1. Introduction 

Kudos Commercial Finance Ltd needs to gather and use certain information about individuals. 

This can include customers, suppliers, business contacts, employees and other people the organisation has a relationship with or may need to contact. 

This policy describes how this personal data must be collected, handled and stored to meet the company’s data protection standards — and to comply with the law. 

2. Why this policy exists 

This data protection policy ensures Kudos Commercial Finance Ltd 

3. Data protection law 

The General Data Protection Regulations describe how organisations — including Kudos Commercial Finance Ltd — must collect, handle and store personal information.  These rules apply regardless of whether data is stored electronically or otherwise. 

To comply with the law, personal information must be; 

Record Keeping: 

A range of information must be detailed in our internal records of processing activities. Such areas include; 

Kudos Commercial Finance Ltd ensures that records of these activities are kept and are updated accordingly. Individuals’ data is kept on file for 6 years in line with the Financial Conduct Authorities record keeping rules. After which point, personal data is retracted to the point it is unidentifiable and used for statistical purposes only. 

4. Lawful Basis for Processing Data 

Under GDPR, it is a requirement that Kudos Commercial Finance Ltd has a valid lawful basis to process personal data, this should be documented. Most lawful bases require that processing is ‘necessary’. 

The lawful bases for processing are set out in Article 6 of the GDPR. At least one of these must apply whenever Kudos Commercial Finance Ltd process personal data:  

Processing is lawful under GDPR as: 

 (a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose. 

(b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract. 

(c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations). 

Kudos Commercial Finance Ltd has chosen this basis for processing data as it is requested from the individuals that we capture data before entering into a contract (e.g. provide a quote for finance). 

5. Responsibilities 

Kudos Commercial Finance Ltd acts as a data Controller and data Processor. All staff are responsible for ensuring that the highest data standards and best practices are met on a continual basis. 

Although a Data Protection Officer (DPO) has not been appointed as Kudos Commercial Finance Ltd does not fall within the scope, the Directors are accountable and responsible for compliance with GDPR and will take on the tasks appointed to them as if they were a DPO. 

6. Data Protection Impact Assessments (DPIA) 

Kudos Commercial Finance Ltd has a general obligation to implement technical and organisational measures to demonstrate that data protection is integrated into our processing activities. A Data Protection Impact Assessment is conducted each time MT Commercial Finance Ltd consider implementing using new technologies  

The DPIA will pertain at least;  

7. Individuals Rights 

Individuals now have more rights under GDPR, Kudos Commercial Finance Ltd, these are; 

Kudos Commercial Finance Ltd provide every customer with a Privacy Notice at the point data is captured.  

The information supplied in this notice demonstrates how Kudos Commercial Finance Ltd is transparent over our data processing. The notice is;  

We include details of (but not limited to);  

the Data Controller, the lawful reason for processing data, if any third parties have legitimate interests, categories of personal data, categories of recipients such as banks and credit unions, the data retention periods,  

the individuals’ rights; including the right to withdraw, where the individual can complain about how the data is processed with a supervisory authority, source of data when it comes from a third party and where personal data is part of a contractual requirement or obligation. 

8. Rectification 

Individuals are entitled to have personal data rectified if it is inaccurate or incomplete. If Kudos Commercial Finance Ltd has disclosed the personal data in question to third parties, then we will inform them of the rectification where possible.  

Kudos Commercial Finance Ltd will respond to this request within one month or extended by two months where the request for rectification is complex. 

9. Erasure 

Individuals have a right to have personal data erased and to prevent processing in specific circumstances; 

Kudos Commercial Finance Ltd may refuse to comply with a request for erasure where the personal data is processed for the following reasons; 

If Kudos Commercial Finance Ltd has disclosed the personal data in question to third parties, a notification will be sent, informing them about the erasure of the personal data, unless it is impossible or involves disproportionate effort to do so.  

10. Restrict processing 

Kudos Commercial Finance Ltd will restrict the processing of personal data in the following circumstances; 

if any data has been disclosed to third parties, Kudos Commercial Finance Ltd will notify them about the restriction on the processing of the personal data, unless it is impossible or involves disproportionate effort to do so. 

11. Portability 

For personal data an individual has provided to a controller; where the processing is based on the individual’s consent or for the performance of a contract; and when processing is carried out by automated means, Kudos Commercial Finance Ltd must provide the personal data in a structured, commonly used and machine-readable form. Open formats include CSV files. Machine readable means that the information is structured so that software can extract specific elements of the data. This enables other organisations to use the data. 

Kudos Commercial Finance Ltd must provide this service free of charge. 

If the individual requests it, we may be required to transmit the data directly to another organisation if this is technically feasible. Kudos Commercial Finance Ltd will respond without undue delay, and within one month or extended by two months where the request is complex or receive many requests.  

12. Objecting 

If an individual has objected to processing data or direct marketing, Kudos Commercial Finance Ltd will cease to process the data.  

Individuals must have an objection on “grounds relating to his or her particular situation”. 

Kudos Commercial Finance Ltd will stop processing the personal data unless; 

This is brought to the attention of the data subject at the first point of communication and in our privacy notice. This is separated out from any other information. 

13. Direct marketing purposes 

As soon as an objection is received, Kudos Commercial Finance Ltd will stop processing personal data for direct marketing purposes.  This will be actioned at any stage and is free of charge. 

[As Your Kudos Commercial Finance Ltd offer an online presence, www.kudoscf.co.uk ; we offer a way for individuals to object online.] 

Automated decision making including profiling 

Kudos Commercial Finance Ltd understand that any form of automated processing of personal data intended to evaluate certain personal aspects relating to a natural person, or to analyse, or predict that person’s performance at work, economic situation, location, health, personal preferences, reliability, or behaviour falls under this right. Where this is conducted, the rules and guidance of the ICO will be adhered to and followed. To date, Kudos Commercial Finance Ltd does not conduct automated decision making including profiling. 

14. Subject Access Requests (SAR) 

Individuals who are the subject of personal data held by Kudos Commercial Finance Ltd are entitled to; 

Individuals contacting the company requesting this information, this is called a Subject Access Request.  

Kudos Commercial Finance Ltd will provide a copy of the information free of charge. However, a ‘reasonable fee’ may be charged when a request is manifestly unfounded or excessive, particularly if it is repetitive. 

A reasonable fee may also be charged to comply with requests for further copies of the same information. The fee is based on the administrative cost of providing the information only. 

Once the identity of the person making the request has been verified, the information will be provided within 1 month, this will be extended to 2 months if the request is complex. Notification will be made to the individual if this is the case. 

15. Complaints 

It is made clear that data subjects who wish to complain about how their personal data has been processed can raise this with Kudos Commercial Finance Ltd complaints procedure. If the data subject is still not happy, then the complaint can be referred to the Information Commissioners Office. 

16. Data Security and Storage 

When data is stored on paper, it should be kept in a secure place where unauthorised people cannot see or have access to it. These guidelines also apply to data that is usually stored electronically but has been printed out for some reason; 

When data is stored electronically, it must be protected from unauthorised access, accidental deletion and malicious hacking attempts; 

The point that personal data is accessed is when it can be at greatest risk of loss, corruption, theft, unlawful access, Kudos Commercial Finance Ltd will;