Privacy Policy

1. INTRODUCTION

This privacy notice provides you with details of how we collect and process your personal data through your use of our site www.heatheriscott.com.

This website is not intended for children and we do not knowingly collect data relating to children.

2. ABOUT

Heather I Scott Ltd is limited company register in Scotland under number SC689782 and our registered office is at 34d Forsyth Street, Greenock PA16 8DT.

If you need to email us about anything related to this privacy notice you can do so at hello @ heatheriscott.com or your can write to us at our registered address (above).

Heather I Scott Ltd is the data controller and we are responsible for your personal data (referred to as “we”, “us” or “our” in this privacy notice)

3 .WHAT PERSONAL DATA WE COLLECT ABOUT YOU

Personal data means any information capable of identifying an individual. It does not include anonymised data.

We will try and limit any personal data we collect to a minimum and aim to only keep this information as long we feel is necessary.  There are some instances where are legally obliged to keep your information for a determined period of time.

Examples of personal information we typically collect when we do work for you:

  • Names and addresses

  • Email addresses

  • Telephone numbers

  • Information held by HMRC

  • Information required to prepare tax returns

  • Information required to prepare your accounts

  • Correspondence between us

Examples of personal information we collect when you use our website:

  • Name (via our contact form)

  • Email address (via our contact form)

  • Contact number (via our contact form)

  • Any information you disclose in the form

4. HOW WE USE YOUR PERSONAL DATA

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Where we need to perform the contract we are about to enter into or have entered into with you.

  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.

Where we need to comply with a legal or regulatory obligation.

5. DATA RETENTION

We will only retain your personal data for as long as is necessary to fulfil the purposes for which it is collected.

When assessing what retention period is appropriate for your personal data, we take into consideration:

• The requirements of our business and the services provided;

• any statutory or legal obligations;

• the purposes for which we originally collected the personal data;

• the lawful grounds on which we based our processing;

• the types of personal data we have collected;

• the amount and categories of your personal data; and

• whether the purpose of the processing could reasonably be fulfilled by other means.

• Change of purpose

Where we need to use your personal data for another reason, other than for the purpose for which we collected it, we will only use your personal data where that reason is compatible with the original purpose.

Should it be necessary to use your personal data for a new purpose, we will notify you and communicate the legal basis which allows us to do so before starting any new processing.

6. DATA SHARING

Why might you share my personal data with third parties?

We will share your personal data with third parties where we are required by law, where it is necessary to administer the relationship between us or where we have another legitimate interest in doing so.

Which third-party service providers process my personal data?

“Third parties” includes third-party service providers. The following activities are carried out by third-party service providers: IT and cloud services, professional advisory services, administration services and banking services.

All of our third-party service providers are required to take commercially reasonable and appropriate security measures to protect your personal data. We only permit our third-party service providers to process your personal data for specified purposes and in accordance with our instructions.

7. TRANSFERRING PERSONAL DATA OUTSIDE THE UK

We do not transfer your personal data outside the UK

8. DATA SECURITY

We have put in place commercially reasonable and appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.

9. YOUR LEGAL RIGHTS

Under data protection laws you have rights in relation to your personal data that include the right to request access, correction, erasure, restriction, transfer, to object to processing, to portability of data and (where the lawful ground of processing is consent) to withdraw consent.

You can see more about these rights at: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/

If you wish to exercise any of the rights set out above, please email us at hello @ heatheriscott.com

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive or refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you.

If you are not happy with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We should be grateful if you would contact us first if you do have a complaint so that we can try to resolve it for you.

10. CHANGES TO THIS NOTICE

This privacy notice was last updated on 10th March 2022.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.