ERU Hygiene, the trading identity of ERU HYGIENE LIMITED, maintains this Privacy Policy to explain how personal data is handled when a person visits this website, contacts the practice or engages our hygiene systems services. The policy describes the categories of data we collect, the lawful reasons for processing, the periods for which records are kept and the rights available to every individual. It applies to this website and to the professional services delivered from our registered address at 45 Oldway Lane, Slough - SL1 5LA, United Kingdom (GB).

We have written this policy to be read without legal training. Where a term carries a specific meaning under data protection law, we explain it in plain language in the relevant section. This policy does not create rights beyond those granted by applicable law, and nothing in it limits the statutory protections available to individuals in the United Kingdom or the European Economic Area.

1. Who We Are

ERU HYGIENE LIMITED is a company registered in the United Kingdom with its registered office at 45 Oldway Lane, Slough - SL1 5LA, United Kingdom (GB). The company designs and delivers hygiene-critical facility control and monitoring systems, including washdown control panels, hygiene monitoring software, cleanroom access control, CIP system integration, compliance dashboards and sensor calibration services.

For the purposes of applicable data protection law, ERU HYGIENE LIMITED is the controller of the personal data described in this policy. As controller, the company decides why personal data is processed and how that processing is carried out. Where the company acts on documented instructions from a client in the course of delivering a service, it may act as a processor for that client data, and the terms of the relevant service agreement or data processing agreement will govern those activities.

Any question about this policy, about a specific data record, or about the way the company handles personal data can be directed to the contact details in the final section. We aim to respond to privacy enquiries promptly and to answer in clear terms.

2. Scope of This Policy

This policy covers personal data processed through this website, through email and telephone contact with the company, through enquiries and quotations, through contracts for services and through the support and calibration work that follows delivery. It also covers the limited personal data that appears in the operation of hygiene monitoring and access control systems where the company provides those systems to a client.

This policy does not cover the practices of any organisation that is not controlled by ERU HYGIENE LIMITED. A client facility that operates its own systems, a third party website reached through a link on this site, and an external service that a visitor chooses to use all fall outside the scope of this policy, and their own privacy notices will apply instead.

Where a client provides the company with personal data about that client employees or visitors, the client remains responsible for ensuring that it has a lawful basis to share that data. In such cases, the company processes the data only as needed to deliver the agreed service and only in line with the client instructions.

3. Data We Collect

The company collects only the personal data that is needed for the purpose at hand. The categories are limited and predictable, and they do not include special category data unless a specific and lawful reason arises and is documented in advance.

Contact and enquiry data

When a person completes the contact form or writes to the company, we receive the name given, the email address, the subject selected and the content of the message. If a person telephones, we may record the telephone number and the details discussed so that a quotation or a follow-up action can be prepared.

Contract and service data

When a client engages the company, we hold the business contact details of the people who manage the engagement, together with site addresses, delivery schedules, commissioning notes and correspondence. This data is needed to deliver panels, software, access control, integration, dashboards and calibration work.

Technical and usage data

When this website is visited, the hosting environment may record standard technical data such as the browser type, the approximate region derived from an internet address, the pages viewed and the time of the visit. This data is used to keep the site available and secure, and it is not used to build advertising profiles.

Facility monitoring data

Where the company supplies hygiene monitoring or access control systems, those systems may record entries, exits, cleaning events, sensor readings and sign-offs. Some of that data may relate to identified individuals if the client chooses to link a name to an access token. In those cases the client determines the purpose of the processing and the company supports the client in operating the system.

4. How We Collect Data

Most personal data reaches the company directly from the individual concerned. A visitor types into the contact form, an enquirer sends an email to the published address, or a client contact provides details during a project conversation. In each case the person knows that the data is being given and can see the purpose for which it is offered.

Some data is collected automatically by the technical environment. The web server records a request when a page is loaded, and those records are kept for a short period for security and diagnostic purposes. This automatic collection is limited to what the server needs in order to serve the page and to detect abuse.

A further category of data is collected indirectly from a client. When a client asks the company to commission a cleanroom access system, the client may provide a list of authorised people and their access tokens. The company uses that list only to configure the system and to keep the access records accurate for the client.

5. Why We Use Data

Personal data is used for a small number of clearly defined purposes. First, it is used to answer an enquiry, to prepare a quotation and to take the steps needed before a contract is formed. Second, it is used to deliver and support the services that a client has engaged, including installation, commissioning, calibration and ongoing support.

Third, data is used to keep the website and the company systems secure, to detect fraudulent or abusive behaviour and to maintain reliable service. Fourth, data is used to meet legal and accounting obligations, including the retention of tax and contract records for the periods required by law. Fifth, where a person has asked to receive updates, contact data is used to send those updates and to allow the person to stop them at any time.

The company does not use personal data for automated decision making that produces legal or similarly significant effects, and it does not sell personal data to any third party for that third party own purposes.

6. Lawful Basis for Processing

Every processing activity rests on a lawful basis. Where a person asks a question or requests a quotation, the basis is the taking of steps at the request of the individual before entering a contract. Where the company delivers a service that a client has engaged, the basis is the performance of that contract.

Where processing is needed to keep systems secure, to prevent fraud or to protect the integrity of the website, the basis is the legitimate interests of the company in operating a safe and reliable service. That interest is balanced against the rights of individuals, and the processing is limited to what is necessary for the stated aim.

Where the law requires the company to keep a record, such as an accounting record, the basis is compliance with a legal obligation. Where a person has given clear consent, such as a request to receive marketing updates, the basis is that consent, and the consent may be withdrawn at any time without affecting the lawfulness of earlier processing.

7. Cookies and Similar Technologies

This website is built to work without advertising cookies. It does not place tracking cookies that follow a visitor across other sites, and it does not embed third party advertising networks. Any cookie that is used serves a functional purpose, such as remembering a preference during a single visit, and it expires when it is no longer needed.

If the company later adds a feature that requires a cookie, a clear notice will be presented and any choice will be respected. A visitor can also block or delete cookies through the settings of the browser, although some functional features may then behave differently. Blocking tracking cookies has no effect on the ability to read this policy or to contact the company.

Server logs are separate from cookies. They record basic request information for security and diagnostics and are not used to identify a person beyond the needs of those purposes.

8. How We Share Data

The company shares personal data only where it is necessary and only with parties that are bound to protect it. Suppliers who provide hosting, email or accounting services may process data on the company behalf under written terms that require confidentiality and appropriate security. These suppliers act on instructions and are not permitted to use the data for their own purposes.

Where a project requires a specialist sub-contractor, such as an electrical installer or a calibration laboratory, relevant contact and site details may be shared to the extent needed to complete the work. The client is informed of the parties involved, and the sharing is limited to what the task demands.

The company may disclose data where the law requires it, where a court order compels it, or where disclosure is needed to establish, exercise or defend a legal claim. In such cases the disclosure is limited to what is legally required, and the company seeks to notify the affected person where it is lawful and practical to do so.

9. International Transfers

The company is based in the United Kingdom, and most processing takes place there. Where a supplier stores data outside the United Kingdom, the company puts appropriate safeguards in place before that transfer occurs. These safeguards may include standard contractual clauses approved for the purpose or a determination that the destination provides an adequate level of protection.

Where a client is located outside the United Kingdom and asks the company to deliver a service there, data needed for the project may be transferred to that location to perform the contract. The transfer is limited to the records required for delivery and support, and the client is informed of the arrangement as part of the engagement.

A person who wishes to know more about the safeguards used for a particular transfer may contact the company using the details in the final section, and we will explain the mechanism that applies.

10. Retention Periods

Personal data is kept only for as long as it is needed for the purpose for which it was collected, plus any period required by law. Enquiry data that does not lead to a contract is normally kept for a limited period so that a follow-up question can be answered, and it is then deleted or anonymised.

Contract and accounting records are kept for the period required by tax and company law, after which they are securely destroyed. Calibration and commissioning records are kept for as long as the relevant system remains in service or for the period agreed with the client, because those records support the audit trail that the client relies upon.

Facility monitoring data is retained according to the schedule agreed with the client that operates the system. Where a client asks the company to delete monitoring records, the request is honoured to the extent that no legal or contractual obligation requires the records to be kept, and the client is informed of any record that must be retained.

11. How We Protect Data

The company applies technical and organisational measures that are appropriate to the risk. Access to personal data is limited to staff and suppliers who need it for a defined task, and access is protected by authentication. Systems are kept updated, and the principle of least privilege is applied so that no account holds more access than its role requires.

Data in transit is protected by encryption where the service supports it, and data at rest is held in environments that apply access controls and regular backups. Physical records, where any exist, are stored securely and are accessible only to authorised staff. Staff are made aware of their responsibilities, and any suspected incident is investigated promptly.

No system can be guaranteed to be entirely secure. If a personal data breach occurs that is likely to result in a risk to the rights of individuals, the company will act to contain it, will notify the relevant supervisory authority where required, and will inform affected individuals where the law requires it.

12. Your Rights

Individuals have rights over the personal data that the company holds about them. These rights include access to the data, correction of inaccurate data, deletion where there is no continuing lawful reason to keep it, restriction of processing in certain circumstances, and objection to processing that rests on legitimate interests.

Where processing rests on consent, the right to withdraw that consent is available at any time. Where processing is carried out by automated means on the basis of consent or contract, a person may ask for a portable copy of the data. These rights are not absolute, and each request is considered against the circumstances and the legal obligations that apply.

To exercise a right, a person may write to the contact details in the final section. The company will confirm identity where necessary, will respond within the period required by law and will explain any reason why a request cannot be fully met. Exercising a right is free of charge in ordinary circumstances.

13. Privacy for Children

This website and the services of ERU HYGIENE LIMITED are intended for businesses and professionals. They are not directed at children, and the company does not knowingly collect personal data from children. The contact facilities on this site are provided for adult representatives of client organisations.

If the company becomes aware that personal data relating to a child has been collected without an appropriate lawful basis, the company will take reasonable steps to delete that data promptly. A parent or guardian who believes that a child has provided data through this site may contact the company so that the matter can be investigated and resolved.

14. Marketing Communications

The company sends marketing communications only where it has a lawful basis, which is normally clear consent or, in the case of existing business contacts, a relevant legitimate interest in sharing information that is closely related to a service already provided. Every communication includes a simple way to stop receiving further messages.

A request to stop marketing is honoured promptly, and the contact is placed on a suppression list so that no further promotional messages are sent. Transactional and service messages that are part of a contract, such as a commissioning notice or a calibration reminder, are separate from marketing and may continue while the contract is active.

The company does not sell or rent contact lists, and it does not pass personal data to third parties for those third parties to market their own products.

15. Facility and Monitoring Data

Hygiene monitoring software, cleanroom access control and compliance dashboards process operational data on behalf of the client that operates the facility. This data is used to hold a hygiene sequence steady and to produce the evidence that an audit or regulator may request. Where it relates to identified people, the client is responsible for the purpose and for informing those people.

As a processor, the company acts only on the documented instructions of the client, applies the agreed security measures, assists the client in responding to individual rights requests and returns or deletes the data at the end of the engagement as the client directs. The company does not use client operational data for its own purposes.

Where the company provides calibration services, the records of verification are kept so that the traceability of a measurement can be shown. These records are service records rather than marketing data, and they support the audit trail that the client and any regulator may examine.

16. Third Party Links

This website may contain links to external sites that are not operated by ERU HYGIENE LIMITED. Those links are provided for convenience, and the company does not control the content or the privacy practices of the destinations. A person who follows a link should read the privacy notice of the destination before providing any personal data there.

The company accepts no responsibility for the data handling of external sites. A link from this site does not imply endorsement of the destination privacy practices, and any interaction with an external site is governed by that site own terms and notices.

17. Changes to This Policy

This policy may be updated from time to time to reflect changes in the services, in the law or in the way the company operates. When a material change is made, the revised policy is published on this page with a new effective date, and the change applies from that date.

Where a change significantly affects how personal data is used, the company will take reasonable steps to bring the change to the attention of affected people, such as a notice on the website or a direct communication where an appropriate contact exists. Continued use of the website or services after a revised policy takes effect indicates acceptance of the update.

Previous versions of this policy are retained internally so that the basis on which earlier processing occurred can be demonstrated if required.

18. Complaints and Supervisory Authorities

A person who is unhappy with the way personal data has been handled may contact the company first so that the matter can be investigated and, where possible, resolved. The company takes complaints seriously and will explain the outcome clearly, including any action that has been taken in response.

In the United Kingdom, a person also has the right to lodge a complaint with the Information Commissioner Office, which is the supervisory authority for data protection. In other jurisdictions, the relevant supervisory authority may be contacted. The company cooperates fully with any lawful investigation conducted by a competent authority.

Nothing in this section prevents a person from seeking a judicial remedy where the law provides one, and the company respects the right of individuals to pursue the protections available to them.

19. How to Contact Us

Questions about this policy, requests to exercise a right, and any concern about the handling of personal data may be sent to ERU HYGIENE LIMITED at the registered address 45 Oldway Lane, Slough - SL1 5LA, United Kingdom (GB). The company may also be contacted by email at digital@eruhygiene.hair or by telephone on +14019223701.

To help us respond quickly, please include enough detail to identify the relevant record, such as the name used in correspondence and the approximate date of contact. Where a request relates to a right, the company may ask for proof of identity before acting, so that data is not disclosed to the wrong person.

This policy is maintained by ERU HYGIENE LIMITED and applies to all processing described above. We are committed to handling personal data with the same discipline that we bring to the hygiene systems we build, and to keeping the record of that handling clear and defensible.