Yestech is committed to complying with data protection legislation and good practice including:

  • Processing personal information only where this is strictly necessary for legitimate business purposes.
  • Collecting only the minimum personal information required for these purposes and not processing excessive personal information.
  • Providing clear information to individuals about how their personal information will be used and by whom.
  • Only processing relevant and adequate personal information.
  • Processing personal information fairly and lawfully.
  • Retaining personal information only for as long as is necessary for legal or regulatory reasons or, for legitimate organisational purposes.
  • Respecting individuals’ rights in relation to their personal information, including their right of subject access.
  • Keeping all personal information secure

The policy applies to all our employees, and trading partners.    Any breach of the GDPR by an employee will be dealt with under our disciplinary policy and may also be a criminal offence, in which case the matter will be reported as soon as possible to the appropriate authorities.

Any third parties working with or for Yestech and who have or may have access to personal information, will be expected to have read, understood and to comply with this policy. No third party may access personal data held by Yestech without having first entered into a data confidentiality agreement, which imposes on the third party, obligations no less onerous than those to which Yestech is committed, and which gives Yestech the right to audit compliance with the agreement.

What information do we keep and why?

The personal information which we keep is restricted to just what we need to carry out our normal business activities.  For people other than our employees, the only personal information which we keep about them is limited to:

  • Names of key business contacts with their email addresses and mobile telephone numbers
  • Business name and trading addresses.
  • Details about their business equipment and services.
  • Personal information of telephone correspondents which might be contained in recorded telephone conversations.

The additional information which we keep about our employees is:

  • Home address
  • Date of birth
  • National Insurance number
  • Previous employment history
  • Payroll history

How we keep personal information secure?

All the personal information which we keep is stored in our cloud-based database systems.  These systems are only accessible by authorised Yestech employees and they are adequately protected by passwords in accordance with good industry practice.

Specific provisions related to recording telephone conversations.

Our hosted telephone platform can record telephone conversations.   Customers can choose whether to enable the call recording feature on their system.

Call recordings are stored securely in encrypted format on our servers.   Customer representatives with sufficient privilege can search for, playback, download and delete call recordings on their system.

Call recordings may contain information about a caller which is confidential or sensitive.  Our position is that the customer must take responsibility for managing call recordings which contain sensitive information.   We provide tools to enable call recordings to be found and deleted if a caller has good reason to request this.

Regardless of the provisions of GDPR, the Payment Card Industry (PCI) data security rules state that a caller’s payment card details must not be recorded by a telephone system.  We provide tools and technical solutions which prevent payment details from being recorded during a telephone conversation.  It is the responsibility of the customer to use these tools.

Data retention policies

Type of Data Retention Policy
Customers’ and suppliers’ contact information Data about a customer or supplier will be erased no later than one calendar month after our trading relationship with the organisation ends.
Business transaction records (such as invoices). We keep these records only for as long as we are legally obliged to.
Routine operational correspondence with trading partners, such as quotations and emails. These records will be erased no later than one calendar month after our trading relationship with the organisation ends.
Telephone call recordings stored on our internal telephone system. 12 months.
Telephone call recordings stored on customers’ telephone systems. We store customers’ telephone call recordings on our servers for as long as each customer asks us to.  We delete call recordings on request.

Responsibilities

Responsibility for ensuring compliance with our GDPR policies rests with our Managing Director.