The Independent Monitoring Authority (“IMA”, “we”, “us”, “our”) of 3rd Floor Civic Centre, Oystermouth Road, Swansea, SA1 3SN are committed to protecting and respecting your privacy. The IMA are committed to the protection of the personal data we process in line with the data protection principles set out in the EU and UK General Data Protection Regulation (“GDPR”) and the Data Protection Act 2018 (“DPA18”).
This privacy notice (“this Notice”) explains what personal data the IMA collects from individuals who visit our website, contact us using our web forms, by email, phone or through one of our social channels; or other marketing communications (“you”, “your”). It also explains what information we collect automatically when you visit our website and the information we collect when you register to use our services.
The Independent Monitoring Authority is the data controller for the purposes of the GDPR in instances where you make an enquiry with us, registered in the UK with the Information Commissioner’s Office, registration number ZA804857.
As an information-led business, we place great importance on ensuring the quality, confidentiality, integrity and availability of the data we hold and in meeting our data protection obligations when processing personal data. The IMA are committed to protecting the security of your personal data. We use a variety of technical and organisational measures to help protect your personal data from unauthorised access, use or disclosure.
We update this Notice from time to time in response to changes in applicable laws and regulations, to our processing practices and to the products and services we offer. When changes are made, we will update the date at the top of this document.
Please review this Notice periodically to check for updates.
You can download a PDF version of this privacy notice by clicking here
What information do we process?
Information you provide to us
We process all information you give us, either through our website https://ima-citizensrights.org.uk/ (“our site”) or by corresponding with us by telephone, email or otherwise. This includes information you provide when you use our site, register for our service, search for a product or service, or other social media functions linked to our site, or when you report a problem with our site.
Information processed following an enquiry
We may process the following information:
- Email address
- Telephone number(s)
- Any information you share through our social media channels
- Device information
- Location data
We use your name, address, email address and telephone number to contact you about your complaint or enquiry.
Information processed when registering a complaint with the IMA
The list of information processed may include, but is not limited to:
- Email address
- Telephone number(s)
- Business name (if applicable)
- Date of Birth
- National Insurance Number
- Medical / Health data or reports.
This information is strictly protected, only accessible by colleagues that need access.
- Portal log-in data
- Portal usage data
- Location data
- Identification documents (e.g., copy of passport, other identity card)
- Information required for legal and regulatory compliance
Cookies and Web Beacons
To learn more about cookies, web beacons and what you can do to opt out of receiving them, please visit https://www.allaboutcookies.org/.
Purpose and bases for processing your data
We may use your data for the following purposes and on the following lawful bases:
|Purpose||Lawful Bases for Processing|
|Responding to correspondence from you||It is in our legitimate interest to respond to enquiries made via our website, by email, through our social channels or any other means.|
|Registering a complaint with the IMA.||When you register a complaint with us, we process your data with your consent. This consent may be withdrawn at any time by emailing firstname.lastname@example.org When processing your special category data, we do so with your explicit consent. This consent may be withdrawn at any time by emailing email@example.com|
|Business management, forecasting and statistical purposes||It is our legitimate interest to identify areas for managing current business relationships, develop our services and for managing our business.|
|Improving our website and the overall website visitor and user experience||It is our legitimate interest to allow analytics and search engine providers to help improve and optimise our website|
|Prevention and detection of crime including money laundering, fraud or other crimes||We have a legal obligation to report any such activity to the relevant authorities and regulators|
|Providing you with updates about your complaint and the stage of the investigation process||It is our legitimate interest to provide accurate and up-to-date information to users of our website and to increase features in order to continually improve and expand the services we provide|
|Improving our website and the overall website visitor experience||It is our legitimate interest to allow analytics and search engine providers to help improve and optimise our website|
|Analyse and track use of our website for reporting and analytical purposes||It is our legitimate interest to monitor our website usage in order to continually improve the user experience|
Sharing your information
We will rarely share your personal data outside the United Kingdom (UK) and the European Economic Area (EEA). If this becomes necessary for the purposes of providing our services to you, we will only share it where appropriate safeguards are in place, such as the EU Standard Contractual Clauses (SCCs), to ensure your personal data is protected to the same standard expected within the UK and EEA.
Once you have registered your complaint with us, to assist with our investigation, we may need to share your personal data with selected Government agencies. We will only do this with your consent, which may be withdrawn at any time by emailing firstname.lastname@example.org. Should you withdraw your consent, we will cease sharing your personal data immediately. We may continue to use the details of your complaint in order to complete the investigation, but all personal data by which you can be identified will be removed so that you remain anonymous. This is to ensure that the issues that you have highlighted can still be fully investigated.
Our website includes links to other third-party websites and social media platforms (Facebook, Instagram, Twitter). Once you navigate away from our site via one of the links, the site may collect your IP address and may set a cookie on your device. When you use one of these links, you are sharing information to another website or service and this Notice will no longer apply. Please read the privacy notices provided by the particular service website you are directed to before posting any personal information using these links.
The GDPR provides you with certain rights in relation to the processing of your personal data, including to:
- Request access to personal data about you (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you, and to check that we are processing it lawfully
- Request rectification, correction, or updating to any of the personal data that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request personal data provided by you to be transferred in machine-readable format (“data portability”).
- Request erasure of personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove personal data where you have exercised your right to object to processing (see below).
- Request the restriction of processing of your personal data. This enables you to ask us to suspend the processing of personal data about you (e.g., if you want us to establish its accuracy or the reason for processing it).
- Object to the processing of your personal data in certain circumstances. This right may apply where the processing of your personal data is based on the legitimate interests of the IMA.
Some of these rights are not absolute and are subject to various conditions under applicable data protection and privacy legislation, laws, and regulations to which we are subject. If at any time you decide that you no longer wish to be contacted for marketing purposes, or if you would like to exercise any of your rights as set out above, you can contact us at email@example.com. You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
In addition to the above, please note that you have the right to make a complaint at any time to the Information Commissioner’s Office if you are concerned about the way in which we are handling your personal data.
Data retention period
We will retain your personal data for as long as is necessary to provide you with our products and ongoing services and for a reasonable period thereafter, to enable us to meet our contractual and legal obligations and to deal with complaints and claims.
At the end of the retention period, which should be no longer than 7 years, your personal data will be securely deleted in accordance with the IMA Personal Data Retention and Destruction Policy.
You can contact the IMA in relation to data protection and this privacy notice by emailing firstname.lastname@example.org.