A lot has been written about how to achieve good outcomes for members of defined benefit (DB) pension schemes. A strong employer covenant, well-managed investments...
Read article “Good administration, the backbone of pensions”5 minutes
Brightwell1 are registered at One America Square, 17 Crosswall, London, England, EC3N 2LB (we, us, our) and are the data controllers for any relevant Data Protection Regulations, including EU GDPR, UK GDPR and DPA 2018.
This Privacy Notice (Notice) sets out the basis on which we will process any personal data we collect from you, or that you or third parties provide to us.
Please read this Notice carefully so that you understand your rights in relation to your personal data, and how we will collect, use, and process your personal data.
In a situation where you provide us with your personal data to share with a third party who will provide a service to you directly, they are the data controller of that personal data and you are strongly advised to review their own privacy notice for details as to how they handle your personal data.
We are committed to protecting and respecting your privacy and this Notice explains our policy in relation to:
We hold the following information about you:
If you provide us with information about someone else, for example your family members and dependants, we will assume that you have their permission to do so. We will process their personal data in accordance with this Notice. Please let them know you have provided their information to us and encourage them to read this Notice.
We will use your personal information for the purposes of administering and managing your pension. We may receive information from third parties who collect your personal data and pass it on to us. For example, a claim organisation contacts us on your behalf. Where this is the case, the third party is responsible for obtaining the relevant consents from you to ensure you are happy with the ways in which your personal data will be used.
More information on the purposes for which we process your data and the legal bases for this processing can be found in section 14 of this Notice – ‘Additional Information’.
We do not sell, rent, or lease your personal information. We share your information with selected recipients as set out in this Notice. This includes sharing information with those who may have a legal or regulatory right to request such information. Please see section 14.2 for more information about who your personal data is shared with.
The information that we collect from you will be transferred to and stored at/processed in the UK/EEA. We will take all steps reasonably necessary to ensure that your personal data is treated securely and in accordance with this Notice.
We will only transfer your information outside of the UK/EEA where we have your consent and there are adequate measures in place to provide appropriate safeguards such as Model Clauses (Standard Contractual Clauses (SCCs) produced by the EU Commission) and other appropriate safeguards such as (Code of Conduct and Certification). Please see section 14.5 for more information about Transfer Mechanisms.
The transmission of information via the internet or email is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your information transmitted through this website or over email; any transmission is at your own risk. Once we have received your information, we will take appropriate technical and organisational measures to safeguard your personal data against loss, theft and unauthorised use, access, or modification.
Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping such password confidential. Please do not share your password with anyone.
Pension benefits are paid over a long period and your right to benefits payable is based on information that may date back many years. We will decide to delete some of the data held in relation to you after 6 years.
However, your personal information may be held for longer where:
After the retention periods have elapsed, we will store your information in an aggregated and anonymised format.
You have certain rights in relation to the personal information we hold about you, which we detail below. Some of these only apply in certain circumstances as set out below. We also set out how to exercise those rights. Please note that we will require you to verify your identity before we respond to any of your requests. We must respond to a request by you to exercise those rights without undue delay and at least within one calendar month (although this may be extended by a further two months in certain circumstances). To exercise any of your rights, please complete the Data Subject Rights Request Form.
Name of Rights | Right Description |
Right of information | You have the right to know the personal information we hold about you, how we use it, who we share it with and how long we keep your personal data. |
Right of access | You have the right to know whether we process your personal information, and if we do, to access information we hold about you, how we use it and who we share it with. If you require more than one copy of information, we hold about you, it is free of charge, unless we deem it necessary to charge you an administration fee. We may not provide you with certain personal information if providing it would interfere with a person’s rights and freedom (e.g., where providing the personal information would reveal information about another person) or where another exemption applies. Please See “how long will we keep your personal data”. |
Right to rectification | The accuracy of the information we hold about you is important to us. Under the DPA 2018 and EU GDPR, you have the right to access the information we hold about you and have any inaccuracies corrected. Where you request correction, please explain in detail why you believe the personal data we hold about you to be inaccurate or incomplete so that we can assess whether a correction is required. Please note that whilst we assess whether the personal data, we hold about you is inaccurate or incomplete, you may exercise your right to restrict our processing of the applicable data. |
Right to erasure | This is also known as the “right to be forgotten”. Please see section 15.3 for more information about the circumstances in which you may request that we erase the personal data we hold about you. |
Right to data portability | You have the right to receive a subset of the personal data we collect from you in a structured, commonly used, and machine-readable format and a right to request that we transfer such personal data to another third party. Please section 15.1 for more information on the data we hold. If you wish for us to transfer the personal data to another third party, please ensure you detail that third party and note that we can only do so where it is technically feasible. We are not responsible for the security of the personal data or it’s processing once received by the third party. We also may not provide you with certain data if providing it would interfere with right and freedom of another person (e.g. where providing the personal data we hold about you would reveal information about another person or our trade secrets or intellectual property). |
Restriction of processing to storage only | You have a right to require us to stop processing the personal data we hold about you other than for storage purposes in certain circumstances. Please note, however, that if we stop processing the personal data, we may use it again if there are valid grounds under data protection laws for us to do so (e.g. for the defence of legal claims or to protect to right and freedom of another person. Please See “how long will we keep your personal data”. Please see section 15.4 for more information on the circumstances in which you may request that we stop processing and just store the personal data we hold about you. |
Make a complaint | You have a right to lodge a complaint with relevant data protection supervisory authorities. In the UK, it is the Information Commissioner’s Office (ICO). |
We may share your personal data with a third party where it is necessary
When you visit our website, we collect technical information about your computer, such as your internet protocol address (which is a number that can uniquely identify a specific computer on the internet), time zone setting, your login information, browser type and version, browser plug-in types and versions, operating systems and platforms.
We use cookies to collect information about your browsing activities over time following your use of our services. This allows us to recognise and count the number of users and to see how users navigate on our website when they are using it. This helps us to improve the services we provide to you and the way our website works.
If you wish to make a complaint about how we process your personal data, please contact us using the contact details below and we will endeavour to deal with your request as soon as possible. This does not interfere with your right to raise a complaint with a relevant data protection supervisory authority.
We keep this notice under regular review and may change it from time to time. When we make changes, the date at the bottom of this notice will be updated accordingly. Any amendment to this notice will be applied as of that date. We encourage you to check this from time to time for any updates or changes.
If you have any questions, comments, or requests regarding any aspect of this Notice, please do not hesitate to contact us as soon as possible at:
One America Square,
17 Crosswall,
London
EC3N 2LB
Category of Personal Data | Purpose for Processing | Legal Basis of Processing |
Personal details such as your name, gender, age, date of birth, email address, postal address, telephone or mobile number and identifiers such as national insurance number |
| Performance of a contract as required. Legitimate interest to run an effective business |
Personal details and family, lifestyle and social circumstances such as details about current marriage and partnerships and marital history, details of family and dependents |
| Performance of a contract as required. Legitimate interests to run an effective business |
Personal details and employment details such as pensionable pay, length of service, employment and career history, recruitment and termination details, attendance record, health and safety records, security records, job title and job responsibilities, financial details such as income, salary, assets and investments, bank account details to process pension payments, benefits, grants and insurance details |
| Performance of a contract as required. Legitimate interests to run an effective business |
Personal details and pension entitlement |
| Performance of a contract Legitimate interests to run an effective business |
Personal details and details in relation to your physical and mental health |
| Legitimate interests to run an effective business Explicit consent |
Technical information and other information about your visits to our website/Pensions Portal |
| Legitimate interest to ensure our website and Pensions Portal is operating effectively |
Voice recordings of calls made to or from Brightwell |
| Performance of a contract Legitimate interests to run an effective business |
Who do we share your personal data with |
|
We will share your information with law enforcement agencies, public authorities or other organisations if legally required to do so, or if we have a good faith belief that such use is reasonably necessary to |
|
We will also disclose your information to third parties |
|
You may request that we erase the personal data we hold about you in the following circumstances |
Also note that you may exercise your right to restrict our processing the data whilst we consider your request as described below. Please provide as much detail as possible on your reasons for the request to assist us in determining whether you have a valid basis for us to erase your personal data. Please note, however, that we may retain the personal data if there are valid grounds under law for us to do so (e.g., for the defence of legal claims or freedom of expression) but we will let you know if that is the case. Where you have requested that we erase your personal data that we have made public and there are grounds for erasure, we will use reasonable steps try to tell others that are displaying the data or providing links to the data to erase the personal data too. |
You have a right to require us to stop processing the personal data we hold about you other than for storage purposes in certain circumstances. Please note, however, that if we stop processing the personal data, we may use it again if there are valid grounds under data protection law for us to do so (e.g. for the defence of legal claims or to protect the rights and freedom of another person). |
You may request we stop processing and just store the personal data we hold if
You may object where:
|
Below are the types of cookies that the site uses:
Purpose | Name | Description |
---|---|---|
Strictly Necessary | ASP.NET_SessionId | Our cookie ensures that you are logged in securely and only you see your information for the duration of your visit. |
Security | __AntiXsrfToken | Used as a security measure against hackers to stop cross site scripting. |
Security | AuthCode | Used as a security token during login and registration. |
Site Appearance | ComplianceCookie | Used to indicate that you have read this notice. |
Analytical | _ga; _gat (Google Analytics) | We use Google Analytics to help us understand how users use our web site. This allows us to improve the quality and content on our site for our visitors. The aggregated statistical data cover items such as total visits or page views, and referrers to our web site. Click here to learn more about Google Analytics and deleting or rejecting the Google cookies. |