Privacy Notice
This privacy notice explains how Macrophage Pharma Ltd uses the personal information we collect from you, either through using our website, or in any other way, electronically, verbally or in writing.
Topics:
- Data controller
- Basis for collecting your data (Lawful processing)
- Recipients of data and data transfers
- Sensitive Information
- Retention policy
- Data Storage and Security
- Your Rights as a data subject
- Automated decision making
- 3rd Party Websites
- Contact Details
Data controller
Macrophage Pharma Ltd is the data controller, because we make decisions about what data we collect and how it is used and with whom it is shared with. We can be contacted at enquiries@macrophagepharma.com or telephone number +44(0)1753 272047
On what basis do we collect and process your data?
Data Protection law defines the basis by which we can lawfully collect and process personal data. We use the following legal basis for our data processing:
Consent
We will collect and process your personal data on the basis of your freely given and informed consent where we have concluded that this is the most appropriate basis for the processing. You are free to withdraw your consent at any time and can do so by contacting us on the numbers above or using the email address.
To enter into or in pursuance of a contract:
We will collect personal data when engaging with individuals to enter into a contract or commercial agreement to supply services or goods. We will continue to process that data for the duration and often subsequently after the contract expires or is terminated.
Where we have a legal obligation:
We will collect personal data when we are required to through a legal obligation, such as requirements from government agencies.
Where processing your data is in your vital interests:
We will process your data if we feel it is required to protect your vital interests, or the vital interests of another person. This might occur in serious life or death situations where immediate disclosure of personal data is required. We have documented our justification for processing your data on this basis.
In our legitimate interest:
We will collect and process personal data where it is in the legitimate interest of Macrophage Pharma Ltd to do so.
For each category of data subject, we have determined the following basis:
Consultants
Purpose of Processing | Data Category | Data Processed | Legal Basis |
---|---|---|---|
Engage commercially | Identity Details | First Name | Contract |
Engage commercially | Identity Details | Surname | Contract |
Engaging commercially | Financial Details | Contract | Contract |
Engaging commercially | Identity Details | Signature | Contract |
Engaging commercially | Commercial Information | Hourly rate | Contract |
Engage commercially | Contact Details | Business Address | Contract |
Engage commercially | Contact Details | Post Code | Contract |
Engage commercially | Contact Details | Mobile No. | Legitimate Interest |
Engage commercially | Contact Details | Work No. | Legitimate Interest |
Engage commercially | Contact Details | Email address | Legitimate Interest |
Engage commercially | Financial Details | Bank Name | Legitimate Interest |
Engaging commercially | Professional details | CV’s | Legitimate Interest |
Legal Obligation | Company Information | VAT Number | Legal Obligation |
Contractors
Engage commercially | Identity Details | First Name | Contract |
Engage commercially | Identity Details | Surname | Contract |
Engage commercially | Contact Details | Mobile No. | Legitimate Interest |
Engage commercially | Contact Details | Work No. | Legitimate Interest |
Engage commercially | Contact Details | Email address | Legitimate Interest |
Engage commercially | Contact Details | Business Address | Contract |
Engage commercially | Contact Details | Post Code | Contract |
Engage commercially | Financial Details | Bank Name | Legitimate Interest |
Legal Obligation | Company Information | VAT Number | Legal Obligation |
Engaging commercially | Professional details | CVs | Legitimate Interest |
Engaging commercially | Commercial Information | CDA (disclosure agreement) | Contract |
Engaging commercially | Identity Details | Signature | Contract |
Information from our Website
Information and Marketing | Contact Details | Name | Consent |
Information and Marketing | Contact Details | Company Name | Consent |
Information and Marketing | Contact Details | Email address | Consent |
Information and Marketing | Contact Details | Telephone Number | Consent |
Information and Marketing | Contact Details | Country of Residence | Consent |
We collect data in relation to your communications and interaction with us. This can include emails, text messaging, postal service delivery, social media posting or any other form of communication. In addition to the lawful purpose described previously for the above categories, we have a legitimate interest purpose to collect and retain this data to enable and improve our communication and for record keeping purposes.
What if you do not provide personal data?
Where personal data is required for the purpose of engaging in a contract, certain information, such as your name and contact details, have to be provided to enable the organisation to enter a contract with you. If you do not provide us with the information, this will result in us not being able to enter into a commercial agreement.
Data recipients and data transfers
We do not sell any of your personal data to any third party. We share your personal data with insurance companies, pension providers, lawyers, banks and auditors.
We also contract other organisations to process your data on our behalf. Specifically, we transfer your data to:
- Bradshaw Daniel CFO service and accounting
- Windsor Accountancy payroll service
- Accounting platform Xero
- Travel and Taxi services
- Regus
- OnIT It Support
- Cloud based file sharing platforms
- DropBox
- Glasscubes
- Sharevault
We may also share your data with third parties as part of a Company sale, restructure, refinancing or for other reasons to comply with a legal obligation upon us.
We transfer your data to cloud providers for document storage and online collaboration also for our email purposes. We may, as required, share your personal information with printing and mailing companies.
Where required we will disclose your personal data with law enforcement and fraud prevention agencies. This is so we can help tackle fraud or where such disclosure is necessary for compliance with a legal obligation to which we are subject. Additionally, in order to protect your vital interests or the vital interests of another natural person, or in connection with the establishment, exercise or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
Personal data in electronic form is held in EU or UK accredited data centres, our email system stores data outside of the EEA in the USA. Where data is transferred outside of the EEA, we ensure that the transfer is covered by an EU adequacy decision such as the USA Privacy Shield or through mechanism such as standard contractual clauses as approved by the EU.
Sensitive information
Macrophage Pharma Ltd does not process special category data as defined by Article 9 of the GDPR.
Retention policy
The data we collect directly from you is the minimum we require to facilitate the lawful processing described above. Personally Identifiable Data placed on our system will be deleted in accordance with legal obligations. Macrophage Pharma Ltd has developed a retention policy to ensure personal data is held only for as long as is required for the purpose we collected it or for our legitimate purposes.
Generally, personal data required for financial transaction and audit purposes, including reporting to the HMRC will be retained for 6 years plus the current year it is collected.
Personal data collected for the purposes of engaging with suppliers will be maintained for the duration of the commercial relationship and for a further 7 years thereafter.
Data Storage and Security
Macrophage Pharma Ltd follows strict security procedures to ensure that your personal information is not damaged, destroyed, or disclosed to a third party without your permission and to prevent unauthorised access. We store both physical and electronic records. We have put in place technical and organisational measures to ensure our physical security as well as technical measures for data backup, authorisation and authentication onto systems. We use secure firewalls and other measures to restrict electronic access, including anti-virus and anti-malware measures. If the data must be transferred to a third party, we require them to have in place similar measures to protect your personal data. We have a process in place to mitigate the impact of any data breach that should occur.
Only persons who need the information to fulfil their duties are granted access to personal data. We may require you to cooperate with our security checks before we disclose information to you. You can update the personal information that you give us at any time by contacting us directly.
Your rights as a data subject
The regulations provide a number of rights to you as the Data Subject. Macrophage Pharma Ltd. is committed to upholding those rights and those applicable to the personal information we collect, and process are listed below. In addition to these rights, you have the right to escalate any concern to the Supervisory Authority, which in the UK is the Information Commissioners Office https://ico.org.uk. A full and detailed explanation of all rights can be found at https://ico.org.uk/for-the-public/
- The Right to be Informed – you should be clear about what, why and in what way your personal information will be processed at the time it is processed. This privacy policy sets out that information
- Right of Access – you have the right to know what personal information is held, by whom and why.
- The Right to Rectification – If the information we have collected and processed is inaccurate or incomplete, you have the right to have it rectified.
- Right to Erasure – You have the right to have your personal data erased and to prevent processing in some specific situations.
- Right to Restrict Processing – If you contest the accuracy of the personal data we hold, we will restrict the processing of your data until accuracy is verified.
- Right to Data Portability – You have the right to move, duplicate or transfer your data easily from one IT environment to another in a safe and secure way.
- Right to Object – You have the right to object to profiling and direct marketing
- You also have rights in relation to automated decision making.
You also have the right to lodge a complaint with the UK’s supervisory body, The Information Commissioners Office www.ico.org.uk
Automated decision making
Macrophage Pharma Ltd does not use automated decision making to process personal data.
Third party websites
Our website may contain links to other websites. This privacy policy only applies to Macrophage Pharma Ltd., so if you follow a link to another website, you should read that organisation’s own privacy policy.
Changes to our privacy policy
We keep our privacy policy under review, and we will place any updates on our website. This privacy policy was last updated in July 2020
How to contact us
You can write to us at this address:
Macrophage Pharma Ltd
Gainsborough House
59-60 Thames Street
Windsor
Berkshire
SL4 1TX
You can telephone us on this number: +44(0)1753 272047
You can email us at this address: enquiry@macrophagepharma.com