Topographical Ltd (“we”/”us”) are predominantly involved with the provision of surveying services in a business to business capacity. We are committed to protecting and respecting any personally identifiable data and any confidential or sensitive commercial information which you share with us as part of this process.
This statement describes what types of information we collect from you, how it is used by us, how we share it with others, how you can manage the information we hold and how you can contact us.
The contents of this statement may change from time to time, so you may wish to check this page occasionally to ensure you are still happy to share your information with us. Where possible, we will also contact you directly to notify you of any substantial changes.
This version of our Privacy Policy is live from 25th May 2018.
The information we collect
We collect information about you and your company when you request a quote or make a query about the services we provide. We only collect information which is necessary, relevant and adequate for this purpose and to fulfil the obligations of any subsequent contract formed.
Any information within correspondence you send to us.
How we use the information
Contractual performance - We may use and process your personal information where this is necessary to perform a contract with you or your company on your behalf or to carry out a precontract request, such as a quote or a query about our services.
Legitimate interests – We may process your data as part of fraud protection, security measures and to assess credit worthiness. We do not currently pursue direct marketing but we may contact you/your company where we can demonstrate a balance of interests, to which you would have the right to object. One example would be to notify you of a new service offering that would complement a service you have previously enquired about. Where we have a relevant and appropriate relationship with you as an existing client, we may contact you to discuss your expectations of our firm.
Legal Obligation - We may process your personal information to comply with our legal requirements. For example, we may be required to give information to legal authorities if they so request or if they have the proper authorisation such as a search warrant or court order. This may include your personal information.
Vital Interest – We may need to process your personal information to protect the vital (health) interests of an individual should the situation arise.
How we store the information
This website is hosted by Hostinger.com
Server and infrastructure protection
24/7 server monitoring.
Server and infrastructure security configuration consistently applied across all servers
Firewall protection.
Advanced security modules that assure the best possible protection, such as mod_security, Suhosin PHP hardening, PHP open_basedir protection, and others.
Anti-malware protection on endpoints and servers.
A dedicated internal Security team.
Implemented internal policies and procedures to support information security.
Continuous scan for vulnerabilities and penetration testing.
Responsible Disclosure Policy and Bug Reward Program.
Applied OWASP secure coding practices and other industry standards.
2FA authentication enabled on all applicable systems.
All operating systems are kept up to date, including security patches.
Database encryption with secure hashing algorithms.
Regular data backups.
Continuous static code analysis to detect potential code security issues.
Hostinger is ISO/IEC 27001:2017 certified.
All traffic (transferral of files) between this website and your browser is encrypted and delivered over HTTPS.
We maintain a secure local copy of specific contract related data to enable us to make organisational and management decisions to deliver our service to you. This is regularly encrypted and backed up to cloud storage provider Microsoft.
Microsoft also provide our cloud based email service.
How we share the information
We use third parties to undertake some processes on our behalf in the interests of providing a high quality of service. Please click the names of the 3rd party data processors below to review their respective privacy policies.
You may pay for a contract by debit/credit card using Stripe. The details you enter are bypassed directly to Stripe and no record is made on our servers.
DropBox Quote and Survey files which may contain personal data you have previously provided - are made available to you securely via DropBox.
Google Maps and Google Analytics records data such as your geographical location, device, internet browser and operating system, none of this information personally identifies you to us. Google also records your computer’s IP address, which could be used to personally identify you but Google do not grant us access to this.
Utility Mapping Group (UK) Ltd
If you request a quote for utility mapping or underground services, where we cannot add value for you by managing the process, we may pass your query on to our partner in order for them to provide a quotation directly to you. In this case, the utility mapping service or associated service will be provided directly to you by Utility Mapping Group (UK) Ltd should you instruct them and we do not receive a commission.
How long we keep your information for
We will hold personal data within business information for a period of 7 years from the point the relationship ends. You may exercise your right to have the information erased (where it applies) and we do not need to hold it in connection with any of the reasons permitted or required under the law.
How you can manage the information we hold about you
You have the right as an individual to access your personal information we hold about you and make corrections if necessary. You can You also have the right to withdraw any consent you have previously given us and ask us to erase information we hold about you. You can also object to us using your personal information (where we rely on our business interests to process and use your personal information).
You have a number of rights in relation to your personal information under data protection law. In relation to most rights, we will ask you for information to confirm your identity and, where applicable, to help us search for your personal information. Except in rare cases, we will respond to you within 28 days after we have received any request (including any identification documents requested).
You have the right to:
Ask for a copy of the information that we hold about you;
Correct and update your information;
Withdraw your consent (where we rely on it). Please see further How do we use this information;
Object to our use of your information (where we rely on our legitimate interests to use your personal information) provided we do not have any continuing lawful reason to continue to use and process the information. When we do rely on our legitimate interests to use your personal information for marketing, we will always comply with your right to object;
Erase your information (or restrict the use of it), provided we do not have any continuing lawful reason to continue to use and process that information; Transfer your information in a structured data file (in a commonly used and machine readable format), where we rely on your consent to use and process your personal information or need to process it in connection with your contract.
You can exercise the above rights and/or manage your information by contacting us using the details below:
Post: Topographical Ltd, Belmont Suite Paragon Business Park, Chorley New Road, Horwich, Bolton, England, BL6 6HG
Email: office@topographical.co.uk
Phone: 0800 644 0014
If you are unhappy, you have the right to lodge a complaint with a data protection regulator in Europe, in particular in a country you work or live or where your legal rights have been infringed. The contact details for the Information Commissioner’s Office, the data protection regulator in the UK, are below:
Post: Information Commissioner's Office
Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF
Call: 0303 123 1113 Email: casework@ico.org.uk