Copywriting Training Ltd – GDPR and Privacy
Whose personal information do we collect and hold?
We only collect and hold personal information about actual and potential students. Potential students are people we have had contact with – we do not purchase, collect or maintain lists of prospects. This information comes from the individual.
What personal information do we hold?
We hold some or all of the following:
- name, position in company, address, email, phone numbers
- in some situations we hold non-business contact details where these have been given to us by the individual
Who do we share personal information with?
We do not share any personal information. It is only available to direct employees, contracted outsourcers, and those involved in the governance of the company.
How is personal information stored and protected?
- All personal information is stored in electronic form on our internal network. Only direct employees have accounts which give access to this information, through password protected computers.
- Wireless access to the network is also password protected.
- Data is not stored on individual PCs or laptops.
- PCs and laptops are secured through internet security subscription services
- Passwords are stored encrypted using password managers, or in password-protected applications.
- In addition to internal backups, encrypted backups are stored offsite using a cloud services provider.
- Accounting data, which includes some personal information, is stored and processed through Kashflow, a UK-based company. Apart from direct employees, only our bookkeeper and accountant have access to the accounting information.
- We sometime ask student to complete a survey using Survey Monkey – names and other personal identifiers are not collected.
How is personal information used and processed?
The “Lawful basis for processing personal data” as defined in the Regulation is “legitimate interest”. This means information is only used to provide services, information, and support to students.
How long is personal information retained?
Information relating to present and past students is retained indefinitely to preserve Copywriting Training Ltd’s accounting records, and to enable the company to service students’ requirements, and provide historical information on request.
Subject Access Requests and Right to Erasure
All ‘Subject Access Requests’ are dealt with personally by one of the Directors of the company. Information will be supplied by email within the stipulated one month.
On request, personal information will be removed, except in the following circumstances:
- Where it would prevent Copywriting Training Ltd conducting normal business with a student, and the following test fails:
Individuals have the right to have their personal data erased if: “the personal data is no longer necessary for the purpose which you originally collected or processed it for”.
- Where it forms part of the Copywriting Training Ltd accounts:
The right to erasure does not apply if processing is necessary for one of the following reasons:
“to comply with a legal obligation”.
- Where it forms part of a data backup which cannot be edited without corrupting the whole backup. It is part of Copywriting Training Ltd’s “legitimate interest” to maintain usable backups to protect the company and its clients in a disaster recovery situation.
Accuracy of data
Copywriting Training Ltd will endeavour to correctly enter and transcribe personal information.
It is the individual’s responsibility to advise Copywriting Training Ltd of any and all changes.
Copywriting Training Ltd is too small an organisation to employ a dedicated Data Protection Officer. Instead, these duties will be added to those of the Director responsible for all technical aspects of the company’s operations.