Data Protection legislation and the Act is currently going through a period of change. The introduction of the European Union’s General Data Protection Regulation (GDPR) and the new British Data Protection Bill, which will replace the Act, is currently passing through Parliament and is the basis of this change. This Privacy Notice is therefore intended to comply with the Act and GDPR but may change over time.
Cut My Utility Bills’s DPO is Martin Pavion (subject to change). The DPO fulfils a number of roles, one of which is to be the primary and independent point of contact for Data Subjects. The mechanism for Data Subjects to raise concerns regarding the processing of their personal data by FPU is to email hello@cutmyutilitybills.com
or telephone +44 (0)7341320193 ; or send a letter by registered mail to Cut My Utility Bills, Utilities House, Southport, Merseyside, PR8 4TH, at which point the inquiry will be forwarded to the DPO for action.
The lawful basis of processing your personal data are as follows:
Legitimate Interest.
As part of general marketing activities.
Consent.
Once you have agreed to this Privacy Notice & the Cookie Policy of our Terms & Conditions, we will process your personal data on the basis of consent.
Contract.
Once you have started the process of signing a contract we will process your personal data on the basis of a Contract, even if the process hasn’t been completed.
The information we hold should be accurate and up to date. The personal information which we hold will be held securely in accordance with our internal security policy and the law. The type or categories of personal data we will collect about you includes your:
Name
Company name
Postal address
Business address
Contact telephone numbers (land, mobile, fax)
Email address
Bank details. They are not stored on our website, or elsewhere. They are used only when providing details to suppliers for contracts.
Under the Act and even more so under the GDPR you have a number of Rights which we have outlined below:
Right of Access
You are entitled to access your personal data so that you are aware of and can verify the lawfulness of the processing. This is achieved through the mechanism of Subject Access Rights (SAR) and you have the right to obtain:
Confirmation that your data is being processed;
Access to your personal data (a copy); and
Other supplementary information, which corresponds to the information in this privacy notice.
Identify Verification
To protect your personal data, Broker For Energy will seek to verify your identity before releasing any information, which will normally be in electronic format.
Right of Rectification
You are entitled to have personal data rectified if it is inaccurate or incomplete. Cut My Utility Bills will respond within one month of your request. In the unlikely event Broker For Energy does not take action to the request for rectification, Cut My Utility Bills will inform you of your rights to complain or seek judicial remedy.
Right of Erasure
You may request the deletion or removal of personal data where there is no compelling reason for its continued processing. The Right to erasure does not provide an absolute ‘right to be forgotten,’ especially once the processing is based upon a contract. However, you do have a right to have personal data erased and to prevent processing in specific circumstances:
Where the personal data is no longer necessary in relation to the purpose for which it was originally collected/processed;
When you withdraw consent (and this is the basis of processing);
When you object to the processing and there is no overriding legitimate interest for continuing the processing;
The personal data was unlawfully processed;
The personal data has to be erased in order to comply with a legal obligation.
Right to Restrict Processing
Under the Act, you have a right to ‘block’ or suppress processing of personal data. The restriction of processing under the GDPR is similar. When processing is restricted, Cut My Utility Bills is permitted to store the personal data, but not further process it. In this event exactly what is held and why will be explained to you.
Right to Data Portability
You may make a request to obtain and reuse your personal data for your own purposes across different services. This allows you to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without hindrance to usability. The Right to Data portability only applies:
To personal data you have provided to Cut My Utility Bills
Where the processing is based on your consent or for the performance of a contract; and
When processing is carried out by automated means.
In these circumstances Cut My Utility Bills will provide a copy of your data in CSV format, free of charge, without undue delay and within one month. If there is a delay to this, you will be informed.
Right to Object
You have the right to object to:
Processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling);
Direct marketing (including profiling); and
Processing for purposes of scientific/historical research and statistics.
Broker For Energy do not participate in the first and third activities, however Cut My Utility Bills does conduct marketing activities as explained above.
Automated Decision Making and Profiling.
Broker For Energy does not employ any automated decision-making or conduct profiling of Data Subjects. However, if you have consented to be held on our Customer Relationship Management (CRM) data base we may periodically send you marketing information so that you are informed of upcoming events, business updates and information about and pertaining to Cut My Utility Bills. These will be automated but they do not involve automated decision-making or profiling.The information we collect from you enables us to fulfil your request for our services – namely, to send you information or content in which you may be interested, and keep you abreast of any updates related to our Site. We also use this information to personalise and continually improve our Site.
On our Site, we may use cookies and other automated devices to collect information about you when you visit our Site and register for the Site. Specifically, we may collect the following information about your use of the Site via these technologies: your domain name; your browser type and operating system; web pages you view; links you click; your IP address; length of time you visit our Site; and the referring URL, or the webpage that led you to our Site.
We may also use automated devices and applications, such as Google Analytics and Facebook Insights, to track usage of our Site. We may use the information gathered through these methods in anonymous or aggregated form to analyse ways to improve our Site. This information may also be associated with your username or email address and may be combined with other information, including personally identifiable information that we collect about you.
We use the information that we gather about you for the following purposes:
To fulfil services to you related to your Account, to communicate with you about your use of our Site or products that we offer or make available through the Site and for other customer service purposes.
To respond to any enquiries, you submit to us.
To operate and improve the Site.
Where permitted by law, for marketing and promotional purposes; For example, we may use your information, such as your email address, to email you news and our newsletters.
To better understand how users access and use our Site and Account, both on an aggregated and individualised basis, for the purposes of improving our Site.
We have implemented commercially reasonable precautions, including, where appropriate, password protection, encryption, SSL, firewalls, and internal restrictions on who may access data to protect our Site and the information we collect from loss, misuse, and unauthorised access, disclosure, alteration, and destruction. Please be aware that despite our best efforts, no data security measures can guarantee 100% security all of the time.
You should take steps to protect against unauthorised access to your password, phone, and computer by, among other things, signing off after using a shared computer, choosing a password that nobody else knows or can easily guess and keeping your password private. Also, you should never share your log-in information with others. We are not responsible for any lost, stolen, or compromised passwords or for any activity on your account via unauthorised password activity.