Client Privacy Notice
WHAT ABOUT SENSITIVE PERSONAL DATA?
Unless we are processing because it is necessary for reasons of substantial public interest, we will only process sensitive personal data, such as data concerning health, with your explicit and informed consent for specific processing activities. In such cases you will be asked to sign a separate consent form to evidence this and that you understand the purpose(s) of the processing of such data. Your consent may be withdrawn at any time.
HOW WILL WE FURTHER USE YOUR PERSONAL INFORMATION (OUR LEGITIMATE INTERESTS)?
- To contact you to ensure that our records of your personal information are correct;
- To respond to questions or complaints you have about our services;
- To update you with changes in our terms;
- For statistical or research analysis relating to the performance of our business or that of our principal and understanding the changing needs of our clients;
- To review, improve and develop services we offer or handle complaints;
- To pursue debts or unpaid fees;
- To evidence company practices;
- To evidence the standards and processes carried out conform to the company’s ethical standards and expectations;
- For direct marketing activities;
- To protect the business from risks which might be introduced by an individual. You have the right to object to processing for these purposes and we shall cease unless we can show we have compelling legitimate grounds to continue.
PROCESSING WHEN PERFORMING A TASK CARRIED OUT IN THE PUBLIC INTEREST
We will use the information provided to protect members of the public against dishonesty, money laundering or fraudulent activities. This must necessarily be carried out without your explicit consent to ensure this function is not prejudiced. Part of this processing involves verifying your identity using third parties such as GB Group Plc or Creditsafe Business Solutions Ltd.
WHAT INFORMATION IS REQUIRED?
We only collect information that is necessary to carry out the purposes listed above. This includes information you supply and data we receive from reference agencies. Where practical and lawful we will inform you about any personal data we receive about you from third parties that you may be unaware of.
HOW SECURE WILL YOUR DATA BE?
We will ensure that your data is only accessible to authorised people in our firm and will remain confidential at all times. Appropriate security measures will be in place to prevent unauthorised access, alteration, disclosure, loss, damage or destruction of your information.
If we have a contract with another organisation to provide us with services or a service on our behalf to process your personal information, we’ll make sure they give reassurances.
regarding appropriate security measures in place and only process your information in the way we’ve authorised them to. These organisations won’t be entitled to use your personal information for their own purposes. If necessary, our security teams will check them to make sure they meet the security requirements we’ve set.
WILL WE SHARE YOUR INFORMATION WITH ANYONE ELSE?
We may share your information with:
- Appropriate staff such as those who carry out financial or compliance functions.
- Organisations that need your information because we are required to provide it by law (eg. The FCA, ombudsman services, HMRC etc).
- Organisations that carry out credit references or identity checks such as GB Group Plc or CreditSafe Business Solutions Ltd. These organisations may keep a record of the information and may disclose the fact that a search of its records was made to its other customers for the purposes of assessing the risk of giving credit, to prevent fraud and to trace debtors.
- Sometimes other authorised firms with specialist advisers, such as pension specialists, who assist us in providing suitable financial advice and services. You will be provided with their details if this applies.
- Law enforcement agencies, courts or other public authorities if we have to, or are authorised to by law.
- Product providers we use to provide financial services or for direct marketing (see below). • Where we or our Principal go through a business transaction, such as a merger, being acquired by another company or selling a portion of its assets, your information will, in most instances, be part of the assets transferred.
TRANSFERRING DATA OUTSIDE THE EUROPEAN UNION
We do not usually transfer any of your personal data outside of the EU except when we need to perform precontractual measures (credit and identity checks) or because the checks we request are necessary for important reasons of public interest. Some companies, like Creditsafe Business Solutions Ltd, may transfer data outside of the EU to countries which do not, in the view of the EU Commission, offer an adequate level of protection. In such cases Creditsafe encrypts any data it sends to other agencies and only transfers information necessary to carry out checks.
(A list of countries used to perform checks include Germany, Netherland, Belgium, France, Sweden, Norway, Finland, Luxembourg, Switzerland, Liechtenstein, Spain, USA, Estonia, Latvia, Lithuania, Poland, Slovakia, Czech Republic, Hungary, Slovenia, Bosnia, Serbia, Montenegro, Croatia, Macedonia, Kosovo, Albania, Bulgaria, Romania, Ukraine, Austria, Denmark, Moldova, Portugal, Italy, Canada, Brazil, Greenland, China, India, Australia, Russia, South Korea, Taiwan, Mexico, South Africa, New Zealand, Hong Kong, UK.)
WHAT ABOUT DIRECT MARKETING?
We may use the information provided to carry out direct marketing activities as these are legitimate interests pursued by us, if you have provided your prior and explicit consent for us to do so, and indicated the method by which you wish to be communicated with (email, telephone, SMS, post). You have the right to object to the use of your data for this purpose at any time and we will cease marketing activity. You can update your preferences with your contact at Complete Financial at any time.
AUTOMATED DECISION-MAKING PROCESSES
We sometimes use automated processes when making decisions, but you will not be subject to a decision based solely on automated processing, including profiling.
TELEPHONE CALL RECORDING
In line with The Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000 we may record incoming or outgoing telephone conversations for the following purposes:
- Establishing facts and evidence for business transactions;
- Ensuring compliance with regulatory or self-regulatory practices;
- Ascertaining and demonstrating that standards are being met;
- Preventing or detecting crime;
- Investigating or detecting the unauthorised use of that or any other telecommunication system;
- Safeguarding the effective operation of the telecommunications system.
HOW LONG WILL WE KEEP YOUR INFORMATION FOR?
The Financial Conduct Authority lays down rules relating to how long information should be held for and we will keep your information to meet these requirements. We will not keep your information for longer than is necessary.
REQUESTING A COPY OF THE INFORMATION WE HOLD
You may at any time ask for a copy of the information we hold about you – it is your legal right. We will provide you with a copy of any non-exempt personal information within one month unless we ask you for an extension of time. To protect your personal data, we will ask you to verify your identity before we release any information. We may refuse your request if we are unable to confirm your identity.
You have the right, on grounds relating to your situation, at any time to object to processing which is carried out as part of our legitimate interests or in the performance of a task carried out in the public interest.
We will no longer process your data unless we can demonstrate there are compelling legitimate grounds which override your rights and freedoms or unless processing is necessary for the establishment, exercise or defence of legal claims. You have the right to object at any time to processing your personal data for marketing activities. In such a case we must stop processing for this purpose.
WHAT ARE YOUR OTHER LEGAL RIGHTS?
In addition to the rights above the additional following rights:
- Where you have given consent, you have the right to withdraw previous consent to processing your personal data at any time;
- You have the right to request from us access to and rectification or erasure of personal data or restriction of processing concerning your data;
- You have the right to receive data you have provided to us in a structured, commonly used and machine-readable format;
- You have the right to lodge a complaint with the regulator (see below).
To exercise any of these rights please contact us (details below).
HOW TO CONTACT OUR DATA PROTECTION OFFICER
You can contact our data protection officer about any data protection or marketing issues by:
- Writing to: The Data Protection Officer, Suite A, Castle House, Park Road, Banstead, SM7 3BT
- Telephoning: 01737 910 650
- Emailing: firstname.lastname@example.org
HOW DO YOU MAKE A COMPLAINT TO THE REGULATOR?
- By writing to: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- By telephoning: 0303 123 1113 •
- By emailing: email@example.com •
- By using their website: https://ico.org.uk/make-a-complaint/