Privacy Policy

Last Updated

Our contact details

Address: Impact Box Co-operative Limited, Lytchett House, 13 Freeland Park, Wareham Road,Poole, Dorset, BH16 6FA

Email: privacy@impactbox.coop

Website: www.impactbox.coop

This Privacy Policy discloses how Impact Box Co-operative Limited (“Impact Box Co-operative” below) gather, use and protect your personal data as a data controller. This Privacy Policy applies to personal data collected by Impact Box Co-operative through its external website www.impactbox.coop or, as described below, by other means during the course of its business.

Impact Box Co-operative Limited, Company Number 13924647, is a limited company registered in England and Wales.

1. General Information

Impact Box Co-operative collects personal data to conduct our business, provide and market our services and products, and meet our legal obligations. We may also collect personal data for other purposes, which we would describe in more detail to you at the point we collect the personal data.

You may refuse to provide us with some or all of your personal data; however, this may limit the ways in which we can interact with you, including providing you with our services.

2. The types of personal data we collect and how we use it

  1. Contacting us: When you contact Impact Box Co-operative, either by email or via the ‘Contact us’ form on our website, we collect your email address, name, organisation and any other information you choose to include in the body of your email or responses. We store this personal information on our Salesforce platform and Google Workspace, and use it solely to handle our contact with you.
  2. Mailing lists: If you sign up to our mailing list to receive newsletters and updates, we will store your name and email address, with your consent. We manage our mailing lists and mass email communications through a third party provider, Mailchimp. Mailchimp also collects device information such as IP address, device attributes, connection information and device locations. It also uses tracking technologies similar to cookies. For more information please see our Cookie Policy. You may unsubscribe at any time by clicking the unsubscribe link in the emails. This will automatically remove your details from all mailing lists in Mailchimp. You can also unsubscribe by emailing privacy@impactbox.coop, and we will remove you from the mailing list as soon as is practicable. Where you have signed up to a mailing list, we will retain your data until such time as consent is withdrawn by you.
  3. Job applications: If you apply for a job at Impact Box Co-operative, either in response to a job advert or speculatively, we collect any personal data provided in your application. This will include name, contact details, education and employment history, and any other personal details supplied by you in the process of your application. This may include special categories of personal data, if supplied by you. With regard to the processing of this personal data you will be asked to grant your explicit consent. We collect this personal data in order to process your application and manage the recruitment process. We will only share your data with any Impact Box Co-operative employee who is involved in the recruitment process. If your application is successful and you are employed by Impact Box Co-operative, your personal data will be kept for the duration of your employment contract and for 6 years after your employment at Impact Box Co-operative ends. At the end of this period, your data will be deleted. If your application is unsuccessful, your data will be kept for a period of 1 year, at the end of which it will be deleted, unless you give us your consent to keep it for a longer period. Where you have provided us with consent to use your personal data, you can withdraw it at any time by emailing privacy@impactbox.coop.
  4. Customer information: As an Impact Box Co-operative customer, we will keep a record of the names, email addresses and phone numbers of relevant contacts within your organisation, as well as any communication between the organisation and Impact Box Co-operative, and any other information provided by the customer in contexts such as customer support. This information is supplied directly by the customer, and is stored in our Salesforce system and Google Workspace. We use this personal data to provide the products and services you contract us for. We may also transfer some financial information to third party providers, such as Xero (our accounting platform), and our accountants, in order to comply with legal requirements. This includes personal data provided on invoices, such as invoice contact name and organisation.
  5. Case studies: With your consent we may post a case study on our website of the work we have completed for your organisation, alongside a testimonial with your name, job title and organisation name. We may also include a photograph provided by the organisation, and screenshots of some of the work we have done for you. The screenshots will never contain real personal data. If you wish to update or delete your testimonial, or to remove your photograph from our website, you can contact us at privacy@impactbox.coop. We will retain your data until such time as consent is withdrawn by you.
  6. Website analytics: We use Plausible Analytics to provide analytics on our website traffic. We use Plausible because they do not use cookies, and do not collect any personal data or personally identifiable information. The goal of Plausible is to track overall trends in website traffic, it is not to track individual visitors. All of the data that is collected through Plausible is aggregated and contains no personal information. For more information on the data that Plausible collects, please visit: https://plausible.io/data-policy.
  7. Cookies: We may also store information about you using cookies (files which are sent by us to your computer or other access device), or other tracking technologies. We do not use cookies on our website. However, some of the Third Party Providers we use to provide our services use cookies and other tracking technologies. Please see our Cookie Policy for more information.

3. How we share personal information

We will respect and protect your privacy as set out in this Privacy Policy. We do not, and will not, sell your personal data to any third parties.

We employ third party service providers to perform functions on our behalf. These third party service providers have access to personal information needed to perform their functions, but may not use it for other purposes. Examples of where we may employ third party service providers include; sending communications, processing payments, analysing data, conducting customer relationship management, cloud services and accountancy. The third party service providers we use are listed in Annex 1 of this Privacy Policy.

We will share personal data as we are required by law, such as to comply with any court order, or other law or legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a governmental or regulatory request.

We may also share personal data to enforce our rights arising from any contracts entered into between you and us and for billing and collection.

You might find links to third party websites on our website. If you click a link to a third-party website and visit that site, you may be allowing that site to collect and share certain data about you. These websites should have their own privacy policies, which you should check. We do not accept any responsibility or liability for their policies whatsoever.

5. International transfers

Impact Box Co-operative is located in the United Kingdom. When we share data, it may be transferred to, and processed in, countries outside of the European Economic Area (EEA), such as to the United States, where some of our third party service providers are located. We ensure that any third party service providers we share information with have safeguards in place to ensure your personal data remains protected.

Where your personal data is transferred outside the EEA, it will only be transferred to a third party where we have approved transfer mechanisms in place to protect your personal data – e.g., by entering into the European Commission’s Standard Contractual Clauses. For further information, please contact us using the details set out in the Contact us section below.

6. Our policy on children

We do not knowingly collect data relating to children under 18 through the Impact Box Co-operative website or activities.

Under the General Data Protection Regulation (GDPR), the lawful bases we rely on for processing this information are:

(a) Your consent. This applies in the cases above where you have consented to Impact Box Co-operative processing your personal data, for example by signing up to a mailing list, applying for a job, or permitting Impact Box Co-operative to publish a case study on our website. You are able to remove your consent at any time. You can do this by contacting privacy@impactbox.coop.

(b) We have a contractual obligation. If you are an Impact Box Co-operative customer, we process your personal data in order to fulfil our contractual obligations to you.

(c) We have a legal obligation. In some cases, we may have a legal obligation to collect or retain personal information.

(d) We have a legitimate interest. In the cases where (a), (b) and (c) do not apply, we will only process personal data where we have a legitimate interest, and this isn’t overridden by your rights.

8. Data retention

We will only retain your personal information for as long as required to fulfil the purposes outlined in this Privacy Policy. We comply with all legislative and regulatory information retention requirements and will securely and permanently delete your personal information where there is no jurisdiction for its further retention, or where you have asked us to delete it. We will not use your personal information for any other purposes.

9. Your data protection rights

Under data protection law, you have rights including:

Your right of access - You have the right to ask us for copies of your personal information.

Your right to rectification - You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.

Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.

Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal information in certain circumstances.

Your right to object to processing - You have the right to object to the processing of your personal information in certain circumstances.

Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.

You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.

Please contact us at privacy@impactbox.coop or write to us at Impact Box Co-operative Limited, Lytchett House, 13 Freeland Park, Wareham Road,Poole, Dorset, BH16 6FA if you wish to make a request.

10. How to contact us

If you have any concerns about our use of your personal information, you can make a complaint to us at privacy@impactbox.coop or write to us at Impact Box Co-operative Limited, Lytchett House, 13 Freeland Park, Wareham Road,Poole, Dorset, BH16 6FA.

You can also complain to the ICO if you are unhappy with how we have used your data.

The ICO’s address:

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline number: 0303 123 1113

ICO website: https://www.ico.org.uk

11. Changes to the Policy

This Privacy Policy may be updated from time to time and will note the date of any updates. In the event of any material and significant changes we will endeavour to provide a more prominent notice of the changes to this Privacy Policy.

Annex 1: Third Party Providers

We use the following third party providers to provide our services:

CitrusHR

  • Location: EU
  • Date Protection Framework: EU GDPR
  • What we share: Employee details
  • Why we share it: To manage our HR processes
  • Privacy Policy: CitrusHR Privacy Policy

Mailchimp

  • Location: US
  • Date Protection Framework: Standard Contractual Clauses
  • What we share: Name. Email address. Device information including; IP address, device attributes, connection information and device locations. It also uses web beacons to show when an email has been opened.
  • Why we share it: To send marketing, newsletters and other communications
  • Privacy Policy: Mailchimp Privacy Policy

DocuSign

  • Location: EU
  • Date Protection Framework: EU GDPR, any transfers outside of EU are covered by Binding Corporate Rules (BCRs)
  • What we share: Contact name. Email address. Organisation. Contract details. For employment contracts this may include home addresses and salary details.
  • Why we share it: To process contracts and agreements
  • Privacy Policy: DocuSign Privacy Policy

GitHub

  • Location: EU & US
  • Date Protection Framework: Standard Contractual Clauses
  • What we share: Customer name, contact details, any information requested to be processed by customer
  • Why we share it: To build automation and operational processes for customers
  • Privacy Policy: GitHub Privacy Policy

Google Workspace

  • Location: EU
  • Date Protection Framework: EU GDPR, any transfers outside of EU are covered by Standard Contractual Clauses
  • What we share: Names, email addresses, content of emails, back-up of Salesforce system.
  • Why we share it: Daily operations including emails, file storage and back-up of Salesforce system
  • Privacy Policy: Google Workspace Privacy Policy

Jira

  • Location: Global
  • Date Protection Framework: Standard Contractual Clauses
  • What we share: Customer name, contact details, information related to contracted project
  • Why we share it: Project management
  • Privacy Policy: Jira Privacy Policy

Salesforce

  • Location: EU
  • Date Protection Framework: EU GDPR, any transfers outside of EU are covered by Binding Corporate Rules (BCRs) and Standard Contractual Clauses
  • What we share: Names, email addresses, job titles, organisations
  • Why we share it: CRM system
  • Privacy Policy: Salesforce Privacy Policy

Impact Box Cooperative Limited

Registered Company Number 13924647

Ⓒ Impact Box 2022