Version: 1.1
Updated on: September 10th 2024
App.emerald-technology.com (“our platform”) is provided by Emerald Technology Consulting Group Limited and it’s Affiliates, trading as Emerald Technology “(we, our or us)”.
We are the controller of personal data obtained via our platform, meaning we are the organisation legally responsible for deciding how and for what purposes it is used.
We take your privacy very seriously. Please read this privacy policy carefully as it contains important information on who we are and how and why we collect, store, use and share any information relating to you (your “personal data”) in connection with your use of our platform. It also explains your rights in relation to your personal data and how to contact us or a relevant regulator in the event you have a complaint.
Privacy standards differ depending on where you are in the world. Due to our global footprint, we are subject to several data protection regulations. At Emerald Technology, we think that everyone deserves strong protection of their data regardless of where they are located. With that said, we will collect, store, process, and disclose personal data and apply the strictest regulation, including but not limited to to UK General Data Protection Regulation (“UK GDPR”), and EU General Data Protection Regulation (“EU GDPR”) to protect your data and privacy globally.
Where we refer to a “client”, we refer to the person, firm or company to whom we, or a third-party employer, provide employer of record services to, in relation to you.
Where we refer to a “third-party employer” we refer to any employer that employs you, at the request of a client.
Where we refer to “you”, we refer to an individual using the platform, whether as an employee of ours, an employee of a third-party employer or as a candidate for employment.
This privacy policy is divided into the following sections:
- What this policy applies to
- Personal data we collect about you
- How and why we use your personal data
- How and why we use your personal data – sharing
- Who we share your personal data with
- Who we share your personal data with — sub processors
- How long your personal data will be kept
- Transferring your personal data out of the UK and EEA
- Cookies and other tracking technologies
- Your rights
- Keeping your personal data secure
- How to complain
- Changes to this privacy policy
- Privacy of minors
- How to contact us
- Do you need extra help?
What this policy applies to:
This privacy policy relates to your use of our platform only.
Personal data we collect about you:
The personal data we collect about you depends on the information that you upload to the platform or that you otherwise share with us. We will collect, store and use the following personal data about you:
- Your name, address and contact information, including email address and telephone number;
- Date of birth;
- Photographic ID – such as passport;
- Your work contact details (i.e. place of work, work landline and mobile numbers and work email address)
- Details of salary and benefits, bank building society, National insurance contributions and tax information, your age;
- Details of your spouse/partner/ next of kin and any dependents;
- Details of your pension arrangements, and all information included in these and necessary to implement and administer them;
- Recruitment information (including copies of right to work documentation);
- Employment records (including job titles, work history, working hours, training records and professional memberships);
- Your account details, such as username and login details;
- Your activities on, and use of, our platform; and
- Information about how you use our platform and technology systems.
Depending on the location of your employment, we may also collect, store and use the following “special categories” of more sensitive personal data, such as:
- Your nationality and immigration status and information from related documents such as your passport or other identification and immigration information;
- Information about health (mental and physical), medical conditions and any disabilities; and
- Criminal record data
You must provide this personal data to be employed by us or by a third-party employer, unless we tell you that you have a choice.
Sometimes you can choose if you want to give us your personal data and let us use it. Where that is the case, we will tell you and give you the choice before you give the personal data to us. We will also tell you whether declining to share that personal data will have any effect on your use of our platform and/or whether we or a third-party employer can offer to employ you and/or continue to employ you.
We collect and use this personal data for the purposes described in the section ‘How and why we use your personal data’ below.
How your personal data is collected:
We collect personal data from you:
- Directly, when you enter or send us information, such as when you register with us, contact us (including via email or through the platform itself), communicate with us via the platform, post material to or upload material onto our platform; and
- Indirectly, such as your browsing activity while on our platform; we will usually
collect information indirectly using the technologies explained in the section on ‘Cookies and other tracking technologies’ below
We also collect personal data about you from our client and, if you are employed by a third-party employer, that employer.
How and why we use your personal data:
Under data protection law, we can only use your personal data if we have a proper reason, e.g.:
- Where you have given consent
- To comply with our legal and regulatory obligations
- For the performance of a contract with you or to take steps at your request before entering into a contract, or
- For our legitimate interests or those of a third party
A legitimate interest is when we have a business or commercial reason to use your personal data, so long as this is not overridden by your own rights and interests. We will carry out an assessment when relying on legitimate interests, to balance our interests against your own. You can obtain details of this assessment by contacting us (see ‘How to contact us’ below).
The information below explains what we use your personal data for and why.
-
Creating and managing your account with us
Purpose: So we can deliver an efficient service to our clients and any third-party employer. To perform our contract with you or to take steps at your request before entering into a contract with you or facilitating the entry into a contract by you with a third-party employer.
Processing Operation: Collecting and storing data relevant for the creation and administration of your account.
Relevant Categories of Personal Data: Your name, address, and contact information (including email and telephone number).
Lawful basis under UK and EU GDPR: Legitimate interests; so that we can efficiently deliver employer of record services to our client, by employing you or facilitating your employment by a third-party employer (where you are to be employed by a third-party employer).
Processing is necessary to take steps at your request before entering into a contract with you or facilitating the entry into a contract by you with a third-party employer.
-
To verify your employment history, education history and qualifications
Purpose: To undertake background checks and/or assess suitability for the role.
Processing Operation: Collecting and storing data relevant for the background checks and/or assess suitability for the role.
Relevant Categories of Personal Data: Educational/qualification certificates and similar. Employment records (such as including job titles, work history, working hours, training records and professional memberships).
Lawful basis under UK and EU GDPR: Legitimate interests; so that we can deliver employer of record services to our client, including pre employment checks.
Processing is necessary to take steps at your request before entering into a contract with you or facilitating the entry into a contract by you with a third-party employer.
-
Conducting checks to identify you and verify your identity or to help prevent and detect fraud against us, our client and/or the third-party employer
Purpose: To minimise fraud, that could be damaging for us and our client and (if you are employed by a third-party employer) a third-party employer.
Processing Operation: Depending on the circumstances, addressing and sending communications to you, our client, , a third-party employer, third party credit insurers and/or our advisors.
Relevant Categories of Personal Data: Your name, address, contact information (including email and telephone number), date of birth, ID such as passport or other photographic ID, National Insurance number.
Lawful basis under UK and EU GDPR: To comply with our legal and regulatory obligations; and/or
Legitimate interests, i.e., to minimise fraud that could be damaging for you and/or us and/or our client and/or a third-party employer (if you are employed or to be employed by a third- party employer).
-
Issuing a contract of employment to you and amendments to that contract (if necessary)
Purpose: So that we may provide employer of record services to our client, or facilitate the provision of such services to our client by a third-party employer (where you are to be employed or are employed by a third-party employer).
Processing Operation: Creation and issuance of an employment contract to you and any amendments thereto.
Relevant Categories of Personal Data: Your name, address, and contact information (including email and telephone number),
Lawful basis under UK and EU GDPR: Legitimate interests; to deliver employer of record services to our client and employ you or (in the event that you are to be employed by a third-party employer) facilitate of your employment by a third-party employer. Processing is necessary to take steps at your request before either (a) entering into a contract with you or (b) facilitating the entry into a contract by you with a third-party employer; and in either case to update the terms of that employment through the issue of amendments to that contract.
Purpose: So that we, or if you are employed by a third-party employer, that third party, can contact you.
Processing Operation: Depending on the circumstances, addressing and sending communications to you.
So that we or, if you are employed by a third-party employer, a third- party employer can contact you by letter, email, or phone where necessary in relation to your employment.
Relevant Categories of Personal Data: Your name, personal contact details (i.e. address, home and personal mobile numbers, personal email address)
Lawful basis under UK and EU GDPR: Where we employ you, our legitimate interest to comply with our obligations under our contract with you;
Legitimate interests: to maintain employment records and good employment practice on our behalf, or (where you are employed by a-third party employer) on behalf of a third-party employer.
-
Enforcing legal rights or defend or undertake legal proceedings
Purpose: To take such action as we deem appropriate to defend or pursue legal action.
Processing Operation: Depending on the circumstances, addressing and sending communications to you, our client, a third-party employer and/or our advisors.
Relevant Categories of Personal Data: Your name, address and contact information (including email address and telephone number).
Lawful basis under UK and EU GDPR: Depending on the circumstances:
—to comply with our legal and regulatory obligations
—in other cases, for our legitimate interests, i.e., to protect our business, interests and rights.
-
To contact your next of kin/emergency contact
Purpose: If we (or if you are employed by a third- party employer, that third-party employer) need to let your next of kin or emergency contact know there has been an emergency e.g. accident or illness.
Processing Operation: Depending on the circumstances, storing the name, contact details and relationship with you of your next of kin/emergency contact, addressing and sending communications to your emergency contact/next of kin. So that we/the third-party employer can contact your next of kin or emergency contacts by phone or by email where necessary.
Relevant Categories of Personal Data: Name, phone number, email address and relationship to you.
Lawful basis under UK and EU GDPR: Where we employ you, our legitimate interest to comply with our obligations under our contract with you; Legitimate interest; to maintain employment records and good employment practices on our own behalf (and/or where you are employed by a third-party employer on behalf of a third-party employer) ;
Legitimate interest: to contact your next of kin or emergency contact if required in case of emergency.
-
To enrol you/your spouse and/or dependants to any applicable benefit scheme and maintain/update that enrolment where required
Purpose: To ensure you and your spouse/partner and any dependants receive the correct benefits
Processing Operation: Depending on the circumstances, collecting and verifying personal and dependent details for enrolling in applicable benefit schemes. This includes gathering information, confirming eligibility, completing enrolment forms, and submitting necessary documentation. Ongoing responsibilities involve maintaining and updating enrolment records to align with any changes or scheme requirements.
Relevant Categories of Personal Data: Name, phone number, email address, relationship to you, date of birth, address.
Lawful basis under UK and EU GDPR: Where we employ you, to perform the employment contract including employment-related benefits, e.g. private medical insurance, life assurance and pension. Where you are employed by a third-party employer, to facilitate their performance the employment contract including employment-related benefits, e.g. private medical insurance, life assurance and pension.
Legitimate interest; to maintain employment records and good employment practices on our own behalf (and/or where you are employed by a third-party employer on behalf of a third-party employer.)
-
To allow for the administration of pay and benefits
Purpose: To ensure you receive the correct pay and benefits
Processing Operation: Depending on the circumstances, sharing your data with payroll administrators bank and tax authorities
Relevant Categories of Personal Data: Details of salary and benefits, bank/building society, national insurance contributions, P46, marital status and tax information, your age.
Lawful basis under UK and EU GDPR: Where we employ you, to perform the employment contract including payment of salary and benefits. Where you are employed by a third-party employer, facilitation of their performance the employment contract including employment-related benefits, e.g. private medical insurance, life assurance and pension.
Legitimate interest; to maintain employment records and good employment practices on our own behalf (and/or where you are employed by a third-party employer on behalf of a third-party employer.)
-
To enrol you into and facilitate your participation in a pension scheme
Purpose: To administer your pension benefits and/or to comply with our pension obligations or those of a third-party employer.
Processing Operation: Depending on the circumstances, collecting necessary personal details, confirming eligibility, completing enrolment forms, and submitting required documentation. Ongoing responsibilities encompass the facilitation and support of individuals’ participation in the pension scheme.
Relevant Categories of Personal Data: Details of your pension arrangement, and all information included in these and necessary to implement and administer these.
Lawful basis under UK and EU GDPR: Where we employ you, to perform the employment contract including employment-related benefits.
Where you are employed by a third-party employer, to facilitate their performance of that contract.
Where we employ you, to comply with our legal obligations.
Where you are employed by a third-party employer, to facilitate their compliance with their employment contract including employment-related benefit.
Legitimate interests: to maintain employment records and to comply with legal, regulatory and corporate governance obligations and good employment practice on our own behalf (and/or where you are employed by a third-party employer on behalf of a third-party employer).
-
If applicable, applying on your behalf/enrolling you for healthcare benefits to which you are entitled
Purpose: To obtain health insurance or the benefit of health insurance for you;
Processing Operation: Assessing eligibility, submitting necessary applications, and enrolling individuals into relevant healthcare programs. The process ensures that individuals receive the healthcare benefits they qualify for, and if applicable, facilitates the application or enrolment on their behalf.
Relevant Categories of Personal Data: Information about health (mental and physical), medical conditions and any disabilities
Lawful basis under UK and EU GDPR: Where we employ you, to perform the employment contract including employment-related benefits
Where you are employed by a third party employer, to facilitate their performance of that employment contract including employment-related benefits.
Where we employ you, to comply with our legal obligations
Legitimate interests: to maintain employment records and to comply with legal, regulatory and corporate governance obligations and good employment practice on our own behalf (and/or where you are employed by a third-party employer on behalf of a third-party employer.)
-
Retaining and evaluating information on your recent visits to our platform and how you move around different sections of our platform for analytics purposes to understand how people use our platform so that we can make it more intuitive or to check our platform is working as intended
Purpose: To optimise your experience of the platform and the experience of other users and to improve the platform our services.
Processing Operation: Utilizing pendo.io integration we collect and analyse user data to gain insights into platform interactions, optimize features, and personalize the user experience. This includes evaluating user preferences and feedback to enhance overall service quality.
Relevant Categories of Personal Data: Email address, Last visit, Number of active days, Average time per active day, Total time logged in, Pages you have visited, Time spent in each page, Number of clicks on platform features, Number of platform guides seen
Lawful basis under UK and EU GDPR: Depending on the circumstances:
—your consent as gathered by the separate cookies tool on our platform—see ‘Cookies and other tracking technologies’ below
—where we are not required to obtain your consent and do not do so, for our legitimate interests, i.e., to be as efficient as we can so we can deliver the best service to you at the best price.
If you have provided such a consent you may withdraw it at any time by changing the setting on the cookies tool and/or by following by emailing this email address: platform@emerald-technology.com
(this will not affect the lawfulness of our use of your personal data in reliance on that consent before it was withdrawn)
-
Protecting the security of systems and data used to provide the services
Purpose: To minimise the risk of unauthorised access to our systems and data.
Processing Operation: Our platform automatically registers and store user activity data which are used to implement robust security measures to prevent unauthorized access, detect and respond to potential threats, and ensure the overall resilience of the systems in use.
Relevant Categories of Personal Data: IP address; login time stamp information and web browser use
Lawful basis under UK and EU GDPR: To comply with our legal and regulatory obligations.
We may also use your personal data to ensure the security of systems and data to a standard that goes beyond our legal obligations, and in those cases our reasons are for our legitimate interests, i.e., to protect systems and data and to prevent and detect criminal activity that could be damaging for you and/or us.
-
Disclosures and other activities necessary to comply with legal and regulatory obligations that apply to our business, e.g., to record and demonstrate evidence of your consents where relevant and compliance with laws of the jurisdictions in which we are employer of record of an employee
Purpose: To comply with our legal and regulatory obligations.
Processing Operation: Depending on the circumstances, addressing and sending communications to you, candidates, employees, 3rd party vendors and/or our advisors.
Relevant Categories of Personal Data: Your name, address, contact information (including email and telephone number), company name, position within the company, payment method, ID such as passport, National Insurance number.
Lawful basis under UK and EU GDPR: To comply with our legal and regulatory obligations.
-
The audit of data (to the extent not covered by ‘activities necessary to comply with legal and regulatory obligations’ above) to ensure we continue to provider and maintain a legal and complaint solution (adhering to accreditations such as ISO27001 and SOC2)
Purpose: To ensure the policies and data stored are held to an accreditations to give comfort to our clients, partners and employees and to be as efficient as we can so we can deliver the best service to you.
Processing Operation: Collecting and storing data relevant for the creation and ongoing administration of your account.
Relevant Categories of Personal Data: Your name, address, contact information (including email and telephone number), company name, position within the company, payment method, as well as personal information such as passport, ID and other local in-country verification methods
Lawful basis under UK and EU GDPR: For our legitimate interests i.e., to maintain our accreditations so we can demonstrate we operate at the highest standards and/or to quality check the service that we provide to you and other customers.
-
To share your personal data with members of our group and third parties that will or may take control or ownership of some or all of our business (and professional advisors acting on our or their behalf) in connection with a significant corporate transaction or restructuring, including a merger, acquisition, asset sale, initial public offering or in the event of our insolvency.
Purpose: This may be required to comply with our legal and regulatory obligations or, in other cases, for us to protect, realise or grow the value in our business and assets.
Processing Operation: Collecting and storing data relevant for the creation and ongoing administration of your account.
Relevant Categories of Personal Data: Your name, address, contact information (including email and telephone number), date of birth, ID such as passport or other photographic ID, National
Lawful basis under UK and EU GDPR: Depending on the circumstances:
—to comply with our legal and regulatory obligations
—in other cases, for our legitimate interests, i.e., to protect, realise or grow the value in our business and assets.
How and why we use your personal data – special category personal data:
Certain personal data we collect is treated as special category to which additional protections apply under data protection law. Where we process such special category personal data, we will ensure we are permitted to do so under data protection laws.
-
To carry out right to work checks
Purpose: To ensure that you are entitled to work within the jurisdiction that you are to be employed
Processing Operation: Includes reviewing relevant documentation such as passports, visas, and work permits to ensure compliance with legal requirements.
Relevant Categories of Personal Data: Your nationality, immigration status and information from related documents such as your passport or other identification and immigration information
Lawful basis under UK and EU GDPR: To enter into/perform the employment contract (or to facilitate the entry into/performance by a third-party employer)
To comply with our legal obligations or to facilitate the compliance by a third-party employer such as the arrangement of visas.
Legitimate interest: to maintain employment records
To carry out obligations and exercise rights in employment law or facilitate the carrying out or exercise by a third-party employer.
Additional Condition: Consent
-
Administration of display screen equipment assessments and assessment of suitability of home working environment
Purpose: To ensure that the display equipment provided is suitable for your needs and further, that your home environment is suitable for working from home (if applicable)
Processing Operation: Includes attending your home or via a video call your work space to ensure compliance with legal requirements.
Relevant Categories of Personal Data: Information concerning your medical health
Lawful basis under UK and EU GDPR: To perform the employment contract;
Where you are employed by a third party employer, to facilitate their performance of that employment contract.
To comply with our legal obligations
Legitimate interests: to maintain employment records and to comply with legal, regulatory and corporate governance obligations and good employment practice, to ensure safe working practices To carry out and exercise obligations and rights in employment and social security law on our own behalf (and/or where you are employed by a third-party employer on behalf of a third-party employer);
Additional Condition: Consent
-
To assess your suitability for the role and to carry out statutory checks
Purpose: To assess whether you have any criminal convictions that would or could mean that you were unsuitable to be employed, or to continue to employed, in the relevant role
Processing Operation: Includes reviewing relevant documentation such as passports, personal ID and work history as well as conducting a background check to ensure compliance with legal requirements (CRC) or enhanced criminal records certificate (ECRC)
Relevant Categories of Personal Data: Criminal records data, including the results of Disclosure and Barring Service (DBS) checks in a criminal records certificate
Lawful basis under UK and EU GDPR: Legitimate interests: to assess whether you have any criminal convictions that would make you unsuitable for employment by us or a third-party employer in the role;
To comply with our legal and regulatory obligations and/or assist the third-party employer with compliance with their legal and regulatory obligations.
Additional Condition: Your consent
-
Administration and facilitation of payment and benefits
Purpose: To facilitate payment of benefits under permanent health insurance (PHI) or early retirement schemes.
Processing Operation: Includes reviewing relevant documentation such as your personal ID to ensure compliance with legal requirements.
Relevant Categories of Personal Data: Information in your sickness and absence records (including special category data regarding your physical and/or mental health
Lawful basis under UK and EU GDPR: To perform the employment contract including employment-related benefits;
Where you are employed by a third party employer, to facilitate their performance of that employment contract including employment-related benefits.
Where we employ you, to comply with our legal obligations.
Legitimate interests: to maintain employment records and to comply with legal, regulatory and corporate governance obligations and good employment practice, to ensure safe working practices To carry out and exercise obligations and rights in employment and social security law on our own behalf (and/or where you are employed by a third-party employer on behalf of a third-party employer);
Additional Condition: Your consent
How and why we use your personal data—sharing:
See ‘Who we share your personal data with’ for further information on the steps we will take to protect your personal data where we need to share it with others.
Who we share your personal data with:
We will routinely share your personal data with:
- The client;
- Where you are employed by a third party employer, that third party employer;
- Third parties we use to help us run our business , e.g. platform hosts, platform analytics providers;
- Third parties that help us comply with our legal and regulatory obligations, such as banks, pension providers and insurance providers;
We only allow those organisations to handle your personal data if we are satisfied they take appropriate measures to protect your personal data. We also impose contractual obligations on them to ensure they can only use your personal data to provide services to us and to you.
We or the third parties mentioned above occasionally also share personal data with:
- Our and their external auditors, e.g., in relation to the audit of our or their accounts, in which case the recipient of the information will be bound by confidentiality obligations;
- Our and their professional advisors (such as lawyers and other advisors), in which case the recipient of the information will be bound by confidentiality obligations;
- Law enforcement agencies, courts, tribunals and regulatory bodies to comply with our legal and regulatory obligations; and
- Other parties that have or may acquire control or ownership of our business (and our or their professional advisers) in connection with a significant corporate transaction or restructuring, including a merger, acquisition, asset sale, initial public offering or in the event of our insolvency—usually, information will be anonymised but this may not always be possible. The recipient of any of your personal data will be bound by confidentiality obligations.
Who we share your personal data with — sub processors:
We may engage third-party sub processors, suppliers, and other partners to assist us in providing and improving our services. These sub processors may have access to your personal data for the purpose of performing services on our behalf. We ensure that these providers comply with data protection regulations and have appropriate security measures in place that is consistent with this Privacy Policy and the agreements we enter into with them.
We use systems and other vendors to help us process personal data, such as:
Email hosting
Data Processing Purpose: To receive and send business communication
Internal and external instant messing
Data Processing Purpose: To facilitate internal employee collaboration and communicate with Resources and clients
Social media marketing tools and vendors
Data Processing Purpose: To recruit new employees, resources, and clients
Type of sub processors: Billing systems
Data Processing Purpose: To process payments and expenses
Payroll and expense management system/vendors
Data Processing Purpose: To provide the necessary employee services
Recruitment platform
Data Processing Purpose: To simplify
HR management software
Data Processing Purpose: HR systems integrated within the platform to make global HR management seamless to our clients
Background check vendor
Data Processing Purpose: Optional service for clients to run a background check on resources they wish to hire
Cloud services
Data Processing Purpose: We host all data collected within the platform in a secure cloud system
Contract management
Data Processing Purpose: To manage contract and collect e-signatures
Survey
Data Processing Purpose: To collect information and opinion from employees and clients
In addition, we will share your personal data with our client and, if you are employed by a third-party employer, with that third party employer. We will provide you with details as to who the client and any third-party employer are in your employment contract.
If we are involved in merger, acquisition, financing due diligence, bankruptcy, sale of all or a portion of our assets, your personal data and other information may be shared in the due diligence process with other parties who will be assisting with this transaction. In such event, we will use reasonable effort to help ensure that your personal information will be subject to appropriate privacy protection, in accordance with applicable data privacy law.
Emerald Technology does not sell and will not sell personal data to any third-party vendor. We only share data with third parties for whom we have contracted to provide a specific data processing purpose, such as payroll, or HR management. We may share your personal data to the extent that we are required by law, in connection with any legal proceedings or prospective legal proceedings.
If you would like more information about who we share our data with and why, please contact us (see ‘How to contact us’ below).
How long your personal data will be kept:
Unless required by law, we will not keep your personal data for longer than we need it for the purpose for which it is used.
Different retention periods apply depending on the country and the types of personal data.
If you stop using your account we will delete your account data after seven years. If you create an account with us but do not become our employee, or an employee of a third-party employer, we will anonymise all personal data within 12 months of your ceasing to use the account and we will delete that data seven years after you cease using the account.
Following the end of the of the relevant retention period, we will delete your personal data.
Transferring your personal data out of the UK and EEA:
The EEA, UK and other countries outside the EEA and the UK have differing data protection laws, some of which may provide lower levels of protection of privacy.
It is sometimes necessary for us to transfer your personal data to countries outside the UK and EEA. In those cases we will comply with applicable laws designed to ensure the privacy of your personal data.
If the client is located outside of the UK and EEA, we will transfer your personal data outside of the UK and EEA.
If the third-party employer is located outside of the UK and EEA, we will transfer your personal data outside of the UK and EEA.
As we are based in the UK we will also transfer your personal data from the EEA to the UK.
Under data protection laws, we can only transfer your personal data to a country outside the UK/EEA where:
- In the case of transfers subject to UK data protection law, the UK government has decided the particular country ensures an adequate level of protection of personal data (known as an ‘“adequacy regulation”’) further to Article 45 of the UK GDPR. A list of countries the UK currently has adequacy regulations in relation to is available https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-transfers-a-guide/#adequacy.
- In the case of transfers subject to EEA data protection laws, the European Commission has decided that the particular country ensures an adequate level of protection of personal data (known as an ‘“adequacy decision”’) further to Article 45 of the EU GDPR. A list of countries the European Commission has currently made adequacy decisions in relation to is available https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en.
- There are appropriate safeguards in place, together with enforceable rights and effective legal remedies for you; or
- A specific exception applies under relevant data protection law.
Where we transfer your personal data outside the UK we ensure that we follow adequate process to safely and privately transfer your data
In the event we cannot or choose not to continue to rely on either of those mechanisms at any time we will not transfer your personal data outside the UK unless we can do so on the basis of an alternative mechanism or exception provided by UK data protection law and reflected in an update to this policy.
Where we transfer your personal data outside the EEA we do so on the basis of an adequacy decision or (where this is not available) legally-approved standard data protection clauses issued further to Article 46(2) of the EU GDPR. In the event we cannot or choose not to continue to rely on either of those mechanisms at any time we will not transfer your personal data outside the EEA unless we can do so on the basis of an alternative mechanism or exception provided by applicable data protection law and reflected in an update to this policy.
Any changes to the destinations to which we send personal data or in the transfer mechanisms we rely on to transfer personal data internationally will be notified to you in accordance with the section on ‘Changes to this privacy policy’ below.
In addition, we will transfer your personal data with our client and, if you are employed by a third-party employer, with that third party employer.
If you would like further information about data transferred outside the UK/EEA, please contact us (see ‘How to contact us’ below).
Cookies and other tracking technologies:
A cookie is a small text file which is placed onto your device (e.g. computer, smartphone or other electronic device) when you use our platform. We use cookies on our platform. These help us recognise you and your device and store some information about your preferences or past actions.
For further information on cookies and our use of ‘cookies’, when we will request your consent before placing them and how to disable them, please contact us (see ‘How to Contact us’).
Your rights:
You generally have the following rights, which you can usually exercise free of charge:
- Access to a copy of your personal data:
The right to be provided with a copy of your personal data
A more detailed explanation of this right under UK law is available here: https://ico.org.uk/for-the-public/your-right-to-get-copies-of-your-data/
- Correction (also known as rectification):
The right to require us to correct any mistakes in your personal data
A more detailed explanation of this right under UK law is available here: https://ico.org.uk/for-the-public/your-right-to-get-your-data-corrected/
- Erasure (also known as the right to be forgotten):
The right to require us to delete your personal data—in certain situations
A more detailed explanation of this right under UK law is available here: https://ico.org.uk/for-the-public/your-right-to-get-your-data-deleted/
The right to require us to restrict use of your personal data in certain circumstances, e.g., if you contest the accuracy of the data
A more detailed explanation of this right under UK law is available here: https://ico.org.uk/for-the-public/your-right-to-limit-how-organisations-use-your-data/
The right to receive the personal data you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party—in certain situations
A more detailed explanation of this right under UK law is available here: https://ico.org.uk/for-the-public/your-right-to-data-portability/
The right to object:
-
- At any time to your personal data being used for direct marketing (including profiling)
- In certain other situations to our continued use of your personal data, e.g. where we use your personal data for our legitimate interests unless there are compelling legitimate grounds for the processing to continue or the processing is required for the establishment, exercise or defence of legal claims
A more detailed explanation of this right under UK law is available here: https://ico.org.uk/for-the-public/the-right-to-object-to-the-use-of-your-data/
- Not to be subject to decisions without human involvement:
The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. We do not make any such decisions based on data collected by our platform
A more detailed explanation of this right under UK law is available here: https://ico.org.uk/for-the-public/your-rights-relating-to-decisions-being-made-about-you-without-human-involvement/
- The right to withdraw consents:
If you have provided us with a consent to use your personal data you have a right to withdraw that consent easily at any time
You may withdraw consents by sending an email to platform@emerald-technology.com
Withdrawing a consent will not affect the lawfulness of our use of your personal data in reliance on that consent before it was withdrawn.
For further information on each of those rights, including the circumstances in which they do and do not apply, please contact us (see ‘How to contact us’ below). You may also find it helpful to refer to the guidance from the UK’s information commissioner on your rights under the UK GDPR. Where we are subject to EU law (if, for example, you have an establishment in the EU), you may find it helpful to refer to the guidance of the supervisory authority for that country. Further details can be found on the European Data Protection Board website.
If you would like to exercise any of those rights, please complete a request form—available at platform@emerald-technology.com or contact us on the information provided below—see: ‘How to contact us’. When contacting us please:
-
- Provide enough information to identify yourself (e.g., your full name, address and customer or matter reference number) and any additional identity information we may reasonably request from you; and
- Let us know which right(s) you want to exercise and the information to which your request relates
- Keeping your personal data secure
We have appropriate security measures to prevent personal data from being accidentally lost, or used or accessed unlawfully. We limit access to your personal data to those who have a genuine need to access it. We continually test our systems and are ISO 27001 and SoC certified, which means we follow top industry standards for information security. We also use end-to-end encryption. We also comply with and follow the principle of the UK’s and EU’s General Data Protection Regulation across our business and strive to process your personal data in a fair, transparent and lawful way wherever possible.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
However, there is no system that is 100% secure and the security of your personal data cannot be guaranteed. You play a part in the protection of your personal information, and so you must ensure you protect your username and password and do not share it with others. We are not liable if your data is accessed due to negligence of protecting your account credentials. In case of a data incident that is likely to result in a high risk of unauthorized access to or disclosure of your personal data, and depending on the circumstances, we will inform you about remedial actions to prevent any further damages. We will also inform the relevant data controller, supervisory authority, or other applicable authorities without undue delay.
How to complain:
Please contact us if you have any queries or concerns about our use of your personal data (see below ‘How to contact us’). We hope we will be able to resolve any issues you may have.
You also have the right to lodge a complaint with:
- The Information Commissioner in the UK;
- David Bell, 49 Hollybank Avenue Lower, Ranelagh, Dublin 6, dbell@thehrdepartment.ie
- Relevant data protection supervisory authority in the EEA state of your habitual residence, place of work or of an alleged infringement of data protection laws in the EEA
The UK’s Information Commissioner may be contacted using the details at https://ico.org.uk/make-a-complaint or by telephone: 0303 123 1113.
For a list of EEA data protection supervisory authorities and their contact details see https://edpb.europa.eu/about-edpb/about-edpb/members_en.
Changes to this privacy policy:
We reserve the right to modify this policy relating to our website, platform, or service at any time, effective upon posting on updated version of this policy on the website. By continuing to use our service or providing with personal data after we have posted an updated privacy policy, or notified you by other means if applicable, you consent to the revised privacy policy and practices described in it. We encourage you to periodically review this page for the lates information on our privacy practices.
Privacy of minors:
We do not knowingly collect any personal data from persons under the age of 18. If you are under the age of 18, please do not submit any personal data through our website or service.
We encourage parents and legal guardians to monitor their children’s internet usage to help enforce our policy by instructing their children to never personal information through our website.
How to contact us:
Individuals in the UK
You can contact us and/or our Data Protection Officer by post, email or telephone if you have any questions about this privacy policy or the information we hold about you, to exercise a right under data protection law or to make a complaint.
Our contact details are shown below:
Our contact details
Our Data Protection Officer’s contact details
Somerset House, 37 Temple Street Birmingham B2 5DP
info@emerald-technology.com
+44 (0) 870 889 0300
platform@emerald-technology.com
Somerset House, 37 Temple Street Birmingham B2 5DP
MelissaC@emerald-technology.com
44 (0) 121 233 6244
Individuals in the EEA
We have appointed David Bell to be our data protection representative within the EEA. Their contact details are: 49 Hollybank Avenue Lower, Ranelagh, Dublin 6, +353 01-6852360, dbell@thehrdepartment.ie.
Individuals within the EEA can contact us direct (see above) or contact our European representative.
Do you need extra help?
If you would like this policy in another format (for example audio, large print, braille) please contact us (see ‘How to contact us’ above).