Privacy & Security
As part of Membership Solution Ltd’s commitment to client care, we take care to protect the information you supply to us. MSL is registered with the ICO under the Data Protection Act 1998 with registration number Z1573054.
Why we are able to process your information
The personal information we process is provided to us directly by you for one of the following reasons:
- You have made an enquiry to us
- You have made an information request to us
- You wish to attend, or have attended, an event
- You subscribe to our newsletter
- You are representing your organisation
- You are a business partner of ours
- You provide services to us
- You have contacted us to discuss your own products/services with us
We may also receive personal information indirectly, in the following scenarios:
- Your contact details are provided to us by someone else representing your organisation
- An employee of ours gives your contact details as an emergency contact or a referee.
Under data protection law, you have certain rights we need to make you aware of. Your rights depend on our reason for processing your information and you can read more about these rights here.
Right of access
You have the right to ask us for copies of your personal information. This right always applies. There are some exemptions, which means you may not receive all the information we process.
Right to rectification
You have the right to ask us to rectify information you think is inaccurate and to complete information you think is incomplete. This right always applies.
Right to erasure
You have the right to ask us to erase your personal information in certain circumstances.
Right to restriction of processing
You have the right to ask us to restrict the processing of your information in certain circumstances.
Right to object to processing
You have the right to object to processing if we process your information because the process is in our legitimate interests.
Right to data portability
You have the right to ask that we transfer the information you gave us to another organisation or return it to you. This only applies to information you have given us and only if we are processing information based on your consent, or under (or in talks about entering into) a contract, and only if the processing is automated.
You do not pay a charge to exercise your rights. We have one month to respond to you.
Please contact us at firstname.lastname@example.org if you wish to make a request.
Purpose and legal basis for processing
Where MSL has a legal agreement with you or with the organisation you belong to, our legal basis for processing your personal data is because it is necessary to perform the contract
- This legal basis also applies if we are in discussions or preliminary steps towards entering a contract, for example if you have asked for product information or a quote.
||Where we process your data in order to carry out direct marketing activities it is because it is necessary for the purposes of our legitimate interests as a business which provides digital solutions to a defined niche market.
||The purpose for implementing the Live Chat facility, Analytics and Cookies is to maintain and monitor the performance of our website and to continuously improve the site and the services it offers to users. The legal basis we rely on to process your data in this case is because it is necessary for the purposes of our legitimate interests.
We retain personal data for as long as we provide services to you or your organisation. However, we may keep some data after you or your organisation ceases to use our services, for the purposes set out below.
Should you cease to use our services, we may retain personal data where reasonably necessary to comply with our legal obligations (including law enforcement requests), meet regulatory requirements, maintain security, prevent fraud and abuse, resolve disputes, enforce our customer terms, offer new services you may be interested in, or to fulfil your request to “unsubscribe” from further messages from us. If none of these obligations apply we will delete your personal data within 12 months of your account being closed.
Processing by third parties
We will not share your information with any third parties for any purposes other than to assist MSL in providing services to you.
We have contracts in place with our third party data processors. This means that they cannot do anything with your personal information unless we have instructed them to do it.
They will not share your personal information with any organisation apart from us. They will hold it securely and retain it for the period we instruct.
In some circumstances we are legally obliged to share information. For example under a court order or where we cooperate with supervisory authorities in handling investigations. In any scenario, we will satisfy ourselves that we have a lawful basis to share the information and document our decision.
Where we provide links to websites of other organisations, this privacy notice does not cover how that organisation processes personal information.
We use the Capsule CRM system which is a service provided by Zestia Ltd., a third party UK data processor.
Capsule CRM data is stored with Amazon Web Services (AWS) in the United States. Data stored outside the EU has to be in a safe country or with a company that complies with the safeguards required by the GDPR. Zestia has agreed a Data Processing Addendum with AWS that commits them to the GDPR Model Contract Clauses, defined by the European Commission. This ensures the safe transfer of data to AWS and is in accordance with UK data protection law.
We use the FogBugz case management system, provided by Fog Creek Software, to support the delivery of our services. The Fogbugz system and the personal data it contains is securely held in the UK on the Warwick University network under MSL management.
When you call our office (+44 (0)2476 572800) we can see your Calling Line Identification (CLI) information which is the phone number you are calling from if it is not withheld. We hold a log of the phone number, date, time and duration of the call, and we may make notes but we do not audio-record the call itself.
We use this information to understand the demand for our services and to improve how we operate. We may also use the number to call you back.
We hold statistical information about the calls we receive, but this does not contain any personal data.
We use a third-party provider, Hootsuite, to manage our social-media interactions. If you send us a private or direct message via social media, it will be stored by Hootsuite for three months. It will not be shared with any other organisations.
We review all this information and decide how we manage it. For example, if you send a message via social media that needs a response from us, we may process it in our case management system as an enquiry.
We use a third-party provider, Click4Assistance, to supply and support our live chat helpdesk service.
If you use this service, we’ll collect your name and the contents of your live chat session. We’ll also collect your email address, if you choose to provide it, to send you a transcript of the chat. We’ll keep this information for the duration of your contract with us. Once the contract is terminated, some of the obligations survive and so we may keep this data for as long as the obligation exists. In addition, the nature of the query may be such that we are required to open a case containing this information in our case management system, FogBugz.
As the sub data processor Click4Assistance will store live chat transcripts for one year.
When you visit www.ukmsl.com we use a third-party service, Google Analytics, to collect standard internet log information and details of visitor behaviour patterns. We do this to find out such things as the number of visitors to the various parts of the site. This information is always processed in a way that does not identify any individual. We do not make, and do not allow Google to make, any attempt to find out the identities of those visiting our website.
If we collect personal data through our website, we will be transparent about this. We’ll make it clear when we collect personal information and we’ll explain what we intend to do with it.
If you have queries or concerns about this policy, please contact us at email@example.com.