Who are we?
DT Information Governance Ltd is a privately-owned training and consultancy company. We carry out these services for a range of clients and it is very important to us that we respect the privacy and protection of personal data. This Privacy Notice sets out how we process personal data (information) that we may collect during our work with you or when you contact us, how we will use it responsibly and how we keep it safe and secure. It also demonstrates our commitment to complying with the UK and EU General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA) and the Data (Use and Access) Act 2025.
We are the ‘Controller’ of the personal data you provide to us. Our Data Protection Officer is Deborah Topping. You can contact her at info@dtinformationgovernance.co.uk.
What data we need
We will collect personal data about you that includes name, address, email and contact number.
We will not ordinarily collect any special types of information such as health information (unless this is necessary for food allergies or accessibility on one of our public courses); and we will not collect any personal data from you we do not need in order to provide the services to you.
How we get the information and why we have it
Most of the information we process is provided to us directly by you for one of the following reasons:
- You are a client that we are working with and we need to collect this information to enable us to work with you;
- You have asked or agreed (consented) to join our mailing list or to receive news updates
- Where we may provide you with updates on our services;
- We are monitoring contracts with individuals and performance of these;
- You are joining a training course with us;
- You have completed out ‘Get in Touch’ contact form;
- You have visited our website and cookies have been applied or accepted.
We may also receive information indirectly, from the following sources in the following scenarios:
- Your employer if they are our client;
- The charity that you are a trustee or volunteer for when the charity is our client;
We will also use the data or information you provide to us to create invoices which will be recorded on our invoice/payment records.
Why we need it – Our lawful bases
We have a number of lawful bases for processing your information in line with GDPR. These vary depending on the work or support we are providing to you.
Where we have agreed to work with you as an individual, or to provide with you with training, our lawful basis will be a contractual obligation.
If you have joined our mailing list, or you have filled in our contact form, the lawful basis will be consent. You are able to withdraw or remove your consent at any time by contacting us at info@dtinformationgovernance.co.uk .
We have a legal obligation to hold financial information so when we invoice you or you pay us, we will comply with all finance and HMRC legislation. We also have a legal obligation to comply with contract laws.
To enable us to operate and administer our business, and to ensure that we can business plan effectively, we have a legitimate interest in processing some personal information. This helps us to remain accountable to our clients.
How we store your personal data
Keeping personal data safe and secure is important to us and we have policies and procedures to do this. We use Microsoft 365 Business to store your personal data and emails. Where possible we will store your data in the UK, however, the service provider may use storage facilities within the EU/EEA. and where this happens, we will ensure we have contracts in place and have undertaken due diligence on how your data will be protected in the other country
For security, our devices have passcode or fingerprint authentication and all software including antivirus/firewall is kept up to date.
We ensure that we have contracts in place for any external service providers such as our accountant, who may have access to name and address for the purpose of preparing accounts.
We do not…
Unless we are required to share your data with them by law or we are ordered to do so by a Court, we do not allow any other third parties to have access to your personal data.
We do not knowingly transfer your personal data to third countries outside of the EEA. We do not make automated decisions on your data, nor do we use your data for profiling purposes. Where AI is embedded in any systems we use, we take all reasonable steps to restrict the use of AI to anonymised data.
Our service and website are not designed for use by children or young people.
How long we keep it
We have a retention schedule which details how long we keep data for. In general we will keep it for a period that is required by law, for example financial records or HMRC records will be kept for 6 years; contracts will be kept for 6 years after the end date of the contract. We may keep personal data for longer if have consented to us keeping it or you have asked us to keep it.
When we no longer need to keep your personal data, we will then dispose of this by secure shredding (paper records) or by secure and permanent deletion (electronic records).
What are your rights?
You have a number of rights relating to the processing of your personal data.
- A right to be informed – This privacy notice fulfils that right.
- A right of access to your personal data held by us, also called a Subject Access Request.
- A right to rectify any personal data held by us that you believe is incorrect.
- A right to erase any personal data that we no longer have a legitimate purpose to process (right to be forgotten).
- A right to restrict the processing of your personal data subject to certain condition and obligations.
- A right of access to a machine-readable version of your data (data portability). There are conditions that apply to this right.
- A right to object to us processing any of your data that we do not have a legal or contractual obligation to process.
- Rights linked to automated decisions or profiling involving your data (we do not undertake any automated decisions or profiling).
- A right to complain directly to us if you believe we have handled your personal data incorrectly or failed to comply with your rights.
We are obliged to comply with these rights within one month unless there are some complex issues. We will tell you if the extended timescale applies to your request.
Generally, there are no charges for exercising (requesting) these rights. The exception is when you ask for further copies of your personal data that we have already provided to you. We will tell you if this applies. If you wish to exercise any of your rights, please email info@dtinformationgovernance.co.uk.
Where you have provided personal data with consent, you can withdraw this consent at any time. Please send an email to info@dtinformationgovernance.co.uk with the subject “withdraw consent” if you wish to do this.
More information on your rights can be found on the Information Commissioner’s website at www.ico.org.uk .
Complaints
We are sure that you will not need to complain, but just in case, if you wish to raise a complaint on how we have handled or processed (used) your personal data, or you have a complaint about the accuracy or retention of your data for example, you should contact us. We will acknowledge within 30 days as outlined in the amended legislation although we aim to do this sooner. We will investigate the matter without undue delay and will provide you with an outcome. If the investigation takes longer than anticipated, we will keep you informed of progress.
If you are not satisfied with our response or believe we are processing your personal data in a way that is not in accordance with the law you have a right to complain to the UK Information Commissioner’s Office. Telephone 0303 123 1113 (local rate) or complete their online form at https://ico.org.uk/make-a-complaint/your-personal-information-concerns/
