Pirvacy Policy
This Privacy Policy explains in detail how we collect, use, share, and protect your personal information when you interact with us. It will also provide you with a better understanding of your rights relating to your personal data and how you can exercise those rights.
We encourage you to take time and carefully read the sections below. You must also show this Privacy Policy to anyone whose personal information you have shared with us as it may also apply to them.
This Privacy Policy works in conjunction with our P08H Retention and Back Up of Records and Data Procedure.
Updating this Privacy Policy
We reserve the right to amend or update this Privacy Policy at any time and in response to changes in the Data Protection Legislation. We will notify you of any changes we consider to be significant, but it is important that you come back from time to time to check for any updates and to ensure that you are happy with them.
Who we are?
We are PV Fit Ltd t/a Genfit at CoWorkz Business Centre, Minerva Avenue, Chester, CH1 4QL.
Personal information
Personal information is information about you from which you can be identified. Dependent on which service you receive from us, we will process different types of information about you. We will not process any personal information about you that we do not actually need in order to provide our services to you.
What personal information we collect?
The types of personal information we collect include:
- personal details, such as title and your full name;
- contact details, such as email address, mobile number, landline phone number and alternative phone number;
- home address, including house name/number, postcode, street name, town and county;
- credit/debit card details, such as the 16 digit card number, name stated on the card, expiry date, and CV2 number. We only provide the mechanism which collects this information, but it is never transmitted through or stored within our systems;
- records of your communication with us, such as call recordings, emails, text messages, survey comments, complaints regarding our products or services, made in any form, including complaints made orally, by email, letter and/or by online contact form submissions;
- information relating to contests or any promotions entered;
- marketing communication, such as your response to marketing from us or through our third parties;
- telemetry information, such as your mobile phone location data and IP address (which is a unique number identifying your computer), all web pages viewed, server requests, details of the browser (including browser type, timings, connections, updates and exceptions), and details of the device you are connected with;
What are our legal grounds and purposes for collecting your personal information?
It is necessary in order for us to provide you with our products and services, such as:
- to fulfil our contractual and regulatory obligations in providing you with our products and services. This will include providing you with the appropriate quotation as well as administering your order, or issuing documentation to you;
- to anonymise, combine, carry out research, analysis and other automated decision making to decide whether to offer you a product and/or service and the price or to create new products.
Because we have a justifiable reason, such as:
- keeping records about you and our correspondence with you. This is so that we can appropriately and effectively manage our relationship with you. We may also have to keep such records to satisfy any legal and regulatory obligations;
- as well as satisfy any legal and regulatory obligations we may have to keep such records;
We have your consent or explicit consent:
- to send you direct marketing communications to keep you informed of our products and services, or other carefully selected offers which we believe may interest you);
If you do not provide the personal information that we request or if you object to your data being processed by automated decision-making, then we will not be able to provide you with our products and services.
Disclosing and sharing your information
We will only disclose/share information about you in the following circumstances:
- in the event that we undergo re-organisation or are sold to a third party, in which case you agree that any personal information we hold about you will be transferred to that re-organised entity or third party;
- it has been authorised by you;
- it is required by law;
- in case you make a complaint to us about the service and products we have provided, we may be obliged to forward details about your complaint, including your personal information, to Contractors and Suppliers.
- it is being provided to suppliers as required to fulfil our contractual and legal obligations, and in which case your personal data will be limited to the minimum ordinarily required for services and products provided.
Your Rights
Under the Data Protection legislation, you have a number of rights relating to the information we hold about you. This includes the right to:
- ask for a free copy of any personal data we hold about you;
- ask for correction of any inaccurate information held about you;
- object to the use of your personal data for direct marketing;
- withdraw any permission you have previously given to us to process your personal data except where this is critical to us fulfilling our contractual and legal obligations;
- ask for your personal data to be deleted from our system/database. Please note that there are times when we will not be able to delete your data. This may be as a result of us fulfilling our legal and regulatory obligations, or where there is a minimum statutory period of time for which we have to keep your information. If we are unable to fulfil a request, we will always let you know our reasons;
- not to be subject to an automated decision making (without human involvement) where that decision produces a legal or significant effect on you. This means you can ask that we involve one of our members of staff in the decision-making process;
- obtain, move, copy or transfer your personal information in a format which enables you to transfer that personal data to another organisation. You may ask to have your personal data transferred by us directly to the other organisation, if this is technically feasible;
- complain to the Information Commissioner’s Office if you are not satisfied with our use of your data (https://ico.org.uk).
Should you wish to exercise any of your rights under the Data Protection legislation, please direct your enquiry to our Accounts Manager at invoicing@genfit.co.uk.
Information Security
Your data is considered to be an important asset to us, and as such, we make reasonable effort to ensure the necessary measures are in place to prevent unauthorised or inappropriate access, use, modification, disclosure or destruction.
Other measures we take to keep your data secure include, but are not limited to:
- making regular backups of files;
- protecting file servers and workstations with virus scanning software;
- using a system of passwords so that access to data is restricted;
- allowing only authorised staff into certain computer areas;
- using data encryption techniques to code data when in transit;
- ensuring that staff are only given sufficient rights to any systems to enable them to perform their job function.
Retaining your information
We will only keep your data for as long as is necessary to provide our products and services to you and/or to fulfil our legal and regulatory obligations.
Links to Other Websites
In our website there are certain links, including hypertext links, will lead you to website or pages that are not under our control. These links are provided for your information and convenience and the inclusion of any link does not imply endorsement by us in any way of the site to which a particular link leads. We accept no responsibility or liability for the content of other websites. If you are redirected to another website via our website, you will need to contact that organisation separately to remove your details from their records. No one may link into this site without prior written consent.
The policy will be reviewed at regular intervals to ensure that it continues to be effective.
Privacy Statement Summary
In this Privacy Policy (“Policy“), we provide details about how PV Fit Ltd, also known as Genfit (“we”/ “us” / “our”), collects, uses, and shares your information. We are located at Evans Business Centre, Minerva Avenue, Chester, CH1 4QL.
This Policy is relevant when we act as a Data Controller, meaning we determine how and why personal data, such as that of our website visitors, service users, clients, partners, etc., is processed.
Who Will Use My Data?
PV Fit Ltd t/a Genfit
What For?
We will store and process your data in order to allow us to provide our products and services. This includes managing customer accounts, processing orders, and ensuring the delivery of requested products and services.
If you contact us we may use personal data to send relevant information, such as updates, offers, and related products and services to its customers.
Genfit also complies with legal requirements to share information with authorities and other organisations when necessary.
What Will Happen If I Contact You?
If you get in touch with us, we may provide you with information that we believe will be of interest to you. This information can include details about our products and services, as well as related offers. We will also address your inquiries and provide assistance as needed.
What Data Will Be Stored?
The types of personal data collected include personal details, contact information, home address, financial data (in some cases), communication records, contest or promotion-related data, responses to marketing, and telemetry information.
What Data Will Be Shared?
We may share your personal data with other parties under certain conditions, as explained in this Privacy Policy. These situations include:
- Reorganization or Sale: If we undergo a reorganization or are sold to a third party, your personal data may be transferred to the reorganized entity or the acquiring third party.
- Authorized by You: If you provide your authorization for the sharing of your personal data, we may do so.
- Legal Requirements: We may share your personal data when required by law.
- Complaints: If you file a complaint with us about our services or products, we may forward relevant details, including your personal data, to Contractors and Suppliers.
- Suppliers: We may share your personal data with suppliers to fulfill contractual and legal obligations, but this sharing will be limited to the minimum information required for providing services and products.
How Long?
We retain your data for the necessary duration to provide our products and services to you and to meet our legal and regulatory obligations. The specific length of time we keep your data depends on the type of data and its intended purpose. It’s important to emphasize that we strictly adhere to the legal requirements in the UK regarding data retention, which may entail retaining your data for a minimum statutory period as mandated by law.
The exact duration of data retention can vary, and we always ensure compliance with the relevant data protection and privacy laws in the UK. For precise information about data retention periods for different types of data, please refer to our Data Retention Policy or feel free to contact us for more details.
Who Can Access My Data?
At Genfit, we take your data privacy seriously, and we want you to know that we handle your data with care and responsibility. Only authorized individuals and entities are granted access to your data, and this access is strictly controlled to ensure your privacy and security. These authorized parties include:
- Our Genfit Team: Our team members access your data as needed to provide our services, respond to your inquiries, and effectively manage our relationship with you.
- Trusted Third-Party Suppliers: In some situations, we may share your data with reputable third-party suppliers, but only to the extent required for them to fulfill their contractual and legal obligations while providing services and products.
- Compliance with Legal and Regulatory Authorities: We may disclose your data to adhere to legal and regulatory requirements, as mandated by law or in response to official requests.
- Reorganization or Sale: If Genfit undergoes reorganization or is acquired by a third party, your personal information may be transferred to the reorganized entity or the acquiring third party.
Rest assured, we are committed to protecting your data and ensuring that it is handled responsibly in compliance with the law and our Privacy Policy. If you have any questions or concerns regarding data access or privacy, please feel free to reach out to us for further information and assistance.
How Is My Data Kept Secure?
At Genfit, we prioritize the security of your data. We employ various technical and organizational security measures to protect it from unauthorized access and misuse, including regular backups, virus scanning software, access controls, restricted access areas, data encryption, and limited access rights for staff.
Our commitment to data security is unwavering, and we continually enhance our measures to ensure the confidentiality and integrity of your information. Your trust in our data security is our top priority.
About This Privacy Policy
This Privacy Policy outlines our procedures for the collection, storage, and processing of your information. We adhere to the General Data Protection Regulation (GDPR), which governs the fair and lawful handling of personal data. GDPR is guided by eight key principles:
- Fair and lawful processing of data.
- Collection for specific, lawful purposes.
- Data adequacy, relevance, and non-excessiveness.
- Ensuring accuracy and currency of data.
- Limited data retention duration.
- Data processing in line with data subjects’ rights.
- Employing appropriate data protection measures.
- Restricting data transfers outside the UK to regions with adequate protection.
We are committed to upholding these principles and safeguarding your data.
This policy serves to mitigate data security risks, including breaches of confidentiality, ensuring choice, protecting our reputation, and addressing risks inherent in data collection, storage, and processing. Your data security is our priority.
Who We Are And How To Contact Us
PV Fit Ltd t/a Genfit is registered in England and Wales and is registered with the Information Commissioner’s Office. The Data Protection Lead is Lauren Davies. You can contact us in any of the following ways:
Name of Data Protection Lead: Lauren Davies
Company name: PV Fit Ltd t/a Genfit
Data Protection Lead Address:49-50 CoWorkz Business Centre, Minerva Avenue Chester Cheshire, CH1 4QL
Data Protection Lead Number: 0344 567 9032
Who This Privacy Policy Applies To
This policy relates to data subjects of PV Fit Ltd t/a Genfit including clients, customers, suppliers, partners, employees, and all other individuals. Processing of your data is required in order to offer you our products and services and to run our company. It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the GDPR. This can include:
- Names of Individuals
- Contact details
- Postal addresses
- Email Addresses
- Telephone numbers
- And other information as required.
What This Policy Applies To
This policy applies to the following:
- Information you provide when contacting us.
- Information gathered during discussions about our services.
- Data associated with your website usage.
- Details related to services, financial transactions, and other personal information essential for completing transactions.
- Information stored as part of our ongoing business relationship.
- Data acquired through our interactions.
- Information obtained from external sources.
- Data maintenance and servicing based on the information we hold.
We typically do not handle sensitive data; however, in instances where we do, we maintain appropriate safeguards to protect your information.
How Your Information Will Be Used
We will only use your personal data for the purposes for which we collected it and as you would reasonably expect your data to be processed and only where there is a lawful basis for such processing, for example:
We may collect and process information about you, including your name, address, date of birth, address, contact details (including email address and mobile phone number), annual Consumption. We may take personal information from a range of sources.
We use this information for the reasons we collected it. Sometimes, with your permission or when there’s a good reason allowed by the law, we may use your info to tell you about things like special offers.
This document explains how you can change your mind about getting these messages. Even if you say no to marketing messages, we can still send you important messages about the services we provide with important services communications, including communications in relation to any services we provide to you.
You’ll only get marketing messages from us if:
- You asked us for information.
- You told us it’s okay to send you marketing when you shared your details.
- You didn’t say no to getting marketing messages.
- We have a good reason allowed by the law.
We’ll always ask for your clear permission before we share your info with other companies for marketing.
How To Change Your Preferences
We operate in line with the GDPR data protection guidelines. We respect your rights and will respond to any request for access to personal information and requests to delete, rectify, transfer, data and to stop processing. We will also advise you on how to complain to the relevant authorities. Where possible any requests or objections should be made in writing to the Data Controller, or you can visit our website, call, or email us to contact us to exercise your rights, make a complaint, or change your preferences at any time.
Opting Out At A Later Date
Where you give your consent for us to process your data, for example when you agree to us sending you marketing information or where you agree to us processing financial data, you can contact us to amend or withdraw your consent at any time. You can also choose to object to processing and request deletion of your data. We respect all user rights as defined in GDPR. If you have any comments or wish to complain please contact us.
How We Store And Process Your Data
Your data will be collected, stored, and processed securely, where we transfer your data internationally, we will ensure we take appropriate precautions to protect this data. Your data will normally be stored for up to 7 years in order to meet our legal obligations and protect our interests.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to find out more about how the processing for the new purpose is compatible with the original purpose, please email us. If we need to use your personal data for a purpose unrelated to the purpose for which we collected the data, we will notify you and we will explain the legal ground of processing.
We may be legally obliged to disclose your personal information without your knowledge to the extent that we are required to do so by law; in connection with any ongoing or prospective legal proceedings; in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk); to any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in our reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information.
Genfit is committed to enhancing the quality of our services. To achieve this, we may implement artificial intelligence (AI) technologies to improve user experiences, personalize content, and streamline processes. These AI systems will process data for the purpose of enhancing the services we provide. We ensure that these technologies are implemented in compliance with data protection regulations.
Our Obligations
We are a Data Controller. In relation to the information that you provide to us, we are legally responsible for how that information is handled. We will comply with the GDPR in the way we use and share your personal data.
Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:
- Request access to your personal data.
- Request correction of your personal data.
- Request erasure of your personal data.
- Object to processing of your personal data.
- Request restriction of processing your personal data.
- Request transfer of your personal data.
- Right to withdraw consent.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We aim to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Third Parties
We may have to share your personal data with selected third parties in order to meet our obligations to you and for the purposes described in this document:
- Service providers who provide IT and system administration services.
- Third parties including data processors, suppliers, service providers, equipment providers, and other third parties as required to run and grow our business.
- Professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, credit scoring, banking, legal, fraud protection, insurance and accounting services.
- Other technology companies providing tracking, analytics, and advertising companies.
- Social media companies.
- Companies in our Group of companies.
- Partners and other organisations involved in the provision of our services to you and as required to operate our company.
- Government organisation, regulators, other legal authorities and other relevant jurisdictions who require reporting of processing activities in certain circumstances.
- Third parties to whom we sell, transfer, or merge parts of our business or our assets.
- Other companies as required to meet our obligations to you and run our business.
We require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.
Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know such data. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
Where required under GDPR will report any breaches or potential breaches to the appropriate authorities within 24 hours and to anyone affected by a breach within 72 hours. If you have any queries or concerns about your data usage, please contact us.
Our website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
Cookies
A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added, and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences. We use traffic log cookies to identify which pages are being used. This helps us analyse data about webpage traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.
Overall, cookies help us provide you with a better website by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.
As well as your ability to accept or reject cookies, we also require your permission to store cookies on your machine, which is why when you visit our site, you are presented with the ability to accept our terms of use, including the storage of cookies on your machine.
Contacting Us, Exercising Your Information Rights And Complaints
If you have any questions or comments about this Privacy Policy, wish to exercise your information rights in connection with the personal data you have shared with us or wish to complain, please contact: Lauren Davies, PV Fit Ltd t/a Genfit. We aim to process data protection requests within 30 days, SAR responses are usually free, but we reserve the right to charge for excessive or unfounded requests. We fully comply with Data Protection legislation and will assist in any investigation or request made by the appropriate authorities.
If you remain dissatisfied, then you have the right to apply directly to your local data protection authority. You can find the list at:
https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm