EKW Group Privacy Policy

Introduction

EKW Group together with its affiliated companies (incorporating EKWilliams Accountants Limited, INNventory Limited, PAYEpeople Limited, HRPeople Limited, IKARA Business Solutions Limited and The Pub Experts Limited) is a leading accounting and financial technology service provider that our customers rely on every day to help them grow and succeed. Our customers, suppliers, prospects and applicants for employment, and others with whom we do business entrust us with their personal data and personally identifiable information (“Personal Information”) and they expect us to protect that Personal Information with the same level of care as we do our own. This is fundamental to the way we do business.

This EKW Group Privacy Policy (the “Policy”) describes and is intended to provide information about the practices we have adopted with respect to processing Personal Information including the collection, use, storage or disclosure of Personal Information, except where there are specific privacy requirements for a product or service (“Service”) and a separate policy has been published for that particular Service.

This statement was last updated on 20 March 2018.

Scope

Whether acting as a data controller, a data processor or data intermediary, EKW Group is required to comply with all applicable laws and regulations protecting the privacy of Personal Information in the jurisdictions where EKW Group conducts business.

We may amend this Policy from time to time, should it become necessary or advisable to do so to comply with regulatory requirements or best practices. The most recent modification date of this Policy will appear at the top of this page. If we materially change our practices in processing Personal Information, we will post an updated policy in place of this Policy.

General Definitions

These definitions may vary slightly according to local data privacy laws.

EKW Group is committed to the responsible handling and protection of personal information.

Personal information means any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

Individuals or entities that are identified or identifiable by Personal Information are referred to as “data subjects”.

We collect, use, disclose, transfer, and store personal information when needed to provide our Services and for our operational and business purposes as described in this Statement. We want to be clear about our privacy practices so that you can make informed choices about the use of your information, and we encourage you to contact us at any time with questions or concerns.

The types of personal information we collect

We collect personal information from you, for example, if you register for an event, request information, purchase or use our Services, or request support we may ask you to provide information such as your name, address, phone number, email address, user name and password. Not all of the personal information EKW Group holds about you will always come directly from you. It may, for example, come from a previous employer, other organisations to which you belong, or a professional service provider such as your tax or accounting professional or attorney. We also collect personal information from third parties such as our partners, service providers, and publicly available websites, to offer Services we think may be of interest and to help us maintain data accuracy and provide and enhance the Service in which you engage us to provide.

Occasionally we collect and process what may be considered sensitive personal information.

Sensitive personal information is a subset of personal information and is generally defined as any information related to racial/ethnic origin, political opinions, religious beliefs, trade union membership, physical or mental health, other medical information including biometric and genetic data, or sexual life or preferences. In some instances, sensitive personal information may also include criminal allegations or convictions, precise geolocation information, financial and bank account numbers, or unique identifiers such as government-issued social security numbers, driver’s license, and passport numbers.

For example, if you purchase something from us or subscribe to our Services, we will collect payment information, such as financial or bank card information, and other information necessary for us to process the transaction. If you or your service professional uses our Tax & Accounting Services, we will collect and process financial and tax information. Some of our Services will ask you to share your precise geolocation so we can customise your experience and increase the accuracy of the Service. We may also collect information such as a government-issued identification. Information that is considered sensitive under applicable law will be handled in accordance with such laws.

How we use personal information

We process personal information for Services provided and business related purposes.

Account setup and administration:

We use personal information such as your name, email address, phone number, and information about you to set up and administer your account, provide customer support and training, verify your identity, and send important information as per the expectations of the Service we provide.

Personalisation:

We use personal information to deliver and suggest tailored content such as news, research, reports, and business information and to personalise your experience with our Services.

Marketing and events:

We use personal information to deliver marketing and event communications to you across various platforms, such as email, telephone and direct mail. If we send you a marketing email, it will include instructions on how to opt out of receiving these emails in the future. If you wish to notify us in writing and wish to opt out, you can do so by emailing marketing@ekwgroup.co.uk Please remember that even if you opt out of receiving marketing emails, we may still send you important Service information related to your Service such as important changes to compliance and legislation.

Hosted services:

Some of our Services provide data and document storage as an integral part of our Service and/or solution offering. For example, documents and data stored by EKW Group and/or our customers may contain personal information in business and personal tax forms, payroll and financial data, and other legal related forms. Any information stored by or on behalf of our customers is controlled and managed by and only made accessible to those customers or others our customers may authorise from time to time. Access to this information is limited to EKW Group personnel to ensure that we provide the Service as per the customer expectations.

Legal obligations:

We may be required to use and retain personal information for legal and compliance reasons, such as the prevention, detection, or investigation of a crime; loss prevention; or fraud. We may also use personal information to meet our internal and external audit requirements, information security purposes, and as we otherwise believe to be necessary or appropriate:

· Under applicable law, which may include laws outside your country of residence;

· To respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include such authorities outside your country of residence;

· To enforce our terms and conditions;

· To protect our rights, privacy, safety, or property, or those of other persons.

When we share personal information

EKW Group shares or discloses personal information when necessary to provide Services or conduct our business operations as described below. When we share personal information, we do so in accordance with data privacy and security requirements. We may occasionally share non-personal, anonymised, and statistical data with third parties. Below are the parties with whom we may share personal information and why.

Our third-party service providers:

We partner with and are supported by service providers around the world. Personal information will be made available to these parties only when necessary to fulfil the services they provide to us, such as software, system, and platform support; cloud hosting services; advertising; data analytics; and order fulfilment and delivery. Our third-party service providers are not permitted to share or use the personal information we make available to them for any other purpose than to provide services to us.

Third parties for legal reasons:

We will share personal information when we believe it is required, such as:

· To comply with legal obligations and respond to requests from government agencies, including law enforcement and other public authorities, which may include such authorities outside your country of residence.

· In the event of a merger, sale, restructure, acquisition, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings)

· To protect our rights, users, systems, and Services.

Where we store and process personal information

EKW Group is based in the UK, and we take the necessary steps to ensure that your personal information is stored and processed in the UK. Information we collect is processed according to this Privacy Statement and the requirements of applicable law wherever the data is located.

EKW Group has networks, databases, servers, systems and support located throughout our offices in the UK. We collaborate with third parties such as cloud hosting services, suppliers, and technology support located in the UK to serve the needs of our business, workforce, and customers. We take appropriate steps to ensure that personal information is processed, secured, and transferred according to applicable law. In some cases, we may need to disclose or transfer your personal information within EKW Group or to third parties in areas outside of your home country.

If there is a need to transfer personal information from the European Economic Area to other countries in which applicable laws do not offer the same level of data privacy protection as in your home country, we take measures to provide an appropriate level of data privacy protection and in any event, we will seek consent from the customer. In other words, your rights and protections remain with your data. For example, we use approved contractual clauses, multiparty data transfer agreements, intragroup agreements, and other measures designed to ensure that the recipients of your personal information protect it.

How we secure personal information

EKW Group takes data security seriously, and we use appropriate technologies and procedures to protect personal information. Our information security policies and procedures are closely aligned with widely accepted international standards and are reviewed regularly and updated as necessary to meet our business needs, changes in technology, and regulatory requirements.

For example:

Policies and procedures

· We have measures in place to protect against accidental loss and unauthorised access, use, destruction, or disclosure of data.

· We have a Business Continuity and Disaster Recovery strategy that is designed to safeguard the continuity of our service to our customers and to protect our people and assets.

· We place appropriate restrictions on access to personal information.

· We implement appropriate measures and controls, including monitoring and physical measures, to store and transfer data securely.

· We conduct Privacy Impact Assessments in accordance with legal requirements and our business policies.

Training for employees and contractors

·  We provide privacy, information security, and other applicable training on a regular basis for our employees and contractors who have access to personal information and other sensitive data.

· We take steps to ensure that our employees and contractors operate in accordance with our information security policies and procedures and any applicable contractual conditions.

Vendor risk management

· We require, through the use of contracts and security reviews, our third-party vendors and providers to protect any personal information with which they are entrusted in

accordance with our security policies and procedures.

How long we keep personal information and customer records

EKW Group implements policies and rules relating to the retention of personal information. We retain personal information for as long as we reasonably require it for legal or business purposes. In determining data retention periods, EKW Group takes into consideration local laws, contractual obligations, and the expectations and requirements of our customers. When we no longer need personal information, we securely delete or destroy it.

Your right to access and correct your personal information

We honour data subjects’ rights under applicable law to access, correct, update, erase, disable and block their Personal Information when lawfully requested to do so. In some circumstances, a data subject may have the right to object to the processing of his or her Personal Information; to withdraw consent to the collection, use or disclosure of his or her Personal Information for any purpose; and/or to obtain information about how his or her Personal Information has been used or disclosed.

  1. We will provide data subjects with access to their Personal Information and honour other rights (such as withdrawal of consent) as applicable upon request sent to info@ekwgroup.co.uk
  2. We will correct a data subject’s Personal Information upon request sent to info@ekwgroup.co.uk.
  3. Data subjects may also opt-out of direct marketing by contacting marketing@ekwgroup.co.uk
  4. Where we are collecting, using or disclosing Personal Information on behalf of one of our customers we will refer requests from data subjects for access to their Personal Information to that client for handling and we will assist our client in responding to access requests we receive.

Marketing preferences

To update your account information or email marketing preferences please email the marketing team direct at marketing@ekwgroup.co.uk

Cookies and similar technologies

EKW Group and our third-party providers set and use cookies and similar technologies to store and manage user preferences, gather analytic and usage data, for example. The use of cookies and other tracking technologies is standard across websites and apps through which information is collected about your online activities across applications, websites, or other services. More information about how we use cookies and similar technologies and how you can control and manage them is below.

What is a cookie?

A cookie is a small text file that is placed on a computer or other device and is used to identify the user or device and to collect information.

Managing cookies

You can manage website cookies in your browser settings, and you always have the choice to change these settings by accepting, rejecting, or deleting cookies. If you choose to change your settings, you may find that certain functions and features will not work as intended on the Services. All browser settings are slightly different, so to manage cookies, you should refer to the relevant settings within your browser.

Connecting via social networks

Some of our Services may include social networking features, such as the Facebook “Like” button and widgets, “Share” buttons, and interactive mini-programs. Additionally, you may choose to use your own social networking logins from, for example, Facebook or LinkedIn, to log into some of our Services. If you choose to connect using a social networking or similar service, we may receive and store authentication information from that service to enable you to log in and other information that you may choose to share when you connect with these services. These services may collect information such as the web pages you visited and IP addresses, and may set cookies to enable features to function properly. We are not responsible for the security or privacy of any information collected by these third parties.You should review the privacy statements or policies applicable to the third-party services you connect to, use, or access. If you do not want your personal information shared with your social media account provider or other users of the social media service, please do not connect your social media account with your account for the Services and do not participate in social sharing on the Services.

Links and connections to third-party services

Our Services may contain links to and may be used by you in conjunction with third-party apps, services, tools, and websites that are not affiliated with, controlled, or managed by us. Examples include Facebook, LinkedIn, Twitter and, third-party apps like voice software and readers. The privacy practices of these third parties will be governed by the parties’ own Privacy Statements. We are not responsible for the security or privacy of any information collected by these third parties.You should review the privacy statements or policies applicable to these third-party services.

Children’s privacy

EKW Group provides information solutions for professionals, and our Services are generally not aimed at children. If, however, we collect and use information about children, such as to develop an educational resource, we will comply with industry guidelines and applicable laws.

Enforcement

We have policies and procedures in place to implement and audit the privacy principles set forth in this Policy. We have adopted a procedure to receive and respond to complaints and inquiries about our policies and practices relating to the handling of Personal Information. We will investigate all complaints in respect of Personal Information. If a complaint is justified, we will take appropriate measures, including, as necessary, amending our policies and practices. Where we are collecting, using or disclosing Personal Information on behalf of one of our customers, we will assist them in responding to questions and complaints respecting their customers’ Personal Information maintained by us on their behalf. Any inquiries or complaints regarding this Policy or our practices relating to the handling of  Personal  Information  should  be  addressed  to info@ekwg roup.co.uk

Consent

Use of any of our Services in conjunction with this Policy is deemed to be consent to the collection, retention, processing, transfer to third parties and transfer to other countries of your Personal Information, all in accordance with the purposes set forth herein. Data subjects provide Personal Information at their own volition and may be entitled to withdraw consent as described above in “Your right to access and correct your personal information”.

Filing a complaint

If you are not satisfied with how EKW Group manages your personal data, you have the right to make a complaint to a data protection regulator. A list of National Data Protection Authorities can be found here: http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.

Contact Us

If you require further information on our privacy policies and practices relating to the handling of Personal Information or any aspects of this statement, please contact one of our Data Protection Officers.

Email: Tel: Address:

info@ekwg roup.co.uk

01942 816 512

1 Pavilion Square Cricketers Way Westhoughton Bolton

Greater Manchester

BL5 3AJ