Who are we, and what is this document for?

The Mayphil (UK) Limited group of companies (“Mayphil Group”) is made up of different legal entities, details of which can be found in Appendix 1 to this Policy. This Privacy Policy is issued on behalf of the Mayphil Group so when it states “the Company”, “Group”, “we”, “us” or “our” in this Privacy Policy, it is referring to the whole Mayphil Group or the relevant company in the Mayphil Group responsible for processing your data. You will be advised which entity will be the controller of your data when you purchase a product or service from us. The Mayphil Group is committed to protecting the privacy and security of your personal information.

“Personal information” or “personal data” means any information about an individual from which that person can be identified, either on its own or by combining it with other information the Company has.

This Privacy Policy describes how we look after your personal data generally and when you visit our website (regardless of where you visit it from) and describes your privacy rights under data protection laws.

Our websites are not intended for children and we do not knowingly collect data relating to children.

It is important that you read this Privacy Policy together with any other privacy notice or policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data.

We may update this policy at any time.

The Company is the “controller” of and responsible for any personal data we hold about you and for any Group company website. This means that we are responsible for deciding how we hold and use that information and are required under data protection laws to notify you of the information contained in this Privacy Policy.

We have appointed a Data Protection Officer (DPO) responsible for dealing with any issues relating to this Privacy Policy, who can be contacted via email at: DPO@Mayphil.com

In the event that the relevant company in the Mayphil Group responsible for processing your data is outside the European Union, the Company’s representative in the European Union for data protection matters is the Data Protection Officer (DPO) who can be contacted via email at: DPO@Mayphil.com

It is important that you read this Policy and any other privacy notices and policies we may provide on specific occasions when we are collecting or processing personal information about you so that you are aware of how and why we are using such information.

Third-party links

The Mayphil Group websites may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.

When you leave our website, we encourage you to read the privacy policy of every website you visit.

Facebook collects user information (including personally identifiable information) from Facebook, Instagram, Messenger and other products and features offered by Facebook apps and other technologies like tags, pixels or unique tracking codes (“Facebook User Data”). Facebook uses Facebook User Data for purposes of delivering Facebook Ads including, where applicable, retargeting and conversions. Facebook uses Facebook User Data for its own purposes, including to improve its services. To learn more about how Facebooks collects, uses and processes information and how you can manage or delete information about you please see its Data Policy.

Google Analytics is a third-party analytics service. We use Google Analytics to collect information about the use of this Site. Google Analytics collects information on visitor behaviour on this Site such as how often users visit this Site, what pages they view when they do so, and what other websites they used prior to coming to this Site. We use the information we get from Google Analytics to analyse user behaviour, improve Site performance, personalize the user experience, and analyse the effectiveness of our marketing campaigns. Google Analytics collects only the IP address assigned to you on the date you visit this site, rather than your name or other identifying information. Google Analytics anonymizes the IP address before it is stored. We do not receive the non-anonymised IP address. We may combine the Google Analytics data with first and third-party data information which may include personally identifiable information. Although Google Analytics plants a permanent cookie on your web browser to identify you as a unique user the next time you visit this site, the cookie cannot be used by anyone but Google. To learn more about how Google collects and uses data, see its Privacy and Terms. For opt-out options specific to Google Analytics, please see its Google Analytics Opt-out Browser Add-on.

 

Cookies

In the event that we utilise cookies on our websites, you can set your browser to refuse all or some browser cookies or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.

What kinds of personal information do we hold about you?

We will collect, store, and use the following categories of personal information about you:

Government Corporation Code, Chamber of Commerce Number, Credit Agency Code, Driving Licence Number, Global Tracking Name, Road Carrier Registration Number, SEPA Creditor Identifier, Shipping Company Carrier / Principal Code and Standard Industrial Classification

 

 

Sensitive data

We do not anticipate needing to collect, store or use “special category” (more sensitive) personal information, which means information about your:

If this changes, we will inform you and, where required by law, obtain your clear consent before doing so.

We do not expect that we will need to process information about you regarding criminal proceedings and convictions (‘Criminal Data’). We will only process Criminal Data:

If we do need to process Criminal Data, we will keep you informed as necessary where this is permitted by law.

How do we collect your personal information?

We collect personal information about customers, clients, suppliers, shareholders, website users and others, either directly from the individuals themselves or sometimes from a third party such as a credit bureau.

We will collect additional personal information in the course of our service-related activities throughout our relationship with you.

How will we use your personal information?

We need all the categories of information listed above (under ‘What kinds of information do we hold about you?’) mainly so we can:

We will use your personal information to pursue legitimate interests of our own or those of third parties, provided your own interests and fundamental rights do not override those interests. The situations in which we will process your personal information include:

Some of the above grounds for processing will overlap and some processing of your personal information may be based on several grounds.

If you fail to provide personal information

If you fail to provide certain personal information when requested, we may be unable to comply with our legal obligations or perform the contract we have with you or are trying to enter into with you (for example, to provide you with our products or services). We will notify you at the time if this is the case.

Change of purpose

We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for a different purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal information without your knowledge or consent where this is required or permitted by law.

Automated decision-making

Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention. We are allowed to use automated decision-making using your personal information if:

  1. we have notified you of the decision and given you 21 days to request a reconsideration; or
  2. the automated decision-making is necessary to perform our contract with you and appropriate measures are in place to safeguard your rights; or
  3. in limited circumstances, with your explicit written consent and where appropriate measures are in place to safeguard your rights.

We will only make an automated decision about you on the basis of any particularly sensitive personal information if:

We do not envisage that any decisions will be taken about you based solely on automated decision making, but we will notify you in writing if this position changes.

Sharing your information with others

We may need to share your personal information with third parties, including government or regulatory authorities, third-party service providers and other entities in the Mayphil Group of Companies, so we or our Group can supply you with our products and services. Further details on the Mayphil Group of Companies may be found in Appendix 1.

Where we do share your information with third parties, they will be under binding contractual obligations to respect the security of your data and to treat it in accordance with the law.

We may transfer your personal information outside the UK and European Economic Area (EEA), but if we do, any such transfer will be subject to the necessary legal measures for safeguarding that information.

Why might we share your personal information with third parties?

We will share your personal information with third parties:

For example, we may share your personal information with other entities in our group as part of our regular reporting activities on company performance, in the context of a business reorganisation or group restructuring exercise, for system maintenance support and hosting of data.

All our third-party service providers and other entities in the group are required to take appropriate security measures to protect your personal information in line with our policies. We do not allow our third-party service providers to use your personal data for their own purposes – they are only permitted to process your personal information for specified purposes and in accordance with our instructions.

Data security

We have put in place:

We also restrict access to your personal information to those of our employees, agents, contractors and other third parties who have a business need to know, and on the basis that:

 

Cross-border transfers of data

Data protection laws restrict transfers of personal information to other countries unless certain conditions are met.  As you are working with an International group of companies, we may transfer data within the Group.  

We will however only transfer personal data outside the UK / EEA if we have a proper legal basis for doing so and at least one of the following conditions applies:

 

How long will we keep your information?

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

In some circumstances we may anonymise your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you. Once you no longer have a working relationship with the company, we will retain and securely destroy your personal information in accordance with applicable laws and regulations.

Updating your information

It is important that the personal information we hold about you is accurate and up-to-date. Please let us know if your personal information changes during your working relationship with us.

Your rights in connection with personal information

Under certain circumstances, you have the right by law to:

 

If you want to review, verify, correct or request erasure of your personal information, object to the processing of your personal data, or request that we transfer a copy of your personal information to another party, please contact our Data Protection Officer at DPO@Mayphil.com

You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, if your request for access is clearly unfounded or excessive, we may charge a reasonable fee or refuse to comply with the request.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

Right to withdraw consent

In the limited circumstances where we have relied on your consent for the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw that consent at any time. To withdraw your consent, please contact our Data Protection Officer at DPO@Mayphil.com Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis in law for doing so.

Questions and complaints

We have appointed a manager responsible for overseeing compliance with this Privacy Policy and any privacy notice we may issue. If you have any questions or complaint about this Policy or any notice on how we handle your personal information, or any requests to exercise your rights in relation to your data, please contact our Data Protection Officer at DPO@Mayphil.com

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues. Details of how to make a complaint are available on the ICO website at https://ico.org.uk/

Changes to this privacy policy

We reserve the right to update this Privacy Policy or any privacy notice at any time. Any changes we may make to this policy in the future will be posted on Group websites so we recommend that you check the Group websites from time to time to take note of any changes we make, as they are binding on you if you provide us with information after such a change has been made. We may also notify you in other ways from time to time about the processing of your personal information.