PRIVACY POLICY
At RT Machinery Ltd (RTM), we are committed to protecting and respecting your privacy.
Last Reviewed: 9th October, 2023
This policy sets out the basis on which any personal data we collect from you, that you provide to us or that we may receive from others about you will be processed by us. It includes data that we hold electronically and in paper files. We must advise that this policy is subject to change, so please check our website on a regular basis for any further changes.
We are required to provide you with this information under the General Data Protection Regulation (GDPR). UK Data Protection Acts of 1984 and 1998.
WEBSITE
By using the website or providing information to us you will have accepted the Privacy Policy in force at the time of use. This policy was last reviewed October 9th 2023 but we may amend it at any time.
This policy does not cover the data collection practices of any third party, including any third-party operators of web pages to which the site links such as machinery partners.
If you access these links they will cause you to leave our website and may result in the collection or sharing of information about you by a third-party (also see our Cookie Policy).
We do not control, endorse or make any representations about those third-party websites or their privacy practices, which may differ from ours. We encourage you to review the privacy policy of any site you interact with before allowing the collection and use of your personal data.
WHO WE ARE, HOW AND WHY WE PROCESS PERSONAL DATA
We will process data to deliver the services that RT Machinery Ltd has been asked or contracted to provide you with through your enquiry or contact. These include administration of your client account, provision of advice, promotion and administration of events, and the promotion and administration of RT Machinery Ltd Customer Services.
RT Machinery is a provider of product and support services, based in Buckinghamshire. RT Machinery has a registered office at Chandos House, School Lane, Buckingham, MK18 1HD and company number 5003780. Richard Taylor is the registered Data Protection Officer for RT Machinery Ltd. RT Machinery Ltd trades as RT Machinery Ltd but may also be referred to as RTM.
Legal Basis for Processing Data
The GDPR came into force on 25 May 2018. Up until that date and for previous transactions we will have continued to rely on your consent under the Data Protection Act 1998 as the legal basis for processing data.
Thereafter, the legal bases for the processing of this data will be under the following paragraphs of the GDPR: Article 6.1 (a). the data subject has given consent to the processing of his or her personal data for one or more specific purposes; Article 6 1.(b), the processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract, and Article 6 1.(f), it is in the legitimate interests of the data controller.
Our legitimate interests is the need to properly process your enquiry, administer your transaction, and administer either your client account or enquiry, transaction with RT Machinery Ltd and to provide you with all the services and information necessary. Safeguards have been put in place to ensure we achieve the correct balance between our interests and yours.
Who Has Access and Why?
Data will be held and processed for the purposes of administrating your client enquiry, order or account and the provision of client information services including the provision of product safety operational advice, product recalls or legal requirements and duties.
Only those staff that has a legitimate need to access data will be authorised to do so.
Retention of Data
The data will be held for the duration of your client account, trade account membership or longer where we have a legal obligation or other legitimate reason for doing so.
Accuracy
You are able to check and update the data we hold on you via the RT Machinery website. From time to time we will invite you to check that everything is correct and up to date. You have a number of rights under the GDPR.
How Do We Collect Personal Data From You?
We receive information about you from you when you use our website, complete forms on our website, if you contact us by phone, email, live-chat or otherwise in respect of any of our products and services or during the purchasing of any such product. Additionally we also collect information from you when you sign up, enter a competition, promotion or survey or when you inform us of any other matter.
If you provide us with personal data about a third party (for example when ordering parts or services on their behalf), you warrant that you have obtained the express consent from the third party for the disclosure and use of their personal data.
Your personal data may be automatically collected when you use our services, including but not limited to, your IP address, device-specific information, email address, address, name and post code, device event information, location information and unique application numbers.
What Type of Data Do We Collect From You?
The personal data that we may collect from you includes your name, address, email address, phone numbers, payment information and IP addresses. We may also keep details of your visits to our site including, but not limited to traffic data, location data, weblogs and other communication data. We also retain records of your queries and correspondence, in the event you contact us.
Please be aware that any video, image, or other content posted, uploaded or otherwise made available by you onto our website or incoming emails, whether published content or not, is not subject to our Privacy Notice.
We merely process such data on your behalf, subject to our Terms and Conditions and you are responsible for any applicable legal requirements in respect of your content.
How Do We Use Your Data?
We use information about you in the following ways:
How we use your data...
• To process orders or enquiries that you have submitted to us;
• To provide you with products and services;
• To comply with our contractual obligations we have with you;
• To help us identify you and any accounts you hold with us;
• To enable us to review, develop and improve our website and services;
• To provide customer care, including responding to your requests if you contact us with a query;
• To administer accounts, process payments and keep track of billing and payments;
• To detect fraud and to make sure what you have told us is correct;
• To carry out marketing and statistical analysis;
• To review job applications;
• To notify you about changes to our website and services;
• To provide you with information about products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes; and
• To inform you of service, product recall or updates and price changes.
Retention Periods
We will keep your personal data for the duration of the period you are a customer of RT Machinery Ltd. We shall retain your data only for as long as necessary in accordance with applicable laws and legitimate record keeping.
On the closure of your account, we may keep your data for up to 7 years after you have cancelled your services with us. We may not be able to delete your data before this time due to our legal and/or accountancy obligations. We may also keep it for research or statistical purposes. We assure you that your personal data shall only be used for these purposes stated herein.
Who Has Access to Your Personal Data?
Here is a list of all the ways that we may use your personal data and how we share the information with third parties. For clarity, we have grouped them into the specific products and services that we offer:
1. General Trading Sales, Service and Enquiries
We process your data for administration, billing, support and the provision of services. Your data will be stored on our server, encryption protected and stored on our back up through accredited and RT Machinery vetted, approved software, our contracted software support and data storage companies. We also process data through our web site and have contracted suppliers for Webhosting, support on our dedicated servers, virtual servers, cloud platform.
We process your data for administration, billing, support and the provision of services through our web page and using our Cloud-based Flowlens and Sage operating systems. Emails and document exchange is processed through Office 365, Outlook, preferred data file delivery service, user data is shared with Microsoft.
Exchange email shares data with third-party infrastructure in the EEA. Standard email is all UK based.
SSL certificates – We are accredited and have a premium certification.
We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place. Our security measures include firewalls, anti-virus software, encryption of data in transit, password protection and role-based access. We use reasonable security measures to help protect against the loss, misuse and alteration of the Personal Information under our control. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure.
2. Third Parties
For the avoidance of doubt, we do not and never shall sell your personal data to third parties for marketing or advertising purposes.
We work closely with a number of third parties (including business parties, service providers and fraud protection services) and we may receive information from them about you. These third parties may collect information about you including, but not limited to, your IP address, device-specific information, server logs, device event information, location information, and unique application numbers. We use their features within our website, however, in some instances, they may be acting as a data controller and they will have their own privacy policies, which we advise you to read.
We may pass your personal data to third parties for the provision of services on our behalf (for example processing your payment). However, we will only ever share information about you that is necessary to provide the service and we have specific contracts in place, which ensure your personal data is secure and will not be used for any marketing purposes.
However, we will not be liable (to the fullest extent permitted by law) for any damages that may result from the misuse of any information, including Personal Information, by these companies.
Consequences of Not Providing Your Data.
You are not obligated to provide your personal information to us, however, as this information is required for us to provide you with our services, we will not be able to offer some/all of our services without it.
CCTV
The Company operates a CCTV surveillance system (“the system”) at its premises, with images being monitored and recorded centrally. The system is owned and managed by the Company.
The purpose of processing personal data through the use of the system is crime prevention and/or our employee’s safety/security. This is further defined as CCTV is used for maintaining public safety, the security of property and premises and for preventing and investigating crime, it may also be used to monitor staff when carrying out work duties.
For these reasons the information processed may include visual images, personal appearance and behaviours. This information may be about staff, customers and suppliers (or their agents), offenders and suspected offenders and those inside, entering or in the immediate vicinity of the area under surveillance.
Where necessary or required this information is shared with the data subjects themselves, employees and agents, services providers, police forces, court or tribunal, security organisations and persons making an enquiry.
TRUSTPILOT
We work with the review and feedback website, Trustpilot, in order to collect customer feedback and improve our service. For this, we share customer and order information with them.
We retain control over the data provided and the purposes for which it is processed. We authorise Trustpilot to process the data provided only for the purpose of sending out the specified review invitation emails and nothing else.
Trustpilot will delete the data within a maximum of 30 days after the invitation email has been sent. Trustpilot will not and does not have the authority to use the data for any other purposes, and will never pass it on to any third parties.
You must agree to share your email address with Trustpilot for the review to be activated on our company profile. This is stated clearly on the review platform. When you submit your review, Trustpilot registers your email address, but this is based on your consent and never happens automatically.
You are able to unsubscribe from all Trustpilot emails by clicking the link at the bottom of their invitation emails.
By ordering with us and confirming you have read these terms and conditions, you agree for us to share this data with Trustpilot and to receiving a review invitation email.
YOUR RIGHTS
Right of Access
You have the right, subject to a number of exceptions, to know what information we hold about you. Unless the issue is complex, we will respond within one month.
Right of Rectification
You have the right to have any information we hold about you corrected if it is inaccurate or incomplete. Unless the issue is complex, we will respond within one month.
Right to Erasure
You have the right to request the deletion or removal of personal data where there is no compelling reason for us to continue to hold it.
Right to Restrict Processing
You have the right to restrict our processing of your data in certain circumstances, such as when there is a question over the way in which we are using it.
Right to Data Portability
You have the right to obtain and reuse your personal data for your own purposes.
Right to Object
You have the right to object to our processing of your personal data on the basis of legitimate interest, for direct marketing and for the purposes of research.
We will stop processing your data on the basis of legitimate interest unless there are compelling legitimate grounds for us to continue.
We will stop any processing of your data for direct marketing as soon as we receive an objection.
We will stop processing your personal data for research purposes if there are grounds that relate to your particular situation.
Automated Processing
We will not make any decision regarding you, your client account or your membership by purely automated means.
FURTHER INFORMATION
Any questions, comments or requests regarding this privacy policy should be addressed to trustline@rtmachinery.co.uk or accounts@rtmachinery.co.uk
Complaints
If you are not satisfied with the way in which we manage your personal data, you can seek recourse through the RT Machinery Ltd Complaints Procedure.
If you remain dissatisfied, you have the right to refer the matter to the Information Commissioner. The Information Commissioner can be contacted at:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Tel. 01625 545 745
Fax. 01625 524 510
Email. enquiries@ico.gsi.gov.uk