Version | 2.0 |
Date | 5th February 2024 |
Filename | GDPR Policy & Privacy Notice |
Privacy Notice for
PRS Plumbing and Heating Services Ltd
This Privacy Notice provides details of the personal data we collect from you, what we do with it, how you might access it and who it might be shared with.
Our Contact Information (Data Controller)
PRS Plumbing and Heating Services Ltd,
Premier House, Winchester Road, Popham, Hants SO21 3BJ
Telephone: 01256 398881
Company Email: enquiries@prsplumbing.co.uk
What we do with your personal data
We process personal data only for the purpose for which they are collected. The purpose is dependent on whether you use only our website, or additionally, our services. If you use our services you are required to register and we collect your personal data. We use this personal data for the provision of the service or the performance of the contract. We may use your personal data for other similar purposes, including marketing and communications, but that will only occur in the case we have your consent or another legal justification for doing so.
From our Website Visitors we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose | Legal basis | Retention period |
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data); and as part of our efforts to keep our Website secure. | It is in our LEGITIMATE INTEREST (or that of a third party) | for 30 days |
To improve our Website to ensure that content is presented in the most effective manner for you and for your computer | It is in our LEGITIMATE INTEREST (or that of a third party) | for 1 year |
For trend monitoring, marketing and advertising; | We have data subject’s CONSENT | until consent is withdrawn |
For purposes made clear to you at the time you submit your information; | We have data subject’s CONSENT | until consent is withdrawn |
From our Developer/Contractor customers we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose | Legal basis | Retention period |
Financial and business administration | We have a CONTRACT with the data subject | Shredded after 4 years |
To manage new sales enquiries | We are in PRE-CONTRACT discussions with the data subject | for as long as contract and legal obligations require |
From our Head Office Visitors, we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose | Legal basis | Retention period |
For health and safety and security | We have LEGAL OBLIGATION | For 90 days |
From our private householder customers, we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose | Legal basis | Retention period |
Collateral warranty lasts for 12 years | We have a CONTRACT with the data subject | for 12 years |
To respond to post-warranty repair requests we need history of appliance and owner. | We have data subject’s CONSENT | for 12 years |
To conduct agreed annual services for developers’ customers and ongoing warranty for 1-2 years | It is in our LEGITIMATE INTEREST | for 12 years |
From our Sub-contractor (labour only), we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose | Legal basis | Retention period |
For financial administration | We have a CONTRACT with the data subject | Shredded after 4 years |
To assess weekly pay | We have a CONTRACT with the data subject | for as long as contract and legal obligations require |
From our suppliers (of materials) we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose | Legal basis | Retention period |
Business admin | It is in our LEGITIMATE INTEREST | for 5 years |
For financial administration | We have a CONTRACT with the data subject | Shredded after 4 years |
What personal data do we collect?
The personal data we collect depends on whether you just visit our website or use our services. If you visit our website, you do not need to provide us with any personal data. However, your browser transmits some data automatically, such as the date and time of retrieval of one of our web pages, your browser type and settings, your operating system, the last web page you visited, the data transmitted and the access status, and your IP address.
If you use our services, personal data is required to fulfil the requirements of a contractual or service relationship, which may exist between you and our organisation.
We may collect:
Employee Performance Data*
Employer
Name
Location Information
Telephone contact details
Family
Banking Details*
Tax Codes*
Date of Birth
Financial Details*
Employment History
ID number (passport; driving licence; NI)*
Vehicle Reg
Photographs together with Identifiers
Criminal Record
Education History
Address
We collect your personal data from the following indirect sources
Data subject type | Personal data type | Indirect source name |
Private householders | Name, Address, Email, Telephone contact details | From house developers |
Who might we share your personal data with?
To maintain and improve our services, your personal data may need to be shared with or disclosed to service providers, other Controllers or, in some cases, public authorities. We may be mandated to disclose your personal data in response to requests from a court, police services or other regulatory bodies. Where feasible, we will consult with you prior to making such disclosure and, in order to protect your privacy, we will ensure that we will disclose only the minimum amount of your information necessary for the required purpose.
We transfer personal data to the following organisations and countries:
Organisation name |
Data subject type |
Type |
Location |
Google LLC |
Private householder, Developer/Contractor customer |
Processor |
USA/Privacy Shield |
Dropbox Inc. |
Private householder, Developer/Contractor customer |
Processor |
USA/Privacy Shield |
Taylorcocks (Auditors) |
Developer/Contractor customer, Suppliers (materials), Sub-contractor (labour only), Private householder |
Controller |
UK |
Canvas Solutions, Inc. GoCanvas |
Private householder |
Processor |
USA |
HCS Safety Ltd |
Private householder, Developer/Contractor customer, Employee |
Processor |
UK |
When a Processor or Controller is in a country outside the EU, we apply the necessary safeguards which may include, confirming whether the EC approves of transfers to the country, whether we need to use the EC’s model contracts or, if the transfer is internal to our organisation, commitment to Binding Corporate Rules. Details of these safeguards may be obtained by contacting us directly.
How do we safeguard your personal data?
We limit the amount of personal data collected only to what is fit for the purpose, as described above. We restrict, secure and control all of our information assets against unauthorised access, damage, loss or destruction; whether physical or electronic. We retain personal data only for as long as is described above, to respond to your requests, or longer if required by law. If we retain your personal data for historical or statistical purposes we ensure that the personal data cannot be used further. While in our possession, together with your assistance, we try to maintain the accuracy of your personal data.
How can you access your personal data?
You have the right to request access to any of your personal data we may hold. If any of that information is incorrect, you may request that we correct it. If we are improperly using your information, you may request that we stop using it or even delete it completely.
If you would like to make a request to see what personal data of yours we might hold, you may make a request from our company website.
Where you have previously given your consent to process your personal data, you also have the right to request that we port or transfer your personal data to a different service provider or to yourself, if you so wish.
Where it may have been necessary to get your consent to use your personal data, at any moment, you have the right to withdraw that consent. If you withdraw your consent, we will cease using your personal data without affecting the lawfulness of processing based on consent before your withdrawal.
Our Data Protection Representative
Thomas Savine
info@prsplumbing.co.uk
Telephone: 01256 398881
Our Supervisory Authority
You have the right to lodge a complaint with any Supervisory Authority. See our Supervisory Authority contact details below
INFORMATION COMMISSIONER’S OFFICE
United Kingdom
Water Lane, Wycliffe House
Wilmslow – Cheshire SK9 5AF
international.team@ico.org.uk
+44 1625 545 745
www.ico.org.uk