How we handle information (Personal Data or otherwise)

The Legal Bits:

From contact details to your confidential records, in this section we’ll take you through the various ways we look after that information.

Who ‘we’ are and where you can find details about us:

For information, this relates to the handling of information by Lighthouse IG Ltd, Registered in England & Wales, Company Number 12289984, Registered Office: Lime House, 75 Church Road, Tiptree, Essex, CO5 0HB.

We are also registered with the Information Commissioner’s Office under registration number ZA796768. 

‘Controller’ vs ‘Processor’:

For the purposes of our own recruitment, finances, insurances, and legal obligations we are a Data Controller

For the purposes of providing you with support, advice and X role ‘as a service’ Lighthouse IG is a Data Controller or Joint Controller depending on the circumstances.. 

For the purposes of the delivery of training sessions we are a Data Processor and our use of Personal Data will be minimal.

Data Processing Agreements:

In each contract we sign it will be outlined what role each party plays and whom is responsible for what where the processing and protection of any Personal Data is concerned. 

What do I do with your data?

In order to work with you I may have the following information at any given time. This will be known to you before I have it and is very much dependant on how I am working with you;

  • Personal Data on you or your staff
  • Personal Data on your customers/citizens
  • Business Confidential Data
  • Operational Confidential Data

Where possible all the data I have is electronic. Physical copies are discouraged however where this does occur they are handled to the same high standards. 

Please note, when paying invoices or for products I do not use or collect your payment information. This is either stored with you (BACS etc) or with PayPal if you are buying products. 

There are occasions where I need to use your information in order to;

  1. Contact you and discuss a service with your consent or as part of the contract
  2. Send you promotional material with your consent, including my blog posts
  3. Work with you to resolve a customer query, complaint or data issue as part of the contract
  4. To administer your attendance at a webinar or other online event with your consent (free ones) or contract (paid ones)
  5. For my own legal and accounting obligations where it is required for us to retain such data
  6. To take payment for any products & promotional merchandise as part of the conditions of sale (contract)
  7. As part of a reference for future client work with your consent

In so far as possible, I ensure that information is either kept within the United Kingdom or the European Union. I have technology that utilises both UK and EU servers. If any information needs to leave either of these locations I will discuss this with you before it does. 

In short, as short a time as is possible and necessary. As a summary;

  • General correspondence = 1 month from date created
  • Contracts = 7 years from delivery date
  • Advice and guidance = 7 years from case closure
  • Accounting information = 6 years from accounting year end
  • Webinar registration information = 5 days after event has occurred
  • Training materials and templates = until superseded unless otherwise agreed
  • Blog subscription data = until you unsubscribe when it will automatically be deleted.

Put simply, no. Your information is not used for analytical or machine learning related purposes. The tools I use to run the company and deliver my services are very ‘every day’ and simple. If this ever changes (because I’ve gone mad), I will consult you beforehand. 

I (with help from some partners below) deploy a number of things to look after and protect the data within my care. This includes (but isn’t limited to) the following; 

  • High standard passwords
  • 2 factor authentication on key systems
  • Encryption of remote devices
  • VPN for remote working
  • Contracts with third parties
  • External review and advice on security controls
  • Clear policies and training
  • Access controls (internal and external)

Where possible, only Lighthouse IG Ltd employees (me) will have ‘routine’ access to your data. However, for reasons like ‘IT maintenance’ and ‘accounting’, third parties will access your information on occasion. Further details on who these organisations are and what they might access are below for your reference. 

The following list is the various systems I use to deliver my services and their respective Data Protection summaries:

You have a number of rights over your data depending on what the data is and why I am holding it. If I can honour your request I will, otherwise I will explain why I cannot or may have to liaise with the respective Data Controller of that data. To find out what I have or exercise any rights over your information please contact info@lighthouseig.com (or your respective Data Controller if you know who that is). 

You also have a right to lodge a complaint with the Supervisory Authority (Information Commissioners Office (ICO) in the UK) about what I am doing. You can do this via www.ico.org.ukcasework@ico.org.uk or 0303 123 1113. 

My website uses very little technology in order to work. 

Cookies:

I only use cookies to remember your preferences, to enable the sharing of content on social media (should you chose to) and to protect the security of the website. Remembering your preferences and protecting the security of the site are necessary for the running of the website. Nether collect invasive information on you other than basic IP address and cookie preferences. The social media cookies however will only work with your consent and where you want to share something to your social media via the sharing links on the site.

 
Submitting queries & subscribing:
At each point where you can submit your personal data for a query or to subscribe I will outline what we do with that data. 
 
Third Party Websites:
Lighthouse IG Ltd cannot accept responsibility for any content on other websites that we may link to. This site does not share any data with those sites, including any preferences, therefore you need to ensure you read that sites privacy notices etc on your visit. 

Version Control:

Version 2.3 Issued 12th July 2021

Who do I share your data with?

Below is a list of partners I work with to deliver services. Some partners I will share personal data with to deliver your training course (for example) and others may only be on the odd occasion. Click on each one to see what I share with them and why. 

Lighthouse IG acts as a processor for the delivery of Act Now online and face-to-face courses. As a processor, we are bound by a contract with Act Now and handle information in accordance with their expectations

Lighthouse IG acts as a processor for the delivery of UMG online and face-to-face courses. As a processor, we are bound by a contract with UMG and handle information in accordance with their expectations

Lighthouse IG acts as a processor for the delivery of Essex Chambers of Commerce face-to-face courses. As a processor, we are bound by a contract with Essex Chambers of Commerce and handle information in accordance with their expectations

Lighthouse IG is provides trainer support for Leadership Through Data (LTD). Lighthouse IG acts as a processor for the delivery of LTD courses. As a processor, we are bound by a contract with LTD and handle information in accordance with their expectations

I work with YorCyberSec on occasion to deliver products and services to mutual clients. Where I do so, I handle information in accordance with that engagement contract. Click here to find out more about them as an organisation. 

We work with Cortida on occasion to deliver products and services to mutual clients. Where we do so, we handle information in accordance with that engagement contract. Click here to find out more about them as a orgnanisation. 

We work with ‘For Your Information’ (FYI) on occasion to deliver products and services to mutual clients. Where we do so, we handle information in accordance with that engagement contract. Click here to find out more about them as a organisation. 

I work with Tom Lingard at ‘The Remote Assistant’ Ltd to help me with general admin and to run my social media and mailing lists. Click here to find out more about them as a organisation. 

Cloud-Tree are responsible for hosting and supporting our IT software and tools. This may require on occasion the need to be exposed to your information. This is only on a case by case basis and as a processor, Cloud-Tree is bound to handle that information in a confidential manner. Click here to find out more about them. 

Thompson Reid are responsible for running my accounts and book keeping. This may require on occasion the need to be exposed to your information. This is only on a case by case basis and as a processor, Thompson Reid is bound to handle that information in a confidential manner. 

Hiscox Insurance provide our business insurance and legal advice services. This may require on occasion the need to be exposed to your information. This is only on a case by case basis and as a separate Data Controller, Hiscox is bound by contract to handle that information in a confidential manner. Click here to view further information on them.