Privacy Policy – Business Contacts and Customers

Contents:

Data we collect
How we use your personal data and legal basis for processing
Sharing and disclosing your personal data
How long we keep your data

Data we collect

We collect personal data, stored on our Insightly customer relationship management system about our clients and contacts to help us run our business effectively, to manage our relationship with you and to develop potential business leads.

The types of data we collect, and process can vary, it may include:

Your name
Company name
Email address
Business telephone number: direct dial-in (DDI) and mobile
Job title
Your hobbies or interests, so we can invite you to events we think you will be interested in
Your Dunedin Advisory contacts
Details of events you have previously attended, meetings we have had with you or hospitality provided to you
If you attend our events, any dietary requirements or details of any adjustments of which you may have informed us
Business related personal data about you which generally focus on your home life e.g. marital status, spouse name and number of children. This information is used to tailor our communication and event invitation to you

We collect this data:

• Directly from you, for example, if you have given us your business card or told us in an email or other correspondence
• Indirectly through our interactions with you
How we use your personal data and legal basis for processing
We process your personal data on the following legal bases for the following purposes.
• To set up your CRM profile which enables us to process and manage our interaction with you to provide business opportunities
• To enable us to match you to applicable hospitality events or seminars
• For marketing purposes, such as sending you updates with our latest information, and services or other information we think you may find interesting
• To help us contact you about upcoming events
• To create reports on the effectiveness of Dunedin Advisory’s Business Development activities
• To occasionally contact you for your views on our services
We have a legitimate interest in using your data for these purposes, as it helps us to manage our relationship with you. We have carried out a Legitimate Interests Assessment (LIA) whereby we have weighed your interests and the risks posed to you against our own interests and consider that they are proportionate and appropriate

Special Categories of Personal Data

We may ask if you have any dietary requirements and you may also inform us of adjustments you require. This could reveal data about your religious beliefs (in the case of dietary information) or data about your health. This data is given special protection under the law as it is particularly sensitive.
(You do not have to provide this information to us although we may not be able to cater for your specific dietary needs without this information).
We will only use the data to the extent necessary.

Marketing

We would like to send you information by email and to call you about our products and services, updates about our business, as well as about events which we think you may be interested in.

If you are a corporate contact, we will send marketing communications to your company email address unless you have opted out. We will give you the opportunity to opt out of receiving marketing communications from us when we first contact you.

For non-corporate contacts, we will only send marketing communications to your personal email address if those communications relate to services or opportunities which are similar to what we have already provided to you in the past or which you have expressed an interest in, or if you have consented to us contacting you in this way.

Sharing and disclosing your personal data

We use third party processors to provide several services and business functions. Those processors will have access to your personal data for these purposes; we require all processors acting on our behalf to only process your data in accordance with instructions from us and to comply fully with this privacy notice, the data protection laws and any other appropriate confidentiality and security measures.

Your personal data may be shared with:

• Our Client Relationship Management (CRM) software provider (Insightly)
• Organisations that provide seminar/presentation venues
• Third party travel, hospitality providers or venues
Occasionally, we may also need to disclose your personal data in the following circumstances:

Based on our legitimate interests, to third parties if we choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice

To law enforcement officials, law courts and government and regulatory authorities: (a) if we believe disclosure is required by any applicable law, regulation or legal process; or (b) to protect and defend our rights, or the rights or safety of third parties, including to defend against legal claims based on our legitimate interests

In exceptional circumstances, to third parties to protect your vital interests if you suffered an injury at one of our offices.

How long we keep your data

We only ever retain personal data for as long as is necessary and we have strict review and retention policies in place to meet these obligations.
Where you have consented to us using your details for marketing, we will keep such data until you notify us otherwise and/or withdraw your consent.