Data Protection
Nova Business Finance Data Protection Statement
This statement refers to UK GDPR (General Data Protection Regulation) and The Data Protection Act 2018. Nova Business Finance is a trading style of Nova Business Finance Ltd (referred to as the Company).
Introduction
The Company needs to gather and use certain information about individuals. This can include customers, suppliers, business contacts, employees, and other people we have a relationship with or may need to contact. This policy describes how this personal data must be collected, handled, and stored to meet our data protection standards and comply with the law.
Why This Policy Exists
This data protection policy ensures the Company:
- Complies with data protection law and follows good practice.
- Protects the rights of all individuals and their data.
- Is open about how it stores and processes individuals data in line with their rights.
- Protects itself from the risks of a data breach.
Data Protection Law
To comply with the law, personal information must be:
- Processed lawfully, fairly, and in a transparent manner.
- Collected for specified, explicit, and legitimate purposes.
- Adequate, relevant, and limited to what is necessary.
- Accurate and kept up to date.
- Kept in a form which permits identification of data subjects for no longer than is necessary.
- Processed in a manner that ensures appropriate security of the personal data.
Record Keeping
We ensure that records of our processing activities are kept and updated accordingly. Individuals data is kept on file for 6 years in line with the Financial Conduct Authority record keeping rules. After this point, personal data is retracted to the point it is unidentifiable and used for statistical purposes only.
Lawful Basis for Processing Data
Under GDPR, it is a requirement that the Company has a valid lawful basis to process personal data. We have chosen this basis for processing data as it is requested from individuals that we capture data before entering into a contract (for example, to provide a quote for finance).
Responsibilities
The Company acts as a Data Controller and Data Processor. All staff are responsible for ensuring that the highest data standards and best practices are met on a continual basis. The Directors of the business are accountable and responsible for compliance with GDPR.
Individuals Rights
Individuals have rights under GDPR, which include:
- The Right to be Informed
- The Right of Access
- The Right to Rectification
- The Right to Erasure
- The Right to Restrict Processing
- The Right to Data Portability
- The Right to Object
- Rights in relation to automated decision making and profiling
We provide every customer with a Privacy Notice at the point data is captured to ensure full transparency regarding these rights and how data is used.
Subject Access Requests (SAR)
Individuals who are the subject of personal data held by the Company are entitled to access their personal data and confirmation that their data is being processed. The Company will provide a copy of the information free of charge within one month of verifying the identity of the person making the request.
Complaints
Data subjects who wish to complain about how their personal data has been processed can raise this through our company complaints procedure by contacting info@novafinance.co.uk or by calling 01908 904 987. If you are still not happy, the complaint can be referred to the Information Commissioners Office (ICO).
Data Security and Storage
We take the security of your data incredibly seriously.
When data is stored on paper, it will be kept in a secure place where unauthorised people cannot see or have access to it. Printouts will be shredded and disposed of securely when no longer required.
When data is stored electronically, it must be protected from unauthorised access, accidental deletion, and malicious hacking attempts. We ensure:
- Data is protected by strong passwords or encryption products.
- Data is backed up frequently and stored on approved secure servers.
- All servers and computers containing data are protected by approved security software and firewalls.
- Personal data is never shared informally and must be encrypted before being transferred electronically.