Privacy Notice – Privacy of Data Subjects
Jigowatt’s business activities are classified under the European Union’s General Data Protection Regulation (‘GDPR’ – link to the
Jigowatt’s business activities mean that Jigowatt is classified as a ‘Data Processor’, under the European Union’s General Data Protection Regulation (‘GDPR’ – link to the GDPR law). This status means we only process personal data on the instructions of our clients. On that basis, we use your personal data to assist our clients in providing the goods or services that you have ordered, answering your enquiries and providing information about other products/services:
- We respect your personal data and take its security very seriously.
- We only hold personal data on behalf of clients, and only for the purpose for which it was obtained, as stipulated by our clients’ instructions
- We delete your data when it has reached the end of its retention period
- You have privacy rights
- We are happy to answer your questions. Our contact details can be found at the end of this notice
What data we hold
On the instructions of our clients, we hold fully encrypted personal data records on our UK based web servers. These data typically include names and linked email addresses (sometimes work email address, sometimes personal). Other personal data records variously include telephone numbers, postal addresses and job titles.
We also generate log files from various servers. These will include an IP addresses assigned to you or to your internet-service provider. These are automatically created on the server, and retained for security reasons.
In the storage and/or processing of any personal data, our IT systems are encrypted (see ‘Technical Security’ below).
How we use your personal data
References to the ‘legal basis’ for processing of your personal data relate to Article 6 of the above-linked General Data Protection Regulation. Each piece of personal data that we process i.e. organise, store, move or otherwise action, must have a legal basis. For Jigowatt, as a ‘Data Processor’, any given legal basis is decided upon by our respective client, as the ‘Data Controller’ in each case,.
We only process personal data on our clients’ instructions.
To deal with enquiries, where you choose not to become a customer/client
If you call us or email us directly i.e. as Jigowatt, we will follow up on your enquiry and see if there is a way in which we can help you. If you choose not to become a client/customer, we delete all data after answering an enquiry.
If you provide us with information for a quote and then do not accept the quotation, we delete all data after answering that enquiry.
If you purchase from us or one of our clients
In order to process your order, we will need to process your data so that your supplier (our client) can send you the goods that you have ordered, or to get the goods delivered to you. At no time do we have access to, or store, sensitive payment information; this is handled and held by third parties and does not pass through our system.
We use the logs from our servers to help with the server’s security, as well as to look at visitor-behaviour e.g. to know which website pages get the most traffic or are the most popular. None of this is linkable to individuals.
Your data and transfers outside of the EEA
We do not transfer or process these data outside the European Economic Area.
You have rights in respect of our processing of your personal data, which are, as follows, the right to:
- Access your personal data and information about our processing of it; you also have the right to request a copy of your personal data (but we will need to remove information about other people)
- Rectify incorrect personal data that we are processing
- Request that we erase your personal data, if:
- we are processing your personal data by ‘consent’, and you wish to withdraw that consent
- we no longer have legitimate grounds to process your personal data, or
- we are processing your personal data unlawfully
- Object to our processing e.g. if ‘legitimate interest’ is the legal basis upon which your data is being processed
- Restrict our processing of your data, which means you may wish to allow certain processing activities, but prohibit others; this right applies where ‘consent’ is the basis upon which your data is being processed, or ‘legitimate interest’
If you want to exercise any of these rights, please contact our Privacy Manager, using the details at the end of this notice.
You also have the right to lodge a complaint about our processing to the UK’s Information Commissioner’s Office (www.ico.org.uk).
As a prospective customer, we do not transfer your personal data to third parties at this stage except in the following cases:
- Companies that provide services to us. Our telephone service providers will get to see your phone number, if we call you. Our broadband supplier could see your email address (but not the content of what you send us, if you encrypt it).
- In response of a court order. It is possible, though unlikely, that we might be forced to disclose your information in response to a court order.
As a customer, we transfer your data to the following third parties:
- Cloud service providers. We use a number of cloud service providers, such as email management services, our accountancy software, email providers, Google and Office 365.
- In response to a court order. It is possible, though unlikely, that we might be forced to disclose your information in response to a court order.
We ensure that all our computers (desktops and/or laptops), mobile and other devices, and IT systems and infrastructure are password-protected, with very strong alpha numeric passwords of at least 10 characters. We ensure that Apple system Firewalls and Norton Security are installed, and kept up to date on each device.
This refers to the length of time that we will continue to process or store your personal data.
- Data about prospective clients who do not choose to use our service is deleted immediately
- Certain data about clients are held for 7 years, for the Tax Authorities and accounting purposes
- For marketing purposes, as a Data Processor, we do not retain our clients’ personal data records for our own marketing purposes. Our marketing uses the ‘work emails’ of clients, whereby we may from time to time send marketing material or other information e.g. Newsletter. Beyond that, we only retain personal data on our clients’ instructions, and it is retained only for as long as those instructions stipulate is required for the purpose(s) stated.
- Server logs (IP addresses): We only retain IP addresses for as long as required by the instructions of our clients.
For Jigowatt Data Protection Policy, please check https://jigowatt.co.uk/data-protection-policy/
Jigowatt is registered with the Information Commissioner’s Office ZA297127
4 Office Village
Forder Way, Cygnet Park,
Cambridgeshire PE7 8GX
Jigowatt Privacy Manager: John Conmy: firstname.lastname@example.org