ENGYS understands that your privacy is important to you and that you care about how your personal data is used and shared online. We respect and value the privacy of everyone who visits any of Our websites: engys.com, clients.engys.com or ugm.engys.com (herein collectively referred to as Our Sites) and will only collect and use personal data in ways that are described here, and in a manner that is consistent with Our obligations and your rights under the law.
Please read this Privacy Notice carefully and ensure that you understand it. Your acceptance of this Privacy Notice is deemed to occur upon your first use of Our Sites. If you do not accept and agree with this Privacy Notice, you must stop using Our Sites immediately.
ENGYS Privacy Notice – 21 May 2018
1. Definitions and Interpretation
In this Privacy Notice, the following terms shall have the following meanings:
- Account means an account required to access and/or use certain areas and features of Our Sites, such as Our customer portal at clients.engys.com;
- Personal data means any and all data that relates to an identifiable person who can be directly or indirectly identified from that data. In this case, it means personal data that you give to Us via Our Sites. This definition shall, where applicable, incorporate the definitions provided in the EU Regulation 2016/679 – the General Data Protection Regulation (GDPR);
- ENGYS/We/Us/Our means (i) ENGYS Ltd., a company registered in England and Wales under 6936178, whose registered address is 1 The Green, Richmond, Surrey, TW91PL, UK and whose main trading address is Studio 20, Royal Victoria Patriotic Building, John Archer Way, London, SW18 3SX, UK, and (ii) all its subsidiary companies:
ENGYS GmbH of Am Güterbahnhof 4, 18055 Rostock, Germany. Registered at AG Rostock HRB 11516.
ENGYS S.r.l. of Via del Follatoio 12, 34148 TRIESTE (TS), Italia. P.IVA e C.F. 01187810328. Capitale sociale € 10.000 i.v. Reg. Imprese di Trieste n. 01187810328. REA n. TS – 131255.
ENGYS AUST PTY LTD 47 of Camelot Street, Tennyson, QLD 4105, Australia. Registration No. 152942893.
ENGYS LLC of 20 South Sarah Street, Saint Louis, MO 63108, USA. EIN 99-0376458.
ENGYS Ltda. of Rua Mostardeiro, 777, Sala 1401, CEP 90430-001, Porto Alegre, RS, Brasil. CNPJ 31.187.000/0001-76.
In the context of legal basis:
- Legitimate Interests means the interest of Our business in conducting and managing Our business to enable Us to give you the best products and services and the best and most secure experience. We make sure We consider and balance any potential impact on you (both positive and negative) and your rights before We process your personal data for Our Legitimate Interests. We do not use your personal data for activities where Our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how We assess Our Legitimate Interests against any potential impact on you in respect of specific activities by contacting Us using the details provided in Clause 14;
- Performance of a Contract means processing your data where it is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into such a contract;
- Comply with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that We are subject to;
In the context of third parties:
- Internal Third Parties means all the subsidiary companies of ENGYS Ltd. listed above acting as joint controllers and who provide general support, IT and system administration services and undertake leadership reporting; and
- External Third Parties means all and any of the following:
Distributors and agents acting as joint controllers based inside and outside the EEA who are authorised by contract to market and sell Our products and/or services;
IT and data administration service providers acting as processors based in the UK (for example Absowebly);
Specialised cloud-based service providers acting as processors based in the UK, EEA and US (for example Microsoft, Zoho Corporation, Freshworks, RingCentral, LogMeIn) who deliver office suite software, data storage services, customer relationship management software, email marketing software, human resources management software, accounting software, customer support software, telephone software, conference software;
Professional advisers acting as processors or joint controllers including lawyers, bankers, auditors, insurers and accountants based inside and outside the EEA who provide consultancy, banking, legal, insurance and accounting services; and/or
HM Revenue & Customs, regulators and other authorities acting as processors or joint controllers based inside and outside the EEA who may require reporting of processing activities under certain circumstances.
2. Purpose of This Privacy Notice
This Privacy Notice aims to give you information on how We collect and processes your personal data through your use of Our Sites.
Our Sites may include links to other websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave Our Sites, we encourage you to read the privacy notice of every website you visit.
Our Sites are not intended for children and we do not knowingly collect data relating to children.
3. Your Legal Rights
As a data subject, you have the right to be informed about Our collection and use of personal data under the GDPR, which this Privacy Notice has been designed to uphold. You also have the right to:
- Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data We hold about you and to check that We are lawfully processing it.
- Request correction of the personal data that We hold about you. This enables you to have any incomplete or inaccurate data We hold about you corrected, though We may need to verify the accuracy of any new data you provide to Us.
- Request erasure of your personal data. This enables you to ask Us to delete or remove personal data where there is no good reason for Us continuing to process it. You also have the right to ask Us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where We may have processed your information unlawfully or where We are required to erase your personal data to comply with local law. Note, however, that We may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
- Object to processing of your personal data where We are relying on Legitimate Interests (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where We are processing your personal data for direct marketing purposes. In some cases, We may demonstrate that We have compelling legitimate grounds to process your information which override your rights and freedoms.
- Request restriction of processing of your personal data. This enables you to ask Us to suspend the processing of your personal data in the following scenarios: (a) if you want Us to establish the data's accuracy; (b) where Our use of the data is unlawful but you do not want Us to erase it; (c) where you need Us to hold the data even if We no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our Use of your data but We need to verify whether we have overriding legitimate grounds to use it.
- Request transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for Us to use or where We used the information to perform a contract with you.
- Withdraw consent at any time where We are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, We may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
If you have any cause for complaint about Our use of your personal data, please contact Us using the details provided in Clause 14 and We will do our best to solve the problem for you. If We are unable to help, you also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) in the UK or the equivalent body in other EEA states.
4. What Data Do We Collect?
Depending upon your use of Our Sites, We may collect, use, store and transfer different kinds of personal data about you which We have grouped together as follows:
- Identity Data includes first name, last name, username or similar identifier, title, date of birth, career information, and gender.
- Contact Data includes home or business address, business name, email address and telephone numbers.
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access Our Sites.
- Profile Data includes your Account username and password.
- Usage Data includes information about how you use Our Sites, access Our marketing emails, products and services.
- Marketing and Communications Data includes your preferences in receiving marketing from Us and Our third parties and your communication preferences.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in the law as this data does not directly or indirectly reveal your identity. For example, We may aggregate your Usage Data to calculate the percentage of users accessing a specific feature in Our Sites. However, if We combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, We treat the combined data as personal data which will then be used in accordance with this Privacy Notice.
We do not collect any Special Categories of Personal Data about you (this includes: details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do We collect any information about criminal convictions and offences.
Where We need to collect personal data by law or under the terms of a contract We have with you, and you fail to provide that data when requested, We may not be able to perform the contract We have or are trying to enter into with you (for example, to provide you with products or services). In this case, We may have to cancel a product or service you have with Us but We will notify you if this is the case at the time.
5. How is Your Data Collected?
We use different methods in Our Sites to collect data from and about you, including through:
We collect your Identity, Contact, Profile and/or Marketing and Communications Data when you fill Our web forms or when you correspond with Us by email, post, phone or otherwise using any of the Contact Us details found in Our Sites. This includes personal data processed when:
- you request information about any of Our products or services;
- you apply for a job with Us;
- We create an Account for you;
- you request marketing to be sent to you; or
- you register to attend any of Our events.
Automated technologies or interactions
We also collect Technical Data and Usage Data about you whenever you receive and open one of Our marketing emails. We collect this data automatically using analytics services provided by Zoho Corporation in the US.
Third parties or publicly available sources
We may also receive additional Identity, Contact, Technical and Usage Data about you from various third parties and public sources beyond Our Sites as listed below:
- Social media channels and public directories, such as Twitter, LinkedIn, Google+ and XING; and/or
- Publicly availably sources such as Companies House based inside the EEA.
6. How Do We Use Your Data?
Our use of your personal data will always have a lawful basis, either (i) because it is necessary for Our Performance of a Contract with you, (ii) because it is in Our Legitimate Interests, or (iii) because We need to comply with a legal or regulatory obligation.
Generally, We do not rely on consent as a legal basis for processing your personal data other than in relation to sending direct marketing communications to you by email.
More specifically, We may use the data We collect from you through Our Sites for the following purposes:
- To register you as a contact, We will use your Identity and Contact Data for Legitimate Interests (to be able to reply to your emails and/or contact requests about Our products and/or services);
- To register you as a job candidate, We will use your Identity and Contact Data for Legitimate Interests (to carry out Our recruitment process);
- To register you as a customer, to supply Our services and/or products to you and to provide and manage your Account, We will use your Identity, Contact and Profile Data to fulfil the Performance of a Contract with you;
- To administer and protect Our business and Our Sites (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data), We will use your Identity, Contact, Profile, Technical and Usage Data to comply with a legal or regulatory obligation and for Legitimate Interests (to run our business, to provide administration and IT services, network security, and to prevent fraud and illegal use of Our intellectual property);
- To perform market research and to deliver relevant content in Our Sites, We will use your Identity, Contact, Technical and Usage Data for Legitimate Interests (to develop Our products and services, to grow Our business and to define our marketing strategy); and
- To analyse your use of Our Sites and to enable Us to continually improve Our Sites and your user experience, We will use your Technical and Usage Data for Legitimate Interests (to develop Our products and services and to grow Our business).
We may also use your Identity, Contact, Technical, Usage and Marketing and Communications Data for marketing purposes, which may include contacting you by email with information, news, events and offers on Our products and/or services.
You will receive marketing emails from Us if (i) you have requested information from Us, (ii) you have purchased products and/or services from Us, (iii) you have subscribed to receive Our newsletters or (iv) you have registered to attend any of Our events and, in each case, you have not opted out from receiving Our communications. We will never send you any unsolicited marketing or spam and will take all reasonable steps to ensure that We fully protect your rights and comply with Our obligations under the GDPR and the Privacy and Electronic Communications (EC Directive) Regulations 2003.
You can opt out at any time from receiving Our marketing communications by using the Unsubscribe link provided with all Our marketing emails. Where you opt out of receiving Our marketing messages, this will not apply to personal data provided to Us as a result of a product/service purchase, product/service experience or other similar transactions
We will only use your personal data for the purposes for which We collected it, unless We reasonably consider that We need to use it for another reason and that reason is compatible with the original purpose. If We need to use your personal data for an unrelated purpose, We will notify you and We will explain the legal basis which allows us to do so.
Please note that We may process your personal data without your knowledge or consent, in compliance with the rules set out in this Privacy Notice, where this is required or permitted by law.
7. How and Where Do We Store Your Data?
Some or all of the data We collect from you may be stored outside of the European Economic Area (the EEA) (The EEA consists of all EU member states, plus Norway, Iceland, and Liechtenstein). You are deemed to accept and agree to this by using Our Sites and submitting information to Us. If We do store data outside the EEA, We will take all reasonable steps to ensure that your data is treated as safely and securely as it would be within the EEA and under the GDPR, including at least one of the following safeguards:
- We will ascertain whether your data will be stored in countries that have been deemed to provide an adequate level of protection for personal data on the basis on the GDPR. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries;
- We will only use data processors based in the US if the providers are compliant with the EU-US Privacy Shield framework, which requires them to afford similar protection to personal data shared between the EU and the US. For further details, see European Commission: EU-US Privacy Shield; and/or
- We will use specific contracts with Internal Third Parties and External Third Parties where needed which include Model Clauses approved by the European Commission which give personal data the same protection it has in the EU. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.
8. Do We Share Your Data?
We may have to share your personal data with the parties listed below for the purposes set out above in Clause 6:
- Internal Third Parties, as defined in Clause 1.
- External Third Parties, as defined in Clause 1.
- Third parties to whom We may choose to sell, transfer, or merge parts of Our business or Our assets. Alternatively, We may seek to create new subsidiaries, acquire other businesses or merge with them. If a change happens to Our business, then We or the new owners will use your personal data in the same way as set out in this Privacy Notice.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow External Third Parties to use your personal data for their own purposes, and only permit them to process your personal data for specified purposes and in accordance with Our instructions.
Many of Our Internal Third Parties and External Third Parties are located outside the EEA. Where We transfer any personal data outside the EEA, We will take all reasonable steps to ensure that your data is treated as safely and securely as it would be within the EEA and under the GDPR by implementing the same safeguards set out above in Clause 7.
Please contact Us using the details provided in Clause 14 if you need further information on the specific mechanisms We use to transfer your personal data out of the EEA.
9. Data Security
Data security is very important to Us, and to protect your data We have taken suitable measures to safeguard and secure data collected through Our Sites.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, We limit access to your personal data to those employees, Internal Third Parties and External Third Parties who have a business need to know. They will only process your personal data on Our instructions and they are all subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and We will notify you and any applicable regulator of a breach where We are legally required to do so.
10. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes We collected it for, including for the purposes of satisfying any legal or business requirements.
To determine the appropriate retention period for personal data, We consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which We process your personal data and whether We can achieve those purposes through other means, and the applicable legal requirements.
By law, We have to keep basic information about our customers (including Contact and Identity Data, as well as sales and financial reports) for at least 10 years after they cease being customers for tax purposes and legal purposes.
In some circumstances you can ask Us to delete your data in accordance with your legal rights, as set out in Clause 3.
In some circumstances We may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case We may use this information indefinitely without further notice to you.
11. Your Right to Withhold Information
You may access certain areas of Our Sites without providing any data at all. However, to use all features and functions available on Our Sites you may be required to submit or allow for the collection of certain data (for example, We need your Profile Data to grant you access to Our customer portal at clients.engys.com).
12. How Can You Access Your Data?
You can contact Us at any time using the details provided in Clause 14 to ask for a copy of any of your personal data held by Us (where such data is held). You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, We may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, We may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help Us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up Our response.
We try to respond to all legitimate requests within one month. Occasionally it may take Us longer than a month if your request is particularly complex or you have made a number of requests. In this case, We will notify you and keep you updated.
14. Contacting Us
We have appointed Our Director of Operations (Francisco J. Campos) as Our data privacy manager, responsible for overseeing all queries in relation to Our Sites and this Privacy Notice.
If you have any questions or complaints about Our Sites or this Privacy Notice, please contact Our data privacy manager by email at email@example.com, by telephone on +44 (0)20 3239 3041, or by post at ENGYS Ltd., Studio 20, Royal Victoria Patriotic Building, John Archer Way, London, SW18 3SX, UK. Please ensure that your query is clear, particularly if it is a request for information related to the data We hold about you (as under Clause 4, above).
15. Changes to Our Privacy Notice
The date on which this Privacy Notice was last updated appears at the head of this page. We may change this Privacy Notice from time to time (for example, if the law changes). Any changes will be immediately posted on Our Sites and you will be deemed to have accepted the terms of the Privacy Notice on your first use of Our Sites following the alterations. On this basis, We recommend that you check this page regularly to stay up to date.
In the event of any conflict between the current version of this Privacy Notice and any previous version(s), the provisions current and in effect shall prevail unless it is expressly stated otherwise.
It is important that the personal data We hold about you is accurate and current. Please keep Us informed if your personal data changes during your relationship with Us.