EU GDPR Policy
This policy specifically pertains to customers and
operations in the European Union. Please refer to our
Privacy Statement and Privacy Policy for application
outside the EU.
BLACK6 (Visiontek)
Last updated: 18 July 2024
The Business is committed to processing data in accordance with its responsibilities under the GDPR. Article 5 of the GDPR requires that personal data shall be:
This policy applies to all personal data processed by the
Business.
The Responsible Person shall take responsibility for the Businesss
ongoing compliance with this policy.
This policy shall be reviewed at least annually.
The Business shall register with the Information Commissioners
Office as an organisation that processes personal data.
To ensure its processing of data is lawful, fair and
transparent, the Business shall maintain a Register of
Systems.
The Register of Systems shall be reviewed at least annually.
Individuals have the right to access their personal data and
any such requests made to the Business shall be dealt with in
a timely manner.
All data processed by the Business must be done on one of
the following lawful bases: consent, contract, legal
obligation, vital interests, public task or legitimate
interests.
The Business shall note the appropriate lawful basis in the Register
of Systems.
Where consent is relied upon as a lawful basis for processing
data, evidence of opt-in consent shall be kept with the personal
data.
Where communications are sent to individuals based on their consent,
the option for the individual to revoke their consent should
be clearly available and systems should be in place to ensure
such revocation is reflected accurately in the Business's systems.
The Business shall ensure that personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
The Business shall take reasonable steps to ensure personal
data is accurate.
Where necessary for the lawful basis on which data is processed,
steps shall be put in place to ensure that personal data is kept
up to date.
To ensure that personal data is kept for no longer than
necessary, the Business shall put in place an archiving
policy for each area in which personal data is processed and
review this process annually.
The archiving policy shall consider what data should/must be
retained, for how long, and why.
The Business shall ensure that personal data is stored
securely using modern software that is kept-up-to-date.
Access to personal data shall be limited to personnel who need
access and appropriate security should be in place to avoid unauthorised
sharing of information.
When personal data is deleted this should be done safely such
that the data is irrecoverable.
Appropriate back-up and disaster recovery solutions shall be
in place.
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, the Business shall promptly assess the risk to people's rights and freedoms and if appropriate report this breach to [email protected] and relevant officials as needed.