Athena PTS Website Privacy Notice

This notice explains how Athena Professional Technical Services Limited (“Athena PTS”) collects, uses, shares and protects the personal information of people who visit athena-pts.co.uk and interact with us online, and the rights you have over your data.

Athena Professional Technical Services Limited is incorporated in England and Wales, company number 07708468. Registered office: Artemis House, 6-8 Greek Street, Stockport, SK3 8AB.

What’s in this notice

  1. Introduction
  2. Who we are and our registrations
  3. Children’s personal data
  4. What we mean by personal information
  5. The information we collect
  6. How we collect your information
  7. Our lawful basis for processing
  8. Who we share your information with
  9. Transfers outside the UK
  10. Keeping your information secure
  11. How long we keep it
  12. Your rights
  13. Automated decision-making
  14. How to contact us or complain
  15. Data Processing Schedule

 

Introduction

We are Athena Professional Technical Services Limited (“Athena PTS”). We are the data controller responsible for the personal information described in this notice, that is, personal information collected through our website and your online interactions with us. When we say “we”, “us”, “our” or “Athena PTS”, we mean Athena Professional Technical Services Limited.

Athena PTS is part of OCU Group, which means we align our data protection governance with OCU Group and other companies within the Group, and we may share data within the Group as explained in this notice.

There are several companies within the OCU Group. Athena PTS is the sole controller for the personal information collected through this website. Where you have a specific relationship with us or with another OCU Group company, for example as a client, supplier, business contact, employee, driver, operative or job applicant, a dedicated privacy notice applies to that relationship and takes precedence for that processing. You can request a copy of any of these notices from our Data Protection Officer.

We may update this notice from time to time to reflect changes in law or in how we use personal information. The version published on this page is the current version, and we will show the date of the latest update above.

  1. Who we are and our registrations

In the UK, the Information Commissioner’s Office (ICO) is our data protection supervisory authority.

Company registration: Athena Professional Technical Services Limited, incorporated in England and Wales. Company number 07708468. Registered office: Artemis House, 6-8 Greek Street, Stockport, SK3 8AB.

Data protection registration: Data controller: Athena Professional Technical Services Limited. ICO registration reference: ZA480014. Other OCU Group companies hold their own ICO registrations, which we can provide on request.

  1. Children’s personal data

Our website and services are aimed at businesses and adults. They are not directed at anyone under 18, and we do not knowingly collect personal data from children. If you are a parent or guardian and believe a child has provided us with their personal data, please contact our Data Protection Officer using the details in section 14 and we will delete it.

  1. What we mean by personal information

Under the UK GDPR, personal information (or personal data) means any information relating to an identified or identifiable living individual. That is a broad scope: it covers anything from a name or email address to technical data such as an IP address. If information can identify you, directly or indirectly, it is personal data.

We only collect personal information that is lawful, relevant and proportionate to our relationship with you. You can browse our website without registering or submitting personal information. You are not obliged to provide us with any personal information; however, if you choose not to provide certain information, we may not be able to respond to your enquiry or provide a service.

  1. The information we collect

The categories of data we may collect through the website are set out below. How and why we use each one, and our lawful basis, is set out in the Data Processing Schedule at the end of this notice.

Category What it can include
Identity information Name, title and job title
Contact information Email address, telephone number, postal address and social media handles
Technical data IP address, browser type and version, time zone settings, device information and similar data about the technology you use to access our website
Usage data How you use our website, including pages visited and interactions, collected through cookies and similar technologies (see our Cookie Policy)
Marketing & communications data Your communication preferences, such as how and when you would like us to contact you
Work and role-specific information If you contact us on behalf of your organisation, information relevant to your role, such as your employer and job function
Transactional & financial information Billing addresses, payment details and transaction records where you or your organisation buy from us or we issue invoices
Content you submit Reviews, comments, enquiry details or other content you choose to send us

Special category and criminal offence data. We do not collect special category data (such as health or biometric data) or criminal offence data through this website. Where Athena PTS processes that kind of information, for example in recruitment, employment or worker engagements, it is covered by the dedicated privacy notice for that relationship, which explains the additional legal conditions we rely on.

  1. How we collect your information

Information you give us

  • When you visit our website or use our online platforms (see our Cookie Policy for cookies and similar technologies)
  • When you sign up for newsletters or mailing lists
  • When you contact us by phone, email, contact form or social media
  • When you attend events or training sessions we organise
  • When you appear in photos or videos we take at our events
  • When you apply for a job or send us your CV (see our Recruitment Privacy Notice)
  • When you or your organisation buys something from us, or you submit personal data for any other reason

Information provided by others

  • From third parties such as marketing agencies acting for us
  • From publicly available sources such as Companies House or professional networking sites
  • If you apply for a job, references from previous employers (covered by our Recruitment Privacy Notice)
  • Where we carry out credit checks in connection with a business transaction, from credit reference agencies (explained in our Client, Supplier and Business Contact Privacy Notice)
  1. Our lawful basis for processing

Data protection law requires us to have a lawful basis for processing your personal information. The basis we rely on for each activity is shown in the Data Processing Schedule. The bases we use are:

Contract

Where processing is necessary to perform a contract we have with you, or to take steps at your request before entering into one. This applies where you, as an individual, are the party to the contract. Where our contract is with your organisation rather than with you personally, we process your business contact details under legitimate interests instead.

Legitimate interests

Where processing is necessary for our legitimate interests, such as managing our business relationships, running and securing our website, and telling existing customers about relevant services. Before relying on this basis we carry out a legitimate interests assessment to check that our interests are not overridden by your rights and freedoms. You can ask us for information about any of these assessments.

Consent

Where we rely on your consent, for example for some marketing and for non-essential cookies. You can withdraw consent at any time; processing carried out before you withdraw remains lawful.

Legal obligation

Where we must process your information to comply with the law, for example sharing data with regulators or authorities.

  1. Who we share your information with

We may share your personal information with trusted third parties to deliver the services or products you request. We carry out due diligence on third parties, and our processors act only on our instructions. We may share with:

  • Other OCU Group companies, including international colleagues where relevant, for the group operations described in the Data Processing Schedule.
  • Vendors and service providers, such as IT support, hosting, auditing, legal advice, payment or delivery, and marketing providers.
  • Regulatory bodies or law enforcement, where required, for example to aid investigations or meet legal obligations.
  • Potential buyers or investors, if we sell or reorganise parts of our business.

Our website may contain links to external sites that we do not control. If you follow a link to a third-party site, their privacy notice will apply, not ours. We encourage you to read their notices carefully.

  1. Transfers outside the UK

Some of our processors and group companies are outside the UK, so your personal information may be transferred internationally. When we transfer personal data outside the UK, we do so only where:

  • the destination country is covered by UK “adequacy regulations”, an assessment that its data protection laws provide adequate protection; or
  • appropriate safeguards are in place, the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum.

We also carry out due diligence on the recipients of these transfers. You can request a copy of the safeguard that applies to a particular transfer by contacting our Data Protection Officer (section 14).

  1. Keeping your information secure

Information security is key to the success of our business. We have technical and organisational measures in place to protect your information from unauthorised access, alteration or disclosure. No system is entirely secure, and transmitting data electronically always carries some risk. We limit access to personal data to employees, agents and contractors who need it to do their jobs and who are under confidentiality obligations. We have procedures to detect and manage personal data breaches and, where required by law, to notify the ICO and affected individuals.

  1. How long we keep it

We retain personal information only as long as necessary for the purposes for which it was collected, including meeting any legal or regulatory requirements. When setting retention periods we consider the amount, nature and sensitivity of the data; the potential risk of harm from unauthorised use or disclosure; and whether the purposes could be achieved by other means. Our retention schedule sets out specific periods for each category of data; contact our Data Protection Officer if you would like details relevant to you.

  1. Your rights

You have the following rights over the personal information we process. To exercise any of them, contact us using the details in section 14. We will respond within the timescales required by law, and exercising a right is free of charge in almost all cases.

  • Right of access. Request a copy of your personal data (a subject access request).
  • Right to rectification. Have inaccuracies corrected or incomplete data completed.
  • Right to erasure. Ask us to delete your data where there is no lawful reason for us to keep it.
  • Right to restrict processing. Ask us to pause our use of your data in certain circumstances.
  • Right to data portability. Receive certain data you provided to us in a structured, machine-readable format.
  • Right to object. Object to processing based on legitimate interests, and to direct marketing at any time. If you object to direct marketing we will stop; for other legitimate interests processing, we will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is needed for legal claims.
  • Right to withdraw consent. Where we rely on consent, withdraw it at any time.
  • Rights around automated decision-making. Not to be subject to decisions with legal or similarly significant effects based solely on automated processing, except in limited circumstances (see section 13).
  1. Automated decision-making

We do not make decisions about you that produce legal effects, or similarly significant effects, based solely on automated processing (including profiling). If this changes, we will update this notice and explain the safeguards that apply, including your rights to obtain human involvement, to make representations and to contest the decision.

  1. How to contact us or complain

If you have any questions about this notice, or you want to exercise your rights, please contact our Data Protection Officer. We would always prefer to resolve any concern directly, but you also have the right to complain to the ICO.

Data Protection Officer: OCU Group Ltd, dpo@ocugroup.com

Right to complain: Information Commissioner’s Office, the UK’s data protection regulator. ico.org.uk/make-a-complaint · 0303 123 1113

Submitting a complaint. Under section 164A of the Data Protection Act 2018 you have a statutory right to complain directly to us if you consider we have infringed your data protection rights. You can complain using our online form at ocugroup.com/contact-us, by emailing our Data Protection Officer above, or by calling our Customer Complaints Team on 0333 200 0011. We will acknowledge your complaint within 30 days, take appropriate steps to investigate without undue delay, keep you informed, and tell you the outcome. If you are unhappy with our response, you can complain to the ICO at any time, although the ICO usually expects you to have raised the issue with us first.

  1. Data Processing Schedule

These are the common ways we process personal information in connection with our website and online services, the data involved, our lawful basis, and how we respect your rights. If you would like more detail about a specific activity, contact our Data Protection Officer.

  1. Website communication (email, forms, telephone)

Data category: Contact data, content you submit

Lawful basis: Legitimate interests (responding to enquiries and managing our relationships); contract, where you are entering into or have a contract with us personally

Purpose and your rights: To respond to queries or provide requested information, for example through our “Contact Us” forms. Without this data we cannot address your request. You can ask us to stop contacting you at any time, though it may affect our ability to follow up.

  1. Customer relationship management (CRM)

Data category: Identity and contact data, work and role-specific information

Lawful basis: Legitimate interests (maintaining accurate records of our business relationships)

Purpose and your rights: We keep a secure CRM system to track clients, suppliers and partners, including contact form submissions. You can ask to see what we hold, request corrections, or ask us to remove it unless we need to keep it for legal or contractual reasons.

  1. Email marketing

Data category: Identity, contact and marketing and communications data

Lawful basis: Legitimate interests, for marketing to existing customers and to business (corporate) contacts; consent, for everyone else (for example newsletter sign-ups)

Purpose and your rights: If you are an existing client we may send relevant updates about our products and services. If you are not, we rely on your consent unless our relationship is business to business. Every message includes an unsubscribe option, and you can opt out at any time.

  1. Promotional images and video

Data category: Identity data (images and footage)

Lawful basis: Consent, where you are clearly identifiable; legitimate interests, for general crowd or event footage

Purpose and your rights: We may feature images or video from events on our website. If you are clearly identifiable we will seek your consent before using your image, and you can withdraw consent at any time or opt out on the spot.

  1. Website analytics (statistics and usage)

Data category: Technical & usage data

Lawful basis: Consent, for non-essential cookies and similar technologies; legitimate interests, for strictly necessary (essential) cookies

Purpose and your rights: We use cookies and similar technologies to understand how visitors use our site. We ask for your consent for any non-essential cookies, and you can manage or withdraw your cookie preferences at any time. See our Cookie Policy for details.

  1. Marketing engagement metrics

Data category: Identity, contact, technical & usage data

Lawful basis: Consent

Purpose and your rights: With your consent (for example cookie acceptance or email open tracking), we monitor interactions with our website, emails and social channels to tailor future communications and improve our marketing. You can revoke consent or opt out of marketing at any time.

  1. Administrative purposes and group operations

Data category: Identity, contact, financial and related data

Lawful basis: Legitimate interests (running the OCU Group efficiently and securely)

Purpose and your rights: We may share certain website-generated information within our group, or with service providers, for business continuity, IT hosting, invoice management or similar operational needs, including making sure the site functions properly and your data remains consistent across our internal systems.

  1. Job applications and recruitment

Data category: Identity and contact data, CV and application details

Lawful basis: Contract (taking steps at your request before entering into an employment contract); legitimate interests (managing recruitment)

Purpose and your rights: If you apply for a job via our website or our dedicated careers site, we pass your application to our Recruitment and HR teams to consider you for suitable roles. From that point your application is covered by our Recruitment Privacy Notice, which explains how any special category or criminal records data is handled and the legal conditions we rely on. You can ask us not to share your details further, though it may affect your application.

  1. Security and safety

Data category: Identity, technical and usage data

Lawful basis: Legitimate interests (protecting our website, systems and users); legal obligation, where the law requires it

Purpose and your rights: We process personal information for security monitoring, fraud prevention and threat detection, for example IP logs and suspicious activity flags. CCTV at our physical sites is covered by the privacy notices displayed at those sites, not by this website notice.

  1. Sharing information with auditors and authorities

Data category: Identity, contact and financial data

Lawful basis: Legal obligation; legitimate interests, where disclosure is not strictly mandatory but is necessary (for example defending legal claims)

Purpose and your rights: If required, we share data with regulators such as HMRC or the ICO, or in connection with legal proceedings such as fraud investigations. We disclose the minimum necessary.