This notice describes the online and support services that GBD SOUTHWEST LIMITED provides. GBD SOUTHWEST LIMITED, also referred to throughout as GBD Southwest or simply the company, is a computer systems design and marine integration practice. The individual developer responsible for product direction and ownership is Liu Qian. All personal information described in this policy is processed with care, kept to what is necessary and used only for the purposes set out below. The full registered details of the company appear in section one and again in the footer of this page. By continuing to use our website or our services after reading this policy you confirm that you understand and accept the practices described.
1. The Company Behind This Policy
This privacy policy is published on the website of GBD SOUTHWEST LIMITED, a company formed and registered in England and Wales under the laws of the United Kingdom. The company designs, builds and operates computer systems for coastal, maritime and scientific clients. Its office is based in Plymouth on the south coast of Devon, close to the water it works with every day.
The services described in this and other pages are designed, developed and operated by GBD Southwest, the developer and operator identity used by the company across its products and web estate. GBD Southwest is the name you will most often see on our charts, dashboards and launch screens. The developer behind that identity, and the technical steward of these systems, is Liu Qian. When you share personal information with GBD Southwest you share it with GBD SOUTHWEST LIMITED and you do so under the terms of this policy.
Because the company sits within the professional, scientific and technical services sector, a great deal of the work it does is business to business and much of the data it touches belongs to clients rather than to private individuals. Even so, the company is committed to protecting the personal information of everyone it deals with, whether you are a client, a supplier, a visitor to this website, an applicant or simply someone who sends an enquiry. This policy explains how that protection works in practice.
The registered company details that you may need for any official correspondence are set out below.
- Company
- GBD SOUTHWEST LIMITED
- Office
- GBD SOUTHWEST LIMITED, 3 Sparke Close, Plymouth - PL7 2YA, United Kingdom (GB)
- Sector
- Computer Systems Design and Related Services
- Developer
- GBD Southwest, represented by Liu Qian
- Contact
- reach@gbdsouthwest.buzz or +17345754279
2. Scope of This Policy
This policy applies to personal information that we collect whenever you interact with GBD Southwest and GBD SOUTHWEST LIMITED. That interaction may take place on this website, on other websites or landing pages we operate, by telephone, by email (including reach@gbdsouthwest.buzz and the +17345754279 line that is answered from Plymouth), by post to our registered office, through written proposals, through support tickets, or when we attend your premises or you attend ours.
The scope of this policy also extends to the personal information that reaches us indirectly. Where we provide systems design, integration or managed operations services to a client organisation, that client may ask us to handle data that ultimately concerns individuals, such as the names and contact details of their own staff or of third parties they coordinate. In those situations we act under the written instructions of our client and the personal information in question remains governed by our agreement with the client and by any separate privacy statement the client publishes to its own users.
This policy does not apply to the websites or services of third parties. Where we link from our own pages to external sites, to regulators, to professional bodies or to partner tools, those destinations are outside our control and carry their own privacy terms. We encourage you to read those terms before you share information through any third party service.
If you are under the age of consent in your country, please ask a parent or guardian to read this policy with you and to confirm on your behalf before you send us any personal information. Our business to business services are not aimed at children and we do not knowingly collect data from children without appropriate consent.
3. Who Controls Your Data
Under the data protection legislation of the United Kingdom and the European Economic Area, the data controller for the personal information described in this policy is GBD SOUTHWEST LIMITED. When we say the controller, we mean the company that decides why and how your personal information is processed. For the purposes of this website and the direct services that GBD Southwest provides to you, GBD SOUTHWEST LIMITED is the controller.
The registered office and postal address of the controller is GBD SOUTHWEST LIMITED, 3 Sparke Close, Plymouth - PL7 2YA, United Kingdom (GB). The quickest way to reach the controller about any privacy matter is to write to reach@gbdsouthwest.buzz or to telephone +17345754279 during the office hours shown on our contact page. All subject access requests, complaints and queries about this policy should be directed to that address.
In a small number of circumstances the company acts as a processor rather than a controller. This happens, for instance, when a client asks us to operate or integrate a system that holds personal data belonging to that client. In those cases the client remains the controller and we process the data only in line with their lawful instructions and our service contract. If you wish to exercise any right in connection with one of those client systems, the first point of contact should be the client organisation itself, though we will assist them where they ask us to.
4. The Information We Collect
We collect personal information only where there is a genuine business reason to do so. We are deliberate about limiting what we gather, because excessive collection burdens both you and us without adding value. The categories of personal information we may collect fall into the groups described below.
Information you provide directly
- Contact details such as your full name, job title, organisation, email address, postal address and telephone number.
- Enquiry details contained in messages you send through this website, by email or by phone, including the content of any message and any attachment you choose to include.
- Project information you share in proposals, discovery sessions, questionnaires or meetings that relates to the services you wish us to deliver.
- Billing details, including a company or personal bank reference where a payment method is needed to establish an account.
- Any preferences you express about how and when you wish to be contacted.
Information collected automatically
- Basic technical data sent by your browser or device, such as internet protocol address, browser type, language, screen resolution and the referring page.
- Limited analytics that help us understand how the pages of this website are used, including which sections attract interest and which links people follow. We keep this data aggregated and use it to improve the usefulness of our content rather than to profile you personally.
- Small files known as cookies and similar technology, described in more detail in section eight of this policy.
Information obtained from other sources
- Public details about a business or a named contact drawn from sources available by law, such as a trade register, a professional directory or a client website.
- Referrals you authorise a colleague or partner to pass to us and the background notes that come with them.
We do not seek sensitive special category data, such as data about health, race, religion or political opinions, and we ask you not to send us such information unless a particular engagement genuinely requires it and you have agreed to its handling. Where you do share such information with us unexpectedly, we will treat it securely and delete it where it is not needed for your work with us.
5. Why We Are Allowed to Process Your Data
The data protection laws require that every use of personal information is justified by a recognised lawful basis. We rely on the bases described below, and we choose the basis that fits each purpose. In most of our dealings with clients and enquirers the lawful basis is one of the following.
- Performance of a contract. When you engage us to design, integrate, operate or support a system, we process the personal information needed to deliver that contract, to manage our relationship with you and to invoice and account for the work.
- Legitimate interests. Where we promote our services, respond to enquiries, maintain the security of our systems, prevent misuse and improve our website, we rely on our own legitimate interests and the interests of those who reply on our coastal systems. We always balance these interests against your rights so that our activity does not override your expectations of reasonable privacy.
- Consent. Where we ask for a personal decision that is truly yours, such as agreeing to a marketing communication not strictly connected to a live matter, we will ask for your consent and you may withdraw that consent at any time without penalty.
- Legal obligation. Where the law obliges us to keep certain records, answer a regulator, prevent unlawful activity or cooperate with a lawful authority, we process data to meet that obligation.
We will not sell your personal information to anyone. We will not rent it, trade it or pass it to a third party for their own marketing without your permission. Those statements are unqualified and form part of the promise we make to every person who shares data with us.
6. How We Use Your Information
We use personal information for a defined set of business purposes. Each purpose is matched to the data it needs and no more. The principal uses are listed here.
- To answer enquiries from this website, by post, by phone on +17345754279 or by email at reach@gbdsouthwest.buzz and to follow those enquiries through to a proposal.
- To prepare and deliver the systems, analytics, telemetry, safety and support services described on our services page.
- To manage accounts, produce invoices, track payments and keep the financial records required by law.
- To operate secure access to client systems and to protect them from unauthorised use.
- To send service notices relevant to the work you commission from us, including maintenance windows, updates and renewals.
- To send occasional professional updates about our company for which we have your consent or a clear legitimate interest.
- To improve this website and our internal ways of working through aggregated statistics.
- To meet our duties in law, to respond to legitimate requests from regulators, and to defend the legal interests of the company and our clients.
Where information is used for more than one of these purposes we do not combine them in a way that would change the basis on which you shared the data. Where a new purpose emerges that is not compatible with the purpose for which you gave the data, we will ask your permission or find a separate lawful basis before we proceed.
9. How Long We Keep Your Information
We keep personal information only for as long as it is needed for the purpose for which it was collected and for any period during which the law or a legitimate business record obligation requires us to keep it. After that point we delete it or make it anonymous so that it can no longer be linked to you.
As a practical guide, we hold the data of a live client for the duration of our contract plus a reasonable period afterwards so that we can honour warranties, answer audit questions and support a smooth handover. Enquiry correspondence that does not become a contract is held only briefly and then removed. Accounting records that must satisfy statutory tax requirements are kept for the period set by law from the end of the relevant financial year. Backup copies of our working files are retained on a schedule that balances the need to recover from a failure against the wish not to keep stale personal data indefinitely.
The retention period for any particular item may be shorter or longer depending on its nature. Where you ask us to delete data we honour the request unless the law or a legitimate and overriding record obligation requires us to keep it. In every case we review our records on a regular cycle so that nothing is kept out of habit.
10. International Transfers of Data
GBD SOUTHWEST LIMITED is registered in the United Kingdom and its office is in Plymouth. Some of the systems and providers that support our work store data on servers located outside the country where you are based, which can include the United Kingdom, the European Economic Area and other regions. When personal information moves across an international boundary we make sure that the transfer is protected by an appropriate safeguard recognised in law.
For transfers from the United Kingdom or the EEA to a country that maintains equivalent protection, such as another country covered by an adequacy decision, the data flows freely under those protections. Where a transfer goes to a country without that standing, we rely on binding contractual terms, standard contractual clauses or another recognised mechanism, all of which oblige the receiving party to keep your data safe to a standard similar to the one it enjoys at home.
You may ask us, using the contact details at the end of this policy, for a summary of the safeguards that apply where your data is transferred abroad. We will provide that summary promptly and without charge.
11. How We Protect Your Information
Security sits at the heart of our own coastal engineering work and we apply the same discipline to the personal information you entrust to us. Our aim is to protect your data against accidental loss, unlawful access, alteration or disclosure and to do so at a level that matches the sensitivity of the data involved.
- Access control. Only named staff and developers who need your data for an authorised purpose may reach it, and access is reviewed as roles change.
- Encryption. Data in transit over public networks is protected with current encryption, and sensitive data at rest is stored on encrypted media where our hosting allows it.
- Secure authentication. Any client system we operate uses strong authentication, password policies and, where appropriate, multi factor verification before someone can reach the area holding personal information.
- Housekeeping. We keep software patched, review logs for unusual behaviour, rehearse our recovery plan and remove unneeded records on schedule.
- Staff training. Our people are reminded regularly of their confidentiality duties and of the small number of acceptable ways in which personal data may be handled.
No system is ever completely immune from risk, and for that reason we also maintain an incident plan. If a security event does compromise personal information in a way that is likely to create a risk to you, we will notify you and the relevant regulator as the law requires and we will do everything reasonable to limit the harm and to prevent a repeat.
12. Your Rights as a Data Subject
The data protection law of the United Kingdom and, where relevant, the European Union gives you a set of clear rights over the personal information we hold. You may exercise any of them at no cost by writing to reach@gbdsouthwest.buzz or in writing to the registered office at GBD SOUTHWEST LIMITED, 3 Sparke Close, Plymouth - PL7 2YA, United Kingdom (GB). The main rights are set out below.
- Right of access. You may ask for a copy of the personal information we hold about you and for details of how we use it.
- Right to rectification. If the information we hold is inaccurate or incomplete you may ask us to correct it, and we will act without undue delay.
- Right to erasure. In the circumstances set out in law you may ask us to delete the personal information we hold about you. We will comply unless there is an overriding legal basis for keeping it.
- Right to restrict processing. You may ask us to pause the use of your information while a dispute about its accuracy or its lawful basis is resolved.
- Right to data portability. Where we process your data on the basis of consent or a contract and by automated means, you may ask for a structured, machine readable copy to give to another provider.
- Right to object. Where we rely on legitimate interests you may object to that use, and we will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms.
- Right to withdraw consent. Where processing depends on your consent you may withdraw it at any time, and stopping will be easy and as quick as giving it.
- Right not to be subject to automated decisions. You have rights related to significant decisions made about you without meaningful human involvement. We do not make such automated decisions about the people who deal with us.
To help us locate the correct record, please tell us who you are and give us enough detail about the information you are concerned with. We will verify your identity before we release personal details to you, and we will respond within the time the law allows, normally one month. If you are not satisfied with how we handle a request you may complain to the data protection authority of your own country, and in the United Kingdom that authority is the Information Commissioner Office.
13. Marketing and Communication Preferences
We do not send speculative marketing to people we have never had contact with. When we do communicate for marketing related reasons, such as a periodic update about our coastal engineering work, we do so only where we have your consent or where there is a clear legitimate interest that connects to work you have discussed with us.
Every update or notice that is purely promotional will carry a simple and obvious way to opt out. You can also update your preferences at any time by emailing reach@gbdsouthwest.buzz and asking us to remove you from a specific mailing list or from all of them. We will action that request promptly and we will retain no details of you beyond what is needed to respect your choice, namely a small suppression record so that we do not accidentally mail you again.
Please note that service messages that relate to an active contract, such as a maintenance window or a renewal reminder, are not marketing. They are part of delivering the service you asked for, and you will continue to receive them for as long as that relationship exists even if you opt out of marketing.
14. Children and This Website
The services of GBD SOUTHWEST LIMITED are provided to businesses and professional organisations serving the coastal, maritime and scientific sectors. They are not directed at children and they are not intended to attract the personal data of individuals under the age from which they can give their own consent to online data processing in their country.
We do not knowingly collect personal information from children without the involvement and consent of a parent or guardian. If you believe that a child has provided us with personal data without that consent, please contact us at reach@gbdsouthwest.buzz and we will review the situation and delete the data where no lawful basis for keeping it exists. We would rather lose a record than keep one that causes a young person concern.
15. Personal Data Inside Client Systems
A significant part of what GBD Southwest does is to design and operate systems for other organisations. A coastal telemetry platform, a harbour analytics dashboard or a compliance system may naturally hold records that relate to members of the public, to vessel crews, to contractors or to the staff of the client itself.
When personal information flows through a system that we have built or that we operate for a client, we act on that flow under the instruction of the client organisation. In that role we are the processor of the data and the client is the controller with the direct relationship to the people the data concerns. We take care to process such data only for the operation of the service, to keep it secure, and to follow any retention or deletion timetable our client confirms to us.
If personal data concerns you within one of these client systems, the most direct route to exercise your rights is through the organisation that contracted the system and that manages the people affected. We stand ready to assist that organisation and to cooperate so that your rights are honoured in full.
16. Changes to This Policy
We review this privacy policy whenever our services, our laws or our technology change in a material way, and at least once a year to confirm that it remains accurate. When we make a significant change we update the last updated date at the top of this page and, where the change is important enough, we draw it to the attention of active clients and contacts so that they can review it.
We encourage you to check this page from time to time so that you stay aware of how your information is handled. The version shown on this page is always the version currently in force. Where a change would alter the basis on which we process information you have already given us, we will give you the opportunity to review and, where needed, to reconfirm your consent within the new terms.
Continued use of this website or of our services after an update to this policy indicates that you have read and accepted the revised version, except where a specific new consent is required by law before we may continue a particular processing activity.
17. Complaints, Queries and Contact Details
If you have any question about how GBD SOUTHWEST LIMITED or GBD Southwest uses personal information, or if you wish to raise a concern about a specific handling of your data, you should in the first instance contact us. We will treat every enquiry seriously, answer it clearly and act to put right anything that has gone wrong.
You can reach the company by email at reach@gbdsouthwest.buzz, by telephone on +17345754279 or by post to GBD SOUTHWEST LIMITED, 3 Sparke Close, Plymouth - PL7 2YA, United Kingdom (GB). Please mark any written privacy correspondence clearly so that it reaches the person responsible for data matters rather than the general desk.
If you remain unhappy after we have responded, you have the right to complain to a supervisory authority. Within the United Kingdom the relevant body is the Information Commissioner Office, which you may contact through the contacts published on its own official website. Within the European Economic Area you may complain to the data protection authority of your own member state. We will never penalise you for raising a legitimate concern, and we will cooperate fully with any authority that investigates a matter relating to our handling of personal information.