Email: info@reg-1.com
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights which are in brief set out below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
If you make a request, we must respond to you without undue delay and in any event within one month.
To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.
Our lawful bases for the collection and use of your data
Our lawful bases for collecting or using personal information to provide and improve products and services for clients are:
Our lawful bases for collecting or using personal information for the operation of client or customer accounts are:
Our lawful bases for collecting or using personal information for the operation of client or customer accounts are:
Our lawful bases for collecting or using personal information for recruitment purposes are:
Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:
NAME | ROLE | STATUS |
---|---|---|
Customer Contracts | 6 years after termination | Retained for potential legal claims or disputes. |
Billing and Payment Records | 7 years | Includes invoices, receipts, and payment history. |
Customer Support Records | 2 years | Ensures continuity of service and dispute resolution. |
User Account Data | Retain while active + 1 year | Deleted or anonymized after account closure unless required by law. |
Marketing Preferences | Until consent withdrawn | Regularly reviewed to ensure relevance and accuracy. |
Employee Data | 6 years after employment ends | Includes contracts, performance reviews, and training records. |
Audit Logs (Access/Activity) | 1 year | Retained for security and forensic investigations. |
Incident Reports (e.g., breaches) | 6 years | Retained to demonstrate accountability and compliance in case of audits. |
Development Data (e.g., logs) | 90 days | Ensures technical troubleshooting and service continuity. |
Cookies and Tracking Data | Retain as per cookie policy (max 13 months) | Retention should be stated in your Cookie Policy and user consent obtained. |
Backup Data | 6 months after deletion of primary data | Periodically reviewed and purged to ensure compliance with retention policies. |
Vendor Contracts | 6 years after termination | Retained for potential disputes or audits. |
Compliance Records | 7 years | Includes GDPR Data Protection Impact Assessments (DPIAs) and data breach records. |
Recruitment Data | 6 months | Candidate data retained only as long as necessary for hiring purposes. |
Health and Safety Records | 3 years | Includes workplace incident reports. |
If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.
If you remain unhappy with how we've used your data after raising a complaint with us, you can also complain to the ICO.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Accept Cookies