1. Introduction
Eltron Europe Ltd is committed to protecting the personal data of individuals it engages with, including customers, suppliers, employees, and other business contacts. This policy outlines how personal data is collected, processed, stored, and protected in line with applicable data protection legislation.
2. Purpose of This Policy
This policy ensures that Eltron Europe Ltd:
- Protects the rights and privacy of employees, clients, and partners.
- Complies fully with data protection laws and upholds best practices.
- Safeguards the company against potential data breaches.
- Maintains transparency in how it manages and stores personal data.
3. Applicable Data Protection Laws
Eltron Europe Ltd complies with the Data Protection Act 1998 and the UK GDPR. These laws apply to all forms of personal data, whether stored electronically, on paper, or by other means. We are committed to handling data lawfully, fairly, securely, and transparently.
Key Principles Include:
- Data must be processed lawfully, fairly, and transparently.
- Data should be collected for specific, legitimate purposes.
- Personal data must be accurate and kept up to date.
- Data must be stored securely and only for as long as necessary.
- Individuals have rights regarding their data, which must be respected.
- Data should not be transferred outside the EEA unless adequate protection is ensured.
4. Scope of the Policy
This policy applies to:
- All company directors, managers, employees, contractors, and third parties working with Eltron Europe Ltd.
- All personal data held by the company relating to individuals (e.g. names, contact details, etc.).
5. Data Protection Risks
This policy helps mitigate the following risks:
- Reputational damage from data breaches.
- Legal risks from non-compliance.
- Loss of trust due to unauthorised access or disclosure.
6. Responsibilities
Everyone at Eltron Europe Ltd has a responsibility to ensure personal data is handled properly. Specific roles include:
- Board of Directors: Overall legal compliance.
- Managing Director (David O’Donoghue): Oversees all data protection efforts, ensures training, responds to queries, and approves third-party data access.
- IT Department: Maintains data security systems, assesses third-party data services, ensures regular security updates and system checks.
7. Staff Guidelines
- Access to personal data is limited to those who need it.
- Strong passwords must be used and not shared.
- Data should not be shared informally or with unauthorised individuals.
- Personal data must be stored securely and deleted when no longer needed.
- Any concerns about data protection must be reported to a manager or the Data Protection Officer.
8. Data Storage
Paper-based data:
- Must be stored in locked drawers or filing cabinets.
- Should not be left unattended in public areas (e.g. printers, desks).
Electronic data:
- Protected with strong, regularly updated passwords.
- Not stored on personal devices or laptops.
- Stored only on approved servers or cloud platforms.
- Regular backups must be performed and tested.
9. Data Usage
- Personal data must not be shared via unsecured methods (e.g. email).
- Data must be encrypted when transferred electronically.
- Data should not be moved outside the EEA without appropriate safeguards.
- Screens should be locked when not in use to prevent unauthorised viewing.
10. Data Accuracy
Employees are responsible for keeping data accurate and up to date by:
- Verifying customer details regularly.
- Correcting inaccuracies promptly.
- Avoiding the creation of duplicate or unnecessary data records.
11. Subject Access Requests (SAR)
Under the UK GDPR, individuals have the right to request:
- Details about what personal data Eltron Europe Ltd holds about them.
- Access to that data.
- Corrections to inaccurate information.
- Information about how their data is being used.
To make a SAR:
Please email: sales@eltroneurope.com
(Note: A nominal fee may apply. Identity verification will be required. Response within 14 days.)
12. Law Enforcement Requests
Eltron Europe Ltd may disclose personal data without consent if required to do so by law enforcement or legal authorities, after verifying the legitimacy of the request.
13. Privacy Statement
Eltron Europe Ltd provides a clear Privacy Statement to all individuals, explaining:
- What data is collected and why.
- How it is processed and stored.
- Their rights and how they can exercise them.
Contact Us Regarding Data Protection
For any data protection queries or concerns, please contact:
📧 sales@eltroneurope.com