1. Zweck
Thought Machine Group Limited und unsere Konzernunternehmen („Thought Machine“, „wir“, „uns“, „unser“) erheben und verarbeiten personenbezogene Daten in Übereinstimmung mit diesem Datenschutzhinweis sowie unter Einhaltung der einschlägigen Datenschutzgesetze und -vorschriften, einschließlich der britischen Datenschutz-Grundverordnung („UK GDPR“), des Data Protection Act 2018, der EU-Datenschutz-Grundverordnung („EU GDPR“) und aller anderen relevanten lokalen Datenschutzgesetze.
Dieser Hinweis fasst zusammen, welche personenbezogenen Daten wir möglicherweise erheben und wie wir Ihre Informationen verwenden. Das Engagement von Thought Machine für den Datenschutz spiegelt den Wert wider, den wir darauf legen, das Vertrauen unserer Kunden, Partner, Lieferanten und anderer Personen, die ihre personenbezogenen Daten mit uns teilen, zu gewinnen und zu bewahren.
2. Begriffsbestimmungen
Ein „Kunde“ ist jede Person oder Organisation, die ein Kunde von Thought Machine ist.
„Verarbeitung“ bezieht sich auf alle Vorgänge oder den Umgang mit personenbezogenen Daten durch manuelle oder automatisierte Verfahren, z. B. Datenerhebung, Löschung und Vernichtung sowie alles dazwischen, einschließlich Aufzeichnung, Nutzung, Offenlegung, Weitergabe und Speicherung.
Ein „Verantwortlicher“ ist eine natürliche oder juristische Person, die:
- Entscheidet, personenbezogene Daten zu erheben oder zu verarbeiten.
- Entscheidet, was der Zweck oder das Ergebnis der Verarbeitung sein soll;
- Entscheidet, welche personenbezogenen Daten erhoben werden sollen;
- Entscheidet, von welchen Personen personenbezogene Daten erhoben werden;
Thought Machine gilt als Verantwortlicher für die Datenverarbeitung, wenn das Unternehmen personenbezogene Daten von Kunden, Lieferanten, Partnern und sonstigen Personen verarbeitet.
Eine „betroffene Person“ ist eine lebende natürliche Person, die anhand der personenbezogenen Daten oder zusätzlicher Informationen, die gespeichert oder erlangt wurden, identifiziert werden kann. Dies kann eine Person sein, die mit einem potenziellen oder bestehenden Kunden, Lieferanten oder Partner in Verbindung steht.
„Sonstige Partei“ bezeichnet jede Person oder Organisation, die kein Kunde, Lieferant oder Partner ist und mit der Thought Machine zu anderen Zwecken in Kontakt steht.
Ein „Partner“ ist jede Person oder Organisation, die mit Thought Machine bei der Bereitstellung und Implementierung der Produkte/Dienstleistungen von Thought Machine zusammenarbeitet oder kompatible Komponenten liefert, die die Produkte von Thought Machine ergänzen.
„Personenbezogene Daten“ sind alle Informationen, die sich auf eine betroffene Person beziehen und dazu verwendet werden können, diese Person direkt oder in Verbindung mit anderen Informationen indirekt zu identifizieren. Dazu gehören unter anderem:
- Name einer Person
- Berufsbezeichnung
- Alter
- Post- oder E-Mail-Adresse
- IP-Adresse, z. B. Online-Kennung
- Kfz-Kennzeichen
- Bankverbindung
Es gibt „besondere Kategorien“ personenbezogener Daten. Dazu gehören unter anderem Daten, aus denen Folgendes hervorgeht:
- Rasse oder ethnische Herkunft
- Religiöse oder weltanschauliche Überzeugungen
- Gewerkschaftszugehörigkeit
- Sexuelle Orientierung
- Genetische oder biometrische Daten
Ein „Lieferant“ ist jede Person oder Organisation, die Thought Machine Waren oder Dienstleistungen bereitstellt
„Dritte“ bezeichnet zusammenfassend Kunden, Lieferanten, Partner und andere Parteien
3. Datenschutzgrundsätze
Thought Machine verpflichtet sich zur Einhaltung der Datenschutzgrundsätze gemäß der UK-DSGVO und anderer Datenschutzvorschriften. Das bedeutet, dass Ihre personenbezogenen Daten wie folgt verarbeitet werden:
- Rechtmäßig, nach Treu und Glauben sowie in transparenter Weise verarbeitet (Rechtmäßigkeit, Verarbeitung nach Treu und Glauben, Transparenz)
- Nur für einen festgelegten, rechtmäßigen Zweck erhoben (Zweckbindung)
- Angemessen, relevant und auf das notwendige Maß beschränkt (Datenminimierung)
- Richtig und, falls erforderlich, auf dem neuesten Stand gehalten (Richtigkeit)
- Nur so lange aufbewahrt, wie es für die von uns genannten Zwecke erforderlich ist (Speicherbegrenzung)
- Sicher aufbewahrt (Integrität, Vertraulichkeit und Sicherheit)
4. Personenbezogene Daten von Kunden, Lieferanten, Partnern und anderen Parteien
Als Verantwortlicher erhebt Thought Machine personenbezogene Daten zum Zweck der Kontaktaufnahme und Pflege der Beziehungen zu seinen Kunden, Lieferanten und Partnern. Thought Machine kann zudem personenbezogene Daten von anderen Parteien erheben, einschließlich, aber nicht beschränkt auf potenzielle Kunden oder Personen, die unsere Büros besuchen oder uns über unsere verfügbaren Kommunikationskanäle kontaktieren.
- Art der personenbezogenen Daten von Kunden, Lieferanten und anderen Parteien, die wir erheben
Zu den Arten personenbezogener Daten, die wir verarbeiten können, gehören:
- Kontaktinformationen von Personen, die einen Dritten vertreten oder in dessen Namen handeln, z. B. Name, Firmenname, Berufsbezeichnung, Telefonnummer, E-Mail-Adresse, Social-Media-Profil und weitere Kontaktdaten
- Videoüberwachungsaufnahmen von Besuchern, die die Büroräume von Thought Machine betreten haben
- Weitere Identifikationsmerkmale zur Überprüfung der Identität von Personen, die einen Dritten vertreten oder in dessen Namen handeln, z. B. Geburtsdatum oder Personalausweis(e)
- Bestimmte technische Daten bei der Interaktion mit und Nutzung unserer Website, z. B. IP-Adresse, Browsertyp und -version, Zeitzoneneinstellung und Standort, Browser-Plug-in-Typen und -Versionen, Betriebssystem und Plattform, Geräte-ID sowie weitere Technologien auf den Geräten, die Sie für den Zugriff auf unsere Website verwenden
- Nutzungsdaten, z. B. Informationen darüber, wie Sie mit unserer Website, unseren Produkten und Dienstleistungen interagieren und diese nutzen
- Benutzername, falls Ihnen im Namen Ihres Unternehmens Zugriff auf das Vault-Portal gewährt wurde
- Marketing- und Kommunikationsdaten, z. B. Ihre Präferenzen für den Erhalt von Marketingmaterialien und Ihre Kommunikationspräferenzen, sofern Sie Interesse an unseren Produkten oder Dienstleistungen bekunden oder eine Anfrage über unsere Website stellen
Thought Machine may anonymize or aggregate any of the information we collect and use it for any purpose, including for research and product development purposes. Such information will not individually identify any of our Clients, Suppliers, Partners and Other Parties is not personal data as it does not directly (or indirectly) reveal your identity.
- How we collect client, supplier and other party personal data
Thought Machine collects personal data:
- From you directly, by post, email telephone or other means, if you give us your personal data by filling in the online enquiry form on our website, request marketing to be sent to you or give us feedback or contact us
- In the course of offering or providing our services if you act on behalf of a Client, Partner or Supplier
- Automatically when you interact with our website, e.g., certain technical data about your equipment, browsing actions and patterns by using cookies and other similar technologies
- From third parties or publicly available sources for the purposes of marketing, Thought Machine may obtain contact details from third parties but only on a lawful basis where it is in the interest of prospective clients, suppliers and partners to know about Thought Machine’s products and services
We may also receive personal Data from public sources, mobile websites or applications you visit or from third parties we have engaged such as analytics providers, intelligence research organisations, search information providers, marketing platforms, recruitment agencies, business associates or subcontractors. In that case, we conduct the appropriate due diligence of such third parties and a risk-based assessment of the lawful basis for processing such personal information shared to us.
If you give us personal data in relation to another individual representing our client, supplier, partner or other party, you confirm that you have provided them the information set out in this privacy notice.
- How we use client, supplier and other party personal data
Thought Machine may use client, supplier, partner and other party personal data to:
- Develop and manage our relationship with potential and existing clients, suppliers, partners and other parties. This may include delivering services or carrying out work that a client, cupplier, partner or other parties have requested or that we are contractually obligated to do so
- Communicate with potential and existing clients, suppliers, partners and other parties. This may include: (i) informing our clients, partners or other parties of Thought Machine products and services that may be of interest to them; (ii) providing information about relevant Thought Machine products or services, including, for example, pricing information, invoices, shipping or production information; and (iii) responding to questions or inquiries from our clients, suppliers, partners or other parties
- To administer and protect our business and our website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
- To use data analytics to improve our website, products/services, customer relationships and experiences and to measure the effectiveness of our communications and marketing
Thought Machine may also use client, supplier, partner and other party personal data for other uses consistent with the context in which the information was collected or with your consent.
- Direct marketing
You may receive marketing communications from us if you have requested information from us or purchased goods or services from us and you have not opted out of receiving the marketing.
- Opting out of marketing
You can ask to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you or by contacting us (dpo@thoughtmachine.net).
If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes.
5. Legal Basis for Processing Client, Supplier, Partner and Other Party Personal Data
We must have a legal basis for using your personal data. We rely on one or more of the following lawful bases:
- Performance of a contract: To establish or carry out our contractual obligations and performing agreements with clients, suppliers, partners or other parties in connection with our products and services
- Legitimate interests: To enable our business or pursue legitimate interests, e.g., facilitating and personalising our interactions with you, notifying you with changes to our services and products, understanding your requirements and performing analysis and comparisons to obtain your view on our products and services, performing targeted marketing activities in order to establish a relationship with a client, analysing personal data, performing internal management and management reporting, managing our and administering safety and security measures
- Consent: Your consent, to supplement a contractual obligation or legitimate interest, or where either of these two bases otherwise does not exist
- Legal obligation: To comply with laws and protect our legal rights, in connection with reporting requirements under applicable laws, legal claims, compliance and regulatory investigative purposes (including disclosure of information in connection with legal process or litigation), and other compliance and ethics reporting
In the event a lawful basis cannot be determined for data collection, we will not collect or process it.
6. Sharing and Transferring Personal Data
Thought Machine may need to make international transfers of Personal Data by electronic or other means:
- Among Thought Machine group companies, including our various branches and offices in many parts of the world. Thought Machine has put in place data processing agreements to ensure that transfers are subject to data protection controls of the highest standards. This may include European Commission- and Information Commissioner’s Office-approved standard clauses and appropriate data transfer arrangements
- To and among third party processors (some of whom may be based outside the UK or the European Economic Area (EEA)) for any one or a combination of the following purposes:
- if we are legally obliged to do so
- where we need to comply with our contractual agreements to our clients, in the case of platform hosting providers, CRM and other technology providers; and
- to support our business, in the case of marketing service providers, survey providers, event organisers and digital agencies
When engaging third parties, we ensure that they are fully compliant with the GDPR and the applicable data protection law in your jurisdiction before engaging with them and, among others, by limiting their use of personal data for the services they perform on our behalf.
The personal data that transferees and third parties have in respect of our clients, suppliers, partners and other parties will be kept no longer than is necessary for the purposes for which they are processed, and all reasonable steps are taken to delete information when it is no longer required.
7. Data Retention
Thought Machine will store client, supplier, partner and other party personal data for the duration of our relationship with the relevant party, and for as long as is reasonably necessary for the purposes for which it was collected, as explained in this privacy notice. In some circumstances, we may store your personal data for longer periods of time, for instance where we are required to do so in accordance with legal, regulatory, tax, accounting, or necessary technical requirements.
In specific circumstances, we may store your personal data for longer periods of time so that we have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your personal data or dealings.
8. Data Security
Thought Machine takes privacy seriously and we have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
All our third party service providers and Thought Machine group companies are required to take appropriate security measures to protect your personal data in line with our policies. They may include encryption, physical access security or other tools that we believe enhance the security of our data processing systems.
We limit access to your Personal Data on a need-to-know basis using LDAP group memberships. Our employees, contractors and agents are subject to a strict duty of confidentiality and required to use personal data only in accordance with our instructions and not for any other purposes.
We have security measures and procedures in place to detect, identify and mitigate suspected and actual personal data breaches and will notify you and the relevant supervisory authority of a relevant personal data breach where we are legally required to do so.
9. Automated Decision-Making
We do not rely solely on automated decision-making. You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making.
10. Data Subject Rights
You have several rights in relation to your personal data that we hold:
- Right of access (commonly known as a “data subject access request”) - This enables you to receive a copy of the personal data we hold about you and to check we are lawfully processing it
- Right to rectification – This enables you have any incomplete or inaccurate information we hold about you corrected
- Right to erasure (also known as the ‘right to be forgotten”) – This enables you, in certain circumstances, to ask us to delete or remove personal data where there is no good reason for us continuing to process it
- Right to restrict processing – This enables you to ask us to suspend processing of your personal data, e.g., if you deem it is being used illegally or the data is not correct
- Right to object to processing - Where we are relying on legitimate interest, you can object to your personal data being used if it is not being used in the manner for which it was collected (e.g., profiting, automation, direct marketing)
- Right to data portability - Thought Machine must provide you with your personal data so that you can reuse it for your own purposes or across different services. We must provide it in a commonly used, machine-readable format
- Right to object to automated individual decision-making – Thought Machine must respect the rights of individuals in relation to automated decision-making and profiling
- Right to lodge a complaint – You have the right to lodge a complaint with the applicable data protection regulator or supervisory authority (e.g., the UK Information Commissioner’s Office)
- Right to withdraw consent (where consent is the lawful basis) - If you have provided consent for the processing of your personal data for the purposes of our recruitment process, you have the right to withdraw that consent at any time which will not affect the lawfulness of the processing before their consent was withdrawn. To withdraw your consent, or for any complaints, requests or queries, individuals should contact dpo@thoughtmachine.net.
Once we have received notification that you have withdrawn your consent, we will no longer process your application and, subject to our retention policy, we will dispose of your personal data securely. We may ask you to verify your identity before acting on the request - this is to ensure that your data is protected and kept secure.
11. Contact Details
Our Data Protection Officer is entrusted with monitoring and enforcing compliance with all data protection laws, to ensure that personal data that is collected and processed is handled appropriately.
If you have any questions or concerns about this privacy notice or how we handle your personal data, our Data Protection Officer can be contacted via the following e-mail address: dpo@thoughtmachine.net
Contact address: Data Protection Officer
7 Herbrand St, London WC1N 1EX
12. Complaints
You have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). However, before doing so please make sure you have first made your complaint to us or asked us for clarification if there is something you do not understand.
13. Changes to this Privacy Policy and Your Duty to Inform Us of Changes
We keep our privacy policy under regular review. Historic versions can be obtained by contacting us.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example a new address or email address.
