• Home
  • About us
  • Meet the team
  • News
  • Recruitment
  • Service Updates
  • Privacy Notice
  • Contact us
  • Client Area
Mail International
  • Distribution
    • International Mail
    • UK Mail Services
    • E-commerce & Parcel
  • Fulfilment
    • Envelope Machine Processing
    • Polythene Machine Processing
    • Manual Fulfilment
    • E-Commerce – Pick & Pack Fulfilment
  • Data
  • Print
    • Mono & Colour Digital Printing
    • Litho Printing
    • Envelope Printing
    • Other Printing Services
  • Returns
  • Supply & Storage
You are here: Home / Privacy Notice

Introduction

Introduction

Mail International Ltd (“we”, “us”, or “our”) is strongly committed to protecting personal data. This Privacy Notice explains why and how we collect and use personal data and provides information about an individual’s rights and the conditions under which we may disclose it to others and how we keep it secure.

It applies to personal data provided to us, both by individuals themselves or by others. We may use personal data provided to us for any of the purposes described in this Privacy Notice or as otherwise stated at the point of collection.

Personal data is any information relating to an identified or identifiable living person. Mail International processes personal data for numerous purposes, and the means of collection, lawful basis of processing, use, disclosure, and retention periods for each purpose may differ.

When collecting and using personal data, our policy is to be transparent about why and how we process personal data. To find out more about our specific processing activities, please go to the relevant sections of this notice.

We may change this Policy from time to time and will inform all individuals or others who provide data to us of any changes via e-mail and through our website.

Any questions regarding this Policy and our privacy practices should be sent by email to [email protected] or in writing to The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom.

This Privacy Statement is premised upon the General Data Protection Regulation, which lays out the rules regarding the processing of personal data and an individual’s rights. From here on, this regulation will be referred to as GDPR.

Who are we?

Who are we?

Mail International Ltd are a mailing and distribution services company providing a wide range of mailing and distribution services to other businesses. These include the production, fulfilment and distribution of mailings as well as standalone data, print, fulfilment and distribution solutions for sectors such as e- commerce or other marketing activity. In the course of carrying out our business activities we collect data directly ourselves, but predominantly most data is sent to us by others (our business clients) in order for us to produce and distribute their mailing and/or deliver the service they require .

We are registered and operate from our offices in England (company reg. 1923564) and deal with individuals, clients, suppliers and third-parties all over the world in delivering our services.

For the purposes of GDPR we can be classed under the GDPR regulations as both a data controller and processor depending on the source/method of collection and the purposes for which we are processing the data. This Privacy Statement aims to help you understand which is relevant to you, and as outlined in the introduction, how we collect and process this data.

Responsibilities and roles under the General Data Protection Regulation (GDPR)

Responsibilities and roles under the General Data Protection

Regulation (GDPR)

Mail International is both a controller and a processor under GDPR depending upon whom it is dealing with.

Mail International maintains records of all categories of processing activities it carries out; inclusive of:

  • The name and contact details of Mail International, other processors used; where applicable and of each controller and the data protection officer
  • The categories of processing carried out
  • Where applicable, transfers of personal data to a third country or an international organisation,including the identification of that third country or international organization
  • Where possible, a general description of the technical and organisational security measuresMail International will make the record available to the supervisory authority on request.Information security roles, responsibilities and authorities (inclusive of The General Data Protection Regulations obligations) have been defined within the company’s ISMS (Information Security Management System) which was developed in accordance with ISO 27001 for which we are accredited. All management roles throughout the business are responsible for developing and maintaining good information handling practices. Amongst these responsibilities are the following
  • The Data Protection Officer (DPO) should be a member of the senior management team, is accountable to Board of Directors of Mail International for the management of personal data within the organization and for ensuring that compliance with data protection legislation and good practice can be demonstrated. Accountabilities include:
  • The development and implementation of the GDPR as required by this policy; and
  • Security and risk management in relation to compliance with the policy.
  • Data Protection Officer, who Board of Directors considers to be suitably qualified and experienced, hasbeen appointed to take responsibility for Mail International’s compliance with this policy on a day-to- day basis and, in particular, has direct responsibility for ensuring that the business complies with the GDPR, as do all staff in respect of data processing that takes place within their area of responsibility.
  • The Data Protection Officer has specific responsibilities in respect of procedures such as the Subject Access Request Procedure and is the first point of call for Employees seeking clarification on any aspect of data protection compliance.
  • Compliance with data protection legislation is the responsibility of all Employees processing personal data.
  • Mail International’s Training Policy sets out specific training and awareness requirements in relation to specific roles and Employees/Staff of Mail International generally.
  • Employees/Staff of Mail International are responsible for ensuring that any personal data about them and supplied by them to the business is accurate and up-to-date.Whilst Mail International is a data controller internally, it predominantly functions as a data processor. Where Mail International is a processor, it is the responsibility of the Controller to put in place any contract with Mail International that sets out the subject-matter, duration of processing, the nature and purpose of the processing, the type of personal data, the categories of data subjects and the obligations and rights of the controller. In the absence of a contract, Mail International will operate according to the terms of our Privacy & Confidentiality Agreement which we also issue to subcontractors and third-parties we deal with. A copy of this agreement can be obtained by contacting our Data Protection Officer whose details are listed below.

As a processor offering global mailing and distribution services, we may engage third-parties (other processors) if they are authorised. A third-party is only deemed authorised if they are on our list of third- parties which is available from our Data Protection Officer via e-mail at [email protected] or in writing from The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND. Please see the sections of this notice titled Transfer of Personal Data to Third- Parties and Transferring your Information Outside of Europe for further information along with any other sections of this Privacy Statement relevant to you.

We inform all data controllers when changes are made to the list of third-parties and will provide the appropriate contact details or link to access the updated or amended version. In any event, all persons, whether we are acting as a controller or processor, have the right to object to the use of any particular third-party. To do so, please contact our data protection officer on the contact details above and we can remove your personal data from being processed by that third-party (NB. this may have an impact on the cost or on our ability to perform the required services).

If you wish to discuss any aspect of our and your responsibilities, please contact our Data Protection Officer, or where relevant, our client services team.

Lawfulness of processing

Lawfulness of processing

Mail International and its senior management team understand that processing shall only be lawful if one or more of the following apply:

  • The data subject has given consent to the processing of personal data for one or more specific purposes;
  • Processing is necessary in accordance with a contract with the data subject or to take steps at the request of the data subject prior to entering into a contract;
  • Processing is necessary for the controller to comply with a legal obligation;
  • Processing is necessary to protect the vital interests of the data subject or of another natural person;
  • Processing is necessary for the performance of a task carried out in the public interest or in the exerciseof official authority given to the controller;
  • Processing is necessary for the purposes of the legitimate interests of the controller or by a third party,except where the interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, particularly where the data subject is a child.

1. Business and Corporate Clients (existing and potential)

Business and Corporate Clients (existing and potential) Contact Information

Collection of Personal Data

Mail International Ltd processes personal data about contacts (existing and potential Mail International clients and/or individuals associated with them) using various systems including a customer relationship management system (the “Mail International CRM”).

The collection of personal data regarding business and corporate contacts (including any communications they send us containing personal contact info) and the addition of that personal data to the Mail International CRM or other systems will only be initiated by an authorised user and will include contact name, employer name, contact title, phone, email and any other relevant other business contact details. It may be collected in varying ways including e-mail, telephone or other oral forms, in writing or from business cards. Additionally it may be supplied by a third-party (i.e. a company working with the client to deliver part of the service).

Mail International systems collecting and storing contact data include for example:

  • E-mail system and built in contacts facility
  • Accounting and Financial Management Software
  • Purchase ordering systems
  • Sales and lead management systems
  • Marketing systems including e-marketing
  • Third-party systems such as credit profiling and risk management software
  • Off-line (i.e. paper based business cards)

Use of Personal Data

Personal data relating to business contacts may be visible to and used by Mail International users to deliver a service or to learn more about an account, client or opportunity they have an interest in. Permitted uses of business contact information include for example:

  • Providing professional services – We provide a diverse range of professional services. Some of our services require us to process personal data in order to provide advice and deliverables.
  • Administering, managing and developing our services
  • Providing information about us and our range of services
  • Making contact information available to Mail International users
  • Identifying clients/contacts with similar needs
  • Describing the nature of a contact’s relationship with Mail International
  • Performing analytics, including producing metrics for Mail International leadership, such as on trends,relationship maps, sales intelligence and progress against business goals
  • Security – We have security measures in place to protect our and our clients’ information (includingpersonal data), which involve detecting, investigating and resolving security threats. Personal data maybe processed as part of the security monitoring that we undertake
  • Quality and risk management activities which may require us to process personal information includingvia third-parties who may host and store that data externally to Mail International.
  • Complying with any requirement of law, regulation or a professional body of which we are a member -As with any provider of professional services, we are subject to legal, regulatory and professional obligations.

We need to keep certain records to demonstrate that our services are provided in compliance with those obligations and those records may contain personal data.

Any personal data or information may be collected, processed and stored in a physical or digital form.

Mail International does not sell or otherwise release personal data contained in the Mail International CRM or associated to third parties for the purpose of allowing them to market their products and services without consent from individuals to do so.

Data Retention

Personal data will be retained within the Mail International CRM and associated systems for as long as it is considered necessary for the purposes set out above (e.g. for as long as we have, or need to keep a record of, a relationship with a business contact) or as required by any applicable law or regulation and in order to establish, exercise or defend our legal rights.

Additionally, as part of a system backup and recovery policy, supplier contact info will be backed up and this may include cloud storage and portable media.

How you can access and update your information

The accuracy of your information is important to us. We’re working on ways to make it easier for you to review and correct the information that we hold about you. In the meantime, if you change your email address, or any of the other information we hold is inaccurate or out of date, please direct any changes to our client services team at [email protected]. Alternatively you can write to us at: Client Services, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND.

You have the right to ask for a copy of the information Mail International hold about you and any such queries should be sent to [email protected] or in writing to The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom. Making a request for personal data or information is free but we may levy a charge where requests are unfounded, excessive or repetitive in nature. Mail International will comply with the data subject’s access request within 1 month from receipt.

Your Communication Choices

You have a choice about whether or not you wish to receive information from us. Whilst the processing of personal data for communications purposes is primarily in order for us to deliver or establish a contract or service, we do also send information and communications that promote the services we offer as well as informational updates (i.e. service alerts or newsletters).

We will state the reason why we are collecting your personal information at the point of collection and we will ask for your consent if we wish to use this for any purpose other than for which it was given. Additionally, where we legitimately process your personal data in order to send you communications for marketing purposes, we will provide an in-communication opt-out or link to update your communications preferences accordingly.

Communications (containing personal data other than contact info)

In addition, Mail International may receive personal data other than contact information from our clients during our relationship and through providing our services to them. Where other personal data or information is shared with us by a client through any form of communication, we ask our clients to ensure that the client has the appropriate authority to provide this information to us. We also ask, and assume, that any consent or required permissions regarding the personal data in the communications have been obtained for the purpose in which it is being used.

Mail International will not use any of this additional personal data outside of the purpose for which it was provided to us. If we wish to use the data beyond this purpose we will directly seek permission from the client and/or person who sent us the information.

For more information regarding this please see the section on ‘Individuals whose personal data we obtain in connection with providing services to our clients’.

2. Personal clients

Personal clients

Collection & Use of Personal Data

Mail International is a business to business organisation and as such does not generally deal with non- business individuals as clients.

In the event that we do provide services for an individual representing themselves or a business trading via a sole trader arrangement etc. we will treat that personal data in the same way as for our business clients. This includes how we collect, process and retain information. In doing so however, we will take account of the of the fact that the client may well be classed as an individual and not an organisation and, where relevant, we will apply any current or future variation that may exist in regulation or law in how we handle your data and communicate with you. For example, if future regulations ask that we treat individual communications to non-businesses differently than for businesses, we will apply these rules.

Mail International does not sell or otherwise release personal data contained in the Mail International CRM or associated to third parties for the purpose of allowing them to market their products and services without consent from individuals to do so.

How you can access and update your information

The accuracy of your information is important to us. We’re working on ways to make it easier for you to review and correct the information that we hold about you. In the meantime, if you change your email address, or any of the other information we hold is inaccurate or out of date, please direct any changes to our client services team at [email protected]. Alternatively you can write to us at: Client Services, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom.

You have the right to ask for a copy of the information Mail International about you and any such queries should be sent to [email protected] or in writing to The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND. Making a request for personal data or information is free but we may levy a charge where requests are unfounded, excessive or repetitive in nature. Mail International will comply with the data subject’s access request within 1 month from receipt.

Your Communication Choices

You have a choice about whether or not you wish to receive information from us. Whilst the processing of personal data for communications purposes is primarily in order for us to deliver or establish a contract or service, we do also send information and communications that promote the services we offer as well as informational updates (i.e. service alerts or newsletters).

We will state the reason why we are collecting your personal information at the point of collection and we will ask for your consent if we wish to use this for any purpose other than for which it was given. Additionally, where we legitimately process your personal data in order to send you communications for marketing purposes, we will provide an in-communication opt-out or link to update your communications preferences accordingly.

3. Individuals whose personal data we obtain in connection with providing services to our clients

Individuals whose personal data we obtain in connection with providing services to our clients

Collection & Use of Personal Data

Our policy is to collect (from clients) only the personal data necessary for agreed purposes and to enable us to deliver the services required by the client. We ask our clients only to share personal data with us where it is strictly needed and that the client should supply the minimum amount of personal data required. If Mail International are sent personal data or information beyond what is needed, we reserve the right to remove the unnecessary data or information from any or all of our systems.

Where an individual’s personal data or information is shared with us by a client, we ask our clients to provide the necessary information to the data subjects regarding its use and ensure that the client has the appropriate authority to transfer the information to us. We also ask and assume that any consent or required permissions required from data subjects have been obtained. We also ask all clients and third- parties to adhere to our Transfer of Personal Data and Information Policy when sending us personal data or information which will have been sent to all clients and is available from [email protected] or from us in writing at the provided address below.

Given the diversity of the services we provide to our clients we collect and process many categories of personal data, including:

  • Individuals contact details (i.e. name, address, telephone no. and other personal contact data)
  • Personal data or information relating to an individual that enables them to be grouped or categorised.For example, income, council tax band etc.
  • Any other personal data or information needed for us to deliver our services or carry out our businessactivities
  • Individuals personal data supplied to us in order for the client and us to manage or assess serviceprovision or quality or to investigate service issues/complaints
  • Individuals associated with the client (controller) supplied for efficiency and effectiveness of serviceprovision and delivery (i.e. other processors or third-parties utilised by the client). Please also see thesection on Business and Corporate Clients within this notice.
  • Payroll or other financial-related details required so we can deliver the financial aspects of our businessactivities.

We may also process an individual’s personal data or information in order to:

  • Administering, managing and developing our businesses and services
  • Security, quality and risk management activities
  • Complying with any requirement of law, regulation or a professional body of which we are a memberPlease see the Business and Corporate Clients section for further explanation of these.Any personal data or information may be collected, processed and stored in a physical or digital form.We are continually looking for ways to help our clients and improve our business and services. Where agreed with our clients or with the data subjects directly if we are the controller, we may use information that we receive in the course of providing professional services for other lawful purposes. These include: analysis to better understand a particular issue, industry or sector, provide insights back to our clients, to improve our business, service delivery and offerings and to develop new Mail International technologies and offerings.

Data Retention

We retain the personal data processed by us for as long as is considered necessary for the purpose for which it was collected (including as required by applicable law or regulation) or for as long as specified by the controller (i.e. a client) in the form of a contract or other communication in writing.

Additionally, as part of a system backup and recovery policy, individual personal data and information will be backed up and this may include cloud storage and portable media.

How you can access and update your information

Where Mail International is the processor, we will endeavour, where possible and where we have the individual’s consent, forward your details to the appropriate controller (i.e. the relevant client) or direct you to them accordingly. Mail International will support our clients in maintaining their commitment to GDPR and any other regulatory or legal framework.

Where we are the controller and have directly collected your information, you can direct any amendments or changes to your personal information to our client services team if you are a client or to our Data Protection Officer in all other instances. Our client services team can be contacted at [email protected] and the Data Protection Officer at [email protected]. Alternatively you can write to the relevant contact at: Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom.

You also have the right to ask for a copy of the information Mail International about you. Where Mail International is not the controller but only a processor, we will, where possible and where we have the individual’s consent, forward your details to the appropriate controller (i.e. the relevant client) or direct you to them accordingly. Where we are the controller and have directly collected your information, you should contact our Data Protection Officer at [email protected]. Alternatively you can write to us at The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom. Making a request for personal data or information is free but we may levy a charge where requests are unfounded, excessive or repetitive in nature. Mail International will comply with the data subject’s access request within 1 month from receipt.

4. Individuals who use our Applications

Individuals who use our Applications

We provide external users access to various applications managed by us. Such applications will contain their own privacy statements explaining why and how personal data is collected and processed by those applications. Some of these applications (and the data they use and store) are provided and hosted by third-parties and we encourage individuals using our applications to refer to the privacy statements available on those applications.

Collection of Personal Data

All applications are for registered client users only and require the collection and storage of personal data in order to function. Depending on the application, the exact amount of personal data required will vary but will always include personal details of the client user to be registered. It may also include details of individuals provided by the client – for example, names, addresses, telephone numbers for deliveries in the stock management system by the client.

All systems enable registered users to add, remove or edit the majority of their (and their customers) information that is held in these applications and we encourage our clients to effectively manage the data they are responsible for as to ensure compliance with their own privacy policies , their customer’s expectations and any legal and regulatory framework in place.

Application’s available to external users which collect or store personal information include:

  • Stock management web-based application
  • Web-based secure file sharing website including FTP, desktop and e-mail transfer functionality
  • E-commerce stock, order and fulfilment web-based portal

Cookies

These applications may use small text files called ‘cookies’. Cookies are usually small text files, given ID tags that are stored on your computer’s browser directory or program data subfolders. Cookies are created when you use your browser to visit a website that uses cookies to keep track of your movements within the site, help you resume where you left off, remember your registered login, theme selection, preferences, and other customization functions. The use of cookies is now standard operating procedure for most websites and web-based services. However if you are uncomfortable with the use of cookies, most browsers now permit users to opt-out of receiving them.

Depending on the application you wish to use, you may need to accept cookies in order to use the application. These additional services are for registered users only and require a login. By disabling cookies for these services you may find functionality in the web-based application impaired or non-functional.

After you finish using an application you can always delete the cookie(s) from your system if you wish. You can find out more about the cookies used by these applications within each application or by contacting our Data Protection Officer at [email protected].

Use of Personal Data

Our applications use the personal data (of our registered clients and of individuals provided by those clients) for the varying purposes including:

  • To validate and authenticate login details and user details
  • To provide access and activity logs (application dependent) for security purposes
  • To provided notifications
  • To provide the services required by the client – for example submitting order and personal details through our E-commerce portal so we can fulfil and distribute the order
  • To securely transfer information and personal data between us and the client, including via automated processing
  • To enable clients to manage their stock and movements of that stock
  • Any personal data or information may be collected, processed and stored in a physical or digital form.

Data Retention

Different applications retain data for different periods. The length the data is retained for depends upon the nature of the application and what is being used for.

As a guide, our secure file transfer system only retains uploaded files for a maximum period of 30 days from upload and any files stored within the facility can be deleted by Mail International or by authorised and registered client users at any time before that. The deletion policy in this application is automated and can only be varied under specific agreement (in writing) with the client. Login, user and user preferences are retained as long as application access is still required by the user. Should a user wish to stop use of the application and/or remove any or all of the files stored, they should contact their appropriate account manager.

All other applications store login, user and user preferences along with any personal data collected by the client (or by Mail International on their behalf) indefinitely as long as the need still exists. This will be until the client (on behalf of any of their registered users) informs us otherwise or until they themselves remove any data.

5. Suppliers to Mail International (Including Sub-contractors and Individuals Associated with our Suppliers and Sub-contractors) .

Suppliers to Mail International (Including Sub-contractors and Individuals Associated with our Suppliers and Sub- contractors)

Collection of Personal Data

We collect and process personal data about our suppliers (including subcontractors and individuals associated with our suppliers and subcontractors) in order to manage the relationship, contract, to receive services from our suppliers and, where relevant, to provide professional services to our clients.

We engage these third-party service providers to perform a variety of business operations on our and our or our client’s behalf. In doing so, we may share this personal information or the personal data you have provided to us in order to deliver the service required and for the purpose specified by us or by our client.

Mail International Ltd collects and processes personal data about our suppliers (including subcontractors and individuals associated with our suppliers and subcontractors) and the communications they send us using various systems. The addition of that personal data to those systems will only be initiated by an authorised user and will include contact name, employer name, contact title, phone, email and any other relevant other business contact details.

Systems include for example:

  • E-mail system and built in contacts facility
  • Accounting and Financial Management Software
  • Purchase ordering systems
  • Sales and lead management systems
  • Marketing systems including e-marketing
  • Third-party systems such as credit profiling and risk management software

Use of Personal Data

We use the personal data of our suppliers (including subcontractors and individuals associated with our suppliers and sub-contractors personal data for the following purposes:

  • Providing professional services – We provide a diverse range of professional services. Some of our services require us to process personal data in order to provide advice and deliverables.
  • Administering, managing and developing our services
  • Providing information about us and our range of services
  • Making contact information available to Mail International users
  • Identifying clients/contacts with similar needs
  • Describing the nature of a contact’s relationship with Mail International
  • Performing analytics, including producing metrics for Mail International leadership, such as on trends,relationship maps, sales intelligence and progress against business goals
  • Security – We have security measures in place to protect our and our clients’ information (includingpersonal data), which involve detecting, investigating and resolving security threats. Personal data maybe processed as part of the security monitoring that we undertake
  • Quality and risk management activities which may require us to process personal information includingvia third-parties who may host and store that data externally to Mail International.
  • Complying with any requirement of law, regulation or a professional body of which we are a member -As with any provider of professional services, we are subject to legal, regulatory and professional

obligations. We need to keep certain records to demonstrate that our services are provided in compliance with those obligations and those records may contain personal data.

Any personal data or information may be collected, processed and stored in a physical or digital form.

Data Retention

Supplier personal data (including that of subcontractors and individuals associated with our suppliers and subcontractors) will be retained within the Mail International systems for as long as it is considered necessary for the purposes set out above (e.g. for as long as we have, or need to keep a record of, a relationship with a supplier or associated contact) or as required by any applicable law or regulation and in order to establish, exercise or defend our legal rights.

Additionally, as part of a system backup and recovery policy, supplier contact info will be backed up and this may include cloud storage and portable media.

How you can access and update your information

The accuracy of your information is important to us. We’re working on ways to make it easier for you to review and correct the information that we hold about you. In the meantime, if you change your email address, or any of the other information we hold is inaccurate or out of date, please direct any changes to our client services team at [email protected]. Alternatively you can write to us at: Client Services, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom.

You have the right to ask for a copy of the information Mail International about you and any such queries should be sent to [email protected] or in writing to The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom. Making a request for personal data or information is free but we may levy a charge where requests are unfounded, excessive or repetitive in nature. Mail International will comply with the data subject’s access request within 1 month from receipt.

Your Communication Choices

You have a choice about whether or not you wish to receive information from us. Whilst the processing of personal data for communications purposes is primarily in order for us to deliver or establish a contract or service, we do also send information and communications that promote the services we offer as well as informational updates (i.e. service alerts or newsletters).

We will state the reason why we are collecting your personal information at the point of collection and we will ask for your consent if we wish to use this for any purpose other than for which it was given. Additionally, where we legitimately process your personal data in order to send you communications for marketing purposes, we will provide an in-communication opt-out or link to update your communications preferences accordingly.

6. Transfer of Personal Data to Third-Parties

Transfer of Personal Data to Third-Parties

Mail International takes the security of personal data very seriously and we only provide our third-party service providers with the personal information they need in order to perform the services we request.

For example, we may use a third-party service provider to:

  • Provide tracked courier or mail delivery services worldwide
  • Provide specialist data services
  • Provide specialist or high volume personalised printing services

Where data is supplied to third-parties, this will only be to those third-parties we, and in turn, our clients have authorised. Mail International hold a list of all third-party providers which details where they are based, what type of service they provide, the type of personal data being transferred along with, where possible, a link to the third-parties privacy policy. This list can be obtained by contacting our data protection officer at [email protected] or in writing to The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom.

Where we send personal data or information to a third-party, we require that they protect this information appropriately and not use it for any other purpose than the one specified. We will only send the minimum amount of personal data of information needed in order for the third-party to deliver the service we and/or our clients are asking them to deliver. Where data is transferred to third-parties, this must be in accordance with our Transfer of Data & Personal Information Policy and any aspect of this Privacy Statement.

We also require most suppliers to sign a Privacy & Confidentiality Agreement and a copy of this agreement can be obtained by contacting our Data Protection Officer whose details are listed above. We do utilise third-parties where such an agreement is not in place but this is ordinarily isolated to national post offices or similar state-owned or multinational suppliers who issue universal terms of service and do not sign individual agreements. In these circumstances we make an assessment of the policies they have in place and the type of personal data or information they may need to access. We encourage all clients to read the privacy policies of the third-parties we utilise and, where possible, a link to these is contained on the list of third-parties that can be obtained from our Data Protection Officer. We be will appending this list of third- party suppliers in due course to also show who has and who hasn’t signed and returned our Privacy and Confidentiality Agreement.

Please be aware that whilst we endeavour to list all third-parties we deal with, some third-parties we utilise may in turn utilise sub-contractors themselves. For example, we may contract a major logistics provider to deliver freight from the UK to Germany but they may in turn sub-contract a German based logistics company for all or part of the line-haul and delivery. Any personal data regarding the shipment and its delivery will therefore be passed on by the contracted third-party to the sub-contracted company. We ask all third-parties who sign our Privacy and Confidentiality Agreement to ensure that where this occurs any subcontractor adheres to the terms agreed between us and the third-party.

All persons, whether we are acting as a controller or processor, have the right to object to the use of any particular third-party. To do so, please contact our data protection officer on the contact details above and we can remove your personal data from being processed by that third-party (NB. this may have an impact on the cost or on our ability to perform the required services).

7. Transferring your Information Outside of the United Kingdom

Transferring your Information Outside of the United Kingdom

In the course of providing, delivering and administering our services, we may store, process or transfer personal data to third-parties outside of United Kingdom (UK). By way of example, this may happen if any of our servers are from time to time located in a country outside of the UK or we transfer personal data to a third-party partner outside of the UK. Where data is transferred to third-parties, this must be in accordance with our Transfer of Data & Personal Information Policy and any aspect of this Privacy Notice.

These countries may not have similar data protection laws to the UK. By submitting personal data to Mail International, you are agreeing to and authorising the transfer, storing or processing of this information outside of the EU including to the third-parties utilised by us. Mail International hold a list of all third-party providers which details where they are based, what type of service they provide, the type of personal data being transferred along with, where possible, a link to the third-parties privacy policy. This list can be obtained by contacting our data protection officer at [email protected] or in writing to The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom.

We may also utilise third-parties who are based within the EU but who may have a need to transfer any supplied personal data or information outside of the EU. For example, we may utilise a UK based supplier to send a tracked parcel to Australia. Whilst the third-party service provider is based in the UK, the personal data will need to be sent to Australia in order for the parcel to delivered and for any customs or delivery processes to be carried out. Additionally, part of this process may be carried out by a party contracted by the supplier or service provider we are utilising. We therefore encourage all clients to read the appropriate privacy policies of these third-parties in order to ensure their personal data, or the personal data they are responsible for, is treated in-line with their expectations. By agreeing to this policy, and assuming no objection has been raised by the controller or by the data subject (where we are the controller) you understand and agree to this process.

As stated in the previous section, you have the right to object to the use of any particular third-party. To do so, please contact our data protection officer on the contact details above and we can remove your personal data from being processed by that third-party (NB. this may have an impact on the cost or on our ability to perform the required services).

Where Mail International is the controller and where we intend to transfer personal data outside of the EU, we acknowledge that such transfers must ensure a “level of protection for the fundamental rights of the data subjects”. In this instance one or more of the following safeguards must be applied. As a processor on behalf of another controller (i.e. a client), Mail International assumes that the controller has made their own appropriate assessment in line with GDPR and any other regulatory or legal framework.

An adequacy decision – The European Commission can and does assess third countries, a territory and/or specific sectors within third countries to assess whether there is an appropriate level of protection for the rights and freedoms of natural persons. In these instances, no authorisation is required. The UK has adequacy regulations regarding the following countries and territories:

  • Members of the European Economic Area (EEA), which comprise EU Member States and EFTA States
  • EU or EEA Institutions, bodies, offices or agencies
  • Gibraltar
  • Countries covered by the European Commission’s Adequacy Decisions

Assessment of adequacy by the data controller – In assessing adequacy, the UK based exporting controller should take account of the following factors:

  • the nature of the information being transferred;
  • the country or territory of origin, and final destination, of the information;
  • how the information will be used and for how long;
  • the laws and practices of the country of the transferee, including relevant codes of practice and international obligations; and the security measures that are to be taken about the data in the overseas location.

Binding corporate rules – Mail International can use approved binding corporate rules for the transfer of data outside the EU. This requires submission to the supervisory authority for approval of the rules that the company is to rely on.

Model contract clauses – Mail International can use approved model contract clauses for the transfer of data outside of the EEA. If the business uses model contract clauses approved by the supervisory authority there is an automatic recognition of adequacy.

Exceptions – In the absence of any of the above a transfer of personal data to a third country or international organisation can only take place on one of the following conditions:

  • the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks with regards to the absence of an adequacy decision and appropriate safeguards;
  • the transfer is necessary for the performance of a contract between the data subject and the controller or the implementation of pre-contractual measures taken at the data subject’s request;
  • the transfer is necessary for the conclusion or performance of a contract between the controller and another natural or legal person in the interest of the data subject;
  • the transfer is necessary for important public interest reasons;
  • the transfer is necessary to establish, exercise or defend a legal claim; and/or the transfer is necessary to protect the vital interests of the data subject or other persons, where the data subject is physically or legally incapable of giving consent.

For those who communicate with us or access our applications and/or website from outside of the European Union, please be aware that this may mean that any personal data or information you access may be transferred outside the EU.

8. Physical items Containing Personal Data or Information

Physical items Containing Personal Data or Information

As a supplier of mailing and distribution services, we will be required to post or distribute physical items of mail, goods or the like and these are likely to have a physical copy of personal data and/or information affixed to them or contained within them. As an accredited ISO 27001 (Information Security) company, Mail International have a physical site security policy in place to protect physical items and we expect the same of any third-party we utilise. These physical items may ultimately be distributed globally beyond the control of Mail International. For example, we may send a mailing to persons in the USA. The final handling, processing and delivery of these items would be carried out in the main by the United States Postal Service (USPS) and we would have no control over the physical item or the personal data or information contained on or within it.

9. Visitors to our Website

Visitors to our Website

Collection of Personal Data

Visitors to our websites are generally in control of the personal data shared with us. We may capture limited personal data automatically via the use of cookies on our website. Please see the section on Cookies below for more information.

Our company website is www.mailint.com. We receive personal data, such as name, title, company address, email address, and telephone numbers, from website visitors; for example when an individual subscribes to updates from us or requests contact or information through our contact form.

Visitors are also able to send an email to us through a website link. The website link will open up a blank e- mail in the users own e-mail software and it is up to the user what information they provide us with in that e-mail.

We ask that you do not provide sensitive information to us when using our website; if you choose to provide sensitive information to us for any reason, the act of doing so constitutes your explicit consent for us to collect and use that information in the ways described in this privacy statement or as described at the point where you choose to disclose this information.

Cookies

These applications may use small text files called ‘cookies’. Cookies are usually small text files, given ID tags that are stored on your computer’s browser directory or program data subfolders. Cookies are created when you use your browser to visit a website that uses cookies to keep track of your movements within the site, help you resume where you left off, remember your registered login, theme selection, preferences, and other customization functions. The use of cookies is now standard operating procedure for most websites and web-based services. However if you are uncomfortable with the use of cookies, most browsers now permit users to opt-out of receiving them.

You do not need to accept cookies in order to use our company website (www.mailint.com) but you may need to accept them if you use one of our web-based services for registered business clients which are referenced and linked to on the company site (i.e. our secure file transfer website, stock management website and our cloud based e-commerce portal). These additional services are for registered users only and require a login. By disabling cookies for these services you may find functionality in the website service impaired. After termination of the visit to our site, you can always delete the cookie from your system if you wish.

You can find out more details regarding our use of cookies on our website under the Privacy section and to find out more details regarding our web-based services for registered business users please see the ‘Individuals who use our applications’ section of this notice.

Use of Personal Data

When a visitor provides personal data to us, we will use it for the purposes for which it was provided to us as stated at point of collection (or as obvious from the context of the collection). Typically, personal data is collected to:

Register for certain areas of the site; Subscribe to updates;
Enquire for further information; Distribute requested materials;

  • Submit curriculum vitae;
  • Monitor and enforce compliance with our terms and conditions for use of our website;
  • Administer and manage our website, including confirming and authenticating identity and preventingunauthorised access to restricted areas, premium content or other services limited to registered users;and
  • Aggregate data for website analytics and improvements.

Unless we are asked not to, we may also use your data to contact you with information about PwC’s business, services and events, and other information which may be of interest to you. Should visitors subsequently choose to unsubscribe from mailing lists or any registrations, we will provide instructions on the appropriate webpage, in our communication to the individual, or the individual may contact us by email to [email protected].

Our websites do not collect or compile personal data for the dissemination or sale to outside parties for consumer marketing purposes or host mailings on behalf of third parties. If there is an instance where such information may be shared with a third party for these purposes, the visitor will be asked for their consent beforehand.

Combined Information: We may combine personal data or information obtained through our website with other information we collect or obtain about you (such as information from e-mail updates or other marketing activities or data we source from our third party partners). This allows us to better serve you and deliver products or services according to your preferences or restrictions, or for advertising or targeting purposes in accordance with this Privacy Statement. When we combine Personal Information with other information in this way, we treat it as, and apply all of the safeguards in this Privacy Statement applicable to, Personal Information.

Our website may also contain links to third party websites and/or social media platforms and widgets. Additionally, our website may utilise social media features such as the facebook like button. Please see the section below entitled ‘Links to other websites’ within this notice for further information on these and how they use personal information.

Any personal data or information may be collected, processed and stored in a physical or digital form.

Data Retention

Personal data collected via our website will be retained by us for as long as it is necessary (e.g. for as long as we have a relationship with the relevant individual) or until the relevant individual requests this data is no longer retained. You can request that we no longer retain your personal data by contacting our Data Protection Office at [email protected] or in writing to us at The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom.

10. Links to other Websites and Features

Links to other Websites and Features

Third-Party Websites

Our website may contain links to other websites run by other organisations. This Privacy Statement applies only to our website‚ so we encourage you to read the privacy statements on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website.

In addition, if you linked to our website from a third party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third party site and recommend that you check the policy of that third party site.

Social Media Platforms and Widgets

Our website may include social media features or link to either our or others social media pages or platforms. These features or platforms may collect information about your IP address and your activity and they may set a cookie to make sure any feature functions properly. Social media features and widgets are either hosted by a third party or hosted directly on our Website. We also maintain presences on social media platforms including LinkedIn. Any information, communications, or materials you submit to us via a social media platform is done at your own risk without any expectation of privacy. We cannot control the actions of other users of these platforms or the actions of the platforms themselves. Your interactions with those features and platforms are governed by the privacy policies of the companies that provide them.

11. Visitors to our Offices

Visitors to our Offices

We have security measures in place at our facility, including CCTV and building access controls.

There are signs in our office showing that CCTV is in operation. The images captured are securely stored and only accessed on a need to know basis (e.g. to look into an incident). CCTV recordings are typically automatically overwritten after a short period of time unless an issue is identified that requires investigation (such as theft).

We require visitors to our offices to sign in at reception and complete a confidentiality agreement for visitor’s form, which we keep for our records. Our visitor records are securely stored and only accessible on a need to know basis (e.g. to look into an incident).

12. Staff

Staff

We collect personal data concerning our own staff as part of the administration, management, delivery, security and promotion of our business activities as well for the administration of personnel, human resources and payroll functions.

We may also collect information with regards to contract, temporary and casual workers who work for Mail International but in the employment of another company.

Any personal data or information may be collected, processed and stored in a physical or digital form.

All staff should refer to appropriate section of the Employee Handbook for information on why and how personal data is collected and processed.

13. Recruitment Applicants

Recruitment Applicants

When applying online for a role at Mail International via e-mail, in writing or via the Mail International website, applicants should refer to the information made available when applying for a job for details about why and how personal data is collected and processed.

For more detail about our recruitment processes, please visit the recruitment page on our website.

14. Others who get in touch with us

Others who get in touch with us

We collect personal data when an individual gets in touch with us with a question, complaint, comment or feedback (such as name, contact details and contents of the communication). In these cases, the individual is in control of the personal data shared with us and we will only use the data for the purpose of responding to the communication. Any personal data or information may be collected, processed and stored in a physical or digital form.

If an individual contacts us regarding one of our clients or raises issues relating not to us but our clients and their activity, we will direct the individual to the appropriate method of contact for that client, or if permissible, pass this information on to the client.

15. Further Processing

Further Processing

If we wish to use your personal data for a new purpose, not covered by this Data Privacy Statement, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions.

16. Security

Security

Mail International is an ISO 27001 accredited company and takes the security of all information (including personal data) very seriously. ISO 27001 is an international standard that lays out the requirements for an organisation wide Information Security Management System. This system is independently audited every 12 and comprises numerous policies and practices to ensure the integrity and security of the data and information we hold. All personal data is only accessible by those who need to use it and this access provision is both approved and managed in line with these policies.

As part of our information management system, we also have incident management and continuity polices in place that can be enacted in the event of a suspected or actual security breach or other critical event.

We ask all clients and third-parties to adhere to our Transfer of Personal Data and Information Policy when sending us personal data or information which will have been sent to all clients and is available from [email protected] or from us in writing at the provided address below.

Mail International always look to proactively to prevent security events and we work with all of our clients to assist them in working with us securely, especially in regard to the transfer of personal data between companies. We do not transfer any personal data or information to unauthorised persons or third-parties.

17. How to Make a Complaint?

How to Make a Complaint?

To exercise all relevant rights, queries or complaints please in the first instance contact the Mail International Data Protection Officer via email at: [email protected], or write to us at: The Data Protection Officer, Mail International Ltd, Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND, United Kingdom.

If this does not resolve your complaint to your satisfaction, you have the right to lodge a complaint with the Information Commissioners Office on 03031231113 or via email https://ico.org.uk/global/contact- us/email/ or at the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, England.

18. Review of this Privacy Statement

Review of this Privacy Statement

This Privacy Statement will be reviewed at least annually or when any major change occurs. This is to ensure it accurately reflects the privacy policies and agreements in place at Mail International or those made with our clients and third parties (i.e. suppliers). It will also be reviewed to ensure compliance with any statutory or regulatory regime in force within the United Kingdom.

Any changes we may make to our Privacy Statement in the future will be posted via an updated Privacy Statement which will be published on our website and, where available, notified to individuals in writing via e-mail. The most recent version of this Privacy Statement will always be available on our website so please check back frequently to see any updates or changes.

Addendum 1 - Definitions.

Addendum 1 – Definitions

Article 2 – The General Data Protection Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.

Article 3 – The General Data Protection Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

Binding corporate rules – Personal data protection policies which are adhered to by a controller or processor and that have been established in the location of the Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity.

Consent – Any freely given, specific, informed and unambiguous indication of the data subject’s wishes to the processing of personal data relating to him or her.

Controller – The natural or legal person, public authority, agency or other body which, alone or jointly determines the purposes and means of the processing of personal data.

Enterprise – A natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.

Group of undertakings – A controlling undertaking and its controlled undertakings.
International organisation – An organization and its subordinate bodies governed by public international

law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.

Version No. 1.0 Last Amended 1st May 2018 Page | 22

Main establishment – The location of the controller’s central administration in the Union, if the operation spans more than one-member state, unless the decisions on the purposes and means of the processing of personal data are taken in another of the controller’s establishments in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be the main establishment.

The location of the processor’s central administration in the Union, if the operation spans more than one- member state, unless the processor has no central administration in which case it will be he location of the main processing activities in the context of the processor’s activities.

Personal Data – Any information relating to an identified or identifiable natural person; one who can be identified, directly or indirectly by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Personal data breach – A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Processing – Any operation/s which is/are performed on personal data, by automated means or not, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Processor – A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Profiling – Any form of automated processing of personal data incorporating the use of personal data to evaluate certain personal aspects relating to a natural person to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

Recipient – A natural or legal person, public authority, agency or another body, to which the personal data are disclosed. Public authorities who receive personal data in the framework of an inquiry in accordance with Union or Member State law shall not be regarded as recipients.

Relevant and reasoned objection – An objection as to whether there is an infringement to the Regulation, or whether the envisaged action in relation to the controller or processor complies with the Regulation, which clearly demonstrates the significance of the risks posed by the draft decision regarding the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union.

Representative – A natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor regarding their respective obligations.

Restriction of processing – Marking of stored personal data with the aim of limiting their processing in the future.

Supervisory authority – An independent public authority which is established by a Member State pursuant to Article 51.

Third party – A natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

Call Us

Call us for more information:

+44 (0) 1444 871111

Email Us

Email us at:

[email protected]

Find Us

See our location:

Click Here!

Brochure

Download our latest brochure:

Click Here!

About us

A leading independent mailing company, we specialise in fulfilment and world wide delivery solutions for mail.

Our Accreditations
Our Testimonials

Company Details

Mail International Ltd.

Registered office:
Braybon Business Park, Consort Way, Burgess Hill, West Sussex, RH15 9ND
Company Number: 1923564, England

Contact Us

Call:
+44 (0) 1444 871111

Email:
[email protected]

FIND US

linkedin

© 2024 Mail International

Web Design by Alphanet