Skip to main content

Privacy Notice

This privacy notice tells you what to expect us to do with your personal information. The information provided is applicable where CMP is acting in the role of Data Controller. 

The majority of the work carried out by CMP is in the role of Data Processor, where CMP is carrying out processing of data on behalf of a client. The basis for this processing is contractual requirement.  

Data Controller: “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Controllers make decisions about processing activities. They exercise overall control of the personal data being processed and are ultimately in charge of and responsible for the processing.” – as defined by the Information Commissioner’s Office 

Data Processor: “the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. Processors act on behalf of the relevant controller and under their authority. In doing so, they serve the controller’s interests rather than their own. Although a processor may make its own day-to-day operational decisions, Article 29 says it should only process personal data in line with a controller’s instructions, unless it is required to do otherwise by law.” – as defined by the Information Commissioner’s Office 

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/controllers-and-processors/controllers-and-processors/what-are-controllers-and-processors/

Where CMP is acting in the role of Data Processor they shall commit to ensure that the data is processed in accordance with both their legal and contractual obligations and meet, as a minimum, the same principles set out within this notice. 

Please note where CMP is acting in the role of Data Processor any complaints, queries and subject access requests should be directed to the relevant Data Controller. CMP shall assist the Data Controller in any response when required and instructed to by the Data Controller. 

Contact details 

CMP has an Information Security Team who are responsible for managing and maintaining Information Security within the organisation. They can be contacted at: 

[email protected]  

What information we collect, use, and why 

We collect or use the following information to meet contractual requirements. The data we collect is used expressly for the purposes specified within our contractual agreements with the client. The data is required for the following purposes: 

  • Administration of Customer or client accounts and records 
  • Performance of contractual agreements including, but not limited to, providing training, investigation, mediation and assessment services 
  • Evaluation of the services performed, in the form of surveys, where consent is given by the data subject 
  • Marketing, where consent is given 

Lawful bases 

Our lawful basis for collecting or using personal information for the purposes listed above is: 

  • Contract 

Where we get personal information from 

  • People directly 
  • Clients acting in the role of Data Controller 
  • Google & website analytics 

How long we keep information 

We will hold on to your information for the time periods detailed below: 

Information relating to investigation cases  120 days from the date the case was closed; or until the timescale specified by the Data Controller 
Information relating to mediation cases  12 months from the date the case was closed; or until the timescale specified by the Data Controller 
Information relating to consultancy & coaching activities  12 months from the date the case was closed; or until the timescale specified by the Data Controller 
Information relating to neutral assessments  12 months from the date the case was closed; or until the timescale specified by the Data Controller 
Client company data required for administration purposes (i.e. not case work involving personal data)  6 years from the date the client contract ends; or until the timescale specified by the Data Controller 
Information relating to training services  6 years from certification / completion of training; or until the timescale specified by the Data Controller 
General email communications  3 years from receipt of email 
Visitor logs  1 year from date of visit 
Commercial Survey responses  6 years from date of survey 
Marketing details for commercial prospects  Until consent is withdrawn 

Who we share information with 

CMP employs the use of the following Data Processors for the purposes of supplying cloud-based SaaS solutions to manage and store client data: 

  • Microsoft, including Outlook, SharePoint, Office, C-Pilot, Teams 
  • Salesforce 
  • Click-up 
  • ILM Walled Garden 
  • Outsec 
  • Xero 

 

CMP employs the use of the following Data Processors for the purposes of managing surveys to evaluate performance of services to clients and data subjects, when consent is given: 

  • Alchemer 

 CMP employs the use of the following Data Processors for the purposes of marketing to commercial prospects, when consent is given: 

  • Salesforce 
  • Pardot 
  • Mail Chimp 
  • Google Ads 
  • Score App 

Your data protection rights 

Under data protection law, you have rights including: 

Your right of access - You have the right to ask us for copies of your personal data. 

Your right to rectification - You have the right to ask us to rectify personal data you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. 

Your right to erasure - You have the right to ask us to erase your personal data in certain circumstances. 

Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal data in certain circumstances. 

Your right to object to processing - You have the right to object to the processing of your personal data in certain circumstances. 

Your right to data portability - You have the right to ask that we transfer the personal data you gave us to another organisation, or to you, in certain circumstances. 

Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent. 

You don’t usually need to pay a fee to exercise your rights. If you make a request, we have one calendar month to respond to you. 

To make a data protection rights request where CMP is the Data Controller, please contact us using the contact details at the top of this privacy notice. 

To make a data protection rights request where CMP is the Data Processor, please contact the Data Controller directly using the contact details provided within their Privacy Notice. 

How to complain 

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice. 

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO. 

The ICO’s address:            

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF 

Helpline number: 0303 123 1113 

Website: https://www.ico.org.uk/make-a-complaint 

Policy Compliance  

Compliance Measurement 

The Information Security Steering Group will verify compliance to this policy through various methods, including but not limited to, business tool reports, internal and external audits, and feedback to the policy owner.  

Exceptions 

Any exception to the policy must be approved and recorded by the Information Security Team in advance and reported to the Senior Leadership Team.  

Non-Compliance 

An employee, associate or other third-party contractor found to have violated this policy may be subject to disciplinary action or contractual review, up to and including termination of employment/contract. 

Continual Improvement 

The policy is updated and reviewed as part of the continual improvement process.