Introduction to this Policy
Gorilla ERP limited are committed to protecting and respecting your privacy.
You should read this Policy carefully as it contains important information about how we will use your information. In certain circumstances you will be required to indicate your consent to the processing of your information as set out in this Policy when you first submit such information to us or through the Website.
We may update this Policy from time to time and this Policy was last updated on 18th September 2019.
Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
For the purposes of data protection legislation in force from time to time the data controller for personal data collected via: www.gorillaerp.co.uk is Gorilla ERP limited
Office location is, The Old Coach House, Goat Street, Haverfordwest, Pembrokeshire, Wales SA61 1PX.
Registered location is, 1 Waterside Station Road, Harpenden, Hertfordshire AL5 4US.
Our nominated representative for data protection matters is Johanna Slade, Digital and Marketing lead at Gorilla ERP Limited.
Who we are and what we do
We are a recruitment agency and recruitment business as defined in the Employment Agencies and Employment Businesses Regulations 2003 (our business). We collect the personal data of the following types of people to allow us to undertake our business;
Prospective and placed candidates for permanent or temporary roles;
Prospective and live client contacts;
Supplier contacts to support our services;
Employees, consultants, temporary workers; and
We collect information about you to carry out our core business and ancillary activities.
Information you give to us or we collect about you.
This is information about you that you give us by filling in forms on our Website or by corresponding with us by phone, e-mail or otherwise. It includes information you provide when you register to use our Website, to enter our database, subscribe to our services, attend our events, participate in discussion boards or other social media functions on our site, enter a competition, promotion or survey, and when you report a problem with our site.
The information you give us or we collect about you may include your name, address, private and corporate e-mail address and phone number, financial information, compliance documentation and references verifying your qualifications and experience and your right to work in the United Kingdom, curriculum vitae and photograph, links to your professional profiles available in the public domain e.g. LinkedIn, Twitter, business Facebook or corporate website.
Information we collect about you when you visit our website.
With regard to each of your visits to our site we will automatically collect the following information:
Information we obtain from other sources.
We are working closely with third parties including companies within our Group, business partners, sub-contractors in technical, professional, payment and other services, advertising networks, analytics providers, search information providers, credit reference agencies and professional advisors. We may receive information about you from them for the purposes of our recruitment services, ancillary support services and business operations.
Purposes of the processing and the legal basis for the processing
We use information held about you in the following ways:
The core service we offer to our candidates and clients is the introduction of candidates to our clients for the purpose of temporary or permanent engagement. However, our service expands to supporting individuals throughout their career and to supporting businesses’ resourcing needs and strategies.
Our legal basis for the processing of personal data is our legitimate business interests, described in more detail below, although we will also rely on contract, legal obligation and consent for specific uses of data.
We will rely on contract if we are negotiating or have entered into a placement agreement with you or your organisation or any other contract to provide services to you or receive services from you or your organisation.
We will rely on legal obligation if we are legally required to hold information on you to fulfil our legal obligations.
We will in some circumstances rely on consent for particular uses of your data and you will be asked for your express consent, if legally required. Examples of when consent may be the lawful basis for processing include permission to introduce you to a client (if you are a candidate).
Our Legitimate Business Interests
Our legitimate interests in collecting and retaining your personal data is described below:
Should we want or need to rely on consent to lawfully process your data we will request your consent orally, by email or by an online process for the specific activity we require consent for and record your response on our system. Where consent is the lawful basis for our processing you have the right to withdraw your consent to this particular processing at any time.
Other uses we will make of your data:
Use of our website;
We will use this information:
We do not undertake automated decision making or profiling. We do use our computer systems to search and identify personal data in accordance with parameters set by a person. A person will always be involved in the decision making process.
Our Website may issue ‘cookies’ (small text files) to your device when you access and use the Website and you will be asked to consent to this at the time (e.g. when you first visit our website). Cookies do not affect your privacy and security since a cookie cannot read data off your system or read cookie files created by other sites.
You can set your system not to accept cookies if you wish (for example by changing your browser settings so cookies are not accepted), however please note that some of our Website features may not function if you remove cookies from your system. For further general information about cookies please visit www.aboutcookies.org or www.allaboutcookies.org.
For detailed information on the cookies we use and the purposes for which we use them see our Cookie notice www.gorillaerp.co.uk/cookies.
Disclosure of your information inside and outside of the EEA
We will share your personal information with:
Selected third parties both in the EEA and outside of the EEA including:
We will disclose your personal information to third parties:
The lawful basis for the third-party processing will include:
Where we store and process your personal data
All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted using SSL technology. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Retention of your data
We understand our legal duty to retain accurate data and only retain personal data for as long as we need it for our legitimate business interests and that you are happy for us to do so. Accordingly, we have a data retention policy and run data routines to remove data that we no longer have a legitimate business interest in maintaining. This policy can be summarised below.
We segregate our data so that we keep different types of data for different time periods. The criteria we use to determine whether we should retain your personal data includes:
We may archive part or all of your personal data or retain it on our financial systems only, deleting all or part of it from our main Customer Relationship Manager (CRM) system. We currently use Bullhorn as our chosen CRM system used across all of Gorilla ERP Limited. We may pseudonymise parts of your data, particularly following a request for suppression or deletion of your data, to ensure that we do not re-enter your personal data on to our database, unless requested to do so.
For your information, Pseudonymised Data is created by taking identifying fields within a database and replacing them with artificial identifiers, or pseudonyms.
Subject to any legal requirements to hold information for longer periods in order to comply with our legal or regulatory obligations, we will keep your Data only for the purposes set out in the table below for:
Seven (7) years where the legal basis for the processing is that it is necessary for the performance of the contract between us
Three (3) years or until consent is withdrawn (whichever is sooner), where the legal basis is express consent.
Our current retention policy is available upon request.
Please let us know when any of your data needs to be updated. We may contact you from time to time to check if your data is correct and up to date.
You have the right to ask us not to process your personal data for marketing purposes. We will usually inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes and we will collect express consent from you if legally required prior to using your personal data for marketing purposes.
You can exercise your right to accept or prevent such processing by checking certain boxes on the forms we use to collect your data. You can also exercise the right at any time by contacting us at firstname.lastname@example.org or contacting Johanna slade directly at Johanna.email@example.com
Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
The GDPR provides you with the following rights. To:
Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
Request the transfer of your personal information to another party in certain formats, if practicable.
Make a complaint to a supervisory body which in the United Kingdom is the Information Commissioner’s Office. The ICO can be contacted through this link: https://ico.org.uk/concerns/
Access to information
Data protection legislation gives you the right to access information held about you. We also encourage you to contact us to ensure your data is accurate and complete. Your right of access can be exercised in