Privacy and cookies
Who we are
SFA (Oxford) Limited (“we”, “us”) is the operator of the website www.sfa-oxford.com. We collect, use and are responsible for certain information about you. When we do so, we are regulated under the General Data Protection Regulation which applies across the European Union (including the United Kingdom) and we are responsible as 'controller' of that personal information for the purposes of those laws. The person responsible for how we handle personal information is David Mobbs, who can be contacted on 01865 784 374 or email@example.com.
The personal information we collect and use
Personal information provided by you
In the course of providing our services and running our events, we collect personal information when you provide it to us, such as your name, business title, physical address, postal address, email address, phone numbers, fax number.
We also collect personal information from you if you apply for a job with us or work for us for any period of time. In this context, personal information we gather may include: contact details, financial and payment details, details of education, qualifications and skills, marital status, nationality, NI number, job title, and CV.
Personal information provided by third parties
Occasionally we may receive information about you from other sources (such as credit reference agencies), which we will add to the information we already hold about you in order to help us provide services to you and to improve and personalise our service to you. If you apply for a job with us, we may receive information from the people who provide references.
Personal information about other individuals
If you give us information on behalf of someone else, for example, a colleague who may be interested in our services or event, a referee or next of kin, you confirm that the other person has agreed that you can:
give consent on his/her behalf to the processing of his/her personal data;
receive on his/her behalf any data protection notices; and
if relevant, give consent to the transfer of his/her personal data abroad.
If you provide us the details of a person who we can contact for a job reference, we may contact that person in connection with your job application.
Sensitive personal information
We will not usually ask you to provide sensitive personal information. We will only ask you to provide sensitive personal information if we need to for a specific reason. If we request such information, we will explain why we are requesting it and how we intend to use it.
Sensitive personal information includes information relating to your ethnic origin, political opinions, religious beliefs, whether you belong to a trade union, your physical or mental health or condition, sexual life, and whether you have committed a criminal offence. We will only collect your sensitive personal information with your explicit consent.
We do not knowingly collect personal data relating to children under the age of 16. If you are a parent or guardian of a child under the age of 16 and think that we may have information relating to that child, please contact us. We will ask you to prove your relationship to the child but if you do so you may (subject to applicable law) request access to and deletion of that child’s personal data.
How and when do we collect information from you?
We may monitor and record communications with you (such as telephone conversations and emails). We may do this for a number of reasons, such as to check the quality of our customer service, for training purposes, to prevent fraud or to make sure we are complying with legal requirements.
If you visit our offices, some personal data may be collected from monitoring devices and systems such as closed-circuit TV (CCTV) and door entry systems at the site.
Reasons we can collect and use your personal information
We rely on a different lawful basis for collecting and using personal data in different situations.
Where you make enquiries about our services or events before you become a customer, we need to collect personal information about you so that we can take steps to enter into a contract with you. Once you have become a customer or signed up for an event, we need to collect and use personal information to provide services to you and to claim our right to be paid in return for our services under our standard terms of business/contract with you. This includes collecting and using your personal information to:
enable us to follow up on enquiries made by you in relation to our services and to give you our quote;
enable us to send you information about any event you have registered for;
prepare an agreement with you;
manage any accounts you or your business hold with us;
contact you for reasons related to the service you have signed up for or to provide information you have requested;
deal with payment for our services and events;
notify you of any changes to our website or to our services or events that may affect you; and
resolve disputes or collect overdue payments.
If you apply for a job with us, we will collect and use personal information to process your application and check references. If you take a job with us, we will collect and use your personal information to enter into an employment contract with you and to administer the employment relationship, including making payments to you, accounting for tax, ensuring safe working practices, monitoring and managing staff access to systems and facilities, monitoring absences and performance and conducting assessments.
We collect and use personal information from our customers and staff to comply with our legal obligations.
Legitimate business interests
Our priority is to make sure we give a high quality and secure service to customers and to follow up effectively on enquiries even though we accept that not all enquiries will lead to a business relationship or contract. We collect personal information to:
follow up on enquiries and provide quotes for our services and events;
conduct research and analyse website visitor behaviour patterns;
customise our website and its content to your particular preferences;
improve our services;
detect and prevent fraud;
prevent offensive, inappropriate or objectionable content being sent to or posted on our websites or to stop any other form of disruptive behaviour.
We will also [communicate with you information about other services we can offer you and] update you about our activities, events [and promotions] which may be of interest to you. If you would like to stop receiving these email newsletters, you can also click on the “unsubscribe” button at the bottom of the email newsletter. It may take a few days for us to process this.] or [If you do not wish to continue receiving these communications, you can opt-out at any time. See 'What rights do you have?’ below for further information. If you ask us to stop contacting you in this way, you can also ask us to start again at any time.
If we propose to use your information for any other uses we will ensure that we notify you first. If we need your consent to use your information for these other purposes, we will give you the opportunity to opt in or refuse. If you opt-in, you will be able to opt-out at any time.
Who your information might be shared with
We may disclose your personal data to:
service providers under contract with us to support our business operations, such as fraud prevention, debt collection, payroll, technology services
trade associations of which we are a member;
law enforcement or government agencies in connection with any investigation to help prevent or detect unlawful activity;
any person or agency if we need to share that information to comply with the law or to enforce any agreement we may have with you or to protect the health and safety of any person;
any person who we are negotiating with as a potential buyer of our business or property or if we are proposing to merge our business with another business subject to our duty of confidentiality to our customers;
credit card associations if specifically required;
If we use an outside party to process your information, we will require them to comply with our instructions in connection with the services they provide for us and not for their own business purposes.
Keeping your personal information secure
We have appropriate security measure in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those people processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We will use technical measures to safeguard your personal data, for example, we store your personal data on secure servers.
We have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory body of a suspected data breach where we are legally required to do so.
While we will use all reasonable efforts to keep your personal data safe, you acknowledge that the use of the internet is not entirely secure and for this reason, we cannot guarantee the security or integrity of any personal data that is transferred from you or to you via the internet. If you have any particular concerns about your information, please contact us (see ‘How to contact us’ below).
Our website contains links to websites and applications owned and operated by other people and businesses. These third-party sites have their own privacy policies and use their own cookies and we recommend that you review them before you provide them with personal information. They will tell you how your personal information is collected and used whilst you are visiting these other websites. We do not accept any responsibility or liability for the content of these sites or the use of your information collected by any of these other sites and you use these other sites at your own risk.
If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
Transfers of your personal information out of the EEA
We will not transfer your personal data outside of the [United Kingdom OR European Economic Area] or to any organisation (or subordinate bodies) governed by public international law or which is set up under any agreement between two or more countries.
How long do we keep your personal information?
We will usually hold your personal information as a customer or employee on our system for the period we are required to retain this information by applicable UK law, currently 6 years from the end of our contract or 6 months after any unsuccessful job application, unless you have told us you want us to delete the information earlier (see section “What rights do you have?” below).
What rights do you have?
Under the General Data Protection Regulation you have a number of important rights. These include the following rights:
- request a copy of your information which we hold (subject access request);
- require us to correct any mistakes in your information which we hold;
- require the erasure of personal information concerning you in certain situations
- require us to stop contacting you for direct marketing purposes;
- object in certain other situations to our continued processing of your personal information;
- restrict our processing of your personal information in certain circumstances;
- object to decisions being taken by automated means which produce legal effects concerning you or which affect you significantly; and
- receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations.
Further information on each of these rights is available from the Information Commissioner’s Office.
If you would like to exercise any of these rights, please:
- email, call or write to us (see ‘How to contact us’ below)
- let us have proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill), and
- let us know the information to which your request relates, including any account or reference numbers, if you have them
We will not charge any fee for any of these services in most cases.
How to contact us
If you wish to contact us, please send an email to firstname.lastname@example.org or write to us at SFA (Oxford) Ltd, The Magdalen Centre, Robert Robinson Avenue, The Oxford Science Park, Oxford, OX4 4GA, UK or call us on 01865 784 374.
The General Data Protection Regulation also gives you the right to lodge a complaint with a supervisory authority. The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns/ or telephone 0303 123 1113.
This Privacy Notice was published on 25th May 2018. We may change this Privacy Notice from time to time. You should check this policy occasionally to ensure you are aware of the most recent version.
Do you need extra help?
If you would like this policy in another format (for example: audio, large print, braille) please contact us (see ‘How can you contact us?’ above).