Workstation Risk Analysis are committed to respecting and protecting your privacy. We wish to be transparent on how we process your data and show you that we are accountable with the GDPR in relation to, not only processing your data but ensuring you understand your rights as a client.
It is the intention of this privacy statement to explain to you the information practices of Workstation Risk Analysis in relation to the information we collect about you.
For the purposes of the GDPR the data controller is:
- Workstation Risk Analysis
- Contact details. Unit 4 Meath Enterprise Centre, Trim Road, Navan, Co. Meath, C15AD61, Ireland.
- When we refer to ‘we’ it is Workstation Risk Analysis
Please read this Statement carefully as this sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us.
Who we are we?
Workstation Risk Analysis provide office based Workstation Assessments, Ergonomics & VDU Eyesight Screening for Companies and Public Organisations Nationwide. Our services comply with the ‘Safety, Health & Welfare at Work Act 2005’ & ‘Safety, Health & Welfare at Work Act 2007` and General (Application) Regulations 2007.
Our Data Protection Officer / GDPR Owner and data protection representative can be contacted directly here:
- Patrick Brady
Purpose for processing your data
Workstation Risk Analysis collect and process personal data about you when you engage with us either as a client or as a potential client.
- To establish or fulfil a contract. For example, if you enter into an agreement to receive our services; this may include verifying your identify and communicating with you otherwise we would not be able to enter into a contract with you.
- To comply with applicable laws and regulations
We may use information you provide:-
- To personalise our communications with you
- To monitor use of our website and online services
- We may use your information to invite you to take part in market research or surveys
Why are we processing your data? Our legal basis
Workstation Risk Analysis need to collect personal data for processing you data under the GDPR as follows;
- Workstation Risk Analysis needs to process your data in relation to a contract of work to which an organization, individual, or other Business Entity has entered into or because an Organization, individual, or Business Entity has requested our services so they can enter into a contract.
In any event, Workstation Risk Analysis are committed to ensuring that the information we collect and use is appropriate for this purpose, and does not constitute an invasion of your privacy.
How will Workstation Risk Analysis use the personal data it collects about me?
Workstation Risk Analysis will process, collect, store and use information you provide in a manner compatible with the EU’s General Data Protection Regulation (GDPR). We will endeavour to keep your information accurate and up to date, and not keep it for longer than is necessary.
Who are we sharing your data with?
In the case of enquiries we do not divulge or share your data with anyone. In the event that you become a client we may pass your personal data on to third-party service providers contracted to Workstation Risk Analysis in the course of dealing with you. Any third parties that we may share your data with are obliged to keep your details securely, and to use them only to fulfil the service they provide on your behalf. When they no longer need your data to fulfil this service, they will dispose of the details in line with Workstation Risk Analysis procedures.
If we wish to pass your sensitive personal data onto a third party we will only do so once we have obtained your explicit consent, unless we are legally required to do otherwise.
The third parties that we pass your personal data to are:-
- CRM providers
We have issued all our third party processors with a Data Processor checklist asking them GDPR specific questions.
If we transfer personal data to a third party or outside the EU we as the data controller will ensure the recipient (processor or another controller) has provided the appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies for you the data subject are available.
Data subject rights:
Workstation Risk Analysis facilitate you, our clients, rights in line with our data protection policy and the subject access request procedure. This is available on request.
Your rights as a data subject
At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:
- Right of access: you have the right to request a copy of the information that we hold about you.
- Right of rectification: you have a right to correct data that we hold about you that is inaccurate or incomplete.
- Right to be forgotten: in certain circumstances you can ask for the data we hold about you to be erased from our records.
- Right to restriction of processing: where certain conditions apply to have a right to restrict the processing.
- Right of portability: you have the right to have the data we hold about you transferred to another organisation.
- Right to object: you have the right to object to certain types of processing such as direct marketing.
- Right to object to automated processing, including profiling: you also have the right to be subject to the legal effects of automated processing or profiling.
- Right to judicial review: in the event that Workstation Risk Analysis refuses your request under rights of access, we will provide you with a reason as to why.
All of the above requests will be forwarded on should there be a third party involved as we have indicated in the processing of your personal data.
Additional information we are providing you with to ensure we are transparent and fair with our processing.
Retention of your personal data
Data will not be held for longer than is necessary for the purpose(s) for which they were obtained. Workstation Risk Analysis will process personal data in accordance with our retention schedule. This retention schedule has been governed by our internal governance.
In the event that you wish to make a complaint about how your personal data is being processed by Workstation Risk Analysis or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and Workstation Risk Analysis data protection representative, Data Protection Officer / GDPR Owner.
If we have received your personal data from another source we will endeavour to share with you:
- One month of obtaining the personal data, in accordance with the specific circumstances of the processing;
- At the first instance of communicating in circumstances where the personal data is used to communicate with the data subject;
- When personal data is first disclosed in circumstances where the personal data is disclosed to another recipient.
Your privacy is important to us. If you have any queries, questions or comments regarding this Statement, please do not hesitate to contact us. firstname.lastname@example.org