Privacy Notice (STAFF)

Personal information we collect

Listed below are the data we currently collect from job applicants and/or staff members:

  • Name and title
  • Contact details (address, telephone numbers and email addresses)
  • Date of birth
  • Sex
  • Name of next of kin / person to contact in an emergency
  • Contact details of next of kin
  • Passport, driving licence or citizenship/immigration/visa status
  • Employment history and qualifications (CV)
  • Name of referee (usually former line-manager) and their contact details
  • National Insurance number
  • Bank sort-code, account number, account name and bank address
  • Pension provider and plan number
  • Driving licence number and record (drivers of company vehicles only)
  • Tachograph records
  • Clothing size
  • Training records
  • Disciplinary records
  • Occupational health screening data
  • Accident / Near Miss report data
  • Medical notes (if applicable) and self-certified reasons for sickness absence
  • PPE issue records
  • Attendance records
  • Time-keeping and working hours data
  • Personal reasons for non-attendance
  • Trade union membership information
  • CCTV footage
  • Photographs
  • Spending history (company loans)

How we get the personal information and why we have it

Most of the personal information we process is provided to us directly by you for one of the following reasons:

  • To consider whether you are suitable for us to employ
  • To engage you in employment and pay you for the work that you do
  • To contact your loved ones in the event of an accident at work
  • To issue you with company workwear
  • To fulfil our statutory responsibilities in relation to health and safety
  • To manage you, and your colleagues, effectively in order to meet the needs of the business
  • To fulfil our statutory responsibilities in relation to equality
  • To enable customers to engage with you in matters of business
  • To assist us in marketing the business
  • To ensure that company money is managed responsibly.

We also receive personal information indirectly, from the following sources in the following scenarios:

  • Previous employers, providing us with information on your skills, performance and disciplinary record, after you have supplied us with a named referee in respect of a job application
  • Government agencies (including HMRC and the Department of Work & Pensions), in respect of money to be deducted from your earnings e.g. student loan repayments, child or familial maintenance payments
  • Rocliff workwear, in order to distribute company workwear to you
  • Spirit Occupational Health, providing us with data from occupational health screening, so that we may effectively manage health and safety.

We may share this information with the following organisations for the following reasons:

  • Sage (in order to administer our payroll and advise us on HR matters)
  • Caerwyn Jones (in order that they may audit the company’s accounts)
  • Lloyds Bank (in order to pay your salary/wages)
  • Midland Financial Limited (in order that they may provide you with pension advice)
  • RANDD UK (in order to prepare a company submission for an R&D tax credit)
  • Rollinson Smith (in order to discuss our insurance and potential claims)
  • The Health and Safety Executive (in order to fulfil our statutory duties)
  • Spirit Occupational Service and OcchNet (for the purposes of occupational health screening and personal exposure monitoring)
  • Elliott Bridgman solicitors (in order to manage a legal dispute)
  • Influx Digital (in order to update the company website and manage digital marketing)
  • External training providers (various) (in order to provide staff training)
  • Vanguard Alarms (in order to maintain the company CCTV system)
  • Competent agencies including the police and HSE (in order to assist a legitimate investigation).

Our legal bases for processing

Under the UK General Data Protection Regulation (UK GDPR), the lawful bases we rely on for processing this information are:

DataLawful basisApplies to
Name and titleConsent*Job applicants
ContractStaff members
Legal obligationFormer staff
Contact detailsConsent*Job applicants
ContractStaff members
Date of birthContractStaff members
Legal obligationFormer staff
SexContractStaff members
Legal obligationFormer staff
Next of kin contactConsent**Staff members
Passport, driving licence or citizenship/immigration/visa status
(Right to work data)
Legal obligationJob applicants
Staff members
Former staff
Employment history and qualifications (CV)Consent*Job applicants
Legitimate interestsStaff members
Former staff
Known associates – referee and referee’s contact detailsConsent*Job applicants
National Insurance NumberLegal obligationStaff members
Former staff
Bank sort-code, account number, account name and bank addressContractStaff members
Legal obligationFormer staff
Pension provider and plan numberConsent**Staff members
Legal obligationFormer staff
Driving licence and recordLegal obligationCompany drivers
Former staff
Tachograph recordsLegal obligationCompany drivers
Former staff
Clothing sizeConsent*Staff members
Training recordsLegal obligationStaff members
Former staff
Disciplinary recordsLegitimate interestsStaff members
Former staff
Occupational health screening dataConsent*Staff members
Former staff
Job Applicants
Accident/Near Miss ReportsLegal obligationStaff members
Job Applicants
Former staff
PPE recordsLegitimate interestsStaff members
Former staff
Attendance recordsContractStaff members
Legal obligationFormer staff
Time-keeping and working hours dataLegal obligationStaff members
Former staff
Fit notes/self-certification formsConsent*Staff members
Former staff
Personal disclosures (attendance)Consent*Staff members
Former staff
CCTV footageLegitimate interestsStaff members
Job applicants
Former staff
PhotographsConsent*Staff members
Spending history (company loans)ContractStaff members

*Consent can be withdrawn at any time by contacting the Managing Director.

**Consent can be withdrawn at any time by contacting the Finance Manager.

How we store staff information

Your information is securely stored.

We store almost all staff personal information on our local servers and/or backed-up to Microsoft (cloud) servers located in the UK. Our CCTV footage is stored to a local hard-drive, which is kept in a secure room on site.

Data is retained for the minimum period necessary. Retention lengths are as follows:

DataRetention period
Name and title6 years after exit
Contact details6 years after exit
Date of birth6 years after exit
Sex6 years after exit
Next of kin contact6 years after exit
Right to work data2 years after exit
Recruitment data1 year after application
National Insurance Number6 years after exit
Banking, tax and pay data6 years after exit
Pensions data4 – 6 years after exit
Driving licence and record6 years after exit
Tachograph records1 year
Clothing size6 years after distribution
Training records6 years after exit
Disciplinary records6 years after exit
Occupational health screening data10 – 40 years after exit
Accident/Near Miss Reports3 – 40 years after incident
PPE records40 years
Attendance records6 years after exit
Time-keeping and working hours data2 years
Fit notes/self-certification6 – 40 years after exit
Personal disclosures (attendance)6 years after exit
Trade union membership6 years after exit
CCTV footage90 days
PhotographsOn exit or on request
Spending history (company loans)6 years after exit

Data is wiped from the server at the end of the retention period (and from the back-up servers within 24 hours). Our CCTV footage is automatically re-written after 3 months, unless we snip and retain a section of footage to support an accident or criminal investigation, in which case it will be kept for the duration of the relevant proceedings or until the statutory limitation period expires.

Your data protection rights

Under data protection law, you have rights including:

Your right of access - You have the right to ask us for copies of your personal information.

Your right to rectification - You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.

Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.

Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal information in certain circumstances.

Your right to object to processing - You have the the right to object to the processing of your personal information in certain circumstances.

Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.

You will not ordinarily be required to pay any charge for exercising your rights, unless you make a request which is manifestly unfounded or excessive (see the company Data Protection Policy for further details). If you make a request, we will normally respond to you within one month of receiving your request (see the company Data Protection Policy for more information).

How to complain

If you have any concerns about how Hitherbest uses your personal information, you should speak to a company Director.

You can also complain to the ICO if you are unhappy with how we have used your data.

The ICO’s address is:            

Information Commissioner’s Office

Wycliffe House

Water Lane




Helpline number: 0303 123 1113

ICO website:

Contact Hitherbest

We welcome enquiries from businesses in any sector. Please outline your requirements by completing the form below.
If you are new to sheet metal fabrication, our checklist details the information we need in order to provide a quotation.
Upload failed. Max size for files is 10 MB.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.