As of the 25th of May 2018, Arc 3 is required under the GPDR (General Data Protection Regulation) to notify all current and potential clients of the lawful and legitimate basis for collecting and processing specific personal information. Further guidance regarding the GPDR is available at:
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/
This privacy statement applies to Arc 3’s use and dispensation of Personal Information collected and used by staff at Arc 3. For information concerning the collection, use or processing of Personal Information by any other entities within and/or associated with Arc 3, please contact our Office directly.
The phrases “Arc 3”, “us” or “we” shall, when used herein mean staff of Arc 3 on behalf of and in respect of whom this Statement is made.
By using Arc 3’s Services and providing your Personal Information to Arc 3, you agree to the collection, use and sharing of your information in accordance with this Privacy Statement. Please read this Privacy Statement carefully and contact us directly if you have any further queries.
The phrasing: “Personal Information” is information, or any combination of separate pieces of information, that could be used to identify you.
COLLECTABLE INFORMATION
Arc 3 directly collect information from Clients or Potential Clients when they chose to enquire with regards to our services either by phone, email or via the contact form on our website. The following are examples of information we may directly collect:
1. Name
2. Social Media Details
3. Email Address
4. Home Address
5. Work/Business Address
6. Project Address
7. Telephone and/or fax numbers
8. Date of birth
9. Payment information (such as a credit card) and bank account details
10. Future communication preferences
11. Other Project-Related Information
Through agreeing to the terms of our appointment, we may collect more information about clients from other sources, including publicly available sources such as the Land Registry, Planning Portal, Councils, the Environment Agency, referral agents etc. Examples of information we may collect from other sources are:
A. Name
B. Property Planning History
C. Property Flood Risk
D. Property Status
E. Property Ownership Status
F. Any other project related or ancillary information
This is not an exhaustive list but is a summary of the main information required by Arc 3 during the progression of a project and it should be noted that Arc 3 will confer with a client should the situation arise where any particularly sensitive information of theirs has to be processed.
HOW ARC 3 USES THIS INFORMATION
As Architects and Chartered Surveyors, we use the information we collect to provide you with services regarding your project only, tailored to your own interest as stated in our appointment. The following are how we may use the information that we collect:
I. Answer your questions and respond to your requests.
II. Compile Verbal Appraisal Packs prior to our Appointment.
III. Create and manage your project file within our office server system.
IV. Process payment for our Services
V. Analyse the use of, and develop, our services and marketing. Enforce our Terms and Conditions and otherwise manage our business.
VI. Provide your details to Project Consultants, Specialists, Suppliers, Installers, Local Planning and Other Statutory Authorities, Appointed Service Providers (such as Gas, Water, Electricity, internet, Television etc.)
VII. Provide your information to the council, Inland Revenue, Auditors, Banks, Financial Institutions and other similar organisations.
All information collected from clients is maintained, securely stored and archived by Arc 3. Data is held for 25 years and will be thoroughly erased from the practice database thereafter.
CONSENT AND INDIVIDUAL RIGHTS
Upon inquiring with Arc 3, Clients have a right to be informed about how the company is using their data, and companies that use any EU citizen’s data must provide an easily accessible privacy policy, written in plain language. Under this right, individuals have the right to contact Arc 3 and ask;
a) Whether their data is being processed or stored
b) Ask what data the company holds about them
c) Why Arc 3 has this data
d) How long Arc 3 intend to hold it
e) What Arc 3 intend to do with the data
Under right of access, all current and potential clients can receive a digital copy of all data that Arc 3 holds about them. This will be provided in digital format, free of charge within one month of receipt of the request. However, if the request is “manifestly unfounded or excessive”, Arc 3 are permitted by the ICO GDPR to charge a reasonable fee. Arc 3 must verify the identity of the person making the request using “reasonable means”.
INDIVIDUAL RIGHT TO RECTIFICATION
If a client or potential client finds that Arc 3 holds incorrect or incomplete data about them, they have a right to contact us directly and have it corrected. This must be responded to by Arc 3 within 1 month, 2 months if the request is particularly complex. In the event that Arc 3 has previously disclosed incorrect information to third parties, under the GDPR Arc 3 must inform any third parties of the change request as well as informing the client’s about the disclosure.
INDIVIDUAL RIGHT TO DATA ERASURE
All clients or potential clients have the right to request complete deletion and removal of their personal data where Arc 3 does not have a compelling reason to continue storing or processing that data. If Arc 3 has disclosed this information to a third party, the third party must also be informed of the erasure request unless it “involves disproportionate effort” (ICO Guide to GDPR Statement) to do so.
INDIVIDUAL RIGHT TO RESTRICT PROCESSING
Under particular circumstances, EU citizens have a right to restrict any processing of their data by Arc 3. When a restriction request has been made, Arc 3 is permitted to store data but not further process it.
INDIVIDUAL RIGHT TO DATA PORTABILITY
Clients or Potential Clients have the right to ask that their data be passed between two organisations on request – for example should they want to change appointment from Arc 3 to another company. The data provided must be in a readily available, machine readable format. These requests should be responded to without delay within one month, though this can be extended to two months if the request is particularly complex.
INDIVIDUAL RIGHT TO OBJECT
Under GDPR, all individuals have the right to object to any direct marketing, analytical processing relating to historical/scientific interests, or processing relating to any “legitimate interests”. Arc 3 explicitly only send direct marketing regarding the firm to those who have agreed to receive it and must immediately stop sending direct marketing materials to anyone who objects. There are no grounds for refusal should any recipients request a marketing objection request.
INDIVIDUAL RIGHTS RELATING TO BREACH NOTIFICATIONS AND ACCOUNTABILITY
As of 25th of May 2018, Arc 3 must remain transparent about their compliance with the GDPR and endeavour to uphold good governance of data security. This includes regular security audits, staff training and on-going reviews of data handling policies. In the event of a data breach that could lead to the loss, alteration, destruction, access to or unauthorised disclosure of personal data, a supervisory body must be informed where the risk is “likely to result in a risk to the rights and freedoms of individuals”. If a breach is sever enough to pose a “HIGH risk to the rights and freedoms of individuals” the individuals must be notified directly.
Based in London and covering Wandsworth, Clapham, West Wickham, and Kent