Privacy Notice – Customers & Suppliers

Introduction

MMD Summerfield Ltd take the security and privacy of your data seriously. We need to gather and use information or ‘data’ about you as part of our business and to manage our relationship with you. We intend to comply with our legal obligations under the Data Protection Act 2018 (the ‘2018 Act’) and the EU General Data Protection Regulation (‘GDPR’) in respect of data privacy and security. We have a duty to notify you of the information contained in this policy.

If you need more information, please contact our data manager at:
Privacy@summerfield-engineering.co.uk
The controller of your data will be MMD Summerfield Ltd.

1. What information do we collect?

We collect and process personal data about you when you interact with us, when you purchase goods from us and sell goods to us. The personal data we process includes:

  • your name;
  • your home or work address, email address and/or phone number;
  • your job title;
  • your bank details
  • information related to the browser or device you use to access our website;
  • internet browser and operating system;
  • and/or any other information you provide

2. How do we use this information and what is the legal basis for this use?

We process the personal data listed in bullet point 1 above for the following purposes:

  • As required to establish and fulfil a contract with you, for example, if you make a purchase from us or enter into an agreement to provide or receive goods/services. This may include verifying your identity, taking payments, communicating with you, providing customer services and arranging the delivery or other provision of products or services. We require this information in order to enter into a contract with you and are unable to do so without it;
  • To comply with applicable law and regulation;
  • In accordance with our legitimate interests in protecting MMD Summerfield Ltd’s legitimate business interests and legal rights, including but not limited to, use in connection with legal claims, compliance, regulatory and investigative purposes (including disclosure of such information in connection with legal process or litigation);
  • With your express consent to respond to any comments or complaints we may receive from you, and/or in accordance with our legitimate interests including to investigate any complaints received from you or from others, about our website or our products or services;
  • To monitor use of our websites and online services. We may use your information to help us check, improve and protect our products, content, services and websites, both online and offline, in accordance with our legitimate interests;
  • We may monitor any customer account to prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crime, in accordance with applicable law and our legitimate interests;
  • We may use your information to invite you to take part in customer satisfaction surveys. 

We may also send you direct marketing in relation to relevant products and services. Electronic direct marketing will only be sent where you have given your consent to receive it, or (where this is allowed) you have been given an opportunity to opt-out. You will continue to be able to opt-out of electronic direct marketing at any time by following the instructions in the relevant communication.

3. With whom and where will we share your personal data?

We may share your personal data with the below third parties:

  • Our professional advisors such as our auditors and external legal and financial advisors;
  • Marketing and communications agencies where they have agreed to process your personal data in line with this Privacy Notice;
  • Our suppliers, business partners and sub-contractors; and/or
  • Search engine and web analytics.

Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if needed for the legal protection of our legitimate interests in compliance with applicable laws. Personal data may also be shared with third party service providers who will process it on behalf of Summerfield Engineering Limited for the purposes above. Such third parties include, but are not limited to, providers of website hosting, maintenance.

4. How long will you keep my personal data?

We will not keep your personal information for any purpose for longer than is necessary and will only retain the personal information that is necessary in relation to the purpose. We are also required to retain certain information as required by law or for as long as is reasonably necessary to meet regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions.
We will keep your information for the length of any contractual relationship you have with us and after that for a period of 7 years.
Where you are a prospective customer and you have expressly consented to us contacting you, we will only retain your data

  • Until you unsubscribe from our communications; or, if you have not unsubscribed;
  • While you interact with us and our content;
  • For 12 months from when you last interacted with us or our content.

In some instances, laws may require Summerfield Engineering Limited to hold certain information for specific periods other than those listed above.

5. Where is my data stored?

The personal data that we collect from you is kept on our server, this is kept in a secure room with controlled access, security measures are in place including but not limited to virus software and firewalls. We use Office 365 which uses Microsoft Cloud to store our contacts database. Data may be transferred to, and stored outside the European Economic Area (“EEA”).  It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers, in which case the third country's data protection laws will have been approved as adequate by the European Commission or other applicable safeguards are in place. Further information may be obtained from our Privacy Team.

6. What are my rights in relation to my personal data?

You have the right to ask us not to process your personal data for marketing purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data, clicking the unsubscribe button on any communication we have sent to you or by contacting us.
Where you have consented to us using your personal data, you can withdraw that consent at any time.
If the information we hold about you is inaccurate or incomplete, you can notify us and ask us to correct or supplement it.
You also have the right, with some exceptions and qualifications, to ask us to provide a copy of any personal data we hold about you.
If you have a complaint about how we have handled your personal data, you may be able to ask us to restrict how we use your personal data while your complaint is resolved.

  • In some circumstances you can ask us to erase your personal data
  • By withdrawing your consent for us to use it;
  • If it is no longer necessary for us to use your personal data;
  • If you object to the use of your personal data and we don't have a good reason to continue to use it;
  • If we haven't handled your personal data in accordance with our obligations.

7. Where can I find more information aboutMMD Summerfield Ltd’s handling of my data?

Should you have any queries regarding this Privacy Notice, about MMD Summerfield Ltd’s processing of your personal data or wish to exercise your rights you can contact MMD Summerfield Ltd’s data manager using this email address: Privacy@summerfield-engineering.co.uk. If you are not happy with our response, you can find information on how to contact the Information Commissioner’s Office at their website (www.ico.org.uk). This website has further information on your rights and our obligations