Privacy Policy – incorporating ‘GDPR 2018’
The Data Protection Officer (DPO) responsible for compliance with the General Data Protection Regulations 2018, for Carey Adams Strategies, is Carey Adams.
The reason for processing client or prospective client data is to promote and deliver personal careers advice and guidance services to individuals and organisations.
The lawful basis for processing this data is summarised as being a ‘contract’. The gathering, holding and working with the data is necessary for delivering a contracted careers advice service to an individual or an organisation, or necessary to the steps taken before entering into a contracted service.
The data is obtained, by being given freely and knowingly by the careers advice client or prospective client at various points during the relationship and may be communicated by;
- Telephone calls
- Emails and attachments
- Website enquiry forms
- Face-to-face meetings
- Video call meetings
The data is stored and secured in a number of ways;
- Emails and attachments stored on an internet service provider’s server
- Printed and handwritten notes stored in files, kept in a dedicated office, secured under lock and key
- Database records stored on a computer hard disk drive, protected by password and secured under lock and key
- Names and phone numbers stored on a mobile phones, protected by fingerprint identification and/or passcode
The data is stored for a limited period. Clients’ data is held for up to 10 years, in order to provide an on-going service to them.
The data is not shared with any other organisations.
Different kinds of data are processed to deliver the personal careers advice and guidance. We may hold a client’s or a prospective client’s data such as;
- Name, address, phone number, email address
- Gender, age, educational level
- Job titles
- Work organisations
- CV, application form, cover letter and LinkedIn profile
- Job and career issues regarding; career direction, job hunting, CVs and application forms, and job interviews.
- Careers advice and guidance services provided ; date, time, duration, contact method, specific service provided, and rate charged.
- We do not record or hold any audio or video material of clients or prospective clients.
In the event of a breach of the data regulations, such as; loss of paperwork, loss of IT devices, forced access to data by malware etc. – Carey Adams Strategies will inform the client or prospective client within 24 hours and seek to rectify the situation as quickly as possible.
Clients and prospective clients have the right to; know why and how their data is being processed – ask for a copy of the data held – have any data corrected that is inaccurate – have the data erased – place restrictions or a stop on the processing of the data – obtain and re-use the data for their own benefit – object to the processing of the data – not be subject to automated decision-making including profiling. Full details on these rights are specified on the ICO website https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/. Clients and prospective clients wanting to exercise their rights should contact the Data Protection Officer (DPO) who is Carey Adams.
This privacy policy was last reviewed and updated on the 12th May 2024. It will be reviewed and updated again on or before the 12th May 2025.