Last updated: 15/01/2021
Key ESG Limited (“We”) are committed to protecting and respecting your privacy.
For the purpose of the EU General Data Protection Regulation 2016/679 (GDPR), the controller of your data is Key ESG Limited, a company registered in England and Wales under company number 12899170 whose registered office is at 81 King's Road, SW3 4NX, London, United Kingdom.
All personal data will be held and processed in accordance with applicable data protection and privacy law, including the GDPR, the GDPR, Electronic Communications (Amendments etc) (EU Exit) Regulations 2019, the CCPA (as defined below) and the Data Protection Act 2018.
We may collect and process the following data about you:
- Information you give us. You may give us information about you by filling in forms on our website or by corresponding with us by phone or email. This includes information you provide when you register to use our site, onboard as a client to our services, provide any information to our site, make an enquiry, provide feedback and when you report a problem with our site.
The information you give us may include your name; address; e-mail address; phone number; billing information; personal identification (such as passports, driving licenses and other information required for us to carry out client background checks); date of birth; country of residence; photographs; organisation details (if relevant); or other personally identifiable information in documents that you send us.
- Information we collect about you. With regard to each of your visits to our site we may automatically collect the following information:
- information about your visit, including the full URL clickstream to, through and from our site (including date and time); pages you viewed or searched for;
- page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page;
- internet protocol (IP) address, your location data, login data, browser type and version, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our website.
- Information we receive from other sources. We also work with third parties (including, for example, clients, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them.
Uses made of the Information
We use information held about you in the following ways:
- Information you give to us. We will use this information:
- to carry out our obligations arising from any contracts entered into between you and us and to provide you with the information, products and services that you request from us;
- to perform anonymised analytics on our clients and community members to ensure we are providing the best possible client service;
- to aggregate (in an anonymised form) for drawing conclusions about our services and relevant industry trends including those relating to ESG reporting and other impact measurements;
- to provide you with information about other goods and services we offer that are similar to those that you have already purchased;
- to collect feedback from people and businesses and for staff training purposes;
- to provide you with information about goods or services we feel may interest you. If you are an existing customer, we will only contact you by electronic means information about goods and services similar to those which were the subject of a previous sale to you, and you will be given an option to unsubscribe with each communication. If you are a new customer, and where we permit selected third parties to use your data, we (or they) will contact you by electronic means only if you have consented to this. If you do not want us to use your data in this way, or to pass your details on to third parties for marketing purposes, please tick the relevant box situated on the form on which we collect your data;
- to notify you about changes to our service;
- to ensure that content from our site is presented in the most effective manner for you and for your computer; and
- for any purposes required by law such as for tax, legal, reporting and auditing obligations.
- Information we collect about you. We will use this information:
- to administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
- to improve our site to ensure that content is presented in the most effective manner for you and for your computer;
- to allow you to participate in interactive features of our service, when you choose to do so;
- as part of our efforts to keep our site safe and secure;
- to measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you;
- to make suggestions and recommendations to you and other users of our site about goods or services that may interest you or them.
- Information we receive from other sources. We may combine this information with information you give to us and information we collect about you. We may us this information and the combined information for the purposes set out above (depending on the types of information we receive).
Where we receive personally identifiable information about you from our clients in the course of us providing legal services to our clients, we will only use it to the extent necessary for us to fulfil these legal services.
The Legal Basis for Processing your Information (for the UK and the EEA)
In accordance with GDPR, the main grounds that we rely upon in order to process your information are as follows:
- Necessary for entering into or performing a contract. In order to perform obligations which arise under any contract we have entered into with you, it will be necessary for us to process your information.
- Necessary for compliance with a legal obligation. We are subject to certain legal requirements which may require us to process your information. We may also be obliged by law to disclose your information to a regulatory body or law enforcement agency.
- Necessary for the purposes of legitimate interests. Either we or a third party will need to process your information for the purposes of our (or a third party’s) legitimate interests, provided that we have established that those interests are not overridden by your rights and freedoms (including your right to have your information protected). Our legitimate interests include responding to requests and enquiries from you or a third party, optimising our website and user experience, informing you about our services and ensuring that our operations are conducted in an appropriate and efficient manner.
- Consent. In some circumstances, we may ask for your consent to process your information in a particular way.
Your Rights (for the UK and EEA)
You have certain rights in relation to the personal data that we hold about you. Details of these rights and how to exercise them are set out below. Please note we will require evidence of your identity before we are able to respond to your request.
- Right of Access. You have the right at any time to ask us for a copy of the personal information that we hold about you and to check that we are lawfully processing it. Where we have good reason, and if the GDPR permits, we can refuse your request for a copy of your personal information, or certain elements of the request. If we refuse your request or any element of it, we will provide you with our reasons for doing so.
- Right of Correction or Completion. If personal information we hold about you is not accurate or is out of date and requires amendment or correction you have a right to have the data rectified or completed.
- Right of Erasure. In certain circumstances, you have the right to request that personal information we hold about you is erased e.g. if the information is no longer necessary for the purposes for which it was collected or processed or our processing of the information is based on your consent and there are no other legal grounds on which we may process the information.
- Right to Object to or Restrict Processing. In certain circumstances, you have the right to object to our processing of your personal information. For example, if we are processing your information on the basis of our legitimate interests and there are no compelling legitimate grounds for our processing which override your rights and interests. You may also have the right to restrict our use of your personal information, such as in circumstances where you have challenged the accuracy of the information and during the period where we are verifying its accuracy.
- Right of Data Portability. In certain instances, you have a right to receive any personal information that we hold about you in a structured, commonly used and machine-readable format.
In such circumstances, you can ask us to transmit that information to you or directly to a third party organisation.
While we are happy for such requests to be made, we are not able to guarantee technical compatibility with a third party organisation’s systems. We are also unable to comply with requests that relate to personal information of others without their consent.
You can exercise any of these rights at any time by contacting us using the details in the ‘Contact’ section below.
Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliate such as Stripe or our Facebook, Twitter, Instagram, LinkedIn or other social media pages. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
Right to Withdraw Consent
In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. You can do this by contacting us using the details in the ‘Contact’ section below.
Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
Your rights (for California)
When it comes to your rights as a consumer, we want to make sure you have everything you need to make informed decisions. You have the right to:
Know how your personal information is used;
Access, request and receive the personal information we have collected in a portable manner;
Object to having your data sold or shared; and
request that we delete your personal data.
Consistent with California law, if you choose to exercise your rights, we won’t charge you different prices or provide different quality of services unless those differences are related to your information. Consistent with California law, you may designate an authorized agent to make a request on your behalf. In order to designate an authorized agent to make a request on your behalf, you must provide a valid power of attorney, the requestor's valid government issued identification, and the authorized agent’s valid government issued identification.
How we process your information
Disclosure of your Information
We may share your personal information with any member of our group from time to time, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.
We may share your information with selected third parties including:
- Business partners, suppliers, regulatory bodies, membership organisations and sub-contractors for the performance of any contract we enter into with them or you.
- Advertisers and advertising networks that require the data to select and serve relevant adverts to you and others.
- Analytics and search engine providers that assist us in the improvement and optimisation of our site.
- Credit reference agencies or background checking service providers for the purpose of assessing your credit score where this is a condition of us entering a contract with you.
- Should it be reasonably necessary, professional advisors including debt recovery organisations.
- In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
- If Key ESG Limited or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
- Our website may include links to third-party websites, such as Stripe or our Facebook, Twitter, Instagram and/or LinkedIn social media pages. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy policies. You should read any policies and other statements on such websites carefully.
Where we Store your Personal Data
To the extent that any of your data is provided to third parties outside the EEA, or accessed by third parties from outside the EEA, we will ensure that appropriate safeguards are in place in accordance with the GDPR (such as the European Commission’s standard contractual clauses).
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
How Long we Hold your Information
We will only retain your information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements. The criteria that we use to determine retention periods will be determined by the nature of the data and the purposes for which it is kept, the sensitivity of the data and the potential risk of harm from unauthorised use or disclosure.
If you are unhappy about our use of your information, you can contact us using the details in the Contact section below. You are also entitled to lodge a complaint with the UK Information Commissioner’s Office using any of the below contact methods:
Telephone: 0303 123 11113
Website: https://ico.org.uk/make-a-complaint/ (https://ico.org.uk/make-a-complaint/)
Post: Information Commissioner’s Office
If you live or work outside of the UK or you have a complaint concerning our activities outside of the UK, you may prefer to lodge a complaint with a different supervisory authority. A list of relevant authorities in the EEA can be accessed here (http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm).
If you have any questions about how we collect, store or use your information, please contact us at email@example.com