About this notice
Last updated: 20/10/20
This website (Babble.work) is owned and operated by Premier Employment Solutions Ltd (“PES”).
We respect and value the privacy of everyone who visits this website and its subdomains, babble.work (“Our Site”), and will only collect and use personal data in ways that are described here, and in a manner that is consistent with Our obligations and your rights under the law.
In this policy ‘PES’, ‘We’, ‘Us’, ‘Our’ means Premier Employer Solutions Limited, company number 4316451, registered office Unit 1 Pinkers Court, Briarlands Office Park, Rudgeway, Bristol, BS35 3QH.
For the purposes of applicable data protection laws, for the purposes we are processing personal data we act in the following ways
Visitors to Our Site and Creating an account – we act as a data controller in the collection and processing of personal data outlined below for providing our services.
Receiving a tailored email from us as part of your employer’s wellbeing campaign – If your employer has signed up to our Insights or a bespoke package, we may process employee personal data to enable us to create a tailored package, for this purpose we act as a Data Processor under contract by your employer, the Data Controller.
by email at firstname.lastname@example.org; by telephone on 01454 808658, or by post at Unit 1 Pinkers Court, Briarlands Office Park, Rudgeway, Bristol, BS35 3QH, UK.
What does this policy cover?
It relates to personal data which means any and all data that relates to an identifiable person who can be directly or indirectly identified from that data. In this case, it means personal data provided to us by you, or your employer give to Us via Our Site. This definition shall, where applicable, incorporate the definitions provided in the EU Regulation 2016/679 – the General Data Protection Regulation (“GDPR”).
Our Site may contain links to other websites. Please note that We have no control over how your data is collected, stored, or used by other websites and We advise you to check the privacy policies of any such websites before providing any data to them.
You have the following rights under the Data Protection Act 2018 / GDPR, which this Policy and Our use of personal data have been designed to uphold:
- The right to be informed about Our collection and use of personal data;
- The right of access to the personal data We hold about you (see How can you access your data ?);
- The right to rectification if any personal data We hold about you is inaccurate or incomplete (please contact Us using the details below);
- The right to be forgotten – i.e. the right to ask Us to delete any personal data We hold about you (We only hold your personal data for a limited time, as explained in section but if you would like Us to delete it sooner, please contact Us using the details below);
- The right to restrict (i.e. prevent) the processing of your personal data;
- The right to data portability (obtaining a copy of your personal data to re-use with another service or organisation);
- The right to object to Us using your personal data for particular purposes; and
- Rights with respect to automated decision making and profiling.
If you have any cause for complaint about Our use of your personal data, please contact Us using the details provided in the section below and We will do Our best to solve the problem for you. We may need to refer you to your HR department or relevant data protection contacts within your organisation if it relates to something outside of our control.
If We are unable to help, you also have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office.
For further information about your rights, please contact the Information Commissioner’s Office or your local Citizens Advice Bureau.
What data do we collect ?
This Site collects personal data provided to us by you so that we can operate our Site. This data may include some or all of the following personal data dependent on the service you have chosen:
- Contact Details (including Firstname, Lastname, Email address, Job title)
- Payment Details (including Payment Card number, Card Expiration, CVV, Cardholder Address, Cardholder Postcode)
- Employee Contact Details, in the event you subscribe to our Insights or Bespoke package, we may process basic employee contact data for providing bespoke communications. Contact details include Employee first name, Last name and Email address.
Depending upon your use of Our Site, We may also collect some or all of the following personal data from you to provide employee benefits that you have requested:
- IP address
- Web browser type and version
- Operating system
How do we use your data?
All personal data is processed and stored securely, for no longer than is necessary in light of the reason(s) for which it was first collected. We will comply with Our obligations and safeguard your rights under the GDPR at all times. More details on security are provided below.
Our use of your personal data will always have a lawful basis, which is performance of a contract. We may use your data for the following purposes:
- When you create an account or subscribe to one of our packages as a company, we will use the information provided to setup and administer your account on Our Site.
- Emailing you with regular insights and updates regarding Our Site including new content, events, surveys and news.
- If applicable, emailing employee communications to you about your employer’s bespoke wellbeing plan and regular updates and news.
- Replying to enquiries from you.
- Analysing your use of Our Site and gathering anonymous feedback to enable Us to continually improve Our Site and your user experience.
You have the right to object to Us using your personal data at any time, and to request that We delete it, unless overriding legal obligations prevent us from doing so.
If you are the account holder with babble.work, you can make this request directly to us by emailing email@example.com. Alternatively, if you are an employee of an account holder you should make this request to your employers HR department or relevant data protection contact as the Data Controller for your personal data. Please be aware that by objecting you will not be able to access the resources of Our Site, or receive information relating to your employer’s bespoke campaign.
You may unsubscribe or opt-out of employee communications from Us at any time by using the unsubscribe link in our emails. Please note opt out will not affect informational emails sent out by the Site relating to your account or subscription.
How long and where do we store your data ?
We only keep your personal data for as long as We need to in order to use it as described above, and/or for as long as We have your permission to keep it.
Your Data will therefore be retained for the following periods:
- Details relating to your account, including payment subscription and transaction details will be kept for 6+ current year, as required under legal obligation.
- Employee contact details provided as part of an Insights or Bespoke package will be retained for the duration of the subscription. In the event the subscription is terminated, employee details will be deleted after 1month of subscription termination.
- Your data is stored on PES company servers in their offices in Rudgeway, UK and in the data centre operating the Site.
- Our email marketing data processor Mailchimp is located in the USA. Your first name, last name and email address is stored in their service. Mailchimp maintains Standard Contractual Clauses for transfers of personal data outside of the EEA. To find out more about their security visit https://mailchimp.com/about/security/
- Where We do store data outside the EEA, We will take all reasonable steps to ensure that your data is treated as safely and securely as it would be within the UK and under the GDPR e.g. by ensuring our data processors have adequate data protection mechanisms in place such Standard Contractual Clauses, Binding Corporate Rules.
- You are deemed to accept and agree to this by using Our Site and submitting information to Us.
Data security is very important to Us, and to protect your data We have taken suitable measures to safeguard and secure data collected through Our Site.
Steps We take to secure and protect your data include, but are not limited to:
- Your personal data is only accessible to PES employees, contractors, agency staff that need to access it to do their jobs. All PES staff are bound by a confidentiality agreement.
- PES is IASME Gold Certified. More details about IASME Certification can be found here: https://www.iasme.co.uk/audited-iasme-governance/
- Our Site uses an SSL certificate to ensure a secure connection when users login and data is uploaded.
- All user passwords must be strong and must be a minimum of 8 characters, include at least 1 uppercase, lower case, number and special character.
- Failed login attempts are limited to 4 before the account is locked out for 24hours.
- Vulnerability tests are conducted on PES’ company network at six-month intervals.
- Data is backed up daily and a copy stored off Site. All backup data is stored in the UK. Please see “How long and Where Do We Store Your Data?” for more information.
We carrying out security vetting of our benefit providers and sub processors to ensure that your personal data is handled in line with GDPR.
Do we share your data ?
We may share your data with other companies in Our group to provide you with services you have expressed an interest in and answer your queries. This includes PES Health Limited and PES Financial Services Limited.
We do not share your data with any other third parties.
In certain circumstances, We may be legally required to share certain data held by Us, which may include your personal data, for example, where We are involved in legal proceedings, where We are complying with legal obligations, a court order, or a governmental authority.
We may compile statistics about the use of Our Site including data on traffic, usage patterns, user numbers, and other information. All such data will be anonymised and will not include any personally identifying data, or any anonymised data that can be combined with other data and used to identify you. We may from time to time share such data with third parties such as prospective investors, affiliates, partners. Data will only be shared and used within the bounds of the law.
What happens if our business changes hands ?
In the event that any of your data is to be transferred in such a manner, you will be contacted in advance and informed of the changes.
How can you control your data ?
In addition to your rights under the GDPR, set out above, when you submit personal data via Our Site, you may be given options to restrict Our use of your data. In particular, We aim to give you strong controls on Our use of your data for employee communications purposes (including the ability to opt-out of receiving emails from Us which you may do by unsubscribing using the links provided in Our emails.
Your right to withhold information
To use all features and functions available on Our Site you may be required to submit or allow for the collection of certain data e.g. payment details. Withholding this information will mean that you are unable to subscribe to our services or use the Site outside of it’s free account.
How can you access your data ?
You have the right to ask for a copy of any of your personal data held by Us. If you are the account holder with babble.work, you can make this request directly to us by emailing firstname.lastname@example.org. Alternatively, if you are an employee of an account holder you should make this request to your employers HR department or relevant data protection contact as the Data Controller for your personal data. We will provide any and all information in response to your request free of charge and within 30 days. You can contact us using the contact details below.
How can you correct your data ?
You have a right to request that your personal data is updated if it is incorrect. If information we hold about you is incorrect. If you are the account holder with babble.work, you can make this request directly to us by emailing email@example.com. Alternatively if you are an employee of an account holder you should make this request to your employers HR department or relevant data protection contact as the Data Controller for your personal data, who will provide this updated information to us in their next data upload.
by email at firstname.lastname@example.org
by telephone on 01454 808658, or
by post at Unit 1 Pinkers Court, Briarlands Office Park, Rudgeway, Bristol, BS35 3QH. UK.
Please ensure that your query is clear, particularly if it is a request for information about the data We hold about you.