Home » Privacy notice
Reviewed and updated October 2024
At CEFM and under data protection laws we are deemed to be a ‘data controller’ in relation to some of the personal information (personal data) we process. We process personal data in a variety of ways and for various reasons.
This notice is to inform you of the personal data we hold, the reasons why we hold it and what you can do about any personal data we may hold on you.
This privacy notice may be updated from time to time and will be published on https://cefm.co.uk.
Within this privacy notice we will inform you of:
Personal data is any information that relates to you and can be used directly or indirectly to identify you.
Personal data and processing are defined as follows:
We process personal data in accordance with the following data protection principles:
When making contact with CEFM you may be asked for or will generally provide some personal details such as your name, job title, email address and contact telephone number. You may provide other aspects of personal data as well, such as transaction and billing information.
This information may come to us via email, letter, application/booking forms or telephone and you may be seeking quotations, advice or registering for updates.
Not all personal information will come directly from you. It may, for example, come from your past, current or future employer, who provides your details so that we can provide you with services. It may also come from a third-party or from a person who represents you.
Data may also come from publicly available sources such as LinkedIn, websites and published databases.
We retain emails, correspondence and records of telephone conversations/voicemail messages. The purpose of processing such information is so that we can:
In most cases, where we process special category data, it is provided to us by you or by your past, present or future employer in order to obtain advice and guidance. Where we provide services through partners and suppliers who process your special category data, we have no direct access to your data.
When you visit our website https://cefm.co.uk we use Google Analytics, a third party, to collect standard internet log information and visitor behaviour details.
We do this to find out which parts of our website are being used and why. The information collected does not identify anyone and we do not allow Google to use the information to identify anyone either. If we do collect information that identifies you personally we will be up front about it and notify you of what is being collected and why.
CEFM records the Internet Protocol (IP) address when registered users (including those who have a free trial) log into our CEFMi members area. This includes information such as the individual log in credentials such as email address and password. It may include your preferences. We also automatically collect data (such as browsing patterns) on each visit.
CEFM members who have access to the CEFMi area are required to log in using their registered credentials so that only authorised users have access to our services. This information is recorded.
We record such information to provide the service, to improve our overall service and to provide user analysis. We also do this to find out things like the number of visitors to our site and the areas our users are using (traffic data) and the resources you use.
We also use this information to maintain the security of our site and to ensure that it is not being used improperly or in breach of the agreement we hold with you.
CEFM will not disclose this personal data to third parties for any reasons other than those covered within this notice.
CEFM set and use cookies and similar technologies to store and manage user preferences, to enable content, and to gather analytic and usage data, for example.
Cookies are small text files that are placed on your computer or other device by websites that you visit.
The use of cookies is standard across websites and apps. They collect information about your online activities. They are used to make websites work, or work more efficiently, and enable the website owner to gain information on the site.
For further information on the cookies we use, please visit the ‘Cookies’ section of our website.
Most web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org.
There are several reasons why we hold, process and share individuals’ personal data. Under data protection laws, the lawful reasons for processing personal data include:
Sometimes the handling of your personal data falls within several of the above lawful grounds.
We may ask for your consent to use your information in certain ways. If we ask for your consent to use your personal data, you can take back this consent at any time. Any use of your information before you withdraw your consent remains valid.
Some of the stated purposes above will fall within the performance of a contract ground.
We need to process data to enter into the Service Level Agreements (SLAs) and to meet our obligations under such contracts. For example, we need to process your data to provide you with a contract, to set out the basis of our services and the terms and conditions.
On some occasions, CEFM will process your personal data for the performance of a contract that it may hold with a third party. For example, a data security contract with a third-party IT services provider or as part of cloud-based storage. Or to refer you to our legal team or other third parties described in our data share agreements.
Some of the stated purposes above will fall within the legal obligation ground.
In some cases, we need to process data to ensure that we are complying with our legal obligations to courts, public bodies and regulatory bodies.
Some of stated purposes above will fall within the legitimate interests ground.
We have a legitimate interest in processing personal data before, during and after the end of the contract, licence or SLA. Some examples include to:
At CEFM we store data, that may include personal data, in both electronic and non-electronic formats.
Our servers and storage systems are based in the EU or the European Economic Area (EEA) and we have ensured that appropriate safeguards are in place to protect your personal data.
We use cloud-based storage systems which are based in the UK.
We will only retain personal data insofar as it is necessary, and we have a right to do so. This can be after the contractual purpose, for which it has been collected, has been addressed. For example, CEFM may retain information for longer periods for accounting, business administration, legal and/or compliance reasons. We have a retention schedule that determines how long we hold data, including personal data.
Once retention of personal data is no longer necessary, we will ensure that the information is either returned to you or, if retained by us, anonymised or confidentially and irretrievably destroyed.
We take the security of your personal data very seriously. We have internal policies and controls in place to try to ensure that data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by our authorised personnel in the performance of their duties.
Where we engage third parties to process personal data on our behalf, they do so under a data share agreement and based on our written instructions, are under a duty of confidentiality and are obliged to implement appropriate technical and organisational measures to ensure the security of data.
We also adopt technical security measures such as using encryption software for files and emails. Our servers carry appropriate security and firewalls.
We may disclose your personal data to any of our employees, officers, agents, suppliers or subcontractors insofar as reasonably necessary for the purposes set out in this privacy notice.
CEFM will not share your personal data with third parties other than:
Where we do share information with third parties, we endeavour to ensure that the safety and security of such data is protected and not used for any purpose other than as required.
We do not make automatic decisions or undertake automated decisions regarding individuals to evaluate certain information about an individual (profiling).
CEFM may contact you by email, letter (newsletter) and telephone to promote our services and to provide you with details of management updates or training events.
You may request the removal of your details from such mailings at any time by following the unsubscribe link within the email.
This will not invalidate your ability receive any other services from us, such as our CEFMinform newsletter.
The CEFM website contains links to other websites. We are not responsible for the content of external sites and, while we endeavour to ensure their integrity, users following the links do so at their own risk and should familiarise themselves with the privacy policy of each site they visit.
You have the following rights in relation to your personal data. Some of these rights are new.
Further guidance and advice on the above rights can be obtained from the ICO’s website https://ico.org.uk/for-the-public.
If you have a concern about the way we are collecting or using your personal data, we ask that you raise your concern with us in the first instance by contacting CEFM’s data manager by writing to M1A Mosquito Studios, De Havilland Court, Penn Street, Amersham, HP7 0PX or via email privacy@cefm.co.uk
Alternatively, if we fail to respond within one month you can contact the Information Commissioner’s Office at https://ico.org.uk/concernsto raise any concerns you have.
One of the most comprehensive online resources available for school managers. Over 7,000 pages of downloadable model policies, templates, forms and guidance.
Get access to our documents and the next three editions of CEFMinform.