Privacy

To find out more about our processing activities, please go the privacy notice that is relevant to you:

En Español:
Politica de privacidad de clientes y Politica de privacidad del servicio de Controlar
Individuals at Achilles ‘buyer’ and ‘supplier’ customer organisation.
Recruitment applicants
Individuals visiting our website, contacting us through our website or our social media channels and subscribers to our newsletter and similar communications
To learn more about how we use cookies, please visit our cookies notice

Privacy Notice: Individuals employed or engaged by Buyers and Suppliers

Effective Date 1st May 2018

INTRODUCTION

Achilles Information Limited, Achilles Information AS, Achilles South Europe, S.L.U and their affiliates (“Achilles”/”we”/”us”/”our”) provide supply chain assurance services to buyer and supplier organisations globally. Our supplier pre-qualification services are provided using our supply chain management platforms (our “platform”).

As an information led business, we place great importance in ensuring the quality, confidentiality, integrity and availability of the data we hold, and in meeting our data protection obligations where we process personal data. Achilles is committed to protecting the security of your personal data. We use a variety of technical and organisational measures to help protect your personal data from unauthorised access, use or disclosure.

This privacy notice explains what personal data Achilles collects about individual users at both buyer and supplier organisations (“you”/”your”) and how we use it.

We update this privacy notice from time to time in response to changes in applicable laws and regulations, to our processing practices and to products and services we offer. When changes are made, we will update the ‘Last Updated’ date at the top of this page. Please review this privacy notice periodically to check for updates.

PERSONAL DATA WE COLLECT

If you are employed or contracted by a supplier organisation

We collect your personal data where your organisation has provided such personal data to us in connection with the services offered to your organisation by Achilles (for example, an online supplier questionnaire may request the name of an individual who holds a key position in your business). We may also collect your personal data from a buyer organisation who has asked us to contact you because you are employed or contracted by a supplier organisation that the buyer organisation wishes to have registered on the platform, and are their contact person for that organisation.

The personal data we collect covers your name, job title, business email, business telephone number and office address.

We also collect information on supplier organisations from publicly available sources and from providers of screening services and combine this with the other information we hold. This sometimes includes information on directors or individuals associated with or working at a supplier organisation and might therefore include your personal data.

If you pay for our services using a credit or debit card in your name, we will also collect your card information when you provide it to us.

If you are employed or contracted by a buyer organisation

We collect your personal data where your organisation has provided such personal data to us in connection with the services offered to your organisation by Achilles (for example, as the Achilles relationship contact or as a named user of the platform).

The personal data we collect covers your name, job title, business email, business telephone number and office address.

HOW WE USE YOUR PERSONAL DATA

If you are employed or contracted by a supplier organisation

We add the information provided to us by your supplier organisation (typically through the online questionnaire), together with the information we collect from publicly available sources and providers of screening services, to our platform. This includes your personal data.

Once on the platform, your personal data will be visible to:

  • the buyer organisations in the Achilles community your organisation has agreed to join; and/or
  • where your organisation has agreed to allow access of your information to a specific buyer organisation only, that specific buyer organisation.
If you are the Achilles contact person for a buyer or supplier organisation

We also use your personal data to help us improve our services and develop our relationship with your organisation. This includes:

  • Providing you with account management and contacting you for feedback
  • Sharing information with you about how you can use our services
  • Providing you with training and support
  • Sending you customer satisfaction surveys
  • Sending you our newsletter, research reports, insights and other Achilles news

You can unsubscribe from customer satisfaction surveys, our newsletter and associated communications at any time.

Where you are employed or contracted by a supplier organisation and we collect your personal data from a buyer organisation who has asked us to contact you with a view to registering your organisation on the platform, we validate this information using publicly available sources. Once validated we use your personal data to contact and invite you to register your organisation on the platform

We use credit card details to take payment for our services.

BASIS FOR USING YOUR PERSONAL DATA

The basis for which we use your data depends on our relationship and how we are using the data.

Where we are using personal data provided by buyer or supplier organisations to provide them with our services, we are doing so because it is necessary for the performance of the service your organisation has registered for or subscribed to, and the contract we have entered into with them. Where we are collecting personal data provided from buyer organisations who wish to engage with your supplier organisation or from screening services, we are doing so because it is in our legitimate interests to invite organisations to become suppliers to our buyer organisations. When we collect personal data from publicly available sources or from providers of screening services, we do so because it is in our legitimate interests to provide our buyer organisations with information to help them identify suitable suppliers and risks in their supply chain.

Where we are using personal data to send you customer satisfaction surveys, newsletters or marketing materials we are doing so because it is in our legitimate interests to collect your feedback, develop our products and services and improve our business. Alternatively, it is because you have consented to receive these types of communication. You can object to, or withdraw your consent for, Achilles using your personal data this way. You can do so by unsubscribing using the link provided in our emails or by contacting us using the details given below.

If you pay for our services using a credit or debit card in your name, we are using the personal data associated with the card because it is necessary for the performance of the contract we have entered into with your organisation.

SHARING YOUR DATA

We share your data with our group companies, including those in countries outside the European Economic Area (the “EEA”) where the data protection laws are not equivalent to those within the EEA. We do so using Standard Contractual Clauses approved by the European Commission which contractually oblige our group companies in those countries to the standard expected within the EEA.

When we add your personal data to our platform, we share it with:

  • buyer organisations in the Achilles community your organisation has agreed to join; and/or
  • where your supplier organisation has agreed to share the information with only a specific buyer organisation, the specific buyer organisation your organisation has allowed to access it.

This includes in countries outside the EEA where the data protection laws are not equivalent to those within the EEA. We do so on the basis of explicit consent you have given for your organisation to share your personal data with buyer organisations outside the EEA. If you have not provided explicit consent or wish to withdraw you consent, please contact us at dataprivacy@achilles.com or by writing to us at the address provided below.

When you provide credit or debit card details to pay for our services, we share this data with banks and our payment transaction providers.

We also share your data with service providers and sub-contractors to our business who process data on our behalf. This includes, for example, cloud service providers such as Microsoft and Amazon Web Services. In such cases, our service providers and suppliers are data processors and may only use the data in line with our instructions and not for any other purpose. This and other obligations are agreed in the contract we enter into with them.

It is possible that we may be required to share your data to comply with applicable laws or with valid legal processes, such as in response to a court order or with government or law enforcement agencies.

HOW LONG WE KEEP YOUR DATA

We will retain personal data provided to us by supplier and buyer organisations for as long as is necessary to provide them with our services. Where we are relying on our legitimate interests or your consent to process your personal data, we will retain your personal data until you object to us processing it or withdraw your consent.

We will also retain personal data where it is necessary to comply with our legal obligations, resolve disputes and enforce agreements.

We do not retain credit or debit card information once payment has been made.

Please note we need to hold contact details for individuals at supplier and buyer organisations for the performance of the service and the contract we have entered into. If you no longer want us to hold your personal data in these circumstances, we will need an alternative contact detail for your organisation or we will be unable to continue providing your organisation with the service.

YOUR RIGHTS

Individuals in the EU whose personal data we hold, and process have the following rights:

  • You have the right of access to your personal data and can request copies of it and information about our processing of it.
  • If the personal data we hold about you in incorrect or incomplete, you can ask us to rectify or add to it.
  • Where we are using your personal data with your consent, you can withdraw your consent at any time.
  • Where we are using your personal because it is in our legitimate interests to do so, you can object to us using it this way.
  • In some circumstances, you can restrict our processing of your data, request a machine-readable copy of your personal data to transfer to another service provider and compel us to erase your personal data

If you wish to exercise your rights, please contact us at dataprivacy@achilles.com.

Individuals in the EU also have the right to lodge a complaint with a supervisory authority in an EU member state if you believe we are infringing EU data protection laws. You can lodge a complaint with the supervisory authority in your EU member state of residence, the member state in which you work or the member state in which the alleged infringement took place.

HOW TO CONTACT US

You can contact Achilles in relation to data protection and this privacy notice by writing to:

General Counsel
Achilles
30 Western Avenue
Milton
Abingdon
OX14 4SH
United Kingdom

Alternatively, you can email us at dataprivacy@achilles.com.

 

Achilles Privacy Notice: Recruitment & Job Applicants

INTRODUCTION

Achilles Group Holdings Limited and its subsidiaries (“Achilles”/”we”/”our”) are committed to protecting your privacy and meeting our legal obligations when you apply for a job or you (or an agent acting on your behalf) share your employment details with us.

This privacy notice explains what personal data Achilles collects about employment and contractor candidates (“you”/”your”) during the recruitment process and how we will use it.

As an information led business, we place great importance in ensuring the quality, confidentiality, integrity and availability of the data we hold, and in meeting our data protection obligations where we process personal data. Achilles is committed to protecting the security of your personal data. We use a variety of technical and organisational measures to help protect your personal data from unauthorised access, use or disclosure.

We update this privacy notice from time to time in response to changes in applicable laws and regulations, to our processing practices and to products and services we offer. When changes are made, we will update the ‘Last Updated’ date at the top of this page. Please review this privacy notice periodically to check for updates.

PERSONAL DATA WE COLLECT

When you apply for a role (whether as an employee or a contractor) or submit your CV (or similar employment information) to us, whether directly or through an agency, or are interviewed by us we will collect your personal data. This may include:

  • Name and contact details, date and place of birth
  • Work history and employment positions held
  • Salary, other compensation and benefits information
  • Nationality / visa / right to work permit information
  • Academic and professional qualifications, education and skills
  • Photographs or videos you submit with your application
  • Demographic information
  • Any other information you choose to give us
  • Records we create during interviews or correspondence with you
  • Results of pre-employment screening checks

We may also collect some sensitive personal data about you, such as disability information. We will only do this to make reasonable adjustments to enable candidates to apply for jobs with us, attend interviews and to start work with us if successful. Also, to ensure we meet our legal obligations when recruiting.

HOW WE USE YOUR PERSONAL DATA

We use the personal data you share with us in a variety of ways, including to:

  • Process your application (including by adding you to our HR and people management system)
    Communicate with you, including by telephone, email and SMS
  • Assess your suitability, skills and experience for the role you have applied for
  • Set up and conduct interviews by telephone and in person
  • Contact third party references you have provided us
  • Conduct pre-employment screening checks

If your candidacy is not successful or if you (or an employment agency on your behalf) have submitted your CV or application to us on a speculative basis, we may also add your details to our list of suitable candidates for future roles (our ‘talent pool’) and may contact you again should a suitable role arise.

BASIS FOR USING YOUR PERSONAL DATA

When processing your personal data for the purposes of administering your job application, assessing your candidacy for a role, communicating with you and contacting third party references we do so with your consent. By submitting your application, you are confirming your consent to us processing your personal data for these purposes. You can withdraw your consent at any time, by contacting us at dataprivacy@achilles.com or by writing to us at the address below.

If we process any sensitive personal data, including performing pre-employment screening checks, we will do so only with your explicit consent or where we are required to do so by law. We will ask for your explicit consent in these circumstances.

If your job application is unsuccessful, and unless you ask us not to, your details will be added to our talent pool and we may make contact with you again (including by telephone, email or SMS). This is because it is in our legitimate interests to maintain the details of, and stay in contact with, suitable candidates for future roles. You can object to being in our talent pool at any time, by contacting us at dataprivacy@achilles.com or by writing to us at the address below.

Less commonly, we may process your personal data in relation to legal claims.

SHARING YOUR DATA

We may share your data with our group companies, including those in countries outside the European Economic Area (the “EEA”) where the data protection laws are not equivalent to those within the EEA. We do so using Standard Contractual Clauses approved by the European Commission which contractually oblige our group companies in those countries to the standard expected within the EEA.

We may also share your data with service providers and suppliers to our business who process data on our behalf. This includes, for example, cloud service providers (e.g our HR and people management system, which is cloud service provided to us by a third party). In such cases, our service providers and suppliers are data processors and may only use the data in line with our instructions and not for any other purpose. This and other obligations are agreed in the contract we enter into with them.

Within Achilles, your personal data will only be shared with those who need to have access to it. This will primarily be our HR personnel and hiring managers.

It is possible that we may be required to share your data to comply with applicable laws or with valid legal processes, such as in response to a court order or with government or law enforcement agencies.

HOW LONG WE KEEP YOUR DATA

We will retain your personal data for only as long as is necessary for the recruitment process. If your candidacy is successful and you are employed by us, your data will be processed and retained as set out in our employee privacy notice, provided to you with your employment paperwork.

If your candidacy is not successful, we will retain your CV, application details and interview notes for 12 months (from the date of first receipt of your details). During this time, we may add your information to our talent pool unless you ask us not to or subsequently object to us doing so.

We will also retain personal data where it is necessary to comply with our legal obligations or as necessary in relation to legal claims. This is rare but may mean we need to retain your data for longer than 12 months.

YOUR RIGHTS

Individuals whose personal data we hold, and process have the following rights:

  • You have the right of access to your personal data and can request copies of it and information about our processing of it.
  • If the personal data we hold about you in incorrect or incomplete, you can ask us to rectify or add to it.
  • Where we are using your personal data with your consent, you can withdraw your consent at any time.
  • Where we are using your personal because it is in our legitimate interests to do so, you can object to us using it this way.
  • In some circumstances, you can restrict our processing of your data, request a machine-readable copy of your personal data to transfer to another service provider and compel us to erase your personal data.

If you wish to exercise your rights, please contact us at dataprivacy@achilles.com or write to us at the address provided below.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

HOW TO CONTACT US

You can contact Achilles in relation to data protection and this privacy notice by writing to:
General Counsel
Achilles
30 Western Avenue
Milton
Abingdon
OX14 4SH
United Kingdom

Alternatively, you can email us at dataprivacy@achilles.com

 

Privacy Notice: Website and other communication channels

INTRODUCTION

Achilles Group Holdings Limited and its subsidiaries (“Achilles”/”we”/”our”) are committed to protecting your privacy and meeting our legal obligations when visiting or contacting us through our website.

This privacy notice explains what personal data Achilles collects from individuals who visit our website, contact us using our web forms, by email or through one of our social channels; or subscribe for our newsletter or other marketing communications (“you”/”your”). It also explains what information we collect automatically when you visit our website.

As an information led business, we place great importance in ensuring the quality, confidentiality, integrity and availability of the data we hold, and in meeting our data protection obligations where we process personal data. Achilles is committed to protecting the security of your personal data. We use a variety of technical and organisational measures to help protect your personal data from unauthorised access, use or disclosure.

If you are employed or engaged by an Achilles “buyer or “seller” organisation and your personal data has been provided to us by your employer as a contact for their organisation, we process your personal data as set out in our privacy notice for individuals employed or engaged by buyers and suppliers.

If you have applied for a role with Achilles or submitted your CV (or similar employment information) to us, we process your personal data as set out in our privacy notice for recruitment candidates.

We update this privacy notice from time to time in response to changes in applicable laws and regulations, to our processing practices and to products and services we offer. When changes are made, we will update the ‘Last Updated’ date at the top of this page. Please review this privacy notice periodically to check for updates.

PERSONAL DATA WE COLLECT

When you contact us using the web form on our website, a corporate email account (such as dataprivacy@achilles.com) or through one of our social channels (including Twitter and Facebook) we collect the information you provide to us. This typically includes your name, job title, employer business address, business email and any additional information you include in your message.

When you visit our website we may collect limited personal data automatically through the use of cookies and web beacons on our website. For more details on cookies and web beacons, please refer to the section on cookies immediately below. We may also automatically collect information including the IP address of your organisation or ISP, your browser family, operating system family and version, your country and continent and your web page viewing path including page response times and download times. This information does not include personal data and is used only help us improve the performance of our website and to troubleshoot problems.

COOKIES & SOCIAL MEDIA LINKS

Achilles uses Cookies and web beacons on our website and web beacons in some emails we send. Cookies are small text files and web beacons are small graphic images. They are downloaded to your device when you visit a website or receive certain emails unless you have set your browser to stop them.

We use cookies to remember your preferences, display content that is more relevant to you and improve your overall experience on our site. We use web beacons to track the actions of individuals (such as email recipients) and measure the success of our marketing campaigns and response rates.

To learn more about cookies and web beacons, and what you can do to opt out of receiving them, please view our Cookies Notice.

Our website includes social media sharing buttons and links to enable you to share our content through your preferred social media site or by email direct from one of our web pages. These features may collect your IP address and the page you are visiting on our website and may set a cookie on your device.

When you use one of these buttons or links, you are sharing information to another website or service (such as Twitter, LinkedIn or Facebook) and this privacy notice will no longer apply. Please read the privacy notices provided by the particular social media website you are sharing through before posting any personal data using these links.

HOW WE USE YOUR PERSONAL DATA

We use the personal data you provide to us to respond to your enquiry and, if you have agreed to us doing so, we use it to subscribe you to our newsletter and contact you with research reports, insights and other Achilles news and information.

You can unsubscribe from our newsletter and associated communications at any time by contacting us at dataprivacy@achilles.com.

We use cookies and web beacons as set out above.

BASIS FOR USING YOUR PERSONAL DATA

We use your personal data communicate with you because it is in our legitimate interests to reply to enquiries made by individuals through our website, by email or through our social channels. Also, to send you our newsletter, research supports, insights and other Achilles news and information where you have consented to us doing so.

You can object to, or withdraw your consent for, Achilles using your personal data in these ways. You can do so by unsubscribing using the link provided in our emails or by contacting us using the details given below.

We only use cookies and web beacons with your consent. Unless you decline them, you consent to our use of cookies and web beacons by visiting and using our website. You can manage your cookie preferences through your web browser settings, as set out in our cookie notice . You can also contact us at dataprivacy@achilles.com if you have any questions about the use of cookies on our website.

SHARING YOUR DATA

Achilles is a global business and to respond properly to your enquiry it is possible that we will share your data with our group companies, including those in countries outside the European Economic Area (the “EEA”) where the data protection laws are not equivalent to those within the EEA. We do so using Standard Contractual Clauses approved by the European Commission which contractually oblige our group companies in those countries to the standard expected within the EEA.

It is possible that we may be required to share your data to comply with applicable laws or with valid legal processes, such as in response to a court order or with government or law enforcement agencies.

HOW LONG WE KEEP YOUR DATA

We will retain your personal data for as long as it necessary for the purpose of our relationship or until you object to us processing it or withdraw your consent.

YOUR RIGHTS

Individuals whose personal data we hold, and process have the following rights:

  • You have the right of access to your personal data and can request copies of it and information about our processing of it.
  • If the personal data we hold about you in incorrect or incomplete, you can ask us to rectify or add to it.
  • Where we are using your personal data with your consent, you can withdraw your consent at any time.
  • Where we are using your personal because it is in our legitimate interests to do so, you can object to us using it this way.
  • In some circumstances, you can restrict our processing of your data, request a machine-readable copy of your personal data to transfer to another service provider and compel us to erase your personal data.

If you wish to exercise your rights, please contact us at dataprivacy@achilles.com.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

HOW TO CONTACT US

You can contact Achilles in relation to data protection and this privacy notice by writing to:

General Counsel
Achilles
30 Western Avenue
Milton
Abingdon
OX14 4SH
United Kingdom

Alternatively, you can email us at dataprivacy@achilles.com