How we use your information…
This privacy statement tells you what to expect when Xperior collects your personal information. It applies to information we collect about:
- Visitors to our website
- Complaints and feedback received
- Information required for commercial purposes for providing our services to our customers
- Information for marketing of Xperior
- Job applicants and our current and former employees
- Mystery Shopping Customers
Visitors to our website
When someone visits our website, we use a third-party service, Google Analytics, to collect standard internet log information and details of visitor behaviour patterns. We do this to find out things such as the number of visitors to the various parts of the site. This information is only processed in a way which does not identify anyone. We do not make, and do not allow Google to make, any attempt to find out the identities of those visiting our website. If we do want to collect personally identifiable information through our website, we will be up front about this. We will make it clear when we collect personal information and will explain what we intend to do with it.
Cookies are small text files that are placed on your computer by websites that you visit. They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site. The information below explains the cookies we use and why.
Cookie: Google Analytics
Name: _ga / _gali
Purpose: Used to measure how users interact with our website content, navigation and pages viewed.
This cookie is used to distinguish visitors to our site.
Purpose: This is the Google Universal Analytics cookie. This cookie is used to store and update a unique value for each page visited on our site.
Purpose: This cookie does not store any user information, it is used to limit the number of requests that have to be made to doubleclick.net
How do I change my cookie settings?
Most web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org.
To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout.
Submission of your information
Submission of your information, requested, from our website is held on our secure platform. This is protected by all methods necessary. Only the required personnel have access to this information. Your information will only be used for the stated intended purpose and will not be shared outside of Xperior without your express consent. Your consent to share your information will be sought at the time of you submitting your data.
Complaints and feedback
Should you wish to make a complaint our complaints process is available upon request. All information received during the course of a complaint is handled with the same level of security protection on need for privacy as any other information we collect.
Information required for commercial purposes for providing our services to our customers
Xperior use information provided by yourself to provide our services and products to our customers. This data is only used for its intended and stated purpose. This includes financial information for the production of invoices and receiving of payments for services provided.
Protecting your information
In order to protect your information, we have in place the following methods of protection: –
- Monitored Firewall protection
- Malware protection on all platforms
- Encryption on data at rest and at point of use
- Ongoing backups
- Auditing for data integrity on an ongoing basis
Xperior have a backup policy in place. We retain backups indefinitely. Upon receiving a request to remove data of a personal nature, this will be completed by removing all reference and data from the production environment. Backups do not exist within a production environment, where data resides solely in the backup following deletion of the entry within the production environment it cannot be accessed.
Requests for your information
We will respond to requests for the information we hold on you within the required 30-day period. Initial requests will not be charged. However, should more than 2 requests be made within a 3-month period of time, subsequent requests will be charged at £10 per request.
All information will be provided in the format of a PDF document.
Xperior collect information from various sources for marketing purposes. This information can be from social media forums, industry forums to name but a few. We retain this information for a period of no more than 18 months, or the duration of the marketing campaign only.
Xperior share contractually relevant information with the following external organisations for commercial purposes: –
- Imperator Group
- Mystery Shopping Customers
Information is shared with organisations within the UK-EU.
The exception to this criteria is the sharing of information with UK authorities for investigatory purposes as per current legislation on finance and personnel.
Xperior are aware that sometime information with regards to suppliers is personal in nature. This information is protected to the full extent as any other information within our environment. This information is not shared unless express permission is granted by the individual.
Job applicants and our current and former employees
When Xperior receive job applications we hold these in a secure manner. The application forms are deleted or, in the instance of hard copies, shredded after the selection period is completed. This information is not shared outside our organisation and is only shared internally with designated personnel. Were information of an applicant is to be retained for future use only the contact information will be retained. Consent from the applicant will be sought prior to the retention of any personal contact information.
All personal information held by Xperior on current employees is managed and maintained in a secure manner, the same as any other information we hold. All employees have the right to view the data we hold on them at any time. A formal request is required to be made for this information through their line manager.
All personal information held by Xperior on former employees is managed and maintained in a secure manner, the same as any other information we hold. Should a former employee wish to view the data that we hold on them the steps for requesting information (detailed above) is followed. Information held on personnel is retained for a period no longer than 3 years after the cessation of employment, in line with current UK legislation. After this period of time all information on the former employee is deleted. If requested, a confirmation of this will be communicated to the person.
Reporting of Data Breaches
Xperior report all major data breaches, of data we have control and are responsible for, to the Information Commissioners Office, our customers and/or suppliers. All potential data breaches are fully investigated as per our Information Security Incident Policy.
When a data breach is detected, and the severity ascertained, this will be reported to the ICO within 72 hours.
Security and Protection
Xperior take security of all information seriously, we have the following policies in place to ensure compliance with GDPR:
- Data Protection Policy
- Backup Policy
- Malware Protection Policy
- Encryption Policy
- Subject Access Request Policy
- Security Incident Management Policy
- Information System Audit Policy
Data Protection Officer
Xperior have designated the Managing Director – Emma Carmody as their Data Protection Officer (DPO). If you have any concerns relating to data protection you are more than welcome to contact the DPO; to contact the DPO please email: firstname.lastname@example.org