Visitors Privacy Notice
Introduction
Revell Research Systems Limited
(the Company, we, us, our)
is providing you with this information in order to comply with the Data Protection Act 2018
and the UK General Data Protection Regulation
(UK GDPR), which require us to
tell you what we do with your personal information.
This notice relates to the personal data that is processed by us when you visit
any of our premises.
This notice explains what personal data we collect, how we use it, the lawful bases we rely
upon, who we may share it with, how long we retain it and the rights available to you under
UK data protection law.
This notice applies whether visitor information is collected directly from you, supplied by
your organisation or host, or generated through visitor management and security processes
associated with your visit.
Who is collecting this personal data?
Revell Research Systems Limited
is collecting this data as the Data Controller.
Revell Research Systems Limited is a private limited company registered in
England and Wales as number 06939580.
Its registered office is at
5 Providence Court, Pynes Hill, Exeter, Devon, EX2 5JL, United Kingdom.
You should send regular correspondence to our principal office at
9-11 Coates Road,
Exeter,
Devon,
EX2 5RH, United Kingdom.
You can also contact us on (01392) 259797
or by email via
office@rrs.co.uk.
Revell Research Systems Limited
is registered with the Information Commissioner in the United Kingdom as a data controller
under
number Z186392X.
Who are we sharing your personal data with?
We may share personal data processed under this notice, where necessary and proportionate,
with the following categories of recipient:-
-
The courts and those involved in legal proceedings and non-contentious matters, including
solicitors and barristers
- Public health bodies
- Police and law enforcement agencies
- Our subsidiaries, our ultimate holding company and all its subsidiaries
- Emergency services
-
Landlords, building managers and other occupiers of shared premises where necessary for reception,
building management, health and safety or security purposes
- Associates
- Agents acting on our behalf
-
Service providers who provide reception, visitor management, security, information technology,
communications, administrative or professional support services
We will not sell or rent your data to third parties. We will not share it with third parties
for marketing purposes.
Why are we collecting and what will we do with your personal data?
We are collecting personal data in order to maintain the security of our premises and protect
the health, safety and welfare of those using them, including yourself. This may involve
sharing your details with any landlord or tenant in the buildings we occupy, particularly
when there is a shared reception. We may also share your details with security contractors
patrolling buildings and ensuring the safety of those in them. We may need to share
your details with the police or emergency services in the event of an emergency
or security incident. We may be legally obliged to collect basic contact details
to comply with public health legislation.
We collect personal data about you when you visit us. We will collect details about
who you are and who you are visiting as well as the time and date of your entry
and departure.
You should be aware that we may ask you to wear a visitor's badge displaying who
you are. We may also take a photograph for this visitor pass. Where required for security
purposes, we may take a photograph for inclusion on visitor identification badges to assist
in verifying authorised access to premises and shared facilities.
This information allows us to account for everybody in the event that our premises
need to be evacuated and helps those charged with security verify that those on
our premises or using shared facilities associated with them have a legitimate reason
to be present.
We may process visitor information for administrative purposes, including maintaining visitor
records, responding to enquiries arising from visits, investigating incidents, establishing
attendance records and maintaining secure backups of our systems.
We may share data with the courts and associated professionals in establishing,
exercising or defending our legal rights. We may share data in reporting crime to
or when co-operating with the police and law enforcement agencies.
What is the legal basis for processing?
Our lawful bases are Legal Obligation, Vital Interests and Legitimate Interests.
-
legal obligation - the Company may be required from time to time to comply with public health
legislation.
-
vital interests - the Company may share personal data to protect your or another's vital interests
in an emergency.
-
legitimate interests - the Company has legitimate interests in protecting its property and
ensuring the health and well-being of those using our premises and in protecting and
asserting our, your or another's legal rights; and in properly administering its business
and backing up data.
We have carefully balanced our interests in maintaining the security of our premises, protecting
our staff, visitors and property, administering visitor access arrangements and establishing,
exercising or defending legal claims against the privacy rights of visitors. We consider that
these activities are reasonably expected by visitors and have a minimal privacy impact while
providing important security and safety benefits.
These lawful bases are detailed in Article 6 of the UK General Data Protection Regulation
(UK GDPR):-
-
processing is necessary for compliance with a legal obligation to which the controller
is subject (Article 6(1)(c)).
-
processing is necessary in order to protect the vital interests of the data subject or of
another natural person (Article 6(1)(d)).
-
processing is necessary for the purposes of the legitimate interests pursued by the controller
or by a third party, except where such interests are overridden by the interests or fundamental
rights and freedoms of the data subject which require protection of personal data, in particular
where the data subject is a child (Article 6(1)(f)).
How are we collecting this information?
We collect personal data about you:-
- directly from you when you visit us
-
correspondence with you, your host or the organisation you represent before your arrival
- our online event booking system
- third-party event registration and booking platforms
Please note that our CCTV Privacy Notice
may also apply to you.
What information are we collecting?
We collect the following personal information when you visit our premises:
- your name and preferred style of address
- job title
- organisation
- your host
- photograph (where required for visitor identification or security purposes)
- date and time of arrival
- date and time of departure
Who can see your information within the Company?
Access to your personal data is restricted to authorised directors, employees, contractors,
staff and associates who require it for legitimate business purposes.
Will your personal data be transferred outside of the United Kingdom?
We do not routinely transfer personal data outside the United Kingdom. However, some professional
services, communication, collaboration, document management, hosting and cloud service providers
used by the Company may process personal data outside the United Kingdom. Where this occurs,
we will ensure that appropriate safeguards recognised by the UK General Data Protection Regulation
(UK GDPR) are in place before the
transfer occurs.
These safeguards may include transfers to countries recognised as providing an adequate level
of protection for personal data or the use of approved contractual arrangements between the
parties involved in the transfer.
How long is your information kept?
We will only keep your information for as long as necessary. The retention period
is either dictated by law or our legitimate requirements. Once your information
is no longer needed it will be securely and confidentially destroyed.
We typically retain visitor records for six years after the financial year in which the visit
occurred based on the Limitation Act 1980.
Visitor photographs are normally retained for the same period as the visitor record to which
they relate. We may retain them for a longer period where reasonably necessary in connection
with a security incident, investigation, complaint or legal claim.
How secure is your information?
We take appropriate technical and organisational measures to protect your information against
unauthorised access, disclosure, alteration and destruction. You can read more about
our approach to security at www.rrs.co.uk/security.
Who keeps your information updated?
You are responsible for keeping your personal details up-to-date. Please advise
the Company of any changes.
Will your information be used for any automated decision making?
No. We do not undertake solely automated decision making, including profiling, that produces
legal effects concerning you or similarly significantly affects you.
Our Privacy Statement
You can access the Company's Privacy Statement at
www.rrs.co.uk/privacy.
This statement provides you with more information about how we address data protection
and privacy as well as informing you of your rights.
Other Privacy Notices
You are likely to interact with us in more than one way, so our other privacy notices
may apply to you in different scenarios. We are open and transparent about how we
use your personal data. You can find all of our Privacy Notices
at www.rrs.co.uk/privacy.
Changes to this Notice
Any changes to this privacy notice will take effect when the revised notice is published.
If these changes affect how your personal data is processed, the Company will take reasonable
steps to make sure you know.
Further Information
If you have any queries about this notice then please do not hesitate to contact
us by telephone on (01392) 259797
or via email to
office@rrs.co.uk.
You can write to us at
9-11 Coates Road,
Exeter,
Devon,
EX2 5RH, United Kingdom.
Version 0.0; 1st September 2020 (Reviewed: 4th October 2026).