-
Introduction
-
1 We are Drinx.Com Ltd (Bottled and Boxed) (referred to as Drinx.Com Ltd, Bottled and Boxed, we, us and our in this Privacy Policy), a company incorporated in Scotland with company registration number SC203859 and whose registered office address is Summitt House, 4-5 Mitchell Street, Edinburgh, EH6 7BD or operates from Head Office: Unit 8 Hurworth Road, Aycliffe Business Park, Newton Aycliffe Co.Durham, DL5 6UD.
-
1.2 The information set out in this Privacy Policy is provided to individuals whose personal data we process (you or your) as data controller, in compliance with our obligations under Articles 13 and 14 of the General Data Protection Regulation 2016/679 (GDPR).
-
1.3 To make this information clear, we have divided the data we receive into the following groups and corresponding Schedules, where each of which refers to: the particular category of information we collect and retain; from where we obtain the information from; the purpose and legal basis of processing and to whom we will (if applicable) disclose the information:
Schedule 1
|
Data about our clients and customers, and all individuals in respect of whom we have acquired personal information in connection with any products or services offered by us (including directors, shareholders, consultants, employees or other personnel of our clients)
|
Schedule 2
|
Data about our suppliers and supplier personnel
|
Schedule 3
|
Data about individuals who apply for employment or work experience with us
|
Schedule 4
|
Data about our directors and staff, and former directors and staff and other individuals who spend time with us (such as consultants and secondees)
|
-
-
1.4 In addition to the above, individuals who interact with us in any of the above capacities should also refer to the following:
Schedule 5
|
Data collected about staff and visitors to our office
|
Schedule 6
|
Retention and deletion policy
|
-
Data controller details
-
2.1 We are the data controller in relation to the processing of the personal information that you provide to us. Our contact details are as follows:
-
2.1 Address: Drinx.Com Ltd, Unit 8 Hurworth Road, Aycliffe Business Park, Newton Aycliffe, Co Durham, DL5 6UD.
-
1.2 Telephone number: +44 (0) 1325 313456.
-
2.1.3 Email address: info@bottledandboxed.com (please include “Personal Data Request” in your subject heading to ensure it receives the correct attention).
-
International transfers
We will not transfer personal data relating to you to a country which is outside the European Economic Area (EEA) unless:
-
3.1 the country or recipient is covered by an adequacy decision of the Commission under GDPR Article 45;
-
3.2 appropriate safeguards have been put in place which meet the requirements of GDPR Article 46 (for example using the European Commission’s Standard Model Clauses for transfers of personal data outside the EEA); or
-
3 one of the derogations for specific situations under GDPR Article 49 is applicable to the transfer. These include (in summary):
-
3.3.1 the transfer is necessary to perform, or to form, a contract to which we are a party:
-
3.3.1 with you; or
-
3.3.1.2 with a third party where the contract is in your interests;
-
3.3.2 the transfer is necessary for the establishment, exercise or defence of legal claims;
-
3.3 you have provided your explicit consent to the transfer; or
-
3.3.4 the transfer is of a limited nature, and is necessary for the purpose of our compelling legitimate interests.
-
Retention of personal data
Our retention and deletion policy can be found here – please see Schedule 6
-
Your rights in respect of your personal data
-
5.1 You have certain rights under existing data protection laws, including the right to (upon written request) access a copy of your personal data that we are processing. From 25 May 2018, in accordance with the GDPR:
-
-
-
5.1 you will have the following rights:
-
5.1.1 right to access: the right to request certain information about, access to and copies of the personal information about you that we are holding (please note that you are entitled to request one copy of the personal information that we hold about you at no cost, but for any further copies, we reserve the right to charge a reasonable fee based on administration costs); and
-
5.1.1.2 right to rectification: the right to have your personal information rectified if it is inaccurate or incomplete; and
-
5.1.2 in certain circumstances, you will also have the following rights:
-
5.2.1 right to erasure/“right to be forgotten”: the right to withdraw your consent to our processing of the data (if the legal basis for processing is based on your consent) and the right to request that we delete or erase your personal information from our systems (however, this will not apply if we are required to hold on to the information for compliance with any legal obligation or if we require the information to establish or defend any legal claim);
-
5.1.2 right to restriction of use of your information: the right to stop us from using your personal information or limit the way in which we can use it;
-
5.1.2.3 right to data portability: the right to request that we return any information you have provided in a structured, commonly used and machine-readable format, or that we send it directly to another company, where technically feasible; and
-
5.1.2.4 right to object: the right to object to our use of your personal information including where we use it for our legitimate interests or for marketing purposes.
-
5.2 Please note that if you withdraw your consent to the use of your personal information for purposes set out in our Privacy Policy, we may not be able to carry out our contractual obligations to you or provide you with access to all or certain parts of our services.
-
5.3 If you consider our use of your personal information to be unlawful, you have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office. Please see further information on their website: www.ico.org.uk.
-
Automatic decision making
-
6.1 We do not make decisions based solely on automated data processing, including profiling.
-
Security
-
7.1 We keep your information protected by taking appropriate technical and organisational measures to guard against unauthorised or unlawful processing, accidental loss, destruction or damage. For example:
-
7.1 where appropriate, data is encrypted when transiting on our system or stored on our databases;
-
7.1.2 we have implemented safeguards in relation to access and confidentiality in order to protect the information held within our systems; and
-
7.1.3 we frequently carry out risk assessments and audits to monitor and review threats and vulnerabilities to our systems to prevent fraud.
-
-
7.2 However, while we will do our best to protect your personal information, we cannot guarantee the security of your information which is transmitted via an internet or similar connection. It is important that all details of any username, password and/or other identification information created to access our servers are kept confidential by you and should not be disclosed to or shared with anyone.
-
Changes to this Privacy Policy
We may amend this Privacy Policy from time to time, for example to keep it up to date, to implement minor technical adjustments and improvements or to comply with legal requirements. We will always update this Privacy Policy on our website, so please try to read it when you visit the website (the “last updated” reference tells you when we last updated our Privacy Policy).
Last updated 22nd May 2018
Schedule 1
Data about our clients and customers, and all individuals in respect of whom we have acquired personal information in connection with any products or services offered by us (including directors, shareholders, consultants, employees or other personnel of our clients).
What we collect:
|
We may use your information for the following purposes, based on the following legal grounds:
|
Recipients:
|
-
Contact details such as your name, home/work addresses, email address, landline/mobile phone or fax numbers.
-
Employment information such as your position/title, employment history, professional specialisms and qualifications.
|
-
If it is necessary for the performance of our contract or for the purposes of entering into a contract: for the purpose of negotiating and entering into contractual agreements with you, in the course of providing our services e.g. contacting individuals to obtain instructions and discuss work involved.
-
If it is in our legitimate business interests to do so: for internal record keeping for administration purposes, for the purpose of communications in relation to establishing a client relationship, obtaining evidence of identity of our clients, communications regarding our service and fees, for insight purposes (e.g. to analyse market trends and demographics, and develop the service which we offer to you or other individuals in the future) and sending information to you about products and services which we think may be of interest to you for marketing purposes.
-
Compliance with a legal obligation: in order to prevent fraud or money laundering or to comply with any other legal or regulatory requirements.
-
-
Feedback
-
We will shear your name and email address with an appointed feedback company that has undertaken the necessary GDPR compliance steps. So you may be given a chance to leave feedback and also so you can read genuine customers reviews.
|
How we share information outside the Drinx.Com Limited
-
Please note that personal information we are holding about you may be shared with and processed by:
-
regulators or other third parties for the purposes of monitoring and/or enforcing our compliance with any legal and regulatory obligations, including statutory or regulatory reporting or the detection or prevention of unlawful acts;
-
credit reference and fraud prevention agencies;
-
any third party in the context of actual or threatened legal proceedings, provided we can do so lawfully (for example in response to a court order);
-
other parties and/or their professional advisers involved in a matter where required as part of the conduct of the services;
-
our own professional advisers and auditors for the purpose of seeking professional advice or to meet our audit responsibilities;
-
our service providers and agents (including their subcontractors) or third parties which process information on our behalf (e.g. internet service and platform providers, our bank, payment processing providers and those organisations we engage to help us send communications to you, including marketing automation platforms/email marketing services) so that they may help us to provide you with the applications, products, services and information you have requested or which we believe may be of interest to you;
-
our suppliers, where they fulfil delivery of the contract to our customers and clients directly;
-
third parties as part of the arrangements for any event for which you have expressed an interest in attending;
-
another organisation to whom we may transfer our agreement with you or if we sell or buy (or negotiate to sell or buy) our business or any of our assets (provided that adequate protections and safeguards are in place); and
-
logistics organisations, including storage, warehousing and shipping/courier services providers (for the purpose of performance of our contract).
|
-
Payment information such as bank details and transaction history.
|
-
If it is necessary for the performance of our contract: for the purpose of making or receiving payments in the course of providing our services.
-
If it is in our legitimate business interests to do so: for internal record keeping for administration purposes, for the purpose of retaining evidence of payment transactions, for insight purposes (e.g. to analyse market trends and demographics in relation to our fees), for establishing our client’s ability to pay costs and to develop the service which we offer to you or other individuals in the future).
-
Compliance with a legal obligation: in order to prevent fraud or money laundering or to comply with any other legal or regulatory requirements.
|
-
Website traffic/browser information provided to us during the use of the services on our website, including information as to the generic types of data accessed, IP addresses, times and volume of use of services and Traffic data (including logs, details of networks, data and systems accessed, details of the sender and recipients of messages sent over our services, times and location of log on or access, duration of sessions, clickstream and similar usage or system data).
|
-
If it is our legitimate business interests to do so:for the purposes of offering our goods and services online, monitoring website traffic and for insight purposes (e.g. to analyse market trends and demographics, and develop the service which we offer to you or other individuals in the future).
|
Schedule 2
Data about suppliers and supplier personnel
What we collect:
|
We may use your information for the following purposes, based on the following legal grounds:
|
Recipients:
|
-
Contact details such as your name, home/work addresses, email address, landline/mobile phone or fax numbers.
-
Employment information such as your position/title, employment history, professional specialisms and qualifications.
|
-
If it is necessary for the performance of our contract or for the purposes of entering into a contract: for the purpose of negotiating and entering into contractual agreements with you, in the course of receiving services from you e.g. contacting individuals where we need to do so to provide instructions and discuss work involved.
-
If it is in our legitimate business interests to do so: for internal record keeping for administration purposes, for the purpose of communications in relation to establishing a supplier relationship, obtaining evidence of identity of our suppliers, communications regarding our service and fees, for insight purposes (e.g. to analyse market trends and demographics, and develop the service which we offer to you or other individuals in the future) and sending information to you about products and services which we think may be of interest to you for marketing purposes.
-
Compliance with a legal obligation: in order to prevent fraud or money laundering or to comply with any other legal or regulatory requirements.
|
How we share information outside the Drinx.Com Limited
-
Please note that personal information we are holding about you may be shared with and processed by:
-
our clients, in the course of providing services for and/or performing our contractual obligations to clients;
-
regulators or other third parties for the purposes of monitoring and/or enforcing our compliance with any legal and regulatory obligations, including statutory or regulatory reporting or the detection or prevention of unlawful acts;
-
credit reference and fraud prevention agencies;
-
any third party in the context of actual or threatened legal proceedings, provided we can do so lawfully (for example in response to a court order);
-
our own professional advisors and auditors for the purpose of seeking professional advice or to meet our audit responsibilities;
-
our service providers and agents (including their subcontractors) or third parties which process information on our behalf (e.g. internet service and platform providers, our bank, payment processing providers); and
-
another organisation to whom we may transfer our agreement with you or if we sell or buy (or negotiate to sell or buy) our business or any of our assets (provided that adequate protections and safeguards are in place).
|
-
Payment information such as bank details and transaction history.
|
-
If it is necessary for the performance of our contract: for the purpose of making or receiving payments in the course of the supplier’s services.
-
If it is in our legitimate business interests to do so: for the purpose of enquiring, requesting or purchasing goods or services, for internal record keeping for administration purposes, for the purpose of retaining evidence of payment transactions and for insight purposes (e.g. to analyse market trends and demographics in relation to our suppliers’ fees).
-
Compliance with a legal obligation: in order to prevent fraud or money laundering or to comply with any other legal or regulatory requirements.
|
-
Identification information contained in or provided to us as part of our supplier ID checks. This includes details included in copy personal photo and residential ID documents we receive.
|
-
Compliance with a legal obligation: in order to prevent fraud or money laundering or to comply with any other legal or regulatory requirements.
|
Schedule 3
Data about individuals who apply for employment or work experience with us
What we collect:
|
We may use your information for the following purposes, based on the following legal grounds:
|
Recipients:
|
-
Contact details such as names, home and work addresses, landline/mobile phone or fax numbers, email addresses, previous addresses.
|
Our legitimate interest in processing such information for contacting individuals where we need to do so and for obtaining/verifying evidence of identity.
|
How we share information: Please note that personal information we are holding about you may be shared with and processed by:
-
recruitment agencies to communicate offer details (if any);
-
UK regulatory and law enforcement bodies, where required of us under UK law or regulation; and
-
Our service providers (such as data storage, typing, administrative support and audit).
|
-
Employment related history and qualifications information such as position/title, date of birth, employment history and CV, references from previous employees, professional specialisms, education and qualifications, salary and benefits, disciplinary record.
|
Our legitimate interest in processing such information for assessing their suitability for the role, or considering potential packages and offers.
|
How we share information: Please note that personal information we are holding about you may be shared with and processed by:
-
recruitment agencies to communicate offer details (if any); and
-
our service providers (such as data storage, typing, administrative support and audit).
|
-
Personal information such as professional and personal interests and languages spoken.
|
Our legitimate interest in processing such information for assessing their suitability for the role.
|
-
Information contained in or provided to us as part of our recruitment or take on process such as details included in copy personal photographs and residential ID documents we receive.
-
Visa documentation (right to work in the UK).
|
Our legitimate interest in processing such information for obtaining/verifying evidence of identity. Compliance with a legal obligation in order to confirm that the individual is entitled to work in the UK and for the purpose of security and prevention of crime.
|
How we share information: Please note that personal information we are holding about you may be shared with and processed by:
-
UK regulatory and law enforcement bodies, where required of us under UK law or regulation; and
-
Our service providers (such as data storage, typing, administrative support and audit).
|
Schedule 4
Data about our directors and staff, consultants, secondees, those on work experience, temporary staff, former directors and staff, next of kin, spouses, beneficiaries
What we collect:
|
We may use your information for the following purposes, based on the following legal grounds:
|
Recipients:
|
-
Contact details (work) such as name, work address, landline/mobile phone or fax numbers, email address.
-
Contact details (personal) and other personal information such as home address, landline/mobile phone number, email address, previous addresses, emergency contact details, date of birth, marital status, next of kin, spouse, beneficiaries’ names and contact details.
|
-
Necessary for the performance of our contract in our capacity as your employer.
-
Necessary to protect the vital interests of the individual concerned for the purposes of security and prevention of crime.
-
Our legitimate interest in processing such information (work contact details) for contacting individuals where we need to do so in the individual’s capacity as employee, director or other member of staff.
-
Our legitimate interest in processing such information (personal contact details) for the purpose of contacting individuals where we need to do so in the individual’s capacity as employee, director/shareholder or other member of staff, in order to keep appropriate employment records, for obtaining/verifying evidence of identity or for contacting next of kin, spouses and beneficiaries if the circumstances require (such as in an emergency).
-
Compliance with a legal obligation to comply with right to work legislation.
|
How we share information outside the Drinx.Com Ltd
-
-
We may share information about you with any company within the Drinx.Com Limited (Bottled and Boxed) for the purposes set out in this Privacy Policy only (e.g. to help us provide employee administration services).
How we share information within the Drinx.Com Ltd
-
Please note that personal information we are holding about you may be shared with and processed by:
-
our clients;
-
other professional advisers of our clients;
-
other parties and/or their professional advisers involved during the course of services provided to our clients;
-
regulators or other third parties for the purposes of monitoring and/or enforcing our compliance with any legal and regulatory obligations, including statutory or regulatory reporting or the detection or prevention of unlawful acts;
-
credit reference and fraud prevention agencies;
-
any third party in the context of actual or threatened legal proceedings, provided we can do so lawfully (for example in response to a court order);
-
other parties and/or their professional advisers involved in a matter where required as part of the conduct of the services;
-
our own professional advisers and auditors for the purpose of seeking professional advice or to meet our audit responsibilities;
-
our service providers and agents (including their subcontractors) or third parties which process information on our behalf (e.g. internet service and platform providers, data storage providers, typing service providers, administrative support, third party payroll processors, audit providers and our bank);
-
third party providers of benefits (such as childcare vouchers, life insurers, pension providers); and
-
another organisation to whom we may transfer our agreement with you or if we sell or buy (or negotiate to sell or buy) our business or any of our assets (provided that adequate protections and safeguard are in place).
|
-
Employment and performance related information such as position/title, date of birth, employment history and CV, references from previous employees, professional specialisms, education and qualifications, salary and benefits, disciplinary records, performance records, appraisals, performance feedback, interview notes, languages spoken, practising certificate details and caveats, professional indemnity information, working patterns (days worked and non-work days).
|
-
Necessary for the performance of the employment contract in order to keep appropriate employment records and carry out our contractual obligations as employer.
-
Our legitimate interest in processing such information in order to keep appropriate employment records, for assessing their continued suitability for their role and for planning progression.
|
-
Payment and financial information such as bank details, transaction history, salary and benefits, life insurance, pension related information, tax-related information, National Insurance number, payroll documentation (P45 / P60 / P11D).
|
-
Necessary for the performance of the employment contract to pay or compensate the individual.
-
Our legitimate interest in processing such information in order to keep appropriate employment records and to allow the individual to receive pension and other benefits.
-
Consent in order to allow nominated family members or beneficiaries to receive benefits or insurance funds.
|
-
Information contained in or provided to us as part of our recruitment or take on process such as details included in copy personal photographs and residential ID documents we receive.
-
Visa documentation (right to work in the UK).
|
-
Our legitimate interest in processing such information for obtaining/verifying evidence of identity.
-
Compliance with a legal obligation in order to confirm that the individual is entitled to work in the UK and for the purpose of security and prevention of crime.
|
-
DBS check (basic disclosure).
|
-
Compliance with a legal obligation pursuant to Schedule 1, Part 1(1)(1)(a) of the Data Protection Act 2018 to satisfy our legal obligations as their employer or as the entity to which members belong and for security and prevention of crime purposes.
|
-
Monitoring information such as images via CCTV, entrance/exit dates/times, movement within the building via security card system.
|
-
Our legitimate interest in maintaining a safe environment and in preventing and detecting crime.
-
Necessary to protect the vital interests of the individual concerned: for security purposes and in order to maintain a safe environment.
-
Compliance with a legal obligation: in order to prevent fraud or money laundering or to comply with any other legal or regulatory requirements.
|
Schedule 5
Data about visitors to our office
What we collect:
|
We may use your information for the following purposes, based on the following legal grounds:
|
Recipients:
|
-
Monitoring information such as, entrance/exit dates/times, movement within the building via security card system.
-
Dietary preferences (if catering is arranged).
-
Identification information provided to us. This may include details included in copy personal photo and residential ID documents we receive.
|
-
If it is in our legitimate business interests to do so: for security purposes and pursuant to our legitimate interest in maintaining a safe environment, for the purpose of confirming attendance/location of the individual, for determining contract performance (in the case of employees and suppliers), and for use where catering is arranged (in the case of dietary preferences).
-
Necessary to protect the vital interests of the individual concerned: for security purposes and in order to maintain a safe environment.
-
Compliance with a legal obligation: in order to prevent fraud or money laundering or to comply with any other legal or regulatory requirements.
|
How we share information: Please note that personal information we are holding about you may be shared with and processed by:
-
building management and law enforcement authorities, or other regulators or other third parties for the purposes of monitoring and/or enforcing our compliance with any legal and regulatory obligations, including statutory or regulatory reporting or the detection or prevention of unlawful acts;
-
the relevant individual’s employer or agent; and
-
external caterers (in the case of dietary preferences).
|
Schedule 6
Retention and deletion policy
Unless we are required or permitted by law to hold on to your information for a specific retention period, we may retain your information for the following purposes and periods:
Category of personal data
|
Period for which personal data will be stored
|
-
Data about our clients, business contacts, and third parties involved in matters in relation to which we provide services to our clients.
|
Contracts and general correspondence (emails, post and other communications) obtained in the course of providing our services: Such information will be stored for six years following completion of the services or termination or expiry of the contract with our client (whichever is later).Contact details for marketing purposes: Contact information relating to clients and contacts will be held for three years or for so long as we believe the information to remain accurate and the individual concerned remains a genuine connection of ours, or of one of our directors and staff. We have a programme for reviewing our contacts regularly, and removing any information which is considered to be out of date or no longer relevant.
|
-
Data about our suppliers and supplier personnel.
|
Contracts and general correspondence (emails, post and other communications) obtained in the course of providing your services: Such information will be stored for six years following completion of the services or termination or expiry of your contract (whichever is later).
|
-
Data about individuals who apply for employment or work experience with us.
|
Personal data obtained from employment or work experience applicants will be deleted after six months.
|
-
Data about our directors and staff, former directors and staff and other individuals who spend time with us (such as consultants and secondees).
|
Human resources (HR) records will be destroyed 12 years following employment, with the exception of pension information and employer’s liability insurance certificates which will have a retention period of fifty years. For the purposes of administration this will be actioned annually in December of each year. Personal data stored in private workspaces created for members of HR (including for appraisals, promotion and probation reviews) will be deleted 12 years after creation.
|
DRINX.COM LIMITED (Bottled and Boxed) CERTIFICATE NUMBER: ZA380977