Alfred Franks & Bartlett PLC (“we”, “us”, or “our”) are committed to protecting and respecting the personal data that we hold. This privacy statement describes why and how we collect and use personal data and provides information about individuals’ rights.
It applies to personal data provided to us, both by individuals themselves or by others on behalf of individuals. We may use personal data provided to us for the purposes described in this privacy statement or as made clear in another form before collecting personal data.
Our registered address is AFB House, Unit 2, Alban Park, Hatfield Road, St Albans, Herts AL4 0JJ. Our website is https://www.afb.co.uk, owned and operated by Alfred Franks & Bartlett PLC.
Under the UK GDPR and Data Protection Act 2018 (‘the Act’), personal data is defined as ‘any information relating to an identified or identifiable natural person (‘data subject’), by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person’.
When collecting and using personal data, our policy is to be transparent about why and how we process it. We process personal data for numerous purposes, and the means of collection, lawful basis of processing, use, disclosure, and retention periods for each purpose differ, and are set out in the relevant sections below.
The personal data provided to us comes either directly from the individual concerned, from a third party acting on their behalf, or from publicly available sources (such as internet searches and Companies House). Where we receive personal data from a third party, we request that they inform the individual of the necessary information regarding the use of their data, and we check the third party in accordance with the Data Processing Agreement.
A data controller is the individual or legal person who controls and is responsible to keep and use personal data in paper or electronic files. Alfred Franks & Bartlett PLC is the data controller as defined by relevant data protection laws and regulation.
The lawful bases for processing are set out in Article 6 of the GDPR. At least one of these must apply whenever personal data is to be processed:
- Consent — you have given consent for your personal data to be processed for a specific purpose.
- Contract performance — processing is necessary for the performance of a contract you have with us, or to take specific steps before entering into a contract.
- Compliance with legal obligation — processing is necessary for us to comply with the law (excluding contractual obligations).
- Protection of vital interests — processing is vital to an individual’s survival.
- Public interest — processing is necessary to perform a task in the public interest with a clear basis in law.
- Legitimate interests — processing is necessary for our legitimate interests or those of a third party, unless overridden by the individual’s rights.
Your data subject rights are:
- the right of access;
- the right to rectification;
- the right to erasure (the right to be forgotten);
- the right to restriction of processing;
- the right to be informed;
- the right to data portability;
- the right to object; and
- the right not to be subject to a decision based solely on automated processing.
Professional services
We provide services to individuals as well as businesses, non-profits, and other organisations. The exact data held depends on the services to be provided. Where we engage clients for professional services, we may collect and process personal data to satisfy a contractual obligation, and request that clients only provide the data required for us to fulfil it.
Data is processed to provide services to clients, manage client relationships, administer our business, and meet regulatory, legal or ethical requirements. The data processed depends on the services provided — for businesses this may include contact details, payroll and employee information, and lists of customers and suppliers; for individuals it may include contact details, tax identifiers, and information about income and financial interests.
Business contacts
Personal data from our contacts — potential and prior customers and employees — is held in our Customer Relationship Management Database, entered after contact is made with a partner or staff member. We use technology to profile business contacts to assess the health of our relationship, relying on contract performance and legitimate interest. Data held may include names, email and physical addresses, job titles, and details of the initial meeting.
Our people & applicants
We collect personal data for our people as part of the administration, management and promotion of our business activities; our Staff Handbook and consultancy agreements explain this further. Where an individual applies to work for us, personal data is collected through the application process (including website forms) and used to assess potential employment and for administration and management.
Suppliers
We collect and process personal data about our suppliers, subcontractors and the individuals associated with them to manage our relationship, contract and receive services, and in some cases provide professional services to our clients. This supports receiving goods and services, delivering services to clients, administering and developing our business, security and risk management, promoting our services, and complying with legal and regulatory obligations. We typically hold suppliers’ names, contact names, and contact details.
People who visit our offices
Personal data is collected when individuals visit our offices via CCTV and a visitors’ sign-in book, for the physical security of client information and the benefit of our staff. ‘CCTV in Operation’ signs in reception confirm CCTV is deployed; images are held securely with limited access and only used when investigating an incident.
People who use our website
When people visit our website, mobile apps and other means, personal data is collected through automated tracking and interactions with forms. We work closely with third parties who may collect data on our behalf. Data is processed for administration, functionality, security, and the promotion and development of our offerings. Where entered to engage with functionality, data may include names, addresses, email addresses, phone numbers, and financial information; collected automatically, it may include technical information such as IP address, browser type, time zone, operating system, and details of your visit. Our website uses cookies to distinguish individuals — see our Cookie Policy.
We may disclose your personal data to third parties when under a duty to do so to comply with a legal obligation, to enforce agreements, or to protect the rights, property or safety of the organisation or others. Before engaging third parties we conduct vendor risk assessments and put contractual arrangements and security mechanisms in place. Personal data may be transferred to: third-party organisations providing applications, IT or data services; organisations that otherwise assist us in providing goods, services or information; auditors and professional advisers; and law enforcement or regulatory agencies where required by law.
Our site may contain links to and from the websites of our partner networks, advertisers and affiliates. These websites have their own privacy policies and we do not accept responsibility or liability for them. Please check those policies before submitting any personal data.
The data we collect from you will be processed at our servers in the UK. We may also store information in our cloud servers based in the USA, with transfers conducted in line with Chapter 5 of the UK GDPR. If personal data is transferred outside the UK to a country without an adequacy rating, we will request the data subject’s consent before processing — unless Binding Corporate Rules, Standard Contractual Clauses or ad-hoc contractual clauses stipulate that the data will be processed in accordance with the GDPR.
To help protect your data, we maintain physical, technical and administrative safeguards, and update and test our security technology on an ongoing basis. We restrict access to your personal data to employees who need it to provide services to you, train our employees on the importance of confidentiality, and take appropriate disciplinary measures to enforce their privacy responsibilities.
We store your personal data in accordance with our Record Retention and Destruction Policy, reviewed internally to ensure we do not keep data longer than necessary. Some data is subject to legal and regulatory minimum retention periods. In summary: professional-services data is typically retained for as long as necessary (often 6 years); business-contact data is not retained where there is no evidence of engagement; applicant data is held for a maximum of two years where no longer necessary; supplier data is retained as long as necessary; visitor CCTV recordings are overwritten after 31 days unless an issue requires investigation; and website data is typically retained for around 6 years. For more information, email data@afb.co.uk.
This privacy policy was last updated on 01/08/2021. Alfred Franks & Bartlett PLC reserves the right to vary this policy from time to time. Variations become effective on posting to this website, and your subsequent use of the website or submission of personal information will be deemed to signify acceptance of the variations.
For further information on your rights and how to complain to the ICO, please refer to the ICO website at https://ico.org.uk/concerns.
The data controller for Alfred Franks & Bartlett PLC, registered in England under registration No. 2937270 — Ground Floor Cooper House, 316 Regents Park Road, London, N3 2JX. VAT No. 646 2591 23.
If you have any questions about this privacy statement or how and why we process personal data, please contact:
This Cookie Policy tells you what to expect when our website collects personal information. It applies to the information we collect about our visitors and those who log in to our website.
A ‘cookie’ is a small text file delivered by our website server onto your computer while you visit, which can subsequently be used to identify particular devices and remember your website preferences and login details. Most cookies do not collect information that identifies you, instead collecting more general information such as how you arrived at and used our website, or your general geographical location.
- Session cookies are temporary and expire once you close your browser (or your session ends).
- Persistent cookies remain on your hard drive until you or your browser erase them, depending on the cookie’s expiration date. Under the ePrivacy Directive they should not last longer than 12 months.
- First-party cookies are placed on your device directly by the website you are visiting.
- Third-party cookies are placed by a party other than the website you are visiting, such as an advertiser or analytics system.
| Cookie | Type | Description | Duration |
|---|---|---|---|
| loc | Advertisement | AddThis geolocation cookie to understand the location of users who share information. | 1 yr 1 mo |
| uvc | Analytics | Set by addthis.com to determine the usage of the AddThis service. | 1 yr 1 mo |
| _ga | Analytics | Installed by Google Analytics; calculates visitor, session and campaign data and keeps track of site usage. Stores information anonymously. | 2 yrs |
| _gid | Analytics | Installed by Google Analytics; stores information on how visitors use the website and creates an analytics report anonymously. | 1 day |
| _gat_gtag_ | Analytics | Set by Google to distinguish users. | 1 min |
| __atuvc | Functional | AddThis cookie ensuring the updated share count is seen when one shares a page and returns to it. | 1 yr 1 mo |
| __atuvs | Functional | AddThis cookie ensuring the updated share count is seen before the cache is updated. | 30 min |
| cookielawinfo- necessary | Necessary | Set by the GDPR Cookie Consent plugin to record consent for the “Necessary” category. | 1 hr |
| cookielawinfo-non- necessary | Necessary | Set by the GDPR Cookie Consent plugin to record consent for the “Non-necessary” category. | 1 hr |
Request a Declaration of Conformity for one of our products. Required fields are marked with an asterisk.