Third Party Index

Snapshot 72430

Document
Privacy policy
URL
https://seven20.io/wp-content/uploads/2026/06/Seven20-Data-Privacy-Policy.docx.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
90286 bytes
SHA-256 (raw)
db4033934aa45c6f7b692c6a592a5aa159df55de33adb795e3d14867945d1053
SHA-256 (normalized text)
866afdb773cb4b4bb5a4d9089980123702e6a55772ef008cf4c92f99ed1d0c6d

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Seven20 Data Privacy Policy

1. Important information

This Data Privacy Policy explains how Seven20 collects, uses, stores, shares and
protects personal data in connection with its website, services, communications and
business operations.​

It is intended to provide transparent information to website users, customers,
prospects, suppliers, candidates, and other individuals whose personal data may be
processed by Seven20.​

This policy should be read alongside any specific privacy notice, cookie notice, fair
processing notice, contract terms, or service-specific notice that may apply in your
particular circumstances.​

2. Who Seven20 is

Seven20 is the controller of personal data processed in connection with its website
and related business activities where Seven20 determines the purposes and means
of processing.​

Questions about this policy or about Seven20’s privacy practices should be directed
to Seven20’s designated Data Protection Manager using the contact details
published by the organisation and at the end of this policy.​

Seven20 keeps this policy under regular review and may update it from time to time
to reflect legal, operational, technical, or organisational changes.​

3. Representation in the UK and EEA

Seven20 confirms that representation arrangements are in place in both the United
Kingdom and the European Economic Area for processing activities where such
representation is required under applicable data protection law.​

Details of the UK representative and the EEA representative, including contact points
for supervisory authorities and data subjects, are included in any published privacy
notice(s), website contact section, or related compliance documentation maintained
by Seven20.​

4. What personal data Seven20 collects

Depending on the nature of the relationship with the individual, Seven20 may collect
and process categories of personal data including identity data, contact data,
financial data, transaction data, technical data, profile data, usage data, marketing
and communications data, and other information voluntarily submitted through forms,
enquiries, recruitment activity, account creation, or service use.​
Seven20 may also create or use aggregated and anonymised information for
statistical, analytical, service improvement, capacity planning, security monitoring, or
reporting purposes where that information does not identify an individual.​

Where special category data or criminal offence data is processed for recruitment
purposes, Seven20 will only do so where a lawful condition or legitimate interest
exists and with additional safeguards appropriate to the sensitivity and risk of that
processing.​

5. How personal data is collected

Personal data may be collected directly from individuals when they contact Seven20,
complete forms, create accounts, use services, request information, subscribe to
updates, purchase services, apply for roles, or otherwise interact with the
organisation.​

Seven20 may also collect technical and usage information automatically through
website technologies such as cookies, logs, analytics tools, security monitoring tools
and similar technologies, subject to applicable transparency and consent
requirements.​

In addition, Seven20 may receive personal data from third parties such as analytics
providers, advertising networks, search information providers, payment providers,
technical service providers, public registers, recruitment partners, business partners,
or other lawful sources.​

6. How Seven20 uses personal data

Seven20 will only use personal data where there is a lawful basis to do so.
Depending on the circumstances, this may include performance of a contract,
compliance with a legal obligation, legitimate interests, consent, or another lawful
basis permitted by applicable law.​

Personal data may be used to provide services, manage accounts, respond to
enquiries, administer contracts, process payments, deliver support, improve website
functionality, maintain security, prevent fraud, analyse service performance, manage
recruitment, send service communications, comply with legal obligations, and, where
permitted, send marketing communications.​

Where Seven20 relies on legitimate interests, it will consider the impact on
individuals and will not rely on that basis where rights and freedoms override the
relevant business interests.​A Legitimate Interest Assessment would occur.

Where consent is required, such as for certain cookies or certain direct marketing
activities, Seven20 will seek that consent and provide a means to withdraw it.​

7. Marketing and cookies
Seven20 may use personal data to send information about services, updates, events
or other content that may be relevant to the recipient, subject to applicable electronic
marketing rules and opt-out rights.​

Individuals can opt out of marketing communications at any time using unsubscribe
options or by contacting Seven20 directly.​

Seven20’s website may use cookies and similar technologies for functionality,
analytics, security and, where relevant, preference or marketing purposes. Where
required by law, cookie choices will be managed through an appropriate consent
mechanism and supported by a separate cookie notice or cookie settings tool.​

8. Disclosure of personal data

Seven20 may share personal data with employees, contractors, professional
advisers, auditors, insurers, technology and hosting providers, analytics providers,
payment providers, recruitment or communications providers, regulators, law
enforcement bodies, and other third parties where disclosure is necessary,
proportionate and lawful.​

Where third-party service providers process personal data on Seven20’s behalf,
Seven20 will require them to act only on documented instructions, apply appropriate
confidentiality and security controls, and meet contractual data protection
obligations.​

Personal data may also be disclosed in connection with a business sale, merger,
acquisition, restructure, investment transaction, legal claim, or regulatory
requirement where such disclosure is lawful and necessary.​

9. International transfers

Where personal data is transferred outside the UK or outside the EEA, Seven20 will
ensure that an appropriate safeguard is in place, such as an adequacy decision,
approved contractual clauses, binding corporate rules, or another lawful transfer
mechanism recognised under applicable law.​

Seven20 will assess international transfers where required and implement
supplementary measures where necessary to ensure that transferred personal data
continues to receive a level of protection essentially equivalent to that required under
applicable data protection law.​

10. Data security and technical measures

Seven20 applies appropriate technical and organisational measures to protect
personal data against accidental or unlawful destruction, loss, alteration,
unauthorised disclosure, unauthorised access, and other unlawful or inappropriate
forms of processing.​
These measures include governance controls, role-based access controls,
authentication measures, least-privilege access, secure configuration, patching,
endpoint protection, logging and monitoring, encryption where appropriate, secure
backup, resilience arrangements, incident management, supplier assurance, and
confidentiality obligations.​

As part of its security framework, Seven20 references ISO/IEC 27001:2022 aligned
controls as technical and organisational measures supporting the protection of
personal data, including controls relating to information security policies, legal and
regulatory compliance, privacy and protection of personally identifiable information,
information classification, deletion, masking, and leakage prevention.

11. Data retention

Seven20 will retain personal data only for as long as necessary for the purposes for
which it was collected, including to meet legal, regulatory, tax, accounting,
contractual, security and dispute-management requirements.​

Retention periods may vary depending on the type of data, the purpose of
processing, the sensitivity of the information, and the applicable legal or operational
obligations. Where data is no longer required, it will be securely deleted, anonymised
or destroyed.​

12. Data subject rights

Subject to applicable law, individuals may have rights to request access to their
personal data, rectification, erasure, restriction, objection, portability, and withdrawal
of consent where consent is relied upon. Individuals may also have rights relating to
automated decision-making, where relevant.​

Seven20 will maintain procedures to verify identity, assess requests, and respond
within applicable legal timescales. Requests may be refused or limited only where
permitted by law.​

Individuals also have the right to raise concerns with Seven20 and to lodge a
complaint with the ICO or another competent supervisory authority where they
believe their personal data has been processed unlawfully.​

13. Children and third-party websites

Seven20’s website is not intended for children unless expressly stated otherwise,
and Seven20 does not knowingly collect personal data from children through the
website without appropriate legal basis and safeguards.​

The website may contain links to third-party websites, plug-ins or applications.
Seven20 is not responsible for the privacy practices of third parties, and users
should review the relevant privacy notices when leaving Seven20’s environment.​
14. Personal data breaches

Seven20 maintains procedures for identifying, reporting, assessing, containing and
investigating suspected or actual personal data breaches. Where required by law,
Seven20 will notify the relevant supervisory authority and affected individuals within
the applicable timescales.​

15. Contact and review

Questions about this policy, privacy rights requests, and privacy concerns should be
directed to Seven20 using the contact information published in its current privacy
notice or website contact details.​

This policy shall be reviewed at least annually and earlier where there are material
changes to law, regulation, business operations, systems, vendors, international
transfers, or risk exposure.​

Seven20 Data Protection Officer – dpo@seven20.io

UK Data Subjects may raise concerns to:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
EEA Data Subjects may raise concerns to:

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28