1. Scope and responsibility
Cartonnex Limited is responsible for the personal information it controls in connection with its website, enquiries, quotations, customers, suppliers, projects and day-to-day business administration. This policy applies to directors, workers and anyone authorised to handle that information on the company’s behalf. It should be read with the public Privacy Policy.
Privacy questions, rights requests, suspected incidents and complaints must be directed promptly to tashan@cartonnex.co.uk. Responsibility for investigating and responding must be assigned to someone with suitable authority and access to the relevant records.
2. Data protection principles
Personal information must be processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes; adequate, relevant and limited to what is necessary; accurate and corrected where needed; kept no longer than necessary; and protected by appropriate technical and organisational measures. Cartonnex must be able to demonstrate compliance with these principles.
Information must not be collected merely because it might be useful later. Access is limited to people who need it for an authorised purpose. A new or materially changed use must be assessed before it begins and explained to affected people where required.
3. Lawful processing and accountability
Before processing begins, Cartonnex identifies the purpose, the categories of information and people involved, an appropriate lawful basis, recipients, retention needs and any international transfer. Common bases are requested pre-contract steps, contractual necessity, legal obligations and legitimate interests. Consent is used only where it is genuinely appropriate, freely given, specific, informed and capable of withdrawal.
Special-category and criminal-offence information require additional legal conditions and safeguards. The ordinary enquiry form does not request such information. High-risk, novel or large-scale processing must not begin until the need for a data protection impact assessment has been considered and any required assessment and mitigations are complete.
Cartonnex maintains proportionate records of processing, retention decisions, rights requests, complaints, incidents, processors and any required assessments. Privacy information must be concise, accessible and given when information is collected or within the applicable period when it comes from another source.
4. Individual rights and complaints
Requests for access, correction, erasure, restriction, objection, portability or withdrawal of consent must be recognised and passed promptly to the person responsible. Identity may be verified proportionately. Relevant systems and correspondence must be searched, third-party information and exemptions considered carefully, and the response issued within the statutory period. Requests are normally free, subject to the limited exceptions provided by law.
Cartonnex does not intend to make solely automated decisions through this website that have legal or similarly significant effects. Any future use of such processing requires prior assessment, appropriate transparency and the safeguards required by law.
Anyone may make a data protection complaint by email, post or the website contact form. Receipt must be acknowledged within 30 days. Appropriate enquiries must be made without undue delay, the complainant must be kept informed where appropriate, and the outcome must be provided without undue delay. The complaint and response must be documented, and the person must be told about their right to complain to the Information Commissioner’s Office.
5. Data quality, retention and security
Material records should be reviewed when necessary to keep them accurate. Personal information must be deleted, anonymised or securely disposed of when there is no continuing business or legal reason to retain it. The working retention periods published in the Privacy Policy apply unless a documented exception is necessary.
Security measures are selected according to the information and risk and may include controlled accounts, multi-factor authentication where available, appropriate passwords, maintained software, secure hosting, protected backups, limited sharing, encryption in transit and careful recipient checking. Personal information must not be stored in unapproved locations, reused for an incompatible purpose or disclosed to an unverified recipient.
6. Personal data incidents
Loss, misdirection, unauthorised access, disclosure, alteration, destruction or unusual system behaviour involving personal information must be reported internally without delay. The immediate priorities are to contain the incident, preserve reliable evidence, protect affected people and establish what happened.
Cartonnex records the facts, information and people affected, likely consequences, risk assessment, containment and remedial action. If the breach is likely to risk people’s rights and freedoms, it must be reported to the ICO as soon as possible and, where feasible, within 72 hours of awareness. If the risk is high, affected people must also be informed without undue delay. An initial ICO report may be updated as reliable information becomes available.
Every personal data breach is documented, including the reason for any decision not to notify. After containment, controls and working practices must be reviewed and proportionate improvements completed.
7. Processors, sharing and international transfers
Before appointing a processor, Cartonnex considers its security, privacy practices, location and ability to assist with rights and incidents. The written arrangement must cover the subject matter and duration, instructions, confidentiality, security, sub-processors, assistance, audits, and deletion or return of information as required by law.
Only the minimum relevant information may be shared with a provider, adviser, supplier or project partner. Restricted transfers outside the United Kingdom require an available UK transfer mechanism and any supplementary safeguards indicated by a transfer risk assessment. Processing must not be moved internationally merely for convenience without checking these requirements.
This policy is reviewed when processing, suppliers, risks or legal requirements change. Questions can be sent to Cartonnex Limited, Unit 16 Enterprise Way, Cheltenham Trade Park, Cheltenham, England, GL51 8LZ or tashan@cartonnex.co.uk.