Welcome to hronline Thank you for using hronline provided by BrightHR Limited, company registration number 9282467, a subsidiary company of Peninsula Business Services Group Limited and whose registered office is situated at The Peninsula, Victoria Place, Manchester, M4 4FB. By logging in and using hronline, you are agreeing to these terms. Please read them carefully. References to ‘us’, ‘we’ and ‘our’ refer to your hronline product provided by BrightHR Limited. Using hronline
Your hronline Account
Privacy and Copyright Protection
Your Content in hronline
Modifying hronline
Our Warranties and Disclaimers
Liability for our Services
Business users of hronline
About these Terms
Data Protection Statement of hronline which is owned and operated by BrightHR Limited
We will use the personal data provided to us only for its intended purpose, and in accordance with Data Protection Law.
Security
We are committed to ensuring that employee information is kept secure at all times, and we will implement appropriate technical and organisational measures against the unauthorised or unlawful disclosure of such information, and so as to prevent its accidental loss, destruction or damage.
Personal access to hronline will only be via a secure username and password. The username and password for each individual is unique and only allows access to their own personal information. Only certain authorised staff, who are required to have access to the personal information of other employees for the purposes of their job role, will be authorised and will have the necessary access rights to do so. They will receive relevant training and will be asked to agree to abide by the terms of this Data Protection Statement.
All users of hronline should keep their unique user and password strictly confidential. Users of hronline must notify us if they become aware of any unauthorised access, and we will notify clients of hronline should we become aware of any security breach involving loss, corruption or theft of employee information.
Storage and Encryption
The data stored on hronline is kept securely in our on-site data centre in Manchester, UK. The information is replicated to an offsite-hosted environment for disaster recovery purposes. We use 128 Bit SSL Encryption for the transportation of data and a Hash Algorithm 128 Bit for passwords. Our systems are periodically penetration tested and kept up to date with ISO 27001 best practices.
This privacy policy explains how personal data is collected and used when you use our websites. It also explains how we process any data that you supply to us on this website, for instance to request a quote or to use our online services.
hronline is the Data Controller for any personal data that you supply to us during your visit to our website.
Our address is
BrightHR Ltd
The Peninsula
Victoria Place
Manchester
M4 4FB
Telephone 0844 892 2779
Email gdpr@hronline.com
What personal data we collect
The personal data collected depends on how you use our website. You can browse the site, you can fill in forms on the website to request information or quotes from us and other activities. Our website collects personal data to provide these services.
We collect information about you when you visit our website; apply for employment with us; and engage in business dealings with us.
What we do with your personal data
When you visit our website, a record of your visit is made. This data includes your device’s IP address. That data is used completely anonymously, in order to determine the number of people who visit our website and the most frequently used sections of the site. This enables us to continually update and refine the site. If you use any forms on the website to send an email to us, a record will also be made of your email address and your telephone number.
The following table sets out how we handle your personal data and our legal basis for doing so under GDPR and the Data Protection Act 2018.
What we do | Our legal basis under GDPR |
Use the personal data that you provide on our web forms and questionnaires | Article 6(1)(b) – when you provide us with your personal data, for instance to obtain a quote for our services, this is a necessary step to take at the request of the data subject prior to entering into a contract |
Provide our online services platforms – Bright HR, or hronline, | Article 6(1)(b) – this is necessary for the performance of a contract with you, our data subject |
Contact you regarding the services we provide | Article 6(1)(f) – we need to contact you for our legitimate interests so that we can gather more information for the provision of our services, or to deliver those services most effectively |
Retain your data under our data retention policy after your contract has expired | Article 6(1)(f) – we need to retain your personal data for only as long as necessary under the law to protect our legitimate interests |
Where you require us to make Reasonable Adjustments to enable you to attend a meeting or interview, we may require further information from you. | Article 9(2)(a) of GDPR (explicit consent). If this includes information about your physical or mental health, such information (being sensitive personal data, Special Category data), will only be used by us, with your explicit consent, to assess your eligibility for Reasonable Adjustments. We will not share or disclose it to others. You can withdraw your consent as anytime by contacting us. Please note that we may not be able to process your request for Reasonable Adjustments if you do this. |
The following table sets out the categories of personal data that we obtain.
Personal Data | Explanation |
Name, postal address, email address, website, identification number, location data, online identifier – these are classed as personal data | This data is provided by you on our web forms and questionnaires, either to obtain a quote from us, request a service from us or as part of the provision of your existing contractual services. This data may be provided if you apply for a job opportunity. |
We may collect, hold, use and disclose the information collected to compile statistical data and to; maintain our database; develop/improve our website; respond to any email enquiries; notify you of any upcoming marketing, training or other events that you have opted in to; provide you with publications; manage quality control; manage systems administration; attend to compliance issues; provide you or your organisation with advice and determine suitability for employment.
We will not use or disclose your personal information for any other purpose which is not related (or in the case of sensitive information, directly related) to the above purposes without your consent, unless otherwise authorised, required or permitted under the laws of England and Wales. hronline does not sell your data to third parties.
If you no longer wish to receive information about our services, please send an email to our Data Protection and Compliance Officer (gdpr@brighthr.com) advising that you do not wish to receive further information.
Will we disclose your data?
Personal data will only be disclosed on a confidential basis to external service providers so that they can provide services such as financial or administrative services in connection with the operation of our business; and to any person (where necessary) in connection with their services, such as law enforcement, regulatory authorities, partners or advisors; or to companies within hronline in the UK.
The handling of these operations is governed by a data processing contract between us and our external service provider, ensuring a commitment to the principals of the GDPR and the Data Protection Act 2018. We ensure external service providers are only authorised to use personal data for the limited purposes specified in our agreement with them.
How long we keep your personal data
Personal data from our data subjects is retained in line with our data retention policy. hronline keeps most data for 7 years, which covers the 6 years by law in which we have to keep certain information for a minimum of 6 years plus the current year. Personal data that is no longer necessary to be kept under hronline’s data retention policy will be deleted. Under hronline’s data retention policy, there are certain exemptions in relation to financial data and health data. A copy of hronline’s data retention policy can be made available upon request.
Your Rights
You have the following rights in relation to personal data held on you by hronline:
If you wish to learn more about these rights and how they operate, please look at the ICO’s website https://ico.org.uk/for-the-public/.
hronline does not operate any automated decision making systems.
You have a right to request a copy of the personal data that we hold about you. If you would like a copy of some or all of your personal data please email gdpr@brighthr.com or write to our Data Protection and Compliance Officer at The Peninsula, Victoria Place, Manchester, M4 4FB. Proof of your identity will be required for security purposes.
If you are unhappy with the response that you receive from us when you exercise your GDPR rights or Data Protection Act 2018 rights, you have the right to lodge a complaint to the ICO. More guidance about raising a complaint with us is available on the ICO’s website https://ico.org.uk/for-the-public/raising-concerns/ and for raising a complaint with the ICO, more information is available on https://ico.org.uk/concerns/.
Cookies
This website uses Google Analytics, a web analytics service provided by Google, Inc. Google Analytics sets a cookie in order to evaluate your use of this website and compile reports for us on activity on the website. Google stores the information collected by the cookie on servers in the United States and the transfer of the data to servers in the USA is governed by the EU-US Privacy Shield framework. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by Google. By using this website, you consent to the processing of data about you by Google in the manner and for the purposes set out above. More information about Google’s compliance with GDPR can be obtained from their website https://privacy.google.com/businesses/compliance.
Cookies are text files placed on your computer to collect standard internet log information and visitor behaviour information. This information is used to track visitor use of the website and to compile statistical reports on website activity. For further information visit www.aboutcookies.org.
You can set your browser not to accept cookies and the above websites tell you how to remove cookies from your browser. However, in a few cases some of our website features may not function as a result.
Other websites
Our website may contain links to other sites. This privacy policy only applies to this website so when you link to other websites you should read their own privacy policy.
How to contact us
Please review the website regularly as this statement may change from time to time. If you have any questions about our privacy policy or information we hold about you please contact:
Data Protection and Compliance Officer
Telephone 0844 892 2779
Email gdpr@brighthr.com
In accordance with the General Data Protection Regulation (GDPR), hronline have implemented this privacy notice to inform you, our client’s employee, of the types of data we process about you. We also include within this notice the reasons for processing your data, the lawful basis that permits us to process it, how long we keep your data for and your rights regarding your data. We are a data processor and your employer remains the data controller at all times. Your data may have been provided to us by the data controller or by you as the data subject.
This notice applies to users of the hronline software who are employees of our Clients.
Our Data Protection Officer, Gail Tuck, who can be contacted at:
hronline, The Peninsula, Victoria Place, Manchester, M4 4FB.
Telephone: 0808 145 3490
Email: gdpr@brighthr.com
Under GDPR, all personal data obtained and held by us must be processed according to a set of core principles. In accordance with these principles, we will ensure that:
We may keep several categories of personal data about you in order to allow you to use the software. We keep this data within our secure computer systems.
Specifically, we may hold the following types of data:
The law on data protection allows us to process your data for certain reasons only. We process your data for our legitimate interests in order to provide you access to and use of the software. We may also process personal data in connection with the establishment, exercise or defence of legal claims.
We are aware of the requirement to ensure your data is protected against accidental loss or disclosure, destruction and abuse. We have implemented processes to guard against such.
We only keep your data for as long as we need it for, which will be at least for the duration of your employer’s contract with us for the provision of the service.
Automated decision making means making decision about you using no human involvement e.g. using computerised filtering equipment. No decision will be made about you solely on the basis of automated decision making (where a decision is taken about you using an electronic system without human involvement) which has a significant impact on you.
You have the following rights in relation to the personal data. However if you wish to exercise your rights any request should be made to your employer as the data controller. Any request made to us as the data processor will be forwarded to our data controller.
Where you have provided consent to our use of your data, you also have the right to withdraw that consent at any time. This means that we will stop processing your data.
If you think your data rights have been breached, you are able to raise a complaint with the Information Commissioner (ICO). You can contact the ICO at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF or by telephone on 0303 123 1113 (local rate) or 01625 545 745.
hronline will only process personal data in accordance with the User’s instructions, the User retains the responsibilities of the data controller and determines the purposes and means of processing personal data.
(a) | Subject matter, nature and purpose of the processing of Personal Data under this Agreement | Subject matter The provision of online human resource management tools and other information services and materials. Nature Processing activities, such as storage, retrieval, analysing, data collection and data transfer will all be undertaken by the Supplier. Purpose Personal Data is processed in order to enable the Supplier to provide access to the services to the Authorised Users of the User, and for administration of the contract and the services. |
(b) | Duration of the processing of Personal Data under this Agreement | For the term of this Agreement. |
(c) | Type of Personal Data processed under this Agreement | Personal Data
|
In accordance with the General Data Protection Regulation (GDPR), hronline have implemented this privacy information notice to inform you, our current and former clients, of the types of data we process about you. We also include within this notice the reasons for processing your data, the lawful basis that permits us to process it, how long we keep your data for and your rights regarding your data.
This notice applies to current and former clients.
We are a Data Processor of the personal data that you supply to us under your contract with us.
Under GDPR, all personal data obtained and held by us must be processed according to a set of core principles. In accordance with these principles, we will ensure that:
We keep several categories of personal data on and from our clients in order to carry out effective and efficient processes. We hold the data within our computer systems to provide our advice service and case management systems.
Specifically, we hold the following types of data:
You provide several pieces of data to us directly when the contract is signed, during the on boarding process and during the contract and after the contract has ended.
Personal data is kept in within the Company’s secure systems.
The law on data protection allows us to process your data for certain reasons only. In the main, we process your data in order to comply with a legal requirement or in order to effectively manage the service contract we have with you, including ensuring we can deliver the service to you.
The information below categorises the types of data processing we undertake and the lawful basis we rely on.
Activity requiring your data | Lawful basis |
Set up your account | Performance of the contract |
Carry out the delivery of the services you have on your account | Performance of the contract |
Ensuring payments are made under your account | Performance of the contract |
Ensuring VAT and insurance premium tax is paid | Legal obligation |
Carrying out checks in relation to your company status and validating the information supplied to us | Legal obligation |
Making financial decisions in relation to entering both initial and subsequent contracts | Our legitimate interests |
Making decisions about service delivery methods | Our legitimate interests |
Ensuring efficient administration of contractual services to you | Our legitimate interests |
Effectively monitoring the service provided including adherence to commitments and service entitlements | Our legitimate interests |
Maintaining up to date records about you to ensure, amongst other things, effective correspondence can be achieved and appropriate contact points in place | Our legitimate interests |
Dealing with legal claims made against us | Our legitimate interests |
Preventing fraud | Our legitimate interests |
Ensuring our administrative and IT systems are secure and robust against unauthorised access | Our legitimate interests |
Your failure to provide us with data may mean that we are unable to fulfil our requirements for entering into a contract with you. This could include being unable to offer you services or administer existing contractual services.
All employees within hronline that handle your personal data are trained in ensuring data is processed in line with GDPR.
Data is shared with other companies within the Peninsula Group of Companies. hronline is a company within the Group. Data may be shared for the following reasons: administration of services specifically supplied by Group subsidiaries. For example, Peninsula/Croner provides employment and health and safety services. Your data is shared with GROUP companies to facilitate the delivery of all the services you are contracted to receive.
Your data is not shared with third parties, except for other reasons to comply with a legal obligation placed upon us. We have a data processing contract in place with such third parties to ensure data is not compromised. Third parties must implement appropriate technical and organisational measures to ensure the security of your data.
We are aware of the requirement to ensure your data is protected against accidental loss or disclosure, destruction and abuse. We have implemented processes to guard against such.
We only keep your data for as long as we need it for, which will be at least for the duration of your service contract plus 12 months from the date that service contract with us terminates, although in some cases we will keep your data for a longer period after your contract has ended. Some data retention periods are set by the law. Retention periods can vary depending on why we need your data, as set out below:
Automated decision making means making decision about you using no human involvement e.g. using computerised filtering equipment. No decision will be made about you solely on the basis of automated decision making (where a decision is taken about you using an electronic system without human involvement) which has a significant impact on you.
You have the following rights in relation to the personal data we hold on you:
Where you have provided consent to our use of your data, you also have the right to withdraw that consent at any time. This means that we will stop processing your data.
If you think your data rights have been breached, you are able to raise a complaint with the Information Commissioner (ICO). You can contact the ICO at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF or by telephone on 0303 123 1113 (local rate) or 01625 545 745.
Our Data Protection and Compliance Officer is:
Gail Tuck
Telephone 0844 892 2779
Email gdpr@brighthr.com