Introduction
Alcumus is committed to protecting your privacy. This privacy notice (Privacy Notice) explains how companies in Alcumus Group Limited’s group of companies (together, Alcumus or we or our or us) use any personal information that we may collect about you when you interact with us. It also explains how we will store, manage and keep that data safe.
We know that there is a lot of information here, but we want you to be fully informed about your rights and how we use your data.
Should we ask you to provide certain information by which you can be identified when using any of Alcumus’ websites, software applications or portals (the Services), then you can be assured that it will only be used in accordance with this Privacy Notice. We may change this Privacy Notice by updating this page. We will notify you of any significant changes, but you are welcome to come back and check it whenever you wish.
Who is Alcumus?
Alcumus includes each of the following companies:
- Alcumus ContractorCheck Inc. (a company registered in Canada)
- Alcumus Group Limited (a company registered in England and Wales)
- Alcumus Holdings Limited (a company registered in England and Wales)
- Alcumus ISOQAR Limited (a company registered in England and Wales)
- Alcumus SafeContractor Limited (a company registered in England and Wales)
- Alcumus SafeWorkforce Limited (a company registered in England and Wales)
- Cognibox Inc. (a company registered in Canada)
- Service D’Intervention sur Mesure Inc. (a company registered in Canada).
Topics:
- When do we collect your information and what information do we collect?
- Use of your information.
- Sharing your information.
- How long we keep your information.
- Recording calls.
- Your Rights.
- Cookies.
- Which countries we transfer your personal data to.
- How to contact us.
1. When do we collect your information and what information do we collect?
We collect your information:
- When you use any of our Services.
- When you make an online purchase.
- When you create an account with us.
- When you engage with us on social media or live chat.
- When you contact us with queries or complaints, or to report a problem with our website.
- When you ask one of our partners to email you information about a product or service.
- When you enter prize draws or competitions or complete any surveys we send you.
- When you comment on or review our products and services.
- When you fill in any forms.
- When you permit a third party to share with us the information they hold about you.
- We collect data from publicly available sources where the information is made public as a matter of law.
- When you apply for a job with us.
We will collect and process the following information about you:
- Information you give us. This may include your name, gender, address, e-mail address and phone number, financial and credit card information, personal description and photograph, and any further details agreed in your contract with Alcumus.
- Information we collect about you. With each of your visits to our websites we will automatically collect the following information:
- technical information, including the internet protocol (IP) address used to connect your computer to the internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system, and platform;
- information about your visit, including the full Uniform Resource Locators (URL), to, through and from our website (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, and any phone number used to call our customer services, sales and/or renewals teams.
- Information we receive from other sources. This is information we receive about you if you use any of the other websites we operate or the other services we provide. In this case we will have informed you when we collected that data if we intend to share that data internally and combine it with data collected on this website. We will also have told you for what purpose we will share and combine your data. We are working closely with third parties (including, for example, business partners, sub-contractors in technical, payment services, advertising networks, analytics providers, credit reference agencies).
2. Use of your information
We use information held about you in the following ways:
Information you give to us. We will use this information:
- to carry out our obligations arising from any contracts entered into between us or Alcumus and your employer or customer and to provide you with the information and services that you request from us (this includes account management and obtaining customer feedback);
- to provide you with information about other services we offer that are similar to those that you have already purchased or enquired about;
- to provide you with information about services we feel may interest you (including services provided by the wider Alcumus group, and our affinity partners and providers of member benefits). If you are an existing customer, we will only contact you by phone call, e-mail, or SMS with information about services similar to those which were the subject of a previous sale or negotiations of a sale to you;
- to notify you about changes to our services; and
- to ensure our website content is presented in the most effective manner for you and your computer.
Information we collect about you. We will use this information:
- to administer our website and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
- to improve our website to ensure that content is presented in the most effective manner for you and for your computer;
- as part of our efforts to keep our website safe and secure;
- to measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you;
- to make suggestions and recommendations to you; and
- to ensure the data we hold for you is complete, accurate and up to date.
Information we receive from other sources. We will combine this information with information you give to us and information we collect about you. We will use this information and the combined information for the purposes set out above.
Service-Specific Usage. If you wish to see how your personal information is used with your use of Alcumus services (“Services”), please refer to the Service section at the bottom of this Privacy Notice.
3. Sharing your Information
We sometimes share your personal data with trusted third parties, including:
Cookies Policy for further details;
We may disclose your personal information to third parties for their own purposes in very specific circumstances, including:
4. How long we keep your information
Whenever we collect or process your personal data, we will only keep it for as long as is necessary for the purpose for which it was collected. At the end of that retention period, your data will either be deleted completely or anonymised (e.g., by aggregating it with other data so that it can be used in a non-identifiable way for business planning).
In certain cases, the law requires us to keep personal data for a specific period which Alcumus must comply with.
5. Recording Calls
We may record calls for training and quality purposes. We will not use the information that we collect from you for any purposes other than for training and monitoring the quality of the information that we provide to you during the call.
Call recordings are stored securely and access to such recordings is limited to certain personnel only. Recorded calls will be saved for no longer than is necessary.
6. Your Rights
You have the right to request:
- Access to the personal data we hold about you, free of charge in most cases.
- The correction of your personal data when incorrect, out of date or incomplete.
- That we stop using your personal data for direct marketing (either through specific channels, or all channels).
- Review of any decision made based solely on automatic processing of your data (i.e., where no human has yet reviewed the outcome and criteria for the decision).
- That we erase your personal data, under certain conditions.
- That we restrict the processing of your personal data, under certain conditions.
- The transfer of your personal data we have collected to another organisation, or directly to you, under certain conditions.
To ask for your information to be amended, please update your online account, or contact your account manager or our Data Protection Officer.
If we choose not to action your request, we will explain to you the reasons for our refusal.
Your right to withdraw consent
Whenever you have given us your consent to use your personal data, you have the right to change your mind at any time and withdraw that consent.
Your objection to our use of your personal information (or withdrawal of any previously given consent) could mean that we are unable to perform the actions necessary to achieve the purposes set out above (see ‘Use of your information’) or that you may not be able to make use of the services and products offered by us. Please note that even after you have chosen to withdraw your consent, we may be able to continue to process your personal information to the extent required or otherwise permitted by law, in particular in connection with exercising and defending our legal rights or meeting our legal and regulatory obligations.
Where we rely on our legitimate interest
Where we are processing your personal data on the basis of our legitimate interest, you can ask us to stop for reasons connected to your individual situation. We must comply unless we believe we have a legitimate overriding reason to continue processing your personal data.
Direct marketing and Opt Out
In most cases, we do not undertake marketing, promotions or competitions via the software applications or portals. This is undertaken via other means. You can ask us to stop sending you marketing messages at any time by contacting us. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us because of a service purchase, service experience or other transactions.
You have the right to stop the use of your personal data for direct marketing activity through all channels, or selected channels. We must always comply with your request.
Checking your identity
To protect your information, we will ask you to verify your identity before proceeding with any request you make under this Privacy Notice. If you have authorised a third party to submit a request on your behalf, we will ask them to prove they have your permission to act.
Partner websites
Our website may contain links to and from the websites of our partner networks, affinity scheme partners, advertisers, and affiliates. Please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. You should check these policies before you submit any personal data to these websites.
Complaints
If you wish to raise a complaint with regard to how we have handled your personal data, you can contact our UK based Data Protection Officer who will investigate the matter.
For data subjects from the UK, if you are not satisfied with our response or believe we are processing your personal data not in accordance with the law you can complain to the Information Commissioner’s Office (ICO).
7. Cookies
Our website uses cookies to distinguish you from other website users. This helps us to provide you with a good browsing experience. For detailed information on the cookies we use and the purposes for which we use them, see our cookie policy.
8. Where we store your personal data
In order to provide our services, we may need to transfer your personal information to locations outside the country in which you provide it or where you are viewing this website for the purposes set out in this Privacy Notice. This may entail a transfer of your information from a location within the European Economic Area (the “EEA”) or the UK to outside the EEA/UK, or from outside the EEA to a location within the EEA/UK. Please see ‘Sharing your information’ for more detail on how the information may be shared within the Alcumus group and with third party service providers.
The level of information protection in countries outside the EEA/UK may be less than that offered within the EEA/UK. Where this is the case, we will implement appropriate measures to ensure that your personal information remains protected and secure in accordance with applicable data protection laws. EU and UK standard contractual clauses are in place between all Alcumus entities that share and process personal data. Please contact us using the details in the ‘How to contact us’ section below to request a copy of these clauses. Where our third-party service providers process personal data outside the EEA/UK in the course of providing services to us, our written agreement with them will include appropriate measures, usually standard contractual clauses.
All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted using SSL technology. Where you have chosen a password which enables you to access certain parts of our website, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our website; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
9. How to contact us
We hope this Privacy Notice has been helpful in terms of how we use your personal data and your rights in relation to such personal data. If you have any questions or wish to make a complaint, please contact our Data Protection Officer:
- Email us at [email protected].
- Write to us at Data Protection Officer, Axys House, Heol Crochendy, Parc Nantgarw, Cardiff CF15 7TW.
This Privacy Notice was last updated on 28 February 2023.
Service-Specific Usage
Data Types
Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Privacy Notice.
Communications Data includes your communication preferences in receiving service communications from us.
Contact Data includes billing and operational address(es), email address and telephone numbers.
Financial Data includes bank account and payment card details.
Identity Data includes first name, last name, username, title, and in certain circumstances, your date of birth (this is used solely to determine whether an individual meets the legal age requirement to undertake specific types of work on behalf of a client).
Marketing and Communications Data includes your marketing and communication preferences in receiving marketing from us.
Sensitive Information includes information relating to any health and safety incident occurring at your workplace, which may include information about your health or medical conditions (which requires a higher level of protection under applicable data protection law).
Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to our services.
Transaction Data includes details about payments to and from you.
Usage Data includes information about how you use our services.
Purposes for which we will use your personal data – all services
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
To register you as a new customer | (a) Identity Data (b) Contact Data | Performance of a contract with you or our client |
To manage our relationship with you which will include: (a) Notifying you about changes to our terms or this Privacy Notice (b) Asking you to leave a review or take a survey | (a) Identity Data (b) Contact Data (c) Marketing and Communications Data | (a) Performance of a contract with you or our client (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services) |
To enable you to partake in a prize draw, competition or complete a survey | (a) Identity Data (b) Contact Data (c) Usage Data (d) Marketing and Communications Data | (a) Performance of a contract with you (b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business) |
To administer and protect our business and a relevant portal (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) and monitoring usage of a relevant portal and compliance with the contract we have in place with our client | (a) Identity Data (b) Contact Data (c) Technical Data | (a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) (b) Necessary to comply with a legal obligation |
To deliver relevant portal content to you | (a) Identity Data (b) Contact Data (c) Usage Data (d) Marketing and Communications Data (e) Technical Data | Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy) |
To use data analytics to improve a portal, services, marketing, customer relationships and experiences | (a) Technical Data (b) Usage Data | Necessary for our legitimate interests (to define types of customers for our products and services, to keep our Portal updated and relevant, to develop our business and to inform our marketing strategy) |
To make suggestions and recommendations to you about goods or services that may be of interest to you | (a) Identity Data (b) Contact Data (c) Technical Data (d) Usage Data | Necessary for our legitimate interests (to develop our products/services and grow our business) |
Collection of personal data
We use different methods to collect data from and about you including through:
Direct interactions: You may give us your Identity and Contact Data by uploading it to one of our Service specific portals, filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
- create an authorised user account on the portal;
- subscribe to our publications;
- request marketing to be sent to you;
- enter a competition, promotion, or survey; or
- give us some feedback.
Automated technologies or interactions: As you interact with our Service specific portals, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies.
Specific services & portals:
Alcumus ContractorCheck and Alcumus Cognibox
Alcumus Cognibox and ContractorCheck
When you use the ContractorCheck service or the Cognibox service, your personal data will be processed in accordance with their respective privacy notices:
Alcumus ISOQAR
When you use the Alcumus ISOQAR service your personal data will be processed in accordance with the information below.
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
To process, deliver and sustain certification including: (a) Manage payments, fees, and charges (b) Collect and recover money owed to us | (a) Identity Data (b) Contact Data (c) Financial Data (d) Transaction Data (e) Marketing and Communications Data | (a) Performance of a contract with you or our client (b) Necessary for our legitimate interests (to recover debts due to us) |
To manage our relationship with you which will include: (a) Notifying you about changes to our terms or this Privacy Policy (b) Asking you to leave a review or take a survey (c) Planning and delivering audits (d) Creating and providing reports | (a) Identity Data (b) Contact Data (c) Marketing and Communications Data | (a) Performance of a contract with you or our client (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services) |
Disclosures of your personal data
In addition to the disclosure of personal data in accordance with this Privacy Notice, Alcumus ISOQAR may have to share your personal data for the purposes set out in the table above.
This includes disclosure to the United Kingdom Accreditation Service (UKAS) as part of their ongoing audit for Alcumus ISOQAR to be UKAS accredited. These audits will include reviewing a selection of reports and occasionally a UKAS representative attending site visits conducted by Alcumus ISOQAR.
Any personal data shared with UKAS is done so on the basis that it is required for auditing purposes and the data deleted after review.
Third-Party Auditors
Alcumus ISOQAR uses a number of subcontractors to provide its services. This includes a pool of qualified third-party auditors who undertake audits on behalf of Alcumus as required. Alcumus occasionally uses subcontracted technical advisors to verify the competence requirements of Alcumus auditors providing the Services.
For certain standards provided by Alcumus (specifically IFS and FSSC), Alcumus subcontracts the Services to our critical office location in Poland (an agency providing services under Alcumus’ UKAS accreditation).
Appointed Subprocessors
Purpose of Processing | Sub-Processors |
Software Provider | SafetyCulture (UK) Limited |
Cloud Hosting | Microsoft Ireland Operations Limited |
Alcumus SafeContractor and SafeSupplier
When you use the SafeContractor accreditation portal (the SafeContractor Portal), your personal data will be processed in accordance with the information below.
Purposes for which we will use your personal data
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
To take you through the SafeContractor accreditation process | (a) Identity Data (b) Contact Data | Performance of a contract with you |
Disclosures of your personal data
In addition to the disclosure of personal data in accordance with this Privacy Notice, with your use of the SafeContractor Portal we may have to share your personal data for the purposes set out in the table above. This includes:
- Safety Schemes in Procurement (SSIP) in relation to accredited SafeContractor members. This usually will be limited to business information, contact data and identity data.
- Third party anchor clients of SafeContractor who may wish to purchase services via a contractor are able to access contractor information (including in some circumstances, personal data) via the SafeContractor Portal. Levels of personal data are limited in nature, restricted, and redacted where appropriate. At present, the types of documents made available to anchor clients include:
- risk assessments;
- health and safety policies;
- training records; and
- equipment issue or maintenance records. These documents may contain employee names, job titles, and contact details (including email or postal addresses).
- Membership benefit providers. We work closely with and will sometimes share information with them about you so that they can send you information about any of their products and services you may be interested in, or any promotions they are running. SafeContractor's current partners are set out below. If you would like more information about the ways in which they process personal data, please refer to their privacy policies (as provided below):
- TradePoint (click here for TradePoint privacy policy)
- Fuel Card Services (click here for Fuel Card Services privacy policy)
- Alcumus Insurance, provided by Kerry’s Insurance Group (click here for Alcumus Insurance privacy policy)
Checks are undertaken by Alcumus to ensure that the documents shared do not contain extensive or unnecessary personal data in excess of the types and categories of personal data outlined above.
Purpose of Processing | Sub-Processors |
Cloud Hosting | Amazon Web Services Inc Microsoft Ireland Operations Limited |
Sales Engagement Platform | Salesloft, Inc |
Alcumus SafeWorkforce
When you use the SafeWorkforce Guard portal (the SafeWorkforce Portal), your personal data will be processed in accordance with the information below.
Information you upload to the SafeWorkforce Portal - Employees
We provide access to the SafeWorkforce Portal to you in accordance with a contract we have in place with your employer. In relation to any personal data that you upload or record on the SafeWorkforce Portal, your employer is the data controller in respect of such personal data, and this means that it remains primarily responsible for such personal data.
We process this personal data on behalf of your employer to provide access to the SafeWorkforce Portal for you and other authorised users. The precise purpose for which the personal data is processed will be determined by the terms of business we have with your employer, and by any applicable laws.
It is your employer’s obligation to ensure that any individual’s personal data uploaded to the Portal understands that their personal data will be processed by us in accordance with our contract with your employer.
Information we upload to the SafeWorkforce Portal
There may be instances where we upload personal data to the SafeWorkforce Portal, either for our own purposes or to perform and provide the services to your employer. We will remain as data controller in relation to this personal data, be primarily responsible, and we will always act in accordance with this privacy policy notice.
Third Parties
We process your card payments via Worldpay, which may allow Worldpay to collect or share data about you. We do not control their actions and we are not responsible for their privacy policies. We therefore encourage you to read their privacy notice.
Appointed Subprocessors
Purpose of Processing | Sub-Processors |
Legal Services Provider | Richard Hall & Partners |
Occupational Health Services Provider | Fusion Occupational Health Limited Valentine Occupational Health Limited |
Insurance Provider | Towergate Insurance Brokers, part of Towergate Underwriting Group Limited Kelliher Insurance Group |
Electronic Signature Service | DocuSign Inc. Evalu-8 Software Limited |
Sales Engagement Platforms | Salesloft Inc. HubSpot Inc. |
Software Provider | EcoOnline Info Exchange |