Privacy policy

Controller

Road Haulage Association Limited (RHA) is the controller and responsible for your personal data (collectively referred to as “RHA”, "we", "us" or "our" in this privacy notice).

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the DPO using the details set out below.

Contact details

Full name of legal entity: Road Haulage Association Limited

Name or title of DPO: Arnold Monk

Email address: gdprenquiries@rha.uk.net

Postal address: Arnold Monk, Data Protection Officer, Road Haulage Association Limited, Roadway House, Bretton Way, Bretton, Peterborough PE3 8DD

Our Commitment to Privacy

Your privacy is important to us. To better protect your privacy, we provide this notice explaining our information practices and the choices you can make about the way your information is collected and used.

The information we collect

This notice applies to all information collected or submitted to RHA. With RHA you can order products and services, make requests and register to receive materials. The types of personal information collected by RHA include:

Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth, gender and copies of identity documents such as driving licences.

Contact Data includes billing address, delivery address, email address and telephone numbers.

Financial Data includes bank account and payment card details.

Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us.

Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.

Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.

Usage Data includes information about how you use our website, products and services.

Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.

How we collect your personal data

We use different methods to collect data from and about you including through:

Direct interactions. You may give us your identity, contact and financial data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:

  • apply for our products or services;
  • create an account on our website;
  • subscribe to our service or publications;
  • request marketing to be sent to you;
  • enter a competition, promotion or survey; or
  • give us some feedback.

Automated technologies or interactions. As you interact with our website, we may automatically collect technical data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies.

The way we use information

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

Where we need to perform the contract, we are about to enter into or have entered into with you.

Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.

Where we need to comply with a legal or regulatory obligation.
We use the information you provide about yourself when placing an order only to complete that order. We may share your information with our business partners and 

other external parties only to the extent necessary to complete the order or to comply with legal requirements.

Return email addresses are used by us to respond to email received. Such addresses are not shared with outside parties.

You can register with our website www.rha.uk.net if you would like to receive news and updates on our new products and services. Information you submit on our website will be used for this purpose, you can unsubscribe at any time.

Generally, we do not rely on consent as a legal basis for processing your personal data other than in relation to sending third party direct marketing communications to you via email or text message. We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data.

Purpose/Activity

Type of data

Lawful basis for processing including basis of legitimate interest

To register you as a new customer

(a)Identity
(b)Contact

Performance of a contract with you

To process and deliver your order including:

(a) Manage payments, fees and charges

(b) Collect and recover money owed to us

(a) Identity
(b) Contact
(c) Financial
(d) Transaction
(e) Marketing and Communications

(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to recover debts due to us)

To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy policy
(b) Asking you to leave a review or take a survey

(a) Identity
(b) Contact
(c) Profile
(d) Marketing and Communications

(a) Performance of a contract with you
(b) Necessary to comply with a legal obligation
(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

To enable you to partake in a prize draw, competition or complete a survey

(a) Identity
(b) Contact
(c) Profile
(d) Usage
(e) Marketing and Communications

(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)

(a) Identity
(b) Contact
(c) Technical

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation

To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you

(a) Identity
(b) Contact
(c) Profile
(d) Usage
(e) Marketing and Communications
(f) Technical

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)

To use data analytics to improve our website, products/services, marketing, customer relationships and experiences

(a) Technical
(b) Usage

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

To make suggestions and recommendations to you about goods or services that may be of interest to you

(a) Identity
(b) Contact
(c) Technical
(d) Usage
(e) Profile

Necessary for our legitimate interests (to develop our products/services and grow our business)

International transfers

Many of our external third parties are based outside the European Economic Area (EEA) so their processing of your personal data may involve a transfer of data outside the EEA.

Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.

Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe.

Where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US.

Our Commitment to Data Security

To prevent unauthorised access, maintain data accuracy and ensure the correct use of information, we have put in place appropriate physical, electronic and managerial procedures to safeguard and secure the information we collect.

How long will you use my personal data for?

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we 

process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

Some data we are required to maintain for a minimum period of time, examples include:

  • Driver CPC records which must be retained for a minimum of 6 years;
  • Financial records minimum of 6 years for auditing purposes;
  • VAT records for minimum 6 years;
  • RHA Membership records 2 years following termination;

We will not keep your information for longer than is appropriate.

 

Your rights

Access

You can ask for the personal information we hold about you and for details about how and for what purpose we use your information.

Rectification

You can ask us to correct any personal information that’s inaccurate or incomplete

Objection

You can ask us to stop processing your personal information in certain circumstances

Restriction

You can ask us to temporarily stop processing your personal information in certain circumstances

Erasure

You can ask us to delete any information we hold about you if the law and our data retention policies no longer require us to keep it.

Data Portability

You can ask us for copies of the information we hold about you so that you can move, copy or transfer personal data easily from one IT environment to another.

Automated decisions/profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which has legal effects for you or affects you in any other significant way.

Marketing

You have the right to opt out of any marketing of products and RHA services you do not wish to receive and will not be contacted.

Third-Party Marketing

We will get your express opt-in consent before we share your personal data with any company for marketing purposes.

Opting out

You can ask us or third parties to stop sending you marketing messages at any time by logging into the website and checking or unchecking relevant boxes to adjust your

marketing preferences or by following the opt-out links on any marketing message sent to you

Contact Us

Should you have question or concerns about our privacy policy or would like to exercise one of your rights, please get in touch.

Email us: gdprenquiries@rha.uk.net

Write to us at: Arnold Monk, Data Protection Officer, Road Haulage Association Limited, Roadway House, Bretton, Peterborough, PE3 8DD