LF code no track

Privacy Notice

    Privacy Policy

    STA International Ltd (‘we’ or ‘us’ or ‘our’) gather and process your personal information in accordance with this privacy notice and in compliance with the relevant data protection Regulation and laws. This notice provides you with the necessary information regarding your rights and our obligations, and explains how, why and when we process your personal data.

    Who We Are

    STA International Ltd registered office is at 3rd Floor, Colman House, King Street, Maidstone ME14 1DN registered in England and Wales under company number 2893487. We are registered on the Information Commissioner’s Office Register, registration number Z7268646. STA International acts as a data controller when processing employees’ and clients’ data.

    You can contact our designated Data Protection Officer, Emanuela Pitzianti, via email at compliance@staonline.com

    Information That We Collect

    STA International Ltd processes your personal information to meet our legal, statutory and contractual obligations. We will never collect any unnecessary personal data from you and do not process your information in any way, other than as specified in this notice.

    Applicants and Employees

    The personal data that we collect is: –

    • Name
    • Date of Birth
    • Home Address
    • Personal Email
    • Home Telephone Number
    • Mobile Telephone Number
    • Special Category Data (eg. health/medical information)
    • Bank Account Details
    • Next of Kin
    • National Insurance Number
    • Passport Number
    • Driver’s License Number
    • DBS Checks/ Criminal records
    • Credit Checks
    • Interview details including CV’s, notes of interviewers, dates and times
    • Candidate’s work history
    • Qualifications and experience relevant to the role
    • Disabilities (for monitoring and adjustments only)
    • References provided by previous employers and personal or educational referees
    • Documents to confirm address such as utility bills, bank statements
    • Details of when you have entered and left the building for safety evacuation purposes

     

    How We Use Your Personal Data

    STA International Ltd takes your privacy very seriously and we never disclose your data without your consent or the data controller’s instructions per the lawful basis stated in this notice; unless required to do so by law. We only retain your data while being processed for the purpose(s) specified in this notice. The purposes and reasons for processing your personal data are as follows: –

    • We collect and store your personal data as part of our legal obligation and for the performance of our contractual obligations.

     

    Consequences of Not Providing Your Data

    You are not obligated to provide your personal information to STA International Ltd; However as this information is required for providing you with information on our services, we will not be able to offer some/all our services without it.

     

    Sharing and Disclosing Your Personal Information

    We do not disclose any of your personal information without your consent, except for the purposes specified in this notice, or when there is a legal requirement. STA International Ltd uses third-parties to provide its daily business functions; however, all processors acting on our behalf only process your data in accordance with instructions from us and comply fully with this privacy notice, the data protection laws, and any other appropriate confidentiality and security measures

     

    How Long We Keep Your Data

    STA International Ltd retains its employees’ personal information indefinitely for employment purposes, to assist in the running of the business, to enable individuals to be paid and to comply with its legal obligations.

    We store any data relating to applicants securely for six months.

     

    Special Categories Data

    STA International Ltd sometimes needs to process sensitive personal information (known as special category data) about you, to meet our legal obligations. Where we collect such information, we will only request and process the minimum necessary for the specified purpose.

    Where we rely on your consent for processing special category data, we will obtain your explicit consent. You can withdraw consent at any time, which we will act on immediately unless there is a legitimate or legal reason for not doing so.

    Cash Management Services

    The personal data that we collect from our clients (data controllers) is: –

    • Name
    • Date of Birth
    • Home Address
    • Personal Email
    • Business Email
    • Home Telephone Number
    • Mobile Telephone Number
    • Financial Information
    • Special Category Data (eg. health/medical information)


    How We Use Your Personal Data

    STA International Ltd takes your privacy very seriously and will never disclose your data without your consent (when required) or without the data controller’s instructions in accordance with the lawful basis stated in this notice; unless required to do so by law. We may act as data controller or data processor depending on our contractual obligations.

    We only retain your data while being processed for the purpose(s) specified in this notice. We detail the purposes and reasons for processing your personal data below: –

    • We collect and process your personal data for debt collection services and in accordance with the lawful basis of the performance of our client’s contract.
    • We securely archive data after your account closure in accordance with the legal basis of legitimate interest and recognise that is in our interest to identify and manage risks to our and our clients’ organization.
    • We also process your information to fulfil our obligations under all laws and regulations based on laws which apply to our business activities.


    Sharing and Disclosing Your Personal Information

    We do not disclose any of your personal information without your consent, other than for the purposes specified in this notice or where there is a legal requirement. STA International Ltd uses third-parties to provide its daily business functions; however, all processors acting on our behalf only process your data in accordance with instructions from us, as agreed with the data controller, and comply fully with this privacy notice, the data protection laws, and any other appropriate confidentiality and security measures.

    Daily Business Functions Processors:
    Firms appointed for further recovery actions in accordance with the lawful basis of “performance of a contract”


    How Long We Keep Your Data

    STA International Ltd only ever retains personal information for as long as we are obliged, under relevant legislation and regulation, or where no such rules apply, for no longer than it is necessary for our lawful purposes. This will be no longer than 6 years after closure of your account after which time it will be anonymized for statistical purposes.

    Archived accounts data is securely stored in the company in house application within a highly secure cloud environment and data centre. This data is not actively processed and information related to all closed files is password protected, accessed by a few Senior Managers and only if and when necessary.


    Special Categories Data

    Owing to the services that we provide, STA International Ltd sometimes needs to process sensitive personal information (known as special category data) about you, only with your consent, to assist you in meeting your contractual obligations. Where we collect such information, we will only request and process the minimum necessary for the specified purpose.

    Where we rely on your consent for processing special category data, we will obtain your explicit consent through a telephone conversation or in writing. You can withdraw consent at any time, which we will act on immediately unless there is a legitimate or legal reason for not doing so.

    Marketing and Cookies

    The personal data that we may collect is: –

    • Name
    • Job Title
    • Business Name
    • Business address
    • Business Email
    • IP Address
    • Turnover


    Cookie Notice

    A ‘cookie’ is a small piece of data sent from a website and stored on the user’s computer by the user’s web browser while the user is browsing. When you visit a site that uses cookies for the first time, a cookie is downloaded onto your computer/mobile device so that the next time you visit that site, your device will remember useful information such as items added in the visited pages or logging in options.

    Cookies are widely used to make websites work or to work more efficiently, and our site relies on cookies to report on user interactions, to optimise users’ experience and for features and services to function correctly.

    When using our website, you have the option to turn off all non-necessary cookies. Most web browsers allow further control to restrict or block cookies through the browser settings. However, if you disable cookies, you may find this affects your ability to use certain parts of our website or services. For more information about cookies visit https://www.aboutcookies.org.

    To view a full list of the cookies we use, what they are used for, or to change your cookie preferences for this site, please click here.


    How We Use Your Personal Data

    STA International Ltd takes your privacy very seriously and will never disclose, share or sell your data without your consent unless required to do so by law. We only retain your data for as long as is necessary and for the purpose(s) specified in this notice. Where you have consented to us providing you with promotional offers and marketing, you are free to withdraw this consent at any time.  We detail the purposes and reasons for processing your personal data below: –

    • We will occasionally send you marketing information where we have assessed that it is beneficial to you as a customer and in our interests. Such information will be non-intrusive and processed on the grounds of legitimate interests.

     

    Legitimate Interests

    As noted in the ‘How We Use Your Personal Data’ section of this notice, we occasionally process your personal information under the legitimate interests’ legal basis. Where this is the case, we have carried out a Legitimate Interests’ Assessment (LIA) to ensure that your interests and any risk posed to you against our interests are proportionate and appropriate.

    Based upon our segmentation by organisation, turnover and specific job function, coupled with our processing of personal data within the context of a business environment, we believe that any individual that receives correspondence from STA International Ltd in direct marketing or a sales capacity could be legitimately interested in our services.  We deem that direct marketing and sales are necessary in the context of promoting our business to professionals to increase awareness of our solution in the marketplace.

     

    Sharing and Disclosing Your Personal Information

    We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this notice, or where there is a legal requirement.

     

    Consequences of Not Providing Your Data

    You are not obligated to provide your personal information to STA International Ltd; however, we need this information to provide you with details of our services, and will not be able to offer some/all our services without it.

     

    How Long We Keep Your Data

    STA International Ltd only ever retains personal information for a maximum period of 6 years and we have strict review and retention policies in place to meet these obligations.

    Your Rights

    You have the right to access any personal information that STA International Ltd processes about you, they are:

     

    Right to be informed

    You have a right to receive clear and easy to understand information on what personal information we have, why and who we share it with – we do this in our privacy notices.

     

    Right of access

    You have the right of access to your personal information. If you wish to receive a copy of the personal information we hold on you, you may make a data subject access request (DSAR). You can download a copy of the DSAR form in either Microsoft Word or printable PDF format. Details on where to return the completed form can be found at the end of the document.

     

    Right to withdraw consent

    If you have given us your consent, you can withdraw that consent at any time. Please contact us if you want to do so. If you withdraw your consent, we may not be able to provide certain services to you. If this is the case, we will tell you.

     

    Right to rectification

    If your personal information is inaccurate or incomplete, you can request that it is corrected.

     

    Right to erasure

    This is also known as “the right to be forgotten” and this means that you can ask us to delete your personal data where it is no longer necessary for us to use it, you have withdrawn consent (where applicable), or where we have no lawful basis for keeping it or otherwise using it. There are limited exceptions, for example where we need to use the information to bring or defend a legal claim.

     

    Right to restrict processing

    You can ask that we block or suppress the processing of your personal information for certain reasons. This means that we are still permitted to keep your information – but only to ensure we don’t use it in the future for those reasons you have restricted.

     

    Right to data portability

    You can ask us to provide you or a third party with some of the personal data that we hold about you in a structured, commonly used, electronic form, so it can be easily transferred. This is limited to personal data you have provided.

     

    Right to object

    You may object to our processing of your personal data by us, where this processing is based on our legitimate interests or for direct marketing. We will assess whether our interest in continuing to process your personal data overrides your rights and freedoms. If not, we will stop processing your personal data. Either way, we will inform you of the outcome.

    If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the request; this is to ensure that your data is protected and kept secure.

    Safeguarding Measures

    STA International Ltd takes your privacy seriously and takes every reasonable measure and precaution to protect and secure your personal data. Maintenance of our network and systems’ controls lies with our hosting company that is ISO 27001 certified.  We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place, including:

    SFTP, encryptions, restricted access, IT authentication, firewalls, anti-virus/malware

    Transfers Outside the EU

    The majority of your information is processed in the UK and European Economic Area (EEA), where personal data is protected by the General Data Protection Regulation (GDPR). However, some of your information may be processed by us or the third parties we work with outside of the EEA.

    Where your information is being processed outside of the EEA, we take additional steps to ensure that your information is protected to at least an equivalent level as would be applied by UK / EEA data privacy laws e.g. we will put in place legal agreements with our third party suppliers and do regular checks to ensure they meet these obligations.

    Lodging a Complaint

    STA International Ltd only processes your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, you have the right to complain to the supervisory authority.

     

    STA International Ltd

    Company DPO: Emanuela Pitzianti

    3rd Floor, Colman House, King Street, Maidstone ME14 1DN

    Telephone: 01622 600 900

    compliance@staonline.com

     

    Information Commissioner Office (ICO)

    Wycliffe House, Water Ln, Wilmslow SK9 5AF

    Telephone: 0303 123 1113

    Website: https://ico.org.uk/concerns/