top of page

E-waste Privacy Policy

Combination Lock

At Thomas Charles Facilities & Maintenance, we are committed to protecting the privacy and security of personal data. This policy outlines how we collect, use, store, and safeguard personal information in compliance with the UK GDPR and Data Protection Act 2018.

1.             By having the collection, you are agreeing with the terms and Data Sanitization Capability Statement below.

2.             Thomas Charles has a complete GDPR Evaluation, Data Security Risk Assessment and Risk Treatment Plan in place which is regularly reviewed.

3.             TCFM is not only bound by GDPR laws but also the laws of the United Kingdom; environmental laws may determine how we are required to handle certain data.

4.             By agreeing to use our services, you acknowledge that the equipment collected is immediately transferred into TCFM ownership and that you are legally entitled to transfer it to us.

5.             Thomas Charles FM will NOT store or collect any data received from assets collected. This data will be destroyed using the following methods within 40 working days and subject to the details below. NO ELECTRONIC OR PHYSICAL DATA FROM ANY DEVICES PROVIDED FOR RECYCLING WILL EVER BE RETAINED.

6.             All data carrying assets which are received will undergo the same process regardless of any assurances from the client that they have already been destroyed.

7.             TCFM do multi-point collections where a single vehicle is used to pick up from different customers at different locations. Systems are in place to ensure segregation.

8.             TCFM uses confidentiality / non-disclosure agreements where necessary and beneficial all parties.

9.             Data/information TCFM holds is identified in a data flow analysis and is treated as confidential data.

10.          You give your consent for data to be handled by the collection contract and any queries will be handled in advance of the collection. If the collection takes place, it will be due to consent being given.

11.          TCFM has processes in place to ensure the accuracy and integrity of data we hold.

12.          Data retention periods and stringent disposal methods have been established.

13.          Our full systems, including policies / procedures / compliance, are audited and monitored regularly to ensure they are performing to the required standard.

A business continuity plan is in place to counteract interruptions to business activities.

14.          Information security education, awareness and training is provided to all staff.

15.          In accordance with our risk treatment plan, all data / information we hold either electronically or in hardware has its access restricted to only those who require it for legitimate business process requirements.

16.          TCFM senior management has nominated Data Protection Officers (DPOs).

17.          All breaches of information security, actual or suspected, will be recorded and investigated immediately in accordance with our Data Security Breach Policy.

18.          TCFM has a quality control process in place which regularly tests a sample number of data carrying assets after the data sanitization process has been completed to ensure compliance with our Data Sanitization Capability Statement.

19.          Thomas Charles FM will NOT share any data collected for the purposes of collection at any time. Data collected will be limited to contact information including email addresses for the purpose of account maintenance. You will only receive 2 automated emails from Thomas Charles FM and the option to opt out is via email; please email info@thomascharlesfm.co.uk with a subject line “opt out” to not receive any automated emails.

20.          Destruction of data is carried out solely by TCFM. Devices / data will not leave the TCFM premises until they are securely destroyed.

21.          Any data collected for the purposes of the collection e.g. address, contact email/phone numbers will be retained by Thomas Charles FM for the purpose of making the collection and complying with waste laws and reporting. Data for this purpose is kept by Thomas Charles FM to comply with environmental laws and for licensing for 3 years.

22.          Regular customers receiving collections more frequently than every 90 days will be kept on regular customer records to aid in booking collections. No data other than the minimum required will be kept on these records. This data can be removed on request. Only data regarding collections, such as email addresses, address and phone number will be retained for this purpose.

23.          Data generated by Thomas Charles FM such as asset reports, data destruction information and customer information regarding this process will be kept on a customer accessible online account for the time the customer requires the information.

24.          Online accounts will remain active for a minimum of a year from creation; however, Thomas Charles FM reserves the right to delete accounts that have not been accessed within 12 months. Customers may request deletion of this account at any time; however, Thomas Charles FM must continue to keep records of the collection to comply with environmental laws and regulations (point 21).

25.          Any requests for held data (SAR) will be completed within 28 days, unless subject to delay. Thomas Charles FM ideally accepts this request in writing by post, addressed to the GDPR Compliance Dept., Thomas Charles FM Ltd, Unit 11 Ridgacre Road, West Bromwich, B71 1BW. Other requests will be accepted but written requests to the above address are checked daily and will receive a faster response, however all requests will be dealt with within 28 days, calculated from the day after the request is received. Further identification may be required and will be requested if necessary. Once complete, the data will be added to the customer portal and notification will be given to the customer at this time. Thomas Charles FM may charge a fee in certain circumstances; this fee would be based on administrative charges as allowed under GDPR guidelines. Under extreme circumstances, the time limit may be extended by a further 2 months if the request is complex or multiple requests have been received from the same customer.

26.          Thomas Charles FM will periodically delete data that is no longer relevant.

27.          Thomas Charles FM may anonymize data when required for statistics and business purposes. All customer specific information would be removed and no customer data from devices or collections would be used in this process. This is limited to areas of collections and other basic collection based information.

28.          Thomas Charles FM will use network security systems in order to protect all data to a high standard. This system is checked daily, regularly monitored and kept up to date. The system is developed and maintained as far as required on a regular basis.

29.          For further GDPR policy information please email info@thomascharlesfm.co.uk

30. Contact Information

For data privacy inquiries, users can contact:
Data Protection Officer (DPO)
Thomas Charles Facilities & Maintenance
Unit 11, Ridgacre Road, West Bromwich, B71 1BW
Info@thomascharlesfm.co.uk

bottom of page