Health and Safety Privacy Notice

Introduction

Revell Research Systems Limited (the Company) is providing you with this information in order to comply with the Data Protection Act 2018 and the General Data Protection Regulation 2016 (GDPR), which require us to tell you what we do with your personal information.

This notice relates to the personal data that is processed by us in recording health and safety accidents, incidents and near-miss events as well as managing our overall health and safety processes. This personal data may relate to members of the public, client or supplier personnel and anyone working for or on our behalf.

Some of this data may be classified as sensitive.

Who is collecting this personal data?

Revell Research Systems Limited is collecting this data as the Data Controller.

Revell Research Systems Limited is a private limited company registered in England and Wales as number 06939580. Its registered office is at 5 Providence Court, Pynes Hill, Exeter, Devon, EX2 5JL, United Kingdom. You should send regular correspondence to our principal office at 9-11 Coates Road, Exeter, Devon, EX2 5RH, United Kingdom.

You can also contact us on (01392) 259797 or by email via office@rrs.co.uk.

Revell Research Systems Limited is registered with the Information Commissioner in the United Kingdom as a data controller under number Z186392X.

Who are we sharing your Personal Data with?

It may be necessary to share your personal data processed under this notice with the following third parties:-

  • The courts and those involved in legal proceedings and non-contentious matters, including solicitors and barristers
  • Police and law enforcement agencies
  • Our subsidiaries, our ultimate holding company and all its subsidiaries
  • Health and Safety Executive
  • Public Health Agencies
  • Medical practitioners
  • Agents acting on our behalf
  • Service providers (including associates)
  • Our insurance broker and insurers
  • Our professional advisors

We will not sell or rent your data to third parties. We will not share it with third parties for marketing purposes.

Why are we collecting and what will we do with Your Personal Data?

We are collecting this information to assist us in complying with legislation and best practice.

We have a legal duty to document workplace incidents and accidents as well as to report certain types of accident, injury and dangerous event to the relevant enforcing authority. For instance, we are legally obliged to report RIDDOR accidents to the Health and Safety Executive. These legal obligations necessitate the collection of personal data (some of which maybe classified as sensitive).

As part of this legal duty, we record health and safety accidents, incidents and near-miss events that happen on our premises or to our staff and associates while they are working for us wherever they may be at the time. These records may include information about our own personnel, client or supplier staff, relevant managers in affected organisations, members of the public involved in an accident and the details of witnesses.

We also collect personal data from various parties when conducting risk assessments in order to ensure, so far as is reasonably practicable, the health, safety and well-being of those affected by the Company's activities.

Additionally, we collect personal data from those working for us to support their well-being and to facilitate appropriate health and safety training and supervision.

We may also report incidents of violent behaviour towards our personnel to the police or other law enforcement agencies. We may share person data in co-operating with the police or law enforcement agencies.

We may also occasionally use your personal information where we need to protect your vital interests (or someone else's vital interests).

We may also need to collect personal data and to share it with public health agencies either by legal obligation or in protecting your or another's vital interests.

We investigate incidents and accidents to establish what lessons can be learned to prevent such incidents or accidents re-occurring including the introduction of additional safeguards, procedures, information, instruction and training, or any combination of these.

We may process this data for the purpose of the proper administration of our business and in communicating with you as well as maintaining backups.

We also retain information in the event of any claims for damages and may pass details to our insurers. We may also use the personal data we collect to establish, exercise or defend possible legal claims.

What is the legal basis for processing?

Our lawful purposes are Legal Obligation, Vital Interests and Legitimate Interest.

  • legal obligation - the Company has an obligation under law to maintain proper health and safety records and may be required from time-to-time to share personal data to comply with health and safety legislation.
  • vital interests - the Company may process personal data in your or another's vital interests in an emergency.
  • legitimate interest - the Company has a legitimate interest in maintaining the health, safety and well-being of those who work for or interact with us; in investigating incidents and accidents to minimise future risk; in improving our health and safety systems; in establishing, exercising or defending legal claims; and in properly administering its business and backing up data.

These lawful purposes are detailed in Article 6 of the General Data Protection Regulation (GDPR):-

  • processing is necessary for compliance with a legal obligation to which the controller is subject (Article 6(1)(c)).
  • processing is necessary in order to protect the vital interests of the data subject or of another natural person (Article 6(1)(d)).
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child (Article 6(1)(f)).

We process sensitive personal data (GDPR Article 9(1)) under the regulation because:-

  • processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent (Article 9(2)(c)).
  • processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity (Article 9(2)(f)).
  • processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3 (Article 9(2)(h)).

The Company is subject to a range of Health and Safety legislation in the United Kingdom, including:-

  • Health and Safety at Work (etc) Act 1974
  • Management of Health and Safety at Work Regulations 1999
  • The Control of Substances Hazardous to Health Regulations 2002
  • Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013
  • Regulatory Reform (Fire Safety) Order 2005
  • Health And Safety (Display Screen Equipment) Regulations 1992 (as amended)

How are we collecting this information?

We collect personal data from data subjects when we record health and safety accidents, incidents or near-miss events. We also collect personal data when we are carrying out health and safety risk assessments and when we are assessing our health and safety training needs or in providing well-being support to our staff.

The Company may collect personal information in a variety of ways such as:-

  • Via email
  • Via telephone
  • Through personal communication with our personnel
  • Accident or incident reports
  • Witness statements

What information are we collecting?

We collect the following personal information when recording accidents, incidents or near-miss events:-

  • your name
  • job title
  • organisation
  • date of birth
  • gender
  • address and other contact details
  • details of any injuries (where applicable)

These details may relate to any injured parties, witnesses, first aiders or any of our personnel involved as well as managers and others perceived to have a legitimate interest in the accident, incident or near-miss event, who may not have been present at the time. We may also collect video, audio and photographic evidence.

We will record the time, date and location as well as any other pertinent information about the accident, incident or near-miss event.

We collect the following personal information when conducting risk assessments:-

  • your name
  • job title
  • organisation
  • date of birth
  • gender
  • address and other contact details

We may also include information about medical conditions that are pertinent to the risk and details of your medical practitioners.

We record any health and safety training provided to staff and associates and keep records of health and safety consultations and meetings.

We may also collect basic contact details of visitors to our premises or events in connection with public health issues, which we will pass to the relevant public health agencies, when requested.

Who can see your information within the Company?

Only authorised directors, staff and associates may access your data.

How long is your information kept?

We will only keep your information for as long as necessary. The retention period is either dictated by law or our legitimate requirements. Once your information is no longer needed it will be securely and confidentially destroyed.

We retain accident books, records and reports for forty years along with general health and safety records. We permanently keep risk assessments and records of consultations with safety representatives and committees. We keep staff medical records for six years after departure in most cases, although in some very special cases (relating to asbestos and radiation) the law requires us to keep certain medical records considerably longer.

We typically retain personal data relating to financial transactions with the Company for six years after the financial year in which they occurred based on the Limitation Act 1980.

How secure is your information?

We take stringent steps to keep your information secure. You can read more about our approach to security at www.rrs.co.uk/security.

Who keeps your information updated?

You are responsible for keeping your personal details up-to-date. Please advise the Company of any changes.

Will your information be used for any automated decision making?

No.

Our Privacy Statement

You can access the Company's Privacy Statement at www.rrs.co.uk/privacy. This statement provides you with more information about how we address data protection and privacy as well as informing you of your rights.

Other Privacy Notices

You are likely to interact with us in more than one way, so our other privacy notices may apply to you in different scenarios. We are open and transparent about how we use your personal data. You can find all of our Privacy Notices at www.rrs.co.uk/privacy.

Changes to this Notice

We may change this privacy notice at any time. Any changes to this privacy notice will apply to you and your data immediately. If these changes affect how your personal data is processed, the Company will take reasonable steps to make sure you know.

Further Information

If you have any queries about this notice then please do not hesitate to contact us by telephone on (01392) 259797 or via email to office@rrs.co.uk. You can write to us at 9-11 Coates Road, Exeter, Devon, EX2 5RH, United Kingdom.

Version 0.0; 1st September 2020