00Legal
Privacy noticeDraft · version 0.1
How we handle your information.
What we collect when you contact us or use the internal sales portal, why we hold it, how long we keep it, and what you can tell us to do about it.
This document is drafting boilerplate written to be filled in, not legal advice and not a finished notice. It must be checked and completed by a solicitor or data protection adviser before Remedium publishes it or relies on it. Every value shown in dashed brackets is a gap the owner has to close.
Who we are
This notice is issued by Remedium Digital (“Remedium”, “we”, “us”), the data controller for the personal data described below.
- Registered name [full legal entity name]
- Company registration number [company number]
- Registered address [registered office address]
- VAT number [VAT number, or state “not VAT registered”]
- ICO registration [ICO registration reference]
- Privacy contact hello@remedium.digital
What this notice covers
This notice covers personal data we handle through this website: enquiries sent to us, direct email to the address above, and any account you hold in the Remedium client portal.
Where we handle personal data inside a client’s own systems as part of a project, we usually do so as a processor acting on that client’s instructions. In plain terms: the records in your CRM stay yours, and we only do what you have told us to do with them. That work is governed by the contract and data processing terms agreed with the client, not by this notice.
What we collect
Enquiries
Your name, company, email address, telephone number if you give one, the type of work you are asking about, the budget band and timescale you select, and whatever you write in the message.
Sales portal accounts
Where you are authorised to use our internal sales portal: your name, work email address, role and permissions, and a record of activity within the workspace.
Technical data
Our hosting provider records standard server information such as IP address, request time, page requested and browser user agent. Any additional measurement or analytics in use must be listed here: [list analytics and measurement tools, or state none].
Why we use it, and our lawful basis
Under the UK GDPR we have to be able to say what allows us to hold each thing, for each reason we hold it. Our answers are in the table below.
Purpose
Data used
Lawful basis
Replying to an enquiry
Data Contact details and the content of your message
Basis Legitimate interests — responding to someone who has asked us to
Preparing a proposal
Data Contact details, requirements, budget band, timescale
Basis Steps taken at your request before entering a contract
Delivering an engagement
Data Client contacts, account and workspace records
Basis Performance of a contract
Running and securing the site
Data Server logs and technical data
Basis Legitimate interests — availability, security and abuse prevention
Accounting and tax records
Data Billing contacts and transaction records
Basis Legal obligation
Marketing email, if any is sent
Data Name and email address
Basis Consent, withdrawable at any time
Where we rely on legitimate interests, we have considered whether that interest is overridden by your rights, and you can object at any time using the contact details above.
Transfers outside the UK
Some providers may process data outside the United Kingdom. Where that happens we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, with appropriate safeguards in place.
The transfers that actually occur must be recorded here: [list each provider, the country, and the safeguard relied on].
How long we keep it
We keep personal data only for as long as we need it, then delete it. The periods below are suggestions in a draft, and must be checked against how the business actually works before this notice is published.
- Enquiries that do not become projects [suggested: 12 months]
- Client project records [suggested: 6 years from the end of the engagement]
- Accounting records [statutory minimum: 6 years]
- Server logs [confirm with the hosting provider]
Your rights
Under the UK GDPR and the Data Protection Act 2018 you have the right to ask us for a copy of your personal data, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to processing, and to receive data you gave us in a portable format. Where we rely on consent, you can withdraw it at any time.
To exercise any of these, email hello@remedium.digital. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are not satisfied with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first so we can put it right.
How we protect it
Access to client systems and to the portal is restricted to the people who need it, and permissions are agreed with the client before a system goes live. Accounts are individual rather than shared, and access is removed when an engagement ends.
The specific technical measures in place — encryption in transit and at rest, backup policy, access review frequency, incident response — must be described here rather than implied: [describe the actual security measures].
Changes to this notice
We will update this notice when what we do with personal data changes. The version and the date it took effect are shown at the foot of the page. Material changes affecting existing clients will be notified directly rather than published quietly.
Effective date [to be set on publication]Last reviewed [not yet reviewed]
Questions about this document go to hello@remedium.digital. The two legal documents on this site are the privacy notice and the terms of business.
01Anything unclear