Privacy policy
- 1. Introduction
Doherty Associates (‘DA’) understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of all of our website users, customers and suppliers and will only collect and use personal data in ways that are described here, and in a way that is consistent with our obligations and your rights under the law.
- 2. Information about who we are
Doherty IT Solutions Ltd T/A Doherty Associates, a private limited company registered in England under company number 2678057
Our Registered address is: The Connection, 198 High Holborn, London, WC1V 7BD
VAT number: GB578 6315 02
Data Protection Officer: Owen Morris
Email address: gdprcompliance@doherty.co.uk
- 3. What does this notice cover?
This privacy notice aims to give you information on how we collect and process your personal data through your use of this website, including any data you may provide through this website, or as a result of your dealings with us as a customer or a supplier.
This website is not intended for children and we do not knowingly collect data relating to children.
It is important that you read this privacy notice together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy notice supplements the other notices and is not intended to override them.
- 4. What is personal data?
Personal data is defined by the General Data Protection Regulation (EU Regulation 2016/679) (the “GDPR”) as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’.
Personal data is considered as any information about you that enables you to be identified. Personal data covers information such as your name and contact details, as well as identification numbers, electronic location data, and other online identifiers.
- 5. What are my rights?
Under the Data Protection Legislation, you have the following rights, which we will always work to uphold:
- a) The right to be informed about our collection and use of your personal data
- b) The right to access the personal data we hold about you
- c) The right to have your personal data rectified if any of your personal data held by us is inaccurate or incomplete
- d) The right to be forgotten, i.e. the right to ask us to delete or otherwise dispose of any of your personal data that we hold
- e) The right to restrict (i.e. prevent) the processing of your personal data
- f) The right to object to us using your personal data for a particular purpose or purposes
- g) The right to withdraw consent. This means that, if we are relying on your consent as the legal basis for using your personal data, you are free to withdraw that consent at any time
- h) The right to data portability. This means that, if you have provided personal data to us directly, we are using it with your consent or for the performance of a contract, and that data is processed using automated means, you can ask us for a copy of that personal data to re-use with another service or business in many cases
- i) Rights relating to automated decision-making and profiling. We do not use your personal data in this way
It is important that your personal data is kept accurate and up-to-date. If any of the personal data we hold about you changes, please keep us informed as long as we have that data.
Further information about your rights can also be obtained from the Information Commissioner’s Office or your local Citizens Advice Bureau.
If you have any cause for complaint about our use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office. We would welcome the opportunity to resolve your concerns ourselves, however, so please contact us first, using the details in ‘How Do I Contact You’ section.
- 6. What personal data do you collect and how?
We may collect and hold some or all of the personal data set out in the list below. We do not collect any ‘special category’ or ‘sensitive’ personal data or personal data relating to children.
- Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender
- Contact Data includes billing address, delivery address, email address and telephone numbers
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website
- Profile Data includes your username and password, feedback and survey responses
- Usage Data includes information about how you use our website, products and services
- Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences
- Recruitment data includes some of the identify and contact data, such as first and last name, home address, email address, title as well as voice recording (captured during the remote, i.e. over Microsoft Teams interview or an calls made in the recruitment process)
- 7. How do you use my personal data?
Under the Data Protection Legislation, we must always have a lawful basis for using personal data. The following table describes how we will or may use your personal data, and our lawful bases for doing so:
- To register you as a new customer;
- To process and deliver your order;
- To manage our relationship with you;
- To enable you to partake in a prize draw, competition or complete a survey;
- To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data);
- To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you;
- To use data analytics to improve our website, products/services, marketing, customer relationships and experiences;
- To make suggestions and recommendations to you about goods or services that may be of interest to you.
Generally, we do not rely on consent as a legal basis for processing your personal data other than in relation to sending third-party direct marketing communications to you via email or text message.
We do not conduct automated decision-making and profiling.
With your permission and/or where permitted by law, we may also use your personal data for marketing purposes, which may include contacting you by email with information, news, and offers on our products and services. You will not be sent any unlawful marketing or spam. We will always work to fully protect your rights and comply with our obligations under the Data Protection Legislation and the Privacy and Electronic Communications (EC Directive) Regulations 2003, and you will always have the opportunity to opt-out. We will always obtain your express opt-in consent before sharing your personal data with third parties for marketing purposes and you will be able to opt-out at any time.
We will only use your personal data for the purpose(s) for which it was originally collected unless we reasonably believe that another purpose is compatible with that or those original purpose(s) and need to use your personal data for that purpose. If we do use your personal data in this way and you wish us to explain how the new purpose is compatible with the original, please contact us using the details in ‘How do I Contact You’ section.
If we need to use your personal data for a purpose that is unrelated to, or incompatible with, the purpose(s) for which it was originally collected, we will inform you and explain the legal basis which allows us to do so.
In some circumstances, where permitted or required by law, we may process your personal data without your knowledge or consent. This will only be done within the bounds of the Data Protection Legislation and your legal rights.
- 8. How long will you keep my personal data?
We will not keep your personal data for any longer than is necessary in light of the reason(s) for which it was first collected.
- 9. International transfer
We may transfer personal data outside the EEA when product and services are provided by external third-party suppliers and/or the processing of personal data is necessary for the performance of a contract.
- Whenever we transfer your personal data outside the EEA, we ensure at least one of the following safeguards is implemented:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission – Adequacy Decisions.
- Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission – Standard Contractual Clauses.
- Please contact us if you want further information on the specific mechanism used by us when transferring your personal data outside the EEA.
- 10. Do you share my personal data?
We will not share any of your Personal Data with any third parties for any purposes, subject to the following exceptions.
If we sell, transfer, or merge parts of our business or assets, your personal data may be transferred to a third party. Any new owner of the business may continue to use your personal data in the same way(s) that we have used it, as specified in this Privacy Notice.
In some limited circumstances, we may be legally required to share certain personal data, which might include yours, if we are involved in legal proceedings or complying with legal obligations, a court order, or the instructions of a government authority.
The performance of a contract between you, the company you work for and DA.
- 11. How Can I Control My Personal Data?
If you want to know what personal data we have about you, you can ask us for details of that personal data and for a copy of it (where any such personal data is held). This is known as a “subject access request”.
All subject access requests should be made in writing and sent to the email or postal addresses shown in ‘How Do I Contact You’ section.
There is not normally any charge for a subject access request. If your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests) a fee may be charged to cover our administrative costs in responding.
We will respond to your subject access request within 28 days, in any case, not more than one month of receiving it. Normally, we aim to provide a complete response, including a copy of your personal data within that time. In some cases, however, particularly if your request is more complex, more time may be required up to a maximum of three months from the date we receive your request. You will be kept fully informed of our progress.
- 12. How Can I Access My Personal Data?
You can ask us for details of the personal data we have about you and a copy of it (where any such personal data is held). This is known as a “subject access request”.
All subject access requests should be made in writing and sent to the email or postal addresses shown in ‘How Do I Contact You’ section.
There is not normally any charge for a subject access request. If your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests) a fee may be charged to cover our administrative costs in responding.
We will respond to your subject access request within one month of receiving it. Normally, we aim to provide a complete response, including a copy of your personal data within that time. In some cases, however, particularly if your request is more complex, more time may be required up to a maximum of three months from the date we receive your request. You will be kept fully informed of our progress.
- 13. How Do I Contact You?
To contact us about anything to do with your personal data and data protection, including making a subject access request, please email: gdprcompliance@doherty.co.uk
- 14. Changes to this Privacy Policy
We may change this Privacy Notice from time to time. This may be necessary, for example, if the law changes, or if we change our business in a way that affects personal data protection.
Any changes will be immediately posted on Our Site and you will be deemed to have accepted the terms of this Notice on your first use of Our Site following the alterations. We recommend that you check this page regularly to keep up-to-date.
- 15. Applicant Tracking System (ATS)
Doherty Associates respect and value the privacy of everyone who applies for our careers page, either directly via the https://www.doherty.co.uk/careers/ page (“Our Site”) or Job Portals.
This part of the Notice explains how your personal data is used at Doherty Associates with respect to your registering an application for a job vacancy.
Principles
We will only collect and use personal data in ways that are described here and in a manner that is consistent with Doherty Associates obligations, and your rights under the law.
Definitions and Interpretation
‘Job Portals’ means other job advertising websites (i.e. LinkedIn, Indeed, Job Street) that Doherty Associates uses to post open vacancies, from which you will always be requested to follow a link to Doherty Associates ATS system, to complete your application. These portals have their own privacy policies. Please check these policies before you decide to submit any Personal Data.
‘ATS’ means Application Tracking System, which is a third-party cloud-based solution, provided by PeopleHR as a sub-processor of Doherty Associates. We this platform to manage all applications for vacancies, and by accepting this Privacy Notice you are agreeing to your data being stored on PeopleHR.
PeopleHR delivers stringent privacy and security protections that are built into the platform. Please check these policies before you decide to submit any Personal Data.‘Personal Data’ means any and all data that relates to an identifiable person who can be directly or indirectly identified from that data. In this case, it means personal data that you give to Doherty Associates via Our Site. This definition shall, where applicable, incorporate the definitions provided in the Data Protection Act 1998 and/or EU Regulation 2016/679 – the General Data Protection Regulation (GDPR) from 25 May 2018.
What Does This Policy Cover?
This Privacy Notice applies only to your use of Our Site. Our Site may contain links to other pages on Doherty Associates website and/or Doherty Associates ATS.
What information do we hold about you?
When you apply for a vacancy with Doherty Associates, to support your application, we will ask for specific information:
- Personal contact details such as name, title, address, telephone numbers and personal email
- Employment records
- Salary remuneration, bonus and benefits history
- Work history, including job titles
- Confirmation of you holding valid rights to work in the UK
- Reference and other information in a CV and/or cover letter or as part of the application process
We may also collect, store and use the following “special categories” of more sensitive personal information, especially if the job you are applying for requires additional security checks:
- Information about criminal convictions and offences
- Information about your race or ethnicity, religious beliefs, sexual orientation and political opinions
- Information about your health, including any medical condition, health and sickness records
How we store information about you
- All information you provide to Doherty Associates is stored on Doherty Associates servers and the ATS system
- By submitting Personal Data, you agree to storing or processing your data by Doherty Associates. We will take all reasonable organisational and technical steps necessary to ensure that the information you supply to Doherty Associates is treated securely and in accordance with this privacy policy
How long we retain your information
We retain your information in line with our data retention policy:
- Unsuccessful applicants – 12 months from the date of application
- Successful applicants – data will be transferred to your staff file
How we use your information
We will only use your personal information when the law allows Doherty Associates to. Most commonly, we will use your Personal Data in the following circumstances:
- Where we need to process your application (this may include sharing your data with a third party in order to complete a specific recruitment stage)
- Undertake pre-employment checks
- To maintain the Doherty Associates recruitment talent pool
- Use and manage the employee data during employment with Doherty Associates (should you be hired by Doherty Associates, at that point our Staff Privacy Policy will apply)
- Where we need to comply with a legal obligation
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests
We may also use your Personal Data in the following situations:
- where we need to protect your interests (or someone else’s interests)
- where it is needed in the public interest or for official purposes
When processing your Personal Data we will aim to do so fairly, lawfully, and in line with the prevailing data protection legislation.
Your rights
As a Data Subject under the Data Protection Legislation, you have the following rights:
- If you submit an enquiry form on Doherty Associates careers page, you give your consent to us contacting you for recruitment purposes. You can exercise your right to prevent Doherty Associates from further contacting you at any time by emailing Doherty Associates at human.resources@doherty.co.uk
- You have the right to ask Doherty Associates to give you a copy of the information we hold on you. This is known as a data subject access request. For further details please contact Doherty Associates at human.resources@doherty.co.uk
- You have the right to ask Doherty Associates to rectify the data we hold in the event that it contains inaccuracies or is incomplete. To discuss this please contact us at human.resources@doherty.co.uk
- You have the right to ask us to erase the Personal Data we hold if:
- it is no longer necessary for Doherty Associates to hold the data
- you wish to withdraw your consent to Doherty Associates holding the data
- you object to Doherty Associates holding or processing the data
- you believe that we have processed the data unlawfully
- the data needs to be erased for Doherty Associates to comply with a particular legal obligation
To make a request please contact Doherty Associates at human.resources@doherty.co.uk
If you have any queries about this notice, please email human.resources@doherty.co.uk