VMA and GDPR
With the introduction of the General Data Protection Regulation coming into force on 25th May 2018 the VMA have posted this GDPR Statement in order to provide our members and future members transparency on how we collect, store and terminate the data we hold.
The information we collect
The VMA will collect information under 3 separate processing topics. Direct contact, Opt in & Accounting.
The processing topic of direct contact covers when a client, prospective client or supplier contacts the VMA in the membership or future membership of the VMA. This information can be collected either over the phone, via our websites contact form or through face to face contact (Networking, Expo’s or Events). This information will always be relevant to the query at hand and will not be used for Promotional or Marketing (Opt-in) purposes unless permission has been granted by the owner of this information.
The processing topic of Opt-in covers any information gathered for the purpose of Promotion & Marketing. The VMA may use multiple ways for this information to be gathered including Newsletter op-in’s on our website, competition entries and contact cards at an event or conference. In accordance with the regulations of GDPR the information gathered in this format will be lawfully acquired through the use of opt-in checkboxes on forms and competitions on both the website and contact cards.
The processing topic of Accounting covers the information acquired in the case of any financial transaction. This will be details provided by the client and also provided online via Companies House or other data website. The kind of information you can expect to be stored would be the Name, Address, Telephone, Company Number and VAT number of an organisation and also the Name and Email Address of the main contact at this organisation. This information applies to both Clients and Suppliers.
The information we store
The VMA will store information in multiple ways depending on our processing topic.
With direct contact information being acquired in multiple ways we follow certain processes in storage of this information. Direct contact information acquired via email will be stored by our email service providers address book functionality. Direct contact information acquired via a phone call can be stored by either the use of a personal diary, notepad or our email service providers address book functionality. Our email provider stores this information on their secured servers and the data is encrypted both on the server and during transfer to and from the server. The server is located in the UK.
Opt-in information is stored in a master database on our internal network and can be distributed to multiple third party locations depending on our marketing requirements. Before using a third party service for marketing we will first check to see if both the storage on this service and transmission to this service is both safe and encrypted.
All accounting information is stored on our third party accounting software. Contact the VMA for more information.
The information we terminate
The VMA will terminate information in multiple ways depending on our processing topic.
Direct contact information as mentioned above is stored on our third party email service provider. To comply to GDPR we will access this information on a regular basis to make sure that the data that is irrelevant or unneeded is removed.
The data of clients or suppliers that we provide services to or request services from will be stored permanently in our email database until this client no longer requires anymore services. These clients will be informed that their data will be stored during this period of time and on request we can delete this data for the client or they will be deleted if there data is deemed irrelevant by our next assessment date.
Contact forms, enquiries or award contact data will be stored by our email server for 12 months, then deleted.
Any information collected in a physical format (Notepad or Diary) will be transferred to a securely encrypted online location such as our Network server or Email Server and the physical format will be destroyed professionally.
Information collected for Opt-in promotion and marketing will be terminated on request of the information owner. This may be by unsubscribing from our marketing services or asking the VMA to delete their details.
All accounting data will be stored for a period of 6 financial years as per the Government’s “Running a limited company” requirements.