Privacy
Policy

Overview

This Privacy Protection Policy explains the principles and arrangements that Creatio Limited (“Creatio”) follows when collecting, using, storing, sharing and protecting personal data. It supports our compliance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and other applicable data-protection legislation. Client contracts contain appropriate data-processing provisions, and we have data-processing agreements in place with sub-processors where required by Article 28 of the UK GDPR.

The Privacy Protection Policy applies to all staff, contractors, partners, clients and third parties who process PII on behalf of Creatio Limited (“Creatio”) and is published on our corporate website and in the footer of each of the creatiogreen websites.

Looking after the personal information you share with Creatio is very important to us, and we want you to be:

  • Aware of the data we collect on behalf of Creatio and/or our clients.

  • Confident that your personal data is kept safely and securely.

  • Aware of how we use the data we hold.

  • Aware of your options you have in relation to opting out of having your data stored.

  • Confident that Creatio considers compliance with GDPR legislation and requirements during design when we consider developing new services and/or features.

ICO Statement

Creatio is registered with the Information Commissioner’s Office (ICO) and is committed to following its guidelines to safeguard the data we hold in any way we can, in an endeavour to prevent any PII breaches affecting our staff, contractors and clients. Our ICO registration can be found at https://ico.org.uk/ESDWebPages/Entry/Z185906X.

Data Protection Principles

We apply the following strict rules in the use of personal data, and we ensure the information we hold is:

  • Used fairly, lawfully and transparently

  • Used for specified and explicit purposes only

  • Used in a way that is adequate, relevant and limited to only what is necessary

  • Accurate (information that is within our control), and where necessary, kept up to date

  • Kept for no longer than is necessary

  • Handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage.

Data Protection by Design and Impact Assessments

Creatio considers data protection by design and by default when developing or materially changing its services, introducing new technology, engaging a new sub-processor or integration, or changing how personal data is collected, used, shared or retained.

DPIA screening is completed when new or materially changed processing involving personal data is considered, in accordance with the ROPA and DPIA Assessment Procedure. Where the screening indicates that the processing is likely to result in a high risk to individuals’ rights and freedoms, a full Data Protection Impact Assessment is completed before the processing begins. The assessment records the proposed processing, its necessity and proportionality, the risks to individuals and the measures adopted to reduce those risks. Assessments and screening decisions are retained and reviewed when the processing or associated risks materially change.

Records of Processing Activities and Data Protection Impact Assessments

Creatio maintains a Record of Processing Activities (ROPA) covering the personal-data processing it undertakes as controller and processor. The ROPA records the nature and purpose of the processing, the categories of individuals and personal data involved, Creatio’s role, recipients and sub-processors, international transfers, retention arrangements and relevant technical and organisational security measures.

A ROPA record must be created or updated when Creatio introduces or materially changes a service, feature, integration, supplier, sub-processor, client requirement or other activity involving personal data. Existing ROPA records are reviewed at least annually and whenever there is a material change to the processing.

DPIA screening is completed as part of the ROPA review. Where the screening identifies that processing is likely to result in a high risk to individuals, Creatio will complete and approve a separate Data Protection Impact Assessment before the processing begins.

The DPIA process considers the nature, scope, context and purposes of the processing, its necessity and proportionality, the risks to individuals and the measures required to reduce those risks. Where Creatio acts as processor, it will support the relevant client in meeting its responsibilities and will assess Creatio’s own technical, contractual, security and operational arrangements.

The Head of Corporate Governance coordinates the ROPA and DPIA records. Relevant Account Managers and Heads of Department are responsible for identifying proposed or changed processing and initiating a review in accordance with the ROPA and DPIA Assessment Procedure.

Information we collect for clients, why and how it may be used

Creatio provides a software solution – primarily to various education companies - which is called creatiogreen (each client calls their version of the software solution by a specific name) – and we generally act as the data processor and the relevant client acts as the data controller.

The creatiogreen software solution is delivered under a contractual agreement with each client and the client is responsible and leads on the configuration of the software to meet their business operations and needs and therefore decides the data they collect and which we then hold on their behalf. The data collected by each client is done so in accordance with their data needs and they process it in accordance with their own specific data processing policies and arrangements. 

Therefore, if you have any queries about the data collected on a version of the creatiogreen software then please contact the client directly or contact Creatio (contact details are at the end of this policy) and we will provide you with their contact details where relevant.

Each client, as controller, is responsible for determining the purposes and lawful basis for its processing and for providing appropriate privacy information to individuals. Creatio remains responsible for meeting its own legal, contractual and security obligations as a processor.

The law states organisations must have one or more of these reasons for collecting personal data and these are:

  • Consent - the individual has given clear consent to process their personal data for a specific purpose. As outlined below, each client using the creatiogreen software can configure the consent features to reflect their own wording and approach including outlining how consent can be withdrawn.

  • Contract - personal information is processed to fulfil a contractual arrangement. Creatio has a contractual agreement with each client, staff member or contractor. We hold and process data in line with clients’ configuration decisions, staff contracts and HR arrangements.

  • Legal obligation - processing is necessary for some of our clients to comply with various legislation requirements that apply to their business and operations - many of our clients are subject to clear regulatory requirements that apply to their sector(s).

  • Vital interests - processing is necessary to protect someone’s life or in the event of an emergency.

  • Public task - processing is necessary for our clients to perform a task in the public interest or for their official functions, and the task or function has a clear basis in law. This reason may apply to some of our clients.

  • Legitimate interests - processing is necessary for our client’s legitimate interests or the legitimate interests of a third-party they may use unless there is good reason to protect the individual’s personal data which overrides those legitimate interests. Also, this is the main reason Creatio holds personal data such as in relation to our staff and/or client’s staff and contacts (e.g. name and contact details).

In relation to Creatio and the data we collect and hold for our business purposes, our main reason for collecting personal information is to provide and improve the services, products, and experiences that our staff and clients expect from us.

The following table provides an indication of the typical data sets we hold for staff, contractors, clients, partners, and third parties and which are likely to contain personal data.

Main client data sets we collect Our reason for collecting this information (legal basis) Creatio and Client’s possible use of the data – note this is a high-level summary of typical reasons we see/are aware of and you should contact each client for specific details on the way they may use the data they collect via the creatiogreen software

User details - entered in creatiogreen as part of setting up or maintaining a User Account. As a minimum this contains first name, last name, and email address per User.

Some clients may configure their version of the creatiogreen software to hold photos, CVs, certificate details and other personal details per User type such as home address.

Creatio processes this information on the documented instructions of the relevant client under our contractual data-processing arrangements. The client, as data controller, determines the applicable lawful basis. Please refer to the client’s privacy notice for details.

Creatio does not use the data collected by our clients other than as part of the service we provide under our contractual agreement with each client.

As with most software solutions a User must be registered before they can use and access the system.

Each client can configure the fields and therefore the data they collect per User type and for assigning the relevant access rights in accordance with their business arrangements.

Also, each client can add a clear ‘consent’-related statement/field which Users should accept and agree to when creating a user account – again, whether this field is included and its wording are decided by each client.

A User would need to contact the relevant client to obtain the reason they collect the information they do, what they may do with the data once collected, and how it is used with third-party systems they have asked Creatio to interface or exchange data with under their contract with Creatio.

Customer/organisation details – including contacts, staff, email addresses, finance including bank card details and other business premises (e.g. sites).

Some clients may configure their version of the creatiogreen software to hold photos, CVs, certificate details and other personal details per record type.

Creatio processes this information on the documented instructions of the relevant client under our contractual data-processing arrangements. The client, as data controller, determines the applicable lawful basis. Please refer to the client’s privacy notice for details.

Creatio does not use the data collected by our clients other than as part of the service we provide under our contractual agreement with each client.

The creatiogreen software can be configured to capture details for our clients in relation to their customers and their associated organisations and companies – including their key contacts, staff details and other venues. All these record types have the potential to contain personal details.

Each client can configure the fields and therefore the data they collect per record type and add a clear ‘consent’ statement/field which users should accept and agree to upon creating a user account – again, the inclusion or not of this field and its wording is decided by each client.

You would need to contact the relevant client to obtain the reason they collect the information they do, what they may do with the data once collected, and how it is used with third-party systems they have asked us to interface or exchange data with under their agreement with us.

Learner details – including name, age, gender and possibly home and contact details and national learner number identifier details.

Also details of the qualifications they have achieved/been registered against and details of the grades/outcomes of their education activities.

Some clients may configure their version of the creatiogreen software to hold photos and other personal details.

Creatio processes this information on the documented instructions of the relevant client under our contractual data-processing arrangements. The client, as data controller, determines the applicable lawful basis. Please refer to the client’s privacy notice for details.

Creatio does not use the data collected by our clients other than as part of the service we provide under our contractual agreement with each client.

The creatiogreen software supports various education bodies and depending on the modules they use within the software it can capture details of learners registered with our clients in relation to the qualifications and products they offer.

Each client can configure the fields associated with learners and add a clear ‘consent’ statement/field in relation to learner records – again, whether this field is included and its wording are decided by each client.

You would need to contact the relevant client to obtain the reason they collect the information they do, what they may do with the data once collected, and how it is used with third-party systems they have asked us to interface or exchange data with under their agreement with us.

Information that may be provided when completing a business process outlined by our clients and which is supported by the creatiogreen software – such as giving information or details when completing a client’s online form or log in the software solution.

This may also include additional files you may upload when addressing requirements outlined by the client in the Form(s). Or comments Users may make in the Form(s) or pass in relation to information exchanged with the client organisation.

This may include information or comments provided in relation to other staff, colleagues, Users or learners at your organisation – such as comments in relation to grading information or performance.

Creatio processes this information on the documented instructions of the relevant client under our contractual data-processing arrangements. The client, as data controller, determines the applicable lawful basis. Please refer to the client’s privacy notice for details.

Creatio does not use the data collected by our clients other than as part of the service we provide under our contractual agreement with each client.

In relation to information entered in the creatiogreen software via forms or onscreen fields there are various reports in the system that will extract this data for the client – for Users they have authorised with such access rights.

Equally clients can configure forms to automatically update a customer’s profile at the end of a transaction (e.g. automated processing).

You would need to contact the relevant client to obtain the reason they collect the information they do, what they may do with the data once collected, and how it is used with third-party systems they have asked us to interface or exchange data with under their agreement with us, as well as to understand any automated decision-making processes they use with the data held in the system.

Information we collect - why and how it may be used

We collect personal information that you share with us when you are employed by Creatio or you contact us or interact with us through our website, social media, email, phone, in person at meetings, and events, or other similar interactions. For example, you will provide information to us when you contact us and/or our staff, invite us to tender for a contract, place an order, complete a survey, competition, or questionnaire, update your preferences and account information, connect with us through our websites.

Additional main data sets we collect Our reason for collecting this information (legal basis) Creatio’s possible use of the data – note this is a high-level summary of typical reasons we see/are aware of

Staff details - personal details in relation to our staff including date of birth, personal contacts, home address and personal email addresses, finance including bank account and payroll details and identification documentation (such as passports and driving licenses).

This may include details that have been provided for HR and payroll arrangements and documentation and details provided to carry out DBS checks.

We process staff information where necessary to perform employment contracts, comply with our legal obligations and pursue our legitimate interests in managing the business, staff and workplace.

Where we process health or other special-category information, we also identify an applicable Article 9 condition. Criminal-offence information, including information used for DBS checks, is processed only where permitted by law and subject to appropriate safeguards.

We use the data for internal and external HR and payroll arrangements, emergencies and DBS security checks for employed staff.

Data is only retained for as reasonably necessary in line with GDPR legislation.

Head office Closed-circuit television (CCTV) Footage – records identifiable people.

We collect for our legitimate business interests to prevent crime, help support staff and public safety, and our secure premises and assets and providing valuable evidence in the case of incidents / investigations.

Creatio does not use this data to monitor staff behaviour and attendance to the office.

We have CCTV installed at our offices and have signs to inform staff and visitors of these arrangements.

We only use this data in the event to safeguard staff and visitors or to help investigations of incidents and data is only monitored by our Managing Director in the event of an incident and retained for no longer than is necessary and is only provided to the necessary authorities upon request to help with investigations.

Creatio corporate website and social media – data collected including (IP) address, browser software you use, the device you use, your operating system, the date and time of access, the internet address of the website from which you link through to our website, information on how you use our website and the activities you undertook, crash data if an error occurred.

We use cookies and similar technologies in accordance with PECR and applicable data-protection legislation. Cookies that are strictly necessary for the operation and security of the service may be used without consent where permitted by law. For other cookies, we obtain consent or rely on an applicable statutory exception. Where an exception requires us to provide a means of objecting, users are given a clear and simple way to do so.

We may interact with you on social media. You may use social media to contact us about our creatiogreen software and services.

The information we collect from social media and online sites sometimes includes personal information that has been put online and is publicly available. We make sure any information we use is done so in accordance with the arrangements in this policy and either properly credited to its source or is made anonymous. These online and social media sites typically have their own privacy policies explaining how they use and share personal information.

Prospective Client Data - data collected including names, job titles, organisations, business email addresses, telephone numbers and information provided through website enquiries, emails, meetings, demonstrations, tenders, referrals and other sales enquiries.

To respond to enquiries, prepare tenders and proposals, discuss potential services and pursue Creatio’s legitimate business interests. Where someone asks us to take steps before entering into a contract, we may also process their information for that purpose.

To respond to enquiries, communicate with prospective clients, prepare tenders and proposals, arrange demonstrations and meetings and manage potential business opportunities. We may also provide relevant business updates where permitted by data protection and electronic marketing rules.

creatiogreen software analytical data collected - including (IP) address, browser software you use, the date and time of access, the internet address of the website from which you link through to our creatiogreen software, information on how you use our creatiogreen software and the activities you undertook, crash data if an error occurred.

We collect data and review data from our creatiogreen software to better understand the conditions in which our creatiogreen software is used/accessed and for investigation purposes in the event of any Cyber Security incidents which may have originated from a client or their customers or Creatio.

To help us deliver on our contract obligations with our clients and optimise the network security and performance, and deal with fixing bugs/defects in the software we provide.

Review the usage of various parts of the software to inform future enhancements and upgrades to the software and service.

Prevent, detect, or investigate fraudulent activity or inappropriate and offensive use or behaviour and to identify violations of service policies.

Support – where required by law or where we believe it is necessary to protect our legal rights, interests, and the interests of others - use information about you in connection with legal claims, compliance, regulatory, and audit functions.

Transform client helpdesk data collected - including User’s first name, surname, and contact details.

We collect for our legitimate business reasons to support the delivery of our services and respond to queries/requests.

And to notify clients about enhancements to our services, such as our regular software updates.

Contact users to carry out KIT meetings, clarify change requirements or assist with bugs/defects that have been reported.

Contact Users to undertake customer satisfaction surveys or invite them to provide product reviews or to inform market research activities.

If you share details of other people with us (for example, your staff/colleagues), then you will need to check with that person that they are happy for you to share their personal information with us, and for us to use it in accordance with this policy.

Use of Cookies

The creatiogreen system and company corporate website(s) use cookies to collect and store certain information. These typically involve pieces of information or code that a website transfers to or accesses from your computer hard drive or mobile device to store and sometimes track information about you. Cookies allow us to create a unique device ID to enable you to be remembered when using that computer or device to interact with websites and online services and can be used to distinguish Users and manage a range of features and content, including storing searches and presenting personalised content to improve your experience.

It is important to note that most cookies we use expire when you close your browser or log out of the system. Others are used to remember you when you return to our system and will last for longer. We use these cookies on the basis that they are necessary for performance of a contract with our clients, or because using them is in our legitimate interests (where we have considered that these are not overridden by your rights), and, in some cases, where required by law, where you have consented to their use.

We use the following types of cookies:

  • Necessary cookies. Required to enable core site functionality and to remember user preferences and choices, such as language preferences or customised settings. Always activated. These cookies that are required for the operation of our creatiogreen system and website(s). They include, for example, cookies that enable you to log into secure areas of our website.

  • Performance/Analytic cookies. These cookies provide quantitative measures of website visitors. With the usage of cookies, we can count visits and traffic sources to improve the performance of our creatiogreen system and website(s) when they are using it. This helps us for our legitimate interests of improving the way they work, for example, by ensuring that users are finding what they are looking for easily.

  • Functionality cookies. These are used to recognise you when you return to our creatiogreen system. This enables us to personalise content relevant to your user permissions.

Most web browsers automatically accept cookies, but if you prefer, you can change your browser to prevent these cookies. The effect of disabling cookies depends on which cookies you disable, but in general, our creatiogreen system will not operate properly if al cookies are switched off.

Who do we share your personal information with?

We may share your personal information with companies that support our clients if the clients require us to interface or exchange data with them in accordance with the scope of the contractual agreement with Creatio to meet their business needs or data portability arrangements. You should therefore contact the client direct to understand the data they have requested to be shared and what they may do with this data (also note it is our client’s responsibility to make it clear in their consent text and/or privacy policies how data you provide is used across different systems they use for their business purposes). Examples of other organisations/systems with whom such data may be shared:

  • Companies that provide financial software to our clients.

  • Companies that provide examination or e-portfolio systems to our clients.

  • Companies that provide certification, print and marketing materials to our clients.

  • Government bodies that require information from our clients (e.g., for regulatory reasons).

  • Clients’ in-house systems to hold or process data they extract from the creatiogreen software and system.

  • Police and/or regulatory bodies to support a client involved in significant malpractice investigations.

In relation to data Creatio holds for its own business purposes we do not share this with external parties except for:

  • Our external Accountancy company, UK Government (HM Revenue & Customs) or pension bodies in relation to details we hold for our staff such as payroll, pensions etc.

  • Our external HR services for the benefits schemes provided to our staff such as leave / absence reporting, healthcare provision and cycle to work schemes.

  • Other companies where you have given us permission to share the data/make an introduction (e.g. to another company/IT supplier in the sector who may be able to help you or your organisation). 

All the data is captured on:

  • creatiogreen software and system is hosted and stored in the UK through our hosting provider Iomart.

  • We use selected third-party service providers and sub-processors to support the delivery of our services. Some of these providers may process personal information outside the UK. Where personal information is transferred internationally, we ensure that an appropriate safeguard is in place in accordance with UK data-protection requirements. We maintain a separate document containing further information about the sub-processors used in delivering creatiogreen, which is available to clients and prospective clients on request.

  • We use Gmail to support our corporate email arrangements.

  • The creatiogreen system sends transactional emails via UK servers only. Email servers retain only message header information, and the message information is not retained for more than 7 days.

Where personal data is transferred outside the UK, we ensure that an appropriate UK data-transfer safeguard or other lawful transfer mechanism is in place, where required.

How long do we keep your personal information f?

Where Creatio processes personal data through creatiogreen on behalf of a client, the information is retained in accordance with the client’s documented instructions, the applicable contract and agreed retention arrangements. On termination, personal data is returned or securely deleted in accordance with those arrangements, subject to any legal requirement or agreed backup-retention period.

However, there may be times when we hold the data for slightly longer if we need this information to establish, bring or defend legal claims (note that in such circumstances we anticipate using not personal data itself, but the details around the total number of users, customers, transactions, and types of transactions undertaken in creatiogreen software and system).

Staff information is retained in accordance with Creatio’s Data Retention Policy or Schedule, taking account of relevant employment, tax, pension, insurance and legal requirements.

For users of our website(s), we keep the details you provide only to respond to your online enquiry and, if this does not lead to a new contract, we delete the details within 7 years or earlier if you contact us to remove the personal data we hold.