Downloaded for printing on: Sun Jun 16 04:43:00 2024 GMT.   Unpaginated content follows.


The FIRMS Privacy Policy

Version No. 2.0        Date of Issue 4 February 2020

The FIRMS Network’s commitment to Privacy

Your privacy is important to us. The FIRMS website (hereafter “Site”) is controlled and operated by The FIRMS Network (which is referred hereafter as “FIRMS”, “we”, “us” and/or “our”).

This Privacy Notice explains our online information practices. This includes a description of the types of personally identifiable information (hereafter “Personal Data”) data we may collect, how we may use it, with whom we may share it and how you can make choices about the way your Personal Data is collected and used.

This Privacy Notice applies to all Personal Data collected or submitted on this Site. Links within this Site to other websites are not covered by this Privacy Notice.

The Personal Information we collect

This Privacy Notice applies to all Personal Data collected or submitted on this Site including information you provide voluntarily to us and information we may collect from your use of our Site. The Site allows you to make requests for information or contacts and register your interest in joining FIRMS.

We may obtain the following types of Personal Data:

  • Name;
  • Job title and Employer’s name;
  • Work or Other Address;
  • Work or Other Email address;
  • Work or Other Phone number;
  • Browsing information relating to your use of the Site; and
  • Internet Protocol (IP) address of your Internet Service Provider

How we collect Personal Information

We collect Personal Data through:

  • Your voluntary input of your personal information on the Site;
  • The use of cookies (as explained in more detail below); and
  • Technologies such as Google Analytics


Like most websites, the Site uses cookies on the Site helps improve your experience by catalogue traffic patterns. They ensure you are provided with an enhanced customer experience each time you return to visit our Site.

The cookie assigns a 'User ID' to your computer and allows us to distinguish you from other users of the Site. However please note these cookies, by themselves, cannot be used to establish the identity of any user. The assignment of a cookie to your computer allows our Site servers only to identify your computer automatically when you visit our Site. Unless you have specifically told us who you are, the cookie will not let us know who you are.

You can set your browser settings to alert you before a cookie is placed on your computer or to reject cookies but please note that this may restrict your ability to use all features of the Site.

Google Analytics

Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Services. This data is shared with other Google services. Google may use the collected data to contextualise and personalise the ads of its own advertising network.

You can opt-out of having made your activity on the Services available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js and dc.js) from sharing information with Google Analytics about visits activity.

For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page:

Vertical Response

Vertical Response ("VR") is a web services company providing email campaign management. FIRMS uses VR to distribute information via email to persons who have shared their email address with us. Every email you receive from FIRMS through VR includes an "unsubscribe" button. Clicking "unsubscribe" ensures that VR can never send an email to that address again.

For more information on the privacy practices of VR, please visit their Privacy & Terms web page:

The way we use Personal Information

We may use the Personal Data we have collected to:

  • Improve the Site and customer experience (i.e. troubleshooting) and enable FIRMS to identify and prevent future issues;
  • Communicate with you (respond to any emails you may send to us, e.g. membership or Approved Practitioner requests); and
  • Compile and analyse trends on the Site

The Personal Data we obtain is used for the purposes (as described above) for which you have given your consent, except where otherwise permitted by applicable privacy laws. FIRMS does not sell on details of our contacts. Where necessary we will seek your consent to use your Personal Data for marketing purposes.

Please note that providing personal information to us is voluntary on your part. If you choose not to provide your details to us, we may not be able to make you aware of forthcoming FIRMS outputs (such as future editions of the Good Practice Guide for IRMS) or events (such as the FIRMS conference).

FIRMS’s legal basis for processing your Personal Information

Our legal grounds for processing your Personal Data for the purposes described above will typically be one of the following:

  • Your consent;
  • Our legitimate business interests; or
  • Compliance with a legal obligation.

Sharing Personal Information

We will never sell your personal information to outside parties.

If we disclose your Personal Data to any outside parties, we will ensure that this sharing is protected under an appropriate contract so that your Personal Data is only used by such outside parties in connection with the services they are delivering on our behalf. Please note that we are not responsible for the privacy practices of outside parties – such practices are subject to their respective privacy policies, but we do seek to work with trusted partners whose practices and values reflect our own.

Please note that your Personal Data may also be disclosed under special circumstances to governmental bodies in order for FIRMS to comply with legal or regulatory requirements.

Retention of data

FIRMS will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes and enforce our legal agreements and policies.

The Personal Data we collect, other than browsing information relating to your use of the Site; and the IP address of your Internet Service Provider are stored in a local database accessible by the Membership Secretary. A backup copy is also stored by the Chair.

Transfers of your Personal Information outside of the EU

Your Personal Data may be shared within FIRMS (e.g. amongst the FIRMS Steering Group). Please note that your Personal Data may sometimes be transferred to countries outside of the European Union on this basis. We will always ensure that appropriate measures are taken in accordance with all applicable laws to protect any such transfer of your personal Data outside of the European Union at all times.

Your right to Opt-Out / Unsubscribing

We never use or share the Personal Data provided to us online in ways unrelated to those described above without also providing you with an opportunity to unsubscribe / opt-out or otherwise prohibit such unrelated use.

You can exercise your right to unsubscribe from contact by emailing FIRMS at You should clearly state your name and the name of this Site on all communications. Please note that while we endeavour to respond to such requests promptly, it can take some time for your opt-out request to be implemented and for future communications to cease; we apologise if you receive emails that have already been scheduled for dispatch while your request is being processed. As noted below, you may also choose to exercise other rights you may have under applicable law – such as the right to access, correct or delete your Personal Data.

Your rights to access, correction and objection

You have the right to request access to the Personal Data we hold about you at any time by emailing and stating your name and the name of this Site. We will take reasonable efforts to provide you with a summary of any Personal Data collected by us. Depending on the nature of your request, this may take up a month for us to deal with, from when we have completed the required verification of your identity and the scope of your request.

While we always endeavour to take reasonable steps to ensure your Personal Data is kept up-to-date and accurate, you have the right to request correction of any Personal Data that is incorrect. You can contact us here or our data privacy lead at to request this. Please state your name and the name of this Site along with specific details of the information you would like us to correct or update in your correspondence.

You further have the right object to our use of your Personal Data in certain circumstances and to request that your Personal Data is forgotten. In the event you wish to exercise this right, please send an email to stating your name, name of this Site and clearly state your request for the deletion of your Personal Data. Such a request may prevent us from informing you about important Product and Service Information.

Your rights to restriction and data portability

You have the right to restrict the processing of your Personal Data by FIRMS in limited circumstances. As an example, where you contest the accuracy of your Personal Data, FIRMS will be required to restrict the processing of your personal information until the accuracy of your personal information has been verified.

You may also be entitled to the right of data portability in limited circumstances.

Our commitment to Data Security

To prevent unauthorized access, maintain data accuracy, and ensure the correct use of information, we have put in place appropriate physical, electronic, and organisational measures to safeguard and secure the information we collect on this Site. We only retain your Personal Data for as long as it is necessary for us to do provide the service you have requested or to which we otherwise have legitimate grounds for holding it.

How to contact us

Should you have questions or concerns about our compliance with this Privacy Notice, or wish to find out how your personal information is handled by FIRMS, please send us an email at FIRMS’ Data Protection Officer will then handle your enquiries.

If you are not satisfied with our response or you feel that the processing of your data by FIRMS infringes any applicable law, you have right to lodge a complaint with the Information Commissioner’s Office (the “ICO”). Further information with respect to such complaints can be found at

Updates to this Privacy Notice

This Privacy Notice may be modified from time to time, at our discretion and without prior notification to you. Changes to this Privacy Notice can be found on this page and will be effective immediately upon posting to this Site.