Cavendish Kane & Associates Limited is a data controller and is committed to protecting your privacy and takes its responsibilities regarding the security of user information very seriously. This privacy statement sets out how Cavendish Kane & Associates Limited complies with both UK and European Union data protection requirements. We have structured our website so that you can visit without identifying yourself or revealing any personal information. Once you choose to provide us with any information by which you can be identified, then you can be assured that it will only be used in accordance with
this Privacy Notice
This website and our services are not intended for children and we do not knowingly collect data relating to children.
If you have any queries about the policy, please get in touch with us using email@example.com or write to us at the address below and we will do our best to answer your questions.
Cavendish Kane & Associates Limited
c/o JS White and Co
25-29 Sandy Way
2. WHAT IS PERSONAL DATA?
Under the EU’s General Data Protection Regulation (GDPR) personal data is defined as: “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.
3. HOW WE USE YOUR INFORMATION
This privacy notice tells you how we, Cavendish Kane & Associates Limited, will collect and use your personal data for example:
To contact you in response to a specific enquiry,
To provide our products and services that you request from us,
Send you transactional communications via the contact details you have provided to us during our services;
Contact third parties on your behalf, with your specific instruction;
Send you email notifications which you have specifically requested;
To personalise the website for you,
To send you promotional emails and mailings about Cavendish Kane & Associates Limited’s products, services, offers and other things that we think may be relevant to you,
Operate and manage your account and manage any application, agreement or correspondence you may have with us;
Carry out, monitor and analyse our business; To identify, prevent, detect or tackle fraud, money laundering, terrorism
and other crimes,
To contact you via email or telephone for market research reasons
To form a view of you as an individual and to identify, develop or improve products, that may be of interest to you.
For audits, regulatory purposes, legal obligations, and compliance with industry standards
Perform other administrative and operational purposes including the testing of systems
Please note that we will not under any circumstances sell or share your data with third party marketing companies without your consent.
5. PERSONAL DATA CATEGORIES WE COLLECT
We may collect, use, store and transfer different kinds of personal data about you which we have categorised as follows:
This includes, first name, maiden name, last name, marital status, title, date of birth and gender
This includes, email address and telephone numbers.
This includes, bank account information and payment details.
This includes, recorded calls for quality checks and staff training. Such recordings may also be used to help us combat fraud.
This includes, internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
This includes, information about how you use our website, products and services.
Marketing and Communications Data
This includes, your preferences in receiving marketing from us and your communication preferences.
This includes statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
Special Categories of Personal Data
This includes health and vulnerability related data that you may voluntarily share with us during the fulfilment of our services to you. We will always ask for your explicit consent to record and share Special Category Data.
6. HOW WE MIGHT COLLECT PERSONAL DATA
We use different methods to collect data from and about you as follows:
When you voluntarily provide it to us: –
You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
apply for our products or services;
request marketing to be sent to you; or
give us some feedback.
Collected automatically: –
Provided by third parties or publicly available sources: –
We may receive personal data about you from various third parties as set out below:
Technical Data from analytics providers such as Google based outside the EU;
Identity and Contact Data from publicly available sources, including Companies House and the Electoral Register based inside the EU.
7. PROCESSING PURPOSE AND OUR LEGAL BASIS
We will always have a legal basis for processing personal data and we have methodically assessed our purposes and legal bases.
Our legal basis for processing your information is most commonly in line with our contractual obligations to fulfil the services and products you request from us.
As a Regulated company we are audited and held to high standards for the services and products we offer. Therefore, we may be legally obligated to process personal data during regulatory audits.
In the process of delivering our services (such as direct marketing), there may be legitimate interests that we pursue, which we have tested to ensure that those interests are balanced, appropriate and we have considered any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). If you have any questions about the legal basis for our processing activities, please feel free to get in touch with us.
8. RECIPIENTS OF YOUR PERSONAL DATA
During the course of providing the services that you request from us, we may share your information with our processing partners, known as recipients and data processors.
None of our Processors have the right to use your data other than for the purposes instructed by Cavendish Kane & Associates Limited.
Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.
If you provide your data through a third party, we may share data with that lead provider in order to assist with the management of the services and to streamline client contact”
We may, from time to time, disclose your data to and receive from your lenders, underwriters, official receiver/insolvency practitioner and our processors, referrers, external auditors & regulator.
9. WHEN WE MAY HAVE TO DISCLOSE YOUR PERSONAL DATA
We may have to disclose your personal data with other third parties as set out below. These organisations or bodies will not use your information to contact you. These third parties will be subject to obligations to process your personal information in compliance with the same safeguards that we deploy.
Compliance Consultants and other like services acting as processors, based in the United Kingdom who require reporting of processing activities in certain legal and compliance circumstances.
10. TRANSFERRING DATA OUTSIDE OF THE EEA
In the provision of our services to you we use data processors that are outside of the European Economic Area (EEA). Specifically, we use data processors based in South Africa.
The General Data Protection Regulation has strict rules about data transfers to international organisations and we use approved data transfer mechanisms, including the EU–US Privacy Shield and contracts with model clauses, particularly when using data processors based in South Africa.
We take extra steps to ensure comprehensive due diligence and regular audits, both onsite and remote, of the data processing activities of our data processors.
If you would like any more information, please get in touch by contacting our office, details can be found at the start of this Privacy Notice.
11. MAKING SURE YOUR DATA IS SECURE
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
12. HOW LONG DO WE KEEP DATA?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal
Details of retention periods for different aspects of your personal data are available and you can request more details of that by contacting our Office. We store all call recordings for 6 months from the last contact.
By law we have to keep certain information about our customers and this data will be held solely and securely for those legal purposes.
13. YOUR RIGHTS AS A DATA SUBJECT
At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:
Right of access – you have the right to request a copy of the information that we hold about you.
Right of rectification – It is important that all of the information that we hold for you is and remains accurate. You can update your information with us on your client portal directly, by advising us over the telephone or via email at firstname.lastname@example.org.
Right to be forgotten – in certain circumstances you can ask for the data we hold about you to be erased from our records.
Right to restriction of processing – where certain conditions apply to have a right to restrict the processing.
Right to object – you have the right to object to certain types of processing such as direct marketing.
Right to judicial review: in the event that Cavendish Kane & Associates Ltd refuses your request under rights of access, we will provide you with a reason as to why. You have the right to complain and we have provided a specific section on this below.
All the above requests will be forwarded on should there be a third party involved in the processing of your personal data.
15. REQUESTING ACCESS TO MY DATA
Cavendish Kane & Associates Limited at your request, can confirm what information we hold about you and how it is
processed. If Cavendish Kane & Associates Limited does hold personal data about you, you can request the following information:
Identity and the contact details of the person or organisation that has determined how and why to process your data.
Contact details of the data protection officer, where applicable.
The purpose of the processing as well as the legal basis for processing.
If the processing is based on the legitimate interests of Cavendish Kane & Associates Limited or a third party, information about those interests.
The categories of personal data collected, stored and processed.
Recipient(s) or categories of recipients that the data is/will be disclosed to.
If we intend to transfer the personal data to a third country or international organisation, information about how we ensure this is done securely. The EU has approved sending personal data to some countries because they meet a minimum standard of data protection. In other cases, we will ensure there are specific measures in place to secure your information.
How long the data will be stored.
Details of your rights to correct, erase, restrict or object to such processing.
Information about your right to withdraw consent at any time.
How to lodge a complaint with the supervisory authority.
Whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether you are obliged to provide the personal data and the possible consequences of failing to provide such data.
The source of personal data if it wasn’t collected directly from you.
Any details and information of automated decision making, such as profiling, and any meaningful information about the logic involved, as well as the significance and expected consequences of such processing.
What forms of ID will I need to provide in order to access this?
Cavendish Kane & Associates Limited accepts copies of the following forms of ID when information on your personal data is requested: Passport, driving licence, birth certificate, utility bill from last 3 months. This is typically required when we have reason to believe the request may not be by the person it belongs to.
Contact details of the Data Protection Officer (DPO):
Data Protection Officer
Cavendish Kane & Associates Limited
c/o JS White and Co
25-29 Sandy Way,