Data Protection Policy
1. Purpose
Southwood Infrastructure Partners LTD. ("Southwood") is committed to protecting personal data and respecting the privacy rights of all individuals.
This policy explains how we collect, use, store, process and protect personal information in accordance with:
-
UK General Data Protection Regulation (UK GDPR)
-
Data Protection Act 2018
-
Privacy and Electronic Communications Regulations (PECR), where applicable
This policy applies to all directors, employees, contractors, consultants and third-party service providers acting on behalf of Southwood.
2. Principles of Data Protection
Southwood processes personal data in accordance with the UK GDPR principles.
Personal data will be:
-
processed lawfully, fairly and transparently
-
collected for specified and legitimate purposes
-
limited to what is necessary
-
accurate and kept up to date
-
retained only for as long as necessary
-
processed securely using appropriate technical and organisational measures
-
processed in a manner that demonstrates accountability
3. Types of Personal Data
Southwood may process personal data including:
-
Name
-
Company
-
Job title
-
Business address
-
Email address
-
Telephone number
-
Project information
-
Supplier information
-
Contract records
-
Procurement information
-
Website enquiries
Southwood does not intentionally collect special category personal data unless required by law or contractual obligations.
4. Lawful Basis for Processing
Personal data is processed under one or more of the following lawful bases:
-
Performance of a contract
-
Compliance with legal obligations
-
Legitimate business interests
-
Consent (where required)
-
Protection of vital interests
5. Confidentiality, Integrity and Availability
Southwood maintains appropriate technical and organisational measures to ensure ongoing confidentiality, integrity, availability and resilience of processing systems.
These measures include:
-
Microsoft 365 secure cloud services
-
Password protected systems
-
Multi-factor authentication (MFA)
-
Role-based access control
-
Secure encrypted communications
-
Regular software updates
-
Anti-virus and endpoint protection
-
Firewall protection
-
Device encryption where applicable
-
Secure document storage
-
Controlled access to company information
-
Backup and recovery procedures
Only authorised personnel are permitted to access personal data.
6. Data Subject Rights
Southwood respects all rights granted under UK GDPR.
Individuals may request:
-
access to personal data
-
correction of inaccurate data
-
deletion of personal data
-
restriction of processing
-
objection to processing
-
data portability
-
withdrawal of consent (where consent is the lawful basis)
Requests will normally be responded to within one calendar month.
Requests may be submitted to Email: info@southwoodinfra.com
7. Privacy Information
Whenever Southwood collects personal information, individuals will receive clear privacy information explaining:
-
what information is collected
-
why it is collected
-
the lawful basis
-
retention periods
-
who data may be shared with
-
individual rights
-
how to make a complaint
Privacy notices are available on our website.
8. Consent Management
Southwood ensures that consent is:
-
freely given
-
specific
-
informed
-
unambiguous
-
actively provided
Consent records are securely maintained and are auditable.
Individuals may withdraw consent at any time.
9. International Data Transfers
Southwood primarily processes data within the United Kingdom.
Where personal data is transferred outside the UK, appropriate safeguards will be implemented, including where applicable:
-
UK International Data Transfer Agreement (IDTA)
-
UK Addendum to the EU Standard Contractual Clauses
-
Adequacy Regulations approved by the UK Government
International transfers will only occur where lawful and appropriate protections are in place.
10. Records of Processing Activities
Southwood maintains records of processing activities including:
-
categories of personal data
-
purposes of processing
-
lawful basis
-
recipients
-
retention periods
-
security measures
-
international transfers where applicable
These records are reviewed regularly.
11. Data Retention
Personal data is retained only for as long as necessary to fulfil:
-
contractual obligations
-
legal requirements
-
regulatory requirements
-
legitimate business purposes
When no longer required, personal data is securely deleted or anonymised.
12. Personal Data Breaches
Southwood maintains procedures for identifying, reporting and managing personal data breaches.
Where required under UK GDPR:
-
breaches will be investigated promptly
-
affected individuals will be informed where necessary
-
the Information Commissioner's Office (ICO) will be notified within statutory time limits
Lessons learned from incidents will be incorporated into continuous improvement.
13. Monitoring and Testing
Southwood regularly reviews and evaluates the effectiveness of its data protection controls.
This includes:
-
periodic policy reviews
-
access permission reviews
-
software update monitoring
-
cybersecurity assessments
-
backup testing
-
staff awareness
-
supplier assessments where appropriate
Continuous improvement is an integral part of our information governance framework.
14. Training and Awareness
Personnel handling personal data receive appropriate awareness and guidance regarding:
-
UK GDPR requirements
-
confidentiality
-
secure handling of information
-
cyber security
-
phishing awareness
-
incident reporting
15. Responsibilities
The Director is responsible for:
-
overseeing compliance with UK GDPR
-
approving this policy
-
ensuring appropriate resources are available
-
reviewing compliance arrangements
All personnel are responsible for protecting personal data and complying with this policy.
16. Contact
For questions regarding this policy or personal data processing:
Southwood Infrastructure Partners LTD.
Email: info@southwoodinfra.com
Website:www.southwoodinfra.com
