Privacy and Cookie Policy

At IDH Direct, we’re committed to protecting and respecting your privacy.

This Policy explains when and why we collect personal information, how we use it, the conditions under which we may disclose it to others and what choices you have. It relates to all our business activities, not just this website. We may change this Policy from time to time so please check this page occasionally to ensure that you’re happy with any changes. By using our services, you’re agreeing to be bound by this Policy.

Any questions regarding this Policy and our privacy practices should be sent by email to sales@idhdirect.co.uk, or via the other methods on our contact page.

Date: 6th March 2023
Next Review Date: 9th March 2024
Author: Ian Holmes

Summary

Here is a summary of our Privacy Information Notice;

    • 1 Who are we? We are IDH Direct, we are specialists in Mesh Partitioning, Mesh Caging, Perimeter Machine Guarding and Anti-Collapse Mesh. We also offer a huge range of products including Shelving and Storage equipment, Workbenches, Materials Handling equipment and Safety & Security products.

    • 2 How do we collect information from you? We obtain information about you when you contact us to enquire about our services and when you use our website

    • 3 What information do we collect & how is it used? We collect information to allow us to fulfil our obligations to our clients and to respond to business enquiries. We also collect your information if you leave a comment on our blog.

    • 4 Controlling your information You have certain rights concerning the information we hold about you, as defined under the General Data Protection Regulation. If you wish to exercise these rights, please contact us.

    • 5 Use of ‘cookies’ This website uses cookies; by using and browsing the IDH Direct website, you consent to cookies being used in accordance with this Policy. If you do not consent, you must turn off cookies or refrain from using the site.

    • 6 Security IDH Direct takes security seriously. Our internal Data Security Policy details the steps we take to safeguard and secure the information we collect.

    • 7 Data Breaches Our Data Security Policy includes a clear process for handling a personal data breach, should one occur. Where appropriate, IDH Direct will promptly notify you of any unauthorized access to your personal information.

    • 8 Complaints If you wish to raise a complaint on how we have handled your personal information, you can contact us directly and we will investigate the matter. If you are not satisfied with our response you can also complain to the Information Commissioner’s Office (ICO).

Who are we?

We are IDH Direct Limited we are specialists in Mesh Partitioning, Mesh Caging, Perimeter Machine Guarding and Anti-Collapse Mesh. We also offer a huge range of products including Shelving and Storage equipment, Workbenches, Materials Handling equipment and Safety & Security products.

IDH Direct is a company limited by guarantee (Registration Number: 07406448); our registered address is 40 George Street, Warminster, Wiltshire, BA12 8QB. Full contact details can be found here: https://www.idhdirect.co.uk/contact-us

How do we collect information from you?

We obtain information about you when you contact us to enquire about our services.
We obtain information about you when you make a purchase on our website allowing us to process your order effectively.
We obtain information about you when you sign up to receive our catalogue in the post.
We also collect information from you if you leave a comment on our blog.

What information do we collect & how is it used?

We collect information to allow us to fulfil our obligations to our clients, and to respond to business enquiries. We also collect your information if you leave a comment on our blog. The table in section 3.3 below outlines exactly what information we collect, and for what purpose.

3.0. Sensitive Data

We do not gather sensitive personal data (e.g. health, genetic, biometric data; racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation, and criminal convictions). We expressly request that you do not provide any such sensitive data to us.

3.1. Children’s information

Our services are not directed to children under 16. If you learn that a child under 16 has provided us with personal information without consent, please contact us.

3.2. Third Parties

We will not sell or rent your information to third parties.
We will not share your information with third parties for marketing purposes.
Integration of the Trusted Shops Trustbadge

Following an order, the Trusted Shops Trustbadge is incorporated into this web page to display our eventually collected reviews.

In balancing the various interests, this serves to safeguard our legitimate prevailing interests in an optimised marketing of our offer. The Trustbadge and the services advertised are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Köln.
Whenever a Trustbadge is called up, the web server automatically stores a so-called server log file which contains, for example, your IP address, the date and time of retrieval, the data volume transferred and the requesting provider (access data) and documents the retrieval. This access data will not be evaluated and will be automatically overwritten seven days after your visit to the page.
Other personal information will only be transferred to Trusted Shops if you decide, after completing an order, to use Trusted Shops products or have already registered for their use. In this case, the contractual agreement between you and Trusted Shops applies.

3.3. Details

The following table outlines the personal data we collect and for what purpose. The table also outlines the 3rd parties the data is processed by or shared with, and how long the data is stored for:

Name What Legal Ground Purpose 3rd Parties Data Retention
Email Prospect, client & supplier contact information Contract To allow initial and ongoing contact with prospects, clients, suppliers, etc. Google Mail
We have signed EU model contract clauses.
Until request for deletion.
Blog Comments Website commenter name, email address and website Legitimate interests To allow website users to comment on and discuss blog posts, or ask questions. Held within WordPress database, hosted with WP Engine Until request for deletion. To maintain flow of conversation comments may not be deleted on request, but all personally identifying information will be removed.
Invoicing Client & supplier purchase history & contact info. Legal obligation For invoicing Sage Indefinitely, for on-going invoicing and accounting records
Password Store Client log-in details for various services, including hosting and domain registration. Contract To allow us to log in and administer services on our clients’ behalf Magento Until cessation of contract/business activities
Hosting Accounts Client contact information Contract Required to set up a user account for each hosting client on WP Engine – so they can access support NuBlue Until request for account deletion/cessation of hosting contract
Backup Backup of documents on local drives – proposals, schedules, etc Contract Cloud backup to ensure business continuity in the event of hardware failure. Netgear Until request for deletion
Analytics Website visitor behaviour (anonymised – full IP address is NOT stored) Legitimate interests To analyse popular content, website performance, etc – so we can further improve. Google Analytics
We have signed DPA & anonymise IP addresses
14 months
Server Logs IP address Legal obligation To help prevent DoS (Denial of Service) attacks; for website security and diagnostics. NuBlue Server logs are stored unencrypted for 7 days, and then moved to an encrypted backup which is stored indefinitely and only accessible by WP Engine.

Controlling your information

You have certain rights concerning the information we hold about you, as defined under the General Data Protection Regulation. If you wish to exercise these rights, please contact us, including your email address in the first instance (this is the unique identifier we use to identify and collate personal information).

Requesting a copy of your information

You may request a copy of any data we hold about you. Upon request, we will provide a CSV file (which you may open in a program such as Microsoft Excel) containing the personal data we hold on record about you.

Updating or correcting your information

The accuracy of your information is important to us. If you change email address, or any of the other information we hold is inaccurate or out of date, please contact us so we may correct our records.

Deleting your information

You have the right to request erasure of your personal information. Unless there is a compelling reason for the data not to be erased (for example, if we need to use that data to fulfil our contractual or legal obligations), your personal data will be deleted on request. Users can leave comments on our blog. To maintain flow of conversation, blog comments will not normally be deleted (unless there is a compelling reason to do so), but all personally identifying information will be removed.

Automated decision making

We do not use any personal information for automated decision making or profiling; your data is not subject to automated decision making or profiling.

Use of ‘cookies’

Like many other websites, the IDH Direct website uses cookies. Cookies are small pieces of information that are stored on your computer or mobile device when you visit a website.

The cookies we use are ‘1st party’ cookies. We don’t use any ’3rd party’ cookies (these are often used to track behaviour across a range of websites, so targeted advertising can then be applied. We don’t do this!!) The following list outlines what we use cookies for:

      • Google Analytics: Google Analytics sets cookies to help us accurately estimate the number of visitors to the website and what content is most popular. This helps to ensure that our website is responding to your needs in the best way possible.
      • WordPress Comments: When you leave a comment on our blog, three cookies are set to store your name, email address and website. This is so that if you wish to leave another comment, you won’t have to re-type this information.

Security

IDH Direct takes security seriously. To protect your information from loss, misuse or unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect. These steps include the following:

      • Data minimisation
      • Password best practice
      • Security best practice concerning devices (PCs, laptops, mobile devices), online accounts, website hosting, physical access and storage
      • Staff training and accountability on data protection

A copy of our internal Data Security Policy is available on request.

Data Breaches

Our Data Security Policy includes a clear process for handling a personal data breach, should one occur. Where appropriate, IDH Direct Limited will promptly notify you of any unauthorized access to your personal information.

Complaints

If you wish to raise a complaint on how we have handled your personal information, you can contact us directly and we will investigate the matter.

If you are not satisfied with our response or believe we are processing your personal information not in accordance with the law, you can complain to the Information Commissioner’s Office (ICO).