Privacy

This policy is provided by The Legal Marketing Innovation Company Ltd t/a Business Stack, with mailing address of Third Floor, Lancaster Buildings, 77 Deansgate, Manchester, M3 2BW (hereinafter, “We”, “Us”, “Our” or “Company”).

We are committed to ensuring that the personal information of all individuals that we deal with is protected and to operating in compliance with data protection laws. This privacy policy sets out the basis on which any personal information we collect from or about you, or that you provide to us, will be processed.

We are the controller and responsible for how your personal data is used and that this is compliant with data protection laws in the United Kingdom. We have appointed a Data Privacy Manager who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact us using the details set out at the end of this policy.

The Company is a provider of business concierge and support services, including in respect of financial, legal, IT , HR, IT support and management services (our Service).

We are the data controller in respect of the personal information we collect when providing our services and operating the below Website(s):

www.businessstack.pro
my.businessstack.pro


When we are a processor

In some instances we provide our services on a subcontracted basis to another client, and in this instance it will be this client who is the data controller in respect of any products or services you buy from them.

In particular We support services with Co-op, Vodafone and Assurant/WG Regus, via:

https://businesssupport.vodafone.co.uk

https://coop.business-concierge.online

https://rovva.business-concierge.online

For the Personal Information you have provided to Co-op, Vodafone, IWG Regus or another client, when purchasing services from them, it will be subject to the privacy information provided by the client. We have been engaged as a data processor and are subject to contractual requirements governing how we process Personal Information shared with us by the client.

However, we are the data controller for some website use and communication data collected through your use of the websites. Personal Information collected in this way will be treated in accordance with our requirements when operating Website, as described this privacy policy.


1. Personal Information We Collect

What we process

We may collect, use, store and transfer different kinds of Personal Information about you which we have grouped together as follows:

Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.

Contact Data includes billing address, email address and telephone numbers.

Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Website.

Profile Data includes your username and password, use of Services made by you, your interests, preferences, feedback and survey responses.

Usage Data includes information about how you use our Website/Service, products and other services.

Financial Data relating to your business and its operations, as well as transaction data.

Marketing and Communications Data includes your preferences, and/or your employer’s preference in receiving marketing from us and our third parties and your communication preferences.

Special Category/Sensitive data: We do not usually collect any Special Categories of Personal Information about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

Anonymous data. We also collect, use and share aggregated data such as statistical or demographic data, as we determine at the time. Aggregated data could be derived from your Personal Information but is not considered Personal Information in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature.

Profiling: means “any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements”. We currently only use profiling to build behavioural or marketing profiles based on usage or navigation on the Service.

Automated Decision Making: is the making of a decision, about an individual, based solely on automated means without any human involvement. We do not currently make automated decisions about you.


How we collect personal information

We generally collect Personal Information either directly from you (by communicating with you through email, phone or otherwise, or your use of our website(s)); from clients (who you work for); from you as a client; and/or other business contacts and third parties or sources (including publicly available sources, such as business/firm websites and business-related social media). We may also collect information about you if you work for one of our suppliers or partners.

In particular, when you use the Service, we will process personal information to log you into your account, search for templates, access your business health check, request a call back from a member of our teams, contact our support lines, and applies to your use of the Service. We also use the Personal Information to ask questions and conducts surveys, to understand if your business would benefit from other services, to communicate with you, and to track usage of the Service and Our products and services.

We may purchase personal data from data aggregators, subject to an appropriate contract and in compliance requirements of UK data protection laws.

Cookies and similar tech. We collect information about devices used to access Our Website, (browser used, browser language preferences, screen settings). Additionally, We use cookies and similar technologies such as web beacons to collect information about how you use and navigate Our Website (for example, the pages that you view and links that you click). We use cookies to help Us recognise you, improve your experience, increase

security, and measure use and effectiveness of Our services. For more information about the cookies We utilise on the website, please view Our Cookie Notice


2. Purposes and Legal Basis for the Processing of your Personal Information

We process your Personal Information for the following purposes:

Based on a contract between us, if you have contracted with us as a sole trader, or otherwise use our websites in accordance with our terms of use.

Based on our legitimate interests when conducting our business, in particular:

We will use your Personal Information to provide Service, our Website and other products and services that you have requested, and respond to any comments or complaints you may send Us.

We monitor use of the Website, and use your Personal Information to help Us to track and analyse preferences and trends, evaluate possible new features, functionality and services, conduct surveys and request additional information, propose and discuss additional services, and improve Our Website

We use Personal Information when engaging with our suppliers and managing those relationships.

We use Personal Information you provide to investigate complaints received from you or from others, about the Website or our products and Service. We also use this Personal Information to track potential issues (for example, issues with fulfilment of services) and trends to better serve you.

We use Personal Information to make decisions about, and to effect, reorganisations or sales of all or part of Our business.

We monitor customer accounts to prevent, investigate and/or report fraud, misrepresentation, or crime, in accordance with applicable law

We will use Personal Information in connection with legal claims, compliance, regulatory and investigative purposes (for example, theft and fraud investigations) as necessary (including disclosure of such information in connection with legal process or litigation).

We use Personal Information of some individuals to invite them to take part in market research and customer surveys.

We use Personal Information to send you information about products and services, such as performance data or to conduct customer experience surveys (where your consent is not required).

We may use Personal Information to market to you, when permitted (see Marketing below)


Where you give Us consent:

We place cookies and use similar technologies in accordance with Our Cookie Notice and the information provided to you when those technologies are used

In some instances for marketing purposes (see Marketing below)

On other occasions where We ask you for consent, We will use the data for the purpose which We explain at that time.

For purposes which are required by law, for example:

In response to requests by government or law enforcement authorities conducting an investigation.

Responding to complaints where We are under a legal or regulatory obligation to adhere to a complaints handling procedure.


3. Disclosure of Personal Information

Disclosure to Our Service Providers and Partners

We employ third party companies and individuals to facilitate our Services (for example, customer support, customer communications, audit, application or database hosting, development, logistics, payment processing, and for fraud detection and prevention purposes). These third parties have limited access to your Personal Information to perform these tasks on Our behalf and are obligated to Us. The personnel of such third parties who use your Personal Information is limited to those individuals which are authorised to do so on a need-to-know basis and as necessary to provide these business services to Us. To provide the Service, we may share your name, contact details (including post code, email address and mobile number), and usage information.

We may also share personal date with our accountants, lawyers and other professional advisors.

Disclosure to Public Authorities

We may disclose your Personal Information if required for the purposes above, if mandated by law or if required for the legal protection of Our legitimate interests in compliance with Applicable Law.

Other Categories of Recipients

We may also disclose your Personal Information, usage information, and other information about you to parties acquiring part or all of Our business and/or assets, as well as to related lawyers and consultants. Also, if any bankruptcy or reorganisation proceeding is brought by or against Us, your Personal Information may be considered a company asset that may be sold or transferred to third parties.

We may also share personal information within our group of companies and businesses.


4. Where your Data is Processed

Your Personal Information will usually be processed inside the UK (and European Economic Area (“EEA”) for as long as it has an adequacy decision from the UK Government) by us and Our service providers, subject to contractual restrictions regarding confidentiality and security in accordance with applicable data protection laws and regulations.

A few of our external third parties and suppliers are based outside the EEA, so if they process personal information this a transfer of data outside the EEA.

Whenever we transfer your personal data out of the UK or EEA, we ensure a similar degree of protection is afforded to it by implementing at least one of the following safeguards:

We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.

Where we use certain service providers, we may use specific contracts approved by the ICO which give personal data the same protection it has in the UK. We will also conduct an appropriate transfer risk assessment.

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK or EEA.


5. Your Choices and Rights

I/You have the right to:

Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected.

Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law.

Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. .

Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

If you want us to establish the data’s accuracy.

Where our use of the data is unlawful, but you do not want us to erase it.

Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.

You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format.

Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

You can exercise any of your rights by contacting Us. In order to safeguard your Personal Information from unauthorized access, We may ask that you provide sufficient information to identify yourself prior to providing access to your Personal Information.

In certain situations, and subject to applicable law, We may not be able or obliged to comply with part or all of your individual requests. For example, We may not comply with an access request if doing so would reveal Personal Information about another person, or comply with a deletion request relating to information which We are required by law to keep or have compelling legitimate interests in keeping.

If you have unresolved concerns, you have the right to complain to the Information Commissioner’s Office (‘supervisory authority’) and for details please visit www.ico.org

Refusing to provide data. To provide certain parts of the Service (for example – Logging in to the Service account, the provision of Personal Information is mandatory: If relevant data is not provided, then We may not be able to provide certain parts of the Service.


6. Communications from Us and Marketing

We will communicate with you through email, phone and SMS. We will send you Service-related communications ,for example – information about your usage of the service, customer satisfaction, information regarding the Service, Our services and market research surveys.

You will receive marketing communications from us if you have requested this information from us or purchased services from us and you have not opted out of receiving marketing.

B2B: If you work for a company we may contact you to understand if your employer/organisation would be interested in the services and products we provide. We rely on our legitimate interest to do this and will provide you/your organisation with an opportunity to opt out. In order to do this, we may collect your Personal Information from publicly available sources, such as your organisation’s website, LinkedIn, industry bodies and other business social media.


THIRD-PARTY MARKETING

We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.

You can change your email and contact preferences through this website or by contacting Us. Please be aware that you cannot opt-out of receiving service-related messages from Us.


7. Data Retention

We retain Personal Information you provide as needed to provide the Service. We may retain your Personal Information if retention is reasonably necessary to comply with Our legal obligations, meet regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce this Notice and Our Terms of Use. We usually maintain records of the customers for a period of 6 years for tax and liability purposes. This may include your personal data if you are a sole trader, in a partnership or a director of a company.

We may retain Personal Information for a limited period of time if requested by law enforcement. Our customer support may retain information for as long as is necessary to provide support-related reporting and trend analysis only, but We generally delete or de-personalise transaction-related data consistent with this Notice. Once Personal Information is anonymised, We may retain and use such information. Additionally, We maintain logs and backups for security, debugging, and site stability purposes for up to 30 days after your transaction has been completed.


8. Information Security

We have implemented safeguards designed to protect your Personal Information in accordance with industry standards.

We have measures in place to restrict access to Personal Information to those individuals whom We know have a valid business purpose to have access to such data. We maintain physical, electronic and procedural safeguards. We follow generally accepted standards designed to protect the Personal Information submitted to Us, both during transmission and once We receive it. We require those who provide services for Us and to whom We provide Personal Information collected through the Service to keep such information secure and confidential. However, no method of transmission over the Internet or method of electronic storage is totally secure. Therefore, We cannot guarantee its absolute security.


9. Important Information

Minimum age

We do not knowingly collect Personal Information from anyone under the age of 18. You must be at least 18 years of age to use the Service.

Changes to this Notice

We may update this Notice from time to time. This Notice was last updated on the Effective Date below.

Contact Us

For customer enquiries, please contact us at: Business Stack Third Floor, Lancaster Buildings, 77 Deansgate, Manchester, M3 2BW. We welcome your questions or comments regarding this Notice. Please write to Business Stack, Data Privacy Manager, Third Floor, Lancaster Buildings, 77 Deansgate ,Manchester, M3 2BW, or send Us an email at hello@businessstack.pro

Effective date: 7th July 2023