Data Protection Policy
1. Purpose
This policy outlines how Digital Mailing Solutions ("DMS", "we", "our", "us") protects and processes personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We are committed to safeguarding the privacy and security of all personal data we hold, whether related to our customers, employees, suppliers, or other third parties.
2. Scope
This policy applies to:
All employees and contractors of DMS
All processing of personal data conducted by or on behalf of DMS
All business activities involving the collection, storage, use, and sharing of personal data
3. Definitions
Personal Data: Any information relating to an identified or identifiable individual.
Processing: Any operation performed on personal data, whether by automated means or not.
Data Subject: The individual whose personal data is being processed.
Data Controller: The organisation that determines the purposes and means of processing personal data.
Data Processor: A third party that processes data on behalf of the data controller.
4. Legal Basis for Processing
We only process personal data when we have a legal basis to do so. These may include:
Consent from the data subject
Fulfilment of a contract
Legal obligation
Legitimate interests (where these are not overridden by the rights of the data subject)
5. Principles of Data Protection
DMS adheres to the following principles as required by the UK GDPR:
Lawfulness, Fairness, and Transparency
We process personal data lawfully, fairly and in a transparent manner.
Purpose Limitation
We collect data for specified, explicit and legitimate purposes, and do not process it in ways incompatible with those purposes.
Data Minimisation
We only collect data that is adequate, relevant and limited to what is necessary.
Accuracy
We keep personal data accurate and up to date.
Storage Limitation
We keep personal data only for as long as necessary.
Integrity and Confidentiality
We process data in a way that ensures appropriate security, including protection against unauthorised access or disclosure.
6. Individual Rights
Data subjects have the right to:
Access their personal data
Request rectification or erasure
Restrict or object to processing
Data portability
Withdraw consent at any time (where processing is based on consent)
Lodge a complaint with the Information Commissioner's Office (ICO)
We will respond to any valid request within one month.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data from unauthorised access, alteration, disclosure, or destruction. These include:
Secure file storage and access controls
Password protection and encryption where necessary
Regular reviews of our data processing activities
8. Data Sharing
We do not sell personal data. We may share data with trusted third parties such as:
Service providers acting as data processors
Regulatory bodies or legal authorities when required by law
All third parties are subject to appropriate confidentiality and security obligations.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose it was collected for, including for legal, accounting or reporting requirements. Once no longer required, data is securely deleted or anonymised.
10. International Transfers
If we transfer personal data outside the UK, we ensure that appropriate safeguards are in place in accordance with data protection laws, such as:
Adequacy decisions
Standard contractual clauses
11. Data Breaches
In the event of a personal data breach, we will assess the risk to individuals and notify the Information Commissioner's Office within 72 hours if required. We will also inform affected individuals when legally obligated.
12. Responsibilities
Management is responsible for ensuring this policy is implemented and reviewed regularly.
Employees and contractors are expected to understand and comply with this policy and attend training where applicable.
Our Data Protection Contact is responsible for overseeing our data protection practices and responding to any data protection queries.
13. Training and Awareness
All employees receive training on this policy and our data protection responsibilities. Additional training may be provided based on role or function.
14. Contact Us
If you have any questions about this Data Protection Policy or your personal data, please contact us:
View our Privacy Policy here
View our Cookie Policy here
Data Protection Policy
Your privacy matters to us. This policy explains how we handle personal data responsibly and securely.
