Privacy Policy

Web Privacy Statement

 

This privacy statement is for individuals who use the CM website or who contact CM via the contact form on CM’s website. If you are a client of CM you will have received a separate privacy statement.

 

CM or ‘we’ includes the three Isle of Man registered entities CM Trust Limited, CM Partners Limited and CM Associates LLC.

 

 

  1. We are committed to protecting your privacy

 

This notice will tell you how we look after your personal data, will tell you about your privacy rights, and about our compliance with and your protections under Data Protection Legislation.

 

In this notice “Data Protection Legislation” means the Data Protection Act 2018 and any other laws and regulations in the Isle of Man applicable to the processing of personal data.

 

For the purpose of the Data Protection Legislation and this notice, CM Trust Limited, CM Partners Limited and CM Associates LLC are all registered Data Controllers and will be Joint Controllers of your data. This means any information you submit via the contact form, or to an email address via the website, will be jointly held by the three entities while it is being processed. This also means that we are responsible for deciding how we hold and use personal data about you. We are required under the Data Protection Legislation to notify you of the information contained in this privacy notice.

 

We endeavour to ensure that this notice is up to date with current legislation, therefore, it may change from time to time. By using our website or engaging our services you agree to be bound by this policy.

 

 

  1. How secure is your data?

 

We have put in place commercially reasonable and appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

 

We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.

 

Any information you send over the internet is open to interception and can never be guaranteed to be 100% secure. Any information you therefore transmit to us by email is at your own risk. Once we receive your information, we make our best effort to ensure its security on our systems is in accordance with our internal procedures.

 

 

  1. Who has access to your information?

 

Communication between us is confidential and we shall take all reasonable steps to keep confidential your information except where we are required to disclose it to third parties by law, by regulatory bodies, by our insurers or as part of an external peer review. Unless we are authorised by you to disclose information on your behalf, this undertaking will apply during and after our engagement.

 

“Third parties” includes third-party service providers. We engage third parties to provide, amongst other services, IT support, statutory maintenance software and an employee database. The security of any information available to such third parties is covered in a contract between us.

 

 

  1. Rights of Access, Correction, Erasure, and Restriction

 

Under certain circumstances, by law you have the right to:

 

  • Request access to your personal data. This enables you to receive details of the personal data we hold about you and to check that we are processing it lawfully.

 

  • Request correction of the personal data that we hold about you.

 

  • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have exercised your right to object to processing (see below).

 

  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this basis.

 

  • Request the restriction of processing of your personal data. This enables you to ask us to suspend the processing of personal data about you, for example if you want us to establish its accuracy or the reason for processing it.

 

  • Request the transfer of your personal data to you or another data controller if the processing is based on consent, carried out by automated means and this is technically feasible.

 

If you want to exercise any of the above rights, please contact our Data Protection Officer.

 

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee for the administrative costs of complying with the request if your request for access is manifestly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

 

 

  1. What data do you collect from website usage?

 

We do not log IP addresses of users for any purpose, and if in the future we decide to, it will only be used to provide statistical information. IP addresses indicate the location of a user’s computer on the internet; however, it should be noted that individuals cannot be identified from such information.

 

You will never need to provide personal information to access this website and it will not be requested from you except through our contact form. The information you provide is not recorded through the website, and once obtained through our contact form, is held securely and only accessible by authorised personnel. If you choose to contact us via an email address from the website the information contained in the email you send will be held securely and will only be accessible by authorised personnel.

 

We do not use cookies. A cookie is a small file which asks permission to be placed on your computer’s hard drive and allows a website to store a small file of information, analyse web traffic, and respond to you as an individual by monitoring your likes and dislikes.

 

 

  1. What data do we collect from you directly?

 

 

If you make contact with us via our website contact form, an email address or submit a CV via our recruitment page, we will hold contact and CV information for you as well as relevant correspondence, and will use the information you have provided to make contact with you in response to your request.

 

As part of our client take on procedures we screen potential clients against appropriate screening software including, but not restricted to, World-Check and internet searches of publicly available resources. We do not use automated decision making or profiling tools.

 

 

  1. How is your information used?

 

We will use your contact information to get in touch with you in response to your enquiry. We may process your personal data for purposes necessary for the performance of our contract with you or contemplated contract with you and to comply with our legal obligations.

 

We may use your personal data in order to:

 

  • carry out our obligations arising from any agreements entered into between you and us (which will most usually be for the provision of our services);

 

  • provide you with information related to our services and our events or seek your thoughts;

 

 

Please note that we may process your personal data for more than one lawful basis depending on the specific purpose for which we are using your data. We may also process your personal data without your knowledge or consent, in accordance with this notice, where we are legally required or permitted to do so.

 

 

 

  1. Do we use your information for marketing purposes?

 

We do not share your information with third parties for marketing purposes.

 

 

  1. How long do you retain my personal data?

 

We will only retain your personal data for as long as is necessary to fulfil the purposes for which it is collected.

 

When assessing what retention period is appropriate for your personal data, we take into consideration the requirements of our business and the services provided, any statutory or legal obligations and the purposes for which we originally collected the personal data.

 

We will arrange for client data to be disposed of via secure means once the retention period has expired.

 

 

  1. Change of Purpose

 

Where we need to use your personal data for a reason, other than the purpose for which we originally collected it, we will only use your personal data where that reason is compatible with the original purpose. If we need to use your data for a new purpose we will notify you and communicate our legal basis for this new processing.

 

 

  1. Transferring Data Outside of the Isle of Man

 

We may transfer personal data we collect about you outside of the Isle of Man when required to do so in the course of business or to otherwise comply with the law.

 

 

  1. How do you make a complaint?

 

If you have a complaint regarding our use of your personal data you should contact the Data Protection Officer or you may go direct to the Isle of Man Information Commissioner whose details can be found at www.inforights.im