We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Where we need the personal data to perform the contract we are about to enter into or have entered into with you.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal or regulatory obligation.
Generally we do not rely on consent as a legal basis for processing your personal data other than in relation to sending direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting us.
Purposes for which we will use your personal data
We have set out below, in a table format, a description of all the ways we plan to use your personal data, the sources of your personal data and which of the legal bases we rely on to process your personal data. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.
|
Purpose/Activity
|
Source
|
Type of data
|
Lawful basis for processing including basis of legitimate interest
|
|
To register you as a new client.
|
Directly
Third parties
|
- (a)Identity;
- (b)Contact.
|
- (a)Performance of a contract with you;
- (b)Necessary to comply with a legal obligation.
|
|
To process and deliver the professional services that you engage us to provide:
- Manage payments, fees and charges;
- Collect and recover money owed to us.
|
Direct
Third Parties
|
- Identity;
- Contact;
- Payment;
- Transaction.
.
|
- Performance of a contract with you;
- Necessary for our legitimate interests (to recover debts due to us).
|
|
To manage our relationship with you which will include:
- Notifying you about changes to our terms or privacy policy;
- Asking you to provide us with feedback.
|
Direct
Third parties
|
- Identity;
- Contact;
- Marketing and Communications.
|
- Performance of a contract with you;
- Necessary to comply with a legal obligation;
- Necessary for our legitimate Interests (to keep our records updated and to study how customers use our products/services).
|
|
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data).
|
Direct
Automatically
Third Parties
|
- (a)Identity;
- (b)Contact;
- (c)Technical;
- (d)Usage
|
- Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise);
- Necessary to comply with a legal obligation.
|
|
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you
|
Direct
Automatically
Third Parties
|
- Identity
- Contact
- Usage
- Marketing and Communications
- Technical
|
Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)
|
|
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences
|
Automatically
|
- (a)Technical
- (b)Usage
|
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
|
|
To make suggestions and recommendations to you about our other services that may be of interest to you
|
Direct
Automatically
Third Parties
|
- (a)Identity
- (b)Contact
- (c)Technical
- (d)Usage
|
Necessary for our legitimate interests (to develop our products/services and grow our business)
|
|
To provide necessary data to Governmental and other regulatory authorities.
|
Direct
Automatically
Third Parties
|
- (a)Identity
- (b)Contact
- (c)Payment
- (d)Financial
- (e)Transactional
|
- Performance of a contract with you;
- Necessary to comply with a legal obligation, including reporting obligations to HMRC;
|
|
To provide necessary information to financial institutions
|
Direct
Automatically
Third Parties
|
- (a)Identity
- (b)Contact
- (c)Payment
- (d)Financial
- (e)Transactional
|
- Performance of a contract with you;
- Necessary to comply with a legal obligation;
(c) Necessary for our legitimate interests to comply with regulatory obligations such as the reporting of financial data for financing, regulatory and compliance reasons.
|
|
To provide necessary information to other authorised and instructed professionals, including our lawyers and other regulatory bodies.
|
Direct
Automatically
Third Parties
|
- (a)Identity
- (b)Contact
(C) Technical
- (d)Payment
- (e)Financial
- Transactional
|
- Performance of a contract with you;
- Necessary to comply with a legal obligation;
(c) Necessary for our legitimate interests to comply with regulatory obligations such as the reporting of financial data for financing, regulatory and compliance reasons relating to CAA and ATOL reporting, or to seek legal advice or to seek legal or other professional advice.
|
Marketing
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
We have set out below the various mechanisms by which we strive to provide you with choices around how we use your personal data, particularly for marketing and advertising purposes. You can also contact our DPO at any time to discuss this further (dataprotectionofficer@whitehartassociates.com).
Promotional offers from us
We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which professional services and offers may be relevant for you (we call this marketing).
Third-party marketing
We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
Opting Out
You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time (dataprotectionofficer@whitehartassociates.com).
Where you opt out of receiving these marketing messages, this will not apply to personal data that you have provided to us as a result of an engagement to provide you with professional services or other such transactions.
Cookies
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see https://whitehartassociates.com/terms-and-conditions/.
Change of purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
‘return to top link’