Sir Richard Arkwright's Masson Mills

Gateway to the Derwent Valley Mills World Heritage Site

1 What is this Privacy Policy for?

This privacy policy describes how and why NEEDLES AND HAYSTACKS LIMITED (Company No: 13177444) (we or the Company) acquire and use your personal data.

For the purpose of the Data Protection Act 2018 and the General Data Protection Regulation (EU) 2016/679 (the GDPR), the Company is the controller of the personal data it processes about you. We are registered with the Information Commissioner’s Office with reference number: ZA458583. We also control and operate www.massonmills.co.uk (the Website). This policy sets out how we collect, process, store and protect your personal data.

This policy applies to employees, job applicants, sub-contractors, suppliers, advisers and customers in relation to whom we process personal data.

2 How we collect your personal data

In relation to job applicants and employees, we collect your personal data when you apply for a job with us, either for an interview or during your employment. If you do not provide us with certain personal data we will not be able to review your job application or employ you.

Our customers may be registered companies, sole traders, partnerships individuals or trusts. Where our customer is a registered company, we will process personal data in relation to our contact at that company.

In relation to customers, contractors, sub-contractors, suppliers and advisors, we collect personal data from you when we engage with you, whether it be in person, on the phone or via email. We also collect information when you use the Website.

We may also process personal data about landowners which is in the public domain or from the landowner directly.

The personal data we collect from you may include:

3 How we use your personal data

We use your personal data in the following ways:

4 Our legal basis for processing

We process your personal data on the basis that it is necessary for the following purposes:

5 Sharing your personal data

We only share your personal data with third parties where it is necessary for us to do so in order to fulfil our obligations to you under our contract, or where we are required to do so in order to comply with a regulatory or legal provision. We will never sell your personal data for direct marketing.

The circumstances in which we may share your personal data with third parties includes:

6 CCTV

We may use CCTV monitoring on some of our sites for the purposes of monitoring our operational assets and the area in which we are working (for example our equipment and water flow). Wherever CCTV is in operation you will be notified of this via appropriate signage. The CCTV is monitored and administered by the Company, or the client who owns the land at the particular site. Further information about the administration of CCTV monitoring can be obtained by contacting us. CCTV images are not recorded or retained.

7 Transfers of your personal data

The personal data that we collect from you may be transferred to, or stored at, a destination outside the European Economic Area (EEA). For example, we use Google Drive which is provided by Google LLC, and Dropbox, which is provided by Dropbox International Unlimited Company, both of which may transfer personal data outside of the EEA.

Where we need to transfer your personal data outside the EEA, we will take all steps reasonably necessary to ensure that any such transfer is made securely and that there is adequate protection in place in order to protect your personal data.

Please contact us if you wish to find out more; you are welcome to ask us for a copy of the relevant safeguards implemented in relation to any transfers outside of the EEA.

8 How long we will retain your personal data

For employees, we will retain your personal data for a period of up to seven (7) years following the end of your employment with us. For job applicants, we will retain your personal data for a period of up to two (2) years following us successfully appointing a candidate. In relation to contractors, sub-contractors and suppliers, we will retain your personal data for a period of up to four (4) years following the end of our contractual relationship.

For customers, we will retain your personal data for as long as is necessary to manage our relationship with you and in order to contact you with any important information regarding the installation of any of our products. We expect that we will retain personal for up to ten (10) years following the end of our relationship with you. However, this may be extended and we might need to hold contact details for our former customers indefinitely where it is necessary for us to make infrequent contact with the customer regarding their hydropower operation.

We may also process personal data about landowners. We will retain the personal data for as long as we deem such data to be commercially important to our business.

9 Changes to this policy

We may edit or amend this privacy policy from time to time. If we make any substantial changes to the ways in which we use your personal data we will notify you by email.

10 Your rights

Your personal data is protected under data protection laws and you have a number of rights (explained below) which you can seek to exercise. Please contact us using the details provided in the contact and complaints section below if you have any queries in relation to your rights.

If you seek to exercise your rights we will explain to you whether or not the right applies to you; these rights do not apply in all circumstances.

11 Contact and Complaints

If you have any questions in relation to anything raised in this privacy policy or how we use your personal data, please contact us by writing to us at: Sir Richard Arkwright's Masson Mills, 41 Derby Road, Matlock Bath, Derbyshire, England, DE4 3PY; email us at: info@massonmills.co.uk or call us on 01629 581001.

You also have the right to lodge a complaint with a supervisory authority (the ICO) by writing to Information Commissioner's Office, Water Lane, Wilmslow, SK9 5AF or calling 0303 123 1113.

Further information about how to do this can be found at: www.ico.org.uk.