www.caulis-fm.com Privacy Policy
Type of website: Blog, consultancy and Facilities Management Services.
Effective date: ——— day of ——-, ——–
www.caulis-fm.com (the “Site”) is owned and operated by Caulis Facilities Management Ltd. Caulis Facilities Management Ltd is the data controller and can be contacted at:
[email protected]
>Insert Registered Address<
Purpose
The purpose of this privacy policy (this “Privacy Policy”) is to inform users of our Site of the following;
- The personal data we will collect;
- Use of collected data;
- Who has access to the data collected;
- The rights of Site users; and
- The Site’s cookie policy
This Privacy Policy applies in addition to the terms and conditions of our Site.
GDPR
For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the “GDPR”). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.
We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to appoint a Data Protection Officer under Article 37 of the GPDR.
Consent
By using our Site users agree that they consent to:
- The conditions set out in this Privacy Policy
When the legal basis for us processing your personal data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.
You can withdraw your consent by: Contacting the Data Controller
Legal Basis for Processing
We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.
We rely on the following legal basis to collect and process the personal data of users in the EU:
- Users have provided their consent to the processing of their data for one or more specific purposes.
Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.
Data Collected Automaticaly
When you visit and use our Site, we may automatically collect and store the following information:
- IP Address;
- Clicked links; and
- Cookies.
Data Collected in a Non-Automatic Way
We may also collect the following data when you perform certain functions on our Site:
- First and Last Name;
- Email Address;
- Phone Number;
- Address; and
- Payment Information.
This data may be collected using the following methods:
- Server Log files;
- Analytics Scripts;
- Browser Cookies;
- Lead Generation Forms;
- Comment Forms; and
- Booking/ Consultation Form
How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.
The data we collect automatically is used for the following purposes:
- System Administration and Technical Optimisation;
- Analytics and Business Improvement; and
- User Experience and Personalisation.
The data we collect when the user performs certain functions may be used for the following purposes:
- To fulfil a commitment to delivery digital assets, and to initiate a professional relationship;
- Business development and to segment the audience, ensuring future communications are relevant;
- Security, validating subscriptions, and preventing spam;
- To confirm and schedule meetings;
- Pre-session preparation, ensuring meetings are high-value and relevant to the user’s needs;
- Use by scheduling platform for spam prevention; and
- For the payment processor to complete the financial transaction, and to enable us to comply with appropriate VAT/ Tax laws.
Who We Share Personal Data With
Employees
We may disclose user data to any member of our organisation who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.
Third Parties
We may share user data with the following third parties:
- Email Service Providers;
- Google Analytics;
- Hosting Providers;
- Scheduling tool providers; and
- Payment Processing Partners
We may share the following user data with third parties;
- Identifier Data;
- Pseudonymous Identifiers;
- Technical Data; and
- Financial Data.
We may share user data with third parties for the following purposes:
- Fulfilling Service & Consent;
- Legitimate Interests (Such as Analytics);
- Legal Obligations & Security; and
- Contractual Necessity.
Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.
Other Disclosures
We will not sell or share your data with other thirds parties, except in the following cases:
- If the law requires it;
- If it is required for any legal proceeding;
- To prove or protect our legal rights; and
- To buyers or potential buyers of this company in the event that we seek to sell the company.
If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.
How Long We Store Personal Data
We will retain personal data for no longer than is necessary for the purposes for which it was collected. This retention period is determined by a formal assessment of the type of data and its intended use, as detailed below.
In practice, this means we keep data until the user unsubscribes or after a defined period of inactivity (18 to 24 months) has elapsed, unless a longer period is required for statutory legal obligations (such as the 7-year requirement for financial records).
How We Protect Your Personal Data
Caulis Facilities Management Ltd is committed to protecting the integrity and confidentiality of your personal data. We maintain a robust set of technical and organisational measures to ensure data security, minimise the risk of unauthorised access, and adhere to the principles of UK GDPR.
- Technical Security Measures (Protecting the Data Itself)
Encryption (Data in Transit): Our entire website utilises Secure Sockets Layer (SSL) encryption (HTTPS) to ensure that all data transmitted between your web browser and our server is secured and cannot be intercepted by unauthorised parties.
Secure Processing Environment: We utilise established, industry-leading, and GDPR-compliant third-party data processors (e.g. MailerLite, Google) who secure data at rest (stored data) using encryption and maintain advanced security infrastructure.
Website Hardening: We utilise specific technical measures including the use of firewall plugins, malicious login attempt blocking, and ensuring all core software (WordPress, themes, and plugins) is maintained with the latest security updates and patches. - Organizational Security Measures (Protecting Access)
Two-Factor Authentication (2FA): Access to all platforms that store or process user data (including our internal MailerLite, WordPress administration, and hosting accounts) is strictly protected by Two-Factor Authentication (2FA).
Access Control and Permissions: Access to personal data is restricted on a strict need-to-know basis
(e.g., only the Data Controller has access to export the full email list).
Personnel Security: All personnel involved in the processing of data are trained on data protection compliance, privacy procedures, and the principle of data minimization.
Secure Devices: We ensure all devices used to access and process user data are protected with strong, unique passwords and up-to-date antivirus/malware protection. - Data Integrity and Availability
Data Minimisation: We only collect and retain the minimum amount of personal data necessary to fulfill the stated purpose (e.g., Name, Email Address, Organizational Type).
Retention Policies: Data is subject to strict retention periods and is periodically reviewed and
securely deleted once it is no longer necessary for the purpose of collection or legal compliance (e.g., HMRC’s 7-year rule).
Backup Strategy: Regular, automated backups of the website and database are maintained to ensure the availability and integrity of data in the event of a technical failure or security incident.
While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.
Your Rights as a User
Under the GDPR, you have the following rights:
- Right to be informed;
- Right of access;
- Right to rectification;
- Right to erasure;
- Right to restrict processing;
- Right to data portability; and
- Right to object
Children
We do not knowingly collect or use personal data from children under 16 years of age. If we learn
that we have collected personal data from a child under 16 years of age, the personal data will be
deleted as soon as possible. If a child under 16 years of age has provided us with personal data their
parent or guardian may contact our privacy officer.
How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal
data, if we have disclosed your personal data and to who we disclosed your personal data, if you
would like your data to be deleted or modified in any way, or if you would like to exercise any of
your other rights under the GDPR, please contact our privacy officer here:
Stuart James
[email protected]
Insert Registered Address Here<
How to Opt-Out of Data Collection, Use or Disclosure
In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data
Collected section, we provide the following specific opt-out methods for the forms of collection,
use, or disclosure of your personal data specified below:
- Marketing Communications (Opt-out of Emails) You can opt-out by users can easily opt-out
of receiving future marketing communications from CaulisFM at any time. This can be done
by clicking the ‘Unsubscribe’ link found at the bottom of every email we send, or by
contacting us directly at [email protected]. - Non-Essential Tracking & Analytics (Opt-out of Cookies) You can opt-out by users can optout
of the placement of non-essential tracking and analytical cookies (such as those used by
Google Analytics) at any time. This is achieved by:
– Adjusting their preferences via the Cookie Consent Tool available on our website upon their
first visit.
– Configuring their web browser settings to block or delete cookies. - Users have the right to request access to their data, object to specific processing activities
(based on our legitimate interests), or request the complete erasure of all personal data we
hold. You can opt-out by to exercise any of these rights, the user must submit a written
request directly to the Data Controller (Stuart, Caulis Facilities Management Ltd) via email at
[email protected] or by postal mail to our registered business address. We will respond
to all such requests within 30 calendar days.
