Introduction
We are 4K Contracts Limited (referred to as “4K”, “we”, “us” and “our” in this Privacy Policy), a company incorporated in England with company registration number 13967046 and whose registered office address is 4 Rosemary Lane, Lower Stondon, Beds, SG16 6NG
The information set out in this Privacy Policy is provided to individuals whose personal data we process (“you” or “your”), in compliance with our obligations under Articles 13 and 14 of the General Data Protection Regulation 2016/679 (GDPR).
To make this information clear, we have divided the data we receive into the following groups and corresponding Schedules, where each of which refers to: the particular category of information we collect and retain; where we obtain the information from; the purpose and legal basis of processing and whom we will (if applicable) disclose the information to:
Schedule 1
Data about our clients and all individuals in respect of whom we have acquired personal information in connection with any products or services offered by us include if B2B: (including directors, shareholders, consultants, employees or other personnel of our clients)
Schedule 2
Data about our suppliers and supplier personnel Schedule 3
Data about individuals who apply for employment or work experience with us Schedule 4
Data about directors and staff of the firm, and former directors and staff and other individuals who spend time at the firm (such as consultants and secondees)
In addition to the above, individuals who interact with us in any of the above capacities should also refer to the following:
Schedule 5
Data collected about staff and visitors to our office
Data controller details
We are the data controller in relation to the processing of the personal information that you provide to us. Our contact details are as follows:
- Address: 4 Rosemary Lane, Lower Stondon, Beds, SG16 6NG
- Email address: enquiries@4kcontracts.co.uk (please include “Personal Data Request” in your subject heading to ensure it receives the correct attention).
International transfers
We will not transfer personal data relating to you to a country which is outside the European Economic Area (EEA) unless:
- the country or recipient is covered by an adequacy decision of the Commission under GDPR Article 45;
- appropriate safeguards have been put in place which meet the requirements of GDPR Article 46 (for example using the European Commission’s Standard Model Clauses for transfers of personal data outside the EEA); or
- One of the derogations for specific situations under GDPR Article 49 is applicable to the transfer. These include (in summary):
the transfer is necessary to perform, or to form, a contract to which we are a party: o with you; or o a third party where the contract is in your interests; - the transfer is necessary for the establishment, exercise or defense of legal claims;
- you have provided your explicit consent to the transfer; or
- the transfer is of a limited nature and is necessary for the purpose of our compelling legitimate interests.
Retention of personal data
Our retention and deletion policy can be found in Schedule 6
Your rights in respect of your personal data
You have certain rights under existing data protection laws, including the right to (upon written request) access a copy of your personal data that we are processing. From 25 May 2018, if you are based within the UK or the EEA or within another jurisdiction having similar data protection laws:
- you will have the following rights:
- right to access: the right to request certain information about, access to and copies of the personal information about you that we are holding (please note that you are entitled to request one copy of the personal information that we hold about you at no cost, but for any further copies, we reserve the right to charge a reasonable fee based on administration costs); and in certain circumstances, you will also have the following rights: o right to erasure/“right to be forgotten”: the right to withdraw your consent to our processing of the data (if the legal basis for processing is based on your consent) and the right to request that we delete or erase your personal information from our systems (however, this will not apply if we are required to hold on to the information for compliance with any legal obligation or if we require the information to establish or defend any legal claim);
- right to restriction of use of your information: the right to stop us from using your personal information or limit the way in which we can use it; o right to data portability: the right to request that we return any information you have provided in a structured, commonly used and machine-readable format, or that we send it directly to another company, where technically feasible; and
- right to object: the right to object to our use of your personal information including where we use it for our legitimate interests or for marketing purposes.
- Please note that if you withdraw your consent to the use of your personal information for purposes set out in our Privacy Policy, we may not be able to carry out our contractual obligations to you or provide you with access to all or parts of our services.
- If you consider our use of your personal information to be unlawful, you have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office. Please see further information on their website: www.ico.org.uk Security
- We keep your information protected by taking appropriate technical and organisational measures to guard against unauthorised or unlawful processing, accidental loss, destruction or damage. For example: o where appropriate, data is encrypted when transiting on our system or stored on our databases; o we have implemented safeguards in relation to access and confidentiality in order to protect the information held within our systems; and o we frequently carry out risk assessments and audits to monitor and review threats and vulnerabilities to our systems to prevent fraud.
- However, whilst we will do our best to protect your personal information, we cannot guarantee the security of your information which is transmitted via an internet or similar connection. It is important that all details of any username, password and/or other identification information created to access our servers are kept confidential by you and should not be disclosed to or shared with anyone.
Changes to this Privacy Policy
We may amend this Privacy Policy from time to time, for example to keep it up to date, to implement minor technical adjustments and improvements or to comply with legal requirements. We will always update this Privacy Policy on our website, so please try to read it when you visit the website (the “last updated” reference tells you when we last updated our Privacy Policy)
Last Updated August 2022
Schedule 1
Data about our clients, and all individuals in respect of whom we have acquired personal information in connection with any products or services offered by us (including directors, shareholders, consultants, employees or other personnel of our clients)
| What we collect: | We may use your information for the follow-ing purposes, based on the following legal grounds: | Recipients: |
|
| Please note that personal information we are holding about you may be shared with and processed by:
|
Schedule 2
Data about suppliers and supplier personnel
| What we collect: | We may use your information for the following purposes, based on the following legal grounds: | Recipients: |
|
| Please note that personal information we are holding about you may be shared with and processed by:
|
Schedule 3
Data about individuals who apply for employment or work experience with the firm.
| What we collect: | We may use your information for the following purposes, based on the following legal grounds: | Recipients: |
| Contact details such as names, home and work addresses, landline/ mobile phone or fax numbers, email addresses, previous addresses. | Our legitimate interest in processing such information for contacting individuals where we need to do so and for obtaining/verifying evidence of identity. We also carry out location mapping, for the purposes of assessing whether a candidate lives near the relevant work site. | Please note that personal information we are holding about you may be shared with and processed by:
|
“Special categories of information” such as:
| We will use your particularly sensitive personal information in the following ways, and based on the following legal grounds:
| Please note that personal information we are holding about you may be shared with and processed by our service providers (such as data storage, typing, administrative support and audit). |
| Employment related history and qualifications information such as position/title, date of birth, employment history and CV, references from previous employees, professional specialisms, education and qualifications, salary and benefits, disciplinary record. | Our legitimate interest in processing such information for assessing their suitability for the role, or considering potential packages and offers. | Please note that personal information we are holding about you may be shared with and processed by:
|
| Personal information such as professional and personal interests and languages spoken. | Our legitimate interest in processing such information for assessing their suitability for the role. | |
| Our legitimate interest in processing such information for obtaining/verifying evidence of identity. Compliance with a legal obligation in order to confirm that the individual is entitled to work in the UK and for the purpose of security and prevention of crime. | Please note that personal information we are holding about you may be shared with and processed by:
|
Schedule 4
Data about directors and staff of the firm, consultants, secondees, those on work experience, temporary staff, former directors and staff, next of kin, spouses, beneficiaries
| What we collect: | We may use your information for the following purposes, based on the following legal grounds: | Recipients: |
“Special categories of information” such as:
|
We will use your particularly sensitive personal information in the following ways, and based on the following legal grounds:
We will use your particularly sensitive personal information in the following ways, and based on the following legal grounds:
| Please note that personal information we are holding about you may be shared with and processed by:
|
| Our legitimate interest in processing such information in order to keep appropriate employment records, for assessing their continued suitability for their role and for planning progression. | Please note that special categories of information will only be disclosed as follows:
| |
| Payment and financial information such as bank details, transaction history, salary and benefits, life insurance, pension related information, tax-related information, National Insurance number, payroll documentation (P45 / P60 / P11D). | Necessary for the performance of the employment contract to pay or compensate the individual.
| |
Information contained in or provided to us as part of our recruitment or take on process such as details included in copy personal photographs and residential ID documents we receive.
| Our legitimate interest in processing such information for obtaining/verifying evidence of identity.
|
Schedule 5
Data about visitors to our office
| What we collect: | We may use your information for the follow-ing purposes, based on the following legal grounds: | Recipients: |
|
| How we share information Please note that personal information we are holding about you may be shared with and processed by:
|
Schedule 6
Retention and deletion policy
Unless we are required or permitted by law to hold on to your information for a specific retention period, we may retain your information for the following purposes and periods:
| Category of personal data | Period for which personal data will be stored |
| Contracts and general correspondence (emails, post and other communications) obtained in the course of providing our services: Such information will be stored for 12 years following completion of the services or termination or expiry of the contract with our client (whichever is later). Contact details for marketing purposes: Contact information relating to clients and contacts will be held for so long as we believe the information to remain accurate and the individual concerned remains a genuine connection of the firm, or of one of our directors and staff. We have a programme for reviewing our contacts regularly, and removing any information which is considered to be out of date or no longer relevant. Contracts and general correspondence (emails, post and other communications) obtained in the course of providing your services: Such information will be stored for 12 years following completion of the services or termination or expiry of your contract (whichever is later). Personal data obtained from employment or work experience applicants will be deleted after 8. Human resources (HR) records will be destroyed 8 years following employment. For the purposes of administration this will be actioned annually in December of each year. Personal data stored in private workspaces created for members of HR (including for appraisals, promotion and probation reviews) will be deleted 8 after creation. CCTV information is destroyed after 90 days |