MEHD: Mobility Equipment Hire Direct Ltd
Retail Customers: anyone who books equipment either online via the company website or by telephone and makes payment at time of booking.
Please Note: all telephone orders are ultimately processed through the website by MEHD sales staff. Any personal data written on paper before processing is shredded after processing.
Agents: Anyone, acting on behalf of a company, who registers with Mobility Equipment Hire Direct Ltd to book equipment via the MEHD website and is invoiced for payment once a month. MEHD are a supplier to agents and act on their behalf
Agent Customers: the client of the agent whom the order applies to.
Retail Data subjects: the individuals of whom Mobility Equipment Hire Direct Ltd holds and uses personal data for the purpose of processing website orders, this includes suppliers, retail customers, agents and agent customers.
Non-Retail Data subjects: the individuals of whom Mobility Equipment Hire Direct Ltd holds and uses personal data NOT for the purpose of processing website orders, this includes staff.
Personal Data: data that can identify a person
Non-Personal Data: data that cannot identify a person
This Privacy Statement sets out an overview of how all personal data that we collect from you as the data subject (retail and non-retail) will be processed by us.
- We've updated the policy to explain your privacy rights.
- We've provided you more information about how you can take control of what cookies are used on your computer.
- We completed a third-party privacy firm GDPR assessment, resulting in specific recommendations and GDPR readiness actions.
MEHD acts as a data controller in the United Kingdom for the purposes of any relevant data protection laws. The data you provide is processed fairly and lawfully and used only for the purposes set out in this policy.
MEHD will collect data about you in accordance with our legitimate interests as a data controller. We collect both non-personal data and personal data. Non-personal data includes any data that cannot be used to identify you such as shopping cart data and how users navigate through the website. Personal data includes your name, contact details and any other data that can be used to identify you. We do not store any sensitive personal data.
MEHD will also obtain explicit consent from you before processing any personal data.
We process personal information for certain legitimate business purposes which include some of the following:
- To book equipment with equipment suppliers
- To dispatch equipment either via a courier company, a taxi or some other ground transport service
- For customer service enquiries
- For the purpose of communication
- To improve user experience on the MEHD website(e.g. website chat, address lookup)
- To improve our service and to make our services more relevant to you (including updating our website to enhance your digital experience)
- To carry out our obligations arising from any contracts that MEHD enters into with third parties in relation to providing your mobility equipment
- Where you have consented to being contacted, send you promotions, offers and market information
- To facilitate the MEHD's payroll and invoicing processes
Retail Data Subject personal data is stored in a database with our hosting company VPCART.
The MEHD website has a SSL certificate. This establishes:
All Retail Data Subject personal data in paper format is stored in locked cabinets.
MEHD do not store customer credit card numbers or any other payment information other than invoices, statements and confirmation of payments. Credit card details taken by phone are shredded immediately.
All Non-Retail Data Subject personal data in digital format is stored on in-house computer systems. These computer systems are password protected. Some of this information will be stored in cloud and backup systems. (Including, but not limited to Dropbox and Norton)
Under GDPR Data Subjects have the right to access their personal data.
All Retail Customers and Agents personal data we store can be viewed at any time by logging into your account.
- Retail Customers select the My Account link in the top right hand corner of the site
- Agents select the Agent Login in the Trade section
For Retail Customers and Agents personal data and previous order information can be viewed and modified here. Personal data can be modified at any time by selecting the Update Personal Information page.
Please note: For Agent Customers the lead name and contact number is stored on our system and passed to our supplier to assist with the delivery.
For Non-Retail Subjects and Agent Customers if you wish to request a copy of the personal data we have stored on our system relating to you, please email your request to firstname.lastname@example.org. Please Note: for security purposes your request must be made using the exact email address your request relates to. We will undertake your request within 30 days of submission.
Some personal information that you provide to us may be passed on to our suppliers and the third parties as specified above. Some of these are located outside of the European Economic Area. When we transfer your personal information outside this area, we will take steps to ensure that your privacy rights continue to be protected.
At MEHD we hold personal data for "as long as is necessary" to adhere to our statutory and contractual obligations and in line with our legitimate interests as a data controller. "As long as necessary" considers data processing of holiday bookings as well as to comply with financial services regulations (e.g. accounting and tax).
The GDPR introduces a right for Data Subjects to have personal data erased. This is known as 'the right to be forgotten'. A request to delete personal data should be made by email. Please email your request to email@example.com.
When we receive a delete request we may require further identity verification or to clarify your request. In order to fulfil our legitimate interests as data controller, we may refuse your delete request based on the "as long as necessary" obligation described above.
MEHD will delete personal data after the "as long as necessary" period if we have not had any meaningful contact with the Data Subject or if we do not hold any records on you that are in our legitimate interests to keep. "Meaningful contact" means contact that adds to the information we already have about you.
We also keep all payroll records, holiday pay, sick pay and pension's auto-enrolment records for as long as is legally required by HMRC and associated national minimum wage, social security and tax legislation.
We use Mailchimp for all our marketing campaigns and there is always a link to unsubscribe at the bottom of the email. Our marketing campaigns include information about special offers and the latest products to be added to the website
If you wish to contact us about any of this or request that we delete you from our mailing list then please email firstname.lastname@example.org
MEHD takes every precaution to protect our users' information. We use the following security measures to safeguard your data;
- Firewalls including anti-spyware software
- Anti-virus software (Norton)
- Anti-spam filters
- All data is backed up daily
- All files/data are stored on password protected systems
- Only employees who need the information to perform a specific job (for example, Equipment Administrator, our accounts clerk or a marketing assistant) are granted access to your information.
MEHD uses all reasonable efforts to safeguard your personal information. However, you should be aware that the use of email/the Internet is not entirely secure and for this reason MEHD cannot guarantee the security or integrity of any personal information which is transferred from you or to you via email/the internet.
The following information is transmitted by us across the internet:
- Correspondence with suppliers to fulfil an order on behalf of the customer (usually but not limited to the lead passenger name, contact phone number, and flight information). This is usually done by email.
- MEHD might occasionally share information with a 3rd party via Dropbox.
In the unlikely event of any data breach, we will notify the appropriate supervisory authority within 72 hours of discovering the breach.
In the unlikely event of such a data breach resulting in a high risk to the rights and freedoms of individuals, we will notify those individuals wherever feasible within 72 hours of discovering the breach.
Any queries or complaints relating to our data protection policy, should be directed to our Data Protection Officer via email: email@example.com. We will aim to respond to any requests within 5 working days of receipt.
The MEHD website monitors how visitors use its website to improve services. The information collected does not allow any individual to be identified, and is only be used to understand the website users better. We may also undertake marketing profiling to help us identify services that may be of interest to you.
If you have any questions, comments or requests regarding this policy, the Mobility Equipment Hire Direct Site or our products, please email us at: firstname.lastname@example.org. Alternatively, you can write to us at: Customer Services Team, Mobility Equipment Hire Direct Ltd, 10 North Grange Rd, Bearsden, Glasgow G61 3AE, Scotland.