1. Privacy statement
1.2 Curo Compensation Limited (we, us, our) is registered under the terms of the General Data Protection Regulation (GDPR). Details of our notification to the data protection regulator may be found in the Information Commissioner’s Office Public Register of Data Controllers at https://ico.org.uk under registration number ZA089894. Our registered office address is at Exchange Tower, 19 Canning Street, Edinburgh EH3 8EH.
2. General information
3. What information do we collect?
3.1 When you register to use our services and/or our site we may ask you to provide certain personal data including but not limited to, your name, company name and contact details (Personal Data).
3.2 In order to perform the services, we may also ask for anonymised information about employees from your organisation, including but not limited to, gender, job title, job level, business unit, position within the organisation, tenure, age, bonus and salary (Employee Data).
4. What do we use the provided data for?
4.1 We may use your Personal Information for the following purposes:
4.1.1 in the normal course of our business, to allow us to register you to receive our services and to provide you with our services;
4.1.2 to allow us to manage your account;
4.1.3 to allow us to analyse your personal preferences and personalise our services to you;
4.1.4 to store your data to pre-populate fields to make it easier for you to provide information when you return to our sites;
4.1.5 to validate your information (and, in some cases, match it against information that has been collected by a third party) to check that the data we hold about our customers/users is accurate, consistent and current; and
4.1.6 to comply with any legal obligations to which we are subject.
4.2 We may use the Employee Data for the following purposes:
4.2.1 to allow us to provide the services to you;
4.2.2 to calculate gender pay gap statistics; and
4.2.3 to produce the reports you request, including the Gender Pay Gap Report, which may include diversity and inclusion reports, regulatory reports and/or other reports.
4.3 We shall periodically check that the Personal Data we store for you is accurate. If you would like to update the Personal Data we hold about you, please contact us on email@example.com with your request.
4.4 The provision of the Provided Data is mandatory if you are to receive our services. If you fail to provide such data we shall be unable to provide our services.
5. Who do we share your information with?
5.1 As part of using our services, you consent to us sharing the Provided Data with the following parties:
5.1.1 the company who provide us with hosting services from time to time;
5.1.2 our professional advisers;
5.1.3 our consulting partners and data management consultants; and
5.1.4 any member of our group and other companies which may be added to our group from time to time.
5.2 We may also share the Provided Data with third parties:
5.2.1 in the event that we, our business, or substantially all of its assets are acquired by a third party (in which case personal information about customers will be one of the transferred assets);
5.2.2 if we are under a duty to disclose or share the Provided Data in order to comply with any legal obligation, or in order to enforce or apply any contract with you; or to protect our rights, property, or safety of our employees, customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
6. How long do we store the provided data for?
6.1 We only store the Provided Data for as long as necessary for the purposes listed in paragraph 4.
7. What are your rights?
7.1.1 Access to your Personal Data: You may request access to a copy of your Personal Data.
7.2 Right to withdraw: You may withdraw your consent at any time. Please contact us using the details located at section 11 of this policy if you would like to withdraw your consent and we will delete your data in line with your right to erasure at 7.4 below.
7.3 Rectification: You may ask us to rectify inaccurate information held about you. If you would like to update the data we hold about you, please log on to your profile at https://curogpg.com/login and update your information.
7.4 Erasure: You may ask us to delete your Personal Data. If you would like us to delete the Personal Data we hold about you, please contact us using the details below, specifying why you would like us to delete your Personal Data.
7.5 Portability: You may ask us to provide you with the Personal Data that we hold about you in a structured, commonly used, machine readable form, or ask for us to send such personal data to another data controller.
7.7 Make a complaint: You may make a complaint about our data processing activities to a supervisory authority, for the UK this is the Information Commissioner’s Office, at https://ico.org.uk.
8.1 Cookies are small files saved to your computer’s hard drive that track, save and store information as well as your interactions and usage of our website. The primary purpose for collection of data from users to our site is to allow us to provide a smooth efficient and personalised experience while using our site.
8.2 You are advised that if you do not consent to the use and saving of cookies from this website on to your computer hard drive then you should take necessary steps within your web browser security settings to block all cookies from this website and its external serving vendors.
9. Security and data storage
9.1 We will treat all of your information in strict confidence and we will endeavour to take all reasonable steps to keep the Provided Data secure once it has been transferred to our systems. We adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorised access, alteration, disclosure or destruction of the Provided Data, and data stored on the website and associated database.
9.2 Please note that the internet is not a secure medium and we cannot guarantee the security of any data you disclose online. You accept the inherent security risks of providing information and dealing online over the Internet and will not hold us responsible for any breaches.