Privacy Policy
Majenta Solutions Limited respects your privacy and is committed to protecting personal data. This notice explains how we collect and use personal data, the safeguards that apply and the rights available under UK data-protection law.
- Important information and who we are
- The data we collect about you
- How personal data is collected
- How we use personal data
- Disclosure of personal data
- International transfers
- Data security
- Data retention
- Your legal rights
- Glossary
1. Important Information and Who We Are
Purpose of this privacy notice
This privacy notice explains how Majenta Solutions Limited collects and processes personal data. Our website is not intended for children and we do not knowingly collect personal data relating to children.
Please read this notice alongside any additional privacy or fair-processing information provided when we collect personal data for a particular purpose. Those notices supplement this policy rather than replacing it.
Controller
Majenta Solutions Limited, company registration number 03056978, is the controller responsible for personal data covered by this notice.
We have appointed a Data Privacy Manager to oversee questions relating to this privacy notice and requests to exercise legal rights.
Majenta Solutions Limited
3 Argosy Court, Scimitar Way, Whitley Business Park, Coventry CV3 4GA
+44 (0) 2476 308 500
You may complain to the Information Commissioner’s Office, the UK regulator for data-protection matters. We would appreciate the opportunity to address your concerns directly first.
Keeping information accurate
We keep this privacy notice under review. Please tell us if personal data you have provided changes during your relationship with us.
Third-party links
Our websites may contain links to third-party websites, plug-ins and services. Those third parties control their own privacy practices, and we encourage you to read their privacy notices when you leave our website.
2. The Data We Collect About You
Personal data is information relating to an identifiable individual. Anonymous information that cannot reasonably identify an individual is not personal data.
Depending on how you interact with us, we may collect and use:
- Identity Data: names, usernames or similar identifiers, title, date of birth, gender and related account information where relevant.
- Contact Data: billing or delivery addresses, email addresses and telephone numbers.
- Financial and Transaction Data: bank, payment and transaction information associated with products and services purchased from us.
- Technical Data: IP address, login information, browser and device details, operating system, time zone and similar technical information.
- Profile Data: account credentials, purchases or orders, preferences, feedback and survey responses.
- Usage Data: information about use of our websites and services.
- Marketing and Communications Data: preferences for receiving marketing and other communications.
We may also create aggregated statistical or demographic information. Where aggregated information is combined with other information so that an individual can be identified, we treat the combined information as personal data.
We do not intentionally collect special-category personal data or criminal-conviction information through our general website and commercial contact processes unless a separate service context and appropriate legal basis apply.
If you do not provide required information
Where information is required by law or to perform a contract and it is not provided, we may be unable to provide the relevant service or enter into the contract. We will explain the consequences when this applies.
3. How Is Your Personal Data Collected?
We use several methods to collect information, including:
- Direct interactions: information you provide through forms, correspondence, meetings, registration, enquiries, subscriptions, marketing requests, feedback or comments.
- Automated technologies: technical, usage and profile information collected through cookies, server logs and similar technologies when you use our websites and services.
- Third parties and public sources: information received from analytics providers, advertising networks, search-information providers and other legitimate sources where applicable.
4. How We Use Your Personal Data
We use personal data only where we have a lawful basis. Depending on the context, this may include performing a contract, complying with a legal obligation, pursuing legitimate interests where those interests do not override individual rights, or relying on consent where consent is required.
We may use personal data to register customers, process and deliver orders, manage payments, provide and support our services, manage our relationship with customers, administer and protect our business and websites, improve services, understand usage, communicate relevant updates and make appropriate service recommendations.
| Purpose | Typical data | Typical lawful basis |
|---|---|---|
| Register a new customer | Identity and Contact Data | Performance of a contract |
| Process and deliver orders, payments and charges | Identity, Contact, Financial, Transaction and Communications Data | Contract performance and legitimate interests such as recovering money owed |
| Manage the customer relationship and provide services | Identity, Contact, Profile and Communications Data | Contract, legal obligations and legitimate interests |
| Administer and protect our business, website and systems | Identity, Contact, Technical, Usage and Profile Data | Legitimate interests and legal obligations |
| Improve website content, services and marketing | Profile, Usage, Technical and Communications Data | Legitimate interests and consent where required |
Marketing
We aim to provide choices about marketing. Where consent is legally required for particular marketing activities, we will request it. You can opt out of marketing communications at any time using the unsubscribe method provided or by contacting us.
Cookies
You can configure your browser to refuse or alert you to cookies. Some website functions may not work correctly if certain cookies are disabled.
Change of purpose
We normally use personal data only for the purposes for which it was collected. If we need to use it for another compatible purpose, we may do so where permitted by law. If an unrelated purpose requires a different legal basis or notice, we will provide the required information.
5. Disclosure of Your Personal Data
We may share personal data with service providers and other external parties where necessary for the purposes described in this notice. This can include providers of IT and system administration, professional advisers such as lawyers, bankers, auditors and insurers, authorities where reporting is required, and fraud or crime-prevention organisations where the law requires or permits disclosure.
Information may also be disclosed in connection with a sale, transfer, merger, acquisition or restructuring of all or part of our business. Any successor would be expected to use personal data in accordance with applicable law and this notice.
We require service providers acting for us to protect personal data and use it only for authorised purposes and in accordance with our instructions.
6. International Transfers
Where personal data is transferred outside the United Kingdom, we use appropriate safeguards required by UK data-protection law. Depending on the destination and circumstances, this may include transfers to countries recognised as providing an adequate level of protection or the use of approved contractual safeguards.
Contact our Data Privacy Manager if you would like information about the mechanism used for a particular international transfer.
7. Data Security
We use appropriate technical and organisational measures intended to protect personal data from accidental loss, misuse, unauthorised access, alteration and disclosure. Access is limited to employees, agents, contractors and other parties who have a legitimate business need and who are subject to appropriate confidentiality obligations.
We maintain procedures for responding to suspected personal-data breaches and will notify affected individuals and regulators where the law requires us to do so.
8. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including legal, regulatory, tax, accounting and reporting requirements. We may keep information for longer where a complaint, claim or potential litigation makes this appropriate.
When determining a suitable retention period, we consider the amount, nature and sensitivity of the information, the potential harm from unauthorised use or disclosure, the purposes of processing, whether those purposes can be achieved in another way, and applicable legal or regulatory requirements.
Basic customer information including relevant identity, contact, financial and transaction records may need to be kept for six years after the customer relationship ends for tax and related legal purposes.
In some circumstances you may ask us to erase personal data, subject to applicable legal exceptions.
9. Your Legal Rights
Depending on the circumstances, UK data-protection law may give you rights to:
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete personal data;
- request erasure where there is no lawful reason for continued processing;
- object to processing based on legitimate interests in appropriate circumstances;
- request restriction of processing;
- request transfer of certain personal data to you or another organisation; and
- withdraw consent where processing relies on consent.
To exercise a right, contact our Data Privacy Manager using the details in section 1. We may need information to verify your identity and ensure personal data is not disclosed to someone without authority.
No fee usually required
You will not normally need to pay a fee to exercise these rights. A reasonable fee may be charged, or a request may be refused, where a request is clearly unfounded, repetitive or excessive and the law permits this.
Response times
We aim to respond to legitimate requests within one month. Complex or multiple requests may take longer, in which case we will explain the delay and keep you informed as required by law.
10. Glossary
Legitimate Interests
This means the interests of our business in conducting and managing our operations so we can provide effective and secure services. We consider the potential impact on individuals and their rights before relying on legitimate interests.
Performance of a Contract
This means processing personal data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract.
Comply with a Legal Obligation
This means processing personal data where it is necessary to comply with a legal obligation that applies to us.
External Third Parties
These can include service providers acting as processors, professional advisers, HM Revenue & Customs, regulators and other authorities, and fraud or crime-prevention bodies where disclosure is required or permitted by law.