DITO Business Solutions Privacy Notice
This Privacy Notice is v1.5 and is valid from 00:01hrs on 4th September 2023. It replaces and supersedes all other Privacy Notices associated with DITO Business Solutions Limited.
We take your privacy very seriously. This Privacy Policy details what personal data we collect and how we shall use it.
Changes to this Privacy Notice.
We continually review our Privacy Notice and update it where necessary. We advise that you regularly check our Privacy Notice for updates. We do not wish to bother you with lots of minor amendments, but where we make significant changes to our policy, we may contact you to inform you.
Our Name & Contact Details.
Our contact details are:
DITO Business Solutions Limited
6 Hope Street
Castletown
IM9 1AS
Isle of Man
Data Protection Officer Contact Details.
In observance of the General Data Protection Regulation and the Data Protection Act 2018, DITO Business Solutions have chosen to establish a Data Protection Officer. Should you wish to contact our Data Protection Officer regarding a data protection matter you can do so by emailing dpo@ditosolutions.com or writing to:
Data Protection Officer
DITO Business Solutions Limited
6 Hope Street
Castletown
IM9 1AS
Isle of Man
Personal data categories we collect
We may process different kinds of personal data which we have categorised as follows:
- Identity Data: This includes first name, maiden name, last name, marital status, title, date of birth and gender.
- Contact Data: This includes email address and telephone numbers.
- Financial Data: This includes bank account information and payment details.
- Compliance Data: This includes recorded calls for quality checks and staff training. Such recordings may also be used to help us combat fraud.
- Technical Data: This includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
- Usage Data: This includes information about how you use our website, products and services.
- Marketing and Communications Data: This includes your preferences in receiving marketing from us and your communication preferences.
- Aggregated Data: This includes statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
- Special Categories of Personal Data: This includes health and vulnerability related data that you may voluntarily share with us during the fulfilment of our services to you. We will always ask for your explicit consent to record and share Special Category Data.
For what purposes do we process personal data, and what are the lawful bases by which we process data?
DITO Business Solutions is a Data Processor for all data processed by us or our sub-processors on behalf of our clients, for the following purposes:
DITO Business Solutions processes Personal Data as a Data Controller for the following purposes:
What are our legitimate interests for processing your data?
Where we have used legitimate interest as the lawful basis for processing your personal data, we may:
- Direct market B2B products and services via post, emails, telephone, SMS text and push notifications where they are similar/aligned to our current products and services, and it conforms with the Privacy and E-Communication Regulation;
- For reporting, analytics and product/service improvement (including training);
- Improve and maintain data accuracy or completeness;
- Personalise our online experience. This could include customising the content and/or layout of our pages for individual users, for both visitors and contributors;
- Resolve complaints and/or disputes;
Sharing your personal data
DITO Business Solutions may share personal data externally to the business. Where we choose to share your information, we shall do so for the following reasons:
- Where we have your “Consent” to do so. Where we process your data under the consent lawful basis you have the right to withdraw consent. Please refer to “Your Right to Withdraw Consent” section below;
- Where necessary to fulfil the services and/or products we are contracted to provide to our clients;
- Where we have a “Legal Obligation” and are required by law and to law enforcement agencies, judicial bodies, government entities, tax authorities or regulating bodies around the world, this includes communicating with you to update you about our privacy notice and changes to how we process your personal data;
- Where we have “Legitimate Interest” to do so, including;
- For the purposes listed in the “What are our legitimate interests for processing your data?” section above.
- For reporting, analytics and service improvement purposes across our trading styles and/or within any future group construct should DITO Business Solutions establish or become part of a group.
- Where we believe it is necessary to protect or defend our rights, property or the personal safety of our people or visitors to our premises or websites;
- Where required for a proposed sale; reorganisation; transfer; financial arrangement; asset disposal; or any other transaction relating to our business and/or assets held by our organisation.
- Where we outsource support functions of our organisations to trusted partners. The categories of these recipients include:
Where we choose and/or have your permission to share your personal data with 3rd Parties we will, where appropriate, ensure that they have signed a contract that requires them to:
- Abide by the requirements of all relevant data protection and privacy legislation;
- Treat your information as carefully as we would;
- Only use the information for the purposes it was supplied (and not for their own purposes or the purposes of any other organisation); and
- Allow us to carry out checks to ensure they are doing all these things.
If you provide your data through a third party, we may share data with that lead provider in order to assist with the management of the services and to streamline client contact.
We may have to disclose your personal data with other third parties as set out below. These organisations or bodies will not use your information to contact you. These third parties will be subject to obligations to process your personal information in compliance with the same safeguards that we deploy.
- HM Revenue & Customs: We’re required to disclose certain data with the HMRC.
- There may be other regulators and authorities such as Solicitors and Accountants, acting as processors based in the IoM who require reporting of processing activities in certain circumstances.
International Personal Data Transfer – Countries & Organisations.
DITO Business Solutions may transfer personal data to countries outside of the IoM and/or EEA. Specifically, we use data processors based in South Africa.
If data is transferred outside of the EEA, DITO Business Solutions will put in place Standard Contractual Clauses with the Data Controller or Data Processor which contractually obliges them to protect your information to the same standard required by the General Data Protection Regulation and Data Protection Act 2018.
Personal Data Retention Period
DITO Business Solutions maintains a retention schedule which defines for how long we will store your personal data. We will only store personal data for as long as we have a legitimate need to retain it, either for statutory/legal reasons or because we need the data to be able to provide you with services or for other legitimate business needs.
When we no longer need this information, we will anonymise your data and/or dispose of it securely.
A copy of our retention schedule is available by request to the DPO.
Personal data may be held in paper and/or electronic format. Email correspondence and any notes from meetings are stored electronically. We may also retain information in spreadsheets or other systems which assist us with administration.
The rights available to individuals in respect of the processing
Unless subject to an exemption under legislation, you have the following rights with respect to your personal data:
- Your right of access.You have the right to ask us for copies of your personal information. This right always applies. There are some exemptions, which means you may not always receive all the information we process. You can read more about your Right to Access here. In most cases DITO Business Solutions will not charge for this service however we do have the right to charge an administrative cost should we feel the request is excessive (excessive means that you submit a subject access request multiple times for the same or similar information). Fees will not exceed £50. Information will be provided within 28 calendar days from the day you request it. We will take all reasonable steps to verify your identity before providing you with details of any personal information we may hold about you.
- Your right to rectification.You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. This right always applies. You can read more about your Right to Rectification here.
- Your right to erasure.You have the right to ask us to erase your personal information in certain circumstances. You can read more about your Right to Erasure here.
- Your right to the restriction of processing.You have the right to ask us to restrict the processing of your information in certain circumstances. You can read more about your Right to the Restriction of Processing here.
- Your right to object to processing. You have the right to object to processing if we are able to process your information because the process forms part of our public task, or is in our legitimate interests. You can read more about your Right to Object to Processing here.
- Your right to data portability.This only applies to information you have given us. You have the right to ask that we transfer the information you gave us from one organisation to another, or give it to you. The right only applies if we are processing information based on your consent or under, or in talks about entering into a contract and the processing is automated. You can read more about your Right to Data Portability here.
If you wish to exercise any of your individual rights, you can do so by informing a member of our team or by contacting our Data Protection Officer by emailing dpo@ditosolutions.com
Automated decision-making, including profiling.
DITO Business Solutions does not use currently use automated decision-making tools or profiling in the processing of your personal data.
Your Right to Lodge a Complaint with the ICO
You have the right to lodge a complaint with the IoM’s Supervising Authority: The Information Commissioners Office. Prior to lodging a complaint, DITO Business Solutions would like the opportunity to address any complaint you may have.
Should you have a complaint please in the first instance contact our Data Protection Officer by emailing dpo@ditosolutions.com or writing to:
Data Protection Officer
DITO Business Solutions Limited
6 Hope Street
Castletown
IM9 1AS
Isle of Man
If your complaint has not been resolved, you can lodge a complaint with the Information Commissioner’s Office by completing this complaints form and emailing it to ask@inforights.im or by writing to:
Information Commissioner's Office
First Floor, Prospect House
Prospect Hill
Douglas, Isle of Man
IM1 1ET
Or by telephone on +44 1624 693260.