Usage Logs Privacy Notice

Introduction

Revell Research Systems Limited (the Company, we, us, our) is providing you with this information in order to comply with the Data Protection Act 2018 and the General Data Protection Regulation 2016 (GDPR), which require us to tell you what we do with your personal information.

This notice relates to the personal data that we automatically collect and process as you use our computing and communication facilities.

We will not use your personal data in subsequent marketing communications without your explicit consent, although we may add details about your organisation to our marketing system as an interested party, which is outside the scope of privacy legislation.

Who is collecting this personal data?

Revell Research Systems Limited is collecting this data as the Data Controller.

Revell Research Systems Limited is a private limited company registered in England and Wales as number 06939580. Its registered office is at 5 Providence Court, Pynes Hill, Exeter, Devon, EX2 5JL, United Kingdom. You should send regular correspondence to our principal office at 9-11 Coates Road, Exeter, Devon, EX2 5RH, United Kingdom.

You can also contact us on (01392) 259797 or by email via office@rrs.co.uk.

Revell Research Systems Limited is registered with the Information Commissioner in the United Kingdom as a data controller under number Z186392X.

Who are we sharing your Personal Data with?

We may share your personal data processed under this notice with the following third parties:-

  • The courts and those involved in legal proceedings and non-contentious matters, including solicitors and barristers
  • Police and law enforcement agencies
  • Our subsidiaries, our ultimate holding company and all its subsidiaries
  • Agents acting on our behalf
  • Service providers (including associates)
  • Professional advisors

We will not sell or rent your data to third parties. We will not share it with third parties for marketing purposes.

Why are we collecting and what will we do with Your Personal Data?

We are collecting this information to monitor, secure, protect and improve our computing and communication facilities.

We may also process this data for the purpose of the proper administration of our business and in communicating with you as well as maintaining backups.

We may share data with the courts and associated professionals in establishing, exercising or defending our legal rights. We may share data in reporting crime to or in co-operating with the police and law enforcement agencies.

What is the legal basis for processing?

Our lawful purposes are Contract and Legitimate Interest.

  • contract - the Company may process your personal data in connection with a contract with you or a third party or as part of pre-contractual negotiations.
  • legitimate interests - the Company has a legitimate interest in monitoring, securing, protecting and improving our computing and communication facilities; in protecting and asserting our or another's legal rights; and in properly administering its business and backing up data.

These lawful purposes are detailed in Article 6 of the General Data Protection Regulation (GDPR):-

  • processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b)).
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child (Article 6(1)(f)).

How are we collecting this information?

The computing and communications equipment we use automatically collects personal data as it is used.

This equipment includes:-

  • firewalls
  • routers
  • switches
  • computers
  • storage systems
  • telephony systems and services
  • CCTV and other surveillance systems
  • physical access control systems

We also receive detailed call logs from our fixed and mobile telephony service providers. We also collect detailed usage information from our cloud-based systems.

What information are we collecting?

We automatically log your access to our web-based systems. We collect your Internet Protocol (IP) address, browser details, operating system, referral source, geolocation, date, time and the resources you access, amongst other usage statistics. We use this information to improve the navigation, layout and content of these facilities as well as the services we offer you. The sources of this information are the servers under our control.

We also automatically log the date, time, subject, sender and recipient details of every email and electronic message we handle as well as the IP address of those machines that our systems communicate with, together with other technical data. Other Internet based systems (such as video-conferencing and voice systems, chat services and newsgroups) also collect similar data. The sources of this information are the systems under our control.

We also automatically log any use of our computing systems (including computers, routers, switches, firewalls and wireless access points) however and wherever they are accessed, which may capture personal identifiable information. We record when people log in or out of our computing systems and track the facilities they access. We record date, time, IP and Media Access Control (MAC ) addresses (as applicable) as well as other technical data relating to system use. The sources of this information are the computing facilities under our control.

We may also automatically log your use of any building access codes we may issue you with and track your use of them to enter and exit our facilities. Where we collect this information, we use it for health and safety purposes and to secure our premises. The sources of this information are the building access control systems at our facilities. We may process any of the data that we collect for the purpose of analysing the use of our computing and communications facilities, business administration, system maintenance and troubleshooting, making backups, ensuring the security of our facilities and preventing fraud.

We also automatically log the calls to and from our telephone, SMS text and facsimile systems. We record Calling Line Identification (CLI) data sent by our telephony providers during each incoming call or transmission. We may record the date, time and duration of any call utilising our telephony systems as well as the telephone numbers of the parties involved and how the call was handled. We may do likewise for SMS and fax transmissions. We use this information to improve our efficiency and effectiveness in dealing with calls and transmissions. The sources of this information are our telephony systems and service providers.

Who can see your information within the Company?

Only authorised directors, staff and associates may access your data.

How long is your information kept?

We will only keep your information for as long as necessary. The retention period is either dictated by law or our legitimate requirements. Once your information is no longer needed it will be securely and confidentially destroyed.

We typically retain personal data that is automatically captured in our system usage logs for six years after the financial year in which they were logged.

How secure is your information?

We take stringent steps to keep your information secure. You can read more about our approach to security at www.rrs.co.uk/security.

Who keeps your information updated?

You are responsible for keeping your personal details up-to-date. Please advise the Company of any changes.

Will your information be used for any automated decision making?

No.

Our Privacy Statement

You can access the Company's Privacy Statement at www.rrs.co.uk/privacy. This statement provides you with more information about how we address data protection and privacy as well as informing you of your rights.

Other Privacy Notices

You are likely to interact with us in more than one way, so our other privacy notices may apply to you in different scenarios. We are open and transparent about how we use your personal data. You can find all of our Privacy Notices at www.rrs.co.uk/privacy.

Changes to this Notice

We may change this privacy notice at any time. Any changes to this privacy notice will apply to you and your data immediately. If these changes affect how your personal data is processed, the Company will take reasonable steps to make sure you know.

Further Information

If you have any queries about this notice then please do not hesitate to contact us by telephone on (01392) 259797 or via email to office@rrs.co.uk. You can write to us at 9-11 Coates Road, Exeter, Devon, EX2 5RH, United Kingdom.

Version 0.0; 1st September 2020