When someone visits www.epm.co.uk we use a third-party service, Google Analytics, to collect standard internet log information and details of visitor behaviour patterns. We do this to find out things such as the number of visitors to the various parts of the site. This information is only processed in a way which does not identify anyone. We do not make, and do not allow Google to make, any attempt to find out the identities of those visiting our website. If we do want to collect personally identifiable information through our website, we will be up front about this. We will make it clear when we collect personal information and will explain what we intend to do with it.
E-newsletter and Events We use a third-party software provider, HubSpot, to deliver our advice notes and invitations for events. We gather statistics around email opening and clicks using industry standard technologies including clear gifs to help us monitor and improve our service. For more information, please see HubSpot’s privacy notice.
Security and Performance EPM uses a third-party service, Chameleon, to help maintain the security and performance of the EPM website. To deliver this service it processes the IP addresses of visitors to the EPM website.
Website We use a third-party service, Chameleon, to publish our website. We use a standard service to collect anonymous information about users’ activity on the site, for example the number of users viewing pages on the site, to monitor and report on the effectiveness of the site and help us improve it.
People who email us
We use Transport Layer Security (TLS) to encrypt and protect email traffic in line with the General Data Protection Regulation (GDPR). If your email service does not support TLS, you should be aware that any emails we send or receive may not be protected in transit.
We will also monitor any emails sent to us, including file attachments, for viruses or malicious software. Please be aware that you have a responsibility to ensure that any email you send is within the bounds of the law.
People who call us
Inbound and outbound calls may be recorded for training, quality purposes and to address queries or issues raised.
People who use EPM services
EPM offers various online services and resources relating to human resources, payroll and pensions. We may use third-parties to deal with some direct marketing campaigns, but they are only allowed to use the information to send out the publications.
We have to hold the details of the people who have requested our services in order to provide them. However, we only use these details to provide the service a person or organisation has requested and for other closely related purposes. When people do subscribe to our services, they can cancel their subscription at any time and are given an easy way of doing this.
Where the personal information is not processed on behalf of a customer, the data controller of your personal information shall be EPM Limited which is registered with the Information Commissioner’s Office with registration number Z4871398.
Our online services portals (EPM Portal and EPM ePayslips Portal) record data relating to human resources, payroll and pensions for and on behalf of our customers and their staff. In these cases, EPM is acting as a Data Processor on behalf of our customers. For more information, please speak to your employer/the relevant Data Controller.
Personal information we collect from you, or from a customer relating to you, will be retained where we have ongoing legitimate business needs to do so (for example, to provide you or our customers with a service or to comply with applicable legal, tax or accounting requirements).
Job applicants, current and former EPM employees
EPM is the data controller for the information you provide during the process unless otherwise stated. If you have any queries about the process or how we handle your information, please contact us on the details at the bottom of the page.
What will we do with the information you provide to us? All information you provide during the application process will only be used for the purpose of progressing your application, or to fulfil legal or regulatory requirements if necessary.
We will not share any of the information you provide during EPM’s internal recruitment process with any third parties for marketing purposes. Data sent electronically or processed beyond the initial application will be stored within the European Economic Area by our third-party processors – all processors have appropriate levels of security and organisational controls to meet data protection requirements. The information you provide will be held securely by us and/or our data processors whether the information is in electronic or physical format.
We will use the contact details you provide to us to contact you to progress your application. We will use the other information you provide to assess your suitability for the role you have applied for.
What information do we ask for and why?
We do not collect more information than we need to fulfil our stated purposes and will not retain it for longer than is necessary.
The information we ask for is used to assess your suitability for employment. You don’t have to provide what we ask for, but it might affect your application if you don’t.
Applications may be received by email, physically by post or through a third-party recruitment agency. We may ask you for your personal details including name and contact details. We will also ask you about your previous experience, education, referees and for answers to questions relevant to the role you have applied for. Our recruitment team will have access to all of this information.
You will also be asked to provide equal opportunities information. This is not mandatory information – if you don’t provide it, it will not affect your application. This information will not be made available to any staff outside of our recruitment team, including hiring managers, in a way which can identify you. Any information you do provide will be used only to produce and monitor equal opportunities statistics.
Shortlisting Our hiring managers’ shortlist applications for interview. They will not be provided with your name or contact details or with your equal opportunities information, if you have provided it.
We might ask you to participate in assessment days; complete tests or occupational personality profile questionnaires; and/or to attend an interview – or a combination of these. Information will be generated by you and by us. For example, you might complete a written test, or we might take interview notes. This information is held by the EPM.
If you are unsuccessful following assessment for the position you have applied for, we may ask if you would like your details to be retained in our talent pool for a period of six months. If you say yes, we would proactively contact you should any further suitable vacancies arise.
Conditional offer If we make a conditional offer of employment we will ask you for information so that we can carry out pre-employment checks. You must successfully complete pre-employment checks to progress to a final offer. We are required to confirm the identity of our staff, their right to work in the United Kingdom and seek assurance as to their trustworthiness, integrity and reliability.
You will therefore be required to provide:
Proof of your identity – you will be asked to attend our office with original documents, we will take copies. Proof of your qualifications – you will be asked to attend our office with original documents, we will take copies. We will contact your referees, using the details you provide in your application, directly to obtain references. We will also ask you to complete a questionnaire about your health. This is to establish your fitness to work. This is done through a data processor (please see below). If we make a final offer, we will also ask you for the following:
Bank details – to process salary payments.
Emergency contact details – so we know who to contact in case you have an emergency at work.
Use of data processors: Data processors are third parties who provide elements of our recruitment service for us. We have contracts in place with our data processors. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will not share your personal information with any organisation apart from us. They will hold it securely and retain it for the period we instruct.
If you are employed by EPM, relevant details about you will be provided to a number of third-party providers, including our payroll and pensions providers. All staff will be given an appropriate privacy notice to explain this in detail.
How long is the information retained for? If you are successful, the information you provide during the application process will be retained by us as part of your employee file for the duration of your employment, plus 6 years following the end of your employment. This includes your criminal records declaration, fitness to work, records of any security checks and references.
If you are unsuccessful at any stage of the process, the information you have provided until that point will be retained for 6 months from the closure of the campaign.
Information generated throughout the assessment process, for example interview notes, is retained by us for 6 months following the closure of the campaign.
Equal opportunities information is retained for 6 months following the closure of the campaign whether you are successful or not. When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
How we make decisions about recruitment?
Final recruitment decisions are made by hiring managers and members of our recruitment team. All of the information gathered during the application process is taken into account.
You are able to ask about decisions made about your application by speaking to your contact within our recruitment team or by contacting the Data Protection Officer on the details at the bottom of this page.
Under data protection legislation, you have rights as an individual, which you can exercise in relation to the information we hold about you.
EPM tries to meet the highest standards when collecting and using personal information. For this reason, we take any complaints we receive about this very seriously. We encourage people to bring it to our attention if they think that our collection or use of information is unfair, misleading or inappropriate. We would also welcome any suggestions for improving our procedures.
This privacy notice was drafted with brevity and clarity in mind. It does not provide exhaustive detail of all aspects of EPM’s collection and use of personal information. However, we are happy to provide any additional information or explanation needed. Any requests for this should be sent to the address below.
If you want to make a complaint about the way we have processed your personal information, you can contact the Information Commissioner’s Office in their capacity as the statutory body which oversees data protection law: www.ico.org.uk/concerns.
Access to Personal information
Where EPM acts as the data controller, EPM tries to be as open as it can be in terms of giving people access to their personal information. Individuals can find out if we hold any personal information by making a ‘data subject access request.
If we do hold information about you we will:
Give you a description of it;
Tell you why we are holding it;
Tell you who it could be disclosed to; and
Let you have a copy of the information in an intelligible form.
Where an individual makes a subject access request to EPM and EPM is acting as a data processor, EPM will pass the details of the request on to the relevant data controller who will deal with the request directly
To make a request to the EPM for any personal information we may hold you need to put the request in writing to the address provided below.
If you agree, we will try to deal with your request informally, for example by providing you with the specific information you need over the telephone.
If we do hold information about you, you can ask us to correct any mistakes by, once again, contacting the Data Protection Officer.
Disclosure of personal information
In many circumstances we will not disclose personal data without consent, unless legally obliged to do or as part of contractual obligations with our customers (where you are a party to the agreement or service).
We may disclose your personal information to the following categories of recipients:
to our group companies, third party services providers and partners who provide data processing services to us (for example, to support the delivery of, provide functionality on, or help to enhance the security of our Website), or who otherwise process personal information for purposes that are described in this Privacy Notice or notified to you when we collect your personal information. The Citation Group consists of:
QMS International Limited
Education Personnel Management Limited
P. & R. Services (Southampton) Limited
to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person;
to a potential buyer (and its agents and advisers) in connection with any proposed purchase, merger or acquisition of any part of our business, provided that we inform the buyer it must use your personal information only for the purposes disclosed in this Privacy Notice;
to enforce or apply our Terms of Service or other agreements or to protect EPM and its customers (including with other companies and organisations for the purposes of fraud protection and credit risk reduction); and to any other person with your consent to the disclosure.
Legal basis for processing personal information
If you are a visitor from the European Economic Area, our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.
However, we will normally collect personal information from you only where we have your consent to do so, where we need the personal information to perform a contract with/involving you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect personal information from you or may otherwise need the personal information to protect your vital interests or those of another person.
If we ask you to provide personal information to comply with a legal requirement or to perform a contact with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).
Similarly, if we collect and use your personal information in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are.
If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided under the “How to contact us” heading below.
Links to other websites
This privacy notice does not cover the links within this site linking to other websites. We encourage you to read the privacy statements on the other websites you visit.
Changes to this privacy notice
We keep our privacy notice under regular review.
How to contact us
If you want to request information about our privacy notice, you can email us at DPO@epm.co.uk or write to:
Data Protection Officer
St John’s House
Ermine Business Park