INTERNET PRIVACY & COOKIES POLICY
(as at 16th March 2020)
HFC Systems Ltd takes your privacy extremely seriously. This policy sets out how we collect and process any personal data you may provide to us when you use our websites (hfcsystems.com and homefixcomputers.com), purchase any services or sign up to our digital marketing.
This policy applies where HFC Systems (referred to as “we”, “us” or “our” in this privacy notice) identify as the data controller and where we are responsible for your personal data.
HFC Systems have appointed a Data Protection Manager, who will be responsible for privacy matters and the protection of personal data we hold as an organisation, their details are below:
Name: Mr Steven Booth
Email address: email@example.com
Telephone number: 01642 686687
HFC Systems is a company registered in England and Wales registration number: 8470957 whose registered office is 1 Roseberry Court, Stokesley Business Park, Stokesley, North Yorkshire TS9 5QT.
If you are unhappy with the way we collect or process your personal information, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) who are the UK’s supervisory authority for data protection.
Complaints and concerns can be lodged with the ICO via this link: https://ico.org.uk/concerns/
We kindly ask that before any complaints are lodged with the ICO, that you contact us first to try and resolve any issues you may have.
2. What data do we collect?
Personal information we may collect and process from you includes:
• Contact information – such as your name, address, telephone number and email address.
• Financial information – such as your bank account details or payment-related data.
• Technical information – this may include your IP address, browser details, location analytics, login details and any other technology information related with you using our site or services.
• Information provided to us by our clients which enable us to provide our services to their staff – this could include email addresses, account details or device identifiers.
• Any other personal information you may provide to us in the process of us providing you with our services or by communicating with us.
Under the General Data Protection Regulation/Data Protection Act 2018, sensitive personal data is data which includes information about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data.
HFC Systems does not collect sensitive personal data about you – if we were to require it for any reason, we would seek explicit consent from you to gather this.
3. How do we use your personal data?
We will only use your personal data for the following reasons:
• To provide you with the services we offer as a business
• To provide you with information you have requested from us
• To keep you updated on our business, offers and news we may have
• To manage our relationship with you as an existing or potential client
• To fulfil any legal or contractual obligations we may have which require the processing of personal data
4. How do we obtain your data?
We can collect data about you via a variety of methods:
• From direct actions we may have with you by communicating via phone, email or post
• When you sign-up to services on our website or portals – including our mailing list, contact forms or purchasing a service
• From automated technologies or interactions as you use our website from analytics engines and cookies – please see our section on cookies for more details
• When you sign-up to attend any events we may hold or be a part of
• When you provide information to us as part of our sign-up process with you as a client
5. Our lawful purposes for collecting and processing your information
We have identified that we will use your information for the following reasons:
• Where we need to perform the contract between us.
• Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
• Where we need to comply with a legal or regulatory obligation.
Generally, we do not rely on consent as a lawful purpose for processing your personal data, other than in relation to sending marketing communications to you when you are not already an existing client or to transfer your data outside of the EEA and recognised third countries and environments. You have the right to withdraw consent (where applicable) at any time by emailing us at firstname.lastname@example.org.
If you have previously purchased goods or services from us we may provide to you details of similar goods or services, or other goods and services we provide as a company, that may be of interest to you.
6. Who do we share your information with?
We may need to share your information with third parties in order to provide you with our services or to market to you, these third parties include:
• GURU Cloud
Any other non-specified companies third parties we share data with have been identified and recorded in our Data Asset Register and have been analysed as part of our Data Risk Assessment process. Such third parties are used to provide systems required to perform our day-to-day business activities and services we supply to our customers.
Where we do share your information with third parties, HFC Systems ensures that the highest levels of data protection are in place in accordance with the law. Third parties with whom we share data are only permitted to process this data for the specified purposes we stipulate with them.
We do not sell your information onto third parties.
7. International transfers
Where possible, we ensure that your data is stored within the European Economic Area (EEA), however some of our storage locations and service providers may be hosted outside of the EEA. When we do need to transfer your personal data out of the EEA, we ensure one of the following safeguards are in place to provide a similar level of security of your data:
• Your personal data has been transferred to a country that has been deemed to provide an adequate level of protection for personal data by the European Commission; or
• The hosting environment we use has specific contracts, codes of conduct or certification mechanisms in-place which have been approved by the European Commission; or
• Where we transfer data to the United States, we ensure our providers are certified as part of the EU-US Privacy Shield programme.
If none of these safeguards are available, we will only transfer your data with your explicit consent – which can be removed at any time by contacting us.
Please email us at email@example.com if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
8. Retention periods
Your personal information will be retained in accordance with our data retention policy which categorises all of the data assets held by us and specifies the appropriate retention period for each data asset.
These periods are based on the requirements to keep the data for as long as necessary to fulfil the purpose for which it was collected, to meet any legal requirements or to satisfy any reporting, accounting or contractual needs.
9. Your rights
Under the General Data Protection Regulation/Data Protection Act (2018), you have certain rights regarding your personal data, these include:
• Request access to your personal data
• Request correction of your personal data
• Request erasure of your personal data
• Object to processing of your personal data
• Request restriction of processing your personal data
• Request transfer of your personal data
• Right to withdraw consent
You may exercise any of these rights by raising a subject access request with us. You can do this by contacting or Data Protection Manager via the details below:
Name: Mr Steven Booth
Email address: firstname.lastname@example.org
Telephone number: 01642 686687
We will not charge you for making a request and we will make all reasonable efforts to respond to you within 30 days. Sometimes it may take longer than 30 days to gather all the information we may hold on you, in this situation we will keep you updated at all times.
You can instruct us at any time to stop processing your personal data for the purposes of marketing.
We may refuse your request or withhold any personal information that you request if there is an overriding legal reason for us to do so.
10. Information security
HFC Systems takes the security of your information extremely seriously. In order to protect your data, we implement a risk-based approach to adopt the strongest organisational and technical controls in order to protect the confidentiality, integrity and availability of your data.
Use of both hardware and software firewalls, anti-malware detection systems, malware protection systems, strong AES encryption and intrusion detection systems are all utilised as part of our security protection. Network vulnerability scans are run on any of our networks to identify and highlight any potential risks to minimise potential intrusion.
Where networks or systems are provided by third party companies entrusted by HFC Systems, we have obtained certification and/or suitable guarantees in all aspects of data security and expect this to be maintained to them as part of their obligation under contract to us.
A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.
The cookies we use
• Login related cookies:
• Forms related cookies:
When you submit data to through a form such as those found on contact pages or comment forms cookies may be set to remember your user details for future correspondence.
• Site preferences cookies:
In order to provide you with a great experience on this site we provide the functionality to set your preferences for how this site runs when you use it. In order to remember your preferences, we need to set cookies so that this information can be called whenever you interact with a page is affected by your preferences.
Third Party Cookies
• This site uses Google Analytics which is one of the most widespread and trusted analytics solution on the web for helping us to understand how you use the site and ways that we can improve your experience. These cookies may track things such as how long you spend on the site and the pages that you visit so we can continue to produce engaging content.
For more information on Google Analytics cookies, see the official Google Analytics page.
• From time to time we test new features and make subtle changes to the way that the site is delivered. When we are still testing new features, these cookies may be used to ensure that you receive a consistent experience whilst on the site whilst ensuring we understand which optimisations our users appreciate the most.
Most browsers allow you to refuse to accept cookies and to delete cookies. The method for doing so differs with each browser, the following guides for the most common internet browsers detail the processes for doing this:
• https://support.google.com/chrome/answer/95647?hl=en (Google Chrome)
• https://support.apple.com/kb/PH21411 (Safari)
• https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy (Microsoft Edge)
Blocking cookies may impact your experience on our website as you may not be able to make full use of the features on it.
12. Third party links
We keep this policy under regular review. This policy was last reviewed on 16th May 2018. Any questions about this policy can be directed to our Data Protection Manager via the details set out in section 1 of this policy.