This policy is provided by The Legal Marketing Innovation Company Ltd t/a Business Stack, with mailing address of Third Floor, Lancaster Buildings, 77 Deansgate, Manchester, M3 2BW (hereinafter, “We”, “Us”, “Our” or “Company”).
The Company is a provider of business concierge and support services, including in respect of financial, legal, IT , HR, IT support and management services (our Service).
We are the data controller in respect of the personal information we collect when providing our services and operating the below Website(s):
When we are a processor
In some instances we provide our services on a subcontracted basis to another client, and in this instance it will be this client who is the data controller in respect of any products or services you buy from them.
In particular We support services with Co-op, Vodafone and Assurant/WG Regus, via:
For the Personal Information you have provided to Co-op, Vodafone, IWG Regus or another client, when purchasing services from them, it will be subject to the privacy information provided by the client. We have been engaged as a data processor and are subject to contractual requirements governing how we process Personal Information shared with us by the client.
1. Personal Information We Collect
What we process
We may collect, use, store and transfer different kinds of Personal Information about you which we have grouped together as follows:
Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.
Contact Data includes billing address, email address and telephone numbers.
Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Website.
Profile Data includes your username and password, use of Services made by you, your interests, preferences, feedback and survey responses.
Usage Data includes information about how you use our Website/Service, products and other services.
Financial Data relating to your business and its operations, as well as transaction data.
Marketing and Communications Data includes your preferences, and/or your employer’s preference in receiving marketing from us and our third parties and your communication preferences.
Special Category/Sensitive data: We do not usually collect any Special Categories of Personal Information about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
Anonymous data. We also collect, use and share aggregated data such as statistical or demographic data, as we determine at the time. Aggregated data could be derived from your Personal Information but is not considered Personal Information in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature.
Profiling: means “any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements”. We currently only use profiling to build behavioural or marketing profiles based on usage or navigation on the Service.
Automated Decision Making: is the making of a decision, about an individual, based solely on automated means without any human involvement. We do not currently make automated decisions about you.
How we collect personal information
We generally collect Personal Information either directly from you (by communicating with you through email, phone or otherwise, or your use of our website(s)); from clients (who you work for); from you as a client; and/or other business contacts and third parties or sources (including publicly available sources, such as business/firm websites and business-related social media). We may also collect information about you if you work for one of our suppliers or partners.
In particular, when you use the Service, we will process personal information to log you into your account, search for templates, access your business health check, request a call back from a member of our teams, contact our support lines, and applies to your use of the Service. We also use the Personal Information to ask questions and conducts surveys, to understand if your business would benefit from other services, to communicate with you, and to track usage of the Service and Our products and services.
We may purchase personal data from data aggregators, subject to an appropriate contract and in compliance requirements of UK data protection laws.
security, and measure use and effectiveness of Our services. For more information about the cookies We utilise on the website, please view Our Cookie Notice
2. Purposes and Legal Basis for the Processing of your Personal Information
We process your Personal Information for the following purposes:
Based on our legitimate interests when conducting our business, in particular:
We will use your Personal Information to provide Service, our Website and other products and services that you have requested, and respond to any comments or complaints you may send Us.
We monitor use of the Website, and use your Personal Information to help Us to track and analyse preferences and trends, evaluate possible new features, functionality and services, conduct surveys and request additional information, propose and discuss additional services, and improve Our Website
We use Personal Information when engaging with our suppliers and managing those relationships.
We use Personal Information you provide to investigate complaints received from you or from others, about the Website or our products and Service. We also use this Personal Information to track potential issues (for example, issues with fulfilment of services) and trends to better serve you.
We use Personal Information to make decisions about, and to effect, reorganisations or sales of all or part of Our business.
We monitor customer accounts to prevent, investigate and/or report fraud, misrepresentation, or crime, in accordance with applicable law
We will use Personal Information in connection with legal claims, compliance, regulatory and investigative purposes (for example, theft and fraud investigations) as necessary (including disclosure of such information in connection with legal process or litigation).
We use Personal Information of some individuals to invite them to take part in market research and customer surveys.
We use Personal Information to send you information about products and services, such as performance data or to conduct customer experience surveys (where your consent is not required).
We may use Personal Information to market to you, when permitted (see Marketing below)
Where you give Us consent:
We place cookies and use similar technologies in accordance with Our Cookie Notice and the information provided to you when those technologies are used
In some instances for marketing purposes (see Marketing below)
On other occasions where We ask you for consent, We will use the data for the purpose which We explain at that time.
For purposes which are required by law, for example:
In response to requests by government or law enforcement authorities conducting an investigation.
Responding to complaints where We are under a legal or regulatory obligation to adhere to a complaints handling procedure.
3. Disclosure of Personal Information
Disclosure to Our Service Providers and Partners
We employ third party companies and individuals to facilitate our Services (for example, customer support, customer communications, audit, application or database hosting, development, logistics, payment processing, and for fraud detection and prevention purposes). These third parties have limited access to your Personal Information to perform these tasks on Our behalf and are obligated to Us. The personnel of such third parties who use your Personal Information is limited to those individuals which are authorised to do so on a need-to-know basis and as necessary to provide these business services to Us. To provide the Service, we may share your name, contact details (including post code, email address and mobile number), and usage information.
We may also share personal date with our accountants, lawyers and other professional advisors.
Disclosure to Public Authorities
We may disclose your Personal Information if required for the purposes above, if mandated by law or if required for the legal protection of Our legitimate interests in compliance with Applicable Law.
Other Categories of Recipients
We may also disclose your Personal Information, usage information, and other information about you to parties acquiring part or all of Our business and/or assets, as well as to related lawyers and consultants. Also, if any bankruptcy or reorganisation proceeding is brought by or against Us, your Personal Information may be considered a company asset that may be sold or transferred to third parties.
We may also share personal information within our group of companies and businesses.
4. Where your Data is Processed
Your Personal Information will usually be processed inside the UK (and European Economic Area (“EEA”) for as long as it has an adequacy decision from the UK Government) by us and Our service providers, subject to contractual restrictions regarding confidentiality and security in accordance with applicable data protection laws and regulations.
A few of our external third parties and suppliers are based outside the EEA, so if they process personal information this a transfer of data outside the EEA.
Whenever we transfer your personal data out of the UK or EEA, we ensure a similar degree of protection is afforded to it by implementing at least one of the following safeguards:
We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
Where we use certain service providers, we may use specific contracts approved by the ICO which give personal data the same protection it has in the UK. We will also conduct an appropriate transfer risk assessment.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK or EEA.
5. Your Choices and Rights
I/You have the right to:
Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected.
Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law.
Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. .
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
If you want us to establish the data’s accuracy.
Where our use of the data is unlawful, but you do not want us to erase it.
Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format.
Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
You can exercise any of your rights by contacting Us. In order to safeguard your Personal Information from unauthorized access, We may ask that you provide sufficient information to identify yourself prior to providing access to your Personal Information.
In certain situations, and subject to applicable law, We may not be able or obliged to comply with part or all of your individual requests. For example, We may not comply with an access request if doing so would reveal Personal Information about another person, or comply with a deletion request relating to information which We are required by law to keep or have compelling legitimate interests in keeping.
If you have unresolved concerns, you have the right to complain to the Information Commissioner’s Office (‘supervisory authority’) and for details please visit www.ico.org
Refusing to provide data. To provide certain parts of the Service (for example – Logging in to the Service account, the provision of Personal Information is mandatory: If relevant data is not provided, then We may not be able to provide certain parts of the Service.
6. Communications from Us and Marketing
We will communicate with you through email, phone and SMS. We will send you Service-related communications ,for example – information about your usage of the service, customer satisfaction, information regarding the Service, Our services and market research surveys.
You will receive marketing communications from us if you have requested this information from us or purchased services from us and you have not opted out of receiving marketing.
B2B: If you work for a company we may contact you to understand if your employer/organisation would be interested in the services and products we provide. We rely on our legitimate interest to do this and will provide you/your organisation with an opportunity to opt out. In order to do this, we may collect your Personal Information from publicly available sources, such as your organisation’s website, LinkedIn, industry bodies and other business social media.
We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
You can change your email and contact preferences through this website or by contacting Us. Please be aware that you cannot opt-out of receiving service-related messages from Us.
7. Data Retention
We may retain Personal Information for a limited period of time if requested by law enforcement. Our customer support may retain information for as long as is necessary to provide support-related reporting and trend analysis only, but We generally delete or de-personalise transaction-related data consistent with this Notice. Once Personal Information is anonymised, We may retain and use such information. Additionally, We maintain logs and backups for security, debugging, and site stability purposes for up to 30 days after your transaction has been completed.
8. Information Security
We have implemented safeguards designed to protect your Personal Information in accordance with industry standards.
We have measures in place to restrict access to Personal Information to those individuals whom We know have a valid business purpose to have access to such data. We maintain physical, electronic and procedural safeguards. We follow generally accepted standards designed to protect the Personal Information submitted to Us, both during transmission and once We receive it. We require those who provide services for Us and to whom We provide Personal Information collected through the Service to keep such information secure and confidential. However, no method of transmission over the Internet or method of electronic storage is totally secure. Therefore, We cannot guarantee its absolute security.
9. Important Information
We do not knowingly collect Personal Information from anyone under the age of 18. You must be at least 18 years of age to use the Service.
Changes to this Notice
We may update this Notice from time to time. This Notice was last updated on the Effective Date below.
For customer enquiries, please contact us at: Business Stack Third Floor, Lancaster Buildings, 77 Deansgate, Manchester, M3 2BW. We welcome your questions or comments regarding this Notice. Please write to Business Stack, Data Privacy Manager, Third Floor, Lancaster Buildings, 77 Deansgate ,Manchester, M3 2BW, or send Us an email at email@example.com
Effective date: 7th July 2023