Privacy Policy
Contents
- Introduction
- The information we collect
- How we use your information
- Who we might share your information with
- How we keeping you updated on our business, products and services
- Your rights over your information
- How long we keep your information for
- Your data and Social Networks
- Security
- Cookies used by this website
- How to contact us
- Introduction
Business Systems or BSL is the trading name of Business Systems (UK) Limited who are registered in England & Wales No. 2199 582. We are committed to protecting the privacy and security of your personal data and ensuring that it is processed correctly within the law.
We have therefore developed this privacy policy to inform you of the data we collect, what we do with your information, what we do to keep it secure as well as the rights and choices you have over your personal information. BSL remain the Data Controller at all times.
- The Personal Information we collect
Business Systems collect, process and store personally identifiable information in accordance with the Data Protection Act 2018 and UK General Data Protection Regulation (GDPR). This data is used to maintain the business relationship, advertise our services and for recruitment activities between you as a customer (or potential customer) or applicant and Business Systems.
Data Collection
Data is collected via various different means:
- Contact details submitted to Business Systems to receive a communication such as a ‘white paper’ or to attend an event.
- Contact details submitted to Business Systems as an enquiry into our services such as receive content created by BSL, attend an event or enquire about working with BSL.
- As a contact for an event or as a contact during a contract.
- Browsing our corporate website or engaging via our social media channels.
- Where you submit your details in regard to employment with Business Systems.
When you visit our website we will collect certain information in order to efficiently maintain the website and establish who is visiting. The information collected includes:
- IP address
- Device Type
- Browser version
- Operating System
- Mobile Network,
- Device Settings and geographical data
You can choose to supply the following details where you wish to receive a service or be contacted by BSL:
- Your full name
- Your role within your organisation
- Your business address
- The name of your company
- Your telephone number(s)
- Your Email address
We may, in further dealings with you, extend this information to include your purchases, services used, and subscriptions, records of conversations and agreements, etc..
- You are under no statutory or contractual requirement or obligation to provide us with your personal information; however we require at least the information above in order for us to deal with you as a prospect or customer in an efficient and effective manner.
- The legal basis for processing your data is based on your performance of a contract that we will have requested at the point the information was initially provided, therefore we will not store, process or transfer your data outside the parties detailed above unless we have an appropriate lawful reason to do so.
Further processing
Information collected is processed with the following suppliers:
- 6sense: IP address to identify who is visiting.
- Salesforce: contact details to manage the sales relationship.
- Act-On: Manage the marketing contacts.
- Sage InContact: Manage any payment or financial relationship.
- Teamdesk: IT Service Management of a service you are receiving from us.
- Personio: HR management tool.
- Microsoft 365: our productivity and communication applications.
Contact Form
The primary instance where our website will ask you for personally identifiable information is when you chose to submit information using the various forms that are available. Form content is loaded into Act-On, our Marketing and form management service. Upon completing your information, you will be asked to consent to our data processing policy which is outlined within this document.
Once submitted, your information will be processed and forwarded to us within a single email sent by the website application. Your information will not be stored within the website application’s database.
- How we use your information
- To contact you, following your enquiry, reply to any questions, suggestions, issues or complaints you have contacted us about;
- Make available our products and services to you;
- For statistical analysis and to get feedback from you about our products, websites, mobile apps, and other services and activities. For example, occasionally we may invite you to review a product or service you’ve bought or used from us. If we do, it’s possible that we’ll use independent research and feedback providers to act on our behalf;
- To power our security measures and services so you can safely access our website and mobile apps;
- Help us understand more about you as a customer, the products and services you consume, so we can serve you better;
- Contact you about products and services provided by BSL;
- Provide you with online advertising and promotions; and
- Help answer your questions and solve any issues you have.
- Who we might share your information with
We may share your personal data with other organisations in the following circumstances:
- If the law or a public authority says we must share the personal data;
- If we need to share personal data in order to establish, exercise or defend our legal rights (this includes providing personal data to others for the purposes of preventing fraud); or
- From time to time, employ the services of other parties for dealing with certain processes necessary for the operation of the Website. However, all the information we share will be collected and anonymised, so neither you nor any of your devices can be identified from it.
- How we keep you updated on our business, products and services
Email Marketing
From time to time we may send you relevant content, offers and news about our business, products and services by email.
When interacting with our website, you may be asked if you’d like to sign-up to receive our email marketing communications.
You can change your Email Marketing subscription anytime by editing your preferences or unsubscribing altogether via the link at the bottom of any of our email marketing communications or by contacting us via the details at the end of this policy.
- Your rights over your information
Right to Access Your Personal Information
You have the right to access the personal information that we hold about you in many circumstances, by making a request. This is sometimes termed ‘Data Subject Access Request’ (DSAR). If we agree that we are obliged to provide personal information to you (or someone else on your behalf), we will provide it to you or them free of charge and aim to do so within 30 days from your request.
We may ask for proof of identity and sufficient information about your interactions with us that we can locate your personal information.
Right to Correction of Your Personal Data
If any of the personal information we hold about you is inaccurate or out of date, you may ask us to correct it.
Right to Stop or Limit Our Processing of Your Data
Under Article 21 of the UK GDPR, you have the right to object to the processing of your personal data at any time. This allows you to stop or prevent us from processing your personal data, if we are not obligated to use it any more. We may need to retain some contact details in a ‘no contact’ register, otherwise we’re unable to record where you’ve asked us not to contact you.
For more information about your privacy rights
The Information Commissioner’s Office (ICO) regulates data protection and privacy matters in the UK. They make a lot of information accessible to consumers on their website and they ensure that the registered details of all data controllers such as ourselves are available publicly. Our registration number is: Z8215680
You can make a complaint to the ICO at any time about the way we use your information. However, we hope that you would consider raising any issue or complaint you have with us first. Your satisfaction is extremely important to us, and we will always do our very best to solve any problems you may have.
- How long we keep your information for
We retain a record of your personal information in order to provide you with a high quality and consistent service. We will always retain your personal information in accordance with the General Data Protection Regulation (GDPR) and Data Protection Act 2018 and never retain your information for longer than is necessary. Unless otherwise required by law, your data will be stored for a period of 5 years after our last contact with you, at which point it will be permanently deleted and irretrievable.
- Your data and Social Networks
When using this website, you may be able to share information through social networks like Facebook and Twitter. For example, when you ‘like’, ‘share’ or review our Services. When doing this, your personal information may be visible to the providers of those social networks and/or their other users. Please remember it is your responsibility to set appropriate privacy settings on your social network accounts so you are comfortable with how your information is used and shared on them.
- Security
Data security is of great importance to Business Systems and to protect your data we have put in place suitable physical, electronic and managerial procedures to safeguard and secure your collected data.
We take security measures to protect your information including:
Physical & Managerial Security Procedures
- Limiting access to our buildings to those that we believe are entitled to be there (by use of passes, key card access and other related technologies);
- Implementing access controls to our information technology
- We use appropriate procedures and technical security measures (including encryption, anonymisation and archiving techniques) to safeguard your information across all our computer systems, networks, offices and stores.
- Never asking you to disclose your own passwords,
- Advising you never to enter your account number or password into an email or after following a link from an email.
- We are ISO27001:2013 (Information Security management) and Cyber Essentials certified.
Website Application and Hosting Security Procedures
- HTTPS – This website is secured via Hyper Text Transfer Protocol Secure (HTTPS). It means all communications between your browser and this website are securely encrypted. This means that even if somebody managed to intercept the connection, they would not be able to decrypt any of the data which passes between you and the website.
- Secure Update Process – Inline with the security processes of our website development partner agency, this website application’s code-base is administered and updated via a password and FTP free process. All code-changes are deployed via a secure process that does not rely on the storage and visible access of passwords.
- Two Factor Authentication – Where possible, the administration interface to this website application and any personally identifiable information herein, is secured using two factor authentication login to all staff who have access to it. Additionally, our website development agency can only access the same interface via their secure Google GSuite accounts and hold no password records for accessing the platform at super-admin level.
- Web Application Maintenance – Our organisation, working in collaboration with our website development agency, regularly monitor the security of this website and consistently update the core CMS platform and supporting extensions and plugins.
- Cloudflare – Our website’s DNS is managed through Cloudflare who provide our content delivery network (CDN), DDoS attack mitigation, Internet security and distributed domain name server services..
- Cookies used by this website
What are Cookies?
Cookies are small pieces of data, stored in text files, that are stored on your computer or other device when a website is loaded within your chosen browser. They are widely used to ‘remember’ you and your preferences, either for a single visit (through a ’session cookie’) or for multiple repeat visits (using a ‘persistent cookie’). They ensure a consistent and efficient experience for visitors, and perform essential functions such as allowing users to register and remain logged in. Cookies may be set by the site that you are visiting (known as ‘first party cookies’), or by other websites who serve up content on that site (‘third party cookies’).
What is Cookie Control?
You may notice that our website utilises a third party Cookie preference tool called ‘Cookie Control’. Cookie Control is a mechanism for controlling user consent and the use of cookies on this website application.
When (as the user) you consent to one of the optional cookie categories, Cookie Control will place a cookie to remember that decision. The name of the cookie will be the name of the category specified within the Cookie Control widget itself. That cookie will be removed when you (the user) revokes consent to that category.
What are ‘Strictly Necessary Cookies’?
These are the cookies that are essential for this website to perform its basic functions. These include those required to allow registered users to authenticate and perform account related functions, as well as to save the contents of virtual ‘carts’ on sites that have an e-commerce functionality.
Strictly Necessary Cookies are highlighted with a double asterisk (**) in the tables below:
Cookies set by WordPress
Cookie Name | Description | Duration |
wordpress_<hash> ** | On login, wordpress uses the wordpress_[hash] cookie to store your authentication details. Its use is limited to the admin console area, /wp-admin/ | 2 years |
wordpress_logged_in_<hash> ** | After login, wordpress sets the wordpress_logged_in_<hash> cookie, which indicates when you’re logged in, and who you are, for most interface use. | Session |
wp-settings-<time>-<UID> ** | WordPress also sets a few wp-settings-<time>-<UID> cookies. The number on the end is your individual user ID from the users database table. This is used to customize your view of the admin interface, and possibly also the main site interface. | Session |
WordPress_google_apps_login ** | This cookie is set by the plugin ‘Google Apps Login for WordPress’ and may be present for users who login to WordPress via their Google or GSuite account. | Session |
wordpress_test_cookie | Used to check whether your web browser is set to allow, or reject cookies. | Session |
wpe-auth |
Cookies set by Google Analytics
Cookie Name | Description | Duration |
_ga | Used to distinguish users. | 2 years |
_gid | Used to distinguish users. | 24 hours |
_gat | Used to throttle request rate. If Google Analytics is deployed via Google Tag Manager, this cookie will be named _dc_gtm_<property-id>. | 1 minute |
AMP_TOKEN | Contains a token that can be used to retrieve a Client ID from AMP Client ID service. Other possible values indicate opt-out, inflight request or an error retrieving a Client ID from AMP Client ID service. | 30 seconds to 1 year |
_gac_<property-id> | Contains campaign related information for the user. If you have linked your Google Analytics and AdWords accounts, AdWords website conversion tags will read this cookie unless you opt-out. Learn more. | 90 days |
_gaexp | Optimize 360 – Used to determine a user’s inclusion in an experiment and the expiry of experiments a user has been included in. | 90 days |
Cookies set by CloudFlare
Cookie Name | Description | Duration |
__cfduid ** | The __cfduid cookie is used to identify individual clients behind a shared IP address and apply security settings on a per-client basis. | 1 years |
Miscellaneous Cookies
Cookie Name | Description | Duration |
complianceCookie | Used to distinguish your acknowledgement of our website’s Cookie Banner and subsequent policy (this document). | 14 days |
How to change your Cookie preferences
The most popular web browsers typically provide additional tools to users for controlling or restricting cookies on their device. To find out more about cookies, including how to see what cookies have been set, you can visit www.aboutcookies.org.
To find information relating to other browsers, visit the browser developer’s website.
To opt out of being tracked by Google Analytics across all websites, visit http://tools.google.com/dlpage/gaoptout.
- How to contact us
If you would like to exercise one of your rights as set out earlier in this policy, or you have a question or a complaint about this policy, the way your personal information is processed, please contact us by one of the following means:
Data Protection Officer
By email: [email protected]
By post: DPO, Business Systems (UK) Limited, Cannon Green, 27 Bush Lane, London, EC4R 0AA.
Main phone number: 020 8326 8200 (09:00-17:30)
Service Desk: 020 8326 8300 (08:00-17:30)
This Policy was last updated on 17/10/2023