Venner Shipley comprises two legal entities (Venner Shipley LLP registered number OC308202 and Venner Shipley Germany LLP registered number OC444240). Collectively; Venner Shipley.
Venner Shipley is committed to protecting your privacy. This privacy notice is our privacy policy, it explains what to expect from us in respect of our use of Personal Data. This policy/notice, may be updated at any time, and so we advise you to check this page from time to time. Most interaction and Personal Data processing by Venner Shipley is via client engagement subject to contract.
We always respect the confidentiality of your information. We process data on permitted legal bases, typically under contractual terms, by consent or legitimate interest.
Any international transfers of your Personal Data outside the EEA and Switzerland are either based on contractual terms that meet data processing requirements, or on your instructions to provide services to you. Please note that in order to provide services to you, or process any application form, we may on occasion be required to share your information with associated firms around the world who provide services on our behalf to you. This will always be subject to our engagement terms with you.
By interacting with our website or any one of our entities you must be willing to be bound by the data practices described in this privacy notice. If you do not agree with any part of this privacy notice, then you should not engage further with our website, or any other service we provide.
This privacy notice explains how we process Personal Data and is provided in accordance with our obligations under applicable privacy and data protection law, including the Data Protection Act 2018, the UK GDPR (which retains the Regulation (EU) 2016/679 (General Data Protection Regulation), and the Privacy and Electronic Communications Regulations 2003 (collectively the ‘Applicable Data Protection Legislation’).
For the purposes of this privacy notice, the term ‘Personal Data’ means any information which identifies a living individual or which allows them to be identified when combined with other information. It does not include data where identity has been removed (‘Anonymised Data’).
Our contact details
Venner Shipley (“We” “Us”) is the controller for the Personal Data we process, unless otherwise stated.
There are many ways you can contact us, including by phone, email and post.
Our contact details are as follows:
Postal address: TIDE Bankside, 8 Emerson Street, London, SE1 9DU
Email: datacompliance@vennershipley.co.uk
T: +44 (0) 20 7600 4212
F: +44 (0) 20 7600 4188
If you need to contact us about Personal Data please email datacompliance@vennershipley.co.uk if using our postal address please mark the envelope ‘Data Protection Officer.’
What Personal Data we collect
We collect Personal Data when you provide it to us directly and through your use of our website at www.vennershipley.co.uk. The categories of Personal Data we collect will vary depending on the activity you choose to undertake with us.
Personal Data is collated from various sources, including:
Personal Data is mainly given to us in order to carry out contracted services. We may collect information and Personal Data from you from a number of sources. You may give us Personal Data by corresponding with us by phone, e-mail or otherwise. By way of non-exhaustive example, this includes information you provide when you register to use one of our websites, subscribe to one of our services, submit your CV to us, or any other communication with us.
Personal Data we collect includes:
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your Personal Data but, like Anonymised Data, is not considered Personal Data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with Personal Data so that it can directly or indirectly identify you, we treat the combined data as Personal Data which will be used in accordance with this privacy policy.
Special category Personal Data
We may occasionally collect, and process special category Personal Data but only where you have given explicit consent. We may also carry out screening checks (including reference, background, directorship, financial probity, identity, eligibility to work, vocational suitability and criminal record checks) you will need to consent to this and if you provide such information then you will be taken to have consented because you are seeking employment with us and understand why this data processing is being done. If you have any questions please ask those you are liaising with who will ensure you are fully informed and that you are only consenting on the basis of full understanding.
Personal data we receive from other sources such as clients
We may collect information from public sources and social media platforms and any information gathered through these channels will also be governed by the privacy settings, policies, and/or procedures of the applicable social media platform, which we strongly encourage you to review. We will comply with this policy.
We may receive Personal Data about you from third parties including, for example: Clients and business partners, sub-contractors in technical, advertising networks, analytics providers, search information providers, and credit reference agencies, regulatory authorities, recruitment agencies, information or service providers, publicly available records. We operate on the basis that we contractually expect them to confirm they have informed you of the potential for your Personal Data being shared. If we need to contact you we shall explain how we came to have your Personal Data and why we are contacting you.
Our Legal Basis for using your Personal Data
We will process Personal Data on the following legal bases:
Performance of a contract: We may need to collect and process Personal Data to fulfil or enter into a contract, and where we respond to your requests and provide you with services in accordance with our terms and conditions.
Compliance with a legal obligation: We may be required to process Personal Data due to legal requirements, including employment laws, tax laws and other regulatory provisions applicable.
Legitimate Interest: Where we consider use of Personal Data as being (a) non-detrimental to you, (b) within your reasonable expectations, and (c) necessary for our own, or a third party’s legitimate purpose.
Under this lawful basis we may process Personal Data, for these purposes:
There may also be circumstances where we might be obliged to report possible criminal acts or threats to public security to a competent authority.
How will we use your Personal Data?
Most commonly, we will use your Personal Data in the following circumstances:
Disclosure
We may exchange your Personal Data with trusted, vetted, third-party service providers (including telephone and IT service providers) where any of the following apply:
We do not sell, rent, or otherwise share Personal Data that identifies you or your organisation with unaffiliated entities for their independent use.
International Transfers
Sharing of Personal Data sometimes involves cross-border data transfers, including transfers outside of the UK in accordance with the law, and that maybe to locations outside the EEA. We only transfer Personal Data to fulfill our services to you, and share to entities in third countries that provide appropriate safeguards to ensure that their level of data protection is in agreement with this privacy notice and applicable law.
Where we receive requests to disclose Personal Data from law enforcement or regulators, we carefully validate these requests, including reviewing the legality before any Personal Data is disclosed.
How long do we keep your Personal Data?
Your personal data is retained for as long as we are required to use it to provide services to you or comply with regulatory or legal obligations. The time varies due to the nature of services that we offer that often require multi-year processing. We will retain Personal Data in accordance with the our document retention policy, taking into account legitimate business needs to retain such information. A maintained copy of our retention policy is available upon request. We endeavour to permanently erase Personal Data once it reaches the end of its retention period or where we receive a valid request to do so; where erasure is not possible, we seek to put it beyond use or access.
Security
We use up-to-date data storage and security techniques to protect your Personal Data from unauthorised access, improper use or disclosure, unauthorised modification or unlawful destruction or accidental loss. We keep data on secure UK based servers. All our employees and any third parties we engage to process your Personal Data are obliged to respect the confidentiality of your information.
Your data protection rights
Under English data protection law, and under the EU GDPR, you have rights including:
Please contact us if you wish to make a request. In order to verify the identity of those who make a request to us, we will often request proof of ID and we typically accept:
How to complain
You can also complain to the ICO if you are unhappy with how we have used your data.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire
SK9 5AF
Helpline number: 0303 123 1113