Rion Group is committed to protecting the privacy and security of personal information. We understand that privacy is important to our employees, clients, customers, and other individuals whose personal information we process.
This privacy policy explains how we collect, use, store, and protect personal information in accordance with data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The organisation is committed to being transparent about how we handle personal information and ensuring that individuals understand their rights in relation to their personal data.
It is the organisation's policy to process personal information fairly, lawfully, and in accordance with data protection principles. We will only collect and use personal information where we have a lawful basis to do so.
This policy does not form part of any employment contract, and can be amended at any time.
Personal information (or personal data) is any information that relates to an identified or identifiable individual. This can include:
For example:
These examples are considered to be the typical types of personal information that we may process. However, the organisation recognises that there may be other types of information that constitute personal data depending on the circumstances.
We collect and process personal information about our employees for employment purposes. This includes recruitment, payroll, performance management, training, and other employment-related activities.
We collect personal information from our clients and customers in order to provide our services and maintain our business relationships. This may include contact details, project information, and billing details.
We may collect personal information from visitors to our premises for security and health and safety purposes. This can include names, contact details, and CCTV footage.
We may collect information about how individuals use our website and digital services, including IP addresses, browser information, and usage data.
We may receive personal information from third parties, such as suppliers, contractors, and other business partners, in the course of our business activities.
The organisation is committed to processing personal information in accordance with data protection principles.
We will ensure that personal information is:
The organisation is committed to protecting personal information through appropriate technical and organisational measures.
We will only process personal information where we have a lawful basis to do so under data protection law.
The lawful bases we rely on include:
For special category data (sensitive personal information), we will identify an additional lawful basis under data protection law.
Personal information may be collected in various ways:
All collection of personal information will be fair and lawful, and individuals will be informed about how their information will be used.
We use personal information for various purposes depending on our relationship with the individual:
Each use of personal information will have a lawful basis under data protection law.
We may share personal information with third parties in certain circumstances:
We will ensure that any sharing of personal information is lawful and that appropriate safeguards are in place.
Where we transfer personal information outside the UK, we will ensure that appropriate safeguards are in place to protect the information in accordance with data protection law.
This may include:
We will only keep personal information for as long as necessary for the purposes for which it was collected.
Retention periods vary depending on the type of information and the purpose for processing:
When personal information is no longer needed, it will be securely deleted or destroyed.
The organisation is committed to keeping personal information secure through appropriate technical and organisational measures.
Security measures include:
We require all staff and third parties to maintain the security of personal information and report any suspected data breaches immediately.
Individuals have various rights in relation to their personal information under data protection law:
To exercise these rights, individuals should contact the Data Protection Officer using the details provided below.
Individuals can make requests to exercise their data protection rights by email or in writing.
Any request must include:
We will respond to requests within one month of receipt, though this may be extended in complex cases.
Our Data Protection Officer is responsible for overseeing data protection compliance and can be contacted about any data protection matters.
Contact details:
Individuals should raise any concerns about our processing of personal information with the Data Protection Officer in the first instance.
If concerns cannot be resolved directly with us, individuals have the right to lodge a complaint with the Information Commissioner's Office (ICO).
ICO contact details:
For further information about this privacy policy, individuals should contact the Data Protection Officer.
This privacy policy may be updated from time to time to reflect changes in our processing activities or data protection law.
Any significant changes will be communicated to relevant individuals through appropriate channels.
The current version of this policy is available on our website and from the Data Protection Officer upon request.
Last updated: 28/05/2025 Next review date: 20/05/2026