This policy is for the following companies which will be collectively known as Indeo:
Indeo Limited
Indeo Construction Services Limited
Indeo Professional Services Limited
Indeo Contracting Limited
Indeo Technologies Limited
Indeo Equipment Limited
This policy applies to:
All employees of Indeo
All contractors, subcontractors, suppliers and anyone else who provides work to or on behalf of Indeo
Definition
Organisations such as Indeo that process personal data are required by law to comply with data protection legislation which creates the standards for the fair and lawful processing of such data.
The following defined terms will be used throughout this policy:
Controller – As defined by the Information Commissioner’s Office, Controllers are the main decision-makers – they exercise overall control over the purposes and means of the processing of personal data. If two or more controllers jointly determine the purposes and means of the processing of the same personal data, they are joint controllers. However, they are not joint controllers if they are processing the same data for different purposes.
Data – means information that is stored either electronically or physically.
Data Protection Legislation – means the Data Protection Act 2018 (the “DPA”) and the General Data Protection Regulation 2016/679 (the “GDPR”).
Data Subject – means the identified or identifiable natural person or organisation
Data Users – means those Indeo employees who are required to use and process the Personal Data collected. This policy requires that Data Users must protect the Personal Data and follow all required procedures in relation to this data.
Data Protection Officer – A DPO can monitor internal compliance, inform and advise on your data protection obligations, provide advice regarding Data Protection Impact Assessments (DPIAs) and act as a contact point for Data Subjects and the Information Commissioner’s Office (ICO). It is not compulsory for the activities that Indeo wish to undertake and therefore there is no DPO within this policy.
Personal Data – under UK GDPR, this means any information relating to an identified or identifiable natural person (‘Data Subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processor – under UK GDPR, this means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Policy
This policy is designed to ensure we (or another organisation on our behalf) collect, store and use Personal Data such that:
It has been obtained legally and fairly
It is both accurate and relevant
It is used for specific and relevant purposes to our business
It is securely stored
It is kept for no longer than is necessary
Our policy also extends to the rights that individuals and organisations have in regards to the Personal Data we collect on them:
The right to obtain confirmation that their data is collected, stored and used
The right to access this data
The right to change the data if it needs correcting
The right to request deletion of the data
This policy applies to all Data Users including all Indeo employees and any external Processors and may be updated at any time to reflect changes in the work Indeo do, changes in the law, or for any other reason.
At the time of this revision of the Data protection and privacy policy, there is no assigned Data Protection Officer for Indeo due to the activities it undertakes.
Purpose of the policy
Every individual has a right to how their Personal Data is handled and processed. Indeo will, as part of how it delivers its business, collect and process Personal Data on its users, suppliers, employees and other third parties. We recognise that there is not just a legal requirement to collect and process this Personal Data correctly but there is also an obligation to the individuals and organisations we work with and who work for us to ensure their data is safe and used correctly in accordance with this policy.
Objectives
Examples of the data collected, stored and used by Indeo include:
Personal data
Commercially sensitive data
Business management information
Productivity data
Industry know how
These are the key areas of data that are vital to the successful running of Indeo and it is therefore the policy that all data is treated with the same level of severity in terms of how it is collected, stored and handled.
The objectives therefore are:
To coordinate how data is collected and stored
To promote confidence in our ability to collect and store this data securely
To provide assurances for third parties
To comply with the law
To provide a standard for all Indeo employees to meet
Indeo are entitled under law to use Personal Data for management and administrative purposes. We will however ensure that this is not misused or used without permission.
Where Personal Data in connection with you is sought, you will be informed how and why this information is being collected and stored.
Anyone collecting, storing and using Personal Data must comply with Data Protection Legislation and therefore this Personal Data must be:
Collected, stored and used fairly and lawfully
Collected for specific and legitimate reasons and not processed beyond those reasons
Relevant and limited to what it is necessary for
Accurate and, where possible, kept up to date. If not possible to be kept up to date, it must be deleted if it is known to be incorrect.
Permitting identification for as long as is necessary
Used in line with the rights of the individual under the Data Protection Legislation and allows the individual to access, change and delete the Personal Data if reasonably requested to do so.
Processed in a manner that is appropriate and secure.
Not transferred to countries outside of the UK
Fair and lawful processing
Data Protection Legislation allows for the processing of Personal Data, it does not prevent it. However, this processing must be fair and must not adversely affect the individual or organisation of which the data has been collected.
We will process this Personal Data fairly, legally and transparently.
Additional protections need to be met when processing Special Categories of Data. Special Categories are defined by UK GDPR as:
personal data revealing racial or ethnic origin;
personal data revealing political opinions;
personal data revealing religious or philosophical beliefs;
personal data revealing trade union membership;
genetic data;
biometric data (where used for identification purposes);
data concerning health;
data concerning a person’s sex life; and
data concerning a person’s sexual orientation
Further protections still will need to be met when processing Criminal Offence data. This covers a wide range of data relating to offences, suspected offences and unproven allegations. It can include anything in the context of:
Criminal activity
Allegations
Investigations
Proceedings
Personal Data about penalties
Conditions or restrictions placed on an individual as part of the criminal justice process
Civil measures which may lead to a criminal penalty if not adhered to
Purpose Limitation when Processing Personal Data
Data must only be processed for specific and legitimate reasons and not processed any further that it no longer complies with those reasons.
In our operations, we may collect any data that is listed within this policy and this may be collected either directly (from emails, forms etc direct from the individual or organisation that the Personal Data relates to) or indirectly (from any source other than the individual or organisation that the Personal Data relates to).
The specific purposes for which the Personal Data will be processed is identified in table 1 at the end of this policy document.
Notifying Data Subjects
Collection of Personal Data must be notified by the Controller either before it is collected or as soon as practicable after it has been collected.
When collecting Personal Data from individuals or organisations, we will inform them about:
The purposes of why the Personal Data is being collected and Processed
The third parties we may share the Personal Data with
The options for the Data Subject of what they may request of their data
The Personal Data we receive on a Data Subject from third parties and what we as Controller of that information will do with that data.
Relevant and non-excessive Processing
Personal Data will only be collected and Processed to the extent that it is relevant and limited to what is necessary in relation to the purposes for which it is Processed.
Accuracy of data
Best endeavours will be made to ensure the accuracy of the Personal Data stored and Processed. If data is known to be incorrect, efforts will be made to correct it and if this is not possible, the data will be deleted if reasonable to do so.
Data retention
Personal Data which allows for the identification of the Data Subject must not be kept longer than is reasonable for the purposes which the Personal Data is collected for.
For example, if data is collected for a specific contract, the data must be stored in accordance with the Indeo policies. However, if the data is collected for a specific marketing campaign, the data must be removed once the campaign has been completed.
All reasonable steps must be taken to totally remove the Personal Data upon the requirement to delete it.
Processing in line with Data Subjects rights
Data Subjects have the right to request access to the Personal Data we hold on them and whether or not this is being Processed. Where it is the case, they have the right to access the Personal Data and the following information:
The purpose for the Processing
The Personal Data categories
The third parties or categories of third party that the information will be shared with
If the information is available, the duration for which the data will be stored
The existence of the right to request the erasure, amendment or rectification of the Personal Data or to object to the Processing of it
The right to lodge a complaint with the supervisory authority
The source of where the Personal Data was obtained if this information has been stored
Which countries the Personal Data has been or may be shared
The access request may come in any form including written or verbal communication. However, Indeo must be able to validate the authenticity of the request and must therefore ensure that the Data Subject is the same identifiable individual as the Data Subject the request is about.
Response to a request will be provided in an electronic communication only.
Where the request is excessive or requires verbal or non electronic written communication, Indeo reserve the right to recover its cost from the Data Subject.
Data Subjects also have the right to have their Personal Data erased, rectified, amended or completed as follows:
The Data Subject may request deletion of some of or all of their Personal Data but this is subject to what data we will need to retain. For example, record keeping of works done will need information keeping in line with Indeo policies to ensure legal obligations are upheld and records are kept.
Data Subject may also request rectification of their Personal Data where there are inaccuracies or where the information has now changed.
Consent by the Data Subject for use of their information may be withdrawn at any time.
The Data Subject has a right to be informed of how the Personal Data is used.
Further to the point above, the Data Subject may then restrict the Processing of their Personal Data as far as is reasonable for the business operations of Indeo.
They may also object to the use of their Personal Data
Data Subjects may ask that their Personal Data is ported to another organisation
Data Security
Personal Data may only be Processed in a manner that ensures the appropriate security of such data and where possible, must protect against accidental release, loss, damage or inappropriate use of the data.
Policies and procedures will be in place for maintaining the security of data from original collection to final destruction.
All data collected shall be protected with confidentiality, integrity and availability.
Confidentiality ensures that only those who need to see the data do so
Integrity ensures that all information will be as relevant and accurate as possible
Availability means that all Personal Data is available to a Data Subject should it be relevant for disclosure upon on a request
Security measures for Personal Data include:
A paper free approach to working which will result in zero risk of physical copies of data being lost or misplaced.
Entry controls to critical electronic documents
When Data Users are in an environment where others may see the screen then they are asked not to have these critical documents open
Computer security to be installed on all devices and only Indeo devices may access Indeo networks
Training of staff on how to keep data secure
Transferring Personal Data to a company outside of the UK
Personal Data is not to be transferred outside of the European Economic Area
Disclosure to Third Parties of Personal Data we have
Indeo reserve the right to disclose Personal Data to third parties where:
The business sells or purchases any assets
If we are required to in order to comply with any legal obligation, enforcement or similar
Any reason set out in table 1 (at the end of this policy document)
Changes to this policy
Indeo may be required to change this policy in accordance with legal obligations or due to changes in the way the business is operated. We therefore reserve the right to change this policy for any reason.
Responsibilities
Managers
Managers of all levels are responsible for the collection and Processing of Personal Data.
They are also responsible for all communications to their teams of how this is to be used and for communications to Data Subjects.
When receiving a request from a Data Subject, it is the managers duty to send a holding email as soon as possible to confirm that the request is being dealt with. A further response should be given within 30 calendar days to either confirm the outcome of the request or to confirm that more time is required.
Everyone else
Everyone else, whether employed directly, via agency or via contract, is required to be mindful of everything within this policy when handling Personal Data.
They are also required to inform their manager whenever they are handling this Personal Data and take every practical step to avoid potential release or mishandling of this information.
Everyone is also responsible for providing updates to Indeo of their own Personal Data changes to ensure the business holds the most up to date relevant information.
Finally, it is everyone’s duty to understand the relevant Data Protection Legislation and the information within this Policy and to conduct their every day work in accordance with both.
Statutory role
The Indeo individual who has ultimate responsibility for the company complying with Data Protection Legislation is the Director.
Data breaches
If you become aware of a breach or a suspected breach, you are required to immediately report this to the Director, whose contact details are at the end of this document.
A breach includes both non compliance with either Data Protection Legislation or this policy or a breach could be the loss of Personal Data.
Data breaches could include:
Loss of theft of IT equipment
Unauthorised access to either office or IT equipment
Unauthorised access to an IT account
Ransomware attack
Lack of protection to allow unauthorised accounts to access information
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.