This is the privacy notice for Themis International Services Ltd, incorporated in England, with company number 11733141, of Castle House, Castle Street, Guilford, GU1 3UW, UK.Themis Headquarters1-2 Paris GardenLondonSE1 8NDUnited KingdomWe are a risk management firm specialising in financial crime. We provide the following services:
This notice explains what personal data we collect in connection with the provision of our Services, why we need that data, and how we use it.We do not share personal data with 3rd parties other than in specific sponsor cases outlined later in this document. This notice should make it clear exactly when and to whom data may be transferred.Our website provides a small number of links to other websites, which are beyond our control. We encourage you to read the privacy statements on the other websites you visit.We might need to change this privacy notice from time to time. We will publish our privacy notice on our website (available at wearethemis.com) and we’ll do our best to update you directly if we think the changes might materially affect you. Please do keep an eye on our notice before giving us any personal data.
Our websites include:
If you visit our websites, we will use cookies: to help us make sure our website performs correctly; to analyse how visitors use our websites (to help us make our websites more effective); and to help us make marketing decisions about how we promote our services online.Cookies are small data files that websites store on your electronic device so that the website can store data and will enable us to collect information, which is likely to include data from which you can be identified.Our lawful basis for using cookies to collect and process usage data is that it is necessary to protect our legitimate interest in promoting our business.
THEMIS collects details from event attendees, event recordings, newsletter subscribers and subscribers of our Products where they have agreed to and accepted our data privacy policy.Separately, we also may identify people who are likely to find our events or products useful for their jobs by looking for source business contact details and information about an individual’s job role on publicly available resources and business websites.Our team will use those business contact details to send event invites and emails about relevant industry news.We always include an unsubscribe link at the bottom of any such email which we send, so that you can let us know if you do not wish to receive any further marketing emails.Our lawful basis for using personal data in this way is that it is necessary to protect our legitimate interest in promoting our business.
If you sign up for an event:
If you are speaking at one of our events:
We will use personal data that we collect from clients (which may include details of our clients’ staff) who have subscribed to receive our Services, in the following ways:
If you contact us about a job, we will use the information you provide us with to assess your suitability for the role and progress your application. Data we will require includes contact details, your curriculum vitae, your previous experience, education and answers to questions relevant to the role you have applied for. Our HR team and the hiring manager for the role will have access to this data.
We will only share your data with contracted third parties if it is necessary for the recruitment process, and will notify you at the time. We will never sell your data or use it for marketing purposes. If we need to securely process the data in another country, we will let you know before the transfer happens.
If your application is not successful, unless you ask us to retain your data for other opportunities in the future, we will store your details for six months to help with any questions, before securely deleting or anonymising the data.
If your application is successful, we will need to complete employment checks for legal reasons, to verify your right to work in the country and to verify your previous employment references.
We will only process such data to the extent required to achieve our legitimate interest of maintaining a workforce for our business.
A copy of our retention policy in respect of all of the personal data we hold can be accessed here.
Security of personal data is very important to us. Our business operates with a Cyber Security Essentials certification and we are working towards the ISO 27001 International Security Standard. We use a wide range of organisational, technical, physical and operational controls, which are assessed for effectiveness on a regular basis.
We will only disclose any personal data that we hold to our employees, affiliated companies and third parties who are contracted to help us provide our Services (some of whom may be based outside the EEA). Any such third parties will be acting as processors on our behalf and will be contractually bound only to use the data in accordance with our instructions and to implement adequate security measures. The data will only be transferred in these circumstances if appropriate safeguards are implemented between us and the processor.We may share personal data with third parties (which will also be acting as controllers in respect of that personal data) in the following circumstances:
Individuals have certain rights under the applicable data protection legislation in respect of the personal data which we hold relating to them. This includes:
If you wish to exercise any of your rights set out in section 6 above or contact us about any another matter, please contact our Data Governance Group on +44 (0)20 8064 1724.
Send and email to info@wearethemis.com
When we receive a request, we will try to verify your identity and the request, before responding to you within 28 days.
Given the nature of the Services we provide, in certain situations, we may be able to rely on certain exemptions under the General Data Protection Regulation and the Data Protection Act 2018. These exemptions may enable us to resist the disclosure of information, erasure requests and rectification requests in certain circumstances, and exempt us from some notification obligations.
We will confirm to you in writing to acknowledge receipt of any request we receive relating to your rights as a Data Subject, and we will let you know if we have complied with your request. If having, carried out an assessment, we believe we have an overriding reason for resisting your request, we will let you know why we have reached that conclusion.
We will retain details of your request for two years, for quality assurance purposes, and may retain request relating to marketing preferences or restricted use for a longer period to ensure that we can comply with your request and to help if you have any further questions about the matter. Any such processing will be limited to the extent strictly necessary to achieve our legitimate interest of providing a robust and secure data management procedure.
Please let us know if you are not happy about how we are handling your data. We will do our best to resolve the matter, but if you have further concerns it is your right to make a complaint to our Data Governance Group on +44 (0)20 8064 1724, or the UK Information Commissioner’s Office at https://www.ico.org.uk.
Responsibility for the implementation of this policy lies with the company CTO and Themis Senior Management Team. They are responsible for making the company aware of the policy, and for its review.
This policy will be reviewed every year and at points of significant change to the business such as the leasing of office premises or the addition of a new team location.
Signed by:
Matthew Deacon, CTO
21st July 2021