WHO WE ARE
The Castlecroft Group (Which comprises Castlecroft Securities Ltd, Scotloo, Scotbox, Scotloo Waste Management and JKB Investments Ltd) (“we”, “us”) is the operator of the websites Castlecroft.com, Scotloo.com, Scotbox.com. We collect, use and are responsible for certain information about you. When we do so, we are regulated under the General Data Protection Regulation which applies across the European Union (including the United Kingdom) and we are responsible as ‘controller’ of that personal information for the purposes of those laws. The person responsible for how we handle personal information is Mrs Anne Smith
THE PERSONAL INFORMATION WE COLLECT AND USE
Personal information provided by you
In the course of operating our business, we collect personal information when you provide it to us, such as your name, postal address, email address, phone numbers, date of birth, payment details.
We also collect personal information from you if you apply for a job with us or work for us for any period of time. In this context, personal information we gather may include: contact details, financial and payment details, details of education, qualifications and skills, marital status, nationality, NI number, job title, and CV.
Personal information provided by third parties
Occasionally we may receive information about you from other sources (such as credit reference agencies), which we will add to the information we already hold about you in order to help us provide services to you and to improve and personalise our service to you. If you apply for a job with us, we may receive information from the people who provide references.
Personal information about other individuals
If you give us information on behalf of someone else as an alternate contact, referee or next of kin, you confirm that the other person has agreed that you can:
- give consent on his/her behalf to the processing of his/her personal data;
- receive on his/her behalf any data protection notices;
Sensitive personal information
We will not usually ask you to provide sensitive personal information. We will only ask you to provide sensitive personal information if we need to for a specific reason, for example, if we believe you are having difficulty dealing with your account due to illness. If we request such information, we will explain why we are requesting it and how we intend to use it.
Sensitive personal information includes information relating to your ethnic origin, political opinions, religious beliefs, whether you belong to a trade union, your physical or mental health or condition, sexual life, and whether you have committed a criminal offence. We will only collect your sensitive personal information with your explicit consent.
We do not knowingly collect personal data relating to children under the age of 16. If you are a parent or guardian of a child under the age of 16 and think that we may have information relating to that child, please contact us. We will ask you to prove your relationship to the child but if you do so you may (subject to applicable law) request access to and deletion of that child’s personal data.
HOW AND WHEN DO WE COLLECT INFORMATION FROM YOU?
We may monitor and record communications with you (such as telephone conversations and emails). We may do this for a number of reasons, such as to check the quality of our customer service, for training purposes, to prevent fraud or to make sure we are complying with legal requirements.
If you visit our offices, yard or view our properties, some personal data may be collected from monitoring devices and systems such as closed circuit TV (CCTV) and door entry systems at the site.
You can set your browser not to accept cookies and the websites below tell you how to remove cookies from your browser. However, some of our website features may not function as a result.
REASONS WE CAN COLLECT AND USE YOUR PERSONAL INFORMATION
We rely on a different lawful basis for collecting and using personal data in different situations.
Where you make enquiries about any or our services with us before you become a customer, we need to collect personal information about you so that we can take steps to enter into a contract with you. Once you have become a customer, we need to collect and use personal information to provide services to you and to claim our right to be paid in return for our services under our standard terms of business/contract with you. This includes collecting and using your personal information to:
- enable us to follow up on enquiries made by and to give you our quote;
- do a credit check—see ‘Credit checking’ section below;
- manage any accounts you hold with us;
- contact you for reasons related to the service you have signed up for or to provide information you have requested;
- deal with payment for our services;
- notify you of any changes to our website or to our services that may affect you; and
- resolve disputes or collect overdue payments.
If you apply for a job with us, we will collect and use personal information to process your application and check references. If you take a job with us, we will collect and use your personal information to enter into an employment contract with you and to administer the employment relationship, including making payments to you, accounting for tax, ensuring safe working practices, monitoring and managing staff access to systems and facilities, monitoring absences and performance and conducting assessments.
We collect and use personal information from our customers and staff to comply with our legal obligations. For example, we will take copies of documents that identify you so that we can comply with anti-money laundering and counter-terrorist financing requirements.
Legitimate business interests
Our priority is to make sure we give a high quality and secure service to customers and to follow up effectively on enquiries even though we accept that not all enquiries will lead to a business relationship or contract. We collect personal information to:
- follow up on enquiries in accordance with industry guidelines and provide quotes for services or offers;
- conduct research and analyse website visitor behaviour patterns;
- customise our website and its content to your particular preferences;
- improve our services;
- detect and prevent fraud;
- prevent offensive, inappropriate or objectionable content being sent to or posted on our websites or to stop any other form of disruptive behaviour.
It is a key feature of our service that we operate CCTV within the external properties and reception. We collect and process CCTV images
- so we can fulfil our contractual obligation to deliver a secure environment;
- to establish whether you are doing something that breaches your contract with us; and
- to assist in the establishment or defence of any crime or other investigation.
We will also communicate with you information about other services we can offer you and update you about our activities [and promotions] which may be of interest to you. If you would like to stop receiving these email newsletters, you can also click on the “unsubscribe” button at the bottom of the email newsletter. It may take a few days for this to take place. If you ask us to stop contacting you in this way, you can also ask us to start again at any time.
If we propose to use your information for any other uses we will ensure that we notify you first. If we need your consent to use your information for these other purposes, we will give you the opportunity to opt in or to refuse. If you opt in, you will be able to opt out at any time.
We may do a credit check on you so that we and other companies in our groupcan make credit decisions about you and people or businesses associated with you. These checks may also be used to help prevent and detect fraud and money laundering.
Our search will be recorded on the files of the credit reference agency.
We may also disclose information about how you conduct your account to credit reference agencies and your information may be linked to records relating to other people living at the same address or who are financially linked to you.
Other credit businesses may use your information to make credit decisions about you and the people with whom you are financially associated, trace debtors, and prevent and detect fraud and money laundering.
If you provide false or inaccurate information to us and we suspect fraud, we will record this.
When will we contact any other person about you?
If you provide us the details of a person who we can contact for a job reference, we may contact that person in connection with your job application.
Who your information might be shared with
We may disclose your personal data to:
- other companies within our group;
- service providers under contract with us to support our business operations, such as fraud prevention, debt collection, payroll, technology services
- credit reference agents—see ‘Credit checking’ above;
- our insurers and insurance brokers if you take out insurance cover through us;
- trade associations of which we are a member;
- law enforcement or government agencies in connection with any investigation to help prevent or detect unlawful activity;
- any person or agency if we need to share that information to comply with the law or to enforce any agreement we may have with you or to protect the health and safety of any person;
- any person who you have named as a person we can contact to discuss your account;
- any person who is your agent or representative, such as the holder of a power of attorney, a legal guardian or person administering a will;
- any person who we are negotiating with as a potential buyer of our business or property or if we are proposing to merge our business with another business;
- credit card associations if specifically required;
If we pass data on to insurers, they may enter your data onto a register of claims which is shared with other insurers to prevent fraudulent claims. If we use an outside party to process your information, we will require them to comply with our instructions in connection with the services they provide for us and not for their own business purposes.
KEEPING YOUR PERSONAL INFORMATION SECURE
We have appropriate security measure in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those people processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We will use technical measures to safeguard your personal data, for example:
- access to your customer account is controlled by a password and user name that are unique to you;
- we store your personal data on secure servers; and
- payment details are stored in a secure location and only accessed when payment is due
We have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory body of a suspected data breach where we are legally required to do so.
While we will use all reasonable efforts to keep your personal data safe, you acknowledge that the use of the internet is not entirely secure and for this reason we cannot guarantee the security or integrity of any personal data that is transferred from you or to you via the internet. If you have any particular concerns about your information, please contact us (see ‘How to contact us’ below).
Our website contains links to websites and applications owned and operated by other people and businesses. These third party sites have their own privacy policies and use their own cookies and we recommend that you review them before you provide them with personal information. They will tell you how your personal information is collected and used whilst you are visiting these other websites. We do not accept any responsibility or liability for the content of these sites or the use of your information collected by any of these other sites and you use these other sites at your own risk.
If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
TRANSFERS OF YOUR PERSONAL INFORMATION OUT OF THE EEA
We will not transfer your personal data outside of the United Kingdom OR European Economic Area or to any organisation (or subordinate bodies) governed by public international law or which is set up under any agreement between two or more countries.
HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION?
We will usually hold your personal information as a customer or employee on our system for the period we are required to retain this information by applicable UK law, currently 6 years from the end of our contract or 6 months after any unsuccessful job application, unless you have told us you want us to delete the information earlier (see section “What rights do you have” below).
WHAT RIGHTS DO YOU HAVE?
Under the General Data Protection Regulation you have a number of important rights. These include the following rights:
- request a copy of your information which we hold (subject access request);
- require us to correct any mistakes in your information which we hold;
- require the erasure of personal information concerning you in certain situations
- require us to stop contacting you for direct marketing purposes;
- object in certain other situations to our continued processing of your personal information;
- restrict our processing of your personal information in certain circumstances;
- object to decisions being taken by automated means which produce legal effects concerning you or which affect you significantly; and
- receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations.
Further information on each of these rights is available from the Information Commissioner’s Office.
If you would like to exercise any of these rights, please:
- email, call or write to us (see ‘How to contact us’ below)
- let us have proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill), and
- let us know the information to which your request relates, including any account or reference numbers, if you have them
We will not charge any fee for any of these services in most cases.
HOW TO CONTACT US
If you wish to contact us, please send an email to firstname.lastname@example.org or write to us at Castlecroft Group, King James VI Business Centre, Friarton Rd, Perth, PH2 8DY or call us on 01738 472000.
The General data Protection Regulation also gives you the right to lodge a complaint with a supervisory authority. The supervisory authority I the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns/or telephone 0303 123 1113
This Privacy Notice was published on 9th April 2018 and last updated on 5thApril 2018. We may change this Privacy Notice from time to time. You should check this policy occasionally to ensure you are aware of the most recent version.
DO YOU NEED EXTRA HELP?
If you would like this policy in another format (for example: audio, large print, braille) please contact us (see ‘How can you contact us?’ above).