161 669 8165
Email: dataprotection@informcpi.com 


Changes to the privacy policy

We keep our privacy policy under regular review. It is important that the personal data we hold is accurate and current. Subjects should keep us informed if personal data changes during their relationship with us.


The data we collect

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include anonymised data where the identity has been removed.

We may collect, use, store and transfer different kinds of personal data as follows:

  •  identity data, which includes first name, maiden name, last name, username or similar identifier, title
    •    contact data, which includes service address, correspondence/billing address, delivery address, email address and telephone numbers (landline and mobile phone number)
    •    financial data, which includes bank account details
    •    transaction data, which includes details about incoming and outgoing payments and other details of products and services have purchased from us.
    •    technical data, which includes internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices used to access our services.
    •    profile data, which includes username, purchases or orders made, interests, preferences, feedback and survey responses.
    •    usage data, which includes information about us of our website and software, products and services.
    •    promotional and communications data, which includes preferences in receiving marketing from us and communication preferences.


We also collect, use and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from personal data but is not considered personal data in law as this data will not directly or indirectly reveal identity. For example, we may aggregate usage data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect aggregated data with personal data so that it can directly or indirectly identify subjects, we treat the combined data as personal data which will be used in accordance with this privacy policy.

We do not collect special categories of personal data.


How personal data is collected

We use different methods to collect data including through:

  1. i)    Direct interactions. Subjects may give us their identity, contact and financial data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data when they:
  •  apply for our products or services
    •    are allocated a user account for our software systems
    •    request marketing information to be sent to them
    •    give us feedback or contact us
  1. ii)    Automated technologies or interactions. As subjects interact with our websites, we will automatically collect technical data about their browsing actions and patterns. We collect this personal data by using cookies and other similar technologies. Please see our Cookie Policy for further details.

iii)    Identity and Contact Data from publicly available sources such as Companies House and the Electoral Register based inside the EU.

 

How we use personal data

We will only use personal data when the law allows us to. Most commonly, we will use personal data in the following circumstances:

  •  Where we need to perform the contract, we are about to enter into or have entered into.
    •    Where it is necessary for our legitimate interests and the subject’s interests and fundamental rights do not override those interests.
    •    Where we need to comply with a legal obligation.
    •    Where the processing is necessary for us to perform a task in the public interest.

Generally, we do not rely on consent as a legal basis for processing personal data although we will get consent before sending third party direct marketing communications via email or text message. Subjects have the right to withdraw consent to marketing at any time by contacting us.


Purposes for which we use personal data

The following describes how we use personal data and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate. We may process personal data for more than one lawful ground depending on the specific purpose for which we are using it.

Purpose/Activity Type of data Lawful basis for processing including basis of legitimate interest
To register a new customer and verify their identity when they use our services or contact us (a) Identity
(b) Contact
Performance of a contract

To process and deliver an order including:

(a)    Manage payments, fees and charges
(b)    Collect and recover money owed to us

(a) Identity
(b) Contact
(c) Financial
(d) Transaction
(e) Marketing and Communications
(a) Performance of a contract
(b) Necessary for our legitimate interests (to recover debts due to us)
To monitor, record, store and use any email or other electronic communications for training purposes, so that we can check any instructions given to us and to improve the quality of our customer service, and in order to meet our legal and regulatory obligations (a) Identity
(b) Contact
(c) Financial
(d) Transaction
(e) Profile
(f) Marketing and Communications
(a) Necessary for our legitimate interests
(b) Necessary to comply with a legal obligation
To manage customer  relationships which may include:
(a) Notifying customers about changes to our website or applications, services, terms or privacy policy
(b) Asking customers to leave a review or take a survey
a) Identity
(b) Contact
(c) Profile
(d) Marketing and Communications
(a) Performance of a contract
(b) Necessary to comply with a legal obligation
(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)
To enable subjects to complete a survey (a) Identity
(b) Contact
(c) Profile
(d) Usage
(e) Marketing and Communications
(a) Performance of a contract
(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
To administer and protect our business and our websites (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) (a) Identity
(b) Contact
(c) Technical
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation
To deliver relevant content and advertisements and measure or understand the effectiveness of any advertising (a) Identity
(b) Contact
(c) Profile
(d) Usage
(e) Marketing and Communications
(f) Technical
Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences (a) Technical
(b) Usage
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our websites updated and relevant, to develop our business and to inform our marketing strategy)
To make suggestions and recommendations about goods or services that may be of interest (a) Identity
(b) Contact
(c) Technical
(d) Usage
(e) Profile
(f) Marketing and Communications
Necessary for our legitimate interests (to develop our products/services and grow our business)
Conducting checks to identify our customers and verify their identity
Screening for financial and other sanctions or embargoes
Other processing necessary to comply with professional, legal and regulatory obligations that apply to our business, e.g. under health and safety regulations or rules issued by our professional regulator
(a) Identity
(b) Contact Data
To comply with our legal and regulatory obligations
Gathering and providing information required by or relating to audits or quality checks, e.g. the audit of our accounts, enquiries or investigations by regulatory bodies (a) Identity
(b) Contact Data
(c) Financial
(d) Transaction
(a) To comply with our legal and regulatory obligations
(b) Necessary for our legitimate interests or a those of a third party, i.e. to maintain our accreditations so we can demonstrate we operate at the highest standards
Ensuring business policies are adhered to, e.g. policies covering security and internet use (a) Technical
(b) Usage
Necessary for our legitimate interests or those of a third party, i.e. to make sure we are following our own internal procedures so we can deliver the best service to customers
Ensuring the confidentiality of commercially sensitive information (a) Identity
(b) Contact Data
(c) Financial
(d) Transaction
(e) Technical
(f) Profile
(a) Necessary for our legitimate interests or those of a third party, i.e. to protect trade secrets and other commercially valuable information
(b) To comply with our legal and regulatory obligations
Preventing unauthorised access and modifications to systems (a) Technical
(b) Usage
(a) Necessary for our legitimate interests or those of a third party, i.e. to prevent and detect criminal activity that could be damaging for us and for you
(b) To comply with our legal and regulatory obligations
Statutory returns (a) Identity
(b) Contact Data
(c) Financial
(d) Transaction
To comply with our legal and regulatory obligations
Ensuring safe working practices, staff administration and assessments (a) Identity
(b) Contact
(c) Technical
(d) Usage
(e) Profile
(f) Marketing and Communications
(a) To comply with our legal and regulatory obligations
(b) Necessary for our legitimate interests or those of a third party, e.g. to make sure we are following our own internal procedures and working efficiently so we can deliver the best service customers
Marketing our services and applications to:
•    existing and former customers
•    potential customers who have previously expressed an interest in our services
•    potential customers with whom we have had no previous dealings
(a) Identity
(b) Contact
(c) Technical
(d) Usage
(e) Profile
(f) Marketing and Communications
Necessary for our legitimate interests or those of a third party, i.e. to promote our business to existing and former customers
Credit reference checks via external credit reference agencies (a) Identity
(b) Contact Data
Necessary for our legitimate interests or those of a third party, i.e. to ensure our customers are likely to be able to pay for our products and services
To compare and provide the personal data of individuals associated with businesses within our SBRR case management system(s) operated by us for case management purposes (a) Identity
(b) Contact
(a) Necessary for our legitimate interests
(b) Necessary for us to perform a task in the public interest


Promotional information

We strive to provide choices regarding certain personal data uses, particularly around marketing and advertising.

i)    Promotional offers from us

We may use Identity, Contact, Technical, Usage and Profile Data to form a view on what we think customers may want or need, or what may be of interest. This is how we decide which products, services and offers may be relevant.

Subjects will receive marketing communications from us if they have requested information from us or purchased goods or services from us and have not opted out of receiving that information.

iii)    Opting out

You can ask us to stop sending promotional messages at any time by contacting us or by following the unsubscribe links on any promotional message sent.

Where a subject opts out of receiving these promotional messages, this will not apply to personal data provided to us as a result of a product/service purchase, warranty registration, product/service experience or other transactions.


Cookies

It is possible to set web browsers to refuse all or some browser cookies, or to display alerts when websites set or access cookies. If cookies are disabled or refused, some parts of our website may become inaccessible or not function properly. For more information about the cookies we use, please see our Cookie Policy.


Change of purpose 

We will only use personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.

If we need to use personal data for an unrelated purpose, we will notify the subject and explain the legal basis which allows us to do so. We may process personal data without knowledge or consent, in compliance with the above rules, where this is required or permitted by law.


Disclosures of personal data

We routinely share personal data with:

  •  third parties we use to help us run our business; namely Amazon Web Services (AWS) based in the EU and Datel based in the United Kingdom;
    •    third parties approved by subjects, e.g. social media sites they choose to link their account to or third-party payment providers;
    •    credit reference agencies;
    •    our bank;
    •    our customers via our case management system(s).

We only allow our service providers to handle personal data if we are satisfied that they take appropriate measures to protect it. We may also share personal data with external auditors, e.g. in relation to accreditation and the audit of our accounts.

We may disclose and exchange information with law enforcement agencies and regulatory bodies such as Ofcom or the Information Commissioner’s Office, to comply with our legal and regulatory obligations.

We require all third parties to respect the security of personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use personal data for their own purposes and only permit them to process personal data for specified purposes and in accordance with our instructions.


Data location and retention

Data may be held at our offices and those of our group companies, third party agencies, service providers, representatives and agents as described above (see above: ‘Disclosures of personal data’).

We will keep personal data for as long as is necessary:

  •  perform services as agreed with customers
    •    to respond to any questions, complaints or claims made;
    •    to show that we treated subjects fairly;
    •    to keep records required by law.

We will not retain personal data for longer than necessary for the purposes set out in this notice. Different retention periods apply for different types of personal data. When it is no longer necessary to retain personal data, we will delete or anonymise it.


Subject’s rights

Subjects have the following rights in relation to personal data:

Access The right to be provided with a copy of their personal data (the right of access)
Rectification The right to require us to correct any mistakes in their personal data
To be forgotten The right to require us to delete their personal data – in certain situations
Restriction of processing The right to require us to restrict processing of their personal data, in certain circumstances, e.g. if they contest the accuracy of the data
Data portability The right to receive the personal data provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party, in certain situations
To object

The right to object:

•    at any time to their personal data being processed for direct marketing (including profiling);
•    in certain other situations, to our continued processing of their personal data, e.g. processing carried out for the purpose of our legitimate interests.

Not to be subject to automated individual decision making The right not to be subject to a decision based solely on automated processing (including profiling) that produces direct legal effects or similarly significantly affects them.

For further information on each of those rights, including the circumstances in which they apply, subjects can contact us or see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals’ rights under the General Data Protection Regulation.

Subjects wishing to exercise any of those rights should contact our Data Protection Lead at dataprotection@informcpi.com or in writing to:

Data Protection Lead
Inform Holdings Limited
Unit 613
6th Floor
125 Deansgate
Manchester
M3 2BY

This contact should include:

  •  enough information to identify the subject
    •    proof of their identity and address (a copy of their driving licence or passport and a recent utility or credit card bill); and
    •    let us know what right they want to exercise and the information to which their request relates.


Keeping personal data secure

We have appropriate security measures to prevent personal data from being accidentally lost or used or accessed unlawfully. We limit access to personal data to those who have a genuine business need to access it. Those processing personal data will do so only in an authorised manner and are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected data security breach. We will notify subjects and any applicable regulator of a suspected data security breach where we are legally required to do so.

Unfortunately, no data transmission over the internet or any other network can be guaranteed as 100% secure.  As a result, whilst we strive to protect personal data, we cannot ensure and do not warrant the security of any information transmitted to us, and this information is transmitted at subjects’ own risk.


Complaints

We hope that our Data Protection Lead can resolve any query or concern raised about our use of personal data.

The General Data Protection Regulation also gives subjects the right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns or telephone: 0303 123 1113.


Cookie Policy

Our website and web applications use cookies to distinguish you from other users. This helps us to provide you with a good experience when you browse our website or use our applications, and also helps us to improve them.

A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer, if you agree. Cookies contain information that is transferred to your computer’s hard drive. They allow a website user to distinguish the activities carried out from your device from other users of that website.  Each website can send its own cookie to your browser or device if your browser’s preferences allow it, but (to project your privacy) your browser only permits a website to access the cookies it has already sent to you, not the cookies sent to you by other websites.

By using our website or web applications, you agree and consent that we can store and access cookies, IP addresses and use other tracking technology methods to enable the website functionality, collect aggregated data about website usage, improve your online experience and manage and tailor our promotional and service communications with you.  There are means of disabling cookies as set out below if you choose to do so, however this may affect your use of the website.  See below for more information about what cookies are, and how we use them.

Our website and web applications use different types of cookies.  Session cookies exist just for your session on our website and persistent cookies exist for a period of time after your visit.  First party cookies are cookies set by our website or web applications.  We utilise both session and persistent cookies, and first party cookies.

We may use the following cookies:

  • Essential cookies. These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas.
  • Analytical or performance cookies. These allow us to recognise and count the number of visitors and to see how visitors move around our website and web applications when they are using them. This helps us to improve the way they work, for example, by ensuring that users are finding what they are looking for easily.
  • Functionality cookies. These are used to recognise you when you return to our websites. This enables us to personalise our content for you, greet you by name and remember your preferences, where relevant.
  • Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website more relevant to your interests.

We use Twitter, Facebook and tracking applications as part of our software service and website provision. As part of these we use different types of cookies. You can find more information about the individual cookies we use and the purposes for which we use them below:


Essential and functionality cookies

  • ASP.Net_SessionID: this is part of running our software. It lasts for the session only
  • AnalyseToken: this is a session cookie used as part of our software navigation. It has a lifespan of 90 minutes
  • Personalization_id: this is part of the Twitter feed on the home page of our some of our software. It has a lifespan of 6 months


Analytical or performance cookies

  • cookieconsent_dismissed: this logs whether consent for use of non-essential cookies has been granted. It has a lifespan of one month
  • Lfuuid: this allows our websites to track visitor behaviour.  Tracking is performed anonymously unless the user identified.  This is a third party, persistent cookie
  • _ga: these are used to store, count and track page views. They have a lifespan of one year
  • wisepops_visits: helps provide pop ups on our websites. It lasts for 2 years
  • wisepops: helps provide pop ups on our websites. It has a lifespan of 2 years
  • wisepops_session: helps provide pop ups on our websites. It lasts for the session only
  • _fbp: this is a Facebook cookie, used to store and track visits across websites. Its lifespan is 3 months
  • Lfuuid: this is used to track visitor behaviour. This is a persistent cookie
  • _gid: this is used to store and count page views. Its lifespan is 1 day
  • _gtm_referrer: this is used for service requests. It lasts for the session only
  • _zlcmid: this is used to store a user ID. It has a lifespan of 1 year
  • _gcl_au: this is used to store and track conversions. This is a persistent tracking cookie


We do not share the information collected by the cookies with any third parties.

Modern browsers allow you to change your cookie settings.  You can set your browsers or devices to accept all cookies, to notify you when a cookie is issued, or not to receive cookies at any time. The last of these means that certain personalised features cannot the be provided to you and accordingly you may not be able to take full advantage of all of the website’s features.

You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our websites.

Except for essential cookies, all cookies will expire when the browser session expires.

Looking for something?
Search here