{"id":29060,"date":"2022-10-18T10:22:48","date_gmt":"2022-10-18T10:22:48","guid":{"rendered":"https:\/\/kerisys.com\/?page_id=29060"},"modified":"2022-10-18T10:27:57","modified_gmt":"2022-10-18T10:27:57","slug":"eu-privacy-policy","status":"publish","type":"page","link":"https:\/\/kerisys.com\/eu-privacy-policy\/","title":{"rendered":"EU Privacy Policy"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;4.18.0&#8243; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; background_color=&#8221;#ffffff&#8221; sticky_enabled=&#8221;0&#8243; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221; da_disable_devices=&#8221;off|off|off&#8221;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.18.0&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243; custom_padding=&#8221;75px|15px|75px|15px|false|false&#8221;]<\/p>\n<h1>UK\/EU Privacy Notice<\/h1>\n<p>&nbsp;<\/p>\n<p>This privacy notice covers Keri Systems UK.\u00a0 We describe here the data we collect from you when you engage with us.<\/p>\n<p>These are our reasons for collecting it, what we do with it and what your rights are.<\/p>\n<h1>Who are we?<\/h1>\n<p>We are Keri Systems UK Ltd., our registered office is 4 Grenville Avenue, Broxbourne, Hertfordshire, EN10 7DH, company registration number\u00a0 <a href=\"https:\/\/find-and-update.company-information.service.gov.uk\/company\/03842772\" target=\"_blank\" rel=\"noopener\">03842772<\/a>.<\/p>\n<p>Our office address is 1-3 The Paddocks, Frettenham Road, Horstead, Norwich, NR12 7LB.<\/p>\n<p>If you have any questions regarding this notice or our processing of your personal data then you can write to us at the above office address, or call us on +44 (0) 1763 273 243 or email us at EUSales@Kerisys.com.<\/p>\n<p>We are registered with the Information Commissioner\u2019s Office (ICO \u2013 the UK\u2019s regulator for personal data processing matters), registration number <a href=\"https:\/\/ico.org.uk\/ESDWebPages\/Entry\/ZB335913\" target=\"_blank\" rel=\"noopener\">ZB335913<\/a>.<\/p>\n<h1>Purpose of processing<\/h1>\n<p>We process your personal data for a variety of purposes as set out in the table below for which we are the Controller.<\/p>\n<p>Where we are providing our Borealis system to our clients in the UK or Europe we act as a Processor on their behalf, please see the Borealis section of this notice for more information.<\/p>\n<table width=\"614\">\n<tbody>\n<tr>\n<td width=\"312\"><strong>Purpose<\/strong><\/td>\n<td width=\"302\"><strong>Lawful Basis under UK GDPR<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Managing your enquiries<\/td>\n<td width=\"302\">Our legitimate interests in responding to and managing your enquiry<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Managing our commercial relationship with you as a contact employed by one of our clients<\/td>\n<td width=\"302\">Our legitimate interests in managing our commercial relationships and any associated contracts between our respective organisations<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Managing our commercial relationship with you as a contact employed by one of our suppliers<\/td>\n<td width=\"302\">\n<p>Our legitimate interests in managing our commercial relationships and any associated contracts between our respective organisations<\/p>\n<p>&nbsp;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Direct marketing<\/td>\n<td width=\"302\">Our legitimate interests in ensuring we appropriately manage, deliver or suppress direct marketing activity<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Recruitment enquiries<\/td>\n<td width=\"302\">Taking the steps necessary to enter into a contract with you.\u00a0 We will provide further privacy information to you as the recruitment process progresses.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>Where we are relying on our legitimate interests you are free to object to that at any time.\u00a0 In the case of direct marketing activity we will ensure that we cease to market our services to you should you object to our legitimate interests.<\/p>\n<p>Where we are relying on your consent you are free to change your mind and withdraw your consent at any time.<\/p>\n<h1>Data we collect<\/h1>\n<p>The table below gives information on the categories of personal data we process for each of the purposes shown above.<\/p>\n<table width=\"614\">\n<tbody>\n<tr>\n<td width=\"302\"><strong>Purpose<\/strong><\/td>\n<td width=\"312\"><strong>Categories of Data Processed<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"302\">Managing your enquiries<\/td>\n<td width=\"312\">Name, contact details, contact history and message content<\/td>\n<\/tr>\n<tr>\n<td width=\"302\">Managing our commercial relationship with you as a contact employed by one of our clients<\/td>\n<td width=\"312\">Name, contact details, organisation &amp; role, contact history<\/td>\n<\/tr>\n<tr>\n<td width=\"302\">Managing our commercial relationship with you as a contact employed by one of our suppliers<\/td>\n<td width=\"312\">\n<p>Name, contact details, organisation &amp; role, contact details.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"302\">Direct marketing<\/td>\n<td width=\"312\">Name, contact details, marketing preferences<\/td>\n<\/tr>\n<tr>\n<td width=\"302\">Recruitment enquiries<\/td>\n<td width=\"312\">Name, contact details, employment history, salary and benefit requirements, details of roles applied for<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h1>Special category data<\/h1>\n<p>There are additional rules we must follow if we collect certain types of more sensitive data, known as Special Category Data.\u00a0 These include details of your ethnicity, beliefs, health and sexuality and in each case we must let you know what our additional lawful basis is for processing such data.<\/p>\n<p>We do not routinely process any such special category data, however we may occasionally do so (for example when we manage an event you are attending we may ask for any dietary or access requirements which could include data relating to belief or health) and will always ensure we have a lawful basis (normally by asking for your explicit consent) and only retain the information for a very limited period of time.<\/p>\n<h1>How long do we keep your data for?<\/h1>\n<p>Where we are relying on our legitimate interests to process your data then we will keep your personal data until you object to our legitimate interests and we agree with your objection, or until the following default periods have elapsed after our last contact with you.<\/p>\n<p>We will retain your personal data by default for the following periods:<\/p>\n<table width=\"614\">\n<tbody>\n<tr>\n<td width=\"312\"><strong>Purpose<\/strong><\/td>\n<td width=\"302\"><strong>Maximum Retention Period<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Managing your enquiries<\/td>\n<td width=\"302\">7 years<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Managing our commercial relationship with you as a contact employed by one of our clients<\/td>\n<td width=\"302\">7 years<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Managing our commercial relationship with you as a contact employed by one of our suppliers<\/td>\n<td width=\"302\">7 years<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Direct marketing<\/td>\n<td width=\"302\">7 years<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">Recruitment enquiries<\/td>\n<td width=\"302\">1 year<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h1>Do we ever share personal data?<\/h1>\n<p>We will share your data if we receive a legitimate request from a law enforcement agency.<\/p>\n<p>When you submit your personal data online your data is shared with our partners who manage our website.<\/p>\n<p>If we are communicating with you via email or social media channels we will be sharing your personal data with those email and social media providers.<\/p>\n<p>We also utilise external suppliers to provide a number of business support services. We always ensure that we have appropriate contracts in place to protect your rights when personal data are processed on our behalf by these third parties.<\/p>\n<h1>How do we keep your data secure?<\/h1>\n<p>We take sensible steps to keep your data secure and ensure we can uphold your rights and meet our obligations under UK GDPR:<\/p>\n<ul>\n<li>All data sent between your browser and our website are encrypted in transit,<\/li>\n<li>Access to personal data is role based: only those members of staff with a legitimate need will have access,<\/li>\n<li>Systems are password protected and multi-factor authentication is enabled where available,<\/li>\n<li>We ensure that appropriate contracts are in place with our suppliers who process your personal data to protect your rights, to ensure that they take appropriate security measures to safeguard your data, and that any international transfers are done correctly under UK GDPR,<\/li>\n<li>Our employees are all subject to an obligation of confidentiality, and receive training on data protection matters,<\/li>\n<li>We utilise appropriate technical and organisational measures to optimise the security of your personal data.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h1>Your Rights<\/h1>\n<p>You have a number of rights relating to the processing of your data, if you would like to use them or have any questions then please contact us.<\/p>\n<p>We won\u2019t charge you for doing any of the following, however we may make a charge in the case of frequent repeat or unfounded requests:<\/p>\n<ul>\n<li>Awareness: You have the right to be fully informed about why and how we process your information.\u00a0 This privacy notice is intended to meet that requirement, but please do contact us if you have any questions.\u00a0 If we obtain your personal data from a third party (e.g. a social media platform or recruitment platform) then we will tell you where we have obtained your information from,<\/li>\n<li>Access: You have the right to a copy of the data we hold about you,<\/li>\n<li>Rectification: If you think some of the data we hold is wrong then you have the right to ask us to correct it,<\/li>\n<li>Erasure: You have the right to ask us to delete the data we hold about you.\u00a0 Where we are holding the data to fulfil a contract with you or your organisation then we will need to retain the data in accordance with the data retention requirements shown above,<\/li>\n<li>Restriction: You have the right to ask us to restrict the processing of personal data whilst we check its accuracy, if you think the processing is unlawful, if you believe we no longer need to process the data but you need us to store it due to pending legal claims, or when you object to our processing based upon our legitimate interests and we are assessing the validity of that,<\/li>\n<li>Object: Where we are processing your personal data based upon our legitimate interests you have the right to object to that.\u00a0 If your objection is valid (for instance in the case of any direct marketing activity) then we will stop processing your personal data for that purpose,<\/li>\n<li>Data portability: You can request a copy of your data in a digital format which you can then supply to another provider when we ae processing your personal data under the lawful basis of performing a contract with you or because we have your consent,<\/li>\n<li>Automated decisions and profiling: You have the right, in certain circumstances, not to be subject to decisions based on automated processing (including profiling) if it has a significant or legal impact on you.\u00a0 This doesn\u2019t apply if the processing is necessary to fulfil a contract with you, or if you have given us your consent to do so.\u00a0 We do not currently use any technology to make automated decisions about you.<\/li>\n<\/ul>\n<h1>Where do we process data?<\/h1>\n<p>We primarily process data in the UK however we use partners to help us deliver our services, some of these services will mean that your personal data are transferred outside of the UK.<\/p>\n<p>Our primary partner is our US based parent company, Keri Systems Inc, and we have appropriate International Data Transfer Agreements in place to correctly facilitate any transfers.<\/p>\n<p>We may share your personal data with professional advisors from time to time, such as our accountants or legal advisors.\u00a0 We will always ensure that appropriate protections to your rights and freedoms are in place.<\/p>\n<h1>Borealis<\/h1>\n<p>Borealis is our cloud based access control system.\u00a0 Keri Systems UK is the provider of the Borealis system to our clients in the UK and Europe:\u00a0 our clients are the Controllers for this processing and Keri Systems UK act as their Processor.<\/p>\n<p>This section provides some useful information about the processing of personal data by Borealis, however if you are an individual seeking to invoke your rights under GDPR\/UK GDPR then you should contact the Controller for this processing directly.<\/p>\n<h2>Subject Matter of Processing<\/h2>\n<p>Provision of the Borealis cloud based access control system, including hosting of all associated data, to enable our client, the Controller, to manage site security and access records.<\/p>\n<h2>Duration of the Processing<\/h2>\n<p>Until such time as the contract with our client for the provision of service ends.<\/p>\n<h2>Type of Personal Data<\/h2>\n<p>User account credentials and administrator permissions, classification of user (Owner, Operator User, Systems Operators), unique identifier of access control fobs and name of associated individual, site access records, customer created custom fields<\/p>\n<p>User credentials for the Controller\u2019s staff<\/p>\n<h2>Special Categories of Personal Data<\/h2>\n<p>No special categories of personal data are processed by default, however our client has the ability to create custom fields.<\/p>\n<h2>International Transfers<\/h2>\n<p>The transfers of data to and from the Processor, Keri Systems UK, \u00a0are enabled by the UK deemed to be an adequate nation for data protection by the EU<\/p>\n<h2>Technical and Organisational Measures<\/h2>\n<p>We implement the following appropriate measures by default to preserve the security of the data collected:<\/p>\n<ul>\n<li>No copies of data are to be held by us without the Controller\u2019s permission<\/li>\n<li>Any such copies data will be held in secure, password protected IT systems<\/li>\n<li>Multi factor authentication shall be enabled on any systems where it is available<\/li>\n<li>We ensure that our IT systems use modern software that is kept up-to-date<\/li>\n<li>When personal data is deleted this will be done safely such that the data is irrecoverable<\/li>\n<li>Appropriate back-up and disaster recovery solutions are in place<\/li>\n<li>All data will be encrypted in transit<\/li>\n<li>All UK\/EU customers are contracted to Keri Systems UK and an additional Data Processing Addendum applies to that processing to comply with GDPR\/UK GDPR.<\/li>\n<\/ul>\n<h2>Sub-Processors<\/h2>\n<p>List of Sub-Processors used by us to deliver the Borealis service<\/p>\n<table width=\"601\">\n<tbody>\n<tr>\n<td width=\"200\">Name of Sub-Processor<\/td>\n<td width=\"200\">Address<\/td>\n<td width=\"200\">Nature of processing activity<\/td>\n<\/tr>\n<tr>\n<td width=\"200\">Keri Systems Inc<\/td>\n<td width=\"200\">\n<p>302 Enzo Dr Suite 190, San Jose, California 95138, USA.<\/p>\n<p>&nbsp;<\/p>\n<p>International transfer facilitated by International Data Transfer Agreement in place with Sub-Processor<\/p>\n<\/td>\n<td width=\"200\">Provision and hosting of Borealis system<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h1>Making a complaint<\/h1>\n<p>Please contact us at the above address.\u00a0 You can also contact the Information Commissioner\u2019s Office (ICO) on their helpline 0303 123 1113 or online at <a href=\"https:\/\/www.ico.org.uk\" target=\"_blank\" rel=\"noopener\">www.ico.org.uk<\/a>.\u00a0 If you should contact the ICO they will normally ask you to contact us first.<\/p>\n<p>If you have a complaint regarding the processing of your personal data by the Borealis system then please direct your complaint to the Controller in the first instance rather than Keri Systems UK.<\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>UK\/EU Privacy Notice &nbsp; This privacy notice covers Keri Systems UK.\u00a0 We describe here the data we collect from you when you engage with us. These are our reasons for [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_et_pb_use_builder":"on","_et_pb_old_content":"Privacy Notice\r\n\r\nThis privacy notice covers Keri Systems UK.  We describe here the data we collect from you when you engage with us.\r\n\r\nThese are our reasons for collecting it, what we do with it and what your rights are.\r\n\r\nWho are we?\r\n\r\nWe are Keri Systems UK Ltd., our registered office is 4 Grenville Avenue, Broxbourne, Hertfordshire, EN10 7DH, company registration number  03842772. \r\n\r\nOur office address is 1-3 The Paddocks, Frettenham Road, Horstead, Norwich, NR12 7LB.\r\n\r\nIf you have any questions regarding this notice or our processing of your personal data then you can write to us at the above office address, or call us on +44 (0) 1763 273 243 or email us at EUSales@Kerisys.com.\r\n\r\nWe are registered with the Information Commissioner\u2019s Office (ICO \u2013 the UK\u2019s regulator for personal data processing matters), registration number ZB335913.  \r\n\r\nPurpose of processing\r\n\r\nWe process your personal data for a variety of purposes as set out in the table below for which we are the Controller.  \r\n\r\nWhere we are providing our Borealis system to our clients in the UK or Europe we act as a Processor on their behalf, please see the Borealis section of this notice for more information.\r\n\r\nPurpose\tLawful Basis under UK GDPR\r\nManaging your enquiries \tOur legitimate interests in responding to and managing your enquiry\r\nManaging our commercial relationship with you as a contact employed by one of our clients\tOur legitimate interests in managing our commercial relationships and any associated contracts between our respective organisations\r\nManaging our commercial relationship with you as a contact employed by one of our suppliers\tOur legitimate interests in managing our commercial relationships and any associated contracts between our respective organisations\r\n\r\nDirect marketing\tOur legitimate interests in ensuring we appropriately manage, deliver or suppress direct marketing activity\r\nRecruitment enquiries \tTaking the steps necessary to enter into a contract with you.  We will provide further privacy information to you as the recruitment process progresses.\r\n\r\nWhere we are relying on our legitimate interests you are free to object to that at any time.  In the case of direct marketing activity we will ensure that we cease to market our services to you should you object to our legitimate interests.\r\n\r\nWhere we are relying on your consent you are free to change your mind and withdraw your consent at any time.\r\n\r\n\r\nData we collect\r\n\r\nThe table below gives information on the categories of personal data we process for each of the purposes shown above.\r\n\r\nPurpose\tCategories of Data Processed\r\nManaging your enquiries \tName, contact details, contact history and message content\r\nManaging our commercial relationship with you as a contact employed by one of our clients\tName, contact details, organisation & role, contact history\r\nManaging our commercial relationship with you as a contact employed by one of our suppliers\tName, contact details, organisation & role, contact details.\r\n\r\n\r\nDirect marketing\tName, contact details, marketing preferences\r\nRecruitment enquiries \tName, contact details, employment history, salary and benefit requirements, details of roles applied for\r\n\r\nSpecial category data\r\n\r\nThere are additional rules we must follow if we collect certain types of more sensitive data, known as Special Category Data.  These include details of your ethnicity, beliefs, health and sexuality and in each case we must let you know what our additional lawful basis is for processing such data.  \r\n\r\nWe do not routinely process any such special category data, however we may occasionally do so (for example when we manage an event you are attending we may ask for any dietary or access requirements which could include data relating to belief or health) and will always ensure we have a lawful basis (normally by asking for your explicit consent) and only retain the information for a very limited period of time.\r\n\r\n\r\nHow long do we keep your data for?\r\n\r\nWhere we are relying on our legitimate interests to process your data then we will keep your personal data until you object to our legitimate interests and we agree with your objection, or until the following default periods have elapsed after our last contact with you.\r\n\r\nWe will retain your personal data by default for the following periods:\r\n\r\nPurpose\tMaximum Retention Period\r\nManaging your enquiries \t7 years \r\nManaging our commercial relationship with you as a contact employed by one of our clients\t7 years\r\nManaging our commercial relationship with you as a contact employed by one of our suppliers\t7 years \r\nDirect marketing\t7 years\r\nRecruitment enquiries \t1 year\r\n\r\n\r\nDo we ever share personal data?\r\n\r\nWe will share your data if we receive a legitimate request from a law enforcement agency.  \r\n\r\nWhen you submit your personal data online your data is shared with our partners who manage our website.\r\n\r\nIf we are communicating with you via email or social media channels we will be sharing your personal data with those email and social media providers.\r\n\r\nWe also utilise external suppliers to provide a number of business support services. We always ensure that we have appropriate contracts in place to protect your rights when personal data are processed on our behalf by these third parties.  \r\n\r\nHow do we keep your data secure?\r\n\r\nWe take sensible steps to keep your data secure and ensure we can uphold your rights and meet our obligations under UK GDPR:\r\n\r\n\u2022\tAll data sent between your browser and our website are encrypted in transit,\r\n\u2022\tAccess to personal data is role based:  only those members of staff with a legitimate need will have access,\r\n\u2022\tSystems are password protected and multi-factor authentication is enabled where available,\r\n\u2022\tWe ensure that appropriate contracts are in place with our suppliers who process your personal data to protect your rights, to ensure that they take appropriate security measures to safeguard your data, and that any international transfers are done correctly under UK GDPR,\r\n\u2022\tOur employees are all subject to an obligation of confidentiality, and receive training on data protection matters,\r\n\u2022\tWe utilise appropriate technical and organisational measures to optimise the security of your personal data.\r\n\r\n\r\nYour Rights\r\n\r\nYou have a number of rights relating to the processing of your data, if you would like to use them or have any questions then please contact us.\r\n\r\nWe won\u2019t charge you for doing any of the following, however we may make a charge in the case of frequent repeat or unfounded requests:\r\n\u2022\tAwareness:  You have the right to be fully informed about why and how we process your information.  This privacy notice is intended to meet that requirement, but please do contact us if you have any questions.  If we obtain your personal data from a third party (e.g. a social media platform or recruitment platform) then we will tell you where we have obtained your information from,\r\n\u2022\tAccess:  You have the right to a copy of the data we hold about you,\r\n\u2022\tRectification:  If you think some of the data we hold is wrong then you have the right to ask us to correct it,\r\n\u2022\tErasure:  You have the right to ask us to delete the data we hold about you.  Where we are holding the data to fulfil a contract with you or your organisation then we will need to retain the data in accordance with the data retention requirements shown above,\r\n\u2022\tRestriction:  You have the right to ask us to restrict the processing of personal data whilst we check its accuracy, if you think the processing is unlawful, if you believe we no longer need to process the data but you need us to store it due to pending legal claims, or when you object to our processing based upon our legitimate interests and we are assessing the validity of that,\r\n\u2022\tObject:  Where we are processing your personal data based upon our legitimate interests you have the right to object to that.  If your objection is valid (for instance in the case of any direct marketing activity) then we will stop processing your personal data for that purpose,\r\n\u2022\tData portability:  You can request a copy of your data in a digital format which you can then supply to another provider when we ae processing your personal data under the lawful basis of performing a contract with you or because we have your consent,\r\n\u2022\tAutomated decisions and profiling:  You have the right, in certain circumstances, not to be subject to decisions based on automated processing (including profiling) if it has a significant or legal impact on you.  This doesn\u2019t apply if the processing is necessary to fulfil a contract with you, or if you have given us your consent to do so.  We do not currently use any technology to make automated decisions about you.\r\n\r\n\r\nWhere do we process data?\r\n\r\nWe primarily process data in the UK however we use partners to help us deliver our services, some of these services will mean that your personal data are transferred outside of the UK.  \r\n\r\nOur primary partner is our US based parent company, Keri Systems Inc, and we have appropriate International Data Transfer Agreements in place to correctly facilitate any transfers.\r\n\r\nWe may share your personal data with professional advisors from time to time, such as our accountants or legal advisors.  We will always ensure that appropriate protections to your rights and freedoms are in place.\r\n\r\n\r\nBorealis\r\n\r\nBorealis is our cloud based access control system.  Keri Systems UK is the provider of the Borealis system to our clients in the UK and Europe:  our clients are the Controllers for this processing and Keri Systems UK act as their Processor.\r\n\r\nThis section provides some useful information about the processing of personal data by Borealis, however if you are an individual seeking to invoke your rights under GDPR\/UK GDPR then you should contact the Controller for this processing directly.\r\n\r\nSubject Matter of Processing\r\n\r\nProvision of the Borealis cloud based access control system, including hosting of all associated data, to enable our client, the Controller, to manage site security and access records.\r\n\r\nDuration of the Processing\r\n\r\nUntil such time as the contract with our client for the provision of service ends.\r\n\r\nType of Personal Data\r\n\r\nUser account credentials and administrator permissions, classification of user (Owner, Operator User, Systems Operators), unique identifier of access control fobs and name of associated individual, site access records, customer created custom fields\r\n\r\nUser credentials for the Controller\u2019s staff\r\n\r\nSpecial Categories of Personal Data\r\n\r\nNo special categories of personal data are processed by default, however our client has the ability to create custom fields.\r\n\r\nInternational Transfers\r\n\r\nThe transfers of data to and from the Processor, Keri Systems UK,  are enabled by the UK deemed to be an adequate nation for data protection by the EU\r\n\r\nTechnical and Organisational Measures \r\n\r\nWe implement the following appropriate measures by default to preserve the security of the data collected:\r\n\r\n\u2022\tNo copies of data are to be held by us without the Controller\u2019s permission\r\n\u2022\tAny such copies data will be held in secure, password protected IT systems\r\n\u2022\tMulti factor authentication shall be enabled on any systems where it is available\r\n\u2022\tWe ensure that our IT systems use modern software that is kept up-to-date\r\n\u2022\tWhen personal data is deleted this will be done safely such that the data is irrecoverable\r\n\u2022\tAppropriate back-up and disaster recovery solutions are in place\r\n\u2022\tAll data will be encrypted in transit\r\n\u2022\tAll UK\/EU customers are contracted to Keri Systems UK and an additional Data Processing Addendum applies to that processing to comply with GDPR\/UK GDPR.\r\n\r\n\r\nSub-Processors\r\n\r\nList of Sub-Processors used by us to deliver the Borealis service\r\n\r\nName of Sub-Processor\tAddress\tNature of processing activity\r\nKeri Systems Inc\t302 Enzo Dr Suite 190, San Jose, California 95138, USA.\r\n\r\nInternational transfer facilitated by International Data Transfer Agreement in place with Sub-Processor\tProvision and hosting of Borealis system\r\n\r\n\r\n\r\n\r\nMaking a complaint\r\n\r\nPlease contact us at the above address.  You can also contact the Information Commissioner\u2019s Office (ICO) on their helpline 0303 123 1113 or online at www.ico.org.uk.  If you should contact the ICO they will normally ask you to contact us first.\r\n\r\nIf you have a compliant regarding processing of your personal data by the Borealis system then please direct your compliant to the Controller in the first instance rather than Keri Systems UK.\r\n\r\n","_et_gb_content_width":"","footnotes":""},"is_legacy":[],"page_category":[],"class_list":["post-29060","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/kerisys.com\/wp-json\/wp\/v2\/pages\/29060","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kerisys.com\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/kerisys.com\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/kerisys.com\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/kerisys.com\/wp-json\/wp\/v2\/comments?post=29060"}],"version-history":[{"count":0,"href":"https:\/\/kerisys.com\/wp-json\/wp\/v2\/pages\/29060\/revisions"}],"wp:attachment":[{"href":"https:\/\/kerisys.com\/wp-json\/wp\/v2\/media?parent=29060"}],"wp:term":[{"taxonomy":"is_legacy","embeddable":true,"href":"https:\/\/kerisys.com\/wp-json\/wp\/v2\/is_legacy?post=29060"},{"taxonomy":"page_category","embeddable":true,"href":"https:\/\/kerisys.com\/wp-json\/wp\/v2\/page_category?post=29060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}