Privacy Policy
Introduction
Neyo is committed to protecting the privacy and security of personal data. This Privacy Policy explains how we collect, use, store, and share personal data in accordance with UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By interacting with us, you consent to the practices described in this policy.
Who We Are
Neyo (registered address: 20-22, Wenlock Road, London, N1 7GU) is the data controller responsible for processing your personal data. If you have any questions about this policy or your rights under it, please contact our Data Protection Officer (DPO) at +447591043661.
What Data We Collect
We collect and process personal data relevant to our business operations and to provide services to our clients. The types of personal data we collect may include:
1. Personal Identifiers: Name, address, email address, phone number, date of birth, gender.
2. Financial Information: Payment card details, bank account information.
3. Employment Data: Job title, employer, employment history (if applicable).
4. Technical Data: IP address, browser type, device information, and data obtained from cookies or similar technologies.
5. Communications: Emails, phone calls, and other records of communications with us.
6. Special Category Data: If necessary, with explicit consent, we may process sensitive personal data, such as health information or data revealing racial orethnic origin.
How We Collect Your Data
We collect personal data from various sources, including:
1. Direct Interactions: When you provide information by filling in forms, contacting us, or subscribing to our services.
2. Automated Technologies: As you interact with our website, we may automatically collect technical data about your equipment, browsing actions, and usage patterns using cookies and similar technologies.
3. Third Parties: We may receive personal data from third parties, such as credit reference agencies, publicly available sources, or business partners.
How We Use Your Data
Neyo processes personal data for the following purposes:
1. To Provide Our Services: We process your personal data to provide the services you have requested, such as managing your account or fulfilling contractual obligations.
2. To Improve Our Services: We use data analytics to monitor and improve our website, services, and customer experience.
3. To Communicate with You: We use your contact information to communicate with you about our services, provide updates, and respond to inquiries.
4. To Comply with Legal Obligations: We may process your personal data to meet legal or regulatory requirements, such as financial reporting and compliance with anti-money laundering regulations.
5. For Marketing: With your consent, we may send you promotional materials about our products and services. You can opt out of receiving these communications at any time.
Lawful Bases for Processing
We process personal data only when there is a lawful basis to do so under UK GDPR, which includes:
1. Consent: You have given us clear consent to process your data for a specific purpose.
2. Contractual Necessity: Processing is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into a contract.
3. Legal Obligation: Processing is necessary for compliance with a legal obligation.
4. Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided your rights and interests are not overridden.
How We Share Your Data
We may share your personal data with the following categories of recipients:
1. Service Providers: Third-party service providers who assist us in delivering our services, such as IT support, payment processors, or marketing services. We require these providers to handle your data securely and only for the purposes for which we have instructed them.
2. Legal Authorities: If required by law or regulation, we may disclose your personal data to law enforcement agencies, courts, regulators, or government bodies.
3. Business Transfers: In the event of a merger, sale, or reorganization of Neyo, personal data may be transferred as part of the business assets.
International Data Transfers
We may transfer your personal data outside the UK if required for the performance of services. Where data is transferred to countries not deemed to provide adequate protection, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs).
Data Security
We take appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. These measures include:
1. Encryption: Personal data is encrypted in transit and at rest.
2. Access Controls: Access to personal data is restricted to authorized personnel only.
3. Regular Security Audits: We conduct regular audits and assessments to ensure the effectiveness of our security measures.
Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, or reporting requirements. When your data is no longer needed, we will securely delete or anonymize it. Specific retention periods are outlined in our Data Retention Policy.
Your Data Protection Rights
You have the following rights regarding your personal data under the UK GDPR:
1. Right to Access: You can request a copy of the personal data we hold about you.
2. Right to Rectification: You can request corrections to inaccurate or incomplete data.
3. Right to Erasure: You can request that we delete your personal data where there is no legal reason for us to continue processing it.
4. Right to Restrict Processing: You can request that we limit the processing of your personal data in certain circumstances.
5. Right to Data Portability: You can request the transfer of your personal data to another organization.
6. Right to Object: You can object to our processing of your personal data where we are relying on legitimate interests or for direct marketing purposes.
7. Right to Withdraw Consent: Where we rely on your consent to process your data, you can withdraw it at any time.
To exercise any of these rights, please contact our Data Protection Officer at +447591043661.
Cookies
Our website uses cookies and similar technologies to enhance your browsing experience and provide relevant content. For more information, please see our Cookie Policy.
Complaints
If you have any concerns about how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s data protection authority:
1. Website: https://ico.org.uk/
2. Phone: 0303 123 1113
Communication and Engagement
This policy will be communicated to all employees, contractors, and suppliers. If requested we can this policy available to clients and stakeholders via our website and other communication channels.
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our data processing practices. Any changes will be posted on our website, and where appropriate, we will notify you by email.
All questions, concerns, and other feedback relating to this policy should be communicated to HR Department (hr@neyoltd.com).
Implementation of Policy
This policy shall be deemed effective as of 10/09/2024. No part of this Policy shall have retroactive effect and shall thus apply only to matter occurring on or after this date.
This Policy has been approved and authorised by
Name: Chirag Karnik
Position: Director, Neyo Ltd
Date: 10/09/2024
Due for Review: 10/09/2025
Signature: 
Document Control
Version | Date | Summary Change | Owner |
1.0 | 10/09/2024 | Initial draft created an signed off and added to Internal Sharepoint | Chirag Karnik |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
