GDPR Compliance Statement
Introduction
Simply put, individuals will now have greater say over how, why, where and when their personal data is gathered, processed and disposed of. Any organisation that works with EU residents’ personal data in any manner, irrespective of location, has obligations to protect the data.
This document outlines what steps sfG Software has taken to fulfil our obligations under the GDPR legislation where we hold or process personal data on your behalf. To find out more information about GDPR, the Information Commissioner’s website is an excellent resource: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr
Our Commitment To You
Data Protection And Gdpr
- A controller determines the purposes and means of processing personal data
- A processor is responsible for processing personal data on behalf of a controller
- ‘Personal data’ means any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.
In most cases our relationship with you is that you are the Data Controller and sfG Software is a Data Processor. There will also be some cases where sfG Software is a Data Controller.
We, as Data Processor, undertake to process data by: acting only on the written instructions of the Data Controller; ensuring that people processing the data are subject to a duty of confidence; taking appropriate measures to ensure the security of processing; and refraining from subcontracting the processing of your data without your consent.
Contracts
sfG Software has appropriate written contracts with all of its sub-processors.
As of 1st May 2018, sfG Software’s standard client contract (ie our contract with you) contains the necessary GDPR clauses, and we have made available a contract addendum to all our customers to ensure we have the correct contract in place going forward. If you have not received and signed one of these contracts then please get in touch at dataprotection@sfgsoftware.com.
Data Security
In order to achieve the more advanced Cyber Essentials Plus certification, an organisation must be audited by an independent accreditation body who tests the five key security controls and performs vulnerability and other scans. sfG Software has been certified at the more advanced “Cyber Essentials Plus” level so we can demonstrate a higher level of security than the basic level provides for.
In summary, these independent certifications demonstrate that we hold your data securely.
Sub-processors
International Transfers
We will not transfer data outside of the European Economic Area without your prior written consent. We are based in the UK and we always aim to store our data within the European Union. However, some organisations which provide services to us may transfer personal data outside of the EEA, but we’ll only allow them to do so if your data is adequately protected.
Management Of Personal Data Breaches
sfG Software has a clearly documented breach management process which complies with the GDPR requirements and ensures that the relevant supervisory authority (the ICO in the UK) is informed if it’s likely that there will be a risk to people’s rights and freedoms; and that the affected individual(s) are informed if it’s likely that there will be a high risk to people’s rights and freedoms.
The Managing Director has overall responsibility for assessing and managing possible breaches.
Internal Policies And Procedures
Privacy Notices
Summary
This document is intended to demonstrate that we have fulfilled all our obligations under the GDPR legislation, but if you have any questions or concerns then please contact as by emailing dataprotection@sfgsoftware.com.
David Garvie
Managing Director