GDPR Statement
This is the GDPR Statement of Northamber PLC, Namber House, 23 Davis Road, Chessington, Surrey, KT9 1HS. This document sets out how Northamber complies with data protection regulations including the latest GDPR requirements, from May 25th 2018. This Statement applies to suppliers, customers and subcontractors and aims to address the Q&A requests that are required by our partners for GDPR related procedures.
This document is available at all times on the Northamber homepage (www.northamber.com/gdpr). It outlines how we collect and use personal information, how we meet our obligations as a data controller and as a data processor. It may be updated from time to time. The online document will always be the most up to date version. You can contact privacy@northamber.com for any questions relating to our GDPR Policies.
Either, both. Depending on the type of transaction.
Under Article 28 of the GDPR, Northamber is defined as a data “controller” for personal data that our customers provide for certain transactions; e.g. when we set up an account & when we process orders for delivery to our customer premises. As data controller we may collect contact details, payment details and company details. These will be used to transact orders, to confirm credit, to take payment, to deliver goods etc, as required to fulfil our legal and contractual obligations in processing the account and orders. This data will only be used by staff who have a business need to access the data, will only be shared with those 3rd parties who enable us to perform our obligations (e.g. credit agencies and delivery firms), will be secure in our online and offline systems and will be retained for a maximum of 7 years in order to enable us to comply with our legal obligations, after which time it will be deleted. Our use of sub-contractors or GDPR “data processors” is governed by an agreement that ensures they are also compliant with GDPR and that the data is dealt with accordingly.
Northamber is defined as a data “processor” for personal data that is provided for certain transactions; e.g. when we “drop ship” orders to our customer’s own end user customers as or when we transact licensing agreements or request special bid pricing. As data processor we may collect end user name, address and other contact details that may be passed on to our own sub-contractors (e.g. delivery firms, vendors), as required to enable us to carry out our contractual commitments to our customers. This data will only be used by staff who have a business need to access the data, will only be shared with those 3rd parties who enable us to perform our obligations (e.g. vendors for licenses, delivery firms for deliveries), will be secure in our online and offline systems and will be retained for a maximum of 7 years in order to enable us to comply with our legal obligations, after which time it will be deleted. Our use of sub-contractors or GDPR “subprocessors” is governed by an agreement that ensures they are also compliant with GDPR and that the data is dealt with accordingly.
• Name, Email address, fax number, postal address, business contact and billing information, transaction and credit card details (during transactions).
• Your preferences on what marketing information (if any) you’d like to receive and how you’d like to receive them
When customers order from Northamber we collect additional information including:
• Payment details – including credit card numbers where relevant
• End user details to enable direct ship / drop ship – including name, address and contact details
• End user details to enable license registration
• End user details to enable special bid pricing requests
Northamber does not collect any Special Category Data as defined by the GDPR for any interactions with customers or suppliers.
• To enable us to confirm business details when setting up an account, for legal, financial and contractual purposes so that we may provide commercial services to our customers.
• To carry out basic checks for due diligence when setting up accounts to ensure all details are genuine and correct and to avoid fraudulent use of data.
• To allow us to comply with legal requirements placed upon us.
• To send you tailored communications by post, fax and/or email about new products, promotions, news items, event details, special offers or other useful items of interest.
When purchasing from Northamber we will request and use customer and sometimes end user data for the purposes listed below:
• To enable delivery of goods directly to our customers.
• To enable delivery of goods to our customers’ end users, including via sub-contractor delivery firms (sub-processors).
• To facilitate the purchase of software licensing.
• To enable special bid pricing requests.
We will keep data for the duration of our joint relationships. Data will be retained in accordance with legal requirements and be deleted after such requirements are met. For example if we end a business relationship, data will be retained for seven years and then destroyed.
Access decisions are taken by the Executive Team.
If you believe we have any incorrect personal information about you, or if anything changes, you may request to see this data, which we will provide within 30 days at no charge. If you are requesting more detailed data that requires an additional amount of resource, we may make a nominal charge to cover our costs.
Any relevant changes in your personal data should be notified to Northamber via your usual contact or to the privacy@northamber.com email address.
Data is physically stored in the UK at Northamber owned facilities and is not passed outside the EEA. Precise location of the data and backups is confidential in order to maintain data security. If you need more information please contact the privacy@northamber.com email address.
Personal data relating to prospective employees who are not successful candidates will be kept for 12 months and then destroyed.
Data is removed through standard deletion and overwriting processes to ensure restoration is not possible.
Data deletion and destruction is authorised via the management process and staff training and compliance checks.
Data breaches are understood by all staff and management and processes are in place to identify and report them through the management system. Training of all staff includes this subject and other GDPR related responsibilities.
Internal tracking and audits are carried out to ensure compliance by staff on all data privacy related matters.
Training is delivered by various internal and external parties and is under the direction of the Privacy Officer. Refresher courses are run on an ongoing basis as new staff join, regulation changes are made or to re-enforce as required.