1. Purpose and scope
This policy describes how Flintfix Limited approaches personal-data responsibilities under the UK General Data Protection Regulation and the Data Protection Act 2018. It applies to personal data handled in connection with website enquiries, customers, prospects, suppliers, project contacts and the administration of our business.
Everyone who handles personal data on behalf of Flintfix Limited is expected to use it only for legitimate business purposes, protect it appropriately and raise concerns when information may have been lost, misused or disclosed incorrectly.
2. Data-protection principles
We aim to process personal data lawfully, fairly and transparently; collect it for specified and legitimate purposes; limit it to what is relevant; keep it accurate where reasonably possible; retain it no longer than necessary; and protect it through appropriate security. We remain responsible for being able to demonstrate how these principles are applied.
3. Lawful processing and transparency
Before using personal information, Flintfix Limited should identify an appropriate lawful basis. Common bases in our work include taking steps before a contract, performing a contract, meeting a legal obligation and pursuing legitimate business interests that do not override individual rights. Consent is used where it is the suitable basis and must be freely given, specific, informed and capable of withdrawal.
People should receive clear information about relevant processing. Our Privacy Policy provides public information for website and business contacts. Additional explanations may be supplied where a particular activity uses information in a materially different way.
4. Data minimisation and accuracy
We should not collect personal information merely because it may be useful later. Project and commercial records should contain information needed for the defined purpose. Reasonable steps should be taken to correct inaccurate contact or account information when an error is identified.
5. Access and security
Access to personal data should be limited to people who need it for their role or the relevant project. Accounts and devices should use appropriate access controls, and information should be shared using methods proportionate to its sensitivity. Paper and electronic records should not be left unnecessarily exposed.
Suppliers that process personal data for Flintfix Limited should be selected with regard to their ability to protect information. Written terms should describe their responsibilities where data-protection law requires them.
6. Individual rights
Individuals may ask to access their personal information or exercise rights of rectification, erasure, restriction, objection and portability where the relevant legal conditions are met. They may also have rights concerning automated decisions. Flintfix Limited does not use website enquiries to make solely automated decisions with legal or similarly significant effects.
Rights requests should be passed promptly to the person responsible for handling them. We may verify identity, clarify a request and consider exemptions before responding. Information about another person must not be disclosed improperly while answering a request.
7. Retention and disposal
Records should be kept for a period that reflects their business purpose, applicable legal duties and the need to establish or defend claims. Routine contact details should not be kept indefinitely without a continuing reason. When a retention period ends, records should be deleted, anonymised or securely destroyed where practicable.
8. Personal-data breaches
A personal-data breach may involve loss, unauthorised access, mistaken disclosure, alteration or destruction. Suspected incidents should be reported internally without delay, preserving available information about what happened, which data is affected and what containment action has been taken.
Flintfix Limited will assess the likely risk to individuals and determine whether notification to the Information Commissioner’s Office or affected individuals is required. Regulatory notification may be subject to a 72-hour period after awareness, so prompt escalation is important.
9. Accountability and review
Data-protection considerations should form part of new processes that involve personal information. Higher-risk processing may require a documented impact assessment. This policy will be reviewed when there is a significant change to our processing or applicable requirements.
Questions or concerns may be sent to tusaine@flintfix.online.