Privacy policy
At Vitaccess, we are committed to protecting your privacy. This policy applies when we are acting as a controller of personal data, i.e. where we have determined the purposes and means of the processing of that personal data. It also applies where are acting as a processor of data on behalf of the data controller.
Customer and Supplier Employees
We will process your personal data for the purposes of communication with our customers and suppliers, ensuring any products or services exchanged between us satisfy agreed requirements and maintaining records. The legal basis for this processing is that it is necessary to achieve our legitimate interest, namely the supply of our products and services and maintaining a business relationship with your employer. We will retain all personal data we have obtained relating to you to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting or reporting requirements. We will share your personal data with customers and suppliers only to the extent that the disclosure is reasonably necessary for the purposes of the supply of our products/services and maintaining a business relationship with you or your employer.
Where we are seeking to establish a business relationship, we will process your personal data for the purpose of communication with your employer. The legal basis for this processing is that it is necessary to achieve our legitimate interest, namely providing information on our products and services that may be of value and establishing a business relationship with your employer. We will retain all personal data we have obtained relating to you to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting or reporting requirements. We will share your personal data with our suppliers only to the extent that the disclosure is reasonably necessary for the purposes of seeking to establish a business relationship with your employer and enhancing the relevance of any communications we have with you and / or your employer.
Promotional Material
We may process your personal data for the purpose of creating marketing material. The legal basis for this processing is that it is necessary to achieve our legitimate interests, namely promoting products and services supplied by us. We will store your personal data relating to marketing material for as long as the marketing material remains relevant to products and services supplied by us. We will share your personal data with other third parties.
Prospective Employees
We will process your personal data for recruitment purposes. The legal basis for this processing is that it is necessary to achieve our legitimate interest, namely the recruiting of personnel to ensure the continued provision of our products and services. We will share your personal data with third parties, such as recruitment advisors, only to the extent that the disclosure is reasonably necessary for the recruitment process.
Consent for Processing of Personal Data
To ensure compliance with UK and International data protection legislation – for example UK Data Protection Act, European General Data Protection Regulation (‘GDPR’), and United States Health Insurance Portability and Accountability Act (‘HIPAA’) – specific consent may be requested from you for specific projects. Where consent in needed / given from you, we will ensure that you are fully aware of all data processing activities (including the storage, retention, and sharing of personal data) prior to commencing processing of your personal data. Please contact us using the email address below if you have any queries relating to consent, including how to ask to withdraw your consent.
Website users – IP address lookup and Cookie use
Our company uses third parties to provide information about visitors to our websites. When you visit our website, we will record your IP address. This address will be matched against public and proprietary IP address databases to provide us with information about your visit. This information may identify the organisation to whom the IP address is registered but not individuals. In some limited cases i.e. single person companies, it may be possible to identify personal data from publicly available ICANN data.
Cookies allow us to provide important site functionality, so you don’t have to re-enter lots of information. They also allow us to remember what links and pages have been clicked or viewed during a session. If you have provided us with personal data, completing a contact form for example, we may associate this personal data with other information. This will allow us to identify and record what is most relevant to you.
You can view our cookie policy in more detail by following this link.
International Transfers
Your personal data may be processed outside the European Economic Area (EEA) by us or the third parties we use. Where these transfers take place, we will ensure the same high standard of protection for your personal data at all times.
How Long We Retain Your Data
The information you provide to us may be archived or stored periodically by us according to backup processes and will only be retained for as long as is required for the purposes for which it was collected, as well as to provide our products and services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws.
Where you have consented to us to use your details for direct marketing, we will keep this data until you notify us or otherwise withdraw your consent.
For further details on our data retention periods please contact us.
Links to Other Web Sites
Our services may contain links to other websites not controlled or operated by Vitaccess. These links do not imply that we endorse these third-party sites. Please review the privacy terms on those sites as well, as they may differ from those on this Site.
Our commitment to children’s privacy
Protecting the privacy of the very young is especially important. For that reason, we do not intend to collect or maintain information at our Site from those we know are under 13 years of age, and no part of our Site is structured to attract anyone under 13. If you learn that your child has provided us with Personal Information without your consent, you may alert us at dpo@vitaccess.com . If we learn that we have collected any Personal Information from children under 13 (and in certain jurisdictions under the age of 16), we will promptly take steps to delete such information and terminate the child’s account.
Your rights
As you are providing us with your personal data, it is important to us that you are aware of the following rights that you have in relation to our processing of that personal data.
- The right to access your personal information (including a data portability request);
- The right to correct or amend any personal information we have on file about you;
- The right to delete your personal information;
- The right to limit the use of your “sensitive” personal information;
- The right to restrict or object to the processing of your personal information (such as for direct marketing purposes);
- The right to restrict the use of your personal information for certain automated decision-making (including profiling); and
- The right to revoke your consent (to the extent applicable).
You can exercise any of the rights listed above by contacting us using the details at the bottom of this policy. If you are unhappy with any aspect of how we processed your personal data or your request to exercise a right, you can lodge a complaint with the Information Commissioner’s Office.
International users and transfers
Where information is transferred outside the EEA to a country that is not subject to an adequacy decision by the EU Commission, data is adequately protected by EU Commission approved standard contractual clauses or another appropriate data transfer mechanism. When appropriate, we rely on the EU-US Data Privacy Framework (DPF) and the UK Extension to the DPF for data transfers from the EU and UK to the United States.
Changes to this Policy
Any changes to our Privacy Policy will be placed here and will supersede this version of our Policy. We will take reasonable steps to draw your attention to any changes in our Policy. However, to be on the safe side, we suggest that you read this document each time you use the website to ensure that it still meets with your approval.
Vitaccess is incorporated and registered in England and Wales with company number 15270184 and whose registered office is at 2nd Floor Nucleus House, 2 Lower Mortlake Road, Richmond, Greater London, TW9 2JA.
We are contactable by email at dpo@vitaccess.com. To ensure your data is protected, if we receive a request from you to exercise your rights, we will ask you to verify your identity before acting on the request.
How to contact us
If you wish to access, correct, update, request removal of or exercise your rights in relation to any of your information you provided to us or if you have any questions regarding this statement or would like more information on our privacy practices, please contact us at: dpo@vitaccess.com.
EEA Representative Contact Information:
For customers residing in the European Economic Area, we have designated CRANIUM as our representative to facilitate contact. Please contact Vitaccess Legal Representative in Europe at https://privacyrep.eu/client/vitaccess-gdpr-representative-eu/
If you are a California user, you may also have additional rights available to you under the California Consumer Privacy Act. Please review our California Privacy Addendum for additional details.