Who is collecting personal data about me?
We are HomeFix (Home Counties) Ltd trading as HomeFix.
Our office address is: Challenge House, Sherwood Drive, Bletchley MK3 6DP
Our registered address is: Staple House, LU6 1SU
Our company registration number is: 09081337
When you deal with HomeFix (Home Counties) Ltd, we will be the ‘controller’ of your personal information. A ‘controller’ is a company that decides why and how your personal information is processed.
What are your legal bases for processing my information?
GDPR – the law on data protection – sets out a number of different reasons for which an organisation may collect and process your personal data. We are allowed to collect your data with:
We can collect and process your data with your consent. This consent must be freely given, specific, informed and unambiguous (such as when you provide your email address so that we can send you our special offers).
We require your personal data to fulfil our contractual obligations or because you have asked us to do something before entering into a contract. For example, to provide information to you to answer an enquiry, or to provide a quotation if you request one from us).
We are able to process your personal data to comply with a common law or statutory obligation. For example, to comply with a HMRC investigation.
We require your data to pursue our legitimate interests in a way which might reasonably be expected as part of running our business and which does not materially impact your rights, freedom or interest. For example, we may contact you about potential installation dates or changes to the products we install.
When do you collect information about me?
• When you contact us with an enquiry
• When you engage us to work on your behalf
• When you attend exhibitions and engage with us at our stand
• When you enter our prize draws or competitions
• When you comment on or review our services
• When you engage with us on social media
What information are you collecting about me?
We collect your full name, address, postcode, telephone number, email address when you contact us with an enquiry or enter into a contract with us.
If you choose to pay by debit card your details will be directly entered into our World Pay terminal. We do not retain these details and World Pay is GDPR-compliant.
We will also collect social media username, if you interact with us through those channels, in order to respond to you.
Why are you collecting information about me?
We want to give you the best possible customer service and/or provide a detailed quotation for our products and services. We use your information to:
• Respond to your enquiries and requests
• Fulfil your requirements as per our engagement – such as organising deliveries of
materials and completing the work required.
• Process payments for work required and to prevent fraudulent transactions
• Administer any of our prize draws or competitions which you enter, based on your consent given at the time of entering.
• Develop and improve the systems and services we provide to you. (We’ll do this on the basis of our legitimate business interests, which falls within the remit of the General Data Protection Regulation.)
• To send you survey and feedback requests to help improve our service and the range of service we offer. These messages will not include any promotional content and do not require prior consent when sent by email or text message. We have a legitimate interest to do so as this helps make our services more relevant to you.
• Your social media username, if you interact with us through those channels, to help us respond to your comments, questions or feedback.
• To protect our business and your account from fraud and other illegal activities.
• With your consent, we will use your personal data to keep you informed by email
about special offers and news. You may opt out of receiving our updates at any time.
Who might you share my information with?
We will share your personal information with trusted third parties on the acceptance of a quotation and as part of the supply chain process. Everyone involved has signed a confidentiality agreement. The information involved is restricted to your name, address and contact details. For example, this may involve scaffolders, suppliers or sub-contractors so that they know the delivery or site address involved with your work.
How will you protect my data?
We know how much data security matters to all our customers. With this in mind we will treat your data with the utmost care and take all appropriate steps to protect it. Access to your personal data is password-protected, sensitive data (such as payment card information) is only taken over the phone and put directly into our “World Pay” terminal. (We do not retain these details.) World Pay is PCI DSS compliant, meeting GDPR requirements.
We regularly monitor our computer system for possible vulnerabilities and attacks.
Our email service is fully encrypted in transit using SSL/TLS and our website is protected in a datacentre which is fully GDPR compliant.
Data held in online systems are password protected and are GDPR-compliant (EU-based) or have certified compliance with the US Privacy Shield Framework, (EU-US-based).
How long will you keep my data for?
Whenever we collect or process your personal data, we’ll only keep it for as long as is necessary for the purpose for which it was collected.
What rights do I have?
You have the right to request:
• Access to the personal data we hold about you.
• The correction of your personal data when incorrect, out of date or incomplete.
• That we stop using your personal data for direct marketing (either through specific channels, or all channels).
• That we stop any consent-based processing of your personal data after you withdraw that consent.
Your right to withdraw consent:
• Whenever you have given us your consent to use your personal data, you have the right to change your mind at any time and withdraw that consent.
• You have the right to stop the use of your personal data for direct marketing activity through all channels, or selected channels. We must always comply with your request. You can stop direct marketing communications from us by clicking the ‘unsubscribe’ link in any email we send you, or by writing to: HomeFix, Challenge House, Sherwood Drive, Bletchley MK3 6DP
• In cases where we are processing your personal data on the basis of our legitimate interest, you can ask us to stop at any time. However – we will not be able to keep you informed of important, relevant updates about our services. For example – you will need to know about any changes to our term and conditions.
Checking your identity
To protect the confidentiality of your information, we will ask you to verify your identity before proceeding with any request you make under this Privacy Notice. If you have
When you place an order with us we will keep the personal data you give us for six years so
we can comply with our legal and contractual obligations.
authorised a third party to submit a request on your behalf, we will ask them to prove they have your permission to act.
Enquiries and concerns
If you think that there is a problem with the way we are handling your data you have the right to complain to us. If you do not get a response within 30 days, you can complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF.
The Data Protection Officer at HomeFix is the Managing Director and can be contacted at firstname.lastname@example.org or by writing to HomeFix, Challenge House, Sherwood Drive, Bletchley MK3 6DP.