We collect and process personal data about our clients and other people we work with, people who provide services to us and people who contact us with an enquiry. Our clients are people who work for organisations for which we provide consultancy or software services; they may include prospective new clients and clients we have worked with in the past.
On our website, www.orhltd.com, we use Google Analytics to collect information on how visitors use the website so that we can make improvements to it.
For information about how we process operational data on behalf of our clients for the purposes of undertaking project work, please see our Data Processing Notice.
We are committed to being transparent about how we collect and use that data and to meeting our data protection obligations in accordance with the UK Data Protection Act 2018 and General Data Protection Regulation 2016.
What information do we collect?
When you work with us or contact us with an enquiry, we may collect and process your business contact information. This includes:
- business e-mail address
- business telephone number and address
- details about your organisation and your job title.
We collect this information in a variety of ways. For example, the information may be provided by you when you make an enquiry. We may receive the information indirectly when it is shared with us by your organisation in the course of arranging or carrying out our consultancy or software services.
It may also be collected by us from a publicly available source, for example, from your organisation’s website or from information posted publicly or provided to us as part of a tender bidding process.
Why do we process personal data?
We need to process data to submit tenders and proposals for work, negotiate contracts and terms for services.
We also have a legitimate interest in processing data to carry out direct marketing of our services to organisations. You are able to opt out of direct marketing at any time. You can do this by contacting the Company Secretary at the address provided below.
When working with a client we need to process data to fulfil our contractual obligations to provide consultancy and/or software services.
If you contact us directly with an enquiry, we will process your personal data with your consent in order to respond to that enquiry. You are able to remove your consent at any time. You can do this by contacting the Company Secretary at the address provided below.
How we store your information
Data is stored in our secure IT systems (including the organisation’s email system) located in our offices in Reading and backed up to a secure cloud server hosted in the UK. ORH’s employees may access e-mails from phones and laptops. Phones are encrypted by passcode or fingerprint and laptops are secured by BitLocker.
Who has access to data?
Your information may be shared with employees internally. Information will only be shared with employees internally where access to the data is necessary for the performance of their roles.
We may share your data with third parties, and/or have third parties process data on our behalf, in order to:
- obtain external business support and advice for IT
- comply with any legal obligations.
Your data may be transferred to countries outside the European Economic Area (EEA) where processing of any of the activities above takes place outside the EEA, or where IT systems are supported outside the EEA. Data is transferred outside the EEA on the basis of relevant safeguards, agreements, EU Model clauses, confidentiality or other adequate arrangements being in place.
How do we protect data?
We take the security of your data seriously. We have internal controls in place to try to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by its employees in the performance of their duties.
Where we engage third parties to process personal data on our behalf, they do so on the basis of written instructions, are under a duty of confidentiality, and are obliged to implement appropriate technical and organisational measures to ensure the security of data.
For how long do we keep data?
We actively maintain directories of contact details of our clients (including prospective clients and clients we have worked with in the past) and periodically review them to ensure they are up-to-date and to remove contact details of people who no longer work for client organisations.
We will not keep your data for longer than is necessary for the purposes for which we collected it as described in this Notice and to satisfy legal requirements. The retention period depends on the information collected and the reasons for processing it.
Website and Cookies
Google Analytics is a third-party tool that we use to collect information and compile reports about how visitors are using our website. We process this information so that we can improve the website.
For more information about how Google uses analytics data, see: https://support.google.com/analytics/answer/6004245
Google provides a browser add-on that allows you to opt out of being tracked by Google Analytics for all websites: https://tools.google.com/dlpage/gaoptout
As a data subject, you have a number of rights. You can:
- access and obtain a copy of your data on request;
- require the organisation to change incorrect or incomplete data;
- require the organisation to delete or stop processing your data, for example, where the data is no longer necessary for the purposes of processing;
- object to the processing of your data where the organisation is relying on its legitimate interests as the legal ground for processing; and
- ask the organisation to stop processing data for a period if data is inaccurate or there is a dispute about whether or not your interests override the organisation’s legitimate grounds for processing data.
If you would like to exercise any of these rights, please contact our Information Governance Lead (see details below).
- Email – firstname.lastname@example.org
- Telephone – +44 (0)118 959 6623
- Post – 3 Queens Road, Reading, Berkshire, RG1 4AR
How to complain
If you believe that the organisation has not complied with your data protection rights, you can complain to the Information Commissioner.
Information Commissioner’s Office: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline number: 0303 123 1113.