• Skip to main content
  • Skip to primary sidebar
  • What we do
  • Who we are
  • Contact
  • Book an enquiry

Form & Function Digital Co-operative

We partner with third-sector organisations to create engaging and inclusive online experiences.

Privacy Information Notice

This Privacy Information Notice was last updated on 28th September 2020.

Who we are

We are Form & Function Digital Co-operative Ltd. Company number SC625583 registered in Scotland at The Melting Pot, 5 Rose Street, Edinburgh EH2 2PR.

We’re committed to protecting and respecting your data privacy.

Note: This Privacy Information Notice relates to Form & Function Digital Co-operative Ltd as Data Controller. If Form & Function Digital Co-operative Ltd is also a Data Processor for your organisation, please read ‘How we process personal data on behalf of clients’.

Collection, processing and storage of personal data

Form & Function Digital Co-operative collects, processes and stores personal data in order to carry out and promote our business of providing consultancy, website design & development, and hosting, maintenance and technical support services to our clients.

This Privacy Information Notice details what personal data we collect, how we collect it, why we collect it, the lawful basis for processing it, where we store it and how long we store it for. The notice also provides information about how to request, modify or delete the personal data we hold through a Subject Access Request (SAR) and how to contact us with any questions about our data protection policies or procedures.

How we collect personal data

Contact form

What we collect

  • Name
  • Email address
  • Phone number
  • Company/organisation
  • IP address

Why we collect it

  • To respond to enquiries

Lawful basis for processing

  • Consent

Where we store it

  • UK based secure server (our website)
  • Google (GSuite)
  • Hubspot CRM
  • Local drives and backups

Third party processors/ International data sharing

  • Flywheel
  • Google (GSuite)
  • Hubspot

Newsletter sign-up form

What we collect

  • Name
  • Organisation
  • Email address

Why we collect it 

  • To send updates and other information about our services

Lawful basis for processing

  • Consent

Where we store it

  • UK based secure server (our website)
  • Google (GSuite)
  • Mailchimp

Third party sharing/ International data sharing

  • Flywheel – a US-based company who host our website
  • Mailchimp – a US-based email marketing service

Email

What we collect

  • Name
  • Email address
  • Phone number
  • Company/organisation
  • Job title
  • Company/organisation Address
  • Other information (eg CVs, internship requests)

Why we collect it

  • To send and respond to communications

Lawful basis for processing

  • Performance of contract/ Legitimate interest

Where we store it

  • Google (GSuite)

Third party sharing/ International data sharing

  • Google (GSuite)

Client Record Management (CRM)

What we collect

  • Name
  • Email address
  • Phone number
  • Company/organisation
  • Job title
  • Company/organisation Address

Why we collect it

  • To send and track communications

Lawful basis for processing

  • Performance of contract/ Legitimate interest

Where we store it

  • Hubspot

Third party sharing/ International data sharing

  • Hubspot

Project management

Project management Software (Teamwork Projects)

What we collect

  • Name
  • Email address
  • Phone number
  • Company/organisation
  • Job title
  • Company/organisation Address

Why we collect it

  • To send and respond to communications
  • To manage projects

Lawful basis for processing

  • Performance of contract

Where we store it

  • EU based server (Republic of Ireland)
  • Google (GSuite)

Third party sharing/ International data sharing

  • Teamwork
  • Google (GSuite)

Support desk

What we collect

  • Name
  • Email address
  • Phone number
  • Company/organisation
  • Job title
  • Company/organisation Address

Why we collect it

  • To respond to and manage support requests

Lawful basis for processing

  • Performance of contract

Where we store it

  • EU based server (Republic of Ireland)
  • Google (GSuite)

Third party sharing/ International data sharing

  • Teamwork

Proposal management

What we collect

  • Name
  • Email address
  • Phone number
  • Company/organisation
  • Job title

Why we collect it

  • To prepare and send project proposals

Lawful basis for processing

  • Performance of contract/Legitimate Interest

Where we store it

Third party sharing/ International data sharing

  • Better Proposals

Content Management System User Accounts (WordPress)

What we collect

  • Name
  • Email address

Why we collect it

  • To create user accounts

Lawful basis for processing

  • Performance of contract

Where we store it

  • UK based secure server

Third party sharing/ International data sharing

  • Flywheel
  • Electric Hosting
  • Dreamhost
  • Google (GSuite)

Server logs

What we collect

  • IP address

Why we collect it

  • To perform data security and maintenance tasks
  • To detect and prevent fraud and unauthorised access

Lawful basis for processing

  • Legitimate interest/Performance of contract

Where we store it

  • UK based secure server

Third party sharing/ International data sharing

  • Flywheel

Analytics

What we collect

  • IP address

Why we collect it

  • To monitor and analyse usage on website

Lawful basis for processing

  • Legitimate interest

Where we store it

  • Google

Third party sharing/ International data sharing

  • Google

Accounting software

What we collect

  • Name
  • Email address

Why we collect it

  • To manage invoicing, payments and financial accounting tasks

Lawful basis for processing

  • Performance of contract

Where we store it

  • Xero

Third party sharing/ International data sharing

  • Xero

Cookies

Cookies are small text files that are placed on your computer by websites that you visit. They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site. The information below explains the cookies we use and why.

Universal Analytics (Google)

Cookie: Universal Analytics (Google)

Name: _gat, _ga, _gid

Purpose: 

These cookies are used to collect information about how visitors use our website. We use the information to compile reports and to help us improve the website. The cookies collect information in ananonymous form, including the number of visitors to the website,where visitors have come to the website from and the pages they visited.

Read Google’s overview of privacy and safeguarding data

Universal Analytics (Matomo - formerly Piwik)

Cookie: Universal Analytics (Matomo – formerly Piwik)

Name: pk_ses, pk_id

Purpose: 

These cookies are used to collect information about how visitors use our website. We use the information to compile reports and to help us improve the website. The cookies collect information in anonymous form, including the number of visitors to the website, where visitors have come to the website from and the pages they visited.

How do I change my cookie settings?

Most web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set, visit www.aboutcookies.org or www.allaboutcookies.org.

Find out how to manage cookies on popular browsers:

  • Google Chrome
  • Microsoft Edge
  • Mozilla Firefox
  • Microsoft Internet Explorer
  • Opera
  • Apple Safari

To find information relating to other browsers, visit the browser developer’s website.

To opt out of being tracked by Google Analytics across all websites, visit https://tools.google.com/dlpage/gaoptout.

Special category personal data

We do not collect, process or store any special categories of personal data such as race, ethnic origin, politics, religion, trade union membership, genetics, biometrics (where used for ID purposes), health, sex life or sexual orientation, or criminal offence data (except where necessary to carry out performance of employment contracts – if you are an employee of Form & Function Digital Co-operative please refer to the Employee Privacy Policy for details of how your personal data is collected, processed and stored).

Retention and deletion of personal data

We identify and delete personal data in our possession when it is no longer needed for the performance of our contract with the client organisation, unless we are required to keep it for legal or security reasons.

We are required by UK government regulations to keep certain types of data (eg payroll, accounts and VAT records) for a minimum of 7 years. We also need to keep details of the fulfilment of business contracts for several years after completion of a contract as part of our professional indemnity insurance.

Accordingly, we routinely delete most other data, including emails, in batches after 8-9 years have elapsed. We keep some accounting and archival data indefinitely.

When deleting personal data, we take steps to delete all copies beyond reasonable possibility of restoration, including copies on backups.

Who do we share your personal data with?

Aside from Form & Function Digital Co-operative staff it is sometimes necessary to share your personal data with Third Party Service Providers working on our behalf:

We may pass your information to our third party service providers, agents, subcontractors and other associated organisations for the purposes of completing tasks and providing services to you on our behalf (for example to process payment and send you mailings). However, when we use third party service providers, we disclose only the personal information that is necessary to deliver the service and we have a contract or agreement in place that requires them to keep your information secure and not to use it for their own marketing purposes.

We will not sell or rent your information to third parties.

It may be necessary to share your personal data where there is a legal requirement to do so.

Your legal rights in relation to personal data and how Form & Function Digital Co-operative addresses these

The right to be informed

This privacy policy forms part of your right to be informed about what personal data is collected about you and what is done with that data.

More information on the the right to be informed

The right of access

You may make a subject access request to ask for any personal data that we hold on you. We are obliged to answer your request within 30 days, free of charge. To make a Subject Access Request please complete the form below or email dpo@formandfunction.coop.

More information on the right of access

The right to rectification

You may ask for any data we hold on you that is incorrect to be corrected by us. To make a data rectification request please email dpo@formandfunction.coop.

More information on the right to rectification

The right to erasure

You may ask for personal data about yourself to be removed, subject to other considerations e.g. we are required by law to keep invoice data for at least 6 years. To make a data erasure request please email dpo@formandfunction.coop.

More information ono the right to erasure

The right to restrict processing

You may ask to restrict the processing of you personal data in certain circumstances. To make a request to restrict processing of your personal data please email dpo@graphics.coop.

More information on the right to restrict processing

The right to data portability

The right to data portability gives individuals the right to receive personal data they have provided to a controller in certain circumstances. To make a data portability request please email dpo@graphics.coop.

More information on the right to data portability

The right to object

You can object to your personal data being used for marketing purposes. We do not use data for marketing except with your consent and you are free to change your preferences at any time.

More information on the right to object

Rights in relation to automated decision making and profiling

We do not use automated decision making or undertake profiling with personal data.

More information on rights in relation to automated decision making and profiling

How we protect your personal data

We maintain a high level of physical and electronic security in relation to the collection, storage and disclosure of your information. We take reasonable steps to ensure that any information we hold about you is protected. We use Secure Socket Layer (SSL), which encrypts information given over the internet to protect all personal data.

Internally Form & Function Digital Co-operative utilises password managers so that passwords can be administered securely. We use and enforce strong passwords and where we store data we encrypt it.

What data breach procedures we have in place

We will document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.We will notify the Information Commissioner Office (ICO) no later than 72 hours if the breach is likely to result in a risk to the rights and freedoms of natural persons in accordance with Article 55.

When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, will we communicate the personal data breach to the data subject without undue delay. This communication will describe in clear and plain language the nature of the personal data breach and include:

  1. the name and contact details of the data protection officer or other contact point where more information can be obtained;
  2. describe the likely consequences of the personal data breach;
  3. describe the measures taken or proposed to be taken by us to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

This communication to the data subject is not required if the conditions in Article 34 – 3a), b) or c) – are met.:

  • the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
  • the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise;
  • it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.

What third parties we receive data from

We do not buy or receive personal data from any third parties.

What automated decision making and/or profiling we do with personal data

We do not use automated decision making or undertake profiling with personal data.

Privacy Notice updates

We may change this Policy from time to time so please check this page occasionally to ensure that you’re happy with any changes. By using our website, you’re agreeing to be bound by this Policy.

This Privacy Information Notice was last updated on 10th May 2019.

How to contact us

We are registered with the Information Commissioner’s Office (ICO) in the UK:

Form & Function Digital Co-operative on the ICO register number ZA513969.

If you are unhappy with the way we handle your personal data and we have not been able to resolve it, you have the right to lodge a complaint with the ICO.

Any questions regarding this Policy and our privacy practices should be sent by email to dpo@formandfunction.coop or by writing to Form & Function Digital Co-operative Ltd, The Melting Pot, 5 Rose Street, Edinburgh EH2 2PR..

 

Primary Sidebar

  • Privacy Information Notice
Copyright © 2021 Form & Function Digital Co-operative Ltd · A workers co-operative ·
Registered in Scotland (Company number: SC625583) · Registered under the Data Protection Act (ICO number: ZA513969) ·
Form & Function Digital Co-operative Ltd, The Melting Pot, 5 Rose Street, Edinburgh EH2 2PR