Privacy and Cookie Policy

  1. Introduction

This Privacy Policy explains what information First Capital Corporation Limited (“we”, “our”, “us”, “FirstCapital”) will collect relating to any individual (“personal data”) in the course of providing any of our services (“Service”) to a client or receiving services from a supplier (“you”, “your”), as well as the purpose and legal basis for that processing and the circumstances in which such personal data could be provided by us to third parties. This Policy also explains how you can manage the information we hold and how you can contact us. Please keep us informed if the personal data provided to us changes during your relationship with us by e-mailing info@firstcapital.co.uk. Our corporate information is in Section 4 below.

We are usually acting as a controller under the Data Protection Act 2018 (“DPA”) in relation to the personal data we process. Capitalised terms used in this Privacy Policy that are not otherwise defined where they first appear shall have the meaning given to them in the DPA or any FirstCapital engagement letter of which this Privacy Policy forms part (“Engagement Letter”) when you agree to receive a Service from us as a client (“Client”) or, where you are a supplier of service to us or a Client (“Supplier”), the agreement that we have with you for that purpose (“Supplier Agreement”).

  1. Collection, purpose and legal basis for Processing

We may collect and process the personal data for the purposes, and on the legal basis, specified in specified in Schedule 1 to this Privacy Policy.

FirstCapital is committed to your privacy and protecting and respecting any personal information you share with us.

We do not use any automated decision-making tools within our business.

We will always give you the option not to receive marketing communications from us. We will never send you unsolicited ‘junk’ email or communications, or share personal data with anyone else who might do so. We do not sell personal data to third parties, but we do work closely with selected partners who help us to provide each Service to you.

  1. Changes to Privacy Policy

We reserve the right to add to or change the terms of this Privacy Policy. If we change this Privacy Policy, we will post the new Privacy Policy here and contact Clients and Suppliers directly to notify them of the changes. It is your responsibility as a Client or Supplier to inform any person whose personal data you have provided to us of those changes.

  1. Who are we?

We are First Capital Corporation Limited, Company No 3881209, trading as FirstCapital.

You may contact us by mail at our head office and administration centre, located at 52 Cornhill, London, EC3V 3PD, or by phone on +44(0)208 563 1563, or by email at info@firstcapital.co.uk.

If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact us using the above.

Our Data Protection Registration Number is Z7783085

  1. What happens if you fail to provide personal data

Where we need to collect personal data by law in relation to the supply of our Services, or under the terms of an Engagement Letter (for example, information required to identity you or your beneficial owner(s)) and you fail to provide that personal data when requested, we may not be able to agree an Engagement Letter or proceed with our Service(s).

  1. Sharing your information

We do not sell your information to third parties, but we do work closely with some third-party suppliers who fulfil business activities for us (like marketing etc.), service providers who help us to deliver the Service to you, such as third party technology companies who may provide elements of the Service functionality, and our group companies (“Third Party Service Providers”). We only disclose personal data to Third Party Service Providers for the purposes explained in Schedule 1 of this Policy.

We require all third parties to respect the security of any personal data we share with them and to treat it in accordance with the DPA. We do not allow our Third-Party Service Providers to use personal data we share with them for their own external commercial purposes and only permit them to process personal data we share with them for specified purposes in connection with the supply of their service to us and in accordance with our instructions.

  1. Location of your information and its security

We store personal data within the United Kingdom.

We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy. We regularly review our data security efforts to ensure that we use appropriate technical and organisational measures procedures to protect your personal data from unauthorised or unlawful processing and against accidental loss, destruction or damage.

We use encryption technology to reduce the risk of personal data being accessed by unauthorised persons, but as the Internet and mobile networks are not completely secure we cannot guarantee the security of personal data while it is being transmitted to or from us, so any transmission is at your own risk.

One of our mailing software providers, The Rocket Science Group LLC, trading as “Mailchimp” is based in the United States. We may transfer to Mailchimp the personal data specified in the relevant section of Schedule 1 so they can mail our communications to you. That transfer takes place under the that forms part of our agreement with Mailchimp, to ensure similar protection for personal data held in the US as in the UK.

We do not outsource elements of our Service to third parties.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

If you think that any part of our personal data processing may not be secure, please email us at data.admin@firstcapital.co.uk. Feedback such as this is always encouraged.

  1. Retaining your information

We will not hold your personal information in an identifiable format for any longer than is necessary (including for legal and compliance reasons). We will store personal data for the duration of any applicable Engagement Letter or Supplier Agreement and for such time thereafter as required by Applicable Law or the limitation period for bringing contractual claims under or in relation to the Engagement Letter or Supplier Agreement, as the case may be.

If we collect your data in respect of a potential business relationship that didn’t proceed, we will retain this data for as long as there is a legitimate business reason or regulatory purpose to do so.

  1. Processing of personal data not provided to us by you

Anti-fraud and anti-money laundering. As required by Applicable Law, we will also check your identity and other personal details with a fraud prevention agency/agencies and credit reference agencies. If you give false or inaccurate information and we identify fraud, this will be recorded and may be shared by those agencies with other organisations, so that we and those other organisations, including law enforcement agencies and debt collection agencies, may access, use and search these records to:

  • help make decisions about credit and credit related services, for you and members of your household;
  • help make decisions on motor, household, credit, life and other insurance proposals and insurance claims, for you and members of your household;
  • trace debtors, recover debt, prevent fraud, and to manage your accounts or insurance policies;
  • prevent fraud and money laundering, for example, when:
  • Checking details on applications for credit and credit related or other facilities;
  • Managing credit and credit related accounts or facilities;
  • Checking details on proposals and claims for all types of insurance; and
  • Checking details of job applicants and employees.

More information about credit reference agencies, their role as fraud prevention agencies, the data they hold, for how long, your rights and how they use personal data is available at the following links to each agency’s Credit Reference Agency Information Notice:

 Call Credit:

 Equifax

 Experian:

Psychometric testing. As part of our internal hiring process, we may arrange for psychometric tests through either DISC or Outmatch,.  We book the tests either through a Sandler Training representative or directly, and links to the tests are provided directly to the candidate undertaking the test(s), so the personal data of the candidate is not provided to DISC or Outmatch by us; and the candidate provides any personal data directly to DISC or Outmatch. We are then only supplied with the results of the psychometric tests on the basis agreed by the candidate with DISC or Outmatch, which we may use for the purpose and on the legal basis described in Schedule 1 to this policy. Sandler Training, DISC and Outmatch are based in the United States. Their privacy policies are displayed at:

  1. Managing personal data and DPA Rights

The table in Schedule 2 to this Privacy Policy explains the rights of data subjects in relation to their personal data under the DPA and how to exercise them.

This Privacy Policy provides confirmation of the details required in relation to the right of access.

  1. Use of Cookies

A cookie is a small text file of letters and numbers that we store on your browser or digital device. Cookies send information back to the originating website on each subsequent visit, or to another website which recognize that cookie.

Generally, there are four types of cookies:

  • Necessary cookies, required for the operation of the Service. They enable you to log into secure accounts and use interactive features, for example.
  • Analytical/performance cookies, which allow us to ecognize and count the number of visitors and users and how they use the Service. This and related services such as Google Analytics, helps us improve how the Service works, by ensuring users find what they are looking for more easily, for example.
  • Functionality cookies, which ecognize when you return to the Service, so we can greet users by name and associate them with their stored preferences; and
  • Targeting cookies (which we do not use), which record your visit to a site and potentially other sites, the pages you have visited and the links you have followed so that the site you visit and third parties’ sites could make the information displayed on them more relevant to your interests and/or serve advertisements.

The information in Schedule 1 covers any use of cookies by us that involves us collecting and processing personal data about you.

Please note that third parties (including, for example, providers of external services like web traffic analysis services) may also use cookies, over which we have no control. You should refer to their Privacy Policies or Cookie Policies for the relevant information about those cookies.

You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. All browsers provide tools that allow you to control how you handle cookies: accept, reject or delete them. These settings are normally accessed via the ‘settings’, ‘preferences’ or ‘options’ menu of the browser you are using, but you could also look for a ‘help’ function or contact the browser provider. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our website.

  1. Links to third parties

Our website may contain links to other websites and services. You should read their privacy policies before providing personal data via those websites or services. We shall not be held responsible for the privacy policies of such other sites and services or their personal data processing.

  1. Comments, questions, and complaints

If you have any questions regarding this notice or if you would like to speak to us about the manner in which we process your personal data, please email data.admin@firstcapital.co.uk or telephone 0208 563 1563

You also have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues, at any time. The ICO’s contact details are as follows:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113 (local rate) or 01625 545 745  – Website: https://ico.org.uk/concerns

Schedule 1

Personal Data Collected Purpose Basis for processing
(a)        Personal data that you provide by filling in forms on the Service. This includes information provided at the time of registering to use the Service, posting material or requesting further services. We may also ask you for information when you report a problem with the Service;

(b)        Your name and contact details, including your e-mail address, home address and telephone numbers;

(c)        Records of any correspondence between you and FirstCapital;

(d)        Details of actions you carry out through the Service;

(e) Details of your visits to the Service and the resources that you access;

(f) payment account and payment transaction data;

 

·       to manage and administer the Service;

·       to enable you to use the Service;

·       to deal with enquiries, complaints and feedback from you;

·       To give you any notices under the Service Terms;

·       To keep you informed about payments you initiate or information that you allow access to via the Service;

·       To categorise payment transactions according to the type or purpose of goods or services purchased;

·       To update FirstCapital’s records;

·       To identify, prevent, detect or tackle fraud, money laundering and other crime;

·       To carry out checks required by applicable regulation or regulatory guidance;

·       To carry out our obligations arising from and exercise our rights under, any agreements between you and us, including tracing and recovering payments and debts;

·       To check any instructions given to us, for training purposes, for crime prevention and to improve the quality of our customer service.

To disclose to third parties:

·       Where you have requested and consented for us to introduce you to another person or organisation, e.g. to a law firm or due diligence provider.

·       Where we are obliged to do so in law.

·       If it is under a duty to disclose or share your personal data in order to comply with any legal obligation;

·       To enforce this Privacy Policy or the Service Terms;

·       to a credit reference agency to check your identity and to prevent fraud, (it will also keep a record of your request and use it whenever anyone applies to be authenticated in your name);

·       to Third Party Service Providers, agents and subcontractors, acting for us, to use for the purpose of operating the Service;

·       to anti-fraud agencies, for the purpose of preventing and detecting fraud;

·       to debt collectors and other third parties to trace you and recover any debt;

·       In the event that FirstCapital sells any business or assets, in which case it may disclose your personal data to the prospective seller or buyer of such business or assets;

·       To protect the rights, property, or safety of it, its customers, or others (which includes exchanging information with other companies and organisations for the purposes of fraud protection);

·       To investigate, prevent or detect fraud or carry out checks against money laundering;

·       For audit purposes and to meet obligations to any relevant regulatory authority or taxing authority.

 

The processing is necessary for:

·       the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract;

·       compliance with a legal obligation to which we are subject;

·       the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.

Information about the device(s) you use to access the Service and your visits to and use of the Service (including your Internet Protocol address, location, browser/platform type and version, internet service provider, operating system, referral source, exit pages, length of visit, page views, website navigation and search terms used, and preferences for receiving different types of communications from us)

 

·       To improve your browsing experience by personalising the Service;

·       To develop and improve the Service;

·       To ensure that content on the Service is presented in the most effective manner for you and for your computer;

·       To meet our obligations concerning the types of communications you have opted to receive.

To disclose to third parties:

·       To comply with a current judicial proceeding, a court order or legal process served on us, any request by the FCA or any other regulator who may have jurisdiction over us from time to time or for audit purposes and to meet obligations to any relevant regulatory authority or taxing authority;

·       To enforce this Privacy Policy or the Service Terms;

 

The processing is necessary for:

·       the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract;

·       the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.

Copies of passports or other identification evidence that you provide for anti-money laundering and anti-fraud purposes;

 

·       To identify, prevent, detect or tackle fraud, money laundering and other crime;

·       To carry out checks required by applicable regulation or regulatory guidance;

To disclose to third parties for:

·       To comply with a current judicial proceeding, a court order or legal process served on us, any request by the FCA or any other regulator who may have jurisdiction over us from time to time or for audit purposes and to meet obligations to any relevant regulatory authority or taxing authority;

·       To enforce this Privacy Policy or the Service Terms;

·       To a credit reference agency to check your identity and to prevent fraud, (it will also keep a record of your request and use it whenever anyone applies to be authenticated in your name);

·       To anti-fraud agencies, for the purpose of preventing and detecting fraud;

 

The processing is necessary for:

·       the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract;

·       compliance with a legal obligation to which we are subject;

·       the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.

Psychometric test reports

 

·       to evaluate candidates for employment purposes; The processing is necessary for:

·       the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract;

·       the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.

 

Your email address

 

·       To send you email communications in accordance with your communication settings;

·       To disclose to Mailchimp to undertake mailing on our behalf, on the basis of the Data Processing Agreement described in Section 7 of this Policy.

The processing is necessary for:

·       the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract;

·       compliance with a legal obligation to which we are subject;

·       the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.

Records of any surveys that you may be asked to complete;

Your e-mail address.

 

·       To provide you with information, products or services that you request or which FirstCapital decides may interest you;

·       For statistical analysis;

·       To identify which elements of the Service or other products might interest you.

To disclose to third parties for:

·       Where we have asked them to provide marketing services, and you have provided consent

 

With your consent

Schedule 2

Your Rights

Your Rights and How to Exercise Them Exception
Right of Access: To obtain from us confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and the following information: (a) the purposes of the processing; (b) the categories of personal data concerned; (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; (d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; (e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning youor to object to such processing; (f) the right to lodge a complaint with a supervisory authority; (g) where the personal data are not collected from you, any available information as to their source; (h) the existence of automated decision-making, including profiling, referred to in Article 22(1) of the GDPR and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for you.

How to exercise:

This Privacy Policy provides confirmation of the details required in relation to your right of access.

Under the DPA, you have a right to access certain personal records that FirstCapital holds about you. Any access request may be subject to a fee to meet FirstCapital’s costs in providing you with details of the information they hold about you if the request is unfounded or excessive. You can exercise the right at any time by contacting FirstCapital at data.admin@firstcapital.co.uk.

 

Right to rectification: to obtain from us without undue delay the rectification of inaccurate personal data concerning you.

We must communication to each recipient to whom the rectified personal data have been disclosed, unless this proves impossible or involves disproportionate effort.

We shall inform you about those recipients if you request it.

You can exercise the right at any time by contacting FirstCapital at data.admin@firstcapital.co.uk.

Right to erasure: to obtain from us the erasure of personal data concerning you without undue delay where:

(a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

(c) you object to the processing based on legitimate interest where there are no overriding legitimate grounds for the processing;

(d) the personal data have been unlawfully processed;

(e) the personal data have to be erased for compliance with a legal obligation to which we are subject.

We must communication to each recipient to whom the erased personal data have been disclosed, unless this proves impossible or involves disproportionate effort.

We shall inform you about those recipients if you request it.

You can exercise the right at any time by contacting FirstCapital at data.admin@firstcapital.co.uk.

Processing is necessary for

(b) compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in us; or

(e) the establishment, exercise or defence of legal claims.

Right to request the restriction of processing concerning you: to obtain from us restriction of processing where:

(a) the accuracy of the personal data is contested by you, for a period enabling us to verify the accuracy of the personal data;

(b) the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;

(c) we no longer need the personal data for the purposes of the processing, but it is required by you for the establishment, exercise or defence of legal claims;

(d) you object to the processing based on legitimate interest pending the verification whether our legitimate grounds override yours.

We must communication to each recipient to whom the restricted personal data have been disclosed, unless this proves impossible or involves disproportionate effort.

We shall inform you about those recipients if you request it.

You can exercise the right at any time by contacting FirstCapital at data.admin@firstcapital.co.uk.

Where processing has been restricted under this right, such personal data shall, with the exception of storage, only be processed:

(a)   with your consent; or

(b)   for the establishment, exercise or defence of legal claims; or

(c)   for the protection of the rights of another natural or legal person; or

(d)   for reasons of important public interest of the Union or of a Member State.

 

The right to data portability: to receive the personal data concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from us, where:

(a) the processing is based on consent or is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract; and

(b) the processing is carried out by automated means.

The exercise of this right shall be without prejudice to the right to erasure.

You have the right to have the personal data transmitted directly from us to another controller, where technically feasible.

You can exercise the right at any time by contacting FirstCapital at data.admin@firstcapital.co.uk.

 

That right shall not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us.

 

The right to object to processing: to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on processing necessary for the purposes of the legitimate interests pursued by us or a third party (except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data), including profiling.

You can exercise the right at any time by contacting FirstCapital at data.admin@firstcapital.co.uk.

Where:

(a)   we demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject; or

(b)   for the establishment, exercise or defence of legal claims.

 

The right to ask us not to process your personal data for direct marketing purposes: to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.

You have the right to ask FirstCapital not to process your personal data for marketing purposes. FirstCapital will usually inform you (before collecting your data) if it intends to use your data for such purposes or if it intends to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms used to collect your data.

You can also exercise the right at any time by contacting FirstCapital at data.admin@firstcapital.co.uk.

The right not to be subject to automated individual decision-making, including profiling: to not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

You can exercise the right at any time by contacting FirstCapital at data.admin@firstcapital.co.uk.

If the decision:

(a) is necessary for entering into, or performance of, a contract between you and us;

(b) is authorised by Union or Member State law to which we are subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or

(c) is based on the data subject’s explicit consent.

In the cases referred to in points (a) and (c) we shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on our part, to express his or her point of view and to contest the decision.