Website Privacy and Data Protection Policy

Purpose

The purpose of this policy is to outline how Earthworks Testing Limited (ETL) manages, protects, and processes personal data collected through its company website and online systems.

It ensures compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and ETL’s internal Data Protection Policy (POL–DP–001).

This policy demonstrates ETL’s commitment to transparency, lawful processing, and data security in relation to information collected via its website or online communications.


Scope

This policy applies to:

  • All personal data collected via the ETL website: https://etlgroup.co.uk
  • All ETL employees, contractors, and agents involved in managing or processing data received through the website.

All systems and IT infrastructure supporting website operations, managed on behalf of ETL by Tristar.


Who We Are

Company Name: Earthworks Testing Ltd 

Registered Address: Earthworks Testing Ltd – Unit 6, Eco Business Park, Eco Way, Dunscroft, Doncaster. DN7 4JJ 

Email: enquiries@earthworkstesting.co.uk

We are the Data Controller of any personal data processed through this website.


Responsibilities

  • Managing Director: Overall accountability for ensuring ETL complies with GDPR and the Data Protection Act 2018.
  • HR Director / Data Protection Officer: Maintains and reviews this policy, oversees data protection compliance, and responds to website-related data protection queries.
  • Tristar (IT Service Provider):
    1- Configures, maintains, and monitors all ETL IT systems, firewalls, and website security.
    2- Restricts, monitors, and records access to ETL’s digital systems and data.
    3- Ensures appropriate encryption, backup, and cyber protection measures are in place.
  • All Employees and Contractors: Must follow ETL’s data protection and IT security procedures, report any potential data breaches, and handle information responsibly.

Data Collected Through the Website

ETL’s website is primarily informational and does not facilitate online accounts or payment processing. The following limited types of personal data may be collected:

Type of DataExamplesPurpose for Collection
Contact InformationName, email, phone number (only when users contact ETL directly)To respond to enquiries and business requests
CookiesSmall files stored on user devicesTo improve functionality and analyse site performance (if enabled)

ETL does not intentionally collect or process sensitive personal data (e.g., health, religion, or criminal data) through its website.


Legal Basis for Processing

ETL processes personal data collected through its website on one or more of the following legal bases:

  • Legitimate Interests – responding to user enquiries, maintaining site functionality, and improving website performance.
  • Consent – where required for cookies or optional communications.
  • Legal Obligation – where data processing is required to comply with UK law or regulatory duties.


Data Security and IT Management

ETL’s data and IT systems are managed by Tristar, a professional IT services provider. Tristar is responsible for:

  • Installing and managing all firewalls to block unauthorised access.
  • Maintaining up-to-date antivirus, malware, and cyber-security protection.
  • Managing user accounts, passwords, and multi-factor authentication.
  • Encrypting data in transit and at rest where appropriate.
  • Monitoring network and website access to prevent misuse.
  • Conducting regular security updates, software patching, and audits.
  • Providing ETL with security performance reports and compliance assurance.

ETL also implements internal controls to ensure that:

  • Company laptops and mobile devices are password protected.
  • Staff follow IT and data security training requirements.
  • Data is only accessible to authorised personnel and retained securely.

Data Retention

ETL retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by legal or regulatory obligations.

Routine review and deletion procedures are in place to ensure data is not kept longer than necessary.


Sharing of Data

ETL does not sell or share personal data for marketing purposes. Limited personal data may be shared only with:

  • Tristar – for IT system administration and security.
  • Website Hosting Providers – for maintaining website functionality.

Where third-party providers are used, appropriate data processing agreements and security assurances are in place.


Cookies

ETL’s website may use cookies to enhance user experience and improve site performance. Users can choose to manage or disable cookies through their browser settings. A separate Cookie Notice is displayed on the ETL website, providing details on the cookies used and user consent options.


Individual Rights

Under the UK GDPR, individuals have the following rights:

  • Access to personal data held about them.
  • Correction of inaccurate or incomplete data.
  • Deletion of personal data where legally applicable (“Right to be Forgotten”).
  • Restriction or objection to processing.
  • Withdrawal of consent (where processing is based on consent).

To exercise these rights, individuals may contact ETL via: enquiries@earthworkstesting.co.uk

Complaints regarding data handling may also be directed to the Information Commissioner’s Office (ICO) at https://www.ico.org.uk.


Data Breach Management

In the event of a suspected or confirmed data breach:

  1. ETL will initiate an internal investigation led by the HSE Manager and supported by Tristar.
  2. If there is a significant risk to individuals’ rights, the ICO will be notified within 72 hours.
  3. Affected individuals will be informed promptly if their data is at risk.
  4. Tristar will assist ETL in technical containment and system recovery.
  5. All breaches will be documented, reviewed, and corrective actions implemented to prevent recurrence.


Monitoring and Review

ETL will review this policy 12 months after implementation and every 24 months thereafter.

Date: November 2025