This privacy statement covers the following areas:
Important information and who we are
City Science Corporation Limited (company number 09891138) is the entity responsible for the collection and use of personal data by City Science. City Science Corporation Limited is registered as a data controller at the Information Commissioner’s Office (ICO) with registration number ZA160336.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Your legal rights
Under certain circumstances, you have legal rights under GDPR in relation to your personal data which are known as data subject rights. Those rights are:
Where you seek to exercise any of your data subject rights, we may need to request specific information from you to help us confirm your identity and establish your right to exercise such rights. This is a security measure to ensure that your personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to exercise your data subject rights to speed up our response.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
You have the right to make a complaint at any time to the ICO regarding the collection and use of personal data by City Science. However, we would appreciate being given the chance to help you with your concerns before you approach the ICO, so please contact us using the details above in the first instance.
The personal data we collect about you
Personal data is any information about an individual which can identify that person. It does not include any information where the individual’s identity has been removed (this is known as anonymous data), which we may collect, use and share for any purpose.
We may collect the following personal data about you:
You may provide your personal data to us by filling in forms or submitting a job application via our website or linked third party websites, or by corresponding with us by phone, e-mail or otherwise. The personal data you give us may include your name, address, e-mail address and phone number, financial information, personal description and photograph and other information regarding your work, education and employment history, activities and personal circumstances.
With regard to each of your visits to our website, we may automatically collect the following personal data:
We may receive personal data about you if you use any of the other websites operated, or other services provided, by the Oxygen House Group. We may also receive personal data about you from our research and project partners and publically available sources.
How we use your personal data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
Generally we do not rely on consent as a legal basis to use your personal data other than where you have agreed that your personal data may be shared with, and used by, other companies within the Oxygen House Group for recruitment purposes only or used by us or any third party to send you marketing information. You have the right to withdraw your consent to such uses at any time.
Set out below is a description of all the ways we plan to use your personal data. We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and will explain the legal basis which allows us to do so.
Please note that we may use your personal data without your knowledge or consent where this is required or permitted by law.
We may use personal data in the following ways:
We may combine personal data we receive from other sources with the personal data you give to us or that we collect about you.
Disclosure of your personal data
City Science’s recruitment is managed centrally by the Oxygen House Group Recruitment Team. We will transfer the personal data you have provided to us in any enquiries, applications or CVs submitted by you in connection with any vacancies advertised by City Science (whether via our website or otherwise) to the Recruitment Team, who will store your personal data in our applicant tracking system, Recruitee, and only use your personal data for the purposes of our recruitment process.
Your personal data may also be disclosed to any of our directors, employees or professional advisers who are involved in our recruitment process.
Your personal data will be retained by the Recruitment Team for 18 months following the relevant vacancy being filled. Once this period has elapsed, your personal data will be permanently deleted.
We may share your personal data with any companies within the Oxygen House group to allow them to provide services to City Science.
We may share your personal data with selected third parties, including:
We may also share your personal data with other third parties:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third party service providers to use your personal data for their own purposes and only permit them to use your personal data for specified purposes and in accordance with our instructions.
The majority of the personal data we collect will be stored and used in the UK at our offices and in our secure data centre(s). We will only transfer your data outside of the European Economic Area (EEA) where it is necessary for us to do so.
Whenever we transfer your personal data out of the EEA, we ensure protection is afforded to it by ensuring at least one of the following safeguards is implemented:
a) We will only transfer your personal data to service providers located in countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. b) Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. c) Where we use service providers based in the US, we may transfer personal data to them if they are certified under the Privacy Shield, which requires them to provide similar protection to personal data shared between the Europe and the US.
Security of personal data
We have put in place appropriate physical, electronic and managerial security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
In addition, we limit access to your personal data to those directors, employees and other third parties who have a business need to know. They will only use your personal data for specified purposes and are required to keep your personal data confidential.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your personal data transmitted to our website; any transmission is at your own risk.
Retention of personal data
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for your personal data, we consider the amount, nature, and sensitivity of your personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we use your personal data, whether we can achieve those purposes through other means and applicable legal requirements.
We will not use your personal data for marketing purposes without your explicit consent. We will inform you (before collecting your personal data) if we intend to use, or disclose to any third party, your personal data for such purposes.
Where you have provided your consent to receive marketing information from us or any third party, you will be given the opportunity to opt out of receiving any future marketing information by checking certain boxes on the forms we use to collect your personal data or unsubscribing from marketing emails via the hyperlink provided in such emails.
Third party websites etc.
Our website may, from time to time, include links to third party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share personal data about you. We do not control these third party websites, plug-ins or applications and are not responsible, and do not accept any liability, for their compliance with data protection laws.
When you leave this website, we encourage you to read the privacy policies of every website you visit or plug-in or application you download, in particular before submitting any personal data to those websites, plug-ins or applications.