MIS Active Management Systems Limited – Privacy Policy

1. This privacy policy gives you information about how MIS Active Management Systems Limited (“MIS-AMS”) collects and uses your personal data through your use of this website, including any data you may provide when you register with us, sign up to our newsletter, purchase a product or service or take part in a competition.

2. This website is not intended for children and we do not knowingly collect data relating to children.

3. The Aareon Group (Group) is made up of different legal entities, details of which can be found here: https://www.aareon.co.uk/aboutus. This privacy policy is issued on behalf of the Group so when we mention “MIS-AMS”, “we”, “us” or “our” in this privacy policy, we are referring to the relevant company in the Group responsible for processing your data. MISAMS is the controller and responsible for this website and any data you provide when registering with us, sign up to our newsletter, purchase a product or service or take part in a competition.

4. We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights (paragraph 9), please contact us using the information set out in the contact details section (paragraph 10).

5. The types of personal data we may collect about you

6. Collection of Information

7. Use of Information 

Purpose/Use Type of data Legal basis [and retention period]
To register you as a new customer (a)  Identity

(b)  Contact

Performance of a contract with you

We will retain this data for the whole period that we supply services to you.

To process and deliver your order including:

(a)              Manage payments, fees and charges

(b)             Collect and recover money owed to us

(a)  Identity

(b)  Contact

(c)  Financial

(d)  Transaction

(e)  Marketing and

Communications

(a)              Performance of a contract with you

(b)             Necessary for our legitimate interests (to recover debts due to us)

We will retain this data for the whole period that we supply services to you.

To manage our relationship with you which will include:

(a)              Notifying you about changes to our terms or privacy policy

(b)             Dealing with your requests, complaints and queries

(a)  Identity

(b)  Contact

(c)  Profile

(d)  Marketing and

Communications

(a)              Performance of a contract with you

(b)             Necessary to comply with a legal obligation

(c)              Necessary for our legitimate interests (to keep our records updated and manage our relationship with you

We will retain this data for the whole period that we supply services to you.

To enable you to partake in a prize draw, competition or complete a survey (a)  Identity

(b)  Contact

(c)  Profile

(d)  Usage

(e)  Marketing and

Communications

(a)              Performance of a contract with you

(b)             Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)

We will retain this data for the whole period that we supply services to you.

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) (a)  Identity

(b)  Contact

(c)  Technical

(a)              Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

(b)             Necessary to comply with a legal obligation

We will retain this data for the whole period that we supply services to you.

To deliver relevant website content and online advertisements to you and measure or understand the effectiveness of the advertising we serve to you (a)              Identity

(b)             Contact

(c)              Profile

(d)             Usage

(e)              Marketing and Communications

(f)               Technical

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)

We will retain this data for the whole period that we supply services to you.

To use data analytics to improve our website, products/services, customer relationships and experiences and to measure the effectiveness of our communications and marketing (a)  Technical

(b)  Usage

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

We will retain this data for the whole period that we supply services to you.

To send you relevant marketing communications and make personalised suggestions and recommendations to you about goods or services that may be of interest to (a)  Identity

(b)  Contact

(c)  Technical

(d)  Usage

(e)  Profile

Necessary for our legitimate interests (to carry out direct marketing, develop our products/services and grow our business) and/or as applicable Consent, having obtained your
you based on your Profile

Data

(f) Marketing and

Communications

prior consent to receiving direct marketing communications

We will retain this data for the whole period that we supply services to you.

To carry out market research through your voluntary participation in surveys Necessary for our legitimate interests (to study how customers use our products/services and to help us improve and develop our products and services).

We will retain this data for the whole period that we supply services to you.

8. Marketing

You will receive marketing communications from us if you have requested information from us or purchased goods or services from us and you have not opted out of receiving the marketing.

We may also analyse your Identity, Contact, Technical, Usage and Profile Data to form a view which products, services and offers may be of interest to you, including those offered by the Group so that we can then send you relevant marketing communications. Opting out of marketing

You can ask to stop sending you marketing communications at any time by contacting us at CustomerServices@mis-ams.com.

If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes for example relating to order confirmations for a product/service warranty registration, updates to our Terms and Conditions or checking that your contact details are correct.

9. Disclosure of Information  

We may disclose information we hold about you to third parties for the purpose of providing services you have requested, or where legitimately requested for legal or regulatory purposes, as part of legal proceedings or prospective legal proceedings. We will not sell, rent or share your personal information, with or to any third parties, without your express permission.

10. Monitoring 

We may monitor and record calls made to us for the purposes of quality assurance, legal, regulatory and training.

11. Protection of Information  

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, including those of the Group, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

12. Links To 3rd Party Web Sites.

Our website may contain links to other recognised and respected organisations websites. We are not responsible for the privacy practices of these sites. This privacy policy applies solely to information collected on MIS-AMS websites.

13. Transferring Data 

Whenever we share your personal data within our Group who are all based within the EU and for the purposes of delivering you a website, responding to your enquiries and/or in the performance of a contract or supplier contract. We ensure an appropriate degree of protection is afforded to it.

Whenever we transfer your personal data out of the European Economic Area (EEA), we ensure an appropriate degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK’s Information Commissioners Office (ICO)

Where we use providers based in the USA, we will only engage companies who have provided assurances that requires them to provide similar protection to personal data shared within the EEA and the UK, and or signed up to the EU-U.S. and Swiss-U.S. Data Privacy Frameworks (DPF) and the UK Extension to the EU-U.S. DPF as set forth by the US Department of Commerce regarding the collection, use and retention of personal information from the EEA, Switzerland and the UK, respectively. Further details on the DPF can be found here: https://www.dataprivacyframework.gov/Program-Overview

MIS-AMS has signed a Data Sharing Agreement which following our exit from the EU, means we can continue to share data within the confines of the Group.

Our directors and other appointed individuals working for MIS-AMS may, in limited circumstances, access individuals personal date outside of the UK and European Union, e.g. if they are remote working, absent from the office and need to access critical business information. If they do so they will be using our security measures and will be subject to their arrangements with us which are subject to English Law, in line with the DPA and the same legal protections that would apply to accessing personal data within the UK

A complete list of the service providers/sub processors used by MIS-AMS can be found at Annex 1.

14. Data Retention  

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for seven years after they cease being customers for tax purposes.

In some circumstances you can ask us to delete your data: see paragraph 15 below for further information.

In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

15. Rights

You have a number of rights under data protection laws in relation to your personal data.  You have the right to:

If you wish to exercise any of the rights set out above, please contact us.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

16. Changes to This Policy 

We reserve the right to change this policy at any time and updated version will be made available from time to time. Your continued use of our sites following the posting of changes to this policy will mean you accept those changes. Information collected prior to the time any change is posted will be used according to the terms of the policy that applied at the time the information was collected.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example a new address or email address.

17. Complaints

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

18. Contact Us

If you would like further information about this policy or you wish to enquire about the data we hold about you, please contact us in writing at:  MIS Active Management Systems Limited, International House, 36-38 Cornhill, London EC3V 3NG. Email: ukdataprotection@aareon.com

19. Version Control Version

Version Date Author
Rev 1 10/05/2018 Christopher McLaughlin New version revised for GDRP
Rev 2 21/08/2018 Christopher McLaughlin CMc updated to make MIS Group compliant
Rev 3 06/01/2023 Andrew McLaughlin Updated to MIS Group Template & included section on right to be forgotten
Rev 4 01/08/2025 Gurdeep Clair Update following Aareon acquisition.

This document is reviewed annually, next date: August 2026

 

 

Annex 1

1. Incline-IT Limited – Charnwood House, Gadbrook Business Centre Northwich, Cheshire CW9 7UG

Provides managed file server hosting services

Data is stored and processed on Incline-IT managed servers hosted on AWS and Microsoft Azure within UK.

2. BluQube Limited – The Old Brewery Business Park, 7–11 Lodway Pill, Bristol, North Somerset BS20 0DH

Provides secure cloud-based accounting and data storage services.

Data is hosted in the United Kingdom, specifically in The Bunker, a highly secure, nuclear-bomb and flood-proof facility with multiple backups and strict physical security controls. BluQube does not transfer data outside the UK/EU unless required by law and only with appropriate safeguards such as Standard Contractual Clauses (SCCs).

3. SAP SE – Dietmar-Hopp-Allee 16, 69190 Walldorf, Baden-Württemberg, Germany

Provides secure cloud hosting and application services for accounting and financial management

Data is hosted in SAP-managed data centres or approved IaaS partners (AWS,

Azure, GCP) within the EU/EEA and UK, including locations such as Germany (Frankfurt, Walldorf), Ireland (Dublin), and the UK (London). SAP deploys secondary data centres in-region for disaster recovery. No personal data will be transferred outside the UK/EU without appropriate safeguards such as Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA).

4. Hubspot UK – 3rd Floor, 1 Ashley Road, Altrincham, Cheshire WA14 2DT

We use HubSpot, a customer relationship management and marketing automation platform, to manage communications, track engagement, and improve our services.

Uses secure cloud infrastructure with data centres located in the EU (primarily Ireland) and the United States, applying GDPR-compliant safeguards for any international transfers (including Standard Contractual Clauses).

HubSpot is certified under ISO 27001, SOC 2, and adheres to GDPR requirements. Data is encrypted in transit and at rest, and access is restricted through role-based controls.

Further information can be found in the HubSpot privacy policy:

https://knowledge.hubspot.com/de/privacy-and-consent/what-cookies-doeshubspot-set-in-a-visitor-s-browser

5. Salesforce UK Limited- Floor 26, Salesforce Tower, 110 Bishopsgate, London EC2N 4AY

We use Salesforce, a cloud-based customer relationship management platform, to manage client data, communications, and service delivery. Hosts data in secure cloud infrastructure located in the UK and EU regions, with some services involving transfers to the United States under GDPRcompliant safeguards (including Standard Contractual Clauses and adherence to UK/EU data transfer rules).

Salesforce is certified under ISO 27001, SOC 2, and complies with GDPR requirements.

For more details on Salesforce’s compliance, see https://www.salesforce.com/company/privacy/.

6. Zscaler Inc. – 120 Holger Way, San Jose, CA 95134, USA

We use Zscaler cloud security services to protect our network and data. For EU/UK customers, data is processed within European regions. Zscaler processes limited metadata (e.g., IP addresses, URLs) for security purposes and does not store or access the content of communications. For more details, see Zscaler’s Privacy Policy.

For more details on Zscaler’s compliance, see COMPANY PRIVACY POLICY | Zscaler

7. Amazon Web Services EMEA SARL – 1 Principal Place, Worship Street, London, EC2A 2FA

We use Amazon Web Services (AWS) to provide secure cloud infrastructure for hosting and processing data. AWS provides customers with control over where their data is stored and processed, offering strong encryption for data in transit and at rest, and robust access controls.

Data for UK customers is hosted and processed in the AWS Europe (London) Region.

8. Sava Limited – 4 Mill Square, Featherstone Road, Milton Keynes, MK12

5ZD, United Kingdom

We use Sava to manage property and energy performance data. Personal data processed within the CRM includes property details, contact information, and EPC-related data, strictly for the purposes of property management and compliance. Data is hosted and processed on secure servers located within the United Kingdom and the European Economic Area (EEA).

For more information, please refer to Sava Privacy Notice Sava.

9. Pendo.io Inc – 418 South Dawson Street, Raleigh, NC 27601, USA

Website and product experience and analytics platform (user behaviour analytics, NPS and feedback collection).

Pendo provides a separately managed environment, hosted entirely within the EU.

For more information, please refer to https://support.pendo.io/hc/en-us/articles/22832528657179-Global-data-hosting

10. Netcall PLC – Suite 203, Bedford Heights, Brickhill Drive, Bedford, MK41 7PH, United Kingdom

We use Netcall’s document management and automation solutions to support secure processing and storage of documents.

Data is primarily hosted and processed within the United Kingdom and may also be stored in secure environments within the European Economic Area (EEA).

For more information, please refer to Netcall’s Privacy Policy.