Privacy Policy
This policy explains what information may be collected, why it is used, the lawful bases that may apply, how information may be shared and protected, and the rights available to individuals under UK data protection law.
1. Who we are
R C OVERSEAS LTD is the legal entity responsible for the RC IT Services website. For the purposes of personal information processed through this website, R C OVERSEAS LTD acts as the data controller where it determines the purposes and means of processing.
References to “RC IT Services”, “RC”, “we”, “us” or “our” in this policy refer to R C OVERSEAS LTD in connection with this website and the technology, management and education consulting services presented through it.
2. Scope of this policy
This policy applies to personal information handled through the public website, contact forms, consultation and demonstration requests, recruitment and CV submission flows, and related communications initiated through the website.
A client engagement, employee relationship, supplier relationship, dedicated portal or other service may be governed by additional privacy information where the processing differs materially from the public website.
3. Information we may collect
The information processed depends on how you interact with us. It may include:
- Identity and contact information, such as your name, business email address, telephone number and location.
- Professional and organisational information, such as employer, company, job title, role, service interest and area of responsibility.
- Business enquiry information, including project context, systems involved, requirements, timelines, messages and other information you choose to provide.
- Recruitment information, such as your CV or resume, skills, employment history, professional profile, work-authorisation information and application-related communications.
- Technical and security information generated when the website is delivered or protected, such as request metadata, IP address, browser or device information, timestamps and security events where available from hosting or security providers.
- Cookie, storage and preference information where storage or access technologies are used. Please see the Cookie Policy for more information.
4. Sources of personal information
Most personal information is provided directly by you when you complete a form, upload a document, contact us or use an interactive feature. We may also receive relevant business information from your organisation, an authorised representative, a recruitment source or a service provider where there is a lawful basis to do so.
Technical information may be generated automatically by the infrastructure used to host, secure and operate the website.
5. Purposes and lawful bases
The lawful basis depends on the purpose and context of the interaction. Typical processing activities are summarised below.
| Purpose | Typical information | Lawful basis typically relied on |
|---|---|---|
| Responding to enquiries and consultation requests | Identity, business contact and enquiry details | Steps requested before entering into a contract and/or legitimate interests in responding to business enquiries |
| Preparing proposals and discussing services | Business requirements, contact details and project context | Steps requested before entering into a contract and legitimate interests |
| Recruitment and candidate assessment | CV, contact details, skills, experience and application information | Steps before entering into an employment or engagement contract and legitimate interests in recruitment |
| Operating, securing and troubleshooting the website | Technical, request and security information | Legitimate interests in secure and reliable digital operations and, where applicable, legal obligations |
| Maintaining business and compliance records | Relevant correspondence, transaction and governance records | Legal obligations and legitimate interests in governance, audit and dispute management |
| Direct marketing where used | Business contact details and communication preferences | Consent or legitimate interests where permitted, together with applicable electronic-marketing requirements |
6. Who we may share information with
We do not treat personal information as a product for sale. Information may be shared only where necessary for a legitimate operational, contractual or legal purpose, including with:
- Hosting, infrastructure, communications, form-processing, document-storage and security providers acting on our behalf.
- Professional advisers, such as legal, accounting, insurance or compliance advisers, where required.
- Recruitment or staffing service providers where relevant to an application or role and where an appropriate basis exists.
- Clients, suppliers or delivery partners where necessary for an authorised business process and subject to appropriate controls.
- Regulators, law-enforcement bodies, courts or other public authorities where disclosure is required or permitted by law.
- A successor organisation in connection with a lawful corporate reorganisation, acquisition or transfer, subject to appropriate confidentiality and data-protection safeguards.
7. International transfers
Some technology or service providers may process information outside the United Kingdom. Where a transfer is subject to UK data protection transfer rules, we assess the destination and provider and use an appropriate transfer mechanism where required, such as UK adequacy regulations, contractual safeguards or another lawful mechanism available under UK law.
The applicable safeguard depends on the provider, destination and nature of the processing.
8. Security and access control
We apply organisational and technical measures intended to protect personal information against unauthorised access, loss, misuse, alteration and disclosure. Controls are selected according to the nature of the system, information and associated risk.
No internet service can be guaranteed to be completely secure. Where a personal data breach occurs, we assess and respond to it in accordance with applicable legal and regulatory requirements.
- Role-appropriate access and least-privilege principles where systems support them.
- Secure transport, hosting and configuration controls appropriate to the service.
- Operational logging, monitoring and incident handling where applicable.
- Supplier and processing reviews proportionate to the data and service risk.
9. Data retention
We keep personal information only for as long as it is reasonably required for the purpose for which it was collected, to maintain appropriate business records, or to meet legal, regulatory, contractual, tax, accounting, security or dispute-resolution requirements.
Retention periods vary by record type and relationship. When information is no longer required, it is deleted, anonymised or securely archived as appropriate. Production systems and suppliers are expected to support retention controls that reflect the approved business process.
10. Your data protection rights
Depending on the circumstances and applicable law, you may have rights in relation to your personal information, including:
- The right to be informed about how personal information is used.
- The right to request access to personal information held about you.
- The right to ask for inaccurate or incomplete information to be corrected.
- The right to request erasure where the legal conditions are met.
- The right to request restriction of processing where the legal conditions are met.
- The right to object to certain processing, including an absolute right to object to direct marketing.
- The right to data portability where the statutory conditions are met.
- Rights relating to qualifying automated decision-making and profiling.
11. Marketing communications
Where direct marketing is used, we apply the lawful basis and electronic-marketing requirements relevant to the communication and recipient. You can ask us to stop direct marketing at any time.
Operational messages concerning an enquiry, application, contract, security matter or requested service are not treated as marketing merely because they are sent electronically.
12. Automated decision-making
The public website is not intended to make decisions that produce legal or similarly significant effects on individuals solely by automated means. If a future service introduces qualifying automated decision-making or profiling, we will provide the additional information and safeguards required for that processing.
13. Privacy requests and complaints
To exercise a privacy right or raise a data protection concern, use the Contact page and clearly identify the message as a “Data Protection Request” or “Data Protection Complaint”. Please provide enough information for us to identify the relevant interaction without sending unnecessary sensitive information.
You also have the right to raise a complaint with the UK Information Commissioner’s Office (ICO). We encourage you to contact us first so that we have an opportunity to investigate and respond.
14. Changes to this policy
We may update this policy when our services, suppliers, processing activities or legal requirements change. The “Last updated” date identifies the current published version. Where a change materially affects how existing personal information is used, we will take reasonable steps to provide additional notice where required.
