CY4OR Legal Limited (“CYFOR”, “we”, “us” or “our”) is a digital forensics, eDiscovery, cyber security and corporate investigations service provider registered in England and Wales with company number 06295131 and registered office at Benjarron House, Greengate Industrial Estate, Greenside Way, Middleton, Manchester, M24 1SW.
CYFOR is a “data controller” registered with the Information Commissioner’s Office (“ICO“) with registration number Z7719845. This means that we collect, hold and are responsible for certain personal data. We are committed to protecting and respecting your privacy and personal data.
HOW TO CONTACT US
We have appointed a data protection officer (“DPO”) who is responsible for overseeing this Privacy Notice. Questions, comments and requests regarding this Privacy Notice (including any requests to exercise your legal rights) should be marked for the attention of our DPO, as follows:
By post at: PO BOX 266, Manchester M24 0BY;
By email at: dpo@cyfor.co.uk; or
By telephone: 0161 797 8123.
Please quote “data protection” in the subject line of any correspondence or when telephoning.
INDEX
HOW TO CONTACT US……………………………………………………………………………………………. 1
INTRODUCTION………………………………………………………………………………………………………. 1
1……… What is the purpose of this Privacy Notice?……………………………………………………….. 2
2……… Who does this Privacy Notice apply to?…………………………………………………………….. 2
3……… Third party links………………………………………………………………………………………………. 2
YOUR PERSONAL DATA…………………………………………………………………………………………. 2
4……… What types of personal data will we collect from you?………………………………………… 2
5……… How is your personal data collected?………………………………………………………………… 4
6……… On what basis do we process your data?………………………………………………………….. 5
7……… Sensitive Data and Criminal Data…………………………………………………………………….. 6
8……… Change of purpose…………………………………………………………………………………………. 6
9……… Marketing communications………………………………………………………………………………. 7
10……. Cookies…………………………………………………………………………………………………………. 7
DATA SHARING………………………………………………………………………………………………………. 7
11……. Who do we share your personal data with?……………………………………………………….. 7
12……. Information we collect about you from others…………………………………………………….. 8
13……. International transfers……………………………………………………………………………………… 9
14……. Information collected from you about others………………………………………………………. 9
DATA SECURITY……………………………………………………………………………………………………… 9
15……. What measures do we have in place to keep your data secure?………………………….. 9
DATA RETENTION…………………………………………………………………………………………………. 10
16……. How long will we use your personal data for?…………………………………………………… 10
YOUR DATA PROTECTION RIGHTS……………………………………………………………………….. 10
17……. What are your rights in connection with the data that we hold?………………………….. 10
18……. How can you exercise your rights?…………………………………………………………………. 11
19……. Are there any restrictions on exercising your rights?…………………………………………. 12
CHANGES TO OUR PRIVACY NOTICE……………………………………………………………………. 12
COMPLAINTS………………………………………………………………………………………………………… 12
Appendix – Data Processing…………………………………………………………………………………….. 1
INTRODUCTION
- What is the purpose of this Privacy Notice?
- This Privacy Notice sets out the basis on which any personal data we collect about you, or that you provide to us, will be processed by us and informs you of your privacy rights and how the law protects you.
- It is important that you read this Privacy Notice together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This Privacy Notice supplements the other policies and notices and is not intended to override them.
- Who does this Privacy Notice apply to?
- This Privacy Notice applies to all data subjects whose personal information we collect and use to include users of our websites (namely, cyfor.co.uk and cyforsecure.co.uk), our clients, prospective clients, business contacts, other professionals, job candidates, suppliers and service providers.
- This Privacy Notice does not apply to our employees or consultants, as the way we collect and use their personal information is governed by the privacy policy in our staff handbook.
- Our websites and the services that we provide are not intended for children and we do not knowingly collect data relating to children.
- Third party links
Our website(s) may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website(s), we encourage you to read the privacy notice of every website that you visit.
YOUR PERSONAL DATA
- What types of personal data will we collect from you?
- Personal data means any information about a living individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
- We may collect personal data from you in the course of our business, including through your use of our website(s), when you contact or request information from us, subscribe to our newsletter/e-bulletins, and when you engage us to provide you with our services and/or enter into a contract with us.
- The types of personal data we may collect from you will depend on the nature of our relationship with you, the work that we are carrying out for you and the context in which we obtain, use and/or process personal data. We have grouped together and summarised the types of personal data that we may collect from (or about) you (which is not exhaustive) as follows:
The following information is a descriptive list of the types of data we may process, with examples:
- How is your personal data collected?
- We collect personal data for a variety of reasons and through different media to include:
- if you are our client, when you enter into a contract with us to enable us to carry out services for you or an entity that you are involved in;
- if you are one of our suppliers, when we enter into a contract for the supply of your goods and/or services to ensure that the contractual arrangements between us can be properly implemented and performed;
- if you apply for a job with us to assess your suitability for the role; and/or
- if you make an enquiry about us or our services, to deal that enquiry and/or respond to that enquiry.
- We collect personal data via a variety of different sources including:
- through your use of our website(s), including when you contact us with an enquiry by completing and submitting your details via our “contact us” form and/or when you email us, if you submit comments to our blogs and/or you sign up to our newsletter. As you interact with our website(s), we may automatically collect Technical Data and Usage Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies. Please see our Cookie Policy https://cyfor.co.uk/cookie-policy/ for further details;
- we collect personal data from our clients to enable us to carry out our services;
- direct from a third party such as from your employees, colleagues or other parties involved in a case that we are dealing with;
- publicly accessible sources such as social media platforms and/or Companies House; and/or
- other third parties including law enforcement agencies and/or the criminal records office (on the specific instructions of our clients).
- On what basis do we process your data?
- We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- if it is necessary for our performance of a contract with you, or for us to take steps prior to entering into a contract with you;
- if it is necessary for the purposes of our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests. To determine this, we make sure that we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted by law); and/or
- where we need to comply with a legal, accounting and/or statutory reporting requirement.
- We may also issue you with a separate privacy notice giving more detail as to how the data you provide (and/or we obtain) may be processed.
- Generally, we do not rely on consent as a legal basis for processing your personal data. If your consent is required, we will notify you separately and if you provide your consent, you will be able to withdraw it at any time by contacting us https://cyfor.co.uk/contact-us.
- We may obtain personal data even if you are not our client in the course of providing services to our clients. We are permitted to use such information because it is in the legitimate interests of our client(s) to do so. We may also have to use your personal data to comply with our legal and/or reporting obligations.
- We have set out in the Appendix to this Privacy Notice, a more detailed description of the ways we may use and process your personal data and which of the legal bases and condition(s) we rely on to do so, including any additional conditions we rely on when processing Criminal Data. We have also identified what our legitimate interests are, where appropriate.
- Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data.
- We do not use your information for automated decision making.
- Sensitive Data and Criminal Data
- We may collect and process Sensitive Data in the following circumstances:
- from data provided to us from our client(s);
- where it is necessary when carrying out our services to meet our contractual obligations; and
- when making arrangements for you to attend a meeting, training session and/or interview and ensuring accessibility and catering for your dietary requirements.
- We only collect and process Criminal Data when instructed to lawfully do so on behalf of our duly authorised client(s) and on their specific instructions in accordance with our contract with them and, in doing so, we act as a data processor in relation to such Criminal Data. In such circumstances, our clients determine the purposes and means of processing and generally we are engaged to securely host Criminal Data and provide our clients with a secure platform to access such data. Our processing of Criminal Data is only carried out under the control of an official authority and/or as authorised by law.
- Change of purpose
- We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. It may not always be apparent at the outset what data we may require, who we may need to obtain it from and/or share it with as this will depend on the nature of the work and how the case progresses.
- If you wish to have an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us https://cyfor.co.uk/contact-us.
- If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
- Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
- Marketing communications
- As part of the services we provide to our clients, we may use personal data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you and/or your business.
- We have a legitimate interest in processing your personal data and information for our business development. We will only send marketing communications to you if you have requested information from us and you have not opted out of receiving that marketing.
- We will only share your personal data with third parties for marketing purposes with your express consent and you can withdraw that consent (if provided) at any time by contacting us https://cyfor.co.uk/contact-us.
- You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you and/or by contacting us at any time https://cyfor.co.uk/contact-us.
- Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of your use of our services and/or under a contract that you have entered into with us.
- Any comments or information that you upload on any CYFOR blog is publicly available. If your information appears on our blog pages and you require it to be removed, you should contact our marketing department at contact@cyfor.co.uk.
- Cookies
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our websites may become inaccessible or not function properly. For more information about the cookies we use, please see our Cookie Policy https://cyfor.co.uk/cookie-policy/.
DATA SHARING
- Who do we share your personal data with?
- We may (depending on the nature of the services we are providing, and the work involved) have to share personal data with other third parties and they may also share the personal data they hold about you with us. This may include:
- solicitors, accountants, legal counsel, and other professionals when providing our services;
- courts, tribunals, arbitrators and/or mediators where we are asked to provide our expert witness and/or e-disclosure services;
- if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, to protect the rights, property, or safety of CYFOR, our clients, or others;
- our IT and telecommunications system providers acting as data processors as a consequence of them providing support to us;
- our software providers to include Relativity;
- analytics and search engine providers that assist us in the improvement and optimisation of our website(s);
- our third-party service providers to include external consultants, contractors, couriers and suppliers;
- if in our reasonable opinion disclosure is required in relation to any criminal investigation or prosecution;
- disclosures to law enforcement agencies, tax authorities, the National Crime Agency or other public or government authorities or regulators where in our reasonable opinion the disclosure is required or permitted by law or applicable regulation; and/or
- in the event that CYFOR sell or buy any business or assets, with the prospective seller or buyer of such business or assets. If a change happens to the ownership of our business, then the new owners may use your data in the same way as set out in this Privacy Notice.
- We require all third parties with whom your data is shared to respect the security and integrity of your personal data and to treat it in accordance with the law. We also impose contractual obligations on service providers to ensure they can only use your personal information to provide services to us and to you.
- We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
- We will not share your information with third parties for marketing purposes (unless you expressly consent to this).
- Information we collect about you from others
- Information about you may be passed to us by third parties and/or obtained from publicly available sources in the course of providing our services and/or complying with our legal obligations. Typically, these sources may include:
- professional advisors (such as accountants, legal counsel); and
- public sources where this relates to you or your organisation (for example, internet searches, your organisation’s website and public social media accounts).
- International transfers
- We will hold your personal data on secure servers within the European Economic Area (“EEA“). CYFOR does not routinely transfer personal data outside of the EEA.
- Some of the external parties in relation to a case may be based outside the EEA so their processing of personal data may involve a transfer of data outside the EEA.
- Whenever we transfer your personal data out of the EEA, we will seek to ensure a similar degree of protection is afforded to it by ensuring that appropriate safeguards are implemented. In some circumstances (particularly where data is to be transferred outside of the EU where data protection laws are not as strict), we may need your express consent to the transfer unless there is an overriding legal requirement to transfer the information.
- Information collected from you about others
- In the course of providing our services to you, we may need you to provide us with personal data about others (such as directors and employees in your organisation and/or persons to which your case relates).
- When you provide personal information to us relating to others, you must ensure that you are legally permitted to share this with us and all data disclosed should be complete, accurate and up to date. You should ensure that those individuals understand how their data may be shared and used by us.
DATA SECURITY
- What measures do we have in place to keep your data secure?
- We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those members of staff and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
- We will hold your personal data on secure servers with all reasonable technological and operational measures to safeguard unauthorised access to include firewalls, gateways, security configuration and malware protection.
- We have gained several accreditations for managing information security effectively (particularly against cyber-attacks) to include IASME Governance, Cyber Essentials Plus, ISO 27001 and ISO 9001 (frameworks for best practice in information security management).
- If we provide you with a username and password which enables you to access certain parts of our systems (e.g. our eDiscovery platform), you are responsible for keeping such log-in details confidential. You must not share such information with anyone.
- We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
DATA RETENTION
- How long will we use your personal data for?
- We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including:
- for the purposes of satisfying any legal, accounting and/or reporting requirements;
- to investigate and defend any complaints and/or legal claims alleged and/or made against us (such as professional negligence claims);
- to carry out our services under our contract with you; and
- to comply with our legal and/or reporting obligations.
- In some circumstances you can ask us to delete your data. See your rights below for further information.
- If we are hosting and/or holding data on your behalf, we will contact you and obtain your instructions before destroying any such data.
YOUR DATA PROTECTION RIGHTS
- What are your rights in connection with the data that we hold?
- Under certain circumstances, you have rights under data protection laws in relation to your personal data. You have the right to request:
- access to your personal data (commonly known as a “data subject access request”). This enables you to receive details of the personal data we hold about you and to check that we are lawfully processing it;
- correction of the personal data that we hold about you. This enables you to have any incomplete, inaccurate or out-of-date data we hold about you corrected and/or updated, though we may need to verify the accuracy of the new data that you provide to us;
- erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons (as explained above in relation to data retention) which will be notified to you, if applicable, at the time of your request;
- object to processing of your personal data where we are relying on a legitimate interest (or that of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms;
- restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
(i) if you want us to establish the data’s accuracy;
(ii) where our use of the data is unlawful, but you do not want us to erase it;
(iii) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
(iv) you have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it; and
- transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a retainer with you.
- How can you exercise your rights?
- If you wish to exercise any of the rights set out above, please contact our DPO https://cyfor.co.uk/contact-us.
- You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in those circumstances.
- We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise your rights). This is a security measure to ensure that personal data is not disclosed to any person who may not have a right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
- We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
- Please note that if you:
(i) want us to restrict or stop processing your data;
(ii) fail to provide data that we have reasonably requested from you; or
(iii) withdraw consent at any time where we are relying on consent to process your personal data, this may impact on our ability to provide our services to you and/or contract with you. Depending on the extent of your request and/or the importance of any information we request from you that you do not provide, we may be unable to continue providing our services to you. We will notify you if this is the case at the time. This will not affect the lawfulness of any processing carried out before your withdrawal of consent. In these situations you would remain liable for the cost of our services up until the date of your request and/or refusal to provide information.
- Are there any restrictions on exercising your rights?
- You should be aware that when providing our services to law enforcement agencies, regulatory authorities and/or legal representatives in the context of litigation and/or potential litigation (both civil and criminal), there may be restrictions on the rights of data subjects (where appropriate and necessary) as follows:
- where such data is subject to legal privilege;
- to avoid obstructing an investigation or enquiry;
- to avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties;
- to protect public security;
- to protect national security; and/or
- to protect the rights and freedoms of others.
- In addition, it may be that we are not the data controller of your personal data (particularly in relation to Case Data, Sensitive Data and/or Criminal Data) and so requests to exercise your rights should be made to the relevant data controller.
- In the event that any of the above restrictions apply to your rights, we will confirm this to you (to the extent that we are able to without breaching our legal obligations).
CHANGES TO OUR PRIVACY NOTICE
Any changes we make to our Privacy Notice in the future will be posted on our websites and, where appropriate, notified to you by email. Please check back frequently to see any updates or changes to our Privacy Notice.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
COMPLAINTS
If you wish to raise a complaint on how we have handled your personal data, you can contact us to have the matter investigated by writing to or emailing our DPO https://cyfor.co.uk/contact-us.
If you are not satisfied with our response or believe we are not processing your personal data in accordance with the law you can complain to the ICO, the UK supervisory authority for data protection issues. Further details can be found at www.ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance https://cyfor.co.uk/contact-us
Appendix – Data Processing