Customer Privacy Policy
At Bliss-Systems we are committed to protecting the privacy and security of personal information. We recognise that the trust of our customers, website visitors, partners, and stakeholders is fundamental to our success.
This Privacy Policy explains how we collect, use, store, protect, and manage personal data when you visit our website, contact us, or use our services.
This policy supports our commitment to quality management, customer satisfaction, continual improvement, and information security, aligning with the principles of ISO 9001 and ISO/IEC 27001.
This policy applies to:
- Visitors to our website.
- Customers and prospective customers.
- Individuals who contact us via email, telephone, forms, or social media.
- Any personal information collected through our website or business activities.
We may collect the following types of information:
Personal Information
- Name
- Job title
- Company name
- Email address
- Telephone number
- Postal address
- Information submitted through enquiry forms
Technical Information
- IP address
- Browser type
- Device information
- Operating system
- Website usage information
- Cookie and tracking data
Service Information
Where applicable, we may collect information necessary to provide products or services, support requests, quotations, or contractual services.
How We Use Your Information
We use personal information to:
- Respond to enquiries and requests.
- Provide products and services.
- Manage customer relationships.
- Improve website performance and user experience.
- Monitor service quality and customer satisfaction.
- Meet contractual, legal, and regulatory obligations.
- Protect our systems, information, and business operations.
- Support continual improvement activities.
We will only use personal information where there is a legitimate business purpose or lawful basis for doing so.
Legal Basis for Processing
Where applicable, we process personal data under one or more of the following legal bases:
- Consent
- Contractual necessity
- Legal obligation
- Legitimate business interests
Cookies and Analytics
Our website may use cookies and similar technologies to:
- Maintain website functionality.
- Understand website usage patterns.
- Improve user experience.
- Enhance website security.
Visitors can control cookie settings through their browser preferences.
Information Security
We take appropriate technical and organisational measures to protect personal information against:
- Unauthorised access
- Accidental loss
- Alteration
- Disclosure
- Destruction
- Cybersecurity threats
These measures may include:
- Access controls
- Secure authentication
- Encryption where appropriate
- Security monitoring
- Employee awareness training
- Regular risk assessments
Our approach to information security supports the principles of an Information Security Management System (ISMS) aligned to ISO/IEC 27001.
Data Sharing
We do not sell personal information.
We may share information with:
- Approved service providers and suppliers.
- Professional advisers.
- Regulatory or law enforcement authorities where required by law.
- Technology providers supporting our website and business operations.
Any third parties processing personal information on our behalf are required to maintain appropriate confidentiality and security controls.
Data Retention
Personal information will only be retained for as long as necessary to:
- Fulfil the purpose for which it was collected.
- Meet legal and contractual obligations.
- Resolve disputes.
- Support business operations and quality management requirements.
When information is no longer required, it will be securely deleted or anonymised.
Your Rights
Subject to applicable data protection laws, you may have the right to:
- Access your personal data.
- Correct inaccurate information.
- Request deletion of your information.
- Restrict processing.
- Object to processing.
- Request data portability.
- Withdraw consent where processing is based on consent.
Customer Focus and Continuous Improvement
As part of our commitment to customer satisfaction and service excellence, we regularly review feedback, security controls, data management processes, and business performance to improve the effectiveness of our services and the protection of personal information. This supports the customer focus and continual improvement principles of ISO 9001 and ISO/IEC 27001.
Third-Party Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices, content, or security of external sites and encourage users to review their privacy policies.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in legal requirements, technology, business operations, or security practices.
Contacting the Company
You can contact the DPO at [email protected].
Subject Access Request (SAR)
A Subject Access Request (SAR) is a request made by an individual seeking confirmation as to whether the organisation processes their personal data and, where applicable, access to that data and associated information.
The organisation reserves the right to request reasonable proof of identity before releasing personal data.
The organisation will respond to all valid SARs without undue delay and no later than one calendar month from receipt.
