Who we are?
Surgimax Instruments Ltd incorporated in England and Wales and is a ‘controller’ under the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
Whose data do we hold?
We may hold data about the following people: –
- Suppliers and service providers.
- Advisers, consultants and other professional experts.
- Complainants and enquirers.
What data we will collect?
We will only collect information from you that is relevant to the matter that we are dealing with. In particular we may collect the following information from you which is defined as ‘personal data’: –
- Personal details, such as name, address and email address.
- Financial details.
- Business activities of the person whose details we are processing.
We may also collect information that is referred to as being in a ‘special category’. This could include: –
- Racial or ethnic origin.
- Religious beliefs or other beliefs of a similar nature.
- Sexual orientation.
Basis for processing
The basis on which we process your personal data is one or more of the following: –
- It is necessary for the performance of our contract with you.
- It is necessary for us to comply with a legal obligation.
- It is in our legitimate interest to do so.
- You have given us your consent (this can be withdrawn at any time by contacting at firstname.lastname@example.org.
How will we use your data?
We may use your information for the following purposes:
- Maintaining accounts and records.
Who will we share your data information with?
- Service providers based in the United Kingdom / outside EEA countries who provide IT and system administration services to us.
- Debt collection agencies if you do not pay our bills.
How long will we keep your information for?
- By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.
- We may from time to time transfer your personal data to a country outside of the EEA. For example, when we store personal data on a cloud server.
- It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers.
- We shall ensure that all the information that you provide to us is kept secure using appropriate technical and organizational measures.
- In the event of a personal data breach, we have in place procedures to ensure that the effects of such a breach are minimized and shall liaise with the Information Commissioner’s office (ICO) and with you as appropriate.
- More information can be obtained by contacting at email@example.com.
What rights do you have?
You have the following rights under the GDPR: –
- Request access to your personal data.
- Request correction of your personal data.
- Request erasure of your personal data.
- Object to processing of your personal data.
- Request restriction of processing your personal data.
- Request transfer of your personal data.
- Right to withdraw consent.
Who you can complain to?
- If you are unhappy about how we are using your information or how we have responded to your request then initially you should contact at firstname.lastname@example.org or give us a ring at 0161 3022 744.
- If your complaint remains unresolved then you can contact the ICO, details are available at www.ico.org.uk.