Privacy Policy

WHO WE ARE

The Finishing Line Ltd (‘the Company’) is a Limited Company registered in England and Wales with company number 02120683. The Company’s registered office address is 2a Forest Drive, Theydon Bois, Epping, Essex, CM16 7EY.

 

The Company is subject to the requirements of data protection legislation applicable to the UK and must use your personal data in accordance with the law.

 

HOW YOU CAN CONTACT US

Telephone: +44 (0)1268 498 950

info@finishingline.co.uk

 

IF YOU ARE A VISITOR TO OUR WEBSITE

Analytics        

When you visit our website, we use Google Analytics (third-party service providers) to collect standard internet log information and details of visitor behaviour patterns. We do this so that we can find out how people use our website e.g. how many people visit our website and which areas they look at.

 

The information generated by Google Analytics is transmitted to and stored by Google on servers in the United States. Google adheres to EU-US Privacy Shield Framework which puts it under an obligation to meet certain security standards approved by the EU. Google will use the information on behalf of the Company for the purposes of evaluating your use of the website, compiling reports on website activity for us and providing us with other services relating to website activity and internet usage.

 

You may refuse the use of Google Analytics via the settings in your browser (see cookies section below). To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout.

 

Our lawful basis for using your information in this way is for our legitimate interests in understanding how our website is used.

 

Cookies

The Company does not currently use any other cookies in addition to the analytics described above.

 

IF YOU ARE A CLIENT

We keep your information confidential and will not disclose it to third parties unless disclosure is:

(a)    Authorised by you;
(b)    Necessary as part of the design services we are providing to you (to perform our contract with you);
(c)    Required by law or our professional rules;
(d)    Necessary for the purposes of our legitimate interests or those of a third party (in other words, we have a compelling justification for the disclosure); or
(e)    Necessary to protect your vital interests or those of another person i.e. to protect a life.

 

We use your information primarily to provide design services to you. We also use your information for: accounting and billing purposes; to comply with our legal obligations, and to manage our business effectively. We may also send you information about our services or events that we think may be of interest to you. You will be given an option to opt-out of receiving these communications from us.

 

We often outsource part of our work to other people or companies to improve efficiency in our services and your client experience. For example, we outsource illustrations and photography. This means that we will need to disclose relevant information about you to them. We will always carry out due diligence and obtain confidentiality agreements from such outsourced providers. If you would like more information about our outsourcing arrangements, please contact us.

 

We may correspond with you by email if you provide us with an email address, unless you advise us in writing that you do not wish us to do so.  You acknowledge that email may not be secure.  Email will be treated as written correspondence and we are entitled to assume that the purported sender of an email is the actual sender and that any express or implied approval or authority referred to in an email has been validly given. Please be aware that the Company may monitor and read any email correspondence travelling between you and any mail recipient at the Company as part of its monitoring activities to ensure compliance with its Information Management & Security Policy.

 

We will aim to communicate with you by such method as you request. More often than not this will be in writing but may be by telephone if it is appropriate.

 

Where you provide us with fax or email addresses for sending material to, you are responsible for ensuring that your arrangements are sufficiently secure and confidential to protect your interests. You must tell us if this method of communication is not secure so that can use an alternative method.

 

The Internet is not secure and there are risks if you send sensitive information in this manner or you ask us to do so. Please be aware that the data we send by email is not routinely encrypted.

 

We will take reasonable steps to protect the integrity of our computer systems by screening for viruses on email sent or received. We expect you to do the same for your computer systems.

 

It is very unlikely that we will change our bank account details during the course of your matter. In any event, we will never contact you by email to tell you that our details have changed. If you receive any communications purporting to be from this company, that you deem suspicious or have any concerns about (however slight), please contact our office by telephone straightaway.

 

During the progress of your instructions, we will hold your information electronically. We will use all reasonable measures to ensure that your information remains confidential and will advise you immediately if we believe that any of your information has been released.

 

Once your instructions have been completed and the project has concluded, we will hold your records on our electronic systems for 6 years from the date that you pay our final invoice. After that period has elapsed, we will delete your records from our electronic systems. Once that has happened, your records will no longer be available.

 

We transfer your personal data outside of European Economic Area (EEA) where your personal data is backed up to cloud storage provided by companies based in the US. However, our storage providers are certified to the EU-US Privacy Shield Framework which means that they agree to process personal data to the standards expected by Europe. Our storage providers are bound by the same data protection laws as us, meaning that they have the same obligations to keep your information safe.

 

IF YOU HAVE APPLIED TO WORK FOR US

All of the information you provide when you apply to work for us, will only be used for the purpose of progressing your application, or to fulfil legal requirements if necessary. We will not share any of the information you provide during the recruitment process with any third parties unless authorised by you or required by law.

 

We will use the contact details you provide to us to contact you to progress your application. We will use the other information you provide to assess your suitability for the role you have applied for. You don’t have to provide what we ask for, but it might affect your application if you don’t.

 

Our legal basis for processing your personal data is two-fold:

1)    For our legitimate interests in ensuring that we have adequate recruitment procedures and undertake the right checks to ensure that we recruit the right candidate; and
2)    To meet our legal obligations, particularly those relating to equality and diversity.

 

If you are successful, the information you provide during the application process will be retained by us as part of your employee file for the duration of your employment plus 6 years following the end of your employment.

 

If you are unsuccessful at any stage of the process, the information you have provided until that point will be retained for 6 months from the closure of the vacancy.

 

Information generated throughout the assessment process, for example interview notes, is retained by us for 6 months following the closure of the vacancy.

 

Equal opportunities information is retained for 6 months following the closure of the vacancy whether you are successful or not.

 

We transfer your personal data outside of European Economic Area (EEA) where your personal data is backed up to cloud storage provided by companies based in the US. However, our storage providers are certified to the EU-US Privacy Shield Framework which means that they agree to process personal data to the standards expected by Europe. Our storage providers are bound by the same data protection laws as us, meaning that they have the same obligations to keep your information safe.

 

IF YOU ARE CURRENT EMPLOYEE OR FORMER EMPLOYEE

We process the following personal information about you (as applicable):

  • Contact details;
  • Bank details;
  • Pension details;
  • Tax details;
  • Pay details;
  • Annual leave details;
  • Sick leave details;
  • Performance details;
  • Qualifications;
  • Employment history;
  • Ethnicity details;
  • Disability details;
  • Training records.

 

We keep your information confidential and will not disclose it to third parties unless disclosure is:

(a)    Authorised by you;
(b)    Necessary for the performance of a contract;
(c)    Required by law or our professional rules;
(d)    Necessary for the purposes of our legitimate interests or those of a third party (in other words, we have a compelling justification for the disclosure); or
(e)    Necessary to protect your vital interests or those of another person i.e. to protect a life.

 

Our legal basis for processing your personal data is two-fold:

1)    For our legitimate interests in ensuring that we have adequate personnel records; and
2)    To meet our legal obligations as employers.

 

We will share your information with the following third parties:
•    HMRC;
•    Student Loan Company;
•    The Company’s pension provider;
•    The Company’s payroll provider;
•    The Company’s IT support provider.

 

Your employee file for the duration of your employment plus 6 years following the end of your employment.

 

We transfer your personal data outside of European Economic Area (EEA) where your personal data is backed up to cloud storage provided by companies based in the US. However, our storage providers are certified to the EU-US Privacy Shield Framework which means that they agree to process personal data to the standards expected by Europe. Our storage providers are bound by the same data protection laws as us, meaning that they have the same obligations to keep your information safe.

 

YOUR RIGHTS

If you are an individual, you have the following rights under the General Data Protection Regulation (GDPR):

(a)    Right to access personal data – you can request details from us of the personal data that we hold about you;
(b)    Right to object to processing – you can tell us that you want us to stop processing your personal data;
(c)    Right to object to automated individual decision making including profiling – you can object to us making decisions about you solely by using a computer system without any human consideration. We do not currently do this;
(d)    Right to rectification – you can ask us to correct personal data that we hold because you believe it is inaccurate;
(e)    Right to erasure – you can ask us to delete the personal data that we hold about you;
(f)    Right to restrict processing – you can tell us that you only want us to use the personal data for a specific reason.

 

Please note that these rights are not absolute rights (they are not rights that will be automatically granted), as we have to consider whether there are any reasons why we cannot meet your request. For example, we will not be able to delete data that we are legally obliged to keep. We will let you know if we not able to meet your request and the reason why (where it is appropriate to disclose this information to you).

 

You also have the right to complain to the Information Commissioner’s Office (ICO) if you are not happy with the way that we handle your personal data. You can contact the ICO at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF or by calling the ICO’s helpline on 0303 123 1113.

 

Please note that where you provide consent to us using your personal data, you are entitled to withdraw that consent at any time. You can do this by informing your file handler or contacting our designated Data Protection Manager.

 

LINKS TO OTHER WEBSITES

This Privacy Notice does not cover any links to other websites that have been included on our website. Please read the Privacy Notices on the other websites that you visit.

 

CHANGES TO OUR PRIVACY POLICY

This privacy notice is reviewed regularly and was last updated in June 2018.