GENERAL DATA PROTECTION REGULATION (GDPR) STATEMENT

We provide this information so that you are informed about the data held by Gillett Limited and how we treat it.

Within this statement:

  • 'contact data' means business contact details provided to us or obtained from the sources described below so that we can communicate with organisations and their representatives.
  • 'service data' means information an organisation provides or enters into our services, or supplies to us for configuration or support. It may contain personal information about end users or other individuals.
  • 'data' means the contact and service data described in this statement.
  • 'organisation' means an organisation using or enquiring about our services.
  • 'you' means the person reading this statement, including an organisation's representative, as applicable.
  • 'clients' means organisations that purchase services from us.
  • 'we' and 'us' means Gillett Limited (company number 11259154), Aizlewood’s Mill, Nursery Street, Sheffield S3 8GG, UK.
  • 'end user' means a person authorised by an organisation to use our services.

We act as a data controller for personal information we use for our own business purposes, such as managing business contacts and billing. We act as a data processor when handling personal information on an organisation’s behalf to configure, provide or support its service under the applicable service agreement and Data Processing Addendum.

End users and representatives should read this statement alongside the organisation’s own privacy information and the relevant product privacy statement.

INTRODUCTION

We respect data privacy and are committed to protecting personal information in accordance with UK data protection law, including the UK GDPR and the Data Protection Act 2018, as amended.

Our team is made aware of the importance of data protection, privacy and the appropriate handling of personal information.

The latest revision of this statement is available on our website. This statement may change from time to time. Please check it periodically for updates.

PRIVACY INFORMATION

We collect and store business contact information to provide our software, services and support, manage sales enquiries and customer relationships, and administer related business records. Customers enter and manage their own service data within our products. We host and process that data on their behalf to operate and support the service under the applicable service agreement and Data Processing Addendum. We do not use customer service data for our own sales or marketing.

We use business contact details for sales enquiries, follow-up communications and relevant information about our products and services. You can ask us to stop using your details for direct marketing at any time by contacting privacy@gillett.co.uk.

We never sell any data that we hold.

Our public websites at www.gillett.co.uk and www.isostock.com use cookies and third-party resources as described below. We do not currently analyse Google Analytics reports for business purposes.

We are the developers and service provider of software systems. We may store data on infrastructure we manage and on selected cloud services used to administer our business.

We use service providers for cloud hosting, business communications and administration, accounting and customer relationship management. Where they process personal information on our behalf, our arrangements include confidentiality, security and data protection requirements. We may also disclose information to public authorities where required by law. Product-specific hosting and sub-processor arrangements are described in the relevant privacy statement and Data Processing Addendum.

Our hosted customer services use Microsoft Azure in the UK. We use Microsoft cloud services for much of our business administration and also use selected third-party services. Our approach is to use UK or European processing locations where practicable and minimise personal information transferred elsewhere. Where a restricted international transfer is required, we use applicable safeguards under UK data protection law, including appropriate standard contractual clauses where relevant. You can contact privacy@gillett.co.uk for information about the safeguards applicable to your data.

DATA PROTECTION BY DESIGN

We consider suppliers' security certifications and commitments to privacy when selecting services that handle personal information.

We apply confidentiality requirements to suppliers, contractors and employees who handle personal information. Access is restricted according to responsibilities and business need.

We use user accounts, passwords and multi-factor authentication to protect staff access to our business systems. Our password policy requires complex passwords and the use of password managers.

INFORMATION HELD BY US

We hold contact data to enable us to provide our services, manage sales enquiries and carry out the day-to-day running of our business.

In the usual course of communicating and conducting business with an organisation, we receive and send information including emails, text messages, telephone communications, files, screenshots and other electronic messages.

Contact data that we store includes:

  • Names, email addresses and telephone numbers for business contacts, including people involved in administration, IT, procurement and accounts.
  • Records of enquiries, correspondence and business-level service or support requests.

Service data that we store includes:

  • Files containing setup or configuration data used to configure our services.
  • Service and support records that may contain end-user details or other customer-controlled personal information.

Other information that we store includes organisation names, invoices, purchase orders and remittance advice.

The relevant product privacy statement describes information held within each service.

HOW THE DATA IS COLLECTED

Following an initial email or telephone conversation, we may ask for contact data so that we can continue to communicate with you.

We may also obtain business contact details through our website, from conference or event organisers who share delegate information, and by searching publicly available sources. We use this information for relevant sales communications in accordance with the applicable lawful basis and marketing rules.

During procurement, we may collect further contact data for people involved in the project. We may retain correspondence to provide information and quotations and manage the business relationship.

At the point of purchase, during a trial or when changes are requested, an organisation may provide service data containing end-user details. We use this information to configure and support the service, including creating accounts where required. Any retained configuration or support copies are subject to the organisation's instructions and the applicable retention arrangements.

We take reasonable steps to keep the contact data we hold accurate and up to date.

The organisation is responsible for the accuracy of service data it provides or enters. We assist with correcting inaccuracies when notified, in accordance with its instructions.

LAWFUL BASIS AND CONSENT

The organisation is responsible for identifying the lawful basis for personal information it enters into our products and, where relevant, an additional condition for special category personal information. We process this service data on the organisation’s behalf to provide and support the service under the applicable service agreement and Data Processing Addendum. Entering information into the service does not, by itself, establish consent from the individuals concerned.

For personal information we control, we rely on our legitimate interests in responding to business enquiries, developing and administering business relationships, providing services and business-level support, and providing relevant information about our products and services. We do so where permitted by law and where those interests are not overridden by your rights and interests. We process information required for statutory accounting and tax records to comply with our legal obligations.

Where consent is required or is the basis we rely on, we use your information for the purposes covered by that consent. You can withdraw consent or object to direct marketing at any time by contacting us via email or webform. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Submitting an enquiry enables us to respond to that enquiry. It does not automatically mean that you have consented to unrelated ongoing marketing. Where we rely on consent obtained through a website form or an event organiser, that consent must cover the intended use of your information by Gillett Limited. Public availability of contact details does not itself constitute consent to marketing.

We may access service data to configure, provide, maintain or support the service under the applicable service agreement and Data Processing Addendum, or where required by law. The relevant product privacy statement and Data Processing Addendum explain these arrangements.

Any queries about consent or privacy should be sent to privacy@gillett.co.uk. We handle requests about personal information we control directly. Where we act as processor, we refer requests to the relevant organisation and assist it in meeting its data protection obligations.

CHILDREN

Our services are supplied to organisations and are not directed at children. Depending on the service and the organisation’s use of it, information entered by the organisation may relate to children, for example next-of-kin information or patient identifiers. We process this information on the organisation’s behalf under the applicable Data Processing Addendum.

DATA BREACH

On becoming aware of a personal data breach, we will investigate and take appropriate steps to contain it and minimise its effects. Where the breach affects information we process on an organisation’s behalf, we will notify that organisation without undue delay and provide available information and assistance, with updates as our investigation progresses.

Where Gillett Limited is the controller, we assess and meet our own obligations to notify the Information Commissioner’s Office and affected individuals. Where we act as processor, the organisation assesses its notification obligations as controller, with our assistance.

RETENTION OF DATA

We retain personal information for the period needed for its stated purpose, taking account of applicable legal obligations. Different arrangements apply to general business records, accounting records and information processed on customers' behalf.

General customer files are moved to our Previous Customer records when the customer ceases to be a customer and are retained for three years from that move. Enquiry files follow a similar approach and are retained for three years after the enquiry becomes inactive or is closed. Separate arrangements apply to accounting records, hosted service data, support copies and backups.

We retain accounting records for at least six years from the end of the financial year to which they relate, and longer where required by law. Personal information may be retained beyond this period where necessary for a specific, documented purpose, such as resolving a dispute or establishing, exercising or defending legal claims. We review continued retention annually and delete or anonymise personal information when it is no longer needed.

Information processed on an organisation's behalf is retained, returned or deleted in accordance with its instructions, the applicable Data Processing Addendum and any legal requirement to retain it.

When a customer stops using a hosted service, we contact the organisation to confirm its instructions for deleting its service data. Pending deletion cases are reviewed as part of our monthly ISMS review. Deletion is managed through our Azure environment, and backup copies are subject to the applicable backup-retention arrangements. These arrangements remain subject to the organisation's documented instructions and our contractual obligations.

YOUR DATA PROTECTION RIGHTS

Under data protection law, you have rights concerning your personal information. The rights available depend on the reason for processing and the applicable legal conditions and exemptions.

  • You have the right to ask for copies of your personal information, subject to applicable exemptions.
  • You have the right to ask for inaccurate information to be corrected and incomplete information to be completed.
  • You have the right to ask for your personal information to be erased in certain circumstances.
  • You have the right to ask for processing to be restricted in certain circumstances.
  • You have the right to object to processing based on legitimate interests. You can object at any time to the use of your personal information for direct marketing.
  • You have the right to receive the personal information you provided in a portable format and, where applicable, have it transferred to another organisation, where processing is automated and based on consent or a contract with you.
  • Where processing is based on consent, you can withdraw that consent.

Requests are normally free of charge. We respond without undue delay and normally within one month, subject to the exceptions and permitted adjustments under data protection law. If an extension is needed, we will explain the reason and applicable timescale.

To exercise your rights concerning personal information we control, contact privacy@gillett.co.uk. For information we process on behalf of your organisation, you should normally contact that organisation; we will assist it and refer any such request we receive to it.

If you have a complaint about how we handle your personal information, please contact info@gillett.co.uk, use our website contact form or write to Gillett Limited at Aizlewood’s Mill, Nursery Street, Sheffield S3 8GG, UK. We also accept data protection complaints raised through other communication channels. We will acknowledge your complaint within 30 days, make appropriate enquiries, keep you informed and explain the outcome without undue delay.

You also have the right to complain to the Information Commissioner’s Office (ICO) about the handling of your personal information. Information on raising a complaint is available at ico.org.uk/make-a-complaint. The ICO normally expects you to raise your concern with the organisation first.

WEBSITE COOKIES AND THIRD-PARTY RESOURCES

This section covers our public websites at www.gillett.co.uk and www.isostock.com. The iRota and IsoStock (Cloud) SaaS applications have separate cookie arrangements.

Cookies are small text files stored on your computer, phone or other device when you visit a website. Cookies and similar technologies can support website operation, remember preferences and collect information about website use.

We use CookieYes to record your cookie choices. Its cookieyes-consent cookie records whether you accepted, rejected or customised your preferences and is configured to retain that choice for 365 days. WordPress and compatible plugins may also use cookies beginning wp_consent_ to share your consent choices between website components. These consent-management cookies support the operation of the cookie controls.

Google Analytics tags are present on www.gillett.co.uk and collect website-usage information. This can include pages visited, traffic sources and session activity. Analytics cookies may include _ga, cookies beginning _ga_, _gid and _gat, depending on the configuration. We do not currently analyse the resulting reports for business purposes. Information collected through Google Analytics may be processed by Google under its applicable privacy terms.

Some pages may include an embedded X (formerly Twitter) timeline. Loading this content can allow X to collect device and usage information and may involve cookies such as guest_id, guest_id_ads, guest_id_marketing and personalization_id, depending on the configuration. Collection may occur when the content loads, even if you do not interact with it.

Our websites use Google Fonts to display text. Downloading fonts from Google can transmit technical information such as your IP address, browser details and the requested resource to Google, even without setting a conventional cookie.

WordPress and Elementor operate and display the websites. Additional cookies may be used in logged-in, form or restricted areas, depending on the feature used.

You can use the website's cookie settings icon to accept or reject optional categories or change your preferences. You can also view, block or delete cookies through your browser settings. Blocking essential cookies may affect website functionality.

For questions about these technologies or your personal information, contact privacy@gillett.co.uk.

SERVICE SPECIFIC PRIVACY POLICIES

For information about data held in our services, please see the relevant product documents: